{"id":72952,"date":"2017-11-28T14:07:02","date_gmt":"2017-11-28T22:07:02","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=72952"},"modified":"2017-11-30T12:07:30","modified_gmt":"2017-11-30T20:07:30","slug":"major-authentication-security-flaw-reported-in-macos-high-sierra","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/","title":{"rendered":"Major Authentication Security Flaw Reported in macOS High Sierra [Update]"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-70381\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/Prepare-macOS-High-Sierra.png\" alt=\"macOS High Sierra Security Vulnerability\" width=\"600\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/Prepare-macOS-High-Sierra.png 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/Prepare-macOS-High-Sierra-150x75.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/Prepare-macOS-High-Sierra-300x150.png 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>Today, software developer Lemi Orhan Ergin <a href=\"https:\/\/twitter.com\/lemiorhan\/status\/935578694541770752\" target=\"_blank\" rel=\"noopener\">posted a tweet<\/a> directed at Apple Support, outlining the discovery of a major security flaw in macOS High Sierra. It appears this flaw was not properly disclosed to Apple, so as of right now there is no fix and the latest beta versions appear to be affected as well, though reports on this are mixed. Typically we\u00a0would\u00a0wait to report on this until a fix is underway, but as this news is spreading fast, we thought it would be better to offer a temporary fox for this flaw instead.<\/p>\n<h3>What&#8217;s the flaw?<\/h3>\n<p>macOS 10.13 High Sierra users who\u00a0leave their Mac unlocked can have anyone with physical access take complete control. Typically any important settings are locked and require an administrator name and password to access.<\/p>\n<p><img loading=\"lazy\" class=\"size-full wp-image-72964 aligncenter\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/1-login.png\" alt=\"\" width=\"444\" height=\"215\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/1-login.png 444w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/1-login-150x73.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/1-login-300x145.png 300w\" sizes=\"(max-width: 444px) 100vw, 444px\" \/><\/p>\n<p>The problem is that this authentication process is broken. Anyone can use the username &#8220;root&#8221; with a blank password and hit return or click the Unlock button. The first time macOS will not allow it, but hitting return or clicking the button again will enable the root user and let anyone log in!<\/p>\n<p><img loading=\"lazy\" class=\"size-full wp-image-72970 aligncenter\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/2-login-root.png\" alt=\"\" width=\"444\" height=\"215\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/2-login-root.png 444w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/2-login-root-150x73.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/2-login-root-300x145.png 300w\" sizes=\"(max-width: 444px) 100vw, 444px\" \/><\/p>\n<p>This trick appears to work on any System Preferences pane that is locked as well as other places in macOS that require authentication to access. To make matters worse, once the root user is enabled, someone can log you out or restart your machine, and then log in to the macOS as root user, having complete control over all your data.<\/p>\n<h3>What can I do to prevent this from happening?<\/h3>\n<p>First and foremost, access to your Mac has to be locked down the second you walk away from your Mac. This can be done with a screensaver password, by logging out, shutting down or locking your screen with the new High Sierra menu option (Apple menu &gt; Lock Screen). Not giving anyone the chance to exploit this flaw is the best way to prevent it at the moment. It is currently not known if this flaw is exploited in the wild, but malware could very easily implement exploits.<\/p>\n<p>The best way to protect yourself from this flaw, apart from the above mentioned suggestions, is to enable the root user on your Mac and set a strong, unique password. If the root user is already enabled, this flaw doesn&#8217;t work. The root user should never be enabled if you don&#8217;t need it, but this is a valid scenario in which said advice can be ignored.<\/p>\n<p>To enable the root user on your Mac, do the following:<\/p>\n<ol>\n<li>Open the Directory Utility application. Use spotlight or find it in <strong>System<\/strong> &gt; <strong>Library<\/strong> &gt; <strong>CoreServices<\/strong> &gt; <strong>Applications<\/strong>.<\/li>\n<li>Click the lock and authenticate with your credentials.<br \/>\n<img loading=\"lazy\" class=\"alignnone size-full wp-image-72976\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/3-DirectoryUtility.png\" alt=\"\" width=\"590\" height=\"443\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/3-DirectoryUtility.png 590w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/3-DirectoryUtility-150x113.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/3-DirectoryUtility-300x225.png 300w\" sizes=\"(max-width: 590px) 100vw, 590px\" \/><\/li>\n<li>Once authenticated, from the Edit menu, select &#8220;Enable Root User&#8221;<br \/>\n<img loading=\"lazy\" class=\"alignnone size-full wp-image-72982\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/4-EmableRoot.png\" alt=\"\" width=\"590\" height=\"466\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/4-EmableRoot.png 590w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/4-EmableRoot-150x118.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/4-EmableRoot-300x237.png 300w\" sizes=\"(max-width: 590px) 100vw, 590px\" \/><\/li>\n<li>Pick a <strong>strong<\/strong> and <strong>unique<\/strong> password!<br \/>\n<img loading=\"lazy\" class=\"alignnone size-full wp-image-72988\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/5-StrongUniquePassword.png\" alt=\"\" width=\"346\" height=\"175\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/5-StrongUniquePassword.png 346w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/5-StrongUniquePassword-150x76.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/11\/5-StrongUniquePassword-300x152.png 300w\" sizes=\"(max-width: 346px) 100vw, 346px\" \/><br \/>\nClick OK when the password has been set and lock the Directory Utility before quitting it.<\/li>\n<\/ol>\n<h3>Am I all set now?<\/h3>\n<p>Not quite. Enabling the root user, even with a strong and unique password should not be done unless it&#8217;s needed (which is virtually never for the vast majority of users). As soon as Apple releases a fix for this flaw, the root user should be disabled again through Directory Utility. Keep a close eye on software updates and read their descriptions to see if this flaw was one of the addressed issues. Of course, we at The Mac Security Blog will let you know as well when this flaw has been patched.<\/p>\n<p>If you are not comfortable enabling the root user (superuser) account on your Mac, make sure it is locked down tight, so no one can even attempt to exploit this flaw. It&#8217;s also important to note that\u00a0this flaw is present only on macOS High Sierra 10.13 and 10.13.1.<\/p>\n<p><strong>Editor&#8217;s Update:<\/strong> On November 29, Apple released Security Update 2017-001 for macOS High Sierra 10.13.1 to address the security flaw discussed in this post.<\/p>\n<p>Apple&#8217;s security team\u00a0<a href=\"https:\/\/support.apple.com\/en-us\/HT208315\" target=\"_blank\">said<\/a>\u00a0the following about this update:<\/p>\n<blockquote><p>An attacker may be able to bypass administrator authentication without supplying to administrator&#8217;s password. [&#8230;] A logic error existed in the validation of credentials. This was addressed with improved credential validation.<\/p><\/blockquote>\n<p>macOS High Sierra users can <a href=\"https:\/\/support.apple.com\/kb\/DL1942?viewlocale=en_US&amp;locale=en_US\" target=\"_blank\">download Security Update 2017-001<\/a> by visiting Apple&#8217;s support download page.\u00a0<del>When you install Security Update 2017-001 on your Mac, the build number of macOS will be 17B1002.<\/del><\/p>\n<p><strong>November 30 Update:<\/strong>\u00a0Apple has released steps Mac users can take to verify that your computer has Security Update 2017-001. To confirm that your Mac has Security Update 2017-001, follow these steps:<\/p>\n<ol>\n<li>Open the Terminal app, which is in the Utilities folder of your Applications folder.<\/li>\n<li>Type the following command and press Return:\n<pre> what \/usr\/libexec\/opendirectoryd<\/pre>\n<\/li>\n<li>If Security Update 2017-001 was installed successfully, you will see one of these project version numbers:<br \/>\nopendirectoryd-483.1.5 on macOS High Sierra 10.13<br \/>\nopendirectoryd-483.20.7 on macOS High Sierra 10.13.1<\/li>\n<\/ol>\n<p>As Apple mentioned, if you require the root user account on your Mac, you will need to <a href=\"https:\/\/support.apple.com\/en-us\/HT204012\" target=\"_blank\">re-enable the root user and change the root user&#8217;s password<\/a> after this update.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today, software developer Lemi Orhan Ergin posted a tweet directed at Apple Support, outlining the discovery of a major security flaw in macOS High Sierra. It appears this flaw was not properly disclosed to Apple, so as of right now there is no fix and the latest beta versions appear to be affected as well, [&hellip;]<\/p>\n","protected":false},"author":79,"featured_media":70387,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[5],"tags":[3793,3175,3652,3385,144],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Today, software developer Lemi Orhan Ergin posted a tweet directed at Apple Support, outlining the discovery of a major security flaw in macOS High\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Major Authentication Security Flaw Reported in macOS High Sierra [Update] - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Today, software developer Lemi Orhan Ergin posted a tweet directed at Apple Support, outlining the discovery of a major security flaw in macOS High\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2017-11-28T22:07:02+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2017-11-30T20:07:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/macOS-High-Sierra-FAQ.png\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jay Vrijenhoek\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/macOS-High-Sierra-FAQ.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/macOS-High-Sierra-FAQ.png\",\"width\":400,\"height\":260,\"caption\":\"macOS High Sierra\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/\",\"name\":\"Major Authentication Security Flaw Reported in macOS High Sierra [Update] - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#primaryimage\"},\"datePublished\":\"2017-11-28T22:07:02+00:00\",\"dateModified\":\"2017-11-30T20:07:30+00:00\",\"description\":\"Today, software developer Lemi Orhan Ergin posted a tweet directed at Apple Support, outlining the discovery of a major security flaw in macOS High\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Major Authentication Security Flaw Reported in macOS High Sierra [Update]\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/0106660ab83668e429deecc051dfa8c0\"},\"headline\":\"Major Authentication Security Flaw Reported in macOS High Sierra [Update]\",\"datePublished\":\"2017-11-28T22:07:02+00:00\",\"dateModified\":\"2017-11-30T20:07:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#webpage\"},\"wordCount\":833,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/macOS-High-Sierra-FAQ.png\",\"keywords\":[\"Authentication\",\"macOS\",\"macOS High Sierra\",\"Security Update 2017-001\",\"Vulnerability\"],\"articleSection\":[\"Security News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/0106660ab83668e429deecc051dfa8c0\",\"name\":\"Jay Vrijenhoek\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8f43effd03d0bb31acff4b88613f0d4a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8f43effd03d0bb31acff4b88613f0d4a?s=96&d=mm&r=g\",\"caption\":\"Jay Vrijenhoek\"},\"description\":\"Jay Vrijenhoek is an IT consultant with a passion for Mac security research.\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/jay-vrijenhoek\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Today, software developer Lemi Orhan Ergin posted a tweet directed at Apple Support, outlining the discovery of a major security flaw in macOS High","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/","og_locale":"en_US","og_type":"article","og_title":"Major Authentication Security Flaw Reported in macOS High Sierra [Update] - The Mac Security Blog","og_description":"Today, software developer Lemi Orhan Ergin posted a tweet directed at Apple Support, outlining the discovery of a major security flaw in macOS High","og_url":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/","og_site_name":"The Mac Security Blog","article_published_time":"2017-11-28T22:07:02+00:00","article_modified_time":"2017-11-30T20:07:30+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/macOS-High-Sierra-FAQ.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jay Vrijenhoek","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/macOS-High-Sierra-FAQ.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/macOS-High-Sierra-FAQ.png","width":400,"height":260,"caption":"macOS High Sierra"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/","name":"Major Authentication Security Flaw Reported in macOS High Sierra [Update] - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#primaryimage"},"datePublished":"2017-11-28T22:07:02+00:00","dateModified":"2017-11-30T20:07:30+00:00","description":"Today, software developer Lemi Orhan Ergin posted a tweet directed at Apple Support, outlining the discovery of a major security flaw in macOS High","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Major Authentication Security Flaw Reported in macOS High Sierra [Update]"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/0106660ab83668e429deecc051dfa8c0"},"headline":"Major Authentication Security Flaw Reported in macOS High Sierra [Update]","datePublished":"2017-11-28T22:07:02+00:00","dateModified":"2017-11-30T20:07:30+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#webpage"},"wordCount":833,"commentCount":1,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/macOS-High-Sierra-FAQ.png","keywords":["Authentication","macOS","macOS High Sierra","Security Update 2017-001","Vulnerability"],"articleSection":["Security News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/major-authentication-security-flaw-reported-in-macos-high-sierra\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/0106660ab83668e429deecc051dfa8c0","name":"Jay Vrijenhoek","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/8f43effd03d0bb31acff4b88613f0d4a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8f43effd03d0bb31acff4b88613f0d4a?s=96&d=mm&r=g","caption":"Jay Vrijenhoek"},"description":"Jay Vrijenhoek is an IT consultant with a passion for Mac security research.","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/jay-vrijenhoek\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/09\/macOS-High-Sierra-FAQ.png","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-iYE","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/72952"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/79"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=72952"}],"version-history":[{"count":15,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/72952\/revisions"}],"predecessor-version":[{"id":73051,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/72952\/revisions\/73051"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/70387"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=72952"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=72952"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=72952"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}