'Show notifications on lock screen' should default to off, otherwise it can be a privacy violation

Originator:pedrum
Number:rdar://16078848 Date Originated:15-Feb-2014 07:20 PM
Status:Closed Resolved:18-Feb-2014 09:28 AM
Product:OS X Product Version:10.9.1
Classification:Security Reproducible:Always
 
Summary:
I share my desktop with my others with separate password accounts. 

I recently discovered that notification for email, calendar events and reminders, and Safari push were being displayed on login screen. I did not expect these private events to be "shared" with everyone.

Steps to Reproduce:
1. Have a notification providers enabled with 'show' option checked on.This appears to be default.
2. Switch to separate account
3. Log out and return to main login screen.
4. Trigger an event and have it displayed publicly to all with potentially sensitive data.

Expected Results:
1) I expect this setting to require explicit opt-in from users.
2) Ability to set all notifications on lock screen to off with one-click (or setting option). Right now, this requires me to go to all notification entries and de-select individually.This also requires me to continually audit this when I install a new app.
3) Perhaps a special case when using multi-user setup and have it be disabled by default.

Actual Results:
Private info shared with all users that use the same computer.

Comments


Please note: Reports posted here will not necessarily be seen by Apple. All problems should be submitted at bugreport.apple.com before they are posted here. Please only post information for Radars that you have filed yourself, and please do not include Apple confidential information in your posts. Thank you!