frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Root Persistence via macOS Recovery Mode Safari

https://yaseenghanem.com/recovery-unrestricted-write-access/
19•yaseeng•2h ago

Comments

AshamedCaptain•1h ago
You boot an operating system on the machine, you have access to all unencrypted files, what is so strange about this ? You can do the same thing with Terminal. And smells of GenAI...
girvo•1h ago
EDIT: The person I replied to entirely rewrote their comment (with no indication they did so) so mine seems weird now, apologies for that.

Apple fixed the issue it seems, but did kind-of-sort-of ignore it. The argument from the OP is that it requires physical access, you don't need to convince the user to do anything, the attacker can do it...

...which Apple pointed out (in the article you're commenting on) that if FileVault was enabled this wouldn't be possible, which is true.

And if you have physical access and no encryption, then it's kind of game over anyway. But still, kind of neat to find something like this and Apple fixed it regardless

lights0123•1h ago
Yep. While the Terminal is not an option from the 4 apps listed in the initial screen, it's available from Utilities → Terminal at the top. They even provide a convenient way to access the hard drive from another computer: https://support.apple.com/guide/mac-help/macos-recovery-a-ma...
yaseeng•49m ago
You're right that Terminal is accessible via Utilities, but Target Disk Mode and Terminal both require an admin password. Safari bypassed that authentication entirely, writing directly to protected system locations with no admin password
jeroenhd•1h ago
Apple tries to lock down access at the very least. They also patched the vulnerability twice (they restricted Safari for some reason and they also disabled the settings in the new version of Safari). It seems like Apple cares at the very least. Which is weird, because they also give you a terminal?

Lots of people I've met were surprised that I was able to get their photos from their windows laptops without ever needing their password. Especially these days in the age where even phones and Windows 11 will enable encryption by default, it's a tad weird that disk encryption isn't on by default on macOS. I, at the very least, was surprised that disk encryption isn't mandatory and always on on macOS, seeing the way Apple controls both the OS and the TPM firmware so that they're pretty much immune to the dreaded "BIOS update made my laptop ask for bitlocker" problem you get on Windows.

I don't really get why this would be AI generated, what makes you think that?

lilyball•1h ago
At the very least the author's submission and follow-ups to Product Security looks written by AI.
yaseeng•48m ago
I come from an Arabic-speaking household so my English can be a bit funky sometimes, sorry. However I did use Claude to help format the CVSS tables and polish the grammar in the formal Apple submission (I was 17 submitting to a major company's security team for the first time). The research and findings however are entirely original.
yaseeng•45m ago
Completely agree on the encryption point. Apple controls the entire stack and could mandate FileVault encryption by default. The fact that it's opt-in is a weird decision that hasn't caught up with their security posture elsewhere.

On the Terminal point, its worth clarifying that Recovery Terminal does require mounting the data volume first, which typically prompts for an admin password. Safari bypassed that step entirely, which is what made it interesting.

yaseeng•50m ago
Actually this is a distinction worth clarifying, in Recovery Mode, Terminal does require mounting the data volume first, which typically prompts for an admin password. Safari bypassed this entirely, writing directly to protected system locations without any authentication. Furthermore, no GenAI was used in writing the article I come from an Egyptian Speaking background so my English may be a bit funky, sorry :)
yaseeng•53m ago
For context: I submitted this to Apple in September 2025 and waited 6 months before publishing. Apple closed both reports citing FileVault as a mitigation, which is technically accurate but FileVault is opt-in and many people disable it during setup without understanding what it does (myself included when I got my MacBook in 2020). My personal view is that the behavior significantly reduces the effort required to persist data on an unencrypted system compared to for example side-loading Linux. Regardless, Tahoe 26.3 (It might have been patched before, I didn't check) appears to have silently patched both issues.

Do RL on a model with your vector db

https://cgft.io/blog/turbopuffer/
1•kumama•9s ago•0 comments

Zopaf – A negotiation math engine as an MCP server (zero LLM tokens)

https://zopaf-mcp-production.up.railway.app/mcp
1•rjandino•58s ago•0 comments

Text editing at the speed of thought (voice UI experiments)

https://grugnotes.com/accounts/login/?next=/keizo/blog/text-editing-at-the-speed-of-thought/
1•keizo•1m ago•0 comments

Show HN: Visualizing React Server Component Boundaries in Next.js

https://github.com/foxted/rsc-boundary
1•valentinprgnd•3m ago•0 comments

Show HN: Kyoo v5 – self hosted media server

https://github.com/zoriya/kyoo
2•zoriya•3m ago•0 comments

Investigation: Unmasking the anonymous hosts of 'Russians With Attitude'

https://kyivindependent.com/exclusive-investigation-reveals-hosts-of-us-popular-far-right-podcast/
1•doener•5m ago•0 comments

Spectre – A design-by-contract, compiled programming language with QBE back end

https://github.com/spectrelang/spectre
1•death_eternal•9m ago•0 comments

TypeScript Enums Are Terrible

https://www.youtube.com/watch?v=0fTdCSH_QEU
1•goodoldneon•10m ago•1 comments

API and MCP that pumps data from SEC filings into your agent context

https://medium.com/@steve_63055/give-your-ai-agent-direct-access-to-kpis-from-sec-filings-e372d04...
2•sjt-at-rev•12m ago•1 comments

Graphify: An AI skill for turning any folder into a queryable knowledge graph

https://github.com/safishamsi/graphify
1•tanelpoder•14m ago•0 comments

Analyzing Reverse Address Translation Overheads in Multi-GPU Scale-Up Pods

https://arxiv.org/abs/2604.02473
1•matt_d•15m ago•0 comments

Surprising hidden pattern connecting over 1,500 languages found

https://www.independent.co.uk/news/science/languages-universal-grammar-rules-pattern-b2952396.html
1•antfarm•19m ago•0 comments

Bitwarden Is Down

https://status.bitwarden.com/issues/69d430c5763f44a7efca7b8a
4•zhan_eg•19m ago•0 comments

Show HN: ACP – Governance for AI Coding Agents (Claude Code, OpenClaw)

https://agenticcontrolplane.com/
1•davidcrowe•20m ago•0 comments

How to Perform a Bulk Permissions Check in FusionAuth FGA by Permify

https://fusionauth.io/blog/permify-bulk-permissions-check
1•mooreds•24m ago•0 comments

Launchyard – vibe code a business

https://launchyard.dev
1•hackmaxim•25m ago•1 comments

HubLite – A native macOS CRM for people who find HubSpot/Salesforce overkill

https://www.innobera.com/hublite/
1•Evian-SP•26m ago•0 comments

Show HN: MemberLane – Paid Communities on Telegram, Discord, and WhatsApp

https://www.memberlane.app
2•grene98•29m ago•0 comments

Reddit is the #1 most cited source across every major AI search platform

https://virtualuncle.com/answer-engine-optimization-aeo-guide-2026/
3•svrbvr•32m ago•0 comments

Kalshi wins appeal against New Jersey in Third Circuit

https://www.dopaminemarkets.com/p/prediction-markets-vs-states-the
1•astorplace•32m ago•1 comments

Show HN: A bespoke magazine for the kid in your life

https://www.juiceboxjournal.com/
1•easymode•35m ago•0 comments

Show HN: Clickly – tool for designers and engineers to build mobile apps

https://clickly.app
1•roskoalexey•40m ago•0 comments

Show HN: Next Moca – control plane for AI agents (pre-seed @ $10M)

https://www.nextmoca.com
1•swanandrao•41m ago•0 comments

Matrix-Kernel-Root

https://github.com/M2KR4R/matrix-kernel-root
1•M2KR4R•42m ago•0 comments

Um método informático para crianças feito com amor

https://www.amazon.com.br/dp/B0DN62YNJF
3•Hanoverdoes•43m ago•0 comments

Anthropic, OpenAI and Google sharing Intel to block Chinese distillation

https://www.bloomberg.com/news/articles/2026-04-06/openai-anthropic-google-unite-to-combat-model-...
2•nikcub•44m ago•0 comments

Building a DIY OpenClaw

https://ben.page/claude-mac
2•j03b•44m ago•0 comments

Bernie Sanders: "AI Is a Threat to Everything the American People Hold Dear"

https://www.wsj.com/opinion/ai-is-a-threat-to-everything-the-american-people-hold-dear-a3286459
7•fortran77•45m ago•7 comments

Real-time tracker for NASA's Artemis II Moon mission

https://artemis.fyi/
2•jsk2600•46m ago•0 comments

GitHub Copilot CLI combines model families for a second opinion

https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-combines-model-families-for-a-sec...
2•salkahfi•47m ago•0 comments