∞ Lion FireWire security issue misleading

Passware, a computer forensics and password discovery company, on Tuesday said it discovered a way to get passwords from a Mac running OS X Lion. However, it may not be as dire as it seems.

[ad#Google Adsense 300×250 in story]While the implication is that you can plug in the Passware Kit Forensic into someone’s Mac and walk away with their passwords, Lion and security experts I’ve spoken with said it’s not quite that easy.

Here’s the bad news — if you leave your computer unattended, with no screen lock, and you are logged in, yes this software could most likely steal your passwords. If you do that, you probably won’t have a computer when you get back, so passwords are the least of your worries.

Here’s the good news — If you are running with password protected login and screen lock enabled (the default settings in Lion), then it is unlikely that this software can access your passwords. FireWire is secure until you enter your password, I’ve been told.

I was contacted this morning by Dmitry Sumin, president of Passware, who says the software can still get the passwords.

“This is not true,” said Sumin. “Even if you have a login password enabled, automatic login disabled and your computer is locked the software is capable of extracting your password. That is the problem unique to Mac OS X. Windows does not store login passwords unencrypted in memory.”

The other issue is with Apple’s FileVault security and privacy application. Passware says that it can grab passwords regardless of whether a user has FileVault enabled or not. Apparently, this too isn’t accurate. I’ve been told that if FileVault is turned on, it also turns on screen lock which means that when your machine is unattended the screen lock runs, and you’re protected.

Update 2: 10:09 am PT July 27 — Added quote from Passware President.

Update: 6:45 am PT July 27 — Clarified the conditions under which the hack will work.



11 thoughts on “∞ Lion FireWire security issue misleading

  1. The FireWire/Thunderbolt hack is simply a scan of the memory of the computer through the direct connection between the FireWire bus and the devices inside the computer.

    Thus if you use FileVault and your computer is awake or went to sleep without being locked, the FileVault key will still be stored in memory. Since the hack is capable of reading the key and accessing the hard drive, it is possible for the attacker to gain access to anything on your computer, just like you do.

    The simple fact of the matter is that a computer that is left unattended is a security risk. The attacker might be able to hook the FireWire/Thunderbolt hack up to your laptop while you’re standing on the bus or train, but if you keep the ports inaccessible (e.g.: MacBook Air locked in your briefcase) this hack can be thwarted.

    This comes back to the old security adage of, “if I have physical access to the computer, it is mine.”

  2. Not quite.

    In Lion, unlike in previous versions of Mac OS, Firewire DMA is disabled when the system is asleep, and when the system is at the login window or screen locker prompt.  Even though the password is in memory, it cannot be accessed through the Firewire port.  

  3. I thought it was interesting that this outfit chose to make a headline out of their software’s capability to steal passwords from Macs when it’s also quite capable of doing the same thing on Windows 7 machines.

    This is a trend I’ve been noticing for a while. Apparently putting something Apple related in the title of your press release or blog post means you get more eyeballs on it. Apple must be doing something right….  It’s created a whole new kind of troll.

  4. So is this is just another case of a company being economical with the truth in order to push sales?

    The press release clearly states that Passware will work… “even if the computer is locked or put into a sleep mode”, which from the comments above may not be true.

    The Passware website claims “Recovers Mac User Login passwords from computer memory” and makes no qualification (i.e. no mention of the Mac being asleep or locked).

    Passware, if you’re watching – how about a little clarification (honesty)?

  5. Hi John,

    Our software will work even if computer is locked. Otherwise this would not be called a vulnerability, after all.

    The software is capable of capturing memory image of a computer via FireWire even if *is locked*.

    >FireWire is secure until you enter your password, I’ve been told.
    FireWire is *not* secure. At least for Mac OS X 10.6 and 10.7.

    If a user logged in at least once the password remains resident in the computer memory and could be reveled using our software.

    Regards,
    Dmitry Sumin
    Passware, Inc.

  6. Loopinsight has become quite annoying with its insistence on using a mobile theme on the iPad. Sorry for the off topic post.

  7. Why don’t you do a demonstration or prepare a video to finish once and for all this controversy?

    I believe that the greater the publicity surrounding this issue so the greater the pressure on Apple to solves the problem, if it actually exists.

    I believe that a fix from Apple is what we all need, isn’t?

  8. Let’s call a pig a pig, there has been no tangible proof this works as advertised – and even if it does the whole thing seems to require extraordinary circumstences which, in and by themselves, can lead to bigger issues than what this hack promises to deliver. 

  9. “in Lion, unlike in previous versions of Mac OS, Firewire DMA is disabled
    when the system is asleep, and when the system is at the login window or
    screen locker prompt.  Even though the password is in memory, it cannot
    be accessed through the Firewire port.”

    THIS IS NOT TRUE

  10. Have been most concerned since I read this piece of news.  I thought with WDE and lock screen enabled, I would be quite safe.

    Please, someone do a test run and this would be settled rather quickly.  Someone with a spare $1000 or so?

Leave a Reply

Your email address will not be published. Required fields are marked *