Unreasonable Limit on Open Firmware Passwords
Lawrence Person writes "Well, this has to be one of the stranger bugs in recent memory: 'If you used Open Firmware Password utility to create a password that contains the capital letter "U", your password will not be recognized during the startup process.' Straight from the mothership. I'm guessing that not too many people use Open Firmware Passwords, but it's a very nasty bug for those who do. Props to the always great As The Apple Turns for pointing this one out."
I saw this too. Anyone care to take a stab at why this might possibly be? Something to do with the bytecode of that particular letter?
--
$tar -xvf
UR70457
....
My trusty password "god" triumphs again!
I would expect such blatant racism on Fark, but on Slashdot? Mods please ban this asshole.
Hmm.. this explains why my STFU posts always disappear.
"Derp de derp."
It sounds like this isn't a bug in Open Firmware (thankfully), but Apple's OF Password app. If so, we just need to wait for an update to the app, and can still set passwords with "U" manually.
Does anyone have more info regarding where this bug originates?
Mikey-San
Karma: +Eleventy billion (mostly affected by watching Celebrity Jeopardy)
Among other things, it:
blocks the ability to use the "C" key to start up from a CD-ROM disc.
blocks the ability to use the "N" key to start up from a NetBoot server.
blocks the ability to use the "T" key to start up in Target Disk Mode (on computers that offer this feature).
Posting this anonymously, since I don't want to be known as the one who figured this out.
Do you need your password to be accepted in order to change the password?
The "solution" in the article is to "change your password if necessary". But how do you change your password when your previous password is not accepted?
What's your GCNSEQNO?
I pity the fool who has a wife or daughter named Ursila. :-(
That may be Praetorian code. I wouldn't mess with it.
They're the ones that want to claim copyright on that letter, so that talking about *nix requires paying a licensing fee.
It also means we can't call them a b*nch of motherf*cking f*ckwits, which is a real shame.
--
Don't like it? Respond with words, not karma.
No, wait. This is Apple, not Microsoft. Bugs like this are acknowledged, with workarounds and/or patches supplied quickly, and this gives the company character and credibility.
to just reset the password. Easily accomplished.
-You may license this sig for only $6.99.
Microsofy story of the day - yet another hole that will get you owned that we're disclosing and patching after years of vulnerability.
Apple story of the day - bug disallows a certain character in little used Openfirmware password.
Slashdot spin - both platforms have bugs. Fair and Balanced - Slashdot News!
=tkk
Bill Gates - Creationist?!?
Yeah, a bug in a feature that hardly anybody uses and affects only the local machine is a REAL SHOW-STOPPER.
I better call my mom and tell her to PATCH THAT IMAC ASAP OR THE BLASTER WORM IS GOING TO READ ALL HER APPLE PIE RECIPES!
I'm selling my powerbook RIGHT NOW and getting TEH SW33333T W1ND0WS L4PT()P! WINDOWS IS THE MOST SECURE OS ON TEH PL4NET U CAN USE ANY LETTER IN TEH APHLABLET IN YOU PASSWROD!!#####~!! MY PASSWROD = UUUUUUUU Take that M4C F4|\|B()YZ!
I'm with him, this is cute and my machine does have character, don't you boy couchycouchycooooo!
Damn shame can't use my pitchfork on this though, just subscribed and got my whole \. set: tin foil hat, pitchfork, a gazzilion distro's and the SCO phone numbers...
I think, therefore I am...I think.
This is clear evidence that despite its user-friendly appearance, deep down, Apple hates U.
Ceci n'est pas un post.
"ready PITCHFORKS!"
I hate when satirical expressions on typical slashdotian responses is modded as troll. Lighten up!
"Derp de derp."
I think you need to lighten up about troll mods.
"I think you need to lighten up about troll mods. "
Unfortunately these troll mods deter people from making creative humorous comments. You're supposed to according to the FAQ.
Chalk up another offtopic for me. Never mind that moderation is very much a part of any topic.
*annoyed*
"Derp de derp."
The article number for this was 107666. If that's not clear proof that Microsoft was somehow involved, I don't know what is.
Um, I need something for the 107 part...
Waiting to see if this gets modded flamebait or funny... ;-)
Are you some kind of fucking idiot savant?
That was classic intercourse!
You don't need to bother. Being based on FreeBSD, OS X comes with its own pitchforks.
I am TheRaven on Soylent News
See, why does everything always have to be about U?
huh?
Stupid geeks!
Somehow I suspect unicode support has something to do with this bug.
grisha.org
Maybe control-U is meant to kill the input, but they used shift-U instead?
Since UNIX begins with U, all rights to this letter belong to SCO. Soon all your NIX will belong to them as well, and watch out you basketball team!
does "cute" also include the 8 character password limit throughout the rest of os X? because i don't see being unable to use the letter U on boot is nearly so much of a problem as os X only recognizing the first 8 characters of any given password, and neither of them actually are "cute". though, i still love os x the mostest!!!
I wonder if this problem exists in my Open Firmware based Pegasos machine.
Karma Whoring for Fun and Profit.
I think this is a problem with the Open Firmware Password application using a different character set than Open Firmware itself. So some characters you can type in the OF Password app you can't type in OF itself. Or maybe OF just doesn't like the shift key...
"Belief means not wanting to know what is true." [Nietzche, The Anti-Christ, 1889]
The value $AA is used to "encrypt" the password in OF. Every letter in the password is obfusticated via XOR with this value.
'U' = $55 XOR $AA = $FF (and this is probably used as a end-of-password marker).
Asskisser.
Ouch... this is a naaaasty little bug.
"Things are more moderner than before- bigger, and yet smaller- it's computers-- San Dimas High School football RULES!"
Just to be safe, I suggest changing the story title.
This is mainly in the UNIX portions of X. Apps which use the proper GUI password input (which is the Authorization API in Security.framework) check the entire password.
Regardless of whether it contains a 'U'.
If I'd heard about this a few weeks back, I'd be so ready with the ol' Nelson "HA-HA!".
Unfortunately, I found a real old bug in our app on some UNIX boxes. It turns out that our implemention of getpass() was eating the letter "c" on some platforms.
So, the appropriate Simpson's reference is now:
-- clvrmnky