johsim

About

Username
johsim
Joined
Visits
0
Last Active
Roles
member
Points
5
Badges
0
Posts
1
  • Flaw in macOS 'Quick Look' could reveal encrypted data

    I think Apple has improved the balance of "easy of use" and security over the last years and a spacebar click to get a preview is something we all like.
    But if you have an attachable encrypted drive, you expect a different behavior. E.g no cache or a hidden cache on the encrypted drive.

    We have build ourself an encrypted Finder app and there are thumbnails and previews too. Our App SimpleumSafe does not have this vulnerability, because we have a different cache design and our caches are encrypted. So this can be easily done by Apple too.

    We have seen lot of "easy to use" features in the past, like automatically open file downloaded in Safari, which isn't a good idea too. Apple has non technical people in mind when designing the UI, but today there are more and more attacks and Apple has more clearly to show what settings are for "easy to use" vs. "security".
    We have built a free security advisor to start that work. SimpleumCheck.

    Hopefully Apple awakes, because this a real leak for people who work with sensitive data.
    cgWerks