Hidden backdoor API to root privileges in Apple OS X(truesecdev.wordpress.com)
truesecdev.wordpress.com
Hidden backdoor API to root privileges in Apple OS X
https://truesecdev.wordpress.com/2015/04/09/hidden-backdoor-api-to-root-privileges-in-apple-os-x/
321 comments
Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility.
To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.
To be even more fair, there's been a number of issues with Yosemite that make some of us want to stick with Mavericks.
Just because something is free doesn't make it better.
Just because something is free doesn't make it better.
Yep. JWZ used to say that Linux is only free if you don't value your time.
OS X has many merits on this front, but since 10.3 I've found that the first few dot releases of OS X have the same caveats often enough (both in terms of bugs/hazards and in terms of gratuitous UI "progress") that it usually seems better to wait past .x.4/5.
Now there's this, of course.
Since the problem showed up in 2011, maybe I should go back to Snow Leopard; I can't think of a single valuable change to OS X since then...
OS X has many merits on this front, but since 10.3 I've found that the first few dot releases of OS X have the same caveats often enough (both in terms of bugs/hazards and in terms of gratuitous UI "progress") that it usually seems better to wait past .x.4/5.
Now there's this, of course.
Since the problem showed up in 2011, maybe I should go back to Snow Leopard; I can't think of a single valuable change to OS X since then...
> JWZ used to say that Linux is only free if you don't value your time.
My reply to that has always been that Windows is only $300 if you don't value your time. (Preserving archaic cost of Windows to match JWZ quote.)
The implication that the one system is free and time-consuming and the other moderately in price but not time-consuming is entirely false. At the time, for many requirements, configuring and administering a Windows machine would have been more time-consuming than for Linux. It's also glossing over the fact that you can't horizontally scale your $-per-cpu/server solution once you do have the configuration worked out, without going back to the well for more money.
This amusing and glib quote also deliberately glosses over the "freedom" part of free software, which is essential. For example, I wonder if Google would exist today if not for a free unix workalike.
My reply to that has always been that Windows is only $300 if you don't value your time. (Preserving archaic cost of Windows to match JWZ quote.)
The implication that the one system is free and time-consuming and the other moderately in price but not time-consuming is entirely false. At the time, for many requirements, configuring and administering a Windows machine would have been more time-consuming than for Linux. It's also glossing over the fact that you can't horizontally scale your $-per-cpu/server solution once you do have the configuration worked out, without going back to the well for more money.
This amusing and glib quote also deliberately glosses over the "freedom" part of free software, which is essential. For example, I wonder if Google would exist today if not for a free unix workalike.
>The implication that the one system is free and time-consuming and the other moderately in price but not time-consuming is entirely false.
Haven't found that to be the case. And I'm an old UNIX hat, using SUN OS, HP UX et al in the early nineties and Linux from around 1998. My two observations:
1) Linux, even the most modern distro like Ubuntu, is a huge time sync for anyone that's not just content to browse the web and check mail in a system setup for them.
2) More users that we think are in that category (besides the proverbial "grandparents" perhaps).
You got a video from your wedding you need to edit? Might or might not work. You got a hobby that requires you to use a specific peripheral (like a soundcard) or software? Do you feel lucky? You got a new phone you need to sync? Prepare for an adventure...
Haven't found that to be the case. And I'm an old UNIX hat, using SUN OS, HP UX et al in the early nineties and Linux from around 1998. My two observations:
1) Linux, even the most modern distro like Ubuntu, is a huge time sync for anyone that's not just content to browse the web and check mail in a system setup for them.
2) More users that we think are in that category (besides the proverbial "grandparents" perhaps).
You got a video from your wedding you need to edit? Might or might not work. You got a hobby that requires you to use a specific peripheral (like a soundcard) or software? Do you feel lucky? You got a new phone you need to sync? Prepare for an adventure...
Things I've encountered frequently:
1. "I need to do X in Linux." Web search for software.
2. Try to install it. Find out I need Gnome 3.44 and I'm not running Gnome at all.
3. Find something else. This doesn't seen Gnome.
4. I try to install it. Wait, I need a newer version of a library.
5. I grab the latest version of that library. Wait, idiot, that version is TOO NEW!
6. So I find the exact version and install it and oh son of a cow now everything is broken.
And at each step there's a different sub-community telling me I'm a complete idiot. ("Why don't you use Gnome?" "Why don't you use package manager X?" "Why the fuck are you using that package manager???!")
1. "I need to do X in Linux." Web search for software.
2. Try to install it. Find out I need Gnome 3.44 and I'm not running Gnome at all.
3. Find something else. This doesn't seen Gnome.
4. I try to install it. Wait, I need a newer version of a library.
5. I grab the latest version of that library. Wait, idiot, that version is TOO NEW!
6. So I find the exact version and install it and oh son of a cow now everything is broken.
And at each step there's a different sub-community telling me I'm a complete idiot. ("Why don't you use Gnome?" "Why don't you use package manager X?" "Why the fuck are you using that package manager???!")
Same thing when people say if you're not the customer, you're the product. That is a logical fallacy because you are still a product even if you pay for the software.
The point is when you include your time your comparing ~10k products and there purchase price is a rounding error, not that Linux is inferior because it's free.
here we see - in their natural habitat - the elusive yet ever present ARGUMENTUS SELFICUS EXEMPLITICUS. A rare treat, indeed.
Linux desktop is and has been second rate for a long long time. Turns out unless there are corporate sponsors paying for development, open source software sucks. The OSS community is pretty much in denial about that.
That's funny, because I haven't managed to find a desktop OS that is up to par with Linux for me. Preferences may vary, but second rate in your book is the only viable contender in mine. Also turns out that Linux does in fact have corporate sponsors, like oracle, red hat, etc. so I'm not sure I follow. Is closed source software top notch without corporate sponsorship?
The sad truth is that most software sucks, regardless of the license, there's just a lower barrier to entry, use, and discoverability with OSS so it's more visible. At least with OSS we can fix the issues instead of just accepting the suckage.
The sad truth is that most software sucks, regardless of the license, there's just a lower barrier to entry, use, and discoverability with OSS so it's more visible. At least with OSS we can fix the issues instead of just accepting the suckage.
I'm probably biased.
After a year I find the only advantage of OSX are browser with touchpad gesture experience and windows edge handling. Haven't tried any distro ever since switching to MBP, wayland might have a better chance of replicating the experience. Hoping for the camera driver to be done.
In Linux everything else is better, fuller implementation of base tools, customizability, no crap like /var/folders..
After a year I find the only advantage of OSX are browser with touchpad gesture experience and windows edge handling. Haven't tried any distro ever since switching to MBP, wayland might have a better chance of replicating the experience. Hoping for the camera driver to be done.
In Linux everything else is better, fuller implementation of base tools, customizability, no crap like /var/folders..
"In Linux everything else is better"
This is entirely subjective; it is not a wise comment to make because it is better FOR YOU, not for everyone. For me, I liked the configurability in Linux desktop land but there comes a time when you want to sit in your office and get stuff done instead of spending all the time moving the furniture around and decorating; OSX doesn't let you do any decorating or move the furniture, so you're forced to do work (to some extent).
I daily use Linux, yet my day-job is to write software on OSX and Windows, so I get to use every system every day. They're all pretty much a muchness.
This is entirely subjective; it is not a wise comment to make because it is better FOR YOU, not for everyone. For me, I liked the configurability in Linux desktop land but there comes a time when you want to sit in your office and get stuff done instead of spending all the time moving the furniture around and decorating; OSX doesn't let you do any decorating or move the furniture, so you're forced to do work (to some extent).
I daily use Linux, yet my day-job is to write software on OSX and Windows, so I get to use every system every day. They're all pretty much a muchness.
Is your comment saying 'linux is amazing, I just can't stop ricing it and get to work! OSX is better because it doesn't let me customize it'?
No, it's saying both are great but Linux constant desktop change and rewriting of underlying systems to break upgrades between OSes isn't for me at the moment (as a desktop system). It may be great for someone else though.
Great for servers.
Basically, each to their own. None is "better".
Great for servers.
Basically, each to their own. None is "better".
I used to find Linux desktop second rate a few years ago but adopting it again recently I've found Gnome 3 better than OSX in many ways, at the very least comparable. Plus Arch Linux has been incredibly stable whereas in the past it also used to break often.
Funny, I'm watching a talk about issues with software quality on free software right now. Perhaps some members of the community are in denial, but not all of them.
https://media.libreplanet.org/u/libby/m/mako/
https://media.libreplanet.org/u/libby/m/mako/
> JWZ used to say that Linux is only free if you don't value your time.
Used to say? How long ago was that?
Ubuntu and many other distros are incredibly easy and effortless to use. I know devs using apple products who spend more time mucking about with brew and other tools trying to accomplish things that are very easy to do on the most popular linux distros.
Used to say? How long ago was that?
Ubuntu and many other distros are incredibly easy and effortless to use. I know devs using apple products who spend more time mucking about with brew and other tools trying to accomplish things that are very easy to do on the most popular linux distros.
I prefer and run Linux. However, troubleshooting Linux issues, even on Ubuntu is a pain in the ass. The fact that Google's page rank favors older stable pages in search results is a factor. A forum post from 2004 is not the best source of information in regards to dual monitors (and xrandr). 2007 instructions for changing the default boot will be based around Grub. I shouldn't adjust ~/.bash_login in 14.10 despite what the internet says. I should use the configuration tool.
My point is that Ubuntu is complex [as is Windows] and when something doesn't run quite right, the right answer is usually hard to find and hard to recognize because it will be embedded in a culture of highly technical cross referencing. The tradeoff for going down the rabbit hole is that Linux is really powerful and flexible.
I'm loving me some Xmonad this week, but I had to root around in xkb and xmodmap and write a little haskell and read about out how to switch layout engines in Ubuntu [and then translate that into xfce based Ubuntu Studio]. It's non-trivial and requires reading stuff on the Arch Linux Wiki. Ubuntu isn't really self contained in the way Windows is.
My point is that Ubuntu is complex [as is Windows] and when something doesn't run quite right, the right answer is usually hard to find and hard to recognize because it will be embedded in a culture of highly technical cross referencing. The tradeoff for going down the rabbit hole is that Linux is really powerful and flexible.
I'm loving me some Xmonad this week, but I had to root around in xkb and xmodmap and write a little haskell and read about out how to switch layout engines in Ubuntu [and then translate that into xfce based Ubuntu Studio]. It's non-trivial and requires reading stuff on the Arch Linux Wiki. Ubuntu isn't really self contained in the way Windows is.
On the Google search results page, click "search tools", and change "any time" to e.g. "past year".
That's exactly the sort of situation I am talking about. When there is a problem with some piece Ubuntu's ecosystem, the answer is "It's not Ubuntu's fault, RTFM for <other software>."
Knowing that information about Ubuntu goes out of date and that changing the search criteria helps: [1] doesn't make Ubuntu less complex [2] prevents it from being as user friendly as Windows for a broad audience.
Knowing that information about Ubuntu goes out of date and that changing the search criteria helps: [1] doesn't make Ubuntu less complex [2] prevents it from being as user friendly as Windows for a broad audience.
Mate I just thought you didn't know that feature and it might help you.
I don't use Ubuntu.
I don't use Ubuntu.
Exactly this. I've found (on OSX) that an Alfred custom search to quickly do a Google Last Year only search is incredibly useful.
I agree with the UI "progress". Lion and Mountain Lion were the biggest changes for me; Mavericks and Yosemite are alright to my eyes (although they took some getting used to).
I have a USB disk with Snow Leopard on it that I can boot on my work's 2008 Mac Pro but that kernel panics on my 2012 MacBook Pro due to the i7 "from the future" according to Snow Leopard. It's a pity because it'd make a really great test system (I would like to check that my software runs on 10.6 OK).
Does anyone know of a way of booting Snow Leopard from disk inside a VM without many kernel kext kerfuffles? Parallels tells me that I stink if I try and install OSX inside it (I have the regular DVD, not the server edition)
I have a USB disk with Snow Leopard on it that I can boot on my work's 2008 Mac Pro but that kernel panics on my 2012 MacBook Pro due to the i7 "from the future" according to Snow Leopard. It's a pity because it'd make a really great test system (I would like to check that my software runs on 10.6 OK).
Does anyone know of a way of booting Snow Leopard from disk inside a VM without many kernel kext kerfuffles? Parallels tells me that I stink if I try and install OSX inside it (I have the regular DVD, not the server edition)
> maybe I should go back to Snow Leopard; I can't think of a single valuable change to OS X since then...
I wish I had that option, but I'm an iOS developer, so I upgrade when Apple forces me to, and right now their forcing Mavericks and up.
> Linux is only free if you don't value your time.
Amazing how the largest server farms on earth are all run by administrators who don't value their time...
I wish I had that option, but I'm an iOS developer, so I upgrade when Apple forces me to, and right now their forcing Mavericks and up.
> Linux is only free if you don't value your time.
Amazing how the largest server farms on earth are all run by administrators who don't value their time...
There's a large difference between linux on the server and on your (personal) desktop.
Not knowing how to operate a server, I have to assume it's harder and you have to know everything it does and the CLI to use it. Not the same for mint or any other pre-packaged distros.
There's a lot less strange issues and hardware incompatabilities are not really a thing. No massive complicated daemons such as X either.
But yes, the CLI is a requirement.
But yes, the CLI is a requirement.
The largest server farms on earth are all run by administrators who are extremely well paid for their time. Linux isn't free for the companies who hire them.
"Linux isn't free for the companies who hire them"
Actually, Windows isn't free for the companies who hire them. And you need to hire a lot more Windows admins than Linux admins if you want to keep your server farm running. But Windows admins are cheaper than Linux/Unix admins, so the phb can crow about that.
Actually, Windows isn't free for the companies who hire them. And you need to hire a lot more Windows admins than Linux admins if you want to keep your server farm running. But Windows admins are cheaper than Linux/Unix admins, so the phb can crow about that.
> Yep. JWZ used to say that Linux is only free if you don't value your time.
Yeah, like installing drivers for all your peripherals on Windows never takes time, right?
Yeah, like installing drivers for all your peripherals on Windows never takes time, right?
He uses OS X. Rantilly.
http://www.jwz.org/blog/tag/mac/
http://www.jwz.org/blog/tag/mac/
I don't think I've ever had to install a driver manually on Windows 7.
Windows is able to get drivers itself over the network. Unless the ethernet driver is missing to, which happens most of the time.
[deleted]
So you don't have a GPU card I guess?
With XP this was valid, but from Windows 7 onwards you don't need to do it anymore unless you actually want to play a game - the majority of users would never need to at all.
I'm with you on this; I can't leave Mavericks just yet. Every colleague I have that's moved on has had numerous issues with their machine.
And now this crap. Ugh.
And now this crap. Ugh.
What kind of issues? I've literally noticed no differences besides UI.
My wife and I have identical 2013 13" MBAs. Mine is on Mavericks. Hers, which was bought a little later, is on Yosemite. So, as close as possible, we've got identical HW with different software.
- My battery lasts longer, maybe 2-3 hours more per charge. I nearly never see < 50%, she's hitting 10% at the end of the day. (Note that both are good enough, but they're way different) - Mail search sucks on Yosemite. Today, we were searching for subjects that I know are there because I'm looking right at them, and nothing is coming up. - Safari does something funky with process per tab that manages to orphan process that take a bunch of cpu/memory. - Time machine is really touchy about backing up to the server over wifi. The last few times, it's had to make a new backup on the Yosemite machine. Mine misses a backup every day or so, but that's just an hourly miss, not a full rebuild.
We're considering blowing away her machine and pushing it back to mavericks with Time Machine/fresh install.
- My battery lasts longer, maybe 2-3 hours more per charge. I nearly never see < 50%, she's hitting 10% at the end of the day. (Note that both are good enough, but they're way different) - Mail search sucks on Yosemite. Today, we were searching for subjects that I know are there because I'm looking right at them, and nothing is coming up. - Safari does something funky with process per tab that manages to orphan process that take a bunch of cpu/memory. - Time machine is really touchy about backing up to the server over wifi. The last few times, it's had to make a new backup on the Yosemite machine. Mine misses a backup every day or so, but that's just an hourly miss, not a full rebuild.
We're considering blowing away her machine and pushing it back to mavericks with Time Machine/fresh install.
Random bugginess. When I came into office, plugged my machine into TB display (have one at home, so should be no issue), I got nothing but black. Could get a login prompt, and even closing lid kept backlight on. Only solution was a hard reboot.
Oh true. I just realized I have the same issue. I connect my macbook to my hengedock which has 3 monitors attached. If I disconnect my macbook and hook up my tv via hdmi, I plug it into my hengedock and my 3rd monitor is just black while plugged into that hdmi port. I always restart it after watching tv and then plugging my monitors to get it to work.
I have all kinds of problems with Bluetooth, specifically with pairing or connecting devices. Hibernation is all kinds of wonky, too. If it's been asleep for a few hours, it will hibernate when I plug it into AC power without resuming it first. (I really wish there was a way to tell it to hibernate if it's been suspended for some user-settable amount of time like I can with Windows, but that's not a problem specific to Mac OS X 10.10.)
Generally much slower response, Final Cut breaking, trouble with hanging apps needing force quits, and it goes on. Minor by themselves; scary when it all seemed to happen after each person upgraded.
Maybe I've waited long enough before moving. Especially now that this vuln is known about.
Maybe I've waited long enough before moving. Especially now that this vuln is known about.
My 2009 imac took 3 sec to respond to each click with Yosemite. Got frustrated and installed Mint and it works great!
I miss 10.6.8.
That's why I Carbon Copy Cloner'd my Snow Leopard partition to a USB HDD!
Pity I can't actually boot it on my 2012 i7 (kernel panics ahoy).
If anyone knows how to get around this, I would appreciate it as it would be truly marvellous to be able to test software that I've written under it.
Pity I can't actually boot it on my 2012 i7 (kernel panics ahoy).
If anyone knows how to get around this, I would appreciate it as it would be truly marvellous to be able to test software that I've written under it.
Just because it's paid doesn't make it better either.
I have a lot of music production software on my Mac, which doesn't all necessarily get updated to work with the latest OS X right away. Upgrading the operating system tends to be a maze of determining what works and what doesn't, possibly including paying for updates of software besides the OS.
I generally put off doing a major Mac OS update for as long as possible.
I generally put off doing a major Mac OS update for as long as possible.
It's even worse that every update makes you wonder if your FireWire interface and control software will ever work or run again, even though you're running on THE SAME HARDWARE as before; the OS update typically breaks it.
<citation needed> on the "run well even on 5+ years old hardware" bit. Sure, the OS will boot and work, but that doesn't mean things will work well.
My late 2011 13-in MacBook Pro became unbearably slow after doing a clean upgrade to Mavericks. Only upgrading the memory to 8GB (which was not supported by Apple for that model) fixed the issue. Yosemite works, but looks like crap on anything without a retina display. Newer versions of iOS have a habit of making older phones become sluggish when compared with the same phone model running an older version of iOS.
I'm not expecting Microsoft-level backwards compatibility, but as someone that has a somewhat complex development environment having to get everything to work on a new version of the OS can take up to a week of tweaking.
My late 2011 13-in MacBook Pro became unbearably slow after doing a clean upgrade to Mavericks. Only upgrading the memory to 8GB (which was not supported by Apple for that model) fixed the issue. Yosemite works, but looks like crap on anything without a retina display. Newer versions of iOS have a habit of making older phones become sluggish when compared with the same phone model running an older version of iOS.
I'm not expecting Microsoft-level backwards compatibility, but as someone that has a somewhat complex development environment having to get everything to work on a new version of the OS can take up to a week of tweaking.
I'm currently running the latest version of Yosemite. I have a 2010 MacBook Pro 15 inch with eight gigs of RAM and an SSD.
I've had little bugs and fiddly bugs with Safari and a few other things, but I really thinks it has worked fine for years and years on the machine. It noticeably improved when they added RAM compression (was that Mavericks?).
I don't find the graphics a problem at all, although they do look better on my Retina iMac. I got used to them pretty quickly.
I've been happy with most OS updates as they sped Safari up or fixed small bugs in it. Photos for OS X is a MASSIVE speed improvement over iPhoto.
I know some people run into pretty catastrophic bugs from time to time, I haven't had that experience personally. The idea that the OS doesn't run well on five-year-old hardware is bunk. I have no need to replace my MacBook Pro, The only thing it's not good at is 3D (and it was never very good at that).
If you have enough RAM and replace the spinning disk old Macs feel fantastic with a if you have enough RAM and replace the spinning hard drive old Mac still feel fantastic with a recent OS.
If you're on a 5400rpm drive with 2GB I'm sure it's painful. But I know even 4GB machines fair very well. SSDs just make an insanely big difference.
I've had little bugs and fiddly bugs with Safari and a few other things, but I really thinks it has worked fine for years and years on the machine. It noticeably improved when they added RAM compression (was that Mavericks?).
I don't find the graphics a problem at all, although they do look better on my Retina iMac. I got used to them pretty quickly.
I've been happy with most OS updates as they sped Safari up or fixed small bugs in it. Photos for OS X is a MASSIVE speed improvement over iPhoto.
I know some people run into pretty catastrophic bugs from time to time, I haven't had that experience personally. The idea that the OS doesn't run well on five-year-old hardware is bunk. I have no need to replace my MacBook Pro, The only thing it's not good at is 3D (and it was never very good at that).
If you have enough RAM and replace the spinning disk old Macs feel fantastic with a if you have enough RAM and replace the spinning hard drive old Mac still feel fantastic with a recent OS.
If you're on a 5400rpm drive with 2GB I'm sure it's painful. But I know even 4GB machines fair very well. SSDs just make an insanely big difference.
Did you upgrade to an SSD? I have a 2012 MBP non-retina with a slow Toshiba drive in it (it seems it is entirely coincidental whether you'll get a Toshiba or Samsung in your new MacBook!) and I am considering upgrading to an SSD. I use BootCamp (periodic Windows gaming) and have a bunch of large VMs within OSX, so I would be interested in how the upgrade went and where to look, how to clone my disk etc. etc.
Yes. It makes all the difference in the world, far more than the additional RAM.
Upgrade was an easy drive pull and replace, and I just restored from Time Machine to get all my data back. No fuss.
But I don't have a windows partition or anything else special. I imagine it will be a bit more work for you since you'll need to backup the Windows partition and restore it.
Upgrade was an easy drive pull and replace, and I just restored from Time Machine to get all my data back. No fuss.
But I don't have a windows partition or anything else special. I imagine it will be a bit more work for you since you'll need to backup the Windows partition and restore it.
I was tempted to do that, but to be honest the battery of that computer is kind of shot (it only lasts about 3 hours nowadays) so I didn't think it was worth spending the money. Might as well sell that one and spend a few hundred more to get something with a retina display and a factory SSD :)
> To be fair, OS X updates are free and usually run well even on 5+ years old hardware
Unless your hardware has been made "incompatible" by Apple (not for any technical reason, but simply because they wish you'd buy new hardware).
Unless your hardware has been made "incompatible" by Apple (not for any technical reason, but simply because they wish you'd buy new hardware).
What hardware have they dropped support for without a technical reason? To my knowledge, the only Intel Macs they've dropped support for are ones with 32-bit processors, 32-bit firmware (requiring a 32-bit kernel and drivers even if the processor is 64-bit), or really old GPUs that can't support recent versions of OpenGL.
To my knowledge no Linux distro packages install media supporting 32-bit firmware and 64-bit kernel+CPU, but it's definitely possible to built a 32-bit GRUB EFI binary and have it load and execute a 64-bit kernel on a 64-bit CPU. I've done it on such a Mac. And there are a number of tablets built this way also (unfortunately).
Intel only contributed the code for that a year ago, so while we now know it can be done, there's no particular reason to believe that it's easy to get working properly. The messy mix of EFI 1.x and UEFI 2.x that Apple uses could make things even trickier.
Early 2009 X-Serve?
It has a quad-core Xeon processor.
[update]
I am wrong. It is the late 2008 X-Serve that won't upgrade ...
Specs: https://support.apple.com/kb/SP10?locale=en_US
Supported H/W:
It has a quad-core Xeon processor.
[update]
I am wrong. It is the late 2008 X-Serve that won't upgrade ...
Specs: https://support.apple.com/kb/SP10?locale=en_US
Supported H/W:
iMac (Mid 2007 or newer)
MacBook (Late 2008 Aluminum, or Early 2009 or newer)
MacBook Pro (Mid/Late 2007 or newer)
MacBook Air (Late 2008 or newer)
Mac mini (Early 2009 or newer)
Mac Pro (Early 2008 or newer)
Xserve (Early 2009)
from https://www.apple.com/osx/how-to-upgrade/I am not sure why you were downvoted. I'd think it is in Apple's vested interest to actually not treat the older hardware so you buy new one. I am no talking about really old hardware. Example: I have seen my iPhone 5S get substantially slower after update to ios 8+.
The OS update might be free, but that's not the only reason that a number of large deployments might stay at a single version.
For us IT Shops, its almost exclusively about ensuring support for the hundreds of other software programs.
I see a lot of folks arguing otherwise, and I'm not sure they realize this.
Sure, it works fine for the 'isolated single user', but it's totally different in a large deployment model.
For us IT Shops, its almost exclusively about ensuring support for the hundreds of other software programs.
I see a lot of folks arguing otherwise, and I'm not sure they realize this.
Sure, it works fine for the 'isolated single user', but it's totally different in a large deployment model.
Maybe most personal users but those of us in larger IT-managed organizations don't always have the luxury of updating on day one (point: I am on 10.9.5 right now).
Indeed, I'm running 10.10 on a 2006 Mac Pro, and it's running really really well (boot.efi replaced to get it working, not supported:).
I was surprised just how well it's working tbh.
I was surprised just how well it's working tbh.
usually run well even on 5+ years old hardware
At my last office we had older macs, a mix of laptops and desktops. They all ran slow, with one user's mac pro using all 4GB RAM on a fresh boot with nothing loaded. These folks were normal users, not power users. When a new OSX release would come out, a few people would upgrade, have a ton of problems, and warn everyone else.
I ran linux myself, and was occasionally called over to help with an OSX problem, and I could never understand how my colleagues could stand to work on such slow computers. In my experience, older macs do not usually run well on newer OSX.
At my last office we had older macs, a mix of laptops and desktops. They all ran slow, with one user's mac pro using all 4GB RAM on a fresh boot with nothing loaded. These folks were normal users, not power users. When a new OSX release would come out, a few people would upgrade, have a ton of problems, and warn everyone else.
I ran linux myself, and was occasionally called over to help with an OSX problem, and I could never understand how my colleagues could stand to work on such slow computers. In my experience, older macs do not usually run well on newer OSX.
I recall the same pain with Vista - booting to an empty desktop saw insane RAM usage.
I'm currently running 10.10.3 on a Mac Pro 1,1, at almost 9 years of use. Of course 10.10 isn't supported by Apple, but it works just fine, and with the combination of an SSD and cheap RAM, I imagine I can get another 3-4 years out of this desktop barring a hardware failure that pushes me to a new system.
They are now. I remember buying upgrades ?
sounds like macs are only in homes from your perspective.
"Most users on the newest version"? Of the seven or eight Macs at my workplace, my personal Macbook is the only one running the latest OSX.
Ya the stats I've seen indicate that a considerable chunk are still on 10.6, for example. I forget where but I'm sure a Google search will yield it.
[citation needed]
80% on 10.9 or 10.10: http://www.intego.com/mac-security-blog/os-x-market-share-st...
Only 50% on Windows 7 or 8: https://analytics.usa.gov
Oh, wait, Windows 7 is from 2009. Only 10% use a Windows younger than two years.
Only 50% on Windows 7 or 8: https://analytics.usa.gov
Oh, wait, Windows 7 is from 2009. Only 10% use a Windows younger than two years.
A large chunk of this is due to business use of Windows.
Microsoft would not be able to get away with the shenanigans that Apple are pulling here.
Microsoft would not be able to get away with the shenanigans that Apple are pulling here.
Don't worry, my company uses plenty of Macs, and they're plenty upset. As does the U.S. government. I wouldn't count on this "oh, we're just not going to backport the update" sticking around. Unless they want to loose all of their government and commercial sales.
Alupis, I support federal government scientists (biologists, chemists, entomologists, etc.), and many of them use Macs. Naturally, there are more Windows PCs than there are Macs, but there are plenty of Macs in our labs.
> As does the U.S. government.
The government is largely Windows PC's (mostly XP and Win7).
The government is largely Windows PC's (mostly XP and Win7).
> If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility.
It's not only about support for "old" products, it's also about having a roadmap to begin with. It used to be common wisdom that Apple releases major updates for the current version of OS X, and security fixes for the last two versions. Well, that common wisdom is outdated now.
Also, backwards compatibility and security fixes are not really the same, and I'd say that the correlation between backwards compatibility and software quality is completely overrated. I know I'd rather trust my life to Windows 7 (the epitome of conservative OS design) than to OS X 10.10 or iOS 8 (speaking as an iOS developer).
In raw numbers, 45% of OS X users are now vulnerable (and probably don't even know about it), and Apple doesn't care. That's an insane number. And I thought not patching the ~10% iPhone 4 in the wild was dangerous!
It's not only about support for "old" products, it's also about having a roadmap to begin with. It used to be common wisdom that Apple releases major updates for the current version of OS X, and security fixes for the last two versions. Well, that common wisdom is outdated now.
Also, backwards compatibility and security fixes are not really the same, and I'd say that the correlation between backwards compatibility and software quality is completely overrated. I know I'd rather trust my life to Windows 7 (the epitome of conservative OS design) than to OS X 10.10 or iOS 8 (speaking as an iOS developer).
In raw numbers, 45% of OS X users are now vulnerable (and probably don't even know about it), and Apple doesn't care. That's an insane number. And I thought not patching the ~10% iPhone 4 in the wild was dangerous!
> Apple's model customer is one who upgrades often.
I don't know any tech company that doesn't have that idea of a model customer :)
To their credit, I can run the latest on a pretty old Mac Mini at home. It's not as fast as it used to be, but it is supported long after the form factor of the Mini has undergone big changes. I don't consider myself being squeezed to upgrade.
I don't know any tech company that doesn't have that idea of a model customer :)
To their credit, I can run the latest on a pretty old Mac Mini at home. It's not as fast as it used to be, but it is supported long after the form factor of the Mini has undergone big changes. I don't consider myself being squeezed to upgrade.
I booted up one of those G3 candy colored clamshell iBooks from the early 2000s recently. Not only did start flawlessly, it found and connected to the WiFi, and actually loaded Google on Internet Explorer for Mac.
Out of interest, did it display the results pages from Google alright? Or was the CSS and JavaScript etc. not recognised?
Was it usable, speedwise, as a machine?
Was it usable, speedwise, as a machine?
Or LTS versions of Linux.
What about developers that need to support customers on older systems?
You basically need VMs for every version of OS X you want to support, and need to keep copies of the old OS X SDKs since Apple seems not to test that newer ones will continue to work despite superficially supporting choosing a target version.
Most developers don't bother, as Apple has successfully made it quite difficult.
Most developers don't bother, as Apple has successfully made it quite difficult.
Many don't.
Or your IT department could force you to use a Golden Master of 10.9, and not let you update.
Holy Apple can't be wrong. Microsoft bad bad and clunky.
We're talking about a security issue!
We're talking about a security issue!
They even released "Security Update 2015-004" at the same time, including many updates for 10.8 and 10.9, but not the admin framework.
https://support.apple.com/en-us/HT204659
https://support.apple.com/en-us/HT204659
If nothing else, they should feel a moral obligation to fix it in previous versions.
What better way to encourage people to upgrade.
"What better way to encourage people to upgrade."
The majority of their user base doesn't know and wouldn't care about this type of thing even if they did.
The majority of their user base doesn't know and wouldn't care about this type of thing even if they did.
They'll care when their mouse starts moving by itself.
They'll just think "oh god, I have viruses!" and call whoever is the family's "computer whiz". The very concept of "this system is not secure" is something that ordinary user does not understand.
Source: I'm a family "computer whiz" :/.
Source: I'm a family "computer whiz" :/.
That's completely untrue, and pretty cynical.
People understand if a system is insecure, and now apparently all non-Yosemite Macs are insecure. Folks will grok that. Whether or not they find out about it, well that's up to you and I, and everyone else on this website.
People understand if a system is insecure, and now apparently all non-Yosemite Macs are insecure. Folks will grok that. Whether or not they find out about it, well that's up to you and I, and everyone else on this website.
I didn't mean it in a cynical way. From my observation, "it has viruses" is the best model that is self-consistent and yet doesn't require investing a lot of time in comprehending the workings of a computer. Non-tech people reach it naturally.
I agree it's up to us to proactively tell our parents, friends and colleagues who may be vulnerable about this problem.
I agree it's up to us to proactively tell our parents, friends and colleagues who may be vulnerable about this problem.
I have to go with the idea that MOST people have no idea about security with their computers. Also most Apple people still say no bugs, no crashes and no viruses. Even when I point out every time something crashes on their Mac.
or to abandon your product
After getting more and more tired of Apple's generally obnoxious behavior over the last few years I'm wondering which straw will be the last for me before doing exactly that. I'm pretty seriously considering wiping OSX off my MBP and running some variety of Linux on it at this point, though regrettably I might still be forced to consider them for future hardware purchases on account of the fact that I don't think I've ever encountered a non-Apple laptop that seemed worthwhile (in terms of general construction and build quality).
In danger of being accused of flogging deceased equines I can but point at the T42p ThinkPad which I'm typing this message on for an example of a device which fits that premise: solid hardware and a generally well though-out design. It is 11 years old, but sports a screen which comes remarkably close to the more recent Apple offerings. It also runs the latest software flawlessly, as long as that latest software is a recent Linux distribution. It has a keyboard which Apple-adepts can only dream about. Ports aplenty, two batteries or drives or whatnots, no problem, ~8 hours on a single battery charge when using the oddly shaped 'extended' battery.
An additional bonus is that you can get these things for free if you know where to look.
Of course, being 11 years old it also has its drawbacks. It won't fit more than 2GB of RAM. It is based around a single-core Pentium M which generally performs fine but shows its age mostly when meeting Javascript-hobbled web-related things.
BUT... and this is one of the main reasons why I use older hardware... if you develop software on this machine, and it works fine on that machine, it'll run circles around the stuff your neighbour made on his latest FlitzBang Fruitmachine. It'll but cause a blip on the CPU meter where his (or her, your choice) result maxes it out. It'll use memory like it was rationed, not like it was on sale.
Of course you can not develop software for the dark side on this older hardware. A small loss, in my opinion.
An additional bonus is that you can get these things for free if you know where to look.
Of course, being 11 years old it also has its drawbacks. It won't fit more than 2GB of RAM. It is based around a single-core Pentium M which generally performs fine but shows its age mostly when meeting Javascript-hobbled web-related things.
BUT... and this is one of the main reasons why I use older hardware... if you develop software on this machine, and it works fine on that machine, it'll run circles around the stuff your neighbour made on his latest FlitzBang Fruitmachine. It'll but cause a blip on the CPU meter where his (or her, your choice) result maxes it out. It'll use memory like it was rationed, not like it was on sale.
Of course you can not develop software for the dark side on this older hardware. A small loss, in my opinion.
There are still organizations paying huge stacks of money for Windows XP support past EOL.
I'm working on a year-long government project now to migrate a small bunch of websites from Windows Server 2003 to 2008 R2 (because extended support for 2003 ends this summer). Yes, we're upgrading to a 6 year old operating system.
That's how I read it. And that's why I'm making plans to migrate away from Apple Desktop.
To what though? All the other offerings don't seem at the same state, unless Windows 10 can rescue us all?
I notice that Windows 10 has had new bits shoe-horned in (a new settings screen!) whilst still keeping ALL the old stuff there (MMC as written in 1998? Control Panel is still there despite this new Settings page, duplication much? None of the icons match etc. etc. what a hodgepodge)
I notice that Windows 10 has had new bits shoe-horned in (a new settings screen!) whilst still keeping ALL the old stuff there (MMC as written in 1998? Control Panel is still there despite this new Settings page, duplication much? None of the icons match etc. etc. what a hodgepodge)
In my case Linux.
Ubuntu on a macbook pro is reasonably comparable. And the Dell offerings are looking damn good.
It would be nice to have a tiling window manager too.
Ubuntu on a macbook pro is reasonably comparable. And the Dell offerings are looking damn good.
It would be nice to have a tiling window manager too.
Looks like they've released patches for Mavericks and Mountain Lion as well:
https://support.apple.com/kb/DL1803 https://support.apple.com/kb/DL1802
https://support.apple.com/kb/DL1803 https://support.apple.com/kb/DL1802
Unfortunately this fix is apparently not included.
What makes you say that?
The submitted article says so. In fact, I quoted the relevant sentence in an above comment.
Interestingly, the release notes for the 2015-004 patch that includes the fix specifically mention it is also available for Mavericks and Mountain Lion.
https://support.apple.com/en-us/HT201222
https://support.apple.com/en-us/HT201222
No it doesn't:
from https://support.apple.com/en-us/HT204659:
> Admin Framework
> Available for: OS X Yosemite v10.10 to v10.10.2
> Impact: A process may gain admin privileges without properly authenticating Description: An issue existed when checking XPC entitlements. This issue was addressed with improved entitlement checking.
> CVE-ID
> CVE-2015-1130 : Emil Kvarnhammar at TrueSec
from https://support.apple.com/en-us/HT204659:
> Admin Framework
> Available for: OS X Yosemite v10.10 to v10.10.2
> Impact: A process may gain admin privileges without properly authenticating Description: An issue existed when checking XPC entitlements. This issue was addressed with improved entitlement checking.
> CVE-ID
> CVE-2015-1130 : Emil Kvarnhammar at TrueSec
I see, so a security update with the same version number does not contain the same patches on all OS X versions it rolls out on, that's... peculiar.
I can't really believe Apple will actually leave this unpatched, as opposed to just saying it won't at this time. The impact of this exploit and the number of affected systems is way too big, they really can't let this sit in OS X versions that were brand new only one or two years ago, that would be insane. With all the resources they have a statement like 'the impact of the changes would be too large' is quite ridiculous.
My guess is that they will patch it in a later update, but haven't finished it yet. Maybe they are even hoping for a few more people to upgrade to Yosemite before they release it. I would be willing to bet that they don't leave a gaping hole like this sitting indefinitely.
I can't really believe Apple will actually leave this unpatched, as opposed to just saying it won't at this time. The impact of this exploit and the number of affected systems is way too big, they really can't let this sit in OS X versions that were brand new only one or two years ago, that would be insane. With all the resources they have a statement like 'the impact of the changes would be too large' is quite ridiculous.
My guess is that they will patch it in a later update, but haven't finished it yet. Maybe they are even hoping for a few more people to upgrade to Yosemite before they release it. I would be willing to bet that they don't leave a gaping hole like this sitting indefinitely.
I agree with this assessment. The initial fix of the exploit may be easy, but I would bet that the compatibility testing and fixes associated with things that will break because of the patch is what is holding it up.
It would be an interesting exercise to try to figure out what made it easier to patch in 10.10. Is it because it is an active code base, or because something was refactored between 10.8/10.9 and 10.10 that eliminated the need to take advantage of this undocumented capability--for instance, something in the System Preferences getting refactored?
It would be an interesting exercise to try to figure out what made it easier to patch in 10.10. Is it because it is an active code base, or because something was refactored between 10.8/10.9 and 10.10 that eliminated the need to take advantage of this undocumented capability--for instance, something in the System Preferences getting refactored?
Title is a little generous about "hidden", the exploit revolves around API & Framework used to power the parts of the control panel, and its authorization scheme being broken.
I do think its too bad that setuid binaries don't have additional restrictions, like 100% must be code-signed or must be run in a sandbox-exec[1] based on that signing.
[1] - https://developer.apple.com/library/mac/documentation/Darwin...
I do think its too bad that setuid binaries don't have additional restrictions, like 100% must be code-signed or must be run in a sandbox-exec[1] based on that signing.
[1] - https://developer.apple.com/library/mac/documentation/Darwin...
Code signing is not interesting. If normal people can get their code signed then so can the attacker and if they can't then it locks you out of your own computer. The only thing code signing is really good for is to verify that an update to a program the machine's owner installed was signed by the same author as the original program, and unfortunately it's rarely implemented that way.
But that's not really what you're asking for anyway. You can assign granular permissions to binaries regardless of code signing.
The real problem is there are so many things that aren't literally root but are effectively equivalent because if you can do them then you have easy privilege escalation. That's why the Windows security model is so silly. An administrator is not allowed to 'su' to another user without the user's password but any reasonable subset of the administrator's privileges can be used to silently cause any user to execute arbitrary code, e.g. by setting their login script or putting executables in the All Users startup folder or just loading a kernel driver that will let them do whatever they want.
But that's not really what you're asking for anyway. You can assign granular permissions to binaries regardless of code signing.
The real problem is there are so many things that aren't literally root but are effectively equivalent because if you can do them then you have easy privilege escalation. That's why the Windows security model is so silly. An administrator is not allowed to 'su' to another user without the user's password but any reasonable subset of the administrator's privileges can be used to silently cause any user to execute arbitrary code, e.g. by setting their login script or putting executables in the All Users startup folder or just loading a kernel driver that will let them do whatever they want.
> That's why the Windows security model is so silly. An administrator is not allowed to 'su' to another user without the user's password but any reasonable subset of the administrator's privileges can be used to silently cause any user to execute arbitrary code
That's like saying kernel memory protection is silly when the user is an admin because he could just as well load a driver into the system to wreak whatever havoc he wants.
Yes, he could. No, it's not silly.
That's like saying kernel memory protection is silly when the user is an admin because he could just as well load a driver into the system to wreak whatever havoc he wants.
Yes, he could. No, it's not silly.
Memory protection is not silly. Not being able to bypass memory protection (and therefore prohibiting all manner of debugging tools) is silly, and that is the appropriate analogy.
If a user correctly has permission to do a thing via a series of ugly hacks then there is no reason not to just let the user do the thing directly.
If a user correctly has permission to do a thing via a series of ugly hacks then there is no reason not to just let the user do the thing directly.
>then so can the attacker
Maybe, but the attacker can also get their certificate revoked when their activities are discovered.
Maybe, but the attacker can also get their certificate revoked when their activities are discovered.
...if their activities are discovered. And then the attacker just gets another certificate under a different name, or steals somebody else's certificate. Ignoring, of course, that revocation is totally broken.
It cannot simultaneously be easy for anyone to get a certificate and hard for an attacker to get a certificate.
It cannot simultaneously be easy for anyone to get a certificate and hard for an attacker to get a certificate.
Isn't the "hidden" part related to them being a private API/Framework?
With physical access, one has been able to create admin accounts for as long as I can remember.
- Start up the Mac whilst holding down ⌘-S. This boots the Mac into Single-User Mode and provides a method of interacting with OS X via the command-line, with full root privileges.
- Then check the filesystem to ensure there are no problems: "/sbin/fsck -fy"
- Then mount the filesystem for it to be accessible: "/sbin/mount -uw /"
- Now remove this file so OS X will re-run Setup Assistant: "rm /var/db/.AppleSetupDone"
Now just restart, and enjoy the cool introduction animation as you create your admin account.
- Start up the Mac whilst holding down ⌘-S. This boots the Mac into Single-User Mode and provides a method of interacting with OS X via the command-line, with full root privileges.
- Then check the filesystem to ensure there are no problems: "/sbin/fsck -fy"
- Then mount the filesystem for it to be accessible: "/sbin/mount -uw /"
- Now remove this file so OS X will re-run Setup Assistant: "rm /var/db/.AppleSetupDone"
Now just restart, and enjoy the cool introduction animation as you create your admin account.
Local privilege escalation is always bad because it means you're one malware payload or RCE away from being rooted and conscripted into someone's botnet (or worse). This isn't just a physical access concern.
What about without local privilege escalation? Is there no way for a malware payload or RCE to turn your computer into a botnet without root privileges?
There certainly is, but rooting a box lets you ensure that you stuff says in place. Once a box is rooted, its owner can never really be sure they have it clean without wiping and rebuilding it.
Even easier is running 'resetpassword' from Terminal in Recovery mode (boot with ⌘-R). This gets you a nice GUI tool where you can reset any account passwords.
But yes, this is not possible with a firmware password or with disk encryption (FileVault) enabled.
But yes, this is not possible with a firmware password or with disk encryption (FileVault) enabled.
Not possible if full disk encryption is enabled. And that is a default since a year or so.
full disk encryption only protects you from passive snooping. If someone has physical access between two of your subsequent uses, no amount of any type of encryption will save you. Except maybe some entangled quantum bit collapsing mechanism. Maybe.
Think hardware keyloggers, fake MBRs, &c.
OP's trick won't work, but that's an "implementation detail;" there are plenty others that will.
EDIT: to clarify; that's not what you said, it's just a common enough misconception that it's worth being explicit about, here.
Think hardware keyloggers, fake MBRs, &c.
OP's trick won't work, but that's an "implementation detail;" there are plenty others that will.
EDIT: to clarify; that's not what you said, it's just a common enough misconception that it's worth being explicit about, here.
Of course keyloggers etc. are a problem. But that is a different story. A bug which can be exploited just by grabbing any device might have a larger impact on the vendors reputation.
A keylogger, fake smc, whatsoever ist much more dangerous for a single person, because the attacker knows what he wants on the specific device.
There's have to be a hardware mod if a firmware password is enabled. It prevents booting from any other media or partition without a password.
That's not very interesting. You can do the same on a linux box, passing init=/bin/sh in the boot loader, and probably the same on windows (boot a WinPE CD or a Linux live CD with NTFS3g).
If I understood the article correctly, this can be exploited remotely by anybody who has managed to get a shell on the system.
It's even worse than it seems if you talk about it as 'anybody'.
Most OSX boxes are probably single user devices. But you do not normally run as root/wheel, you need sudo (sometimes through a nice GUI) for software to get root privs.
It's not 'somebody' as if another person were logged into their own account. It's that malware running as you can now get root, to further compromise your system, without needing a sudo password.
Most OSX boxes are probably single user devices. But you do not normally run as root/wheel, you need sudo (sometimes through a nice GUI) for software to get root privs.
It's not 'somebody' as if another person were logged into their own account. It's that malware running as you can now get root, to further compromise your system, without needing a sudo password.
Just to clarify, this is _not_ a remote vulnerability. If it was a means to create a remote shell, then it would be. An attacker would need to first find some way to gain remote access and then could use this bug to gain root privilege.
The parent comment and some of the child comments are implying you need to be physically near the system, which doesn't seem to be true.
You still need to find a way to execute code on the target system (also called "getting a shell"), but this can be done over the wire, too.
You still need to find a way to execute code on the target system (also called "getting a shell"), but this can be done over the wire, too.
[deleted]
That's how all local exploits work.
Yes, but that's not really a concern. Physical access with no disk encryption is always 'vulnerable'.
What's pretty bad here is that any user now has a backdoor to obtaining root privileges. That's an awful security flaw.
What's pretty bad here is that any user now has a backdoor to obtaining root privileges. That's an awful security flaw.
There's a huge difference between physical access vulnerabilities (which are basically impossible to prevent) and local privesc vulnerabilities (which can be exploited in software).
To exemplify, for instance, this vulnerability could be packed in a phishing mail executable giving the remote attacker root access if the user falls for the trap, no?
It could be packaged into any executable that someone might think about downloading off the Internet for some reason.
So its really, really not good. Apple need to fix this soon, or else every OSX machine out there is going to start being targeted for misuse. This is really a powerful security bug.
So its really, really not good. Apple need to fix this soon, or else every OSX machine out there is going to start being targeted for misuse. This is really a powerful security bug.
Yes.
Isn't the idea though that with physical access, the game is already over anyway? If an intruder has physical access to your machine they will eventually be able to get to anything they want.
If someone really wants to protect their data, they have to count physical access as a possibility and rely on encryption and/or remote wiping - the operating system login isn't going to do much anyway.
If someone really wants to protect their data, they have to count physical access as a possibility and rely on encryption and/or remote wiping - the operating system login isn't going to do much anyway.
Yep, physical access is total access. However, this trick falls under cool-at-school-tech-labs, I'd hope enterprise systems would do something to prevent this kind of low-level shenanigans.
School tech labs are modelled after the enterprise networks, the only difference is usually a bit more competent IT staff. I'd expect most of the school-lab tricks to be directly transferable to enterprise.
> With physical access
What malware requires physical access? This is a local privilege escalation to root. It's only local because you need an account on the machine to make it work, but it can be bootstrapped to a remote exploit.
What malware requires physical access? This is a local privilege escalation to root. It's only local because you need an account on the machine to make it work, but it can be bootstrapped to a remote exploit.
About two months or three ago I stupidly changed my password to my only account to a password I promptly forgot. I was losing it when I realized what I had done. To make matters worse, I did this change a day before our office was scheduled to move to automated backups via Time Machine.
Luckily after some digging I came across this fix and was back in to my computer, albeit a little shaken up by the back door.
Luckily after some digging I came across this fix and was back in to my computer, albeit a little shaken up by the back door.
If you're paranoid enough to think someone you don't trust can have physical access to your Mac, it is possible to prevent this by setting up firmware password though.
See https://support.apple.com/en-us/HT204455
See https://support.apple.com/en-us/HT204455
Firmware passwords can be bypassed by a local user with a Thunderbolt Option ROM. The 10.10.2 fix for Thunderstrike left that hole open during normal boots: https://trmm.net/Thunderstrike_FAQ#Is_Thunderstrike_fixed_in...
The first Mac I ever got, the IT department forgot to give me admin access, so I couldn't install any software. Having never used a Mac before, it took a grand total of about 15 minutes of Googling to figure out how to boot into single user mode and give myself admin access.
Of course this exploits XPC.
I really hate all the desktop IPC bullshit. IPC frameworks are pure fucking evil. COM, D-Bus, XPC, everything SUCKS.
If you want completely separate programs on one machine to talk, use UNIX domain sockets (with something like ZeroMQ or HTTP), FIFOs (named pipes), anything that you can chmod and chown, not a daemon that reinvents access control, badly.
I really hate all the desktop IPC bullshit. IPC frameworks are pure fucking evil. COM, D-Bus, XPC, everything SUCKS.
If you want completely separate programs on one machine to talk, use UNIX domain sockets (with something like ZeroMQ or HTTP), FIFOs (named pipes), anything that you can chmod and chown, not a daemon that reinvents access control, badly.
Well, this is a very trivial "exploit" of XPC. The real problem is that such an API even exists at all. I mean, a method to create an arbitrary file in an arbitrary location with arbitrary attributes? That is completely braindead. That is clearly equivalent to root privileges, and therefore such an API shouldn't exist - sudo should be used instead, or other OS X methods of explicitly gaining root privileges.
This method wouldn't pass the most cursory of security checks. It's clear that it was never actually reviewed, and that the original programmer was relying on the proprietary nature of the OS X system for security. Something like this would never happen with Linux IPC - reviewing the methods published on dbus by services running as root by default is a basic check that any sane distro will do. Something as straightforwardly exploitable as this (literally just call the method while running as an admin user!) would never go in to Debian.
This method wouldn't pass the most cursory of security checks. It's clear that it was never actually reviewed, and that the original programmer was relying on the proprietary nature of the OS X system for security. Something like this would never happen with Linux IPC - reviewing the methods published on dbus by services running as root by default is a basic check that any sane distro will do. Something as straightforwardly exploitable as this (literally just call the method while running as an admin user!) would never go in to Debian.
> I really hate all the desktop IPC bullshit. IPC frameworks are pure fucking evil. COM, D-Bus, XPC, everything SUCKS.
> If you want completely separate programs on one machine to talk, use UNIX domain sockets
D-Bus does use UNIX domain sockets. Your ruthless hate should probably try harder at informing itself.
> If you want completely separate programs on one machine to talk, use UNIX domain sockets
D-Bus does use UNIX domain sockets. Your ruthless hate should probably try harder at informing itself.
Hm? This wouldn't have been any better if implemented using sockets.
Indeed, it wouldn't. It's just another typical example of someone who doesn't understand why a complicated IPC system exists, and thus blames all possible problems on its mere existence.
It's like users who encounter a random problem in a program, and then blame it on the fact that the program is written in C++, simply because they do not like C++.
It's like users who encounter a random problem in a program, and then blame it on the fact that the program is written in C++, simply because they do not like C++.
[deleted]
While this is a significant vulnerability, I don't think the article is correct when it calls it a 'backdoor.' The term backdoor typically implies something that was intentionally left to allow illicit access, and while this is a significant bug, I don't see anything to indicate that's the case here.
This is a hole that exists because an Apple-written application needed a method to gain elevated access. This was done through unpublished APIs which, when used by another application in a similar way, also resulted in elevated access.
So, this was clearly intentional, because it's used by Apple directly. And it allows illicit access, because any program can use it to gain access.
So, this was clearly intentional, because it's used by Apple directly. And it allows illicit access, because any program can use it to gain access.
I'm not so sure. Unless I'm missing something, he doesn't demonstrate that this 'backdoor' is in use. It looks like they were using an escalation backdoor in `systemsetup`, but quickly patched a fix after 10.8.5. He just found a way around it.
Now, the fact that 'it takes too much effort' to backport would suggest that it was still in use. I don't see any other evidence, though. I'd be interested if someone found it!
Now, the fact that 'it takes too much effort' to backport would suggest that it was still in use. I don't see any other evidence, though. I'd be interested if someone found it!
This seems to be the path followed:
systemsetup pointed to the Admin framework.
Admin framework analysis revealed use of "createFileWithContents". The function in which this use occurs is not named in the analysis.
An error message in the initial proof attempt led to "authenticateUsingAuthorization". Back to systemsetup to determine how to use "authenticateUsingAuthorization". (This is where I ended up mentally relinking the issue back to systemsetup.)
So, I concede that is is not stated where within the Admin framework this "createFileWithContents" method is invoked. However, I also agree that if that function was not used, it would be simple to remove it and the issue would be fixed.
systemsetup pointed to the Admin framework.
Admin framework analysis revealed use of "createFileWithContents". The function in which this use occurs is not named in the analysis.
An error message in the initial proof attempt led to "authenticateUsingAuthorization". Back to systemsetup to determine how to use "authenticateUsingAuthorization". (This is where I ended up mentally relinking the issue back to systemsetup.)
So, I concede that is is not stated where within the Admin framework this "createFileWithContents" method is invoked. However, I also agree that if that function was not used, it would be simple to remove it and the issue would be fixed.
There's no way to tell for sure if something like this is intentional or not. Also, waiting to fix it until a researcher makes it public may have been intentional.
> There's no way to tell for sure if something like this is intentional or not.
Right, so the simplest explanation is that it's an unintentional bug. The absence of evidence that it was unintentional isn't evidence that it was intentional. If there were some magic string or default password or something, that'd be an obvious backdoor, but to me this looks like a pretty typical privesc bug, albeit in an undocumented api.
It was found through a chain of events that started with looking at the patch related to another privilege escalation vulnerability, one which no one seems to be claiming was a backdoor.
> Also, waiting to fix it until a researcher makes it public may have been intentional.
I'm guessing it's more likely the the researcher waiting to go public until it was fixed.
This is evidenced both by the fact that it was patched alongside other vulns (ie. not a rushed out one-off patch) and from the article's disclosure timeline, which shows 'Full disclosure' occurring 04/09, while the 'Release of OS X 10.10.3' occurred 04/08. This is a pretty typical disclosure timeline; they couldn't begin to fix it until it was tracked as a bug, after all.
Right, so the simplest explanation is that it's an unintentional bug. The absence of evidence that it was unintentional isn't evidence that it was intentional. If there were some magic string or default password or something, that'd be an obvious backdoor, but to me this looks like a pretty typical privesc bug, albeit in an undocumented api.
It was found through a chain of events that started with looking at the patch related to another privilege escalation vulnerability, one which no one seems to be claiming was a backdoor.
> Also, waiting to fix it until a researcher makes it public may have been intentional.
I'm guessing it's more likely the the researcher waiting to go public until it was fixed.
This is evidenced both by the fact that it was patched alongside other vulns (ie. not a rushed out one-off patch) and from the article's disclosure timeline, which shows 'Full disclosure' occurring 04/09, while the 'Release of OS X 10.10.3' occurred 04/08. This is a pretty typical disclosure timeline; they couldn't begin to fix it until it was tracked as a bug, after all.
A function named "createFileWithContents" is clearly intentional - through its creator probably just hadn't realised the security implication, making this a negligent, rather than malicious, backdoor, not unlike default router passwords.
OT but I have to say that the amount of Apple apologists in these comments is mind blowing. HN reader of all people should be the ones urging Apple to issue a fix for a very serious bug such as this one. Yet many comments here are saying that people should just upgrade while it might solve the problem for some, there are ones who can't upgrade machines at will.
Yeah, this is scandalous. I've heard enough things about Yosemite bugs that I held off upgrading, especially as I want to avoid software compatibility issues.
I hate Apple's new yearly release cycle. There's not enough time to stabilize and improve OS's.
This update just rolled out, but it indicates the admin fixes are only for Yosemite:
https://support.apple.com/en-us/HT204659
How worried should I be about not having updated? There's still a risk I may lose some program compatibility by updating.
I hate Apple's new yearly release cycle. There's not enough time to stabilize and improve OS's.
This update just rolled out, but it indicates the admin fixes are only for Yosemite:
https://support.apple.com/en-us/HT204659
How worried should I be about not having updated? There's still a risk I may lose some program compatibility by updating.
Is your mac a server or a multi-user desktop where some users intentionally don't have admin access? If so, you're in trouble. If not, this bug probably doesn't really matter to you.
For a single-user desktop machine, realistically, user/root privilege separation doesn't matter, because all your important data is in your home directory and not protected by root privileges anyhow. The root-protected stuff is actually the stuff that's easiest to replace, because it's just a bunch of software that you can re-install. Viruses don't need to infect your software to stay resident; they can just as easily register a login hook without root permissions.
(That said, some people will violently disagree with me on this.)
For a single-user desktop machine, realistically, user/root privilege separation doesn't matter, because all your important data is in your home directory and not protected by root privileges anyhow. The root-protected stuff is actually the stuff that's easiest to replace, because it's just a bunch of software that you can re-install. Viruses don't need to infect your software to stay resident; they can just as easily register a login hook without root permissions.
(That said, some people will violently disagree with me on this.)
>Yet many comments here are saying that people should just upgrade while it might solve the problem for some, there are ones who can't upgrade machines at will.
It's dumbfounding how people here are simply shrugging this off and posting "So what? Just upgrade. Simples" type comments. This isn't acceptable. I know many people in creative industries alone who can't just upgrade immediately any time something comes out as they've to wait for their products to support the newer version. Similarly there are many who are using Macs in work whose corporate policies won't let them simply update immediately.
Then there's many who don't immediately upgrade versions as a point while bugs/other issues in that new version are found and resolved.
It's not an acceptable answer whatsoever.
It's dumbfounding how people here are simply shrugging this off and posting "So what? Just upgrade. Simples" type comments. This isn't acceptable. I know many people in creative industries alone who can't just upgrade immediately any time something comes out as they've to wait for their products to support the newer version. Similarly there are many who are using Macs in work whose corporate policies won't let them simply update immediately.
Then there's many who don't immediately upgrade versions as a point while bugs/other issues in that new version are found and resolved.
It's not an acceptable answer whatsoever.
I have 3 macs. One of them is an older iMac. I can't put enough RAM in it to run Mavericks (which is a memory hog). It is a perfectly good computer, there is no reason to upgrade from Lion.
The next one is a 3 year old Mac Mini. I upgraded to Yosemite and it performs TERRIBLY. It has 16G of RAM. I've tried everything. Yosemite just sucks. The machine is now much slower than the 6 or 7 year old iMac with only 4G or RAM. If it was practical to back out to Mavericks I would.
The last one is a 2 year old Macbook. I rely on it for my job. There is no way I'm going to risk the crappy Yosemite performance to upgrade. I'll live with the security flaw.
Here is what I now know about Apple: They will not support you for the lifetime of the product. They consistently release buggy code these days. Unless you are willing to shell out more money for new hardware every time they come out with something new, you will be stuck "as-is (with bugs)" until you get rid of it.
No more Apple anything for me. I'm thinking I'll switch the Mac Mini to Ubuntu if I can get it to work there. I'll use the iMac until it doesn't work any more, and when my Macbook is ready for an upgrade (in another year or two), I'll be trading in that still-Mavericks based system for a Linux laptop or maybe I'll go back to Windows.
The next one is a 3 year old Mac Mini. I upgraded to Yosemite and it performs TERRIBLY. It has 16G of RAM. I've tried everything. Yosemite just sucks. The machine is now much slower than the 6 or 7 year old iMac with only 4G or RAM. If it was practical to back out to Mavericks I would.
The last one is a 2 year old Macbook. I rely on it for my job. There is no way I'm going to risk the crappy Yosemite performance to upgrade. I'll live with the security flaw.
Here is what I now know about Apple: They will not support you for the lifetime of the product. They consistently release buggy code these days. Unless you are willing to shell out more money for new hardware every time they come out with something new, you will be stuck "as-is (with bugs)" until you get rid of it.
No more Apple anything for me. I'm thinking I'll switch the Mac Mini to Ubuntu if I can get it to work there. I'll use the iMac until it doesn't work any more, and when my Macbook is ready for an upgrade (in another year or two), I'll be trading in that still-Mavericks based system for a Linux laptop or maybe I'll go back to Windows.
"I can't put enough RAM in it to run Mavericks (which is a memory hog)."
I'd upgrade to Yosemite today with the latest updates. They just freed up 4 GB of ram for me. Sadly if I had known all of this beforehand I wouldn't have gone out of the way to buy some old Mac Pro where I could upgrade the memory to 32 GB or more, so I just wasted about $1500 for the whole setup.
Then again like you, I transitioned my work to an Ubuntu box, but even for my personal stuff my Mac was just really slow unless you get an SSD drive which is time consuming to install on an iMac.
I'd upgrade to Yosemite today with the latest updates. They just freed up 4 GB of ram for me. Sadly if I had known all of this beforehand I wouldn't have gone out of the way to buy some old Mac Pro where I could upgrade the memory to 32 GB or more, so I just wasted about $1500 for the whole setup.
Then again like you, I transitioned my work to an Ubuntu box, but even for my personal stuff my Mac was just really slow unless you get an SSD drive which is time consuming to install on an iMac.
You can't run Yosemite on a lot of older hardware: http://www.apple.com/osx/how-to-upgrade.
2007 is pretty old when it comes to Macs.
For 2009 and up Mac Pros, there are plenty of hardware options for upgrades; and firmware as well for 2009.
For 2009 and up Mac Pros, there are plenty of hardware options for upgrades; and firmware as well for 2009.
>It's dumbfounding how people here are simply shrugging this off and posting "So what? Just upgrade. Simples" type comments.
Zero people is dumbfounding to you? Because that's how many people are saying that.
Zero people is dumbfounding to you? Because that's how many people are saying that.
> Zero people
Reread the comments.
Reread the comments.
Please link to a comment that says something remotely close to, "So what? Just upgrade. Simples"
https://news.ycombinator.com/item?id=9348257
The second comment from the top when you go to
https://news.ycombinator.com/item?id=9347669
The second comment from the top when you go to
https://news.ycombinator.com/item?id=9347669
>Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility.
This is nothing close to "So what? Just upgrade." He's saying that from apple's perspective the best customer is one who upgrades their machine on every upgrade cycle which explains why they don't care about previous generation OSes. And how can you say this comment is apple-apologetic when he goes on to say that Microsoft does a better job maintaining backwards-compatibility?
This is nothing close to "So what? Just upgrade." He's saying that from apple's perspective the best customer is one who upgrades their machine on every upgrade cycle which explains why they don't care about previous generation OSes. And how can you say this comment is apple-apologetic when he goes on to say that Microsoft does a better job maintaining backwards-compatibility?
Hey, at least there weren't any of the 'Well, I don't care if anyone sees all my boring details anyway' variety. At least people are beginning to understand the most basic implications of loss of privacy.
Same devs who just say "users should just upgrade their browsers" perhaps?
If only it were that easy. Yosemite just seems to "break" some things and I've still been waiting it out.
If only it were that easy. Yosemite just seems to "break" some things and I've still been waiting it out.
What apologists? Were the comments deleted or something, because I really don't see anyone defending Apple in this thread.
> Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility.
> To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.
> While this is a significant vulnerability, I don't think the article is correct when it calls it a 'backdoor.' The term backdoor typically implies something that was intentionally left to allow illicit access, and while this is a significant bug, I don't see anything to indicate that's the case here.
> Title is a little generous about "hidden", the exploit revolves around API & Framework used to power the parts of the control panel, and its authorization scheme being broken.
> Smells like an oversight to me. Some new developer got assigned to implement or tweak the SSH enabling switch (or whatever), and this was their solution, which never got reviewed.
> Referring to Snow Leopard now not secure > Still pretty much the best OSX.
> Among other things upgrading (to 10.10.3) will do, it'll fix the issue in the article.
> To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.
> While this is a significant vulnerability, I don't think the article is correct when it calls it a 'backdoor.' The term backdoor typically implies something that was intentionally left to allow illicit access, and while this is a significant bug, I don't see anything to indicate that's the case here.
> Title is a little generous about "hidden", the exploit revolves around API & Framework used to power the parts of the control panel, and its authorization scheme being broken.
> Smells like an oversight to me. Some new developer got assigned to implement or tweak the SSH enabling switch (or whatever), and this was their solution, which never got reviewed.
> Referring to Snow Leopard now not secure > Still pretty much the best OSX.
> Among other things upgrading (to 10.10.3) will do, it'll fix the issue in the article.
So, it's my comment you quoted questioning whether this can be called a backdoor.
I don't intend that to be apologetic for Apple. I called it a 'significant vulnerability' but at the end of the day, it's a privilege escalation like those that have come before and will likely continue to be found occasionally, regardless of OS. I don't see what's apologetic about acknowledging a significant vulnerable while questioning whether it should be called a backdoor.
If you want to talk about Apple's response - I find it concerning that they aren't backporting the fix.
I don't intend that to be apologetic for Apple. I called it a 'significant vulnerability' but at the end of the day, it's a privilege escalation like those that have come before and will likely continue to be found occasionally, regardless of OS. I don't see what's apologetic about acknowledging a significant vulnerable while questioning whether it should be called a backdoor.
If you want to talk about Apple's response - I find it concerning that they aren't backporting the fix.
Most of those are people giving fairly reasonable benefit of the doubt, no apologism. But I suspect you're probably about as biased against Apple as the people you're assuming are biased towards Apple.
Oh your really off base.. I am MUCH MORE biased against Apple. You know those Linux users who hate on Microsoft? I am the Linux user who HATES Apple since I was first lied to by Apple in 1983 (Color Mac coming in the next year, wasn't till March 1987) (Color Mac will destroy Amiga 1000 in 1985)
I have never seen Apple as being honest or making products for me as a nerd. So I live mostly in Linux nowadays.
I have never seen Apple as being honest or making products for me as a nerd. So I live mostly in Linux nowadays.
Alrighty.... I can't think of a better way to undermine your credibility, so I think we're done here.
A biased person isn't credible? What did I say that was factually wrong or personal opinion. I don't like Apple products (Locked down and no fun for a hacker and expensive)
I have no credibility since I don't like a company? What about the opposite people who like the company?
Credible people are always upfront with their biases. I never trust anyone that says they are neutral.
I have no credibility since I don't like a company? What about the opposite people who like the company?
Credible people are always upfront with their biases. I never trust anyone that says they are neutral.
Of course not. You're admitting and prideful that you aren't going to look at things fairly, and your complaints are therefore unhelpful, naive and very likely wrong to boot. People who simply like Apple are not uncredible, though a fanboy would be, for similar but opposite reasons. Credible people are aware of their biases and strive to overcome them. When you embrace your biases like you have, you're just offering some bullshit with a disclaimer that it's bullshit. At least you have honesty going for you.
> very likely wrong to boot
Well the answer to that is when someone says something you call for proof. You don't throw out the baby with the bathwater. That's what I do with David Pouge and Walt Mossberg. But I usually get my news from Tech Press that has been black balled by Apple.
Well the answer to that is when someone says something you call for proof. You don't throw out the baby with the bathwater. That's what I do with David Pouge and Walt Mossberg. But I usually get my news from Tech Press that has been black balled by Apple.
At least you're honest about it. Most who feel similarly will coat it in a thin veneer of pretend equal-handedness and categorically deny any emotional investment.
[deleted]
Do you legitimately see these comments are being apologetic towards apple?
He seems to see anything that doesn't include pitchforks and torches as apologetic.
> To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.
Which was a response to:
>Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility.
He was rebutting that regular upgrades are somehow a type of revenue to apple since they are free and work on some previous generation hardware. How is that apologetic?
>Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility.
He was rebutting that regular upgrades are somehow a type of revenue to apple since they are free and work on some previous generation hardware. How is that apologetic?
It sounds apologetic to him because he's more interested in tribalism than business or technology. It's not unlike much religious fundamentalism- the pursuit of truth takes a back seat to the pursuit of feeling like you're right about things, especially if it means you get to hate a caricature of some other group of people and blame some of your personal disappointments on them.
A similar force seems to drive politics, or at least motivates disturbingly huge blocs of voters. :(
A similar force seems to drive politics, or at least motivates disturbingly huge blocs of voters. :(
Wait saying that 5 years hardware support is to short is wrong and that yearly updates in OS makes me into a religious Anti-Apple Zealot and Tribalism?
I don't like Apple's business practices, hard to hack devices and technology philosophy doesn't mean I am Tribal.
I have many machines that are over 5 years old.
I don't like Apple's business practices, hard to hack devices and technology philosophy doesn't mean I am Tribal.
I have many machines that are over 5 years old.
How is it good business sense to have 5 years support for hardware? I have much older hardware doing very productive things also my non-profit couldn't afford to upgrade every desktop every five years and update every desktop's OS every year.
I have to agree. I have an older macbook that if I upgrade to another above Snow Leopard, it runs pretty slow. But I do understand that support for older devices has to stop at some point.
>many comments here are saying that people should just upgrade
I don't see a single comment in this thread that says that.
I don't see a single comment in this thread that says that.
po1nter,
We do not allow developers to criticize our revolutionary and beautiful platform. Good luck ever getting an app featured again.
- Apple
We do not allow developers to criticize our revolutionary and beautiful platform. Good luck ever getting an app featured again.
- Apple
Haha reminds me of the article from the other week: http://www.elischiff.com/blog/2015/3/24/fear-of-apple
Yeah, imagine if the same was true of say, Rails 4.0.
I'm having a hard time understanding whether this is an intentional backdoor or just an accident.
Smells like an oversight to me. Some new developer got assigned to implement or tweak the SSH enabling switch (or whatever), and this was their solution, which never got reviewed.
In that case, I think "backdoor" is hyperbolic. That word is usually uses to indicate intentional secret security holes.
What do you call something that grants root access without authentication, but wasn't intended to let arbitrary people or programs use it?
"Backdoor" isn't quite right, since that implies that the intent was to allow unauthorized use.
"Security vulnerability" isn't quite right either, since that usually implies getting code to exhibit some sort of behavior it was never supposed to have.
I can't think of any other term. Of the two, "backdoor" seems closer. Maybe "unintentional backdoor"?
"Backdoor" isn't quite right, since that implies that the intent was to allow unauthorized use.
"Security vulnerability" isn't quite right either, since that usually implies getting code to exhibit some sort of behavior it was never supposed to have.
I can't think of any other term. Of the two, "backdoor" seems closer. Maybe "unintentional backdoor"?
> What do you call something that grants root access without authentication, but wasn't intended to let arbitrary people or programs use it?
Local privilege escalation. In a huge number of established LPEs, the exploit is by leveraging a weakness in checking who makes the call that allows legitimate privilege escalation. This is a legitimate privilege escalation (sshd binds to port 22, among others tasks), that can be exploited through a weakness in checking who is making that request and if they can have that granted.
Local privilege escalation. In a huge number of established LPEs, the exploit is by leveraging a weakness in checking who makes the call that allows legitimate privilege escalation. This is a legitimate privilege escalation (sshd binds to port 22, among others tasks), that can be exploited through a weakness in checking who is making that request and if they can have that granted.
Unintentional backdoor is better, wouldn't be my choice though.
To me the term backdoor implies malevolence and purposeful decision to allow you to remotely access someone's system without their permission later.
And purposeful decision to allow you to remotely access someone's system without their permission later.
This seems more like a mistake, although a pretty big one. It seems like it was designed as a small escaped out to make some of Apple's scripts cleaner it wasn't locked down to the degree that should've been.
It's a big security hole, but I'm not sure backdoor fits.
To me the term backdoor implies malevolence and purposeful decision to allow you to remotely access someone's system without their permission later.
And purposeful decision to allow you to remotely access someone's system without their permission later.
This seems more like a mistake, although a pretty big one. It seems like it was designed as a small escaped out to make some of Apple's scripts cleaner it wasn't locked down to the degree that should've been.
It's a big security hole, but I'm not sure backdoor fits.
There is no jargon for "obscure, deliberately implemented security hole which supports system functionality", because nobody does that.
(For values of 'nobody' which are not members of a set that includes such as Apple, obviously.)
Jargon and slang is needed for shortening the names of everyday things that people do, use or encounter.
If Apple has started a trend, we might need a new term, like "root kludge". A deliberate solution with negative attributes is a kludge (that much we have slang for, because we encounter such things with reasonable frequency). This type of kludge gets us root. So ...
Wait, if Apple starts a trend with this, then it will be cool, and have some name that begins with 'i'.
How about "iHole".
"An iHole was discovered in my wi-fi router's firmware".
Hmmm ...
(For values of 'nobody' which are not members of a set that includes such as Apple, obviously.)
Jargon and slang is needed for shortening the names of everyday things that people do, use or encounter.
If Apple has started a trend, we might need a new term, like "root kludge". A deliberate solution with negative attributes is a kludge (that much we have slang for, because we encounter such things with reasonable frequency). This type of kludge gets us root. So ...
Wait, if Apple starts a trend with this, then it will be cool, and have some name that begins with 'i'.
How about "iHole".
"An iHole was discovered in my wi-fi router's firmware".
Hmmm ...
I guess. It's a backdoor in the sense that you can intentionally bypass privilege checks by calling a certain API with a particular argument. But I don't think it's a backdoor in the sense that the developers wanted a secret way to gain root on an arbitrary machine.
Worked wonders for getting to the top of HN though.
Works the same way for whoever uses it.
The reading indicates a few times it was likely there for System Preferences, not for a government agency or anything like that.
As someone who loathes Yosemite, I was hoping to find another fix for this. However, the exploit code when run in my console already returns "You need an administrator password" prompt. Huh? I'm running 10.9.5.
Run the python script at the end of the article as non admin/non root user. The script allows you to create a copy of a binary in say /usr/bin with "set user ID execution" bit set and owned by root! This should not be possible without root privileges.
This is pretty bad, and trivially exploitable. Basically anyone that has non-root access to your computer can trivially become root and take over the system.
This is pretty bad, and trivially exploitable. Basically anyone that has non-root access to your computer can trivially become root and take over the system.
I am really pissed they are only releasing a patch for 10.10, and forcing me to upgrade to 10.10.
When Apple refuses to fix something that's good the public's interest, the best way to get Apple's attention is to make this a rootpipe gate by sending tips to all Apple focused media outlets like AppleInsider Macrumors etc. Talk about the power of press.
Case in point: Antenna gate, Bend-gate etc.
Case in point: Antenna gate, Bend-gate etc.
Objective-C's "null pointer dereferences doesn't crash" behaviour rears its ugly horrible head again.
Programs crash for a reason! Crashing when faced with nonsense is a good thing! Let us not forget this.
Programs crash for a reason! Crashing when faced with nonsense is a good thing! Let us not forget this.
Null pointer dereferences do crash in Objective-C. Sending messages to nil is generally not nonsense in Objective-C, though. It has well-defined semantics and is useful in many cases. It isn't a "Don't crash when faced with nonsense" policy. I'm not sure the benefits are enough to justify its propensity to trip people up, but it's not like it's just some kind of crash prevention.
This is not considered "nonsense" in Objective-C is part of the issue: having "no receiver" do nothing is well defined behavior that has a long tradition at least back to Smalltalk. People use this to write shorter code, on purpose, causing an effect similar to Haskell's Maybe monad.
(Note: I, myself, do not ever rely on this functionality, and even disagree with it, but the context in which people use it is important to understand when judging it; and with that context, I consider my own objections mostly due to my biases and not something that I would argue is "correct".)
(Note: I, myself, do not ever rely on this functionality, and even disagree with it, but the context in which people use it is important to understand when judging it; and with that context, I consider my own objections mostly due to my biases and not something that I would argue is "correct".)
To be fair, calling a virtual method on a null receiver is undefined behavior (not necessarily a segfault!) in C++ too. The compiler is free to replicate Objective-C's behavior if it wants to.
(Of course, no compilers actually do precisely that, but it is possible for compilers to delete virtual method calls entirely if it can prove the receiver had to be null...)
(Of course, no compilers actually do precisely that, but it is possible for compilers to delete virtual method calls entirely if it can prove the receiver had to be null...)
Why is that undefined? Seems like it should obviously cause a fault...
It's an optimization. Virtual methods that don't dereference this (by not accessing any non static member variables for example) don't have to check if this is null. For example,
EDIT:
Also, it's worth explaining why test1 works even though do_it_if is virtual. Since there aren't any methods that override do_it_if, the virtual method lookup can be elided and you don't have to dereference this to find the vtable. If do_it_if had been overridden and the runtime type was unknown, you would need to dereference this to lookup do_it_if in the vtable, which would segfault in both tests.
class Example {
public:
static bool do_it;
virtual void do_it_if() {
if (g_do_it) return;
/* otherwise do something that dereferences this... */
}
};
void test1() {
Example::do_it = false;
static_cast<Example *>(NULL)->do_it_if();
}
void test2() {
Example::do_it = true;
static_cast<Example *>(NULL)->do_it_if();
}
In the above code, only test2 crashes (clang 6.0). If crashing was defined behavior you would need an extra check in the code generated for do_it_if.EDIT:
Also, it's worth explaining why test1 works even though do_it_if is virtual. Since there aren't any methods that override do_it_if, the virtual method lookup can be elided and you don't have to dereference this to find the vtable. If do_it_if had been overridden and the runtime type was unknown, you would need to dereference this to lookup do_it_if in the vtable, which would segfault in both tests.
C and C++ need to be usable in systems without memory protection, so they don't guarantee any faults for operations like method calls. (There are some standard-guaranteed exceptions, for example std::bad_alloc, but those are only on relatively expensive operations.)
Compilers then take advantage of these undefined behaviors to optimize even on systems that do have memory protection.
I'm kind of surprised there's not a means (to my knowledge, at least) to crash/throw an exception upon sending a message to nil for people who want to better ensure their code doesn't have lurking issues like this. I suppose it'd have to be smart enough to filter out system frameworks to be useful, but I'd imagine that to be do-able.
There is a means to do that: http://ddeville.me/2013/06/ruby-like-nil-messaging-in-object...
I have a feeling it wouldn't work well in practice if you made the handler raise an exception. As the author notes, you're not the only one sending messages, and Cocoa will probably crash your program with a nil message send sooner or later. But you might be able to use it to find out where it's happening, at least.
I have a feeling it wouldn't work well in practice if you made the handler raise an exception. As the author notes, you're not the only one sending messages, and Cocoa will probably crash your program with a nil message send sooner or later. But you might be able to use it to find out where it's happening, at least.
There was, in the form of the -fno-nil-receivers compiler flag. It looks like clang doesn't support this flag. I'm guessing nobody used it. You'd have to be really careful when turning it on, since you're effectively using a language that's similar but not quite identical to Objective-C, and which will crash on lots of legal and sensible Objective-C code.
Why not just some old-fashioned input guarding?
if (input == nil)
haltAndCatchFire();
Or whatever the Objective-C syntax for that is.To make a scheme like that work, you'd essentially need to check before every single method invocation in your entire program because the issue — such as it is — is with method invocations being made against nil references, not with nil parameters being passed in as arguments to method calls.
I was imagining something more like a modified version of the runtime's objc_msgSend() C function (which Obj-C method invocations get compiled into) that guarded against that, but you do make me realize that such checks could conceivably be automatically tacked on at build time.
Anyway, I'm not entirely sure how useful such a thing would be, but I am curious how often my code (unintentionally) makes calls against nil and I've just never noticed because it doesn't cause harm.
I was imagining something more like a modified version of the runtime's objc_msgSend() C function (which Obj-C method invocations get compiled into) that guarded against that, but you do make me realize that such checks could conceivably be automatically tacked on at build time.
Anyway, I'm not entirely sure how useful such a thing would be, but I am curious how often my code (unintentionally) makes calls against nil and I've just never noticed because it doesn't cause harm.
Ah, I see. I think that at some point you have to trust something. The only true way is to never trust any of your inputs. This is, after all, what the JVM does in order to throw out kindly NullPointerExceptions on null dereferences. But realistically that is extremely consuming and has little payoff in most cases. I typically do not trust arguments, but do trust the results of functions to be what the documentation says it will be.
Static analysis could potentially go a long way here to expose values that could be potentially "infected" with nil. (And, for all I know, the JVM JIT could do exactly this to skip checks on provably non-null values.)
Static analysis could potentially go a long way here to expose values that could be potentially "infected" with nil. (And, for all I know, the JVM JIT could do exactly this to skip checks on provably non-null values.)
Can you explain this to non Obj-C users? How does it not crash on null pointers?
The Obj-C function call [foo doSomething] compiles to the equivalent of objc_msgSend(foo, "doSomething"); (for the pedantic, I'm intentionally simplifying and leaving out objc_selfrefs)
The first thing objc_msgSend does is check if foo is nil and, if so, returns 0/nil/the all-zero bit pattern/whatever. It can be extremely convenient, but it can also be extremely inconvenient.
The first thing objc_msgSend does is check if foo is nil and, if so, returns 0/nil/the all-zero bit pattern/whatever. It can be extremely convenient, but it can also be extremely inconvenient.
Very informative, thanks. I am a C++ developer and recently had to fix a bug in an OSX app using Obj-C, which looks insane syntax to me. This only goes to reaffirm my belief that it's insane.
Anyway, I'll carry on reading my ObjC book as obviously the language has uses, although there's a Swift book in the post. Which do I read first though, eh?
Anyway, I'll carry on reading my ObjC book as obviously the language has uses, although there's a Swift book in the post. Which do I read first though, eh?
Calling any method ("sending any message" in Objective-C terminology) on a nil receiver does nothing and returns the zero value of the method's result type (a value of the right size with all bits zeroed).
In Objective-C 'nil' is a special object (internally rwpresented by a null pointer). When the runtime is instructed to invoke any method on nil, the method does nothing and returns nil (rather than crashing). I think this is an artifact of Smalltalk behavior.
This is all Objective-C. In Smalltalk sending messages to nil results in a #doesNotUnderstand: runtime exception.
> Okay, so the systemsetup binary simply checks if we are running as the root user?
>Philip tried patching that function (replacing sete with setne), with success:
How do you patch the binary without root or the admin user password anyway?
>Philip tried patching that function (replacing sete with setne), with success:
How do you patch the binary without root or the admin user password anyway?
Pretty sure they did that as root, so they could get past that and explore how the program worked when being run as a non-root user. The final exploit doesn't depend on this program, though; it uses the same RPC interfaces this program does, from a separate program, so the patching was just part of their exploration, not part of the exploit.
Just make a copy of the binary that's editable by the user. Or copy its code into a new program. There's nothing special about the specific root-owned systemsetup binary. (It's not setuid.)
I think this is not part of the exploit, it was simply a step to ensure that their intuition about the assembly code was correct.
Hint: the first sentence you quoted ends with a question mark.
Hint: the first sentence you quoted ends with a question mark.
Could anyone summarize the implications of this finding in plain English?
Sometimes these things are easier to explain if you look at it like an attacker:
If you're a regular user of an OSX system before 10.10.3, and you want to become root (admin user), you can use this exploit to become root.
If you're an author of malicious OSX software, and a user without admin permissions installs your malware, you can use this exploit to make your malware run as root.
Once you have root, you can do anything on a system.
If the system you're attacking is 10.10.3 or later, you won't be able to use this exploit because Apple has a fix in 10.10.3.
Apple will not make the fix available to anyone on 10.9 or earlier.
If you're a regular user of an OSX system before 10.10.3, and you want to become root (admin user), you can use this exploit to become root.
If you're an author of malicious OSX software, and a user without admin permissions installs your malware, you can use this exploit to make your malware run as root.
Once you have root, you can do anything on a system.
If the system you're attacking is 10.10.3 or later, you won't be able to use this exploit because Apple has a fix in 10.10.3.
Apple will not make the fix available to anyone on 10.9 or earlier.
Any code running as any user on an unpatched version can become root (and do whatever it wants, E.g. install keyloggers)
Sandboxed apps (from the app storr) may be blocked from doing this, I'm not sure.
Sandboxed apps (from the app storr) may be blocked from doing this, I'm not sure.
>Sandboxed apps (from the app storr) may be blocked from doing this, I'm not sure.
Just tried. Sandbox lets this through. (As long as you pass nil to authenticateUsingAuthorizationSync:).
Just tried. Sandbox lets this through. (As long as you pass nil to authenticateUsingAuthorizationSync:).
Ouch.
https://support.apple.com/en-us/HT204659 makes for depressing reading.
Impact: A local user may be able to cause a system denial of service
Impact: A local user may be able to cause unexpected system shutdown
These two made me laugh though.
Impact: A local user may be able to cause a system denial of service
Impact: A local user may be able to cause unexpected system shutdown
These two made me laugh though.
So who wants to sell a patch for the now unsupported users of OS X 10.9, 10.8, ...? It could be as simple as changing the permissions on System Preferences so that now you must enter your password before running them (so that they always run as root). Then patch out the backdoor.
[deleted]
I also don't think this indicates malicious intent. It's as likely that some collection of junior engineers who were tasked with something other than system security, simply invented something that was both insecure and obscure. This happens all the time. It takes a lot of extra time and code to engineer security and it's historically been one of the first things that product managers and senior management will toss out the door when the schedule inevitably becomes the gating factor. Hey, they fixed it. And you know, some Day One bugs are simply very very hard to fix when you find out years later that there's all this other code that depends on it...
Six months for a fix? I would have given them 90 days and released it.
It does explicitly say that Security Update 2015-004 only updates Admin Framework on 10.10+ (it does not require 10.10.3) to fix CVE-2015-1130 : Emil Kvarnhammar at TrueSec
https://support.apple.com/en-us/HT204659
Quite a few other security related things are fixed with this update that do apply to older versions of OS X.
Quite a few other security related things are fixed with this update that do apply to older versions of OS X.
This article has a nice exploit code written in python down below for curious ones how works in code.
I wonder how long before malware that uses this will appear, given this is trivial to exploit.
so... Anyone preparing OpenBSD to work on newer macbooks?
Couldn't they have made the update slightly smaller than 2GB? Apple sucks at distribution and their software update infrastructure is hosing.
[deleted]
10.10.3 came out 2 days ago. This counts as reasonable disclosure?
He discovered it 6 months ago. Maybe he gave Apple 6 months to fix it before disclosing?
I get that, but surely you have to provide a reasonable amount of time for patches to be installed. Perhaps a 2-part blog entry, where he gives general details (to instill urgency) and then release exploit code a month later?
If he published because Apple just patched, then I agree. If he published because he said he was going to disclose it at a certain time, then I think it's Apple's fault for dragging their feet. 6 months is an eternity.
Once the fix is out there, attackers can compare the new and old code and home in on the vulnerability very quickly.
Related to this, how have people found running Yosemite compared to Mavericks, performance and compatibility-wise?
Are you sorry you upgraded? (I'm asking for a friend.)
Are you sorry you upgraded? (I'm asking for a friend.)
I recently got a mac mini that shipped with Yosemite.
It has the nice feature of completely killing the WiFi interface when you attach a USB hub - googling around it seems a Yosemite bug. I have been told that also using bluetooth devices (such as the apple mouse) can trigger the same behaviour.
So I'd say I'm sorry that the mac shipped with Yosemite, except that at least I received the fix for the privilege escalation bug.
It isn't just Yosemite... I had exactly this behavior with Mavericks on a new MacBook last year. Fired up a Bluetooth mouse, and next time I opened the lid wireless had completely gone.
I've managed to get it working after a fashion, although not reliably, and have come to the conclusion that Apple just don't do wireless well.
I've managed to get it working after a fashion, although not reliably, and have come to the conclusion that Apple just don't do wireless well.
I had this bug plaguing me for a while. My WiFi connection would drop every fifteen minutes or so, requiring me to turn off the WiFi and then turn it on again. I was able to fix it by doing a clean install of Yosemite (from a bootable drive).
My personal computer is a late 2008 MBP, and Yosemite runs fine on that. It's been upgraded to 8 gigs of ram, and that's enough to smoothly do dev work in vagrant environments.
I have the exact same setup with 8GB of RAM, and it's still going strong. I wish I could upgrade to 16GB to extend its life even further.
If you're seriously concerned, why not use an external drive of some sort and install Yosemite to it? (Bonus points: clone your internal disk to it first, and upgrade that.) Boot it up, test out your critical functions, and then update your main volume if it works out for you.
You need to do the Bonus points version of your recommendation. Running an OS off an external will just make everything feel sluggish (unless you have a lightning enclosure and spare SSD laying around).
Would using an external drive make it noticeably slower, making performance non-representative?
That would depend on which interface and drive technologies you use. A SSD connected via Thunderbolt would likely be faster than an internal hard drive.
Not if you get one of these:
http://www.amazon.com/Samsung-Portable-250GB-External-MU-PS2...
http://www.amazon.com/Samsung-Portable-250GB-External-MU-PS2...
This + SSD (Crucial IIRC) gives me 200+Mb/s write, 400+Mb/s read speeds:
http://amzn.com/B00FCLG65U
USB 3.0 is pretty fast. Without TRIM performance will probably degrade but that will take time.
USB 3.0 is pretty fast. Without TRIM performance will probably degrade but that will take time.
I upgraded. I haven't had any problems that I wasn't already having in Mavericks (Anyone else have kernel panics when sleeping with a thunderbolt monitor attached?).
I haven't had any issues with that, and I have two thunderbolt monitors attached in daisy chain mode.
The only kernel panics I've experienced so far have been Parallels Desktop bugs that crashed the system. I'm regularly stressing my Macbook Pro to the max running vagrant images through Parallel Desktop with full integration tests running inside, and this tends to be pretty effective at finding strange bugs in Parallels Desktop.
The only kernel panics I've experienced so far have been Parallels Desktop bugs that crashed the system. I'm regularly stressing my Macbook Pro to the max running vagrant images through Parallel Desktop with full integration tests running inside, and this tends to be pretty effective at finding strange bugs in Parallels Desktop.
Yes! (although minus the thunderbolt monitor)
I also have a problem with a Dual-link DVI adapter. If I sleep with it connected, at some point it wakes up and "kernel_task" takes up 100% CPU (all 8 cores) until I put it to sleep and wake it up again. Sucks coming down in the morning and finding my Macbook burning a hole in the desk.
I've been running with a Thunderbolt Display for a few years now with few problems. I've had zero problems on Yosemite.
Among other things upgrading (to 10.10.3) will do, it'll fix the issue in the article.
[deleted](2)
OT but does anyone know how OSX bluetooth keyboards work? I thought I had BT disabled and a prompt popped up on hotel wi-fi asking me to enter the code for (not my) keyboard
I upgraded my 2014 15" rMBP and it killed the wifi, so now ping times have gone from about 12ms to several thousand or nothing. https://medium.com/@mariociabarra/wifried-ios-8-wifi-perform... no longer works. Depressing. I miss my chromebook.
You could sell your rMBP and use the proceeds to buy like 4-5 chromebooks.
wait, you expected to find people at a security conference that weren't aware of the fact that even OS X can have exploitable vulnerabilities?
What? So all OS X boxes are simply broken, privileges-wise, if they're not on 10.10?