MalwareTips.com
Current time: 05-22-2013, 07:03 PM
Hello,is this your first visit?! If NOT use this login panel!
Nick:  
Password:     
If YES, you should join
our amazing community!
Create an account!
Follow us
Facebook MalwareTips.com Twitter MalwareTips.com Google Plus  MalwareTips.com
  • Portal
    Home
  • News
    Headlines
  • Forums
    Community
  • Tutorials
    How-to's
  • Malware Help
    Assistance
    • Removal assistance
    • Malware removal guides
    • Security wizard
  • Reviews
    Products review
    • Video reviews
    • Written reviews
  • Giveaways
    Free stuff
    • Giveaways and promo
    • Discounts
    • Desktop enhancements
  • Malware Hub
    Virus Pipe
    • Virus Exchange
    • Virus List
  • Blogs
    Research

User Control Panel View New Posts View Today's Posts House Rules

MalwareTips.com / Daily News & Tips / News Section / News Archive v
« Previous 1 ... 58 59 60 61 62 ... 136 Next »
/ Apple update to OS X Lion exposes encryption passwords
Tweet
Threaded Mode | Linear Mode
Apple update to OS X Lion exposes encryption passwords
05-07-2012, 11:35 AM
Post: #1
Jack Online
Community Admin
Posts: 6,198
Joined: Jan 2011
Kudos 2241
Apple update to OS X Lion exposes encryption passwords
Sophos wrote:Apple's had a rough time lately on the security front. Last month it was caught out having delayed the release of a security update for Java, resulting in more than 600,000 Macs being recruited into a botnet. Now a quality assurance mistake can cause OS X users' FileVault encryption passwords to be exposed.

On Friday, David Emery posted to an encryption mailing list disclosing this flaw in the latest OS X Lion security update, 10.7.3, which was released in February.

It appears that a debug option was accidentally left enabled in FileVault, resulting in the user's password being saved in plain text in a log file accessible outside of the encrypted area.

Anyone with access to the disk can read the file containing the password and use it to log into the encrypted area of the disk, rendering the encryption pointless and permitting access to potentially sensitive documents. This could occur through theft, physical access, or a piece of malware that knows where to look.

To my knowledge, this only applies to users of Snow Leopard who used the FileVault encryption option for their home directories. It does not impact users of FileVault2 who have turned on Apple's full disk encryption, nor does it impact users who did not upgrade from Snow Leopard.

Read more: http://nakedsecurity.sophos.com/2012/05/...passwords/
Visit this user's website Find all posts by this user
« Next Oldest | Next Newest »


Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  Apple finally adds App Store encryption after 6-months of open exploit Earth 1 605 03-11-2013 06:29 AM
Last Post: McLovin
  Evernote Hacked, 50 Million passwords reset Earth 12 761 03-07-2013 06:05 AM
Last Post: exterminator20
  Phishing attack attempts to steal Google passwords via Red Cross website Payback 0 205 01-19-2013 03:54 PM
Last Post: Payback
  Zero-Day Vulnerability Uncovered in Symantec’s PGP Whole Disk Encryption Fiery 1 325 01-06-2013 10:24 AM
Last Post: McLovin
  Facebook passwords laws go into effect in some US states McLovin 0 259 01-02-2013 01:54 AM
Last Post: McLovin

  • View a Printable Version
  • Send this Thread to a Friend
  • Subscribe to this thread


User(s) browsing this thread: 1 Guest(s)

 


Proudly powered by MyBB.
Copyright - MalwareTips.com © 2012. All rights reserved. | Webdesign by End Soft Design
Contact Us | Privacy policy | Return to Top | Return to Content | Lite (Archive) Mode | RSS Syndication | Members List | Forum Team

MalwareTips.com is an independent website.All trademarks mentioned on this page are the property of their respective owners.