Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le mai 07, 2012, 23:00:05

Titre: [ThreatPost]Flaw in OS X Lion Encryption Leaves User Credentials in Plaintext
Posté par: igor51 le mai 07, 2012, 23:00:05
Flaw in OS X Lion Encryption Leaves User Credentials in Plaintext

<p><a href="https://threatpost.com/en_us/blogs/flaw-os-x-lion-encryption-leaves-user-credentials-plaintext-050712"><img src="https://threatpost.com/sites/default/files/lionsecurity.jpg" alt="" title="" style="float: right;" border="0" height="107" width="145" /></a>There's a serious weakness in certain versions of Apple OS X that causes the operating system to store users' login credentials for the FileVault encrypted storage in plaintext. The bug, which is found in older versions of FileVault present on OS X Lion 10.7.3 systems, enables anyone with admin access to the machine to get the login password for the FileVault system. The flaw also can be exploited when a machine is in FireWire disk mode and accessible to another computer.</p><p><a href="http://threatpost.com/en_us/blogs/flaw-os-x-lion-encryption-leaves-user-credentials-plaintext-050712" target="_blank">read more</a></p>
Source: Flaw in OS X Lion Encryption Leaves User Credentials in Plaintext (http://threatpost.com/en_us/blogs/flaw-os-x-lion-encryption-leaves-user-credentials-plaintext-050712)