storePassword(form[“password”])
storeHint(form[“password”])Of course, you can argue about the design but it's still not a dynamic vs. static type issue.
FooWidget(string s)
and
SecureFooWidget(string s)
could just as easily been confused..
1. Lack of automated unit tests covering the code in question. 2. Lack of automated functional tests running through scenarios of setting up an encrypted volume with or without a hint. 3. Lack of strict review process for the disk utility's codebase.
This assumes automated tests are also peer-reviewed.
1 - 3 won't guarantee a bug-free project, but I doubt this bug would've made it into production.
You'd think the developer/QA that worked on that particular feature would have manually tested it at least once.
Or anyone else, it is seemingly not a hidden, elusive bug that can only be caught when a number of particular conditions concurrently happen.
According to Matheus Mariano (that seemingly was the first to find it and report to Apple):
https://news.ycombinator.com/item?id=15408258
https://medium.com/@matheusmariano/new-macos-high-sierra-vul...
The only needed condition is that the Mac has a SSD, and in his words:
"I really don’t know how this went unnoticed by Apple (and anyone else). "
Doing a typo of writing passwordInput instead of passwordHintInput is not that unlikely, even though it is unfortunate.