TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

APFS encrypted plaintext password found in another log file

171 pointsby chmarsabout 7 years ago

9 comments

oneplaneabout 7 years ago
This is rather crappy QA or the lack of verification of the QA process at Apple. I really hope they pick up the slack they have been forming over the past ~5 years, it's starting to get predictably bad.
评论 #16724519 未加载
评论 #16725288 未加载
评论 #16725030 未加载
radicaldreamerabout 7 years ago
There are so many security holes in the latest MacOS release, I’m wondering if it’s currently the least secure desktop OS.<p>Vulnerabilities are one thing but these issues are simple enough for non-technical end users to exploit on anyone’s computers.
评论 #16723819 未加载
评论 #16723798 未加载
评论 #16724933 未加载
post_breakabout 7 years ago
This is just embarrassing. It&#x27;s not like Apple is spread so thin because of poor sales or a corporate shake up. There&#x27;s really no excuse for all of these core bugs.
评论 #16723919 未加载
konceptzabout 7 years ago
Before we just jump on Apple we should probably see if we can recreate the issue.<p>The article stated that another user could not replicate this issue and the original researcher was also unable to replicate after a possible stealth update.
评论 #16724096 未加载
评论 #16724668 未加载
评论 #16723984 未加载
评论 #16724170 未加载
评论 #16724427 未加载
justincormackabout 7 years ago
There are definitely some issues with files ending up with contents of other files, particularly with sparse files and nearly full disks, presumably due to new allocations not being zeroed. Hard to replicate, but not impossible. We filed a bug and it was closed as a duplicate. Possibly fixed in todays 10.3.4 release, can&#x27;t confirm yet.
评论 #16726029 未加载
crankylinuxuserabout 7 years ago
So, is the iPhone full of these as well?<p>Has anyone did a public audit of the leaked secure enclave firmware? I know there&#x27;s that company who sells the black haxx0r boxes for $15k or $30k.<p>Long question short: do we have a secure cell we can buy&#x2F;make?
评论 #16724179 未加载
评论 #16725537 未加载
评论 #16724176 未加载
评论 #16723883 未加载
llaoabout 7 years ago
So, did no one grep -R --as-text &quot;my password&quot; &#x2F; before?
评论 #16724355 未加载
ams6110about 7 years ago
Good illustration of why command line utilities should not take passwords as a parameter. They should always be provided as prompted input or via a pipe if it needs to be scripted.
fwgwgwgchabout 7 years ago
I was planning to ditch my android for iPhone but reports like this make me worried.<p>Can we have a reasonable discussion without fanboy ism about what is the most secure phone right now?<p>(reply only if you have a security background)
评论 #16723999 未加载
评论 #16725544 未加载