This isn't shaping up to be a great year for Mac security. On the heels of last month's Flashback trojan pandemic, reports indicate that the latest OS X Lion update uncovers user passwords to prying eyes, too.
As ZDNet reports, OS X 10.7.3 spits out a debug log file containing "the login passwords of every user who has logged in since the update was applied." The file isn't generated on all configurations. However, "anyone who used FileVault encryption on their Mac prior to Lion, upgraded to Lion, but kept the folders encrypted using the legacy version of FileVault" could be affected. ZDNet quotes security researcher David Emery, who says the log files can be accessed by third parties in a variety of ways:
This is worse than it seems, since the log in question can also be read by booting the machine into firewire disk mode and reading it by opening the drive as a disk or by booting the new-with-LION recovery partition and using the available superuser shell to mount the main file system partition and read the file. This would allow someone to break into encrypted partitions on machines they did not have any idea of any login passwords for.
The worst part? OS X 10.7.3 came out on February 1, and someone pointed out the bug less than a week later on Apple's own Supper Communities message board. The only replies were posted yesterday, after his post was linked in the ZDNet story.
This is disappointing. Apple is bigger and more powerful than ever, and its Macs are gaining market share fast, yet it seems OS X's security is lagging behind. I hope the Mac maker locks down its operating system better than it has, and fast.
|1. BIF - $340||2. Ryu Connor - $250||3. mbutrovich - $250|
|4. YetAnotherGeek2 - $200||5. End User - $150||6. Captain Ned - $100|
|7. Anonymous Gerbil - $100||8. Bill Door - $100||9. ericfulmer - $100|
|10. dkanter - $100|
|Lenovo ThinkCentre and ThinkPad machines pack AMD PRO APUs||19|
|Seagate 5TB BarraCuda and 2TB FireCuda drives are big and speedy||11|
|Nvidia licenses Rambus' DPA tech for side-channel data leak prevention||15|
|iOS 10.1 update includes portrait mode beta for iPhone 7 Plus||5|
|Biostar belatedly announces GTX 1060 graphics cards||12|
|HyperX Alloy keyboard gets lean and mean for FPS gaming||8|
|AMD drops prices on the Radeon RX 460 and RX 470||50|
|Reports: Radeon RX 470D is a budget Polaris card for China||9|
|Examining reports of slow write speeds on the 32GB iPhone 7||33|
|Signing your posts is daftly redundant. Meadows||+27|