Welcome to our website
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
OS X Lion update accidentally outs user passwords in plain text, stumbles over FileVault
Posted by Philipp Esselbach on: 05/07/2012 07:08 AM [ Print | 0 comment(s) ]
According to security researcher David Emry, users who used FileVault prior to upgrading to 10.7.3 may be able to find their password in a system-wide debug log file, stored in plain text outside of the encrypted area.
From Engadget:
OS X Lion update accidentally outs user passwords in plain text, stumbles over FileVault
This puts the password at risk of being read by other users or enterprising cyber criminals, Emry explains, and even opens the door for new flaw-specific malware. FileVault 2, on the other hand, seems to be unaffected by the bug. The community doesn't currently have a way to fight the flaw without disabling FileVault, so users rushing to change their password now may find it being logged as well.
OS X Lion update accidentally outs user passwords in plain text, stumbles over FileVault
