Are you prepared for Wrath of the Lich King? WoW Insider has you covered!

Mac OS X password recoverable from RAM?

In a recent post over at Ars Technica, they say that Mac OS X users could have their login passwords recovered through physically accessing the RAM. This comes after FileVault was proven to be cracked. The article notes that Mac OS X and certain applications store the user's password in memory, leaving it there after you've logged in. While locally-running apps cannot readily retrieve the password, someone could get access to the contents of RAM after the computer has been rebooted or shut down.

This could be accomplished by physical means and might require the hacker to remove the RAM cover on your Mac and chill the RAM, as suggested by Edward Felten's research team at Princeton. This freezing allows the information to stay on the RAM for longer than the normal 2.5 to 35 seconds -- allowing someone to place it in another computer and read the contents.

In a separate approach to the password-in-RAM vulnerability, CNET witnessed an EFF demo of an attack using a custom NetBoot "EFI memory scraper" to record the RAM contents on reboot and save the data as a file on another machine over the network -- the attackers were able to clearly find the login password in the file. Again, this attack requires physical access to the machine (in order to force the NetBoot via holding down the N key on restart) within a minute or two of shutdown. However, an attacker could conceivably target a machine that was locked or sleeping (with RAM contents 'live'), power it off and back on, and use the NetBoot attack immediately.

While Apple has been made aware of the attack (notified on February 5), no fixes for these issues were reported in the 2/11 security update. According to CNET, an Apple spokesperson said they were aware of the issues and were "working to fix it in an upcoming software update." Until this update comes out, you may want to set a firmware password for your Mac, or wait longer to leave your unattended Mac after a shut down. Alternatively, we have lovely TUAW-branded tin foil hats available for purchase.

[via Ars Technica]

Related Headlines

Reader Comments (Page 1 of 2)

Add your comments

Please keep your comments relevant to this blog entry. Email addresses are never displayed, but they are required to confirm your comments.

When you enter your name and email address, you'll be sent a link to confirm your comment, and a password. To leave another comment, just use that password.

To create a live link, simply type the URL (including http://) or email address and we will make it a live link for you. You can put up to 3 URLs in your comments. Line breaks and paragraphs are automatically converted — no need to use <p> or <br> tags.

New Users

Current Users

TUAW Features

Mac 101 iPhone Around the Worldask-tuaw
Mac News
Macworld (497)
.Mac (38)
Accessories (624)
Airport (75)
Analysis / Opinion (1291)
Apple (1609)
Apple Corporate (547)
Apple Financial (186)
Apple History (38)
Apple Professional (49)
Apple TV (160)
Audio (441)
Bad Apple (119)
Beta Beat (148)
Blogging (87)
Bluetooth (15)
Bugs/Recalls (56)
Cult of Mac (869)
Deals (200)
Desktops (114)
Developer (205)
Education (93)
eMac (10)
Enterprise (126)
Features (373)
Freeware (363)
Gaming (344)
Graphic Design (18)
Hardware (1269)
Holidays (41)
Humor (587)
iBook (65)
iLife (237)
iMac (183)
Internet (306)
Internet Tools (1289)
iPhone (1350)
iPod Family (2020)
iTS (962)
iTunes (794)
iWork (18)
Leopard (355)
Mac mini (109)
Mac Pro (50)
MacBook (196)
MacBook Air (77)
Macbook Pro (214)
Multimedia (432)
Odds and ends (1417)
Open Source (270)
OS (890)
Peripherals (190)
Podcasting (181)
Podcasts (83)
Portables (196)
PowerBook (137)
PowerMac G5 (50)
Retail (572)
Retro Mac (47)
Rig of the Week (42)
Rumors (612)
Software (4219)
Software Update (395)
Steve Jobs (252)
Stocking Stuffers (55)
Surveys and Polls (96)
Switchers (111)
The Woz (34)
TUAW Business (227)
Universal Binary (281)
UNIX / BSD (62)
Video (908)
Weekend Review (74)
WIN Business (49)
Wireless (80)
XServe (35)
Mac Events
One More Thing (27)
Liveblog (0)
Other Events (231)
WWDC (181)
Mac Learning
Ask TUAW (96)
Blogs (85)
Books (23)
Books and Blogs (63)
Cool tools (444)
Hacks (462)
How-tos (480)
Interviews (33)
Mods (184)
Productivity (583)
Reviews (99)
Security (145)
Terminal Tips (56)
Tips and tricks (559)
Troubleshooting (161)
TUAW Features
iPhone 101 (23)
TUAW Labs (3)
Blast From the Past (17)
TUAW Tips (141)
Flickr Find (32)
Found Footage (70)
Mac 101 (81)
TUAW Interview (30)
Widget Watch (196)
The Daily Best (2)
TUAW Faceoff (5)

RESOURCES

RSS NEWSFEEDS

Powered by Blogsmith

Sponsored Links

The Unofficial Apple Weblog (TUAW) bloggers (30 days)

#BloggerPostsCmts
1Dave Caolo490
2Cory Bohon455
3Mat Lu374
4Erica Sadun351
5Scott McNulty341
6Michael Rose2919
7Brett Terpstra240
8Mike Schramm194
9Robert Palmer1322
10Steven Sande139
11Joshua Ellis64
12Christina Warren618
13Nik Fletcher41
14Chris Ullrich21
15Victor Agreda, Jr.14
16Jason Clarke11
17Lisa Hoover11

Featured Galleries

Macworld 2008 Keynote
Macworld 2008 Build-up
Macworld Expo 2007 show floor
The Macworld Faithful in Line
iPhone First Look
iPhone 2.0 - .Mac push e-mail
iMac 1998
TUAW Faceoff: Screenshot apps on the firing line
Boston Apple Store (Boylston Street)

 

    Most Commented On (7 days)

    Recent Comments

    More Apple Analysis

    More from AOL Money and Finance

    Weblogs, Inc. Network

    Other Weblogs Inc. Network blogs you might be interested in: