{"id":378557,"date":"2017-11-29T06:15:32","date_gmt":"2017-11-29T06:15:32","guid":{"rendered":"http:\/\/citifmonline.com\/?p=378557"},"modified":"2017-11-29T05:23:06","modified_gmt":"2017-11-29T05:23:06","slug":"apple-rushes-fix-password-bug","status":"publish","type":"post","link":"https:\/\/citifmonline.com\/?p=378557","title":{"rendered":"Apple rushes to fix password bug"},"content":{"rendered":"<p class=\"story-body__introduction\">Apple has said it is working to fix a serious bug within its Mac operating system.<\/p>\n<p>The flaw in MacOS High Sierra &#8211; the most recent version &#8211; makes it possible to gain entry to the machine without a password, and also have access to powerful administrator rights.<\/p>\n<p>\u201cWe are working on a software update to address this issue,\u201d Apple said in a statement.<\/p>\n<p>The bug was discovered by Turkish developer Lemi Ergin.<\/p>\n<p>He found that by entering the username &#8220;root&#8221;, leaving the password field blank, and hitting &#8220;enter&#8221; a few times, he would be granted unrestricted access to the target machine.<\/p>\n<p>Mr Ergin faced criticism for apparently not following responsible disclosure guidelines typically observed by security professionals.<\/p>\n<p>Those guidelines instruct security experts to notify companies of flaws in their products, giving them a reasonable amount of time to fix the flaw before going public.<\/p>\n<p>Mr Ergin did not respond to those claims when asked on Twitter, and the BBC was unable to reach him on Tuesday.<\/p>\n<p>Apple would not confirm or deny whether it knew about the flaw beforehand.<\/p>\n<p><strong>The exploit<\/strong><\/p>\n<p>Considering the power it gives, the bug is remarkably simple, described by security experts as a &#8220;howler&#8221; and &#8220;embarrassing&#8221;.<\/p>\n<p>Those with root access can do more than a normal user, such as read and write the files of other accounts on the same machine. A superuser could also delete crucial system files, rendering the computer useless &#8211; or install malware that typical security software would find hard to detect.<\/p>\n<p>Thankfully, the bug cannot be exploited remotely, meaning an attacker would have to have physical access to a computer. That said, someone who gained remote access through other means would be able to use the flaw to control the machine it had access to.<\/p>\n<p>The timing of the disclosure presents a major issue to Apple as it now must hurriedly put in place a fix before the vulnerability can be exploited by criminals.<\/p>\n<p>&#8220;Haste and security don\u2019t make good bedfellows,\u201d said Prof Alan Woodward from the University of Surrey.<\/p>\n<p>&#8220;They will need to be careful the patch doesn\u2019t introduce some other problem as they\u2019ve not had time to properly test it.&#8221;<\/p>\n<p><strong>Temporary workaround<\/strong><\/p>\n<p>While Apple works on its fix, it offered a workaround for users concerned about the bug.<\/p>\n<p>\u201cSetting a root password prevents unauthorized access to your Mac,\u201d the company explained.<\/p>\n<p>&#8220;To enable the Root User and set a password, please follow the instructions here:\u00a0https:\/\/support.apple.com\/en-us\/HT204012.<\/p>\n<p>&#8220;If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the \u2018Change the root password\u2019 section.\u201d<\/p>\n<p>Fuller instructions on how to set the root password were\u00a0written up by MacRumors.<\/p>\n<p>For those not confident enough to change system settings like this, security experts advise simply &#8211; don&#8217;t let your Mac out of your sight, and be sure to apply the system update when prompted.<\/p>\n<p>&#8211;<\/p>\n<p>Source: BBC<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple has said it is working to fix a serious bug within its Mac operating system. The flaw in MacOS High Sierra &#8211; the most recent version &#8211; makes it possible to gain entry to the machine without a password, and also have access to powerful administrator rights. \u201cWe are working on a software update [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":378559,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jnews-multi-image_gallery":[],"jnews_single_post":[],"jnews_primary_category":[],"jnews_social_meta":[],"jnews_override_counter":[],"footnotes":""},"categories":[106],"tags":[224,3,15034],"class_list":["post-378557","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-apple","tag-ghana-news","tag-password-bug"],"_links":{"self":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts\/378557","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=378557"}],"version-history":[{"count":0,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts\/378557\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/media\/378559"}],"wp:attachment":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=378557"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=378557"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=378557"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}