New key icon when using "sudo" implies security when it isn't secure

Originator:jalkut
Number:rdar://22058894 Date Originated:29-Jul-2015 05:09 PM
Status:Open Resolved:
Product:OS X Product Version:10.11 Beta (15A235d)
Classification:Security Reproducible:Always
 
Summary:
Starting in OS X 10.11 betas, using "sudo" or other apps that prompt the user for password using a standard password requestion function causes a "key icon" that strongly implies typing is secure. Previously the icon was a kind of "bullet" that effectively implied that typing would not be visible, but didn't as strongly imply that typing was secure.

As I requested in Radar #19189911, typing should be secured from prying eyes of e.g. system event taps while the Terminal is prompting for secure input. In lieu of that support, the icon shouldn't so strongly convey security that isn't being provided.

Steps to Reproduce:


Expected Results:


Actual Results:


Version:
10.11 Beta (15A235d)

Notes:


Configuration:


Attachments:
'NotSecure.png' was successfully uploaded.

Comments


Please note: Reports posted here will not necessarily be seen by Apple. All problems should be submitted at bugreport.apple.com before they are posted here. Please only post information for Radars that you have filed yourself, and please do not include Apple confidential information in your posts. Thank you!