facebook rss twitter

Apple OS X Lion update dumps FileVault passwords to plain text

by Alistair Lowe on 7 May 2012, 09:37

Tags: Apple (NASDAQ:AAPL)

Quick Link: HEXUS.net/qabgbn

Add to My Vault: x

Whilst past reports of Mac OS X security have never shown Apple's big-boy operating system to be the most secure of softwares, Mac users may be particularly surprised this time to find out that if they had used Apple's FileVault for storing their passwords, prior to updating to OS X Lion and eventually, 10.7.3, there's a chance that their passwords have been left out in the open, in plain text, sitting in a debug log file.

The flaw is caused by a rogue debug flag set by one of Apple's programmers; those that used FileVault and encrypted spaces will have held on to the older version of FileVault after upgrading to OS X Lion, in order to retain their encrypted data; it's these users who are affected by the programming error, with users of the new FileVault 2 disk-wide encryption unaffected, though, mind you, reports earlier this year also showed that despite its encryption, FileVault 2 can be brute-force hacked in just 40 minutes, through the use of live memory analysis.

Currently, the only way for users to ensure that the issue doesn't repeat itself, is to disable FileVault altogether, exposing encrypted data. Likewise, this bug affects TimeMachine backups too, and so any historical data is also exposing passwords and remains a risk if stolen.

We wonder what virus/trojan will, inevitably, be the first to exploit this flaw?



HEXUS Forums :: 7 Comments

Login with Forum Account

Don't have an account? Register today!
Wow that's a pretty big flaw to let slip wild, lets see how long it takes for a fix - if indeed its even possible to fix given that old backups need purging of the offending file.
Fail.
kingpotnoodle
Wow that's a pretty big flaw to let slip wild, lets see how long it takes for a fix - if indeed its even possible to fix given that old backups need purging of the offending file.

It is a tad of a fail, can they not just release a hotfix to change the debug setting that was causing it !
Masterclass in why not to use password vault software.

Butuz
Butuz
Masterclass in why not to use password vault software.

Butuz

Is Apple's Filevault a password vault though?. I thought it was more like a proprietary Truecrypt?