OS X plain text password flaw has been around for 3 months and counting
A security flaw in the most recent version of OS X Lion, 10.7.3, can allow anyone with access to system logs to gather passwords to decrypt legacy FileVault home directories or access remote home directories of networked users. Though the flaw was first discovered a whopping three months ago, it has been widely publicized after a security researcher posted details of the flaw to a cryptography mailing list on Friday.
While only users with admin or root access could access the passwords stored as plain text in the log files, it's possible that malware could be created to look into the file for any passwords in order to access personal data.
The security implications are even worse, though, according to security researcher David Emery. "The [system] log in question can also be read by booting the machine into firewire disk mode and reading it by opening the drive as a disk or by booting the new-with-Lion recovery partition and using the available superuser shell to mount the main file system partition and read the file," he wrote to the cryptography e-mail list on Friday. "This would allow someone to break into encrypted partitions on machines they did not have any idea of any login passwords for."
Read the comments on this post
computer repair kansas city mo computer repair kansas city ks computer repair kansas city north computer repair kansas city missouri


0 Comments:
Post a Comment
Subscribe to Post Comments [Atom]
<< Home