The sooner everyone STOPS downloading the new versions - the sooner Apple will notice that folks are tired of beta testing and buggy software.
But in this day and age in the western world, people have nothing better to do than download the latest greatest in between work and reality tv.![]()
Click on the password field then leave it blank. Don't just leave it blank.Doesn't work for me. Can't replicate. Tried numerous times. Keeps asking for my password.
No - this appears to be constrained to High Sierra. Anecdotally, I can say that my co-worker's Sierra 10.12 install does not have this vulnerability.Is this something that has been possible since the very first OSX release?????
OMG IT WORKS!!!!
Mommy, I am scared.
Scene: Trying to make a Lisa with bigger um you get the idea (funny Lisa is an Apple computer).We're ******** eggrolls
I just tried this on my Active Directory Domain Joined Macbook Pro 13" on macOS 10.13.1 and this exploit gets worse!
Macbook has FileVault Turned ON
Brought up the lock screen and clicked switch user
Was able to bring up a Blank User ID and Password prompt
Username root
Manually clicked with the trackpad in the password field (left it blank)
Hit Enter key
System let me right in the "System Administrator" account. This so called account does not appear in the users section of the preference pane.
Also I am able to unlock any locked system preference with this root user and no password.
This is insanity. All a person needs is physical access to a machine and you are done. Not as big of a problem for the home but a massive issue for corporations like IBM or Google, both of which have thousands of Macs for their developers.
So they have to have already had access to the computer? Who else would have enabled it?
Read the article. The login screen can be fooled too. That means, anyone with physical access, have root access.
This level of "hack" requires the IQ of a potato to perform which means this is one of the worst security bugs to pop up in YEARS!
Is this something that has been possible since the very first OSX release?????
Slow down Apple please focus the next major release on OSX refinements not buggy and slow feature releases.
True. This can be fixed but still inexcusable.Read the news item. Fixed the bug with per Apple's instructions. All good. Move along peeps.
then if you once again enter root with no password it lets you in, in my beta 2 anyways.Nope, prompts for admin credentials if I do that, latest beta.
root? Lawd, I can hear the Unix sys admins I used to work with now... I have to forward this to my Security instructor. More importantly, I need to tell my friends who have Macs that DON’T frequent these forums.
Fortunately, I’m still on Sierra, but coincidentally was just having conversations earlier this evening with a friend who wanted to buy a MacBook Pro for the first time. He was asking my opinion and experience. I’m over here singing praises over the phone all while THIS is going on. Wow, let me go back and tell him to make sure whatever he decides to buy is NOT on High Sierra.
As crazy as this is to read, it’s sadly not surprising (outside of it being Apple where this happened!). Testing always gets shafted when software development projects get under the gun - if that phase is even given enough time to begin with. It’s becoming more and more common, but Apple really should know better. This is basic security and absolutely unacceptable. Apple should probably investigate this looking for malicious intent - it’s so basic and it clearly didn’t exist before. Just unbelievable.
I expect more to come out of this besides heads rolling. Just wow.
Hats off to the devs who found this and are spreading the word on fixes until Apple resolves this.
Read the news item. Fixed the bug with per Apple's instructions. All good. Move along peeps.
This should be an immediate patch sent out by Apple ... THAT is a fix. If this was Microsoft on Windows (take your pick on ANY version) .... man Bloomberg and everyone else would be pointing fingers dissing and saying this/that.
Spreading themselves too thin and I've heard can't retain talent? Not sure about the second one.This is worrying. Apple need to focus on Mac and stop rushing! What’s happening with Apple?
Is this something that has been possible since the very first OSX release?????
Slow down Apple please focus the next major release on OSX refinements not buggy and slow feature releases.
Is this only a High Sierra issue? Is the hack possible with the previous OS?
PUll it together Craig. You’re embarrassing yourself and Apple with iOS 11 and now this? What a shame.
Thanks. I currently run Sierra on an early 2016 MacBook Pro. Recently offered upgrade to High Sierra. Another reason not to I guess...It’s a High Sierra issue.