Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
1–10 of 123 posts
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#2Fixed in 10.13.2 - but wow, was High Sierra ever a sloppy release.
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#3Fixed in 10.13.2 - but wow, was High Sierra ever a sloppy release.
It’s appallingly sloppy. I can’t say I’m regretting my switch to essentially holding off on major OS upgrades until just before the next one is released. I wish Xcode’s current version still supported the most recent two OS versions, though.
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#4Fixed in 10.13.2 - but wow, was High Sierra ever a sloppy release.
The post mentions that it's also back in some cases on 10.13.3 - which is probably why this post came back up
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#5Fixed in 10.13.2 - but wow, was High Sierra ever a sloppy release.
> This is still vulnerable on current versions of macOS 10.13.3 when encrypted an ALREADY EXISTING unencrypted APFS volume
Only partially.
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#6That's pretty bad. It's been known for decades on other Unix systems that you shouldn't pass passwords by command line parameter, or even support doing so. I guess no-one told Apple.
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#7Please don't link to mac4n6, it serves malware on some page loads. The article author is aware of it but apparently doesn't have the ability to fix the issue
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#8Please don't link to mac4n6, it serves malware on some page loads. The article author is aware of it but apparently doesn't have the ability to fix the issue
What kind of malware did you run into?
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#9Please don't link to mac4n6, it serves malware on some page loads. The article author is aware of it but apparently doesn't have the ability to fix the issue
Not calling you out but I'd like to see a source for this. A quick web search for mac4n6 malware didn't turn up anything.
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#10That's pretty bad. It's been known for decades on other Unix systems that you shouldn't pass passwords by command line parameter, or even support doing so. I guess no-one told Apple.
Exactly. More to the point, even if it doesn't log it any more, I bet it's still on the command line itself.