For years many Apple purists (I used to be one) have been touting the inherent security of the Apple operating system. According to Techcrunch in February, 2012 it was discovered that OSX Lion (the newest OS from Apple) had a major security weakness and released widely within the last few days. It was disclosed that the FileVault encryption passwords are now visible in plain text outside of a computer’s encrypted area. This effectively renders the encryption useless as the keys (the passwords) are not secure. While it was originally believed that the vulnerability as specific to the encrypted File Vault solution, it appears now that the vulnerability is larger…potentially much larger. Sophos Naked Security blog states: “Anyone with access to the disk can read the file containing the password and use it to log into the encrypted area of the disk, rendering the encryption pointless and permitting access to potentially sensitive documents. This could occur through theft, physical access, or a piece of malware that knows where to look.” Key management and password security continue to be the weakest link in most encryption implementations.
Follow Me on Twitter
Follow Me on Twitter
Whitepapers & Articles
-
Recent Posts
General
Categories
- competitive intelligence (3)
- cyberespionage (10)
- cybersecurity (32)
- Data Breach (16)
- Failed States (2)
- Industry News (77)
- InfoSec & Privacy (70)
- Laws and Leglslation (34)
- News (17)
- PCI DSS (9)
- Piracy & Maritime Security (70)
- Politics (10)
- privacy (3)
- Risk & Risk Management (75)
- security theater (1)
- terrorism (29)
- Uncategorized (114)
- United Nations (1)
- weapons and tactics (25)
Tweets
- US mulls action against China cyberattacks | Fox News fxn.ws/ThN7QH via @foxnews 3 months ago
- Great blog post on the intersection between risk, security and compliance. bit.ly/ZXcnQb 4 months ago
- Donation Information For Newtown, CT wp.me/p1vqe1-ud via @ChrisAMark 5 months ago
- "The War God's Face Has Become Indistinct" - Unrestricted Warfare wp.me/p1vqe1-u3 via @ChrisAMark 5 months ago
- Offensive Cyber Attacks - A Dangerous Proposition wp.me/p1vqe1-u0 via @ChrisAMark 5 months ago
Stats

