Is this a terrible security breach?

I have two admin accounts on my MacBook Pro running 10.5.7. I am logged into one of them. Activate the screensaver. To wake up from screensaver I've set it up to require the password. So the password prompt comes up. It's already got my account name filled in, and is waiting for my password.
Now, I pretend I don't remember my password for the account that's already logged in. So I go into the already filled out field for account name, I type over it my other admin account name, then enter that second account's password in. I am expecting to be logged in as the second admin user, right?
Wrong! The screen flips, and I see where admin account 1 left off!
Surely this is not supposed to happen?

If the behaviour of the screensaver password box bothers you, it is configurable via the "/private/etc/authorizations" file.
However, you appear to have a misconception of what an "admin" is in "OS X", and what they can do. An administrator can certainly administer the system, but another aspect of their function is to administer other users. Creating accounts for new users, deleting them when they are no longer necessary, cleaning up their files, etc. They can also do things like turn on screen sharing to access the user's desktop view remotely, which can be useful in a "help desk" context, but also to eg. make sure students are doing their work instead of something else, i.e. to snoop.
Make no mistake - an "admin" has full access to any logged in session, and any unencrypted file on the system so there is no security risk in allowing them to unlock the screen.
It is important for Mac owners to recognize this, so that they only give admin rights to trusted individuals, don't leave their own "admin" sessions unattended, and for that matter, only log in to an "admin" account when necessary to perfor administrative tasks.

Similar Messages

  • Did you know when you type in your email in google your behance pdf resume shows up? This is a security breach!

    I typed my email address in Google and my Behance pdf resume shows up with all my information. Did you all know this? This is a security breach in my opinion.
    Message was edited by: Carol Smith

    HI Carol,
    Thanks for writing. It looks like you had selected your work experience to be visible to the public, so this is why it was visible online. Now I see that you have your work experience listed as private (other than what you have on your profile), so this should no longer be the case. Let me know if you're still seeing this searh result and what exact google term you searched for it to come up.
    Thanks, talk to you soon!

  • App store not asking for password, security breach

    Earlier today, I was using the app Words with Friends by Zynga, and it crashed. Although I am not able to get the app working again even after uninstalling and reinstalling the app (developer issue) I have noticed that since this app crashed my App Store on my iPhone 4S is not asking me for my Apple password anymore. I have even restarted my iPhone and reset it by holding down the home button and power button until my iPhone restarts. Has this happened to anyone before? I feel like this is a security breach as my App Store is no longer requesting my password for downloading apps.

    iTunes is currently having problems in reference to the apps. If you have icloud, then toggle contacts off/on. If not then restore from itune backup

  • When I close firefox "everything " is cleared! EXCEPT when I open it again and anything i have copied to the clipboard (paste icon) remains lit... I believe this can be a security breach because I clear everything when closing firefox !!

    I have my settings to clear everything when I close firefox ver 3.6.13. If I copy something to the clipboard, the Paste icon lights up so I can paste the text... which is normal.
    The problem is when I close the browser and everything is suppose to clear (history, etc) the PASTE Icon still lights up for me to paste again.
    This can be a security breach because I want everything cleared when closing the browser !!!
    The only way I can rid myself of this problem is to restart the computer... which clears the clipboard of the operatinging... which is absolutely normal as well.
    I should not have to restart the computer each time.
    Try It !!! type text in any box... then paste it by using the PASTE Icon
    CLEAR all your history, everything ... then close firefox
    Reopen the browser... and the PASTE Icon will light up

    I only had a few addons installed, I disabled Zone Alarm toolbar, View Source Chart 3.01. I also had 5 separate java console updates/addons, and I uninstalled all but the latest java console 6.0.21. All I have now is Roboform 6.9.98, Firebug 1.5.4, Java console 6.0.21, Java quick starter 1.0. So far, so good, the problem has not occurred today. I hope this is it, I will be more sure after a few days problem free. Thanks for the info.

  • Does this new security breach affect iPad first generation users?

    Does this new security breach affect iPad first generation users?  My model uses IOS 5.1.1 software.  Will they be making a patch for us too?

    What breach?
    Nothing was breached.
    There was a flaw in ios 6 and 7 in how ssl ccertificates were handled.
    Since over 80% of users are on ios 7, around 18% on ios 6 and less than 3% on ios 5-ios 5 is dead.

  • Popup with the text "Security Breach" in Safari

    My son told me he saw a popup with the text "Security Breach" when visiting a website. He is concerned that his phone may be compromized. He is using Safari, iOS 6.0.1 on a iPhone 4S. The was a n OK button on the popup. He pressed it and the popup disappeared. Is there serious danger here?

    This may be caused by a problem with an add-on. Try the procedure in the [[Troubleshooting extensions and themes]] article.

  • Security Breach on the Ubuntu Forums

    So apparently the ubuntu forums got hacked and someone made out with 2 million usernames, passwords and email adresses- ouch! Their site is currently down. Just posting as an FYI because their advice is to change your password if you have an account there and use it for multiple sites. 
    Ubuntu Forums is down for maintenance
    There has been a security breach on the Ubuntu Forums. The Canonical IS team is working hard as we speak to restore normal operations. This page will be updated regularly with progress reports.
    What we know
    Unfortunately the attackers have gotten every user's local username, password, and email address from the Ubuntu Forums database.
    The passwords are not stored in plain text, they are stored as salted hashes. However, if you were using the same password as your Ubuntu Forums one on another service (such as email), you are strongly encouraged to change the password on the other service ASAP.
    Ubuntu One, Launchpad and other Ubuntu/Canonical services are NOT affected by the breach.
    Progress report
    2013-07-20 2011UTC: Reports of defacement
    2013-07-20 2015UTC: Site taken down, this splash page put in place while investigation continues.
    If you're using Ubuntu and need technical support please see the following page for support:
    Finding Help.
    If you're looking for a place to discuss Ubuntu, in the meantime we encourage you to check out these sites:
    Last edited by w201 (2013-07-22 08:59:58)

    fukawi2 wrote:An unfortunate event for Canonical and the Ubuntu team. Glad to see the passwords were at least hashed, and with a salt.
    Unfortunately md5 hashes even with salt are easily crackable. On the other hand, it's just a forum account and since they alerted people early, anyone foolish enough to use the same password elseware can change the other password on time.
    One thing I disliked is that they haven't alerted people by email, at least I haven't got one yet. I got this information from various source, but many people (dormant accounts / less frequent users) are unlikely to know of it.
    Last edited by x33a (2013-07-22 17:15:35)

  • Mail OS X Security breach...

    FYI.
    Apparently my Mail program was hacked. I'm no expert on security breaches but the story goes like this...
    Our ISP was acting up. I've verified w/4 others in the neighborhood (both Windows and Mac) using the same ISP who were experiencing the same issue. Would load some sites, some just wouldn't load. I've no idea if this is relative or not, but...
    The wife couldn't check her email because the Internet wouldn't connect. I looked at it, figured it was down, and went to bed. Next morning EVERY email in all 5 of my emails accounts was gone, except for my wife's account. Per the wife, she checked before she went to bed and all emails were gone in all accounts. She said there was an open window called Tiger Mail that said; If you'd like to continue to receive your email, click here. (Uh oh). She did and her inbox filled right up.
    Malware?
    I did a full erase/reformat regardless.

    See if you might have this malware redirecting DNS queries...
    http://macmegasite.com/node/3924
    How to fix...
    http://www.macosxhints.com/article.php?story=20071031114140862
    Nasty Nasty ! 1023.dmg...
    http://x704.net/bbs/viewtopic.php?f=12&t=2178
    http://www.dnschanger.com/

  • Does anyone know of the security breach on the iphone and what to down load to fix it?

    DOES ANYONE KNOW ANYTHING ABOUT THE SECURITY BREACH ON THE IPHONE AND IF YOU DO, WHAT DO YOU DOWN LOAD TO FIX IT?

    http://support.apple.com/kb/HT6147
    http://support.apple.com/kb/HT1222
    http://support.apple.com/kb/DL1723
    There is no security breach as such but rather a possibility of one dependant on a number of factors which may or may not be applicable to you and/or your usage.
    The recommendation is to update to the latest 7.0.6 update listed above. For iDevices such as the iPhone I would recommend doing this using iTunes rather than OTA. Tends to be more reliable that way.

  • New Apps User defaults with all User Edition Privileges - Security Breach?

    Please check the following Scenario/Issue and please let me know if anyone has a solution for it.
    1. In Apps, created following Responsibilities
    - Payables Inquiry-Only User
    - Projects Inquiry-Only User
    2. In Discoverer Admin, Tools->Privileges, assigned following privilege to "Payables Inquiry-Only User"
    - User Edition Parent only (unchecked all child privileges such as Create/Edit Query)
    3. In Discoverer Admin, Tools->Security, mapped following Responsibilities/Business Areas (BA)
    - Resp: Payables Inquiry-Only User BA: AP Payables
    - Resp: Projects Inquiry-Only User BA: PA Projects
    4. In Apps, created user DISC_INQUIRY_USER, assigned following responsibilities
    - Payables Inquiry-Only User
    - Projects Inquiry-Only User
    5. At this stage, if user connects to User Edition;
    - user is able to create new query in BA: AP Payables or BA: PA Projects depending on login Responsibility
    - By default Discoverer assigns all User Edition Privileges to new Apps User including Create/Edit Query
    Requirement
    1. Create new Apps User DISC_INQUIRY_USER, assign it Inquiry-Only Responsbilities
    2. Login to User Edition - DISC_INQUIRY_USER: Payables Inquiry-Only User
    - User can inquiry Workbooks associated with Resp: Payables Inqiry-Only user
    - Should not be able to create new workbooks
    3. Login to User Edition - DISC_INQUIRY_USER: Projects Inquiry-Only User
    - User can inquiry Workbooks associated with Resp: Projects Inquiry-Only User
    - Should not be able to create new workbooks
    Issue
    There is time-gap between creating Apps User and login to Discoverer Admin to remove user privileges. This is security Breach, is their any way to change get around it.
    - Discoverer gives precedence to Responsibility Privileges over User Privileges. Is their any way to change it?
    - Is it possible to change default Privileges for new Apps User?
    - I am facing this issue in Discoverer 4.1.48, Does discoverer Admin behaves differently in latest Versions?

    Nobody helps you except yourself. ;)
    So, this query get privileges for user PUBLIC
    select eap.ap_id, eap.gp_app_id
    from eul5_eul_users eeu,
    eul5_access_privs eap
    where eeu.eu_username = 'PUBLIC'
    and eap.ap_eu_id = eeu.eu_id
    and eap.ap_type = 'GP'
    In my case
    3001     1000
    3002     1001
    3003     1002
    3004     1003
    3005     1004
    3006     1005
    3015     1013
    3016     1014
    3017     1018
    3018     1024
    I research а corresponding between gp_app_id (second column) and real name of privilege and get the next list:
    1000     Discoverer and Plus Privilege
    1001     Create/Edit Query
    1002     Item Drill
    1003     Drill Out
    1004     Grant Workbook
    1005     Collect Query Statistics
    1006     Administration Privilege
    1007     Set Privilege
    1008     Create/Edit Business Area
    1009     Format Business Area
    1010     Create/Edit Summaries
    1012     Schedule Workbook
    1013     Unknown
    1014     Save Workbooks to Database
    1015     Manage Scheduled Workbooks
    1018     Unknown
    1024     Create Link
    So, the ID of privilege 'Save Workbooks to Database' is 1014. This privilege exists in table in spite of in Discoverer Administrator this option UNCHECK for user PUBLIC.
    This is a REAL BUG!!!
    Then I executed query
    delete from eul5_access_privs where ap_id = 3016
    and after that all became right.
    Now please explain me this bug. And I have question - which privileges have IDs 1013 and 1018?
    Thank you.

  • How many security breaches do you think there really are?

    Lieberman Software released a study today that finds 87% of IT pros believe the reports of security breaches among financial institutions belie the true number of hacks occurring within the industry.According to eWeek, the report, which surveyed nearly 150 IT pros, concludes that IT faces a lack of confidence concerning of advanced persistent threat (APT) attacks and how organizations are able to deal with them.Speaking with eWeek, the current President of Lieberman Software, Philip Lieberman, explained that the rising use of "automation among attackers and the increased use of zero days and unpatched vulnerabilities are adding to [the security risks that organizations face]." While IT is partof the problem, Lieberman places a larger portion of blame with senior leadership, which doesn't build "resiliency into their business operations...
    This topic first appeared in the Spiceworks Community

    Hi Shanti,
    I did not have that specific problem.
    The way I stripped the envelope was by simply using embedded JAVA and a regular expression (an alternative to this could be to make your message a DOM object and use XPath to extract the payload).
    I found that this did not work in my case because I needed the header in the original message. So instead I am currently using XPath at the invoked webservice instead.
    I am still working on finding a way to get a proper message sent from BPEL. Here is some suggestions from my SR to Oracle:
    1. Continue to use your current solution. (paraphrased by me)
    2. Do not wrap the MESSAGES with a SOAP envelope before they are placed on the inbound JMS queue.
    3. If appropriate try and use HTTP BINDINGS to invoke the WebSevices.
    I am working on the 3rd option, since the first two are not usable in my case.
    Regards,
    Aagaard
    PS: My reg. ex. looked something like this:
    aSource = aSource.replaceAll("(?s)<backslashbackslash/SOAP-ENV:Body>.*", "");
    aSource = aSource.replaceFirst("(?s)^.*<SOAP-ENV:Body>\n+", "");
    aSource = aSource.replaceAll("(?s)backslashbackslash-backslashbackslashs+", "");

  • Confusing Packets Received vs. Packets Sent... Security breach?

    Hello,
    I want to know if the non-logical difference in bytes received and bytes sent is signaling a securty breach. 
    I controll my wireless connection very tightly; meaning, I only enable wireless when I am goint to use the internet wirlessly.  If I am not connected through the internet wirelessly, wireless part of router is disabled. 
    However, through the router's control panel traffic monitoring interface, I have noticed that the amout of bytes I received vs. the amount of bytes sent doesn't make sense, and I wonder if this discrepancy may actually indicate a security breach of my network. 
    For example, I watched video through wireless connection for 3 hours. Before I started the wireless connection, the router's control panel traffic monitoring screen showed no bytes sent no bytes received. After the 3 hours, I got ths stats: 
    Received Bytes 101233736
    Sent Bytes 3629425895
    This is a huge difference for activity which I think is mostly receiveing data packets, and not sending packets elsewhere. 
    This difference is more than 2G of data sent out while I was watching video and doing nothing else. How can this be? I get almost 1G of video data, and I sent our 3G of data just watching video? 
    Could I get some feedback on why is there such a big difference, and whether this is normal traffic acitivty given the circumsances I described (e.g. watching video content, not doing anything else). 
    Thank you

    Looks normal to me.
    From the router much more data is to your PC and much less data is needed to sent from your PC.

  • Apple ID - security breach?

    For over a week now I have been attmepting to establish the iCloud account for my new iPhone. However, I continue to run into problems with access. According to the Apple site, there is already an account established with MY email address ([email protected]) I have been able to log in to the account, but it asks for me to verify the ID, and when the email to do so is sent - it doesn't come to my email address.
    The account has my last name but another first name.  I don't know why someone else would use my email address, only I have access to it. But I want to establish ONE account for me with MY email address. The assistance I have been getting via email from the (wonderful Indian) advisors online has just pushed me around in circles with no results. Can someone please offer advice? How do I get my email address on my Apple ID?
    Any help would be greatly appreciated! Thank you.
    < Edited by Host >

    It sounds like through a typo or cluelessness or what have you that someone else signed up for that Apple ID before you, so it "belongs" to them now.
    There would be some things they could not do with it unless they verify a different email address as primary though since obviously they don't have access to your real email account.
    But anyone can create any possible Apple ID by making up any possible ID in an email address format, whether or not it is a real email address of theirs, what matters are the verified email addresses within it at appleid.apple.com.
    You would need to pick another Apple ID though. It would be a security breach at this point to someone else if you managed to take that Apple ID from the other person regardless of their mistake.
    Diana

  • Find my iPhone - security breach?

    Dear Apple community,
    Here is a Find My iPhone brain teaser. I have an iPhone and if I track it via Find My iPhone it appears in site A, a work place. That is where it should be. However, there are times when the device appears in a second site, site B, which is approximately 3 to 4 direct miles away from site A. When it is located in site B it is not a wide green circle suggesting its whereabouts. It quite accurately locates the phone inside a building which must be 25,000 square feet and set in its own grounds. The phone will appear there for a while and then after a new Find my iPhone search or a after some minutes the phone sometimes goes back to site A. I've observed this happening generally through the hours of 9am to 3pm and on several occasions. You might also like to know that site A and B are both in a city.
    Firstly, the phone has never been in site B, ever neither is the route taken to site A any where near site B.  Secondly I am tracing its position from another iPhone, iPad and a MacBook Pro that are located over 15 miles away. They all show the same mysterious location issue. The only common factor between site A and site B is that there is a person, a colleague, who works part time in both sites. My concern is that there is some sort of security breach. Can anyone advise?
    Looking forward to your replies.
    Mike

    Hi Mike,
    Thank you for using Apple Support Communities. 
    I have seen the same anomolies on occasion. From the following article:
    Note: Maps and location information depend on data collection services provided by third parties. These services are subject to change and may not be available in all geographic areas, resulting in inaccurate or incomplete maps or location information.
    iCloud: Locate your device
    Regards,
    Jeff D. 

  • Recording of Security Breach

    Hi,
    Is there a standard infotype/way for recording Security Breach of any sort..
    Or any alternate place
    BR
    SK

    Hi,
    Thanks for the response.
    I am not looking for the change log.
    I am looking for a place to record security breach done by an employee.
    I want to record the same against his pernr.
    Hope this clarifies.
    SK

Maybe you are looking for