macOS' Quick Look Cache May Leak Encrypted Data

Ionut Arghire | June 20, 2018

macOS' Quick Look Cache May Leak Encrypted Data
The Quick Look mechanism on macOS, which allows users to check file contents without actually opening the files, may leak information on cached files, even if they reside on encrypted drives or if the files have been deleted. According to Apple, “Quick Look enables apps like Finder and Mail to display thumbnail images and full-size previews of Keynote, Numbers, Pages, and PDF documents, as well as images and other types of files.”  Quick Look registers the com.apple.quicklook.ThumbnailsAgent XPC service, which creates a thumbnails database and stores it in the /var/folders/.../C/com.apple.QuickLook.thumbnailcache/ directory. The issue, discovered by Wojciech Reguła, is that the service creates thumbnails of all supported files located in an accessed folder, regardless of whether the folder resides on an internal or external drive. It does the same for macOS Encrypted HFS+/APFS drives as well.  Because of that, the SQLite database in the com.apple.QuickLook.thumbnailcache/ directory contains previews, metadata and file paths of photos and other files in the accessed folders, depending on the file type and the installed Quick Look plugins. Said thumbnails, however, are not created only for the files a user has chosen to preview with Quick Look (which automatically results in the service caching file information), but for other files residing in the accessed folders as well. While the created thumbnails for previewed files are larger, smaller thumbnails are created for the other files, but even those could be used to leak content, Objective-See’s Patrick Wardle suggests.

Spotlight

One of the most common use cases for an SD-WAN solution is when bandwidth is constrained. Join Nitel VP of Product Management Pat Herron for this episode of "The Guys in Orange" to learn how SD-WAN solves this challenge for businesses.


Other News

AI APPLICATIONS

Enterprise AI platform Dataiku launches managed service for smaller companies

Dataiku | June 15, 2021

Dataiku is going downstream with a new product today called Dataiku Online. As the name suggests, Dataiku Online is a fully managed version of Dataiku. It lets you take advantage of the data science platform without going through a complicated setup process that involves a system administrator and your own infrastructure. If you’re not familiar with Dataiku, the platform lets you turn raw data into advanced analytics, run some data visualization tasks, create data-backed dashboards and train machine learning models. In particular, Dataiku can be used by data scientists, but also business analysts and less technical people. The company has been mostly focus...

Read More

AI TECH

Tech Mahindra and Subex Partner to Drive Scale Adoption of Blockchain-based Solutions for Telecom Operators Globally

Subex | November 05, 2020

To enable fraud mitigation and drive operational efficiencies for communication service providers by reducing compliance complexities and faster time-to-market 5th November 2020, BENGALURU, INDIA – Tech Mahindra, a leading provider of digital transformation, consulting, and business re-engineering services and solutions, and Subex, an industry leader in providing services based on Digital Trust, have announced strategic partnership to roll-out blockchain based solutions for telecom operators globally. These solutions will enable fraud mitigation and drive operational efficiencies for communication service providers (CSP) by reducing compliance complexities and faster tim...

Read More

Google Cloud and STS to Automate U.S. Navy Maintenance Inspections Using AI and ML Technology

Prnewswire | August 28, 2020

Google Cloud and Simple Technology Solutions (STS)—a Google Cloud partner and small business specializing in multi-cloud solutions for the federal government—today announced they are working with the U.S. Navy to modernize the maintenance and repairs inspection process for Navy vessels and facilities. STS will use Google Cloud artificial intelligence (AI) and machine learning (ML) technologies on inspection drone-captured images to detect, prioritize, and predict its maintenance needs. The work was awarded to STS as a Phase I Small Business Innovation Research project due to the technology innovation and potential for commercialization....

Read More

THE BEST UPWORK AGENCY – THE FOURTH AWARD

MobiDev | July 24, 2020

This year MobiDev won the fourth award as Upwork’s Best Agency in Ukraine. The first place in the Web, Mobile & Software Development category is ours for the fourth year in a row. Although this year, the Upwork Ukraine Awards Ceremony took place online in Zoom, that didn’t stop us from attending it.We are proud to keep the leading position and to justify the confidence of our clients for many years. Without such an awesome team none of this would have been possible. Thank you, guys! Alone we could do so little, together we are capable of so much....

Read More

Spotlight

One of the most common use cases for an SD-WAN solution is when bandwidth is constrained. Join Nitel VP of Product Management Pat Herron for this episode of "The Guys in Orange" to learn how SD-WAN solves this challenge for businesses.

Resources

Events