Lion Security Flaw

A flaw was recently discovered in OS X Lion that allows any user on the Mac to extract a file containing an administrative user’s password. As with past versions of OS X, user passwords are encrypted and stored securely as “shadow files” within the computer’s hard drive. Those files can then only be accessed by that specific user, or administrators, with proper authentication. The flaw with this procedure in Lion is that these files can be accessed by any user on the Mac. So, a Standard or heavily restricted user could potentially obtain an encrypted file containing an Administrator’s password from which the password can be extracted.

The necessity of local access is what restricts this issue the most. The hacker would need to have physical access to your machine. Hopefully this goes without saying, but allowing a potentially dishonest person unsupervised physical access to your machine is never a good idea. Properly securing your Mac by turning off Automatic Login, using strong passwords (letters, numbers, and characters) and even requiring a password immediately after your system has it’s screen saver going, which can be done in the Security Preference pane, are some simple yet substantial security measures.

It is also possible for the hacker to remotely log into the Mac and grab these password files, but this would require conscious configuration on the Mac owner’s part, as well as the hacker’s knowledge of a valid username and password.

I’m confident that Apple will release a Lion Software Update soon enough to correct this issue. In the meantime, however, it is a good idea to utilize the aforementioned security steps, and always keep in mind: there’s no security like physical security.

Similar Posts

  • Mac OS X Tiger 10.4.7 Released

    This morning I walked into work and saw I had the Software Update screen up. I thought it said I needed to update…

  • VLC Media Player Updated

    A media player that I’ve written about almost since the day I started working at Small Dog got a nice update this week….

  • Google + Nest = Nest+?

    You may have heard that yesterday, Google acquired “*Nest,*”:https://nest.com the company most known for its smarter, simpler thermostat design. Reactions to the sale have been largely negative, at least according to “*fans of Nest on Facebook.*”:https://www.facebook.com/nest/posts/10152167824360681 What would this mean for your privacy? For device support (especially non-Google devices such as iPhone)? ARE WE ALL GOING TO BE WATCHED IN OUR HOMES?

    I’ve been intrigued by Nest’s thermostat design since it was developed by Nest Labs in 2011, and still believe that it has set a standard for innovation and what it means to have a “connected home” — a term that has proven to be highly sought after in the past few years. I mean, you can leave the over-the-top “smart” tech products at CES (except for the WeMo-enabled “*Belkin Crock-Pot*”:http://www.macrumors.com/2014/01/07/belkin-slow-cooker/ … I think I’d love that guy), but Nest makes a lot of sense for the average home.

    Recently, Nest Labs introduced a smarter “*smoke and carbon monoxide detector,*”:https://nest.com/smoke-co-alarm/life-with-nest-protect/ taking on another mundane household staple that they determined significant improvement (for the annoyance factor alone). That brings the total number of products to two. Two. For which Google paid 3.2 billion! Obviously, they were viewed as game-changers.

    So, what do you think Google plans to do with Nest? We’d love to hear your thoughts!

    More on the acquisition “*here.*”http://online.wsj.com/news/articles/SB10001424052702303595404579318952802236612

    More on the Facebook backlash “*here.*”:http://www.adweek.com/news/advertising-branding/most-nests-facebook-fans-dislike-google-deal-154974