{"id":378557,"date":"2017-11-29T06:15:32","date_gmt":"2017-11-29T06:15:32","guid":{"rendered":"http:\/\/citifmonline.com\/?p=378557"},"modified":"2017-11-29T05:23:06","modified_gmt":"2017-11-29T05:23:06","slug":"apple-rushes-fix-password-bug","status":"publish","type":"post","link":"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/","title":{"rendered":"Apple rushes to fix password bug"},"content":{"rendered":"

Apple has said it is working to fix a serious bug within its Mac operating system.<\/p>\n

The flaw in MacOS High Sierra – the most recent version – makes it possible to gain entry to the machine without a password, and also have access to powerful administrator rights.<\/p>\n

\u201cWe are working on a software update to address this issue,\u201d Apple said in a statement.<\/p>\n

The bug was discovered by Turkish developer Lemi Ergin.<\/p>\n

He found that by entering the username “root”, leaving the password field blank, and hitting “enter” a few times, he would be granted unrestricted access to the target machine.<\/p>\n

Mr Ergin faced criticism for apparently not following responsible disclosure guidelines typically observed by security professionals.<\/p>\n

Those guidelines instruct security experts to notify companies of flaws in their products, giving them a reasonable amount of time to fix the flaw before going public.<\/p>\n

Mr Ergin did not respond to those claims when asked on Twitter, and the BBC was unable to reach him on Tuesday.<\/p>\n

Apple would not confirm or deny whether it knew about the flaw beforehand.<\/p>\n

The exploit<\/strong><\/p>\n

Considering the power it gives, the bug is remarkably simple, described by security experts as a “howler” and “embarrassing”.<\/p>\n

Those with root access can do more than a normal user, such as read and write the files of other accounts on the same machine. A superuser could also delete crucial system files, rendering the computer useless – or install malware that typical security software would find hard to detect.<\/p>\n

Thankfully, the bug cannot be exploited remotely, meaning an attacker would have to have physical access to a computer. That said, someone who gained remote access through other means would be able to use the flaw to control the machine it had access to.<\/p>\n

The timing of the disclosure presents a major issue to Apple as it now must hurriedly put in place a fix before the vulnerability can be exploited by criminals.<\/p>\n

“Haste and security don\u2019t make good bedfellows,\u201d said Prof Alan Woodward from the University of Surrey.<\/p>\n

“They will need to be careful the patch doesn\u2019t introduce some other problem as they\u2019ve not had time to properly test it.”<\/p>\n

Temporary workaround<\/strong><\/p>\n

While Apple works on its fix, it offered a workaround for users concerned about the bug.<\/p>\n

\u201cSetting a root password prevents unauthorized access to your Mac,\u201d the company explained.<\/p>\n

“To enable the Root User and set a password, please follow the instructions here:\u00a0https:\/\/support.apple.com\/en-us\/HT204012.<\/p>\n

“If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the \u2018Change the root password\u2019 section.\u201d<\/p>\n

Fuller instructions on how to set the root password were\u00a0written up by MacRumors.<\/p>\n

For those not confident enough to change system settings like this, security experts advise simply – don’t let your Mac out of your sight, and be sure to apply the system update when prompted.<\/p>\n

–<\/p>\n

Source: BBC<\/p>\n","protected":false},"excerpt":{"rendered":"

Apple has said it is working to fix a serious bug within its Mac operating system. The flaw in MacOS High Sierra – the most recent version – makes it possible to gain entry to the machine without a password, and also have access to powerful administrator rights. \u201cWe are working on a software update […]<\/p>\n","protected":false},"author":14,"featured_media":378559,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[106],"tags":[224,3,15034],"yoast_head":"\nApple rushes to fix password bug - Citi 97.3 FM - Relevant Radio. Always<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apple rushes to fix password bug - Citi 97.3 FM - Relevant Radio. Always\" \/>\n<meta property=\"og:description\" content=\"Apple has said it is working to fix a serious bug within its Mac operating system. The flaw in MacOS High Sierra – the most recent version – makes it possible to gain entry to the machine without a password, and also have access to powerful administrator rights. \u201cWe are working on a software update […]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/\" \/>\n<meta property=\"og:site_name\" content=\"Citi 97.3 FM - Relevant Radio. Always\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/citi97.3\" \/>\n<meta property=\"article:published_time\" content=\"2017-11-29T06:15:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2017-11-29T05:23:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/citifmonline.com\/wp-content\/uploads\/2017\/11\/Apple.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"320\" \/>\n\t<meta property=\"og:image:height\" content=\"180\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Kojo Akoto Boateng\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@citi973\" \/>\n<meta name=\"twitter:site\" content=\"@citi973\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kojo Akoto Boateng\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/\",\"url\":\"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/\",\"name\":\"Apple rushes to fix password bug - Citi 97.3 FM - Relevant Radio. Always\",\"isPartOf\":{\"@id\":\"https:\/\/citifmonline.com\/#website\"},\"datePublished\":\"2017-11-29T06:15:32+00:00\",\"dateModified\":\"2017-11-29T05:23:06+00:00\",\"author\":{\"@id\":\"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1\"},\"breadcrumb\":{\"@id\":\"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/citifmonline.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apple rushes to fix password bug\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/citifmonline.com\/#website\",\"url\":\"https:\/\/citifmonline.com\/\",\"name\":\"Citi 97.3 FM - Relevant Radio. Always\",\"description\":\"Ghana News | Ghana Politics | Ghana Soccer | Ghana Showbiz\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/citifmonline.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1\",\"name\":\"Kojo Akoto Boateng\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/citifmonline.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g\",\"caption\":\"Kojo Akoto Boateng\"},\"url\":\"https:\/\/citifmonline.com\/author\/kojo\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apple rushes to fix password bug - Citi 97.3 FM - Relevant Radio. Always","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/","og_locale":"en_US","og_type":"article","og_title":"Apple rushes to fix password bug - Citi 97.3 FM - Relevant Radio. Always","og_description":"Apple has said it is working to fix a serious bug within its Mac operating system. The flaw in MacOS High Sierra – the most recent version – makes it possible to gain entry to the machine without a password, and also have access to powerful administrator rights. \u201cWe are working on a software update […]","og_url":"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/","og_site_name":"Citi 97.3 FM - Relevant Radio. Always","article_publisher":"https:\/\/www.facebook.com\/citi97.3","article_published_time":"2017-11-29T06:15:32+00:00","article_modified_time":"2017-11-29T05:23:06+00:00","og_image":[{"width":320,"height":180,"url":"https:\/\/citifmonline.com\/wp-content\/uploads\/2017\/11\/Apple.jpg","type":"image\/jpeg"}],"author":"Kojo Akoto Boateng","twitter_card":"summary_large_image","twitter_creator":"@citi973","twitter_site":"@citi973","twitter_misc":{"Written by":"Kojo Akoto Boateng","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/","url":"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/","name":"Apple rushes to fix password bug - Citi 97.3 FM - Relevant Radio. Always","isPartOf":{"@id":"https:\/\/citifmonline.com\/#website"},"datePublished":"2017-11-29T06:15:32+00:00","dateModified":"2017-11-29T05:23:06+00:00","author":{"@id":"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1"},"breadcrumb":{"@id":"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/citifmonline.com\/2017\/11\/apple-rushes-fix-password-bug\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/citifmonline.com\/"},{"@type":"ListItem","position":2,"name":"Apple rushes to fix password bug"}]},{"@type":"WebSite","@id":"https:\/\/citifmonline.com\/#website","url":"https:\/\/citifmonline.com\/","name":"Citi 97.3 FM - Relevant Radio. Always","description":"Ghana News | Ghana Politics | Ghana Soccer | Ghana Showbiz","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/citifmonline.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1","name":"Kojo Akoto Boateng","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/citifmonline.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g","caption":"Kojo Akoto Boateng"},"url":"https:\/\/citifmonline.com\/author\/kojo\/"}]}},"_links":{"self":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/posts\/378557"}],"collection":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/comments?post=378557"}],"version-history":[{"count":0,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/posts\/378557\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/media\/378559"}],"wp:attachment":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/media?parent=378557"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/categories?post=378557"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/tags?post=378557"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}