macOS lock screen: “I just sent my session pass to my whole team”
twitter.com
twitter.com
For those interested, the sample exploitation that I've discovered was connecting any iPod/iPhone device to a OSX laptop while screen was locked was taking the focus away from login prompt 'into' the system, where iTunes was gaining it and from there it was just few OS level keyboard shortcuts from gaining network access to the system, while still locked: launch finder, go to tools folder, launch terminal, launch `nc` in the terminal to get the access via network. Lots of blind typing but it worked more times than not.
Any proofs? Perhaps you can demand a bounty payout or sue them ignoring!
Also, if you read the rest of the comment, Apple didn't ignore it. They fixed it.
To get the bugs fixed?
Also, we don't know why they didn't get recognition. The simplest answer is someone else may have reported it first. But it doesn't really matter. And I really don't see how "secrecy" comes into play here.
Perhaps, if the entire tech community regards Apple as a joke, they will start paying attention.
“Responsible disclosure” is great stuff for creating a culture of free outsourcing of tech companies’ most imporant feature (security) to the same people that paid those companies thousands of dollars for that privilege.
Show and focus a window when the user locks their machine.
- (void) viewDidAppear{
[super viewDidAppear];
[self.passwordfield becomeFirstResponder];
} func viewDidAppear(){
super.viewDidAppear()
passwordField.becomeFirstResponder()
}Responsible disclosure is more or less earned as your resources go to infinity.
I do agree that apple has had a ton of problems in this area and needs to work on it, but this example is very played out and boring.
Only by casual hackers. The pros will probably have been exploiting the flaw for weeks or months against gainful targets.
If there is a reasonable end-user workaround against the vulnerability then I'd argue it's more responsible to publish early and widely than to wait for the vendor.
It becomes greyer if there is no workaround. I'm not sure what I'd support in that case.
Calling what you describe as "Responsible" is intellectually dishonest.
I'd much rather that those things which are remotely exploitable across millions of devices to be kept quite for a small period of time (30-90 days depending on the complexity of the fix required) so that I can get patches from our vendors and schedule an update at the first available opportunity.
You might call it security through obscurity, I call it keeping shit from burning down.
Not telling the world about it does not keep shit from burning down. Eliminating vulnerable targets is the only thing that does that. And that is more expediently served by full and prompt disclosure.
If companies want more responsible disclosure they should introduce harder to find bugs - sneaky edge cases in memory allocation sequences, stuff you'd have to pore over a disassembler for weeks, or slightly weakened PRNGs that would take some serious knowledge of finite fields to discover :-)
s/that goes viral before reaching \"proper\" channels//
The fact that the problems existed to begin with is more troubling than whether they became known outside the company or not. IMO.
With an open source UNIX-like OS (like the ones Apple sourced from for parts of macOS), both the developers and the users can watch the commits as they happen. Developers and users anywhere can choose to watch the commits and may be able to detect a series of poor quality ones. At least they can make informed decisions on the relative merits of changes from one version to the next. (Edit: They might choose not to compile or install certain components. I do not use X11. Nor do I use systemd.)
The fact that development of macOS is hidden from those outside Apple and that problems are protected from "going viral" does not make the problems any less of an issue for macOS users.
The issue is not how fast and secretively they fix problems, it is how many problems their developers are introducing into the existing version to begin with.
If there are problems routinely being introduced then no amount of fixing after the fact and behind the scenes is going to make the OS higher quality. Only due care taken before introducing changes will guard against further deterioration of quality level.
(Edit: The mention of open source is not intended to be interpreted as an argument that open source inherently results in better software. Perhaps skill and attention to detail are at cause. This is a debate worth avoiding.
The relevance of the mention of open source is intended to suggest that detecting and avoiding problematic software may be easier for some users, e.g. yours truly, if they can access the source code. As opposed to hoping that Acme Hardware and Software Corporation will quickly and secretly fix all software problems that slipped through their QC procedures. Too late for the user who has already paid for the software and updated to the new version. That argument should not be too controversial.)
I'd send you to the relevant jwz rants but I'd rather spare everyone the goatse-ing...
Also, Linus' Law has some doubters. Things like Heartbleed show that Open Source isn't immune to long-standing, very impactful bugs.
Why all-or-nothing?
The fact is that free software has transparency as one of its advantages.
When software is closed-source, its users must rely on the developers to maintain that software.
> Why all-or-nothin?
The parent was citing the existence of a few specific bugs in macOS and Open Source as an alternative (implying it wasn't vulnerable). I really think the "given enough eyeballs, all bugs are shallow" is something Open Source advocates take too much comfort in. The idea does have merit, but there needs to be more study/context to how it plays out in real life.
Another example where this idea fails; there are credible suspicions that the NSA has influenced encryption standards introducing backdoors or known flaws even though the algorithms themselves are publicly known and freely available as well as the implementations.
That may be true, but the alternative is certainly worse.
If I found a bug in ssl, I can't imagine I'd re-compile that and track down every package I use that relies on it and re-compile those. Everyone uses their own build system and managing dependencies suck. I'd try and mitigate the risk against those tools until fixes were distributed through normal channels--just like I would in Windows or macOS.
If I was a large company, with closed source software I would have a vendor agreement to get fixes/changes, with open source I would have the expertise in-house and extra labor (or I'd have an agreement with a support company like Red Hat much like closed source software). A small company likely won't have the expertise in house or the spare bandwidth to mess with those things. For home users it would have to be someone with a serious hobby and specific skills.
Apple customers dont care about the tech , they care about cool. This is what Steve Jobs and apple as branded themselves on so thats what you get, cool without good tech. And it wont matter becuase that is not the reason people buy Apple.
Tech community doesnt care about Apple, but the engineers will happily take their money to work on their products. If apple falls programming and computing will go on happily and at least we wont have to build over priced products for a bunch of children to take selfie shots that dont care 2 cents that they have a technical marvel in their hands.
Also "Responsible disclosure" means absolute nothing to most people who are not security researchers. They don't know about it, even if there is a bounty and they could make a decent profit, they have no idea what those things are. They notice they can get root access or the focus sends their password to Slack and they'll tweet about it.
They didn't even include it into the big bounty, did they?
It feels like they don't give a shit about non-iOS-devices.
If the Woodway treadmills at the Palo Alto Equinox had the same uptime as my Macbook Pro, I don't think certain Apple execs would be happy.
This was one of the reasons I never adopted Linux on a laptop. Power management simply never worked. I used Windows for many years on a ThinkPad with Linux in a VM but this felt dirty. Bought a Mac and life was good. Well it was until 10.13. 50% of wake up events I have to log in to a trashed desktop now.
It makes me long for a computer nailed to a bit of ethernet that is never turned off.
Edit: also I just went through hell trying to get a USB to serial converter working on OSX. Not exactly a crap one, a Keysight U1173B with Prolific chipset.
Still getting random freezes sleeping and waking though. Especially if I don't open the internal panel before disconnecting the external monitors and USB hub before putting the laptop to sleep.
Aside:
I just wish there was an option in Mac to use "PC Shortcuts" in all my apps... it's the only place where some of the key combinations feel truly alien in most apps. I use a "PC" keyboard, but remap CMD to CTRL, ALT to SUPER/WIN, and CTRL to ALT... but in the end, terminal is awkward, and some other shortcuts are hard.
May take the time to figure out how to get VSCode how I like it with the windows/linux shortcuts, but my key bindings.. find/replace are particularly awkward to remember, and usually resort to mouse menus.
But holy hell do they need to work on their external monitor support. Yesterday I had one of my monitors randomly go black for a second. I’ve had audio over usbc just not show up anymore and it refusing to see my gigabit ethernet when waking up unless I unplug the actual ethernet cable. Simply amazing this passed their QA - and Id find it hard to believe no one at Apple uses clamshell mode with two monitors.
No problems with my Debian or Win 7 boxes which are presumably on the same switch
Strange that other two machines aren't effected if the DHCP server is to blame
Strongly disagree, and I can not conceive of how it could be viewed as "better" than hardware keys. Maybe if they moved it above the FN row and we regained the hardware escape key, while making it a build to order option. Even then, I personally would have no interest in it, and neither would anyone else I know. I do not want to look at my hands while I type, ever.
I wouldn't mind if they made the touch pad into a screen. Probably not that useful, but it wouldn't bother me.
You mean like making the laptop LCD a touchscreen?
Like other PC manufacturers have been doing for years?
… or that's what the fanboys will think.
I hope this is hyperbole, because it shouldn't be hard to understand. The TouchBar is absolutely an improvement. I can't remember the last time I actually used a laptop keyboard's F-keys for anything, but the TouchBar makes that space useful.
I use them regularly to switch consoles. MacOS supports multiple consoles, right?
Very awesome. I'm sure that Macs support something similar.
macOS also has Spaces, which is just virtual desktops, but again, it doesn't use the F-keys to switch between them.
My (un-trolling) point still stands, though: I use the Function keys on a daily basis, to switch between consoles.
Not even F5 in a web browser?
God forbid you try to use this with Windows though. Sometimes half of the screen cuts out, sometimes one side of it shifts by a couple hundred pixels (and wraps the right edge of the image around to a stripe down the middle of the screen), and god knows what other problems that I can't even remember. This was with a GTX 900 series GPU which is definitely "supported."
I used to have it hooked up to my Windows desktop since that's the fast computer with more storage and RAM, so it should be great for stuff like Lightroom. But since the screen doesn't work reliably, I moved that back to my MBP.
A friend with the same screen had identical issues on Windows and a similar solution. It's now on his wife's desk for her to plug her Macbook into.
Display signaling has gotten a lot more complicated than DVI/VGA were, and the reliability problems that have cropped up from that are present across the industry.
MST worked: https://www.amazon.com/gp/product/B01N11K30W/
MST did not work: https://www.amazon.com/gp/product/B06XFG1YKT/
I can't say for sure if it's the cable's fault or if it's the particular combination of cable/computer/screen that has some obscure compatibility problem. Makes me miss the days when a cable was a cable and we could tell people "Just buy any HDMI cable, no need to spend $60 on it."
I then got a usb c/thunderbolt to display port for 4k 60fps, and the issues significantly dropped, but it still occasionally happens.
The reality is that Apple's software is absolute shit. OS X was the only software that wasn't shit. I can't think of a single counterexample otherwise. They take great software (like logic audio) and turn it to shit. It's incredible. Clearly macos follows in the shit tradition of iTunes, the legendary mother of Apple's shit software.
I invested $15 in stay https://cordlessdog.com/stay/
I would not say the problem is solved (it's not going to solve artifacts, etc), but it helped me.
Thankfully, I haven't owned one, but I hear so much. Which sucks, because there are more and more nvidia-specific things I'd like to do on a mac laptop.
Super frustrating when I I sit down and wake up the machine to find both displays flashing. Usually unplugging the LG clears things up, but replugging often results in the brightness on one display being set randomly.
Here are the steps to reproduce:
- Start Mac
- Login
- Turn on Screen Lock: System Preferences > Security > General > Check "Require Password" and Select 5 Seconds.
- Turn on Hot Corner Sleep Display: System Preferences > Mission Control > Hot Corners > Select upper left > Put Display to Sleep > Ok
- Attach external monitor
- Activate hot corner by dragging mouse to upper left corner of screen
- Wait 6 seconds
- Click the mouse to trigger waking the screen
- See brief flash of the desktop without logging in!
Overall, there appears to be something funky with this overlay technique and how things are asynchronously rendered.
My gut instinct says that a some former people at Apple used to do a lot of undocumented QA work and sanity checks, and that as the company has grown and changed, nobody picked up the slack when they left. Now, they'll have to go through a formal process of re-identifying QA steps that need to exist, and hiring against them. It's been a hell of a month for them, though.
- Very good
- Wants to live near Palo Alto
- Is able to live in the US
- Wants to be subjected to Apple's privacy rules
- Wants to work on fixing bugs instead of making new features
In the software engineering game, money only goes so far.
If, in any other field you found people that only wanted to make first drafts, you'd call them copywriters and designers, not engineers. And even if it is totally normal to eschew bug fixing in favor of drafting, isn't there a salary that would cause people to do it? If so, Apple should just pay that and hire those people - it'll still pay off in the long run.
Also, I don't think the privacy restrictions would be so bad. Apple's UIKit engineers occasionally chit-chat with indie devs on Twitter.
The problem is that this job would be absolutely futile. If Apple hired 100 great engineers to fix bugs, management would simply double the amount of features that go into each yearly release.
The TouchBar, while interesting, is the perfect example of this. I'd love to have had it along with the physical buttons - there's plenty of room. Alone, though, it is pretty weird.
I assume that the real problem is that Apple's managers do email and web browsing, and that's it. They probably don't spend enough time in pro apps or trying to be productive to understand that a window manager built in, or physical keys or an improvement to their native text editor would be helpful.
I was used to hammering return a few times to wake the machine up, then typing in the password, then hitting return again.
The few times I hammered return woke the machine, the watch unlocked the mac and the password plus the return key went into the app that had focus which for me also was Slack.
Is it possible that this user had the same thing happen to them? When I disable the watch unlocking, I can't make the password go anywhere but into the login screen (10.13.1 here with last weeks security update applied)
Return is a dangerous key!
No idea how to prevent the issue, but I've been caught mid sentence before and accepted installs, upgrades, random popups, etc. Ones from Skype tend to be the most infuriating / scary..
We looked into this while I was Trolltech. Decided against doing it for Qt unilaterally, it's really something the system must do, or else it's too annoying.
They are just tidying up parameters for a bit of post constrast injection imaging. They hit enter to accept a parameter change just as a notification appeared to trigger the next scan. Basically it missed the key imaging phase and the scan had to be repeated a day later once the injected contrast had been cleared out of the patient’s system. Imaging equipment vendors seem to make custom UI in places where it is unneeded (software buttons which trigger on touch down, not touch up for critical functionality?! Why?) but in places where it would be safer to make something custom they don’t.
Edit: a possible exception being the “please enter your iCloud password” curse I somehow cast on myself sometimes.
See https://twitter.com/BenoitLetondor/status/939164367962148864
I witnessed it. I was not able to reproduce it in 10-15 minutes of testing. She did NOT type in the password. Just banging on the keyboard, playing with the screensaver.
Basically HN is him when he worked for Netscape and he doesn't like the reminder...
DON'T OPEN THAT LINK
https://news.ycombinator.com/item?id=11135200
>sirsar: JWZ used to detect the hacker news referrer and redirect all links that originated on hacker news to goatse. Now it's only slightly less graphic
There has been work to solve this by registering the session, compositor, and screen locker each with the session manager.
If the screen locker (which now can use any toolkit) crashes, the session manager can try to restart it. If it fails again, it just displays "your unlocker has crashed. To unlock this session, open a tty, login, and type `loginctl session-unlock`"
This solves all the issues, but he (and many others) have been fighting against systemd for a while (which fixes this, and so many other issues, which no competing project ever handled)
I've seen similar behavior when switching users. The full-screen password entry login comes up, but focus is still on regular apps.
This is also vaguely similar to the 'test SSL submit' security technique of first entering enough data into login forms to process a submission, and then entering real login info into the 'login failed' retry page after verifying SSL. This has lost some of its luster as non-SSL form submission has fallen out of wide usage.
AuthenticationMethods requiring both wasn't availabe in OpenSSH prior to v6.2 (May 2013)[1] and I'm on Windows anyway so I went with https://www.bitvise.com/ssh-server.
Is this why everyone does 2-step login on websites now?
I've also noticed another thing happening more lately - locking the screen, only to have it automatically unlock itself a second or two later. I always have to make sure it actually stays on the screensaver for a few seconds before I trust it will actually lock.
While most of the bugs have disappeared with the recent update, there are still some minor ones that really pisses me off: Screen freezing unresponsively for 30-60 seconds before things get back to control; and music playing randomly (happened a few times. Everything calm. Boom, music starts to play).
I'm pretty sure this mess wasn't here before the update to iOS 11.
Edit: Just found there is a new update. Let's see if they are getting their shit together this time.
It wasn't Slack-specific as I've only started using Slack recently.
Ever since systemd was a thing, that command has stopped being 'safe'. It no longers solely affect the filesystem. It can wipe your EFI variables and make your comnputer unable to boot at all, even unable to boot installers to reinstall linux.
https://github.com/systemd/systemd/issues/2402
Don't think of the file system as just the file system. If you keep thinking of / as only meaning 'whatever's in that hard drive' you will not like what you may encounter.
That specific setting was: my keyboard was used to setup his mini, mini was turned off and on later. My keyboard, already properly reconnected to my mac at that time, disconnects on timeout (or for whatever reason it does that few times a day). Mini “grabs” my keyboard when it goes back on air. I wake my sleeping mac via trackpad and try to type my password into focused password field. Non-obviously, no characters appear on my screen.
Maybe Slack or other apps have to call for focus, and MacOS is allowing those calls while it's locked.
The sheer amount of bugs in High Sierra is ridiculous, with the exception of the root password bug, I've personally experienced the following bugs with my Thunderbolt display:
* In 10.13 or 10.13.1 the built-in web camera was broken. The video would freeze after a few seconds when attempting to use the camera in FaceTime. This was fixed in 10.13.2.
* In 10.13.2 USB audio devices connected to the TB display no longer work properly. After playing audio through the device (USB DAC in my case) for 30-60 seconds, some sort of interference/electrical noise appears for 5-10 seconds every minute or so. I assume this has something to with "Improves compatibility with certain third-party USB audio devices." from the 10.13.2 release notes.
App Store is not working.
Downloading fix from website tells that my fusion drive is not compatible with this kind of install. Use App Store.
I don't even have a fusion drive.
Reminds me of people being told in chat to hit F10 to enable cheats in Counterstrike Source. Half the gamers would exit immediately.
Try it out: /disco party
This is why Windows NT runs the log-on user interface, the screen saver, and the elevation consent UI on separate desktops that have restrictive ACLs disallowing interactive user processes from creating windows there.
Nobody is denying that the "anti-hijacking" forcing of CTRL-ALT-Delete adds to security, what they're saying is that it has nothing to do with this topic.
This topic is about keyboard input focus. In Windows, due to the process hierarchy the login UI isn't running in the same context as desktop applications, so stealing focus or focus drift couldn't occur.
Yes, and the SAS guarantees that after you enter it, nothing else can have keyboard focus. I don't see why this is such a controversial point. You will never come to unlock your NT workstation and find that the keyboard focus is somewhere you don't expect, because you need to enter the SAS first.
Because It's untrue. The SAS is a sanity check.
If something is spoofing a login screen on your desktop and you press CTRL+ALT+DEL, you will get a system menu instead of a password prompt.
If you are in the login screen, which is able to hook CTRL+ALT+DEL, it will switch to the password prompt.
Here's the clincher: even if you have the SAS disabled (which it is by default on Windows 10) there is still no way for an app to steal focus from the login screen. The keyboard focus assurances are handled by something completely different - protected desktops (these also handle the UAC prompt for the most secure setting).
Full circle: even though nothing can ever steal focus from the login screen (unless it is running within that protected desktop), if you don't use the SAS there is no way for you to know that you are looking at the real Windows login screen.
I usually press control key to wake up every computer (shift doesnt work on some). that one time I woke it up by tapping on the touchpad.
Many of OSX's problems come from trying to shoehorn security on top of operating system concepts that were developed in 1969.
those are users dogfooding a product they paid for. and probably well off already, so the twitter bragging rigths is more valuable than the loss of anonymity + $500.
Posting it on Twitter, however, draws attention to Apple's waning security practices and how such glaring holes manage to slip past their peer review. It sparks public outrage, and may serve as a wake-up call to the company.
https://medium.com/@lemiorhan/the-story-behind-anyone-can-lo...