We've expanded our news coverage and improved our search! Visit
oreilly.com for the latest or search for all things across O'Reilly!
| Weblog: |
|
New (local) Mac OS X vulnerability : Passwords in Swap files
|
| Subject: |
|
What process is the password being swapped in? |
| Date: |
|
2004-07-02 01:34:57 |
| From: |
|
recusant
|
|
|
|
One an application retrieves the password from the keychain, Apple cannot enforce that the key is used in a secure manner.
If these passwords are being swapped to disk by third party applications that are being granted the passwords, there's little Apple can do to prevent it.
Is KEYCHAIN swapping the passwords out, or programs getting the passwords through keychain?
|