{"id":4796,"date":"2012-05-06T20:58:25","date_gmt":"2012-05-07T01:58:25","guid":{"rendered":"http:\/\/mjtsai.com\/blog\/?p=4796"},"modified":"2016-06-10T14:41:01","modified_gmt":"2016-06-10T18:41:01","slug":"lion-login-passwords-in-clear-text","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2012\/05\/06\/lion-login-passwords-in-clear-text\/","title":{"rendered":"Lion Login Passwords in Clear Text"},"content":{"rendered":"<p><a href=\"http:\/\/www.zdnet.com\/blog\/security\/apple-security-blunder-exposes-lion-login-passwords-in-clear-text\/11963\">Emil Protalinski<\/a> (via <a href=\"http:\/\/apple.slashdot.org\/story\/12\/05\/06\/1621216\/apple-security-blunder-exposes-lion-login-passwords-in-clear-text\">Slashdot<\/a>):<\/p>\r\n<blockquote cite=\"http:\/\/www.zdnet.com\/blog\/security\/apple-security-blunder-exposes-lion-login-passwords-in-clear-text\/11963\"><p>An Apple programmer, apparently by accident, left a debug flag in the most recent version of the Mac OS X operating system. In specific configurations, applying OS X Lion update 10.7.3 turns on a system-wide debug log file that contains the login passwords of every user who has logged in since the update was applied. The passwords are stored in clear text.<\/p>\r\n<p>Anyone who used FileVault encryption on their Mac prior to Lion, upgraded to Lion, but kept the folders encrypted using the legacy version of FileVault is vulnerable. FileVault 2 (whole disk encryption) is unaffected.<\/p>\r\n<\/blockquote>\r\n<p>User <a href=\"https:\/\/discussions.apple.com\/thread\/3715366\">tarwinator<\/a> posted about this in Apple&rsquo;s support forum three months ago but didn&rsquo;t get a response.<\/p>\r\n<p>Update (2012-05-09): It&rsquo;s <a href=\"http:\/\/www.theverge.com\/2012\/5\/9\/3010155\/os-x-lion-10-7-4-fixes-filevault-password-bug\">fixed<\/a> in Mac OS X 10.7.4.<\/p>\r\n<p>Update (2012-05-10): Apple has posted a <a href=\"http:\/\/support.apple.com\/kb\/TS4272?viewlocale=en_US&amp;locale=en_US\">support article<\/a> about the problem.<\/p>","protected":false},"excerpt":{"rendered":"<p>Emil Protalinski (via Slashdot): An Apple programmer, apparently by accident, left a debug flag in the most recent version of the Mac OS X operating system. In specific configurations, applying OS X Lion update 10.7.3 turns on a system-wide debug log file that contains the login passwords of every user who has logged in since [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"","apple_news_api_id":"","apple_news_api_modified_at":"","apple_news_api_revision":"","apple_news_api_share_url":"","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[],"class_list":["post-4796","post","type-post","status-publish","format-standard","hentry","category-technology"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/4796","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=4796"}],"version-history":[{"count":7,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/4796\/revisions"}],"predecessor-version":[{"id":14788,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/4796\/revisions\/14788"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=4796"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=4796"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=4796"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}