Live data from Hacker News

Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes

mac4n6.com

71–80 of 123 posts

Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes

#71
post #22

Earlier quoted context omitted.

Sloppy and marketed as a stability build. There were hardly any new features in it.

Yeah, they just deployed a whole new FS to 100s of millions of users, in record time, with almost zero incidents. Hardly any new features...

You have to give Apple credit that they showed some restraint and didn't just add all the features to their new file system that they found in a table on some Wikipedia page.

https://en.wikipedia.org/w/index.php?title=Comparison_of_fil...

Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes

#72
post #58

What exactly happened to macOS development at Apple? There's always bad luck but Apple has had multiple very visible and very serious vulnerabilities over the last few quarters. They've made multiple grave errors with encrypted volumes. I don't think Microsoft with Bitlocker or Linux with dm-crypt has ever made mistakes as bad as Apple has made here and multiple other times. Forget the stability issues, a lot of the…

My theory: the NeXT developers who were around for osx v10.0 and around then have all retired.

Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes

#73
post #58

What exactly happened to macOS development at Apple? There's always bad luck but Apple has had multiple very visible and very serious vulnerabilities over the last few quarters. They've made multiple grave errors with encrypted volumes. I don't think Microsoft with Bitlocker or Linux with dm-crypt has ever made mistakes as bad as Apple has made here and multiple other times. Forget the stability issues, a lot of the…

You don't even need to look at security vulnerabilities to wonder what happened to macOS development at Apple.

My wife recently bought a mighty mouse. It worked for a few days, but then macOS would fail to associate with it via Bluetooth unless it's plugged in via the lightning cable, in which case it's unusable, the connector being on the side that normally sits on the table.

Anyways, after a quick Google, I found a workaround that I couldn't believe would work, but I tried it anyways: open preferences, and check off "Allow Handoff between this Mac and your iCloud devices". ... and it worked instantly.

My wife doesn't even have an iCloud account...

The problem (and workaround) has been known for at least 4 years.

Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes

#74
post #55
post #6

That's pretty bad. It's been known for decades on other Unix systems that you shouldn't pass passwords by command line parameter, or even support doing so. I guess no-one told Apple.

Not to disagree, but could you provide some references to the statement?

>> It's been known for decades on other Unix systems that you shouldn't pass passwords by command line parameter

> could you provide some references to the statement?

If you search the Usenet archives, you can find many discussions about this. It's one of those topics that came up frequently in the comp.unix newsgroup as early as 1991 that I see in some messages.

Usenet discussion from 1994:

"ps e gets you a processes environment. It is totally unsafe to store anything that should be secret. if there needs to be secret data, the best way to get it is with scanf(), once the program is running."[1]

And here is the Secure UNIX Programming FAQ from 1999:

"A security hole related to FreeBSD's 'ps' utility. The utility would allow users to view another process' environment variables. Consequently applications like pppd that accepted passwords via environment variables became vulnerable to unauthorized release of privileged information attacks. In fact, thehole was not related to 'ps' if you think about it critically. The application that places privileged information in the environment variable is at fault."[2]

[1]https://groups.google.com/forum/m/#!search/ then search for "ps shows command line parameters" (for the exact message, search for "ps e gets you a processes environment")

[2]http://faqs.cs.uu.nl/na-dir/unix-faq/programmer/secure-progr...

Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes

#75
post #69

Earlier quoted context omitted.

Lots of Mac users wait before they upgrade. (Myself included) I recently looked at stats for my app, and only around 60% of my users are on 10.13, 30% on 10.12, and 10% on older versions. If you use your Mac professionally, there‘s no point in updating every year — it‘s always a hassle and a few weeks of upgrading 3rd party software and fixing random things that don‘t work any more.

It seems quite a lot of people around here have a thing for El Capitan. Coincidentally this is the last one called "OS X".

Confirm. El Capitan is the last good and stable version.

Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes

#76
post #70
post #68

Earlier quoted context omitted.

> with almost zero incidents. Sparse files are hopelessly broken, prompting Docker for Mac to roll back to qcow2 when using APFS[0] (HFS+ sparse files are fine). [0]: https://docs.docker.com/docker-for-mac/release-notes/#docker... EDIT: reference

HFS+ sparse files - now that’s a contradiction in terms.

HFS+ sparse images, sorry (not quite the same as sparse files, but here DfM uses sparse files are used to create a raw image, so I wanted to lift some possible confusion, and tripped on)

Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes

#77

Earlier quoted context omitted.

https://appletoolbox.com/2018/01/disable-macos-software-upda...

You rock, thank you very much. Shame on Apple for the "control click on a hidden control" design pattern in order to stop the update messages. After not seeing an option to hide it, my morning ritual lately had consisted of clicking "Details" button and then quickly CMD+Q'ing out of the MAS dialog that popped up. Glad it's finally disabled, but really kind of ridiculous that it was literally a hidden option.

Actually, I just tested this. And it's not a control-click, it's a right click. The person that wrote it probably uses the old control click to right click paradigm.

Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes

#78
post #32
post #22

Earlier quoted context omitted.

Yeah, they just deployed a whole new FS to 100s of millions of users, in record time, with almost zero incidents. Hardly any new features...

What new features do users gain from the new file system?

The main feature is that it is a modern filesystem that doesn’t carry around 25 years of baggage.

Re: Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes

#79
.... in a galaxy far far away ... an egocentric narcisistic CEO with a god complex and hell-of-a-neck for usability would never agree with the full extent of what "external forces" were requesting from his company. Getting rid of him led to mistakes he'd never allowed to happen. But that's the price you have to pay when you are (due to product demographics aot) sitting on the most valuable private data in the world..not even a neverending chain of government-funded privacy PR stunts could make a difference.

/end

As a new-ish iOS mobile user, I was very dissapointed

Post reply on HN