Password leak in High Sierra's Disk Utility creating encrypted APFS volumes

sdagley
Esteemed Contributor II

Heads up for folks...

There's a thread on Twitter (look for @patrickwardle) about encrypted APFS volumes created via Disk Utility in High Sierra having their password stored as the password hint. It does not happen if you use diskutil to create the encrypted volume.

3 REPLIES 3

bvrooman
Valued Contributor

Looks like this was resolved in today's "supplemental update."

Chris_Hafner
Valued Contributor II

... wow.