Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Passwords in Mac OS X can be pilfered with new tool

The tool capitalizes on a long-known issue in how FireWire can be used to read a computer's memory

A company that makes password recovery tools has released one that can snatch passwords from a locked or sleeping Macintosh running Mac OS X Lion by plugging another computer into the Mac's FireWire port. The attack technique is several years old and the only way to defend against it is to turn the Mac off.

Passware, which has engineering facilities in Moscow and headquarters in Mountain View, California, said its Passware Kit Forensic v11 analyzes a Mac's live memory via FireWire. FireWire is a fast serial interface developed in the 1980s by Apple. It is also known by Sony as i.LINK and was standardized as IEEE 1394.

If a computer is turned on and has been logged into at least once, Passware's software can extract passwords in a few minutes, even if the computer is locked or sleeping. It can even extract passwords in the Mac's keychain password store -- regardless of password strength and even if FileVault encryption is used, the company said in a news release.

The issue affects all "modern" Mac OS versions, including Snow Leopard and the latest one, Lion.

Apple officials contacted in London did not have an immediate comment.

Passware said there's an easy defense: turn off the computer, which erases the passwords from the computer's memory. Passware also suggested disabling the feature that automatically logs in a user when the computer is turned on, a basic security step.

The FireWire password issue has been for some time. In 2008, Uwe Hermann -- a Debian developer -- compiled a list of research papers from over the years summarizing issues with FireWire. Hermann wrote that if you can gain access to a computer with a FireWire port, it is possible to read or write data in the computer's RAM.

Other defenses against the attack include simply not having a computer with a FireWire port or plugging an existing one up. If a computer has a PCMCIA or PCI card slot, however, it could still be vulnerable if a FireWire-enabled card is inserted, Hermann wrote. Another precautionary measure is to try and ensure no one gets access to your computer.

Passware's Kit Forensic costs $995 with one year of free updates.

Send news tips and comments to jeremy_kirk@idg.com

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Apple, Apple., Debian, DMA, IEEE, Mountain View, Sony
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Access control and authentication, Apple, data protection, Exploits / vulnerabilities, Mac OS, operating systems, security, software
Latest Blog Posts
Whitepapers
  • Look both ways - Protecting your data with content inspection
    Today’s threat environment is as dynamic as the business world in which we operate. As the communications channels we use continue to proliferate and evolve, so too have the vulnerabilities. Finding the right balance between ensuring the security of sensitive data, enabling the free flow of information and making full use of the latest web-based technologies can be a challenge. Deep content inspection is a vital layer in any unified information security strategy, helping organisations to take control over their information assets while proactively protecting against malware and data leakage. Read on.
    Learn more »
  • Justifying Business Intelligence Applications
    This white paper explores the decision criteria used in a build vs. buy scenario when considering the Oracle BI Applications. The major benefits of the BI Applications will be discussed in the framework of an overall buy vs. build argument.
    Learn more »
  • Revolutionizing Enterprise Storage Infrastructure with Enterprise Flash Technology
    Businesses increasingly rely on datacenters to provide access to services, applications, and data. As demand rises and applications grow in complexity, datacenter infrastructure must provide tremendous capacity and rapid access to information in order to keep pace with business priorities. Read on.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments