Apple shutters FileVault password hole

Powered by SC Magazine
 

Urges users to mop up logs.

Apple has patched an OS X flaw that enabled FileVault passwords to be viewed in clear text.

The flaw (CVE-2012-0652) meant that a debugging feature would log OS X Lion passwords but only under specific conditions.

Those logs would detail clear text legacy FileVault passwords for every user who logged in since the update was applied.

It was introduced in the update 10.7.3.

And while the latest update 10.7.4 fixed the issue, already captured passwords may not be erased. “The sensitive information may persist in saved logs after installation of this update,” Apple said in its notice.

Apple recommended users remove logged passwords by first updating OS X, changing user account passwords, then running in Terminal:

sudo srm --force --simple /var/log/secure.log

sudo srm --force --simple /var/log/secure.log.{0,1,2,3,4,5}.bz2

find -xX /var/log/asl | grep ".U0.G80" | xargs sudo srm --force --simple

The OS X log-in screen was not enough to safeguard logged passwords.

Security researcher David Emery pointed out that attackers could bypass the log-in screen by “booting the machine into firewire disk mode and reading it by opening the drive as a disk or by booting the new-with-LION recovery partition and using the available superuser shell to mount the main file system partition”.

Copyright © SC Magazine, Australia


Apple shutters FileVault password hole
 
 
 
Top Stories
Earning the right to innovate
Breaking down the barriers to innovation is a long, but rewarding process, says Bank of Queensland Group CIO, Julie Bale.
 
A call for timely reporting
[Blog post] Businesses need incentives to keep customer data secure.
 
Doubts cast on Queensland's ICT Dashboard
Opposition, former Govt CIO say it can't be trusted.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  25%
 
Application integration concerns
  3%
 
Security and compliance concerns
  29%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  23%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  5%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 823

Vote