TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

High Sierra vulnerability exposes the password of an encrypted APFS container

36 点作者 cimnine超过 7 年前

4 条评论

jmdocherty超过 7 年前
Glass half-full: &quot;Oops! They missed this because they were busy making all the other stuff super-secure.&quot;<p>Glass half-empty: &quot;Oh-my-goodness...what would Steve say? FFS. We can&#x27;t trust anyone any more!&quot;<p>I&#x27;m inclined to be half-full.
评论 #15409525 未加载
jchw超过 7 年前
So... it stores the password as a password hint?<p>One must wonder how Apple&#x27;s QA process didn&#x27;t catch something as egregious as that in a piece of security code.
评论 #15409823 未加载
jaclaz超过 7 年前
It is now officially acknowledged by Apple (though they don&#x27;t seem like treating it as a bug):<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15410953" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15410953</a><p><a href="https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT208168" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT208168</a>
runesoerensen超过 7 年前
<i>&quot;Creating a volume via diskutil, the hint, not the pw is shown. Looks like the root cause is Disk Utility storing the password as hint.&quot;</i><p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;felix_schwarz&#x2F;status&#x2F;915857500330700801" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;felix_schwarz&#x2F;status&#x2F;915857500330700801</a>