Reply to post: Re: Mistakes happen

As Apple fixes macOS root password hole, here's what went wrong

Dan 55 Silver badge

Re: Mistakes happen

Twice is enough.

The first time sets the root password to whatever's in the password box due to the logic fail meaning that a password entry for root is created in the new encryption format (really what this bit of code should be doing is updating a correct password stored in the old encryption format to the new encryption format).

The second time gets you access as the root password entry now exists in the new encryption format and the password in the box was correct.

Entering the same password twice for root is enough to do it. A blank password is easiest.

Apple needs more code review and QA and less shiny and marketing need to back off and realise their yearly fixed deadline means more mistakes like this get through.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon