10.5: Careful with the "Guest" account - ehMac.ca
Facebook
Twitter
YouTube
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read


Reply
 
LinkBack Thread Tools Display Modes
Old Nov 25th, 2007, 06:25 PM   #1
Full Citizen
 
Join Date: Dec 2005
Location: londonon
Posts: 376
10.5: Careful with the "Guest" account

I haven't been able to reproduce it myself, but it seems a malfunction with the "Guest" account has cost a few people their "home" folders:

Apple - Support - Discussions - Everything Erased in my account!!!(i ...
Apple - Support - Discussions - main user account ERASED as mistaken ...
Apple - Support - Discussions - Big problem - all files lost due to ...

Just a heads-up in case you were thinking of trying out this new v. x.0 feature.
biovizier is offline   Reply With Quote
Sponsored Links
Advertisement
 
Old Nov 25th, 2007, 07:54 PM   #2
Honourable Citizen
 
NBiBooker's Avatar
 
Join Date: Apr 2004
Location: Moncton, New Brunswick
Posts: 1,473
Don't these people use Time Machine?
__________________
My gear: White MacBook 1.83, 2 Gigs of Ram, Combo Drive, OS 10.5, iPod Video 30 Gig, Canon Digital Rebel XT. iPhone 3G 8 Gig.
NBiBooker is offline   Reply With Quote
Old Nov 25th, 2007, 11:56 PM   #3
Full Citizen
 
spoonie's Avatar
 
Join Date: Nov 2007
Location: Beaches
Posts: 212
is this a potential hazard if you don't have a guest account activated?
__________________
2012 MBP, 16GB, 512SSD
2009 Mac Pro, 64GB, JBOD, upgraded to x5570 x2.
spoonie is offline   Reply With Quote
Old Nov 26th, 2007, 10:11 AM   #4
Full Citizen
 
Join Date: Dec 2005
Location: londonon
Posts: 376
It's hard to say at this point with just three reports and I wouldn't rule anything out, but it doesn't look like it would be a problem if "Guest" isn't enabled. In two of the threads at least, actually logging in to "Guest" at some point was involved before the bug's effects were seen.
biovizier is offline   Reply With Quote
Old Nov 26th, 2007, 11:38 AM   #5
mguertin
Guest
 
Posts: n/a
ouch, that's a nasty one. Thanks for the heads up.
  Reply With Quote
Old Nov 26th, 2007, 02:43 PM   #6
Honourable Citizen?
 
GratuitousApplesauce's Avatar
 
Join Date: Jan 2004
Location: Isle in the Salish Sea
Posts: 4,853
Yikes — yeah, thanks for the heads up as well.

I think I will immediately get rid of the guest account I set up. I didn't like the way it worked anyway, in that it reset to defaults. I had previously set up limited access guest accounts in Tiger and Panther and tweaked them to be the way I wanted them, with no access to Mail.app and a few other apps. That worked better than the Leopard guest account.
__________________
The price of apathy toward public affairs, is to be ruled by evil men. -- Plato.
GratuitousApplesauce is offline   Reply With Quote
Old Nov 26th, 2007, 03:37 PM   #7
Full Citizen
 
Join Date: Dec 2005
Location: londonon
Posts: 376
I still haven't been able to reproduce the problem (not that I've been trying all that hard). But I have been playing around with the "Guest" account, and it looks like the presence of a single "locked" file or folder anywhere in the "home" folder is enough to prevent anything from the "Guest" account from being deleted. Things might be different in the case of this glitch, but perhaps locking something in all of the non-Guest accounts would serve as insurance to prevent them from being deleted in place of the "Guest" home folder.

I'm really not sure how that works - eg. in "Finder", nothing prevents you from trashing a folder containing a locked file, and things like 'rm -r' will delete everything around the locked item so how does a single locked item protect the whole Guest home folder?

As a side note, if you are ever using someone else's Guest account and you don't want your stuff to be deleted when you log out, just lock something, I guess...

Quote:
I had previously set up limited access guest accounts in Tiger and Panther and tweaked them to be the way I wanted them
I'm inclined to agree. While it is possible to tweak the "Guest" account itself to some extent, a regular "managed" account seems more sensible. I guess "Guest" might come in handy if you suddenly are faced with having to let someone use your computer, but otherwise I don't see much use for it.
biovizier is offline   Reply With Quote
Old Nov 26th, 2007, 03:52 PM   #8
Honourable Citizen?
 
GratuitousApplesauce's Avatar
 
Join Date: Jan 2004
Location: Isle in the Salish Sea
Posts: 4,853
Quote:
Originally Posted by biovizier View Post
I'm inclined to agree. While it is possible to tweak the "Guest" account itself to some extent, a regular "managed" account seems more sensible. I guess "Guest" might come in handy if you suddenly are faced with having to let someone use your computer, but otherwise I don't see much use for it.
I used my previous managed Guest account for exactly the situation that the Leopard Guest account was designed for, when someone needed to use my computer but I didn't want them to have access to any of my accounts. I also didn't want them to be able to access Mail.app since I figured that a visitor who might want to check their email on my computer would be using web mail anyway, that's what I do when I use other's computers.

I guess I'll set up a managed Guest account in Leopard.
__________________
The price of apathy toward public affairs, is to be ruled by evil men. -- Plato.
GratuitousApplesauce is offline   Reply With Quote
Old Sep 15th, 2008, 05:35 PM   #9
Full Citizen
 
Join Date: Dec 2005
Location: londonon
Posts: 376
I don't know for sure if it's the same thing, but 10.5.5 might have addressed this issue and provide an explanation of what was happening:
Quote:
Originally Posted by http://support.apple.com/kb/HT3137
Login Window
CVE-ID: CVE-2008-3610
Available for: Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
Impact: A user may log in without providing a password
Description: A race condition exists in Login Window. To trigger this issue, the system must have the Guest account enabled or another account with no password. In a small proportion of attempts, an attempt to log in to such an account will not complete. The user list would then be presented again, and the person would be able to log in as any user without providing a password. If the original account were the Guest account, the contents of the new account will be deleted on logout. This update addresses the issue by properly clearing Login Window state when the login does not complete. This issue does not affect systems prior to Mac OS X v10.5.
biovizier is offline   Reply With Quote
Old Sep 17th, 2008, 11:18 PM   #10
Full Citizen
 
broken_g3's Avatar
 
Join Date: Jun 2008
Location: London, Ontario
Posts: 942
HOLY CRAP. I would be so scared if something like this happened to me. Imagine... all your user data wiped, no way to tell what went wrong...

How are they going to find the source of this critical design flaw? It's probably fragmented over several million lines of code.
broken_g3 is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
iTunes freezes on second account Garry Mac, iPhone, iPad and iPod Help & Troubleshooting 0 Mar 29th, 2007 01:00 AM
Has My Pay Pal Account Been Compromised? SINC Everything Else, eh! 39 Dec 3rd, 2006 03:23 PM
Login password toast: grateful for "test" account! HowEver Mac, iPhone, iPad and iPod Help & Troubleshooting 3 Jan 17th, 2006 08:39 AM
Admin account login problems joeldey Mac, iPhone, iPad and iPod Help & Troubleshooting 0 Nov 6th, 2005 04:59 PM
Account corruption DP004 Mac, iPhone, iPad and iPod Help & Troubleshooting 0 Sep 18th, 2005 12:24 AM


All times are GMT -4. The time now is 06:15 AM.



Copyright © 1999 - 2012, ehMac.ca All rights reserved. ehMac is not affiliated with Apple Inc. Mac, iPod, iTunes, iPhone, Apple TV are trademarks of Apple Inc. Content Relevant URLs by vBSEO 3.6.0 RC 2

Tribe.ca: Urban living in Toronto!