The first step is to stop relying on home-folder FileVault and move to full-disk encryption. Affected systems should be reconfigured in System Preferences so the entire disk is encrypted, then the OS X login password should be changed. That reduces exposure from logged credentials and limits the chance that older password material remains usable elsewhere on the system.
Why FileVault home-folder encryption is the wrong place to start
Home-folder encryption protects a narrower slice of the Mac than full-disk encryption, so the first response should be to remove that weaker design assumption rather than try to tune around it. If login credentials may be written or exposed by the encryption workflow, the issue is not just confidentiality of files, but the trust boundary around the user’s password and any data it can unlock.
Affected systems should be converted to full-disk encryption in the operating system settings, because that changes protection from “selected data at rest” to “the entire volume is encrypted when the machine is off.” That is the meaningful first move when password material may be involved.
What changes after you move to full-disk encryption
Once the whole disk is encrypted, the laptop’s rest-state exposure is materially reduced, and login secrets are less likely to sit in a partially protected location that can be reused elsewhere on the system. The password change matters because any password-related residue, cached derivation, or stale credential material should be treated as potentially usable until the account secret is refreshed.
This is also a practical containment step: if a local encryption feature is mishandling login material, changing the login password narrows the window in which older material remains valuable to an attacker or to later misuse by a different local process.
How to think about the fix operationally
The safe sequence is to reconfigure encryption first, then rotate the login password, then verify the system is using the stronger disk-level protection end to end. On a managed Mac fleet, that usually means confirming the encryption policy, checking that user guidance matches the new setup, and making sure the old configuration is not left enabled on only some devices.
That sequencing matters because changing the password alone does not correct the storage model, and enabling stronger encryption without credential rotation can leave previously exposed password material with residual value.
Risk and Threat Considerations
Logging or retaining login passwords creates a credential exposure risk, especially if the machine is shared, compromised, or later inspected by someone with local access. The concern is not only theft of the password itself, but reuse of that secret to access other services tied to the same account.
Failure mechanism: A weaker encryption design can leave login-related material outside the strongest protection boundary, so a local attacker, forensic examiner, or malware with file access may recover something that should have been isolated.
Impact: Exposure can lead to account compromise, reuse against other systems, and broader trust in the Mac being undermined, because a “protected” local account password may no longer be trustworthy after the incident.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Password exposure and rotation are directly about credential lifecycle control. |
| SC-28 — Protection of Information at Rest | The issue is about strengthening storage protection for data and secrets at rest. | |
| Recommendation — Rotate the affected login secret and enforce expiration and reissuance rules. Use full-disk encryption to protect stored information at rest. | ||
| ISO/IEC 27001:2022 | A.8.24 — Use of cryptography | Disk encryption is the core control change recommended by the answer. |
| Recommendation — Apply approved cryptography to protect local data and secret material. | ||
| CIS Controls v8 | CIS-3 — Data Protection | The answer centers on protecting data and credential material on the device. |
| Recommendation — Encrypt endpoints fully and reduce exposed local secret material. | ||
Practitioner Guidance
What to verify: Confirm that the Mac is actually using full-disk encryption after the change, and not just a user-home encryption feature or partial protection mode. Then verify that the login password is unique enough that resetting it does not break other access paths unexpectedly.
Common mistake: Teams often assume encryption is a binary on-or-off decision and miss the difference between protecting a home folder and protecting the entire disk. For password-related exposure, that distinction is the whole point.
Practitioner takeaway: Treat suspected password logging as a credential hygiene event, not just an encryption preference issue, and prioritize moving the device to the stronger disk-level model before considering the problem closed.
Related resources from NHI Mgmt Group
- What should users do first to improve home WiFi security?
- What happens when a Mac that uses Home Folder mounting keeps running an unfixed password logging bug?
- What happens when a remote access service is abused while users still trust its normal login process?
- What should organisations do first when breach data shows that passwords may already be exposed?