NEWS - May 07, 2012
by Carol~
- 5/7/12 6:44 AM
Apple Engineering Mistake Exposes Clear-text Passwords for Lion
Apple's latest update to OS X contains a dangerous programming error that reveals the passwords for material stored in the first version of FileVault, the company's encryption technology, a software consultant said.
David I. Emery wrote on Cryptome that a debugging switch inadvertently left on in the current release of Lion, version 10.7.3, records in clear text the password needed to open the folder encrypted by the older version of FileVault.
Users who are vulnerable are those who upgraded to Lion but are using the older version of FileVault. The debug switch will record the Lion passwords for anyone who has logged in since the upgrade to version 10.7.3, released in early February.
"This is what the secure FileVault partition was supposed to protect against after all," Emery said in an interview.
Apple has two versions of FileVault. The first version allowed a user to encrypt the contents of the home folder using the Advanced Encryption Standard (AES) with 128-bit keys. An upgraded product, FileVault 2, which shipped with OS X Lion, encrypts the entire content of the hard drive.
Continued : http://www.pcworld.com/businesscenter/article/255104/apple_engineering_mistake_exposes_cleartext_passwords_for_lion.html
Also:
Apple update to OS X Lion exposes encryption passwords
Mac OS X leaking passwords of FileVault users

Moderator
CNET Staff
Samsung Staff
Dell Staff