Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > Security Flaw in 10.3.4

Security Flaw in 10.3.4
Thread Tools
Mac Elite
Join Date: Nov 2001
Status: Offline
Reply With Quote
Jul 1, 2004, 05:11 PM
 
I just noticed this.

Our G4 has 2 users, my dad and me. He uses it most so his user automatically logs in at startup.

I just rebooted and before his Login Items has finished loading i went to the fast user switching menu and selected my user. As usual the password dialog came up but when i typed my password it was displayed as plaintext, not as the usual series of ••••'s that it usually is. Can anyone recreate this?
     
Mac Elite
Join Date: May 2001
Location: Cambridge UK
Status: Offline
Reply With Quote
Jul 2, 2004, 07:29 AM
 
That sounds quite dangerous if it turns out to be true...

(I would confirm it, but I don't have more than one user on my machine).
     
Mac Elite
Join Date: Dec 2000
Location: Tempe, AZ
Status: Offline
Reply With Quote
Jul 2, 2004, 10:00 AM
 
I do not have Automatic Login selected, and with that I could not re-create the problem. Have you tried re-creating it yourself? Can you make it happen every single time you boot up the Mac?
     
Mac Elite
Join Date: Sep 2000
Location: Edmond, OK USA
Status: Offline
Reply With Quote
Jul 2, 2004, 10:06 AM
 
Originally posted by Krypton:
That sounds quite dangerous if it turns out to be true...
I don't really think so. Think about it - the only vulnerability is if an admin has a machine set to auto-login as a user, then does a fast user switch to his account immediately at startup, and types in his password with another user standing over his shoulder without realizing that his password is in plaintext (and once realized, he doesn't bother to change his password).

This seems a remote possibility and an alert user should notice his password is being displayed, if this is indeed verified to be authentic and not an aberration of this user's machine.

Granted if true it should be fixed - but I don't think this is a critical flaw (certainly not a remote attack).
     
Addicted to MacNN
Join Date: Jun 1999
Location: Las Vegas, NV, USA
Status: Offline
Reply With Quote
Jul 2, 2004, 10:28 AM
 
I just tried this on my wife's eMac, on which she has auto login turned on. It didn't display the password in plaintext. It showed the usual series of ••••'s that I would have expected.

Perhaps there is something unique to your system.

Chris
     
Mac Elite
Join Date: Nov 2001
Status: Offline
Reply With Quote
Jul 2, 2004, 10:38 AM
 
it does it every time on the G4. This is very bizarre.
     
Mac Elite
Join Date: Dec 2000
Location: Tempe, AZ
Status: Offline
Reply With Quote
Jul 2, 2004, 10:53 AM
 
And just for "fun", have you repaired the permissions on the Mac? Have you tried setting the Automatic Login to the other user, and see if it still does it?
     
Mac Elite
Join Date: Sep 2000
Location: Tempe, AZ
Status: Offline
Reply With Quote
Jul 2, 2004, 11:28 AM
 
This happened to me once, making me go "whoah..."

Don't remember the circumstances, and it's never happened again. But once is too many times.
Geekspiff - generating spiffdiddlee software since before you began paying attention.
     
Admin Emeritus
Join Date: Oct 1999
Location: Zurich, Switzerland
Status: Offline
Reply With Quote
Jul 2, 2004, 11:02 PM
 
Something in the very back of my mind is telling me that I've heard of this problem before.

I'd look at:
-fonts
-3rd-party add-ons

tooki
     
Addicted to MacNN
Join Date: Oct 2003
Location: Far above Cayuga's waters.
Status: Offline
Reply With Quote
Aug 23, 2004, 04:54 PM
 
my parents sawtooth with 9.0.4 used to do this with passwords. never resolved it.
     
Mac Elite
Join Date: Feb 2001
Location: France
Status: Offline
Reply With Quote
Aug 23, 2004, 07:07 PM
 
Originally posted by Krypton:
That sounds quite dangerous if it turns out to be true...

(I would confirm it, but I don't have more than one user on my machine).
If you "would" confirm it but have only one user...it takes ± 5 mins to make one which you later on can easily delete...
     
Mac Elite
Join Date: Nov 2001
Location: Trafalmadore
Status: Offline
Reply With Quote
Aug 23, 2004, 08:07 PM
 
Originally posted by Appleman:
If you "would" confirm it but have only one user...it takes ± 5 mins to make one which you later on can easily delete...
I also updated to 10.3.5, so maybe it's not an issue any more for most.

± 5 minutes?
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 12:03 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2