Yesterday, the world of digital technology was rocked by the revelation that Apple’s Mac Operating System (High Sierra) had a bug. A bad bug. In fact, if you have a moment, it was a bug so bad and so big that it made the black plague and the Spanish Influenza look like a runny nose.
A developer in Turkey found that by entering the username ‘root’ and leaving the password blank, if you hit the login button often enough, you’d eventually log in. As a root user.
Dear @AppleSupport, we noticed a *HUGE* security issue at MacOS High Sierra. Anyone can login as “root” with empty password after clicking on login button several times. Are you aware of it @Apple?
— Lemi Orhan Ergin (@lemiorhan) November 28, 2017
If you’d like an analogy, that’s not just like leaving your keys in the door, but including a detailed room-by-room guide to your valuables stapled to them, a red carpet leading up to the door and a personal note welcoming your burglars and reassuring them you’re out of the country for another week.
It then became even more squirmingly embarrassing when it was discovered that the bug had been reported, on Apple’s own developer forum, as a workaround for someone unable to create an admin account. On November 13. Which means that a lot of people may well have known about this before Lemi brought it to Apple’s attention and that Apple clearly isn’t reading its developer forums.
If you can hear a high-pitched whine, it may be Steve Jobs hitting around 8,000 rpm.
When you have someone like Edward Snowden saying “This is really bad…” then you should assume things are really bad.
This is really bad, but will be fixed. Remember this bug next time the FBI & DOJ ask for “reasonable” encryption. This is what that world looks like every day. https://t.co/XK9qQDJubI
— Edward Snowden (@Snowden) November 28, 2017
Apple sprang into action and outlined a workaround, which would allow people to disable the root user and change the password.
The company has now issued a security update for MacOS (2017-001) which fixes the flaw.
If you’re on a Mac, or own a Mac, you should stop reading this NOW and go open the App Store and install the update. Go on. We’ll wait… (we did it 10 minutes ago).
It has been a no doubt anxious couple of days for the tech giant. Who have moved reassuringly quickly to address the vulnerability. However, it shows that even the world’s largest tech companies can find flaws and bugs which compromise even the most secure systems, devices and products.
The lessons here are
- update your software regularly (switch on your automatic updates if you’re busy)
- pay attention to security news (not every device will automatically update)
- read DIGIT (how else will you know what’s going on?)
Now go and patch your Mac.





