2 min read

Apple fixes flaw that displayed actual password rather than password hint

Graham CLULEY

October 06, 2017

Apple fixes flaw that displayed actual password rather than password hint

If you’re running macOS High Sierra on your desktop or laptop, stop right now and make sure you have applied the latest security update.

Yesterday, Apple released a free supplemental update to macOS High Sierra 10.13 – just over one week since the general release of the operating system.

As an Apple support knowledgebase article explains, macOS High Sierra shipped with a potentially disastrous security hole in its Disk Utility tool that could have allowed anyone to access encrypted Apple File System (APFS) volumes.

As Brazilian developer Matheus Mariano discovered , a bug in the operating system’s code meant that clicking on the “Show Hint” button when attempting to access an encrypted volume would *not* display the password hint as you would expect.

Instead, it would display the actual plaintext password for the volume.

In short, if you don’t know the password don’t panic. Just hit the password hint button and the operating system will tell you.

Mariano demonstrated the security flaw in a YouTube video:

According to Apple, the password can be displayed instead of the password hint if you use Disk Utility to add an encrypted APFS Volume, and you supplied a password hint.

Fortunately, the new supplemental update patches macOS High Sierra 10.13 – as well as against other bugs, including a zero-day flaw that could allow a malicious attacker to steal passwords from the Keychain.

The update can be easily downloaded and applied using the Software Update functionality within the Mac App Store.

In its knowledgebase article, Apple recommends that after updating macOS High Sierra you go through a process to erase and recreate affected encrypted APFS volumes

To its credit, Apple issued a fix for the password-revealing bug very quickly, and its responsiveness in addressing this issue should be applauded. However, that doesn’t change the fact that such a serious bug like this really should have been intercepted during its quality control process, rather than allowed to ship to millions of computers around the world.

tags


Author



Right now

Top posts

Ultimate Privacy Guide for Your Facebook Account

Ultimate Privacy Guide for Your Facebook Account

August 31, 2021

6 min read
7 Signs It’s Time to Use Parental Controls On Your Family’s Devices

7 Signs It’s Time to Use Parental Controls On Your Family’s Devices

August 27, 2021

2 min read
Your Netflix Account May Be on Sale on Darkweb. Protect It

Your Netflix Account May Be on Sale on Darkweb. Protect It

August 13, 2021

3 min read
E-mails claiming your computer was hacked and your privacy exposed - what you need to know (spoiler: you can relax - they’re bluffing)

E-mails claiming your computer was hacked and your privacy exposed - what you need to know (spoiler: you can relax - they’re bluffing)

July 29, 2021

5 min read
Watch Out for These Ongoing Bank of America Phishing Campaigns Targeting Customers in the US

Watch Out for These Ongoing Bank of America Phishing Campaigns Targeting Customers in the US

July 16, 2021

3 min read
How to protect yourself against cyberstalking

How to protect yourself against cyberstalking

July 06, 2021

2 min read

FOLLOW US ON

SOCIAL MEDIA


You might also like

Microsoft Drops Password Authentication for Most Products Microsoft Drops Password Authentication for Most Products
Silviu STAHIE

September 16, 2021

1 min read
Apple Rolls Out Urgent Patch for Zero-Day Flaws in iOS, macOS and watchOS Apple Rolls Out Urgent Patch for Zero-Day Flaws in iOS, macOS and watchOS
Filip TRUȚĂ

September 14, 2021

2 min read
WhatsApp Users Get Option to Encrypt Backups WhatsApp Users Get Option to Encrypt Backups
Silviu STAHIE

September 13, 2021

1 min read