Apple Releases macOS High Sierra; Ex-NSA Hacker Publishes Zero-Day
Apple today released the newest version of its operating system for Macs, macOS High Sierra, to the public. macOS High Sierra is a free download, and offers a range of new features and improvements including the new Apple File System, and support for High Efficiency Video Encoding (HEVC) for better compression without loss of quality, and HEIF for smaller photo sizes. Zack Whittaker, reporting for ZDNet: Patrick Wardle, a former NSA hacker who now serves as chief security researcher at -- Synack, posted a video of the hack -- a password exfiltration exploit -- in action. Passwords are stored in the Mac's Keychain, which typically requires a master login password to access the vault. But Wardle has shown that the vulnerability allows an attacker to grab and steal every password in plain-text using an unsigned app downloaded from the internet, without needing that password.
This hack affects High Sierra as well as older versions according to the article. The title of this implies that this is specifically something related only to the new OS.
Seems odd that two only slightly related news stories are concatenated into a single /. post.
The keychain hack seems to be working on any Mac OS, not just High Sierra.
http://www.geoffreylandis.com