Apple Addresses a Bug That Caused Disk Utility in macOS High Sierra To Expose Passwords of Encrypted APFS Volumes (macrumors.com)
Joe Rossignol, writing for MacRumours: Brazilian software developer Matheus Mariano appears to have discovered a significant Disk Utility bug that exposes the passwords of encrypted Apple File System volumes in plain text on macOS High Sierra. Mariano added a new encrypted APFS volume to a container, set a password and hint, and unmounted and remounted the container in order to force a password prompt for demonstration purposes. Then, he clicked the "Show Hint" button, which revealed the full password in plain text rather than the hint. [...] Apple has addressed this bug by releasing a macOS High Sierra 10.13 Supplemental Update, available from the Updates tab in the Mac App Store.
When creating a new volume, it apparently puts the password into the password hints field.
If you create a new volume using command-line tools, things are fine.
The encryption is still OK; this bug just leaves the key to the front door under the mat.
Which is still appalling.
To a Lisp hacker, XML is S-expressions in drag.
So it seems that Apple fixed the issue faster than slashdot was able to publish its report?
Get a proper computer instead of a fashion accessory, you feckless nonces.
"It just works", ROFLMA.
Confucius say, "Find worm in apple - bad. Find half a worm - worse."
AppFS is the appiest app system, so the filthy LUDDITES are trying to ruin it by claiming it's worse than LUDDITE systems like LUDDITE NTFS and LUDDITE Linux!
Apps!
Why does the password even exist to be recovered? I thought the first thing one did is hash the password and use the hash to encrypt/decrypt the volume. Also even the hash is not recorded anywhere, it would need to be entered each time.
That way if some looked they would not see the password used.
Of-course if you have the hash and know in detail how the volume is encrypted you can still get at the data, but you would need the hash and the exact method of encryption to do this.
E.C.P.
It's true Windows had some occasional security issues in the past. However, over the years they have all been closed. Meanwhile, Linux and MaxOS boxes are easily hackable and form the backbone of DDOS networks. Linux doesn't even auto-updates!!
How can such a bug in a security sensitive component of OS-X be overlooked in testing?
I once switched the username and password fields while creating the account in Slashdot and I am still living with it ;-)
But my friend, who runs a small company, got the shock of his life when the bank clerk switched the amount and data while entering some transaction. (It was in Chennai, India, not fully automated banking). The bank debited 12102015 rupees from his account or something.
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
I'm going to continue using the Host File Engine. Your software is well written, functional. The Host File Engine performs exactly as promised by mmell
his hosts program is actually pretty good by xenotransplant
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg
(APK's) work, I've flat out said it's good by BronsCon
I've tried his hosts file generating software. It works by bmo
APK your posts on this & the hosts file posts, and more, have never been in error &/or bad advice by BlueStrat
Your premise that hostfiles are a good way to deal with advertising & malvertising is quite valid by JazzLad
I like your host file system by Karmashock
(NEED MORE? Ask!)
* It's recommended/hosted by Malwarebytes' hpHosts!
APK
P.S.=> China imitated me http://www.theregister.co.uk/2017/04/26/boffins_supercharge_the_hosts_file_to_save_users_plagued_by_dns_outages/ ... apk
See subject DontBeAMoran: You can't show you've done better (especially earlier)? Nope https://it.slashdot.org/comments.pl?sid=11197935&cid=55317113/
* QUESTION: What's it like being a USELESS UNIDENTIFIABLE do-nothing "ne'er-do-well" BIG TALKER like you that TRIES to cut someone like ME down & YOU HAVEN'T DONE SQUAT BY COMPARISON?
APK
P.S.=> I'll answer the question above for you - it must SUCK to be "your kind" (a FAKE NAME for your FAKE LIFE fuck)... apk
Lighten up Francine. Youâ(TM)re gonna have a stroke. And you probably suck as a developer so Iâ(TM)m guessing your anger is more directed at your own failures.
I'm going to continue using the Host File Engine. Your software is well written, functional. The Host File Engine performs exactly as promised by mmell
his hosts program is actually pretty good by xenotransplant
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg
(APK's) work, I've flat out said it's good by BronsCon
I've tried his hosts file generating software. It works by bmo
APK your posts on this & the hosts file posts, and more, have never been in error &/or bad advice by BlueStrat
Your premise that hostfiles are a good way to deal with advertising & malvertising is quite valid by JazzLad
I like your host file system by Karmashock
(NEED MORE? Ask!)
* It's recommended/hosted by Malwarebytes' hpHosts!
APK
P.S.=> China imitated me http://www.theregister.co.uk/2017/04/26/boffins_supercharge_the_hosts_file_to_save_users_plagued_by_dns_outages/ ... apk
For such a serious issue there is a lack of clarity on the extent of the problem and what we need to do to mitigate.
1. Does the bug apply to apfs-formatted encrypted disk images?
2. Does the issue persist after the update on volumes/images you have already created? I assume yes, meaning everyone should do what? Just change the password, or does it have to be recreated from scratch?
The 'new' Disk Utlity that has been around since El Capitan is a mess. It had to be updated for reasons apparently, but the old version was far FAR better, to the point that people patched the old verison to run on El Cap, maybe Sierra.
It constantly does weird and wonderful things and has knackered my disk on more than one occasion, leaving me an unbootable machine that I've had to fix via diskutil from Internet Recovery mode.
I'm going to continue using the Host File Engine. Your software is well written, functional. The Host File Engine performs exactly as promised by mmell
his hosts program is actually pretty good by xenotransplant
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg
(APK's) work, I've flat out said it's good by BronsCon
I've tried his hosts file generating software. It works by bmo
APK your posts on this & the hosts file posts, and more, have never been in error &/or bad advice by BlueStrat
Your premise that hostfiles are a good way to deal with advertising & malvertising is quite valid by JazzLad
I like your host file system by Karmashock
(NEED MORE? Ask!)
* It's recommended/hosted by Malwarebytes' hpHosts!
APK
P.S.=> China imitated me http://www.theregister.co.uk/2017/04/26/boffins_supercharge_the_hosts_file_to_save_users_plagued_by_dns_outages/ ... apk
I don't use pirated of Windows or Delphi. THAT lie of yours ="best ya got"? Yes. Like you, It's not squat DontBeAMoran.
* Additionally - Thanks for PROJECTING your own misdoings loser (trying to place them on ME).
APK
P.S.=> You don't have shit to your name (hence your use of UNIDENTIFIABLE anonymous posting)... apk