The Root Bug Patch Broke My File Sharing

The Root Bug Patch Broke My File Sharing

Tutorials apple bugs macos security

So by now you've almost certainly heard about the macOS root bug. It broke out on Twitter Tuesday when a developer in Istanbul, fed up with getting nowhere through normal channels, just tweeted straight at Apple Support asking why anyone could log into a Mac as root with an empty password field. Type "root," hit enter a couple times, and you're in. No password needed. On a laptop. In 2017.

I'm not going to spend 900 words re-explaining the bug itself, everybody and their cousin has already written that post this week and by the time this goes up you'll have read it three times over. What I want to talk about is what happened after Apple patched it, because that part got a lot less coverage and it's the part that actually ate my Wednesday night.

Apple moved fast, credit where it's due. The bug went public Tuesday morning and by Tuesday evening there was already a security update out, which for a company that sometimes takes weeks to fix stuff is genuinely impressive turnaround. I installed it the second I saw the notification, because obviously, a blank-password root exploit is not something you sit on.

Except then my file sharing stopped working.

I didn't notice right away. I went to grab a folder off my Mac from my wife's laptop the next morning like I do most days, and the share just wasn't there anymore. Spent a good twenty minutes assuming it was a wifi thing, restarted the router, restarted both machines, the usual troubleshooting theater you do before you admit something is actually broken. Eventually I found a thread (bless the people who post in Apple's support forums within hours of something breaking) explaining that the security patch, if you installed it on top of an already-updated 10.13.1 system, could silently disable SMB file sharing for some users. Not everyone. Just enough people to make you feel crazy Googling it at 11pm.

The actual fix, for anyone who lands here with the same problem: open System Preferences, go to Sharing, and just toggle File Sharing off and back on. For most people that kicks the service into re-registering itself properly and it comes back. If that doesn't do it, there's a more involved fix that has you reinstalling the combo update from Apple's support site directly rather than through the App Store updater, which apparently applies more cleanly. I didn't have to go that far, the toggle trick worked for me on the second try.

What actually bugs me about all this isn't the original vulnerability. Software has bugs, embarrassing ones happen, whatever. What gets me is that the guy who found this, an app developer named Lemi Orhan Ergin, says he'd already reported it to Apple through their normal channels before going public, and by his account nothing happened until he made noise on Twitter. I don't know the internal timeline at Apple and I'm not going to pretend I do. But if that's roughly accurate, it's a pretty bad look for a company that runs an entire bug bounty apparatus for iOS and, as of earlier this year, extended some of that program to macOS too. Root access with no password is about as severe as a bug gets on a desktop OS. That shouldn't need a viral tweet to get triaged.

Anyway. If you're running High Sierra and you haven't installed Security Update 2017-001 yet, stop reading and go do that first, this post will still be here. Then check your file sharing, check any AFP or SMB shares you've got set up for backups or home servers, and don't just assume everything came through fine. A few practical habits worth picking up out of this whole mess while you're at it:

  • Turn on FileVault if you haven't already (Security & Privacy > FileVault). It doesn't stop this particular bug but it's just good hygiene and takes five minutes.
  • If you've got a Mac that's ever unattended in a shared space, physical access plus a blank root password is about as bad a combination as exists. Worth thinking about even after the patch, since patches sometimes get walked back or reintroduced in later updates (it's happened before).
  • Keep an eye on release notes for the next update too. Fast patches written under pressure are exactly the kind that introduce this sort of side effect, and I'd bet money this isn't the last file-sharing hiccup from this particular fix.

I've been doing this blog long enough now (six years next month, which is a genuinely strange thing to type) that I've watched this exact pattern play out with Apple more than once. Big scary bug, fast patch, smaller annoying bug hiding inside the fast patch. Never gets old.