Apple Takes 3 Months But Finally Stops Printing Passwords in Plaintext
May 9, 2012 5:20 PM
comment(s) - last by
Company is showing signs of improvement, past flaws took it up to a year to patch
Famed OS X hacker
once told a security blog
, "Mac OS X is like living in a farmhouse in the country with no locks, and Windows is living in a house with bars on the windows in the bad part of town."
But of late there have been
in the farm house, and even Apple, Inc. (
started to admit that it has security issues
-- well, after realizing that telling its technicians to
lie to customers about them
might be bad publicity. One recent piece of malware is estimated to have
infected 600K Macs
generated millions in profit
for identity thieves alone.
Kapersky Labs, a top security firm recently warned the public that Apple's security was
10 years behind Microsoft
). Evidence of that was seen in the 10.7.3 build of OS X "Lion", which due a programming error (a stray debugging flag left on in OS X's source) accidentally logged
the passwords of users who used legacy FileVault settings.
An Apple user, Eric Hildum
in the support forums three months ago:
I’ve tried it on another Mac as well, same result: The login of a normal network user writes this log line as his homedir gets mounted.
This poses a security risk. We have some users who are local admins, they could ask another user to login on their Mac and look for the password afterwards. Extration in single user mode would be possible as well.
Is this a “speciality” of our environment or is this a known bug? Can I turn this behavior off?
We are running Lion clients with a SL Server and using OpenDirectory.
Apparently the Apple answer was that this was a "feature" for the time being, because the user received no reply to his pleas for three months. Then a security researcher by the name of David Emery, posted his findings to the
mailing list, a list frequent by hackers.
As noted by Mr. Emery, the issue did not effect purchasers of new Lion systems, but might have affected many users of legacy systems who upgraded to Lion.
With the Cryptome email, the media began to catch wind of Lion's penchant for plaintext password dumping and Apple was forced into the awkward position of providing an "update" for its "feature".
Hence OS X 10.7.4 was born, and aired today to loyal Lion subscribers.
The patch also "improves" other "features", such as no longer losing settings to the "reopen windows when logging back in" checkbox, and allowing "certain British third-party keyboards" to finally work.
Apple may still be living in the dark ages of security, but at least it's figured out not to stores users' passwords in plaintext, even if it took the company three months of complaints. On the plus side, the three month turnaround is faster than past incidents where Apple took
up to a year to fix past security issues/features
This article is over a month old, voting and posting comments is disabled
RE: More biased anti-apple Trolling
5/9/2012 8:24:10 PM
Are you even serious? Statistically speaking, if only 5 percent of Macs get a virus by your rationale, how many would that be if they had the same base installment as windows machines???? Remember now, there are still even win 98 machines on the net, it is only obvious that if even both of these machines where equally secured, than windows would billions more infections by market dominance alone!
What hacker would want to create a virus to target the least amount of computers to spread to? Doesn't make any sense...
Windows is always under attack due to their dominance, this has made them hardened and use to dealing with non stop attacks. Only recently has Apple started to barely gain enough of the market share to be targeted by hackers (that and its easy when Apple didn't supposedly need antivirus software)making them an easy target, but yet not ready to deal with these ongoing threats.
Trust me, I love to love an underdog, but Apple is not the underdog to love, just by supporting them, even knowing the way that they deal business and treat their customers as idiots tells me quite a bit about your personality.
But hey, Apple can instill a feeling of superiority and coolness right?
"It looks like the iPhone 4 might be their Vista, and I'm okay with that." -- Microsoft COO Kevin Turner
Symantec: Flashback Trojan for Mac Generates $10,000/Day
May 1, 2012, 1:46 PM
Kaspersky Labs: Apple's Security 10 Years Behind Microsoft
April 26, 2012, 7:39 AM
Apple Admits Its Macs Have a Malware Problem
April 12, 2012, 12:07 PM
Malware Authors Get Boost from Apple's Sluggish Updates, Infect 600K Macs
April 6, 2012, 8:40 AM
"Devil Robber" Trojan Infects Macs, Leeches Their GPUs for Bitcoin Profit
November 1, 2011, 10:59 AM
Testers Trolled by Promise of Uninstallable Windows 10 Preview Build 10061
April 16, 2015, 2:52 PM
Rumors Heat up About 2016 Windows 10.1 (Windows "Redstone") Release
April 8, 2015, 9:26 PM
Report: Windows 10 Successor is Codenamed "Redstone" After Minecraft Item
April 7, 2015, 2:03 PM
Windows 10 Build 10049 Installation May Take Hours, Will Fail if You Have < 8 GB
March 31, 2015, 2:59 PM
Windows 10 Build 10049 Airs, Complete With Project Spartan Browser
March 30, 2015, 7:12 PM
Office 2016 Preview Comes to Mac w/ Retina Support
March 6, 2015, 3:32 PM
Most Popular Articles
Windows 10 Build 10056 -- What's New in the Latest Leak
April 13, 2015, 10:38 PM
TSMC Hypes Its Upcoming 10 nm Process, Amid Struggles to Hit Volume at 16 nm
April 10, 2015, 7:57 PM
Sharp Unveils World's First "4K" Phone Display at Mind-Boggling 806 PPI
April 13, 2015, 11:24 AM
Tech's Biggest Loser on Tax Day: eBay Pays Nearly 99 Percent Tax Rate
April 15, 2015, 3:28 PM
In California Hippies, Religious Right Find Common Enemy in Vaccine Science
April 9, 2015, 4:42 PM
Latest Blog Posts
Sceptre Airs 27", 120 Hz. 1080p Monitor/HDTV w/ 5 ms Response Time for $220
Dec 3, 2014, 10:32 PM
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
More Blog Posts
Copyright 2015 DailyTech LLC. -
Terms, Conditions & Privacy Information