Skip to content

Comment on CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claudeparent

Comments

MacOS X prompted users for their passwords in 2001.

Microsoft's implementation was (twenty years later still is) a joke because it prompted users to hit enter or click a button.

Microsoft's Secure Desktop feature is actually incredibly well designed, and provides strong protect against fraudulent prompts or prompt interception attacks.

Only if you configure it like that, you can make it ask for a password, and on more recent versions of Windows 11, optionally, a single use token.

Ironically Apple just recently added the same simpified approach.

Only if you configure it like that

It is the default (unless they changed it in the last 2 years or so). I know for a fact that my PC and Laptop don't ask for my password and I know for a fact that I reinstalled Windows on my laptop less than 2 years ago and changed nothing regarding the UAC prompt (the closest that is even remotely close is enabling sudo in the settings).

May be, I never leave defaults on neither does our IT, so I might have that wrong.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.