And it’s not just one manager. The whole management is screwed, it’s a disaster. I think now is really time to say : would you imagine this happening under steve jobs ?
And it’s not just one manager. The whole management is screwed, it’s a disaster. I think now is really time to say : would you imagine this happening under steve jobs ?
It's nowhere close to the greatest security failure in a decade. It's not even a contender in the far off distance. It's a well publicized vulnerability, and it's quite silly, but in the scheme of things it's just a Tuesday for CVE writers. We even had a vulnerability functionally identical to this, and similar in both severity and silliness, hit Linux within the past year.
If you're talking about Apple specifically, it's still not that bad. The vulnerability couldn't be arbitrarily executed remotely with default OS settings, and it didn't grant kernel access. The Trident flaws were significantly worse than this, and that's just the first that comes to mind.
Yes, yes, I know this wasn't the thrust of your point...but still. People get kind of hyperbolic when it comes to rating security vulnerabilities. It's more silly than it is severe. I expect at least one vulnerability of comparable impact on every major point release of every major operating system and web browser (not that this is a good thing, but it's logistically realistic). I don't think this is particularly bad for Apple's public image or reputation. Headlines about "the sky is falling!" vulnerabilities make the rounds every so often; for better or worse, it never really seems to stick in public consciousness.
If guest accounts are enabled by default and a guest account can exploit it, yea.. that's pretty bad.
Not necessarily; this aspect was unfortunately underreported:
"macos 10.13 bug isn't limited to root in all circumstances; via ARD, you can log in as any existing user (e.g. _applepay) and share the screen of the logged-in user. also _uucp is allowed to log in"
https://twitter.com/unsynchronized/status/935656609140711426
So that limits things in terms of who is affected.
> You'd still need physical access to a logged-in machine to exploit it.
Yes it does; if Remote Management was enabled (as is often the case for remote servers or mass deployments), an attacker could login via Apple Remote Desktop using default, pre-existing user accounts (_applepay, _uucp, etc) and a blank password without ever needing physical access.
Just tested again with a new, unpatched install of 10.13.1 on one Mac, connecting via Screen Sharing from another. To be clear, I never logged in as root on the 10.13.1 Mac at all, even via the exploit.
As I mentioned below, this remote exploit did NOT require ever logging in as root, whether with or without a password. This was a much more serious bug than is commonly understood.
You don't. You can exploit it from the login screen after a machine wakes from sleep, you can also exploit it remotely via Screen Sharing.
It's very silly, and I would also be embarrassed if I was involved in it, but those aren't good metrics for judging the realistic frequency of bugs like this, nor their severity. I've had vulnerabilities I've reported picked up by a bunch of news media before even though they weren't that serious. As it turns out, the media just latches on to security headlines, and everyone sort of forgets about it except us grumblers on Hacker News, because we Never Forget.
Someone from Google Project Zero has probably been inspired to start fuzzing the macOS at the UI level now, and that's a good thing - they should. But that's about all I'm taking away from this story.
Moreover:
> on an OS that’s only used as a personal computer, not as a server
This makes it less severe, not more so. I'd rather have a Heartbleed impacting nearly every server on the internet than a...whatever we're calling this, impacting every macOS computer in the world. I guess I can make a botnet...except I still have to be local to it in the majority of cases, or do specific targeting, or chain this with another piece of popular, compromised software, etc. It suddenly becomes a bit more complex than just someone pressing enter on a root prompt twice. Plus, if the vulnerability is laughably silly, it's usually easier to find than a chain of them that evidences a systemic misconfiguration in the entire OS.
In fact, I'd posit that the reason this story is getting so much attention is precisely because the vulnerability is so easy to understand, and because someone disclosed it on Twitter. Frankly, the whole situation is really quite funny in a black comedy sort of way. But while it's fun to write stories poking fun at large companies for their silly mistakes, it doesn't meaningfully reflect their security competency or the long term perception of their security competency.
Really I don't mean to trivialize it. It's not a good look, and definitely it's worthy of being patched. But I think it's worth looking at from a much broader perspective.
> This makes it less severe, not more so.
You are looking at it from the perspective of a seasoned security professional. It's like looking at the terrorist attack in Nice from a military point of view and saying "eh, this was just a guy on a lorry; it's much more difficult to raid Osama in the middle of Pakistan". That might well be, but this does not matter to the general public - to them, concepts like "botnets" are immaterial, whereas Slippin' Jimmy entering their macbooks to read their emails while they're sleeping is very real.
In that sense, the impact here was bigger than any other security hole ever experienced on the Mac.
I think I must be misunderstanding this, or else the rest of your comment. Did you really mean it this way (more Heartbleeds is better than more personal-OS vulnerabilities), rather than the other way around?
It was, via Screen Sharing and a few other remote mechanisms.
It "likely" wasn't often internet accessible due to firewalls, but it was remotely exploitable on many large Mac deployments in enterprise and education.
My laptop was vulnerable to this one for quite a while. [1] http://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetu...
So, being able to install spying software on any Mac OSX is something silly for you?
Let's say I just don't agree.
How many people read patch notes or are aware what security patch their Android has?
Of course it could have. Making software is hard, and mistakes get made. The idea that the magical presence of Steve would prevent this is absurd.
There were plenty of terrible MacOS bugs under Steve's reign too. I can't help but feel there is perhaps a new generation of Mac users who don't remember or didn't experience how painful OS X was at times, even many years after the OS 9 to X transition had started.
OS X versions 1-3 were pretty bad. 10.3 was the first to be useable. 10.4 was actually good. Then 10.5 Leopard (or Leper as we knew it) was awful on release. From Snow Leopard onwards it’s been much better, with the occasional howler of course.
It seems to be a constant refrain that Apple’s software quality is declining in the same way civilisation is always falling or HN is becoming more like reddit.
In High Sierra they painlessly replaced the filesystem. Quite an achievement. Although everyone involved in this latest problem should be highly embarrassed.
No, they did not. They still cannot upgrade any Mac mini server running RAID 1. They sold that configuration and crippled there software to put in the new file system. That is only painless for flash drive owners.
Funny - until recent years, I remember the mantra on MacOS being "yeah, but it's gotten better in the latest release".
Except that a colleague of mine who was adventurous enough to try it lost all the data. That stopped any one of us from upgrading (fortunately, if I may say so).
(it might be due to encryption, but it doesn't matter - the "painless" part is clearly not for everybody)
In big companies there are layers of 'management', including down to dev leads and tech/virtual leads who are devs by title. Knowledge of codebase/systems/deployment increases as you get down to the leaves. There are architects, release managers, product managers, etc. that should have provided multiple checks/balances. It's easy to point at "management" in big companies just as it is easy to point at "developers". But there's a whole bunch of nuances in the middle.
The fact that all the architects, release managers, and product managers that you mentioned do not function as a coherent structure capable of eliminating the occurrence of critical defects is the definition of management failure. NASA also had plenty of architects and directors when Challenger exploded. Such catastrophic failures, especially on repeat, are indicative of systemic disfunction. That is always the fault of top management.
Can't it be both? I feel like when people talk like this, it abstracts away from the concept of a bad decision. Everything's a tradeoff! Sounds great until you hit actual consequences.