Mac forensics expert Sarah Edwards says recent versions of Mac High Sierra are logging encryption passwords for APFS-formatted external drives in plaintext, and storing this information in non-volatile (on-disk) log files. The issue, if exploited, could allow an attacker easy access to the encryption password of encrypted APFS external volumes, such as USB thumb drives, portable hard drives, and other external storage mediums. This is the third major APFS bug reported in a technology that Apple introduced in March 2017.
Source: https://www.bleepingcomputer.com/news/apple/macos-high-sierra-logs-encryption-passwords-in-plaintext-for-apfs-external-drives/

