Live data from Hacker News

macOS lock screen: “I just sent my session pass to my whole team”

twitter.com

1–10 of 276 posts

Re: macOS lock screen: “I just sent my session pass to my whole team”

#6
I did something similar too - I was typing in the password while the Mac was being unlocked by the watch using that unlock-with-the-watch feature.

I was used to hammering return a few times to wake the machine up, then typing in the password, then hitting return again.

The few times I hammered return woke the machine, the watch unlocked the mac and the password plus the return key went into the app that had focus which for me also was Slack.

Is it possible that this user had the same thing happen to them? When I disable the watch unlocking, I can't make the password go anywhere but into the login screen (10.13.1 here with last weeks security update applied)

Re: macOS lock screen: “I just sent my session pass to my whole team”

#7
post #3

How about people stop releasing this sh*t on twitter?

Most people not in tech or infosec have never heard of and are totally uneducated about the concept of responsible disclosure. Maybe it needs to be added to high school computer class?

Re: macOS lock screen: “I just sent my session pass to my whole team”

#10
I worked at an open source shop where almost everyone ran Linux and used IRC for chat. For a while I made the mistake of having the screen black time lower than the screensaver timeout, so I'd unlock my screen and see my password go out in IRC. I ended up changing my password to something that looked like a shell command.
Post reply on HN