{"id":21852,"date":"2018-06-18T15:00:30","date_gmt":"2018-06-18T19:00:30","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=21852"},"modified":"2018-06-26T11:03:00","modified_gmt":"2018-06-26T15:03:00","slug":"quick-look-cache-reveals-sensitive-data-from-encrypted-drives","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2018\/06\/18\/quick-look-cache-reveals-sensitive-data-from-encrypted-drives\/","title":{"rendered":"Quick Look Cache Reveals Sensitive Data From Encrypted Drives"},"content":{"rendered":"<p><a href=\"https:\/\/wojciechregula.blog\/your-encrypted-photos-in-macos-cache\/\">Wojciech Regula<\/a>:<\/p>\n<blockquote cite=\"https:\/\/wojciechregula.blog\/your-encrypted-photos-in-macos-cache\/\"><p>I found out that Quicklook registers com.apple.quicklook.ThumbnailsAgent XPC service that is responsible for creating thumbnails database and storing it in <tt>\/var\/folders\/&#8230;\/C\/com.apple.QuickLook.thumbnailcache\/<\/tt> directory.<\/p><p>It means that all photos that you have previewed using space (or Quicklook cached them independently) are stored in that directory as a miniature and its path. They stay there even if you delete these files or if you have previewed them in encrypted HDD or TrueCrypt\/VeraCrypt container.<\/p><\/blockquote><p>Via <a href=\"https:\/\/thehackernews.com\/2018\/06\/apple-macos-quicklook.html\">Swati Khandelwal<\/a>:<\/p><blockquote cite=\"https:\/\/thehackernews.com\/2018\/06\/apple-macos-quicklook.html\"><p>Patrick Wardle, chief research officer at Digital Security, equally shared the concern, saying that the issue has long been <a href=\"http:\/\/osxdaily.com\/2010\/07\/25\/filevault-and-quicklook-leak-some-information-from-encrypted-volumes\/\">known<\/a> for at least eight years, &ldquo;however the fact that behavior is still present in the latest version of macOS, and (though potentially having serious privacy implications), is not widely known by Mac users, warrants additional discussion.&rdquo;<\/p><p>[&#8230;]<\/p><p>In a separate <a href=\"https:\/\/objective-see.com\/blog\/blog_0x30.html\">blog post<\/a>, Wardle demonstrated that macOS behaves same for the password-protected encrypted AFPS containers, eventually exposing even encrypted volumes to potential snooping.<\/p><\/blockquote>\n<p>This also affects third-party applications such as <a href=\"https:\/\/c-command.com\/forums\/showthread.php\/5317-Quick-Look-Cache-Reveals-Sensitive-Data-From-Encrypted-Drives\">EagleFiler<\/a> that use Quick Look to display images.<\/p>\n\n<p>Update (2018-06-20): See also: <a href=\"https:\/\/www.macrumors.com\/2018\/06\/18\/macos-quick-look-encrypted-data-bug\/\">MacRumors<\/a>, <a href=\"https:\/\/apple.slashdot.org\/story\/18\/06\/18\/1336248\/macos-breaks-your-opsec-by-caching-data-from-encrypted-hard-drives\">Slashdot<\/a>, <a href=\"https:\/\/www.zdnet.com\/article\/macos-quick-look-bug-leaks-encrypted-data-researchers-find\/\">ZDNet<\/a>.<\/p>\n\n<p>Update (2018-06-25): <a href=\"https:\/\/twitter.com\/objective_see\/status\/1010042118730145793\">Patrick Wardle<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/objective_see\/status\/1010042118730145793\">\n<p>Want to disable Quick Look from caching your sensitive files?<\/p>\n<pre>$ qlmanage -r disablecache<\/pre>\n<\/blockquote>\n\n<p><a href=\"https:\/\/eclecticlight.co\/2018\/06\/25\/control-your-quicklook-cache-with-aquiline-check-1-0b2-and-aquiliner-for-your-menubar\/\">Howard Oakley<\/a>:<\/p>\n<blockquote cite=\"https:\/\/eclecticlight.co\/2018\/06\/25\/control-your-quicklook-cache-with-aquiline-check-1-0b2-and-aquiliner-for-your-menubar\/\">\n<p>I am delighted to offer an update to improve my new tool for managing your QuickLook (or Quick Look) cache, Aquiline Check.<\/p>\n<\/blockquote>\n\n<p>Update (2018-06-26): <a href=\"https:\/\/eclecticlight.co\/2018\/06\/26\/hidden-caches-in-macos-where-your-private-data-gets-stored\/\">Howard Oakley<\/a>:<\/p>\n<blockquote cite=\"https:\/\/eclecticlight.co\/2018\/06\/26\/hidden-caches-in-macos-where-your-private-data-gets-stored\/\">\n<p>Here is a brief overview of some of the potentially sensitive information which macOS secretes away in unexpected places.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Wojciech Regula: I found out that Quicklook registers com.apple.quicklook.ThumbnailsAgent XPC service that is responsible for creating thumbnails database and storing it in \/var\/folders\/&#8230;\/C\/com.apple.QuickLook.thumbnailcache\/ directory.It means that all photos that you have previewed using space (or Quicklook cached them independently) are stored in that directory as a miniature and its path. They stay there even if [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2018-06-26T15:03:03Z","apple_news_api_id":"66d34397-b6a6-4bae-9443-82e4235f2182","apple_news_api_modified_at":"2018-06-26T15:03:04Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAABA==","apple_news_api_share_url":"https:\/\/apple.news\/AZtNDl7amS66UQ4LkI18hgg","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[],"tags":[131,595,30,1529,355,1103],"class_list":["post-21852","post","type-post","status-publish","format-standard","hentry","tag-bug","tag-eaglefiler","tag-mac","tag-macos-10-13","tag-privacy","tag-quick-look"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/21852","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=21852"}],"version-history":[{"count":6,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/21852\/revisions"}],"predecessor-version":[{"id":21930,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/21852\/revisions\/21930"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=21852"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=21852"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=21852"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}