Swedish hacker finds 'serious' vulnerability in OS X Yosemite
cso.com.au
cso.com.au
But nothing, absolutely nothing, on how to protect myself as an ordinary user. The only thing I was able to infer from the craptastic video is that the user they're escalating from is member of the "admin" group, i.e. not a "Standard User" but an "Admin" in OS X lingo.
Among other things, the most obvious difference to regular Accounts is that "Admin" users can use sudo by default, but no clue whatsoever is exploited here. Some pipe-fu with sudo? Or a stupid setting by apple allowing "admin" group members doing dangerous things without (re-)authentication?
In closing, best make sure you're using OS X as a "Standard" User, not "Admin". In my experience, it's quite painless.
Edit: > "Normally there are 'sudo' password requirements, which work as a barrier, so the admin can't gain root access without entering the correct password. However, rootpipe circumvents this," he says.
This at least hints at the possibility that said exploit does not work from a standard user. So there's that...
¹most likely not the researchers themselves, but some "CEO" or other suit-level.
"[...] nothing, absolutely nothing, on how to protect myself as an ordinary user." Really? He gave you two tips, didn't he? Make sure your default account doesn't have admin rights and use FileVault. He obviously can't tell us why FileVault helps without risking our safety. That's clearly not nothing.
> Really? He gave you two tips, didn't he?
I do stand corrected. Either the last paragraph was edited into the article after I wrote my comment, or I did not see it the first time. Unfortunately, I can no longer edit my previous comment.
It reminds me of the old suggestion given to Windows users and derided by OS X users.
Microsoft broke this chain of bad decisions in Vista--which itself resulted in the much-derided flood of UAC warnings.
I feel so naked.
Has anyone who uses brew and other dev stuff tried running Mac OS as a user account? Does it work out well?
Some banks, require that you use the token generator you've gotten to log on and manage your bank account while most other use a seperate password for the Verified by Visa/Mastercard SecureCode thing.
I'm super sketched out by the program as it appears to be run by a third party rather than Visa/Mastercard.
Other things "you have" in popular 2FA solutions are quite different, for instance your mobile phone number identity (for SMS) or your Google Authenticator.
[1] http://en.wikipedia.org/wiki/Transaction_authentication_numb...
It's a good idea, certainly, just a partly lousy implementation. Some banks will offer the option of sending you a TAN via SMS instead (so your phone is the "something you have"), but usually for a fee.
In Finland one bank (Nordea) uses one-time passwords so you get a pad with passwords in the mail (they automatically send new ones when you're about to run out) and you need to use them sequentially to log in, only the numeric "username" is static. Then when you try to transfer money you also need to input a challenge-response from the same pad.
IIRC another bank (Danske Bank) allows you to set a static username and password but you must also enter a challenge-response from a permanent pad to log in and to initiate transfers as well.
Can't speak about the others but they should be about the same.
Americans apparently just use a static username and password which is pretty mind boggling.
In the UK we tend to have a static username and password then either a hardware device, or a "Enter characters 1, 3, 8 from your secret information". (Where the secret information is 8-10 characters long and you're requested to enter from random offsets each time.)
I've used both systems, and entering three characters from the secret information is the least hassle, but not as reassuring as the hardware token.
I lived in the US for 6 months and was surprised to find that my American collegues found it less safe to use a bank card (with PIN) than a CC. Their arguments were that 'if someone gets your card AND PIN, they can do anything' as opposed to someone stealing JUST your CC and then he can do anything... Yes seems much safer.
We also have zero liability for unauthorized CC charges. So even if someone were to do that, the bank would be on the hook, not the user. Banks rely on a lot of computer analysis to determine whether a charge should be allowed.
It's much more of a pain to get money back into your bank account after it's been withdrawn. So although it's technically true that a bank card with PIN is more secure, to the end user, it's not any better.
Not at all the token system the parent describes.
For example, in India, by LAW, all domestic online transactions go through two-factor authentication. For one of my cards, I need to enter a secondary password while for another I need to enter a pin texted to my mobile. The second option is a hassle though, especially when I am travelling abroad and my standard mobile number is not functional.
For international transactions, this does not apply and the card details are enough for the transaction to go through. I guess there is no standard agreement between countries which Visa, MasterCard or Amex can implement (these are the only payment networks I use).
When I make online payments, I get redirected to a page where I have to answer a question/answer I've set-up a priori.
The two-factor authentication is optional. I enable it to feel more secure. I don't make too many online payments, but I do at least 5-6 times per month.
Attacking just Windows was just a consequence of it being the most widespread consumer OS.
If you're implying this new exploit and perhaps the other high-profile malware issues in more recents years is indicative of hacker interest due to surging Mac OS market share, I'm not sure that's entirely correct.
Outside of Apple iOS (mobile), Mac OS X (desktops and laptops) market share hasn't risen relatively that much over the past decade or so. And, in recent times, even the peak is only a few percentage points higher than it's been for many years.
When Mac OS market share was lower back in its Mac OS 9 days, there were far more widespread, problematic malware issues (viruses, trojans, etc.) that were propagating fairly well in the wild (by Apple's standards). That scenario proves that hackers were interested in Mac OS devices even when the Mac OS market share was lower than it is today.
Since the 90's, Macs have hovered around approximately 1 in 10 (give or take) of all computers in the United States with a customer base of a predominately higher income demographic. In other words, one may very well get more money out of a smaller subset of Mac users than a larger group of typical Windows users. Therefore, Macs have always been a target for a subset of hackers that, er... "specialize" in that kind of scenario.
In other words, while Mac OS market share may play some minor role in hacker interest in the platform overall in recent times, there hasn't been a huge surge in market share that would account for some radically increased hacker interest.
The reason malware was drastically reduced on the Mac platform since it switched from OS 9 to OS X (based upon a flavor of UNIX) was because of the superior security Mac OS X afforded the platform compared to Mac OS 9. That's why even as market share gradually climbed, overall Mac OS malware dropped dramatically for most of the past decade until more recent years.
I think the relatively small increase in malware (compared to Mac OS 9) for Mac OS X in the last few years is due to the fact that over time hackers are more likely to find exploits the longer they poke and prod at an OS. Also, over time, Apple programmers are increasingly likely to make mistakes here and there as time and piles of code goes on.
And, perhaps Apple is slipping in quality in regards to security for various reasons since their resources have been somewhat distracted with iOS devices in more recent years. Plus, over time, the amount of hackers, hacking skills, knowledge and tools have been increasing and improving quite drastically worldwide especially more so in recent years.
On top of those issues, there's been more attention brought to Apple via an iOS halo effect from iPads and iPhones that perhaps plays into more hacker interest in the Mac OS. I also suspect that the abundance of high-profile Apple commercials over the years has perhaps influenced some hacker perceptions that the Mac OS platform is more ubiquitous than it really is. And, the icing on the cake is perhaps more disgruntled hackers and hacktivists who are increasingly disillusioned or even hostile with the Apple brand for various reasons over the years.
But, as far as purely Mac OS X market share goes, there really hasn't been that large of an uptick to prod properly educated hackers to take much more interest than they did a few years ago or even a decade ago overall based upon market share alone.
When I first started doing this (about 10 years ago) I ran into some problems if I attempted to authenticate from a standard user to an admin user when trying to do sys admin stuff. I'd get weird permission errors.
So now when I want to do admin stuff like install software, I don't attempt it as a standard user. I simply log in to the admin account and install from there. Also I always log in to admin account when doing software updates such as for Firefox.
If you adopt this mindset it's really very simple to stick to it, and it's hardly much of an inconvenience. At least not for me, I'm not installing software every day.
Also when I'm about to visit a dodgy website or run some suspect software I log in to the Guest user account. That doesn't protect against local root escalation, but at least it's something. Then when I log out, I hopefully leave my problems behind.
Finally I maintain yet another account solely for accessing my financial sites. That way if my day-to-day account gets compromised, I still have a modicum of protection.
I really should use a separate machine solely for financial transactions. But I don't. I doubt if even 1% of people do. Any old machine should work, no matter how slow, because it's not used very often.
I think it has more potential for danger since it is not going to be used often, you would lack the security updates that might leave the computer vulnerable (e.g. shellshock). You might do all the updates before doing any transaction which is very troubling to wait for. But depending on the attack surface, there might be a window for attack between you connect to the internet and do the updates.
One example is you could have get attacked via shellshock from a malicious / infected router over DHCP.
Ditto. Only difficulties that come to mind are some installers failing to escalate, Adobe in particular.
Using separate accounts for dodgy and financial sites is a good idea, but I don't know if I'd stick to it. I fell out of the habit of using a separate account for building software.
The most cumbersome thing for now seems to be running `sudo` in terminal, but then again, how often do you really need to?
Using a standard user account was one of the things I started with on OS X after being used to the "user must be administrator" paradigm that's deeply entrenched in the Windows world for a very long time. Before Windows Vista came up with some way of UAC (User Access Control), being an administrator user on a Windows system was the least painful way to use the system. This style is still propagated even today in several companies with the latest versions of Windows.
The philosophy about being a non-admin user also ties into the UNIX-ness of OS X, and in all * NIX systems the recommendation is always to use a standard account and switch to a superuser/root account only when needed within a specific terminal for a specific task and exit out as soon as that work is done. When people on * NIX joke about "rm -rf /", there are people who remember the wounds of such experiences from real life when running as root (fortunately, I didn't have to learn from experience). :)
The "annoyances" for a standard user on OS X are that installing applications into /Applications or unlocking panels in System Preferences (if it has been configured to be that way) needs administrator credentials. And it's also required if one fancies getting into system (or protected) directories and wants to move/delete/rename/add files.
On the terminal, when needed, I switch from the standard user to the administrator account and then use sudo. It is indeed a little more cumbersome than providing sudo privileges to the standard user account, but it's not often that I need this and I don't find this inconvenience as a big waste of time.
On a lighter note, using a * NIX system as an administrator user all the time seems dirty, just like using a Windows system as a non-admin user does. :P
P.S.: Couldn't figure out a way to escape and type an asterisk followed by a non-whitespace character for the * NIX references.
It all works fine. For most things, like software installs and updates, I just get prompted for admin account credentials. For a few things (brew and editing hosts file), I su to my admin account in Terminal, then run the command.
I can't remember the last time I actually logged into my admin account, though.
There's a difference.
> Normally [...] the admin can't gain root access without entering the correct password. However, rootpipe circumvents this