yellow said:Not true at all. There are a variety of attack vectors. Unpatched apache, ssh, OS pieces, etc. It's definitely happened. Unfortauntely, the easy of setting up OS X and some of it's nicer services makes it a rich target for attack. Grandma Jones doesn't know or care about security, but she does want to show those pictures of her grandchildren on her website!
But Grandma Jones isn't going to run an Apche server on her computer & serve the files up from there and I don't se how using iPhoto to publish photo's to .mac posts a security risk for her local computer.
yellow said:As for needing root to change passwords, naah..
Single User Mode -> use niutil to change the password properties. That should work, no?
Good time to use the OF Password!
So in single user mode you can change the pasword without knowing the current one? That isn't too smart...
I hadn't even thought of setting up an OF password though as unlike Wintel machines you don't get to see the usual BIOS stuff on Macs that sets off that little reminder in your head that you really should setup BIOS passwords one day.