B4Print.com

Operating Systems => Macintosh => Topic started by: Joe on November 29, 2017, 08:57:57 AM

Title: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Joe on November 29, 2017, 08:57:57 AM
Stupid, stupid MacOS security flaw grants admin access to anyone (http://www.zdnet.com/article/stupid-stupid-macos-security-flaw/?loc=newsletter_large_thumb_related&ftag=TREc64629f&bhid=20703142171098067451473055926429)
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: ninjaPB_43 on November 29, 2017, 09:14:16 AM
Wow.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Possum on November 29, 2017, 09:20:31 AM
We'll address that in the next version, Mt. Yamagetchu.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Farabomb on November 29, 2017, 11:24:08 AM
Nah, it's a Mac OS problem. They still have to figure out how to make their cash cow, the iPhone be able to type an i.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Possum on November 29, 2017, 02:33:11 PM
Now they've got a fix.

https://arstechnica.com/gadgets/2017/11/new-security-update-fixes-macos-root-bug/

Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Ear on November 30, 2017, 12:22:22 PM
Exactly why I hit the "later" button on OS upgrades for a year after their release. Sierra is enough of a turd... not touching HighSierra until .6 or so.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Possum on December 04, 2017, 02:33:31 PM
And updating High Sierra brings it back. Stay tuned.

https://arstechnica.com/gadgets/2017/12/updating-macos-can-bring-back-the-nasty-root-security-bug/
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: mc hristel on December 04, 2017, 08:20:58 PM
So Apple released a security patch to fix this but never updated the actual installer for High Sierra.  :facepalm:

... And who are these people who ran the security patch before they had High Sierra installed and thought that would fix it?  :facepalm: :facepalm:

...And who doesn't restart their computer after installing a new OS?  :facepalm: :facepalm: :facepalm:
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Joe on December 04, 2017, 09:31:09 PM
The security issue was in 13.0. They released the security update at about the same time they released 13.1. So if you had 13.0 installed and then installed the security patch to fix it and then installed 13.1 you brought the security problem back because the 13.1 update didn't get the security patch before it was released. It has been an embarrassing couple of weeks for Apple.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: mc hristel on December 04, 2017, 10:54:53 PM
Ah! I get it. The way the article was written (or was it because I just skimmed the article) it sounded like people were running the security update before upgrading to High Sierra.  :undecided:
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Farabomb on December 05, 2017, 07:18:35 AM
Yeah, Apple hasn't been doing well on the iPhone or OSX fronts lately.

"It just works" well, maybe...
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Ear on December 05, 2017, 11:25:31 AM
Agreed about the OS.

The new Ubuntu is looking pretty slick. Runs like a striped assed ape on my old '09 iMac.

I made a bootable Linux stick and am going to put it on a half dead windows box that my kid wants me to fix.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Farabomb on December 05, 2017, 11:32:32 AM
I haven't played around with linux since redhat had the first boxed distro. I've run Ubuntu on the tablet but never on an actual computer. I probably should since I have enough old hardware kicking around. It's a good idea to at least keep somewhat current since the "newest" OS I have is windows 7.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Ear on December 05, 2017, 11:41:55 AM
I too used redhat, back in the day. The newer GUI feels a lot like the Mac, which makes base operation real nice. I loaded the latest Ubuntu 16.x version, instead of the brand new v17, for stability and support.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Joe on December 05, 2017, 12:22:50 PM
I suppose an '09 iMac has enough power to run Ubuntu acceptably. About a year ago I put it on an old Dell that had been running XP and it majorly sucked performance wise. All I can say is on the PC it takes some horsepower to run Ubuntu.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Joe on December 05, 2017, 12:23:51 PM
You can still run Redhat for free. Just load Cent OS. It is the open source version of Redhat.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: ninjaPB_43 on December 05, 2017, 12:46:57 PM
Quote from: Ear on December 05, 2017, 11:41:55 AMI too used redhat, back in the day. The newer GUI feels a lot like the Mac, which makes base operation real nice. I loaded the latest Ubuntu 16.x version, instead of the brand new v17, for stability and support.

Being open source, is Ubuntu safe for me to load onto an old desktop and let the 5 year old go to town with games and educational crap? Can I lock it down so he can't access pron or add his own games/apps?

It's been probably 8-9 years since I messed with Ubuntu at all.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: ninjaPB_43 on December 05, 2017, 12:47:49 PM
Quote from: Joe on December 05, 2017, 12:22:50 PMI suppose an '09 iMac has enough power to run Ubuntu acceptably. About a year ago I put it on an old Dell that had been running XP and it majorly sucked performance wise. All I can say is on the PC it takes some horsepower to run Ubuntu.

How much horsepower?
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Joe on December 05, 2017, 12:59:03 PM
Like I said...an old Dell running XP was horrible. It had a Pentium 4. Ubuntu says:

[attachimg=1 width=400]
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: ninjaPB_43 on December 05, 2017, 01:04:08 PM
Quote from: Joe on December 05, 2017, 12:59:03 PMLike I said...an old Dell running XP was horrible. It had a Pentium 4. Ubuntu says:

[attachimg=1 width=400]

Sorry, I thought maybe you meant it needed something more than what they list there..  my bad.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Ear on December 05, 2017, 01:50:44 PM
Quote from: ninjaPB_43 on December 05, 2017, 12:46:57 PM
Quote from: Ear on December 05, 2017, 11:41:55 AMI too used redhat, back in the day. The newer GUI feels a lot like the Mac, which makes base operation real nice. I loaded the latest Ubuntu 16.x version, instead of the brand new v17, for stability and support.

Being open source, is Ubuntu safe for me to load onto an old desktop and let the 5 year old go to town with games and educational crap? Can I lock it down so he can't access pron or add his own games/apps?

It's been probably 8-9 years since I messed with Ubuntu at all.

Yes. I think it would be perfect. Open source just means you need to not be a doosh about what you load onto it. There are still signed, certified apps. I think it's like most things, you will usually only get in trouble if you go looking for it. 
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Joe on December 05, 2017, 01:54:08 PM
Quote from: ninjaPB_43 on December 05, 2017, 01:04:08 PM
Quote from: Joe on December 05, 2017, 12:59:03 PMLike I said...an old Dell running XP was horrible. It had a Pentium 4. Ubuntu says:

[attachimg=1 width=400]

Sorry, I thought maybe you meant it needed something more than what they list there..  my bad.

I always consider their recommended requirements as not enough.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Ear on December 05, 2017, 01:55:25 PM
Quote from: Joe on December 05, 2017, 12:59:03 PMLike I said...an old Dell running XP was horrible. It had a Pentium 4. Ubuntu says:

[attachimg=1 width=400]
I would imagine. Ubuntu has a good GUI, which means it's a resource hog.

You can probably load something like redhat or Debian... might be a rougher interface with better performance.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Joe on December 05, 2017, 02:02:01 PM
Mint has a decent interface and not as resource hungry as Ubuntu. But not as many bells and whistles either. I still hate any desktop Linux. I still can't find anything in their file system. They need an Applications folder so if you someone how lose your alias to an app you can find the app and double click it to run with having to search through 40 layers of folders to find the secret place they store it.
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: Ear on December 05, 2017, 02:20:29 PM
Linus will show you his secret application folder location if you give him belly scratches, like a kitty. 
Title: Re: Stupid, stupid MacOS security flaw grants admin access to anyone
Post by: DigiCorn on December 08, 2017, 05:48:18 PM
They could learn a lesson from Microsoft Office for Mac OS; it's won't allow access to any file.