Apple issued an update for its High Sierra desktop operating system on _____ are likely to have a history of eroticized cross-dressing in childhood and adolescence.Thursday.
Called the "macOS High Sierra 10.13 Supplemental Update," the new update fixes two dangerous bugs in High Sierra, both of which exposed user passwords in some way.
SEE ALSO: Whoops, a hacker found a way to steal your passwords from macOS High SierraNaked Security has a great technical explanation of the first bug Apple fixed with the High Sierra update. In the simplest of terms, with the bug, if you created a new APFS (Apple File System) encrypted volume on High Sierra, and set anything at all as the password hint, then your password was stored as the hint. In plain text.
That means anyone could've gotten your password simply by clicking on the "Show Hint" button.
Interestingly, if you didn't choose anything as your password hint, you were safe.
The bug did require an attacker to have physical access to one's encrypted volume, like a drive on your MacBook or a USB stick. But this is not one of those bugs that requires a highly technical exploit: Apple literally handed out your encrypted disk's password to everyone, with one click of a mouse.
The bug was discovered by security expert Matheus Mariano on Sept. 27, and the collective response it got from experts was one of disbelief.
This Tweet is currently unavailable. It might be loading or has been removed.
If you have an encrypted APFS volume, check whether your password hint displays your password. If it does, we've got more bad news: Fixing this isn't all that simple.
Per Apple's official explanation, you need to install the 10.13 High Sierra update from App Store, backup the data from the affected volume, unmount and erase the affected volume, reformat it as new APFS volume, encrypt it, choose a new password (hint optional), and then restore your data to the volume. Ouch.
Additionally, if you used that same password (the one you used for an affected encrypted APFS volume), you should change that as well.
Thursday's High Sierra update also fixes another nasty High Sierra bug, which we've written about in September. That particular issue allowed a malicious attacker to extract all your keychain passwords with an unsigned app.
While we're glad these bugs are now squashed, we certainly hope we won't see any such glaring omissions in Apple's software in the future.
Topics Apple Cybersecurity
'Stranger Things' reveals Season 2 plot details, where the characters are nowJohn F. Kennedy could give off serious serial'Stranger Things' reveals Season 2 plot details, where the characters are nowIndia plans to rename all its airports and it makes a lot of senseGordon Ramsay delivers Twitter food reviews with classic brutalityNamibia has joined Europe in mocking Trump and it's glorious'Shooting Stars' meme blends epic fails with one electro track and it's taking overWill going public ruin Snapchat?'Stranger Things'Amazon's Echo Tap gets the one feature it should have had all alongMashReads Podcast: 'Universal Harvester'Verizon Total Mobile Protection to offer home screen repair service12 sexy movies you should watch instead of 'Fifty Shades Darker'Nation's innovation report card shows it can, and should, do betterSamsung Chromebook Plus review12 sexy movies you should watch instead of 'Fifty Shades Darker'Former NSA contractor accused of stealing top secret documents says he was just a hoarderMiranda Kerr to Facebook: 'How do they sleep at night?'If you really don't want to get pregnant, don't use this fancy app. Get an IUD.Some owners of the matte black iPhone 7 complain about chipped paint NVIDIA RTX 5060 reportedly launching on May 19, priced at around $349 · TechNode Amazon Prime Day deal: This Echo bundle is $140 off DeepSeek credits Tencent for major performance boost in open China’s Xpeng showcases EVs at Milan Design Week, makes foray into Italy · TechNode ShengShu rolls out Vidu Q1, puts full Tencent, Huawei, Baidu Fuel the Rise of China’s Cloud Tencent reports $8.26 billion in gaming revenue for Q1, up 24% y NASA's Parker Solar Probe just flew over 500 times the speed of sound Xiaomi sets up Xring division to develop in JD Food Delivery plans to hire 100,000 full The best fitness tracker deals ahead of Prime Day 2024 China’s Midea to deploy humanoid robots in factory operations next month · TechNode Best early Prime Day robot vacuum deal: Roborock Q5 Pro+ deal for $300 off Best early Prime Day gaming deals 2024: Save on games, accessories, and more Game Mode on iOS 18 and macOS Sequoia: 3 little Best Amazon robot vacuum deals: The iRobot j9+ is at its lowest price ever Ele.me deploys Unitree humanoid robots to promote flash delivery · TechNode NVIDIA may launch new export Early Prime Day deal: Get $200 off the M3 MacBook Air Taobao and Ele.me race into China’s instant retail battlefield · TechNode
3.4401s , 10171.34375 kb
Copyright © 2025 Powered by 【_____ are likely to have a history of eroticized cross-dressing in childhood and adolescence.】,Charm Information Network