Apple users ..heads up w/High Sierra

PKR

Mentor
Local time
5:25 AM
Joined
Jul 15, 2010
Messages
2,702
Apple rushes to resolve ‘huge’ password glitch on its new operating system



Sam Meredith | @smeredith19

CNBC | 2017-11-29T12:49:03-0500




Apple is scrambling to fix a serious glitch within its latest Mac operating system.

A major flaw in the way the MacOS High Sierra operates means that anyone can gain entry to a computer without the use of a password, obtaining access to powerful administrator rights in the process.

Warnings about the bug were shared by computing experts such as Edward Snowden, who described Apple's operating system as "really bad" on Tuesday.

In a statement released Wednesday, Apple said: "We are working on a software update to address this issue."

The bug was first made public by Turkish developer Lemi Ergin. He discovered that by entering the username "root" and leaving the password field blank, he would eventually be able to gain unrestricted access after repeated presses of the log-in button.

Ergin said the glitch was a "huge security issue," before adding that the end result was "unbelievable."

https://www.cnbc.com/2017/11/29/app...uge-password-glitch-on-macos-high-sierra.html



.
 
"While the security vulnerability was a rather serious one, Apple has promptly responded with a fix less than 24 hours after it became public. The issue did not affect older versions of macOS, although there doesn’t appear to be a fix available for macOS 10.13.2 beta yet as the fix (downloadable here) only appears to apply to macOS 10.13.1 for now."

https://9to5mac.com/2017/11/29/macos-root-fix/


.
 
Good to know. I haven't updated to High Sierra yet. I recall there was a note that one app I use wasn't compatible yet.

Apple is very good at responding quickly when one of these things happens. :)

G
 
Thank you for posting this. I had to bump to HS for Final Cut Pro X work and since I follow RF forums WAY more than any apple forums I got the patch quickly. Another update was also posted.
 
Back
Top