Reply to post: Re: That's not even wrong

Dumb bug of the week: Apple's macOS reveals your encrypted drive's password in the hint box

Ben Tasker Silver badge

Re: That's not even wrong

How do they even _have_ the plaintext password to display there?

They have it in plaintext at the time you enter it to create the volume. The root of the issue is that they've done something like

diskval.hint = null

diskval.pass = buildKey(password)

if (hint)

set diskval.hint = password

createVolume(diskval)

The root cause is probably a copy/paste of a block that checked for and set the password, and then they changed the conditional but forgot to change the name of the variable they were taking data from

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Biting the hand that feeds IT © 1998–2019