8 ms·
Apple security blunder exposes Lion login passwords in clear text
- joshmlewis 14y agoSo are there literally security researchers that go and poke around of every release of everything major in the software industry to find things like this?
- amalter 14y agoYes, they are called "hackers" .. Especially the black hat kind.
- stcredzero 14y ago> There literally security researchers that go and poke around of every release of everything [snip] in the software industry to find things like this Fixed.
- ams6110 14y agoThere are. It's the main reason why "security through obscurity" isn't a good idea. There are people who spend their working days searching for this kind of stuff. Log files are probably one of the first places they would look for clues.
- skeletonjelly 14y ago`grep password` isn't the hardest thing to do either
- toemetoch 14y agoIt's actually a very lucrative business if you keep the security bugs secret and sell them on the market. Google "Vupen" for an example.
- greedo 14y agoYep. Some are white hats hoping to either make money or reputation by discovering flaws. Don't think that these flaws don't get discovered; sometimes pentest experts discover flaws and keep them in their arsenal for a particularly difficult assessment. Other times, it's a blackhat who discovers them and sells them in the underground world. If you want to experience a jolt, visit www.exploitdb.com and search for vulnerabilities in your favorite software. And be sure that for every exploit listed, there are a few that are kept hush hush.
- Xuzz 14y agoNote: only applies to people using the old "FileVault" on Lion, not the new "FileVault2" (the one with full-disk encryption).
- sliverstorm 14y agoGo on, let's hear about how devoted Apple is to security again.
- ams6110 14y agoSeems more like a QA problem to me, there should be some tests in the QA of a final release build that makes sure all the debug flags are turned off.
- eblume 14y agoYeah, that seems like a no-brainer to me. Even my company's small 2-person software 2-person QA team has a release test to make sure all debug parameters are shut off. The software won't even run if a debug parameter is on without some special shim that only us devs have.
- sliverstorm 14y agoThat's my point. "Security" is a complete package, that includes good QA.
- DanBC 14y agoIt's a bit worrying that people noticed this 3 months ago, and there have been no fixes.
- DenisM 14y agoYou could have made the same point in a less inflammatory way. Next time, please do.
- sliverstorm 14y agoApologies. Sometimes it just seems I can only catch the attention of the zealots with something a little inflammatory.
- sbuk 14y agoWhy "catch the attention of the zealots" at all? Isn't that just an admission of trolling?
- greghinch 14y agoWhile I agree that this is a security hole and it should be fixed, a headline like that is completely misleading and a scare tactic to drive eyeballs to the article. This flaw only would affect a very small subset of users, but the headline makes it sound like everyone just had their passwords compromised
- sceptre 14y agoThe headline is straight forward. I guess you are looking at it from a fanboi perspective.
- sakopov 14y agoWhat I got out of the article seems to be more important than the number of users this could impact. 1. A vital piece of the operating system was compiled with debug flags intact. 2. Apple's lack of response on the issue. I think this goes hand-in-hand with recent Kaspersky statement about Apple's poor security considerations.
- bilbo0s 14y agoThose are definitely the two 'take-aways'. If there is a hole here... there may be other holes that might be REAL security threats. Other people are correct as well, in that the headline is link bait. I was expecting to find a way to get clear text passwords from my test OSX Lion setup. I can't actually do that on my test system, and I'd wager the vast majority of hackers can't pull that off either. At least not without changing the setup. Of course... probably my fault for believing you could.
- tptacek 14y agoI can't name a single person who ever used "Legacy Filevault"; that's the "encrypt your home directory" thing from Leopard. This issue doesn't impact Lion FDE at all. Lots of people use Lion FDE. Even the subhed on this story is misleading, and the lede paragraph seems to go out of its way to bury the true article lede, which is "if you're using FileVault home directory encryption, this impacts you" --- instead, it says "in specific configurations". More generally: can anyone name a single case where ZDNet has broken a story we cared about? Even in this case, ZDNet is rehashing stuff published elsewhere earlier.
- Tloewald 14y agoI don't know about breaking stories anyone cares about, but sometimes they post stories I find interesting, just never about Apple
- mrich 14y agoI find it interesting how Apple is defended when they make security blunders, while Microsoft was heavily slammed back in the day. It is simply inacceptable that a user basically reported the issue on their support forum and didn't even get an answer back.
- joejohnson 14y agoThe parent comment isn't defending Apple; @tptacek is pointing out that this issue won't impact a large number of users, that the headline is misleading, and that maybe ZDNet is sensationalizing a minor issue.
- mrich 14y agoIt sounded defensive to me. "name a single case where ZDNet has broken a story we cared about" sounded like ZDNet should have shut up about this very important issue. It doesn't matter that they are not the first reporting it, their readers may thank them for it.
- 14y ago
- millzlane 14y agoSteve called, he said "Just don't use it that way". On a serious note, this has happened before. This is just the first time anyone has caught it before a patch. The QA at Apple is pretty noteworthy.
- thespin 14y agoI thought FireWire was being phased out. (Doubtfully due to security considerations. If I recall, Intel has something faster that uses a USB port.) I have some older hardware, which was state of the art when I bought it, that uses FW. Is FW going to go the way of PCMCIA and CardBus?
- bodyfour 14y ago"Target mode" also works with Thunderbolt. In fact it used to work with SCSI as well; it far predates OS/X as a feature on Macs. It doesn't work over USB though. The stuff in the article about Firewire mode being involved is really a red herring. You would have the same problem if your stolen laptop were opened up and the harddrive removed. Firewire target mode is just a less-invasive way of doing the same thing.
- 0x0 14y agoBTW, another curious part of firewire (unrelated to target mode) is that a firewire device can read and write RAM from a running PC, without interaction. Even when you have "locked the workstation". Random google link: http://www.hermann-uwe.de/blog/physical-memory-attacks-via-firewire-dma-part-1-overview-and-mitigation http://www.hermann-uwe.de/blog/physical-memory-attacks-via-f...
- st3fan 14y agoNot possible anymore on locked (screen saver, login screen) Macs with Lion's FDE enabled.
- thespin 14y agoThat's what I was thinking of when I mentioned security. Maybe it's irrelevant to this story, but I thought it was interesting when I read it.
- bodyfour 14y agoYes, a firewire has the ability to do whatever DMA requests it wants. This is a thruput advantage (especially when processors were slower) since the host CPU only has to set up the data transfer and the rest can happen in hardware. Back in the day, FW400 would beat USB2 in most benchmarks even though the raw bandwidth of USB2 is 20% higher. The solution to this is to use an IOMMU, which protects memory from DMA traffic just like the CPU's MMU protects it from userland processes. However, I don't know if any current Mac laptops do this. Thunderbolt, ExpressCard, and PCMCIA ports have the same issue although it'd require some fancier hardware to exploit. I think SD cards as well, but I'm not 100% sure about that. USB isn't vulnerable to this because the protocol is more like a network card: devices send you packets rather than initiating direct DMA.
- zobzu 14y agoOriginal link: (not zdnet) http://cryptome.org/2012/05/apple-filevault-hole.htm http://cryptome.org/2012/05/apple-filevault-hole.htm
- vectorpush 14y agoOnly slightly related, but this thread bears a striking resemblance to another HN exploit discussion: http://news.ycombinator.com/item?id=3925452 http://news.ycombinator.com/item?id=3925452 The exact same back and forth: Wow! This is really bad... but it only affects a small subset of users... but they knew about it for months and didn't fix it... come on, nobody real actually uses such a setup... what about me... you're all fanboys, this is just another example of how your religion doesn't hold security as a core tenant among its faithful.
- remixhacker 14y agothe Console Message Inspector is pretty useful, it shows a lot of stuff that is normally hidden.
- robomartin 14y agoDoes anyone else thing that it is slimy for ZDNet interpret clicks to the site background as the user clicking the ad below the nav-bar? As an advertiser I would feel defrauded. Not one person clicking on the background is doing so out of interest in the advertiser's product. How common is this practice?
- sp332 14y agoI'm definitely not seeing that behavior. There was a pop-over ad that I had to skip though. I guess if that were malfunctioning / transparent, you wouldn't realize there was an ad frame hovering over the text?
- robomartin 14y agoPerhaps I wasn't clear. It's not the white background, it's the patterned background to the right and left of the content area. To be more precise, they have two div's with class "skinClick" setup on the right and left of the "content" div. You click on either one of those and it's the same as having clicked on the ad just below the nav-bar. I tested in Safari, Firefox, IE and Chrome, same behavior. There's also the "Wait, your page is loading" popup ad you mentioned.
- sp332 14y agoOh, I see. Sorry my browser window wasn't that wide, I didn't even notice that background.