https://github.com/drduh/macOS-Security-and-Privacy-Guide
Very good also if you liked this
31–40 of 78 posts
https://github.com/drduh/macOS-Security-and-Privacy-Guide
Very good also if you liked this
Why disable the captive portal detection? Is macOS detecting MITMing for you bad?
> An attacker could trigger the utility and direct a Mac to a site with malware without user interaction, so it's best to disable this feature and log in to captive portals using your regular Web browser, provided you have first disable any custom dns and/or proxy settings. See https://github.com/drduh/macOS-Security-and-Privacy-Guide#ca...
Very interesting! I’m reading it quite thoroughly so I don’t have any immediate thoughts but this did remind me of another similar guide in the spirit of things if you haven’t seen it: https://github.com/drduh/macOS-Security-and-Privacy-Guide Very good also if you liked this
Thanks for the kind words!
I like the title and premise of the article, but a list of tips with no description makes this feel like the standard "Tweak Ur Registry" article. I know OP is the author so I'm not trying to be a jerk, but I think adding details would improve things. To give specific examples, it is totally unclear why the article recommends creating an unprivileged account (the default user account is already unprivileged without e…
To give specific examples, it is totally unclear why the article recommends creating an unprivileged account (the default user account is already unprivileged without entering a password for anything That's not correct. The first account created is an Admin account. It has more privileges than a Standard account. Try the following in macOS High Sierra 10.13.6 as a Standard account then again as an Admin account. Open…
I like the title and premise of the article, but a list of tips with no description makes this feel like the standard "Tweak Ur Registry" article. I know OP is the author so I'm not trying to be a jerk, but I think adding details would improve things. To give specific examples, it is totally unclear why the article recommends creating an unprivileged account (the default user account is already unprivileged without e…
Thanks for the feedback! Standard accounts are recommended by Apple itself as a best practice in lieu of administrator accounts. Also, sudo is not available in standard accounts which protects against any would-be vulnerability. I updated the post regarding application sources. I changed Google DNS with Cloudflare's 1.0.0.1. Others also mentioned the fact that suggesting a VPN provider is risky, so I also removed it.…
Unless standard accounts don't have access to "su" at all, but I can't see that being the case without locking off access to terminal functions altogether, which would make macOS completely unusable for I would wager most of the people on this site. Looking at /usr/bin/, su is 0755 permissions.
Even if you didn't know the username of the admin account, /etc/passwd is 0644 so you could look it up as an unprivileged user -- again, unless macOS has some system level thing blocking all access to the terminal.
(Security & Privacy / Location Services / System Services / Details / Setting Time Zone)
Interesting: If I deny System Services location access for 'Setting Time Zone', my iMac 5K changes the color temperature … (Security & Privacy / Location Services / System Services / Details / Setting Time Zone)
Give me a good reason why defaults chosen by a macOS user would be more secure than those chosen by a security team working full time on developing the system. This article isn't even that bad if you are willing to make your system less practical, but even here you are potentially making your system less secure as suggested in some other comments.
(Yep, 'safe' files, not safe files, it's almost like a long-running joke by some Safari developer.)
Curious, what are some opinions of those "endpoint security" solutions that companies make engineers install on their laptops? Effective, intrusive? What's your experience.
They can be effective or intrusive, it depends on the implementation. I've used one (Fleetsmith) on MacOS and configured it to be non-intrusive. It was able to enforce some of the items in this blog post (encrypted drives with key escrow, screen saver with password time), and it also was able to require latest updates for some software such as Chrome, Docker, Slack, etc. We don't use this for engineers only, we use e…
(Jamf Now usually gets mentioned but it's not my thing …)
Interesting: If I deny System Services location access for 'Setting Time Zone', my iMac 5K changes the color temperature … (Security & Privacy / Location Services / System Services / Details / Setting Time Zone)