Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Some more in-depth information on the root password issue:

https://objective-see.com/blog/blog_0x24.html

Bonus HN comment:

If I am understanding this correctly:

Any existing but disabled account (an account with no shadow hash) will be upgraded to an account with a shadowhash. Normally this is fine, because it is an in-memory upgrade that allows the authentication code to run.

And then, because of a brain-dead if check, whatever password the user attempted to use is saved as the shadowhash for that account, permanently enabling the account with the password that was being tried. In this case, that means a blank password.

This allows a subsequent authentication with that same password to succeed. This accounts for the initial need to repeat the login multiple times.

Adbot
ADBOT LOVES YOU

Pivo
Aug 20, 2004


The comment has it slightly backwards. It wants to save it as a shadowhash ('upgrade' the account, it's not just in-memory), but the verify crypt password routine returns SUCCESS for any password for a disabled account. So, the following code was told the password entered is the correct password, and hashes that - since it can't have any other source for the plaintext. Thereby creating the shadowhash entry for root with the entered password and enabling the account. As the blog points out, obviously, the verify crypt password function should be failing, not succeeding. That's a pretty big 'oops'.

Star War Sex Parrot
Oct 2, 2003

Security Update 2017-001for High Sierra just came out to address the issue.

Pivo
Aug 20, 2004


Apple did something literally overnight for once, other than ship an iPhone? Cool.

edit: no reboot required

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Star War Sex Parrot posted:

Security Update 2017-001for High Sierra just came out to address the issue.

https://support.apple.com/en-us/HT208315

Binary Badger
Oct 11, 2005

Trolling Link for a decade


Make sure you check the Build Number to make sure you were updated, the patched macOS will report Version 10.3.1 (17B1002)

I rebooted just to make sure the patch stuck; High Sierra acts as if it just got a major update or you signed on as a new user (boots to Analytics screen, then says your account has been setup again.)

Pivo
Aug 20, 2004


I just confirmed for you: with no reboot, that is the build shown, and the exploit no longer works.

Star War Sex Parrot
Oct 2, 2003

Binary Badger posted:

I rebooted just to make sure the patch stuck; High Sierra acts as if it just got a major update or you signed on as a new user (boots to Analytics screen, then says your account has been setup again.)
Yeah I got this too and was a bit surprised.

Shaocaholica
Oct 29, 2002

Fig. 5E
Is the update forced or do you have to manually click stuff/enter password? Just curious, not actually trying to apply it.

Comfy Fleece Sweater
Apr 2, 2013

You see, but you do not observe.

Shaocaholica posted:

Is the update forced or do you have to manually click stuff/enter password? Just curious, not actually trying to apply it.

Haven’t you heard you don’t need passwords in Mac OS

Shaocaholica
Oct 29, 2002

Fig. 5E

Comfy Fleece Sweater posted:

Haven’t you heard you don’t need passwords in Mac OS

Lol, everyone please apply the patch using the exploit.

Binary Badger
Oct 11, 2005

Trolling Link for a decade


Shaocaholica posted:

Is the update forced or do you have to manually click stuff/enter password? Just curious, not actually trying to apply it.

nope, one click in the App Store, no fuss, no muss.

Also, if you hate the Mac App Store with all your heart, you can download the security update by itself here:

https://support.apple.com/kb/DL1942?locale=en_US

Also rather annoying that if you download High Sierra from the App Store, it's still the image of 10.13.1 from October that still has the exploit unpatched.

Binary Badger fucked around with this message at 00:29 on Nov 30, 2017

Djimi
Jan 23, 2004

I like digital data

"Apple" posted:

MacOS Security: Courage At Its Root

Djimi
Jan 23, 2004

I like digital data
or

Apple posted:

MacOS Security: Rooted in Courage
Better I think.

Quantum of Phallus
Dec 27, 2010

LMAO the security fix broke File Sharing


Apple's software teams need to step their games up. iOS 11 is the buggiest i've ever seen, so unbelievably bad and then you have this security issue with High Sierra


was it for this Stebe died? :qq:

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

ios 11 is a flaming pile of dogshit

Theophany
Jul 22, 2014

SUCCHIAMI IL MIO CAZZO DA DIETRO, RANA RAGAZZO



2022 FIA Formula 1 WDC

Quantum of Phallus posted:

LMAO the security fix broke File Sharing


Apple's software teams need to step their games up. iOS 11 is the buggiest i've ever seen, so unbelievably bad and then you have this security issue with High Sierra


was it for this Stebe died? :qq:

It's a security feature to keep your files safe!

Quantum of Phallus
Dec 27, 2010

Bob Morales posted:

ios 11 is a flaming pile of dogshit

The .0 release was legit embarrassing.

Last Chance
Dec 31, 2004

I'm not having any issues with iOS 11 so far..

Binary Badger
Oct 11, 2005

Trolling Link for a decade


Take iOS discussion to iOS threads where it belongs.

Meanwhile, if your File Sharing is broken, here's the fix:

https://support.apple.com/en-us/HT208317

Apple posted:

Repair file sharing after Security Update 2017-001 for macOS High Sierra 10.13.1

If file sharing doesn’t work after you install Security Update 2017-001, follow these steps.

If you experience issues with authenticating or connecting to file shares on your Mac after you install Security Update 2017-001 for macOS High Sierra 10.13.1, follow these steps to repair file sharing:

Open the Terminal app, which is in the Utilities folder of your Applications folder.

Type sudo /usr/libexec/configureLocalKDC and press Return.

Enter your administrator password and press Return.

Quit the Terminal app.


Published Date: Nov 30, 2017

Hair Force One should be profusely apologizing for this poo poo on his watch.

Binary Badger fucked around with this message at 17:28 on Nov 30, 2017

Theophany
Jul 22, 2014

SUCCHIAMI IL MIO CAZZO DA DIETRO, RANA RAGAZZO



2022 FIA Formula 1 WDC

Binary Badger posted:

Hair Force One should be profusely apologizing for this poo poo on his watch.

lol that name will never not be funny

Data Graham
Dec 28, 2009

📈📊🍪😋



Apple Maps 1.0 led to high-profile firings as I recall.

Last Chance
Dec 31, 2004

Binary Badger posted:

Hair Force One should be profusely apologizing for this poo poo on his watch.

Take watchOS discussion elsewhere please

Pivo
Aug 20, 2004


I wonder why the Kerberos local key distribution center (what is that even) needs to be re-initialized because Apple is now checking the error code of the verify crypt password function in the crypt->shadowhash user upgrade routine.

Somehow I think writing operating systems is hard

Binary Badger
Oct 11, 2005

Trolling Link for a decade


Last Chance posted:

Take watchOS discussion elsewhere please

Apple posted:

Craig Federighi is Apple’s senior vice president of Software Engineering, reporting to CEO Tim Cook. Craig oversees the development of iOS, macOS, and Siri. His teams are responsible for delivering the software at the heart of Apple’s innovative products, including the user interface, applications and frameworks.

So yeah, he should wear a toupee or something to show his shame.

Last Chance
Dec 31, 2004

Binary Badger posted:

So yeah, he should wear a toupee or something to show his shame.

it was a joke because you were backseat modding and said "on his watch"

Binary Badger
Oct 11, 2005

Trolling Link for a decade


Last Chance posted:

it was a joke because you were backseat modding and said "on his watch"

Ok now I get it

Binary Badger fucked around with this message at 00:14 on Dec 1, 2017

Binary Badger
Oct 11, 2005

Trolling Link for a decade


Apple updated the Security Update to include the fix for file sharing.

A totally patched 10.3.1 system should now have build number 17B1003.

:sigh:

some kinda jackal
Feb 25, 2003

 
 

Binary Badger posted:

Apple updated the Security Update to include the fix for file sharing.

A totally patched 10.3.1 system should now have build number 17B1003.

:sigh:

Great, File Sharing is fixed but now I can't print.













Just kidding, but maybe not?? Who knows what's broken now

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

I'm going back to Snow Leopard

Weedle
May 31, 2006




Bob Morales posted:

I'm going back to Snow Leopard

I’m going back to the PowerBook G4 you sent me

Binary Badger
Oct 11, 2005

Trolling Link for a decade


I'm going back to Geoworks Ensemble pray for me

carry on then
Jul 10, 2010

by VideoGames

(and can't post for 10 years!)

I'm going back to college.

Tippis
Mar 21, 2008

It's yet another day in the wasteland.

I'm never going back, and you can't make me!

qutius
Apr 2, 2003
NO PARTIES
never left OS2, suckers

Binary Badger
Oct 11, 2005

Trolling Link for a decade


I'm digging my Apple //e out and never booting anything but Paul Lutus's GraForth.

3D graphics, 1 KHz scratchy music, and seven colors all in glorious 280 * 192 resolution

pzy
Feb 20, 2004

Da Boom!
oh gently caress guys another one

https://www.reddit.com/r/VintageApple/comments/7gjnig/reset_technique_for_os_9_mac_os_setup_assistant/

Last Chance
Dec 31, 2004


lol

:pusheen:

Djimi
Jan 23, 2004

I like digital data

Binary Badger posted:

I'm digging my Apple //e out and never booting anything but Paul Lutus's GraForth.

3D graphics, 1 KHz scratchy music, and seven colors all in glorious 280 * 192 resolution

Will it run on my Apple ][ (INT, no FP)?

Adbot
ADBOT LOVES YOU

Binary Badger
Oct 11, 2005

Trolling Link for a decade


Runs on Apple ][, Apple ][ Plus with only 48K, so yeah, Integer Basic is fine. (GraForth only lets you use integers anyway.)



Will also run on clones like Franklin Ace, Laser 128.. here's video of the GraFORTH demo running on a Russian Apple ][ clone!

https://www.youtube.com/watch?v=4Fay38pUU7Y

All in 1 MHz and no hardware GPU..

Binary Badger fucked around with this message at 06:50 on Dec 1, 2017

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply