Apple quickly updates a vulnerability in macOS High Sierra that showed the password for encrypted SSDs

As usual, each time a new version of an operating system is launched, little by little, small or large errors are found in their operation. As soon as iOS 11.0 was released, Outlook users were found to be unable to configure their accounts in the Mail app, an issue that was fixed last week with an update. Now it is the turn of macOS High Sierra. Developer Matheus Mariano has discovered a vulnerability that affects only encrypted SSDs and that have been formatted with the new macOS High Sierra operating system, APFS.

As we can see in the video above, when we format a drive in APFS and add an encryption password, the system recommends using a hint to be able to remember it in case of forgetting. But as we can see, if we need the help of this track, instead of showing the hint needed to remember the password, what is displayed is the password itself.

As I mentioned above, this security problem, only affects SSDs that have been encrypted, so if it is not your case, it does not affect you at all. It also does not affect mechanical hard drives or the so-called Fusion Drive, since none of these models is compatible with the new file system, although the latter will do so shortly, according to Apple a few days ago.

This error It is only shown if we use Disk Utility to remember the encryption password, since if we carry out this process by means of commands through Terminal, the result that is displayed is the hint and not the password as it happens with Disk Utility. On this occasion, Apple has been very quick to launch the corresponding update to macOS High Sierra that solves this security problem.


Buy a domain
You are interested in:
The secrets to launching your website successfully

Leave a Comment

Your email address will not be published. Required fields are marked with *

*

*

  1. Responsible for the data: Miguel Ángel Gatón
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.

  1.   Alberto Guerrero placeholder image said

    They would have to be much more careful with these types of failures.