Feeds

Panther bitten by second data damaging bug

FileVault to blame this time

  • alert
  • submit to reddit

Mac OS X 10.3's FileVault system, which protects each user's home folder with on-the-fly 128-but AES data encryption, has been found to contain a data-damaging glitch, Apple has admitted.

The bug manifests itself as a request to regain lost disk space in the encrypted directory. If the user responds in the affirmative, FileVault's reclamation process damages the user's keychain data. Keychain is the Mac OS' secure password storage system, allowing passwords to be accessed through a single master code.

Damaging the data held in the keychain prevents the Safari web browser from automatically signing on to certain web sites, stops Mail logging on to email servers and so on. Many other applications that store passwords in the keychain are likely to be affected too.

Apple last night said it was aware of the problem but was not yet recommending that users disable FileVault. Simply refusing to allow the software to reclaim lost disk space keeps the bug at bay.

The FileVault problem follows an earlier clash between Panther and version 1.0.3 of Oxford Semiconductor's 800MBps FireWire interface chip. That bug lead to data being damaged on external hard drives connected to the host Mac after Panther had been installed on the host system. Oxford sent out updated firmware in September, but drive vendors have only now started to offer it to their customers. ®

Related Story

Apple blames Oxford for Firewire data loss bug

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.