Technology content trusted by users in Australia and around the world.
4,957 Articles | 29,929 Posts
Select Your Edition:  
Tweakipedia
A wealth of
tech information!

TRENDING NOW: Xbox One - Just what is Microsoft thinking?!
AU EditionYou are located: Home > All News > Hacking & Security News > Another Mac security issue exposes Lion login passwords in plaintext

Another Mac security issue exposes Lion login passwords in plaintext

By: (more) | Hacking & Security News | Posted: May 7, 2012 3:29 pm

This year, so far, has not exactly been a stunning display for Macs. Between the Flashback malware and now this, it really shows just how weak the security of Mac OSX is. The latest blunder by Apple and its security team is that they turned on a debug log file which stores the user's password outside of the encrypted area.

 

another_mac_security_issue_exposes_lion_login_passwords_in_plaintext

 

If you were using FileVault prior to upgrading to Lion, it may be time to think about changing your passwords as this would affect you. FileValut 2 users (whole drive encryption) are not affected by this accident. Additionally, if you have Time Machine backups, the plaintext log file has stored your password for the long term.

 

Security researcher David Emery explains:

 

This is worse than it seems, since the log in question can also be read by booting the machine into firewire disk mode and reading it by opening the drive as a disk or by booting the new-with-LION recovery partition and using the available superuser shell to mount the main file system partition and read the file. This would allow someone to break into encrypted partitions on machines they did not have any idea of any login passwords for.

 

Ironically, someone had posted on the Apple Support Communities after he noticed the flaw exactly 3 months ago. Not a single person had gotten back to him. This highlights Apple's quality assurance problems. This needs to be fixed fast. But even after a patch is released, it will be impossible to make sure all copies of the log file are deleted, so remember to change your password!


SOURCE #1

Related Tags



Further Reading: Read and find more Hacking & Security news at our Hacking & Security news index page.

TweakTown News RSS FeedDo you get our news RSS feed? Get It! Got a news tip? Tell Us!

Post a Comment about this news



Check out our
RSS feeds!
  • Upcoming Content: MSI Z77A-GD65 Gaming Series (Intel Z77) Motherboard Review
  • Upcoming Content: HGST Travelstar 7K1000 1TB 2.5" Hard Drive Review
  • Upcoming Content: Western Digital My Passport Edge for Mac 500GB External HDD Review
  • Upcoming Content: PQI Air Card 4GB Wi-Fi SDHC Review
  • Upcoming Content: LaCie CloudBox 1TB Personal NAS Review
  • Upcoming Content: Star Trek: The Next Generation - Season Three (1989) Blu-ray Review
  • Upcoming Content: The Hobbit: An Unexpected Journey (2012) Blu-ray Movie Review
  • Upcoming Content: Whatever happened to Comodo Time Machine?
  • Upcoming Content: SuperSpeed RamDisk Plus 11 Software Review
  • Upcoming Content: ADATA DashDrive Elite UE700 USB 3.0 Flash Drive Review
  • Upcoming Content: MyDigitalSSD BP4 240GB mSATA Review


Hacking & Security News Posts

View More Hacking & Security News Posts


TweakTown Web Poll

Question: What new stuff are you most excited to see at Computex Taipei 2013?

Cases, Coolers & PSU’s

CPU's

Gadgets

GPU's & Video Cards

Keyboards & Mice

Laptops, Tablets & Phones

Motherboards & Chipsets

New Tech

SSD's & Memory

Booth Babes

or View the Results

View More Polls

Forum Activity

View More Forum Posts

Hacking & Security Press Releases

View More Hacking & Security Press Releases