Parental Controls bypass OS X 10.9

Hi, 
Unfortunately I made an experiment: making a standard user account with parental controls and putting in a random password to my admin account. I entered Osx utilities, entered Terminal, and typed ths command: resetpassword  -Then I was confronted by a window with the reset password, selected the Mac HD, and selected root. I typed a password for it, remembered it, saved changes, and then i finally rebooted the computer. When it started up, I was faced with the usual login screen, but there was an "other" user button. I clicked it, and i typed root as username, and put the password i reset to earlier. I pressed enter, and walaa! I was logged in as the super admin account "root". In the same case as if a child had parental controls and he did not know the password of the admin that put him/her parental controls, with some experience in computing they could have done the utilities thing and reset the password of the root and logged in as it, and would have been free to do anything and bypassed Parental controls. He/She would be in full control of the computer and without the parent's consent. Can you apple employees or anyone here that can contact one alert apple of this flaw? Now kids could bypass parental controls on any mac, and without the parents knowing. Of course there are other ways, but this is the most effective. Can they fix this? any kid would take full control of any mac, on any OS X version.
Its not right. Even on school computers this could happen. Please can apple fix this? Imagine the kids taking control of any mac around the world!

You can set a firmware password (http://osxdaily.com/2014/01/06/set-firmware-password-mac/) if necessary, which prevents anyone from resetting the password in that way. Most institutions, such as schools, use this. Otherwise, there is no real way to prevent a child from doing this if they really want to - the best prevention is communication about acceptable and unacceptable behaviour. Or, just encourage their intellectual curiosity - I imagine this is how most programmers and developers first got into computers!

Similar Messages

  • For some reason when I shut down my computer then turn it back on, it comes back directly into my account, bypassing having to enter a password to get into my account.  This works in direct conflict with the parental controls I've got set up.  Any ideas?

    For some reason when I shut down my computer then turn it back on, it comes back directly into my account, bypassing having to enter a password to get into my account.  This works in direct conflict with the parental controls I've got set up.  Any ideas?

    Thank you so much for the quick response to my question.  I tested your directions and it works!!  Thank you.  I would never have figured that out.  I knew I had to go into System Preferences but would not have guessed that I needed to have Automatic Login set to off. 

  • Parental Controls trivial to bypass in any home router?

    In trying to figure out why the parental controls in my Linksys router were not working, I learned that my kid had trivally by-passed the parental controls that I had set up.  I found his PC was associated with multiple MAC addresses.  A simple google search found this Youtube video that even a grade school kid could follow.  https://www.youtube.com/watch?v=Fqdib7D-MCY At the end, the poster goes to the Linksys help page for Parental Control just to laugh.  This means at All MAC based access controls and parental controls are useless in any product.  More research on DNS based partental controls shows they are trival to bypass as well.  Installing a control on his PC requires taking away Admin access from his Window login and prevent software install, but then I have to install all the games and software and  that's easy to circumvent too.  Any recommendations other than taking my kids computer away?

    Not sure this works but try setting up the MAC allow list for only the one MAC that is on the pc itself. set it up under Wireless>MAC filtering and click on the Allow button and add only the addresses you want ot have access. Unless your kid knows the password of the router and is able to changes settings in the router then when he changes his MAC is should not connect at all.edit: to add to this. you would need to use the mac filtering as well as the parental controls. If he changes his mac and it still gets in then that is definately a problem. Move the pc to the living room. Best parental control there is!

  • HT2900 Forgot user & password for Safari parental controls. Is there a bypass?

    We set up parental control on Safari but forgot the username and password needed to change or reset the parental control settings.  Is there a bypass in order to turn the controls off?

    Any user with Admin access to the Mac should be able to use their account name and password to unlock the Accounts Preferences and access parental controls.

  • Any ideas for security and parental control software yet???

    Just received two of the touchpads from the fire sale and gave them to my kids, both under 10.  I am very interested in limiting the sites that can be accessed through the browser, as well as a few other things.  Has anyone found a practical means of doing this?  I'd hate to give up on this and switch it over to Android, especially since there is only Gingerbread available.  But, I just don't know what else I can do about these.  Any ideas? 
    Thanks!
    Post relates to: HP TouchPad (WiFi)

    Please take this post with a grain of salt. I don't claim to be a security and parental control software expert, but I have researched these solutions and have some personal experience with them. That being said, here's some ideas to get you started.
    As speedtouch mentioned, OpenDNS is a fantastic solution for website filtering. They have a great set of filters that can be customized and are one of the easiest systems to set up. Simply install an updater app on one of your desktop computers (or directly on your router if it's supported), configure your router to use their DNS servers, and you're good to go. I personally use this system mysefl and it works really well. The only downside in my experience is that there is not a temporary override system (at least, not in the free version that I use). An example of when this might be handy: my wife goes clothes shopping and looking at new bras. Every once in a while, a perfectly legitimate site might get blocked (in this case, probably something I don't want my kid looking at but perfectly fine for my wife). The option to "temporarily override the block" or "temporarily allow" the site would be nice, but it doesn't exist.
    Another FANTASTIC solution that I've used in the past is the Astaro Security Gateway. They have a free home version of their "Software Appliance" that goes above and beyond OpenDNS. I haven't used it in a while, but when I did it was able to not only filter web sites but also monitor Instant Messaging and other online activites. It's a bit more involved as you need your own hardware (I used an old computer with 2 network cards and stuck it in between my router and my broadband modem), but the results are pretty powerful.
    The downside to all these solutions, however, is that they will only work when the TouchPad is on your network. If they connect to a neighbors network of if the go to a friends house, all of these systems will be moot because they are completely bypassed. The only way to monitor that content from ANY network would be to install an application on the device itself and to my knowledge, none exist.

  • How well does website filter work in parental controls?

    Hello there,
    I'm curious to know how well the adult filter works ok the ios7 built in parental controls. I noticed they have a websites option now to filter different levels of the internet. Does this also work across the entire device in 3 party in app browsers?
    Thanks,
    LJ

    They work pretty good, & are across the device. Read here:
    http://support.apple.com/kb/HT4213
    Just be aware, crafty kids can figure out a way to bypass pretty much anything they want. Just get in the habit of regularly checking the device.

  • Is it possible to set up parental control in MultiPoint Server 2012?

    Hello everyone!
    Is it possible to set up parental control in MultiPoint Server 2012. I'd like to filter adult web sites.
    Kind regards,
    Pavel

    I found an issue with Multipoint Dashboard that when student select to signout and then select "Cancel" to signout to go back to the session, the Multipoint Dashboard filtering is no longer applied to the session.
    here is the scenario -
     - Student login to the Multipoint server using the end point device as an standard user.
     - The Multipoint Dashboard has the configuration to "limit the website to all desktop". "cnn.com" only
     - The student session, limits the use of the web browser to only to cnn.com - this is working.
     - Studen open an app like notepad - click save --> prompted him to where to save the file.
    do not save the file. leave the "Save as" windows open.
     - Click Start (left bottom corner)
     - Click the account’s name on the top right corner, Click Sign Out
     - It will prompt you with a warning that there is a file open and needs to be saved
     - "Signout anyway" or "Cancel"
     - student select to "Cancel"
     - He is now back to the session
    This will allow the student/account logged in to bypass the web filtering

  • Safari, Secure connection to sites, and Parental Control

    I'm setting up Safari for a child, and have Parental Controls enabled and am customizing the list of sites that can be visited. I'm allowing Netflix.com and have multiple http and https Netflix URL's allowed. However, when I test accessing this site, Safari gives an error stating that it cannot establish a "secure connection".
    The same computer, with a different account, can access the same URL without the error. My assumption would be that since I specifically allowed several Netflix.com URL's, that this would work just fine. By granting specific access, you are bypassing Parental Controls in a controlled way.
    What's causing this to not work?
    Thanks for your help.

    Netflix only provides HTTPS when loggin in or visting the main site, not for the content or it would have to encrpyt the video stream (expensive).
    It also sends one to another site (with another name "movies.netflix.com" here) to view the content, perhaps you have to access the account from another machine, grab the URL it directs you too and enter that into Parental Controls.
    Silverlight also has to be updated, check your Flash too.
    https://www.mozilla.org/en-US/plugincheck/
    I did see the thread about using the IP address for HTTPS sites, but wouldn't there be a large number of IP addresses associated with a Netflix type of site due to all of the streaming video feeds available?
    If that wouldn't be a problem, does anyone know how to determine the IP address of Netflix?
    The video streams are not encrypted, and IP addresses are just the physical buildings of the servers themselves, the buisness name (URL) can change locations and that's what the Domain Name Server is used for to resolve those IP numbers for you in case they do change.
    Netflix log in and content delivery have different IP addresses, the content delivery may use IP's of servers closer to your location, so it would not assist you for me to give those out.
    You can install Firefox web browser and a add-on called FlagFox, which displays a little country flag in the URL address bar of each website you visit which you can right click and "Copy IP" if you so need it.
    I don't advise using the IP, as that can change, use the URL so the Domain Name Server of your ISP can provide the correct IP address so your comptuer can connect.
    Also Firefox has more add-ons for control and a nearly completely customizable web browser that may be a better choice for children/special needs (big buttons, type etc) than Safari.
    There is Public Fox which can lock down certain aspects of the browser (prevent downloads for instance or changing things.)
    Theme Font & Size Changer which can enlarge the type of Firefox itself, there is NoSquint which can auto-zoom all web pages etc.
    There are Firefox Personas and Themes that can dress up or "childize" the browser so it's more fun for children.

  • I am having issues with parental controls.  My kids are able to access websites that are NOT on our approved list.

    My children are only allowed to access certain websites, but as of late have been able to bypass the list by typing in a website. 

    Check out KB Article Mac OS X v10.5, 10.6: About the Parental Controls Internet content filter - Apple Support and Configuring Parental Controls for possible solutions.

  • Safari Parental Controls Blocks YouTube Login?

    I have parental controls enabled on a user account to "limit adult websites automatically". Whenever I try to log in to YouTube (with www.youtube.com allowed), it comes up with this:
    I've heard that a similar problem with Google Mail can be bypassed by entering google.com's ip address into the "Allowed" section in the Parental Controls preference, but this did not not work with YouTube's ip. Perhaps I have the wrong ip? Or is there no way around this?

    If you were to create another standard account and apply the same parental controls, would the same thing happen?

  • Smart DNS and BT Parental Controls

    I wish to have parental controls turned on, but is there any way to allow Smart DNS to get through?
    BT Parental Controls seem to block any DNS other than the BT DNS servers, but is there any way I can allow my Smart DNS service through?
    http://en.wikipedia.org/wiki/Smart_DNS_proxy_server
    Many thanks for any help.

    OnFire wrote:
    I wish to have parental controls turned on, but is there any way to allow Smart DNS to get through?
    BT Parental Controls seem to block any DNS other than the BT DNS servers, but is there any way I can allow my Smart DNS service through?
    No, its not possible. BT have done it that way to ensure that people cannot bypass the Parental Controls by using different DNS servers.
    There are some useful help pages here, for BT Broadband customers only, on my personal website.
    BT Broadband customers - help with broadband, WiFi, networking, e-mail and phones.

  • Website listed in the "never allowed" section of web browsing in parental controls still comes up!

    I have listed YouTube.com on my list of websites to never allow for my daughter's user account on my MacBook Pro, but it still allows it!  I am updating to mavericks OS right now - hoping it's a bug that will be fixed. 
    Please help if you know what might work.  I bought a Mac because of the parental controls, which are apparently useless!

    You might think that if you change "Website Restrictions" under the "Content" tab > to "Allow unrestricted access to websites" that it would bypass the proxy server > entirely. Unfortunately it does not.
    Why would you think that? There's not a single commercial cache engine or proxy I'm aware of that works that way. If a site isn't restricted the proxy server simply passes the traffic instead of restricting it. It doesn't change the routing or proxy on the guest machine.

  • Internet Recovery Parental Controls

    Hi,
    I've noticed that while using Safari in internet recovery mode, some pages are blocked by parental controls, but the parental controls don't seem to follow the controls set up in the admin account.  Anybody have any ideas of where those settings are set?  Is there a way to change them?
    Any help is appreciated!

    Open firmware password may be the way to do it.   Mind you, a clever enough person can bypass that, but it takes more effort than it usually is worth.  Put a hidden camera in the room if you are worried something will happen, and backup the data only when you are present.  And if you forget the open firmware password, you may have locked yourself out for good anyway.

  • McAfee NetProtect/Net Protect Parental Controls vs...

    Dear All,
    My 14 year old has inadvertantly discovered a way to circumvent the YouTube block on McAfee, which was preventing him from loading YouTube videos.
    If you are on a Google search page and click the new "app launcher" grid menu, you can access YouTube directly from Google without being logged in, thereby bypassing every filter in place, including the ones set up under my permanent Google log-in.
    I am raising this issue directly with Google - in the meantime, how do I make McAfee aware that NetProtect no longer does the job we need it to, and I urgently need a better solution?  All Help Menus appear to lead to BT - nothing seems to refer to a McAfee contact.

    Clearing DNS cache did not help.
    It has finally come back, but a very long wait; long after the 'minute or so' it said it would take. I agree there was a clear error message.  Maybe it would have come back eventually even with it just temporarily disabled rather than fully turned off?
    No further changes to setting by me (still totally removed) but now the blocking is back again ....
    Clearing dns cache no effect.
    No major worry as I can revert to BT dns servers till it is resolved, but irritating.
    But I see now at http://bt.custhelp.com/app/answers/detail/a_id/46768/c/346,6679,6681/related/1#turnoffperm
    "It can take up to two hours for BT Parental Controls to be completely deactivated."

  • Initial Setup- Parental Controls

    Purchasing 2 Mac Airs for my teenagers for Christmas (spoilt). I would like to get the parental control setup correct from the start.
    I have viewed the guide movie for this but would like to clarify the initial setup.
    In the initial setup, do I have to setup a profile for admin and then my child profile so my child cannot simply use the admin part but has to log into their account to use?
    Just want to get this right from the start.
    Thanks in advance.

    That's right. If you seriously want to try to prevent your kids from bypassing Parental Controls, you also have to set a firmware password, so they can't boot from a system on an external drive without the controls. And you have to check periodically to make sure the firmware password hasn't been removed or changed, as it can be if they take the machine to an Apple Store saying they've forgotten the password.

Maybe you are looking for

  • HT4901 How can I change my iCloud email address?

    I had someone set up my iCloud email address and now I need to change it. Can someone tell me how? Thank you

  • Any major changes to the database for SCCM 2012 and Reporting?

    I'm in the process of migrating my custom reports from SCCM 2007 to SCCM 2012. I wonder if all the tables / views in SCCM 2007 are the same in SCCM 2012 for my reporting purposes? So far everything I've migrated over appears to work without a problem

  • Document Upload depending on Properties

    HI all KM gurus, I have created various document types and corresponding properties as described in "Advanced Concepts in Metadata Properties in KM " . Now my requirement is to upload the document in to the folder depending upon selection of properti

  • Window Shade Option:

    Why was the "window shade" option removed from OS 10.x.x? The "double click top of doc to roll it up & down" option. Or is it still operative and I am just too dense to find it? Any info, thoughts, ideas? Can we pressure Mr. Steve to resurrect it, if

  • Updating CS^ Web Premium

    I have CS6 loaded on two macs and a limited internet connection as my location has little service. How can I download updates for CS6 and apply them to both macs without having to download the files for each machine separately. Thx