Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Logs in High Sierra Show Plaintext Password for APFS Encrypted External Volumes (mac4n6.com)
4 points by strmpnk on March 23, 2018 | hide | past | favorite | 1 comment


The new log system does have the concept of “private” data (that can only be viewed after explicitly enabling it) but I don’t know how they determine what qualifies.

Apparently a 10.13.x update addressed this. Still, if a password is in a command line, that is basically impossible to predict if you don’t know the tool in advance, and would still leak elsewhere (e.g. another user on the system examining “ps” output).

It is better to use something like an environment variable to pass information to the subprocess without revealing it in the command.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: