Fixed in 10.13.2 - but wow, was High Sierra ever a sloppy release.
Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
11–20 of 123 posts
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#12Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#13Please don't link to mac4n6, it serves malware on some page loads. The article author is aware of it but apparently doesn't have the ability to fix the issue
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#14That's pretty bad. It's been known for decades on other Unix systems that you shouldn't pass passwords by command line parameter, or even support doing so. I guess no-one told Apple.
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#15Please don't link to mac4n6, it serves malware on some page loads. The article author is aware of it but apparently doesn't have the ability to fix the issue
What kind of malware did you run into?
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#16Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#17Please don't link to mac4n6, it serves malware on some page loads. The article author is aware of it but apparently doesn't have the ability to fix the issue
Not calling you out but I'd like to see a source for this. A quick web search for mac4n6 malware didn't turn up anything.
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#18Please don't link to mac4n6, it serves malware on some page loads. The article author is aware of it but apparently doesn't have the ability to fix the issue
After doing a quick sweep of the network and processes, I didn't find anything overtly malicious (unless you count 6 MB pages for a blog, 150k lines for squarespace's JS, and 3000 rules over 400KB).
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#19That's pretty bad. It's been known for decades on other Unix systems that you shouldn't pass passwords by command line parameter, or even support doing so. I guess no-one told Apple.
Exactly. More to the point, even if it doesn't log it any more, I bet it's still on the command line itself.
Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes
#20Please don't link to mac4n6, it serves malware on some page loads. The article author is aware of it but apparently doesn't have the ability to fix the issue
Not calling you out but I'd like to see a source for this. A quick web search for mac4n6 malware didn't turn up anything.