<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4678115497130169362</id><updated>2011-07-07T15:48:07.765-07:00</updated><title type='text'>Orestes Melgarejo</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://orestesm.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4678115497130169362/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://orestesm.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Orestes</name><uri>http://www.blogger.com/profile/13285144182851574837</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4678115497130169362.post-2556197118159526346</id><published>2009-10-31T15:55:00.000-07:00</published><updated>2009-10-31T16:13:33.765-07:00</updated><title type='text'>Serious Security Vulnerability in Mac OS X?</title><content type='html'>My 14 year old son pointed this one out and I was shocked when I saw him do this on the Mac.  We both have user accounts on the same machine (both with admin &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_0"&gt;privileges&lt;/span&gt;) which is a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;MacBook&lt;/span&gt; Pro running version 10.5.8 with all the latest updates.  With my account logged  in I shut the lid and put the Mac to sleep.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;He then said, "Dad let me show you something".  He opened the lid and it showed the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;login&lt;/span&gt; screen with my name and an empty password field.  On that same &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;login&lt;/span&gt; dialog box he changed the user name to his name and entered his password.  The expected result here should be that it should log him into his account right?  The actual result is that the Mac lets him unlock the screen using his password and actually use my account as if it was me who had entered my own password!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This is obviously a huge security flaw.  A user of a machine can access another user's account on the same machine and have full control over applications and files and impersonate that user any time.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Has anyone else seen this?  I am amazed that Apple has not come across this before and has not fixed this.  Can anyone else verify that they can do this on their Mac?  Does anyone know whether this was fixed in Snow Leopard?&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4678115497130169362-2556197118159526346?l=orestesm.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://orestesm.blogspot.com/feeds/2556197118159526346/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://orestesm.blogspot.com/2009/10/serious-security-vulnerability-in-mac.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4678115497130169362/posts/default/2556197118159526346'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4678115497130169362/posts/default/2556197118159526346'/><link rel='alternate' type='text/html' href='http://orestesm.blogspot.com/2009/10/serious-security-vulnerability-in-mac.html' title='Serious Security Vulnerability in Mac OS X?'/><author><name>Orestes</name><uri>http://www.blogger.com/profile/13285144182851574837</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry></feed>
