Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is more than just Filevault. This is /any/ user mount of an AFP share, so things like shared user directories, which are common in large organizations, are also vulnerable. The issue here is that this security vulnerability exists, 3 months after it was publicly reported. Surely it wouldn't take that long to release a patch for a pretty critical vulnerability.


So that's a good point, but I feel compelled to point out that I've never seen a large organization with AFP shared user directories.

There are far more important vulnerabilities --- clientside drive-by remote code execution, for instance --- that have gone unpatched for longer than this. Do I think 3 months is a reasonable time-to-fix? No comment.


Can these far more important vulnerabilities be fixed as easily as turning off a debug flag?

Personally, in the rare cases when a fix is easy I'd expect it to be deployed promptly (and 3 months doesn't sound reasonable to me).


Yes.


What do you mean? I just mounted an AFP share and my password did not end up in the syslog.


Okay, re-reading the bug reports, from here and other places, it involves mounting an AFP-mounted home directory. So an average user mount wouldn't log to syslog, but if your home directory was set for a remote mount, or a loopback afs mount, it would be. I'd need a lion box to properly test on; I'd given up on OS X a few years back because I got tired of Apple's idea of Just Fucking Works.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: