Feeds

Panther bitten by second data damaging bug

FileVault to blame this time

  • alert
  • submit to reddit

Mac OS X 10.3's FileVault system, which protects each user's home folder with on-the-fly 128-but AES data encryption, has been found to contain a data-damaging glitch, Apple has admitted.

The bug manifests itself as a request to regain lost disk space in the encrypted directory. If the user responds in the affirmative, FileVault's reclamation process damages the user's keychain data. Keychain is the Mac OS' secure password storage system, allowing passwords to be accessed through a single master code.

Damaging the data held in the keychain prevents the Safari web browser from automatically signing on to certain web sites, stops Mail logging on to email servers and so on. Many other applications that store passwords in the keychain are likely to be affected too.

Apple last night said it was aware of the problem but was not yet recommending that users disable FileVault. Simply refusing to allow the software to reclaim lost disk space keeps the bug at bay.

The FileVault problem follows an earlier clash between Panther and version 1.0.3 of Oxford Semiconductor's 800MBps FireWire interface chip. That bug lead to data being damaged on external hard drives connected to the host Mac after Panther had been installed on the host system. Oxford sent out updated firmware in September, but drive vendors have only now started to offer it to their customers. ®

Related Story

Apple blames Oxford for Firewire data loss bug

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
10 threats to successful enterprise endpoint backup
10 threats to a successful backup including issues with BYOD, slow backups and ineffective security.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The hidden costs of self-signed SSL certificates
Exploring the true TCO for self-signed SSL certificates, including a side-by-side comparison of a self-signed architecture versus working with a third-party SSL vendor.