Live data from Hacker News

macOS 11’s hidden security improvements

blog.malwarebytes.com

71–80 of 152 posts

Re: macOS 11’s hidden security improvements

#71
post #61

Earlier quoted context omitted.

This, a million times. Now that Mojave is starting to get dropped, Linux is exactly what the doctor ordered for me. I feel a lot safer in a system where I can check the locks instead of being told "the door's closed, you're fine."

Make no mistake, there are back doors into Linux as well.

Care to point out a few that I might accidentally have installed?

Re: macOS 11’s hidden security improvements

#72
post #67

Sounds good but a problem with Apple's latest releases are that a lot of its security features listen only to Apple and not to the user. This doesn't concern most of the improvements mentioned in the article, those are purely technical improvements at a very low level. But the signed system volume for example (also mentioned), while a good idea, lacks a convenient way for the user to make changes to it. I'm not very…

> signed system volume for example (also mentioned), while a good idea, lacks a convenient way for the user to make changes to it. MacOS has no convenient way to know if changes are made by the user or malware. It is a feature, not a bug, for most users. Why would you need to change system volume anyway?

As others have said, you might want to modify sshd_config. However, I disagree that that is a big deal. Just write a little script to fix whatever you want to modify after a major system upgrade. If you are messing with sshd_config, you should now how to write a script to modify it. It is not protected by SIP. I don't understand why so many unix competent people seem to think this is a big problem.

Re: macOS 11’s hidden security improvements

#73

Earlier quoted context omitted.

You get that. And about a million tradeoffs in terms of usability. No thanks. Edit: To those downvoting. If you genueinly think running linux isn't a UIUX downgrade on macOS you are totally deluded. Its more open. Cool. It's also a UX nightmare.

For a new job I've switched to 100% Ubuntu from Windows and I'm not missing much.. What would you be giving up?

office365 support? That's about it.

Re: macOS 11’s hidden security improvements

#74
post #61

Earlier quoted context omitted.

Make no mistake, there are back doors into Linux as well.

Back doors in the Linux kernel source code? No. Back doors in GNU/Linux distribution repositories? Maybe.

You don't think, with all the resources available to them, the intelligence community would spend just about whatever it took to sneak a vulnerability or two into the most-run piece of code on the planet? The core devs don't even have to be corrupted--there are 28 million lines of code in the kernel, you don't think a motivated adversary could sneak something past the gate keepers?

Re: macOS 11’s hidden security improvements

#75

The security improvement I want is that when I run ‘ps ax’ on a fresh install, I have reduced attack surface instead of dozens of random daemons hardwired into launchd like the one for classrooms(??), iCloud and photo sharing even when those features are disabled, etc.

This is a big issue - on Windows you can set services to not start up unless they are needed, and you can turn them off so they don't run at all. On macOS, the launchd configuration seems to be hard-wired and protected by SIP; there's no easy way to disable random daemons for features like remote student device management - something that most users would not need or want. And as you note even if you disable the asso…

> Not to mention photoanalysisd, which burns large amounts of CPU for days/weeks and runs even if you disable the intrusive and obnoxious holiday events/memories features in Photos.

This and many other daemons related to photos is very annoying. I have my photos stored on an external drive because the internal SSD isn’t large enough for that, and it’s a nightmare every time trying to eject the external drive. Even when nothing has changed in the photos library, these daemons will be busy scrubbing the disk and keeping it busy for hours or days. The only solution is to find each process (per user) and kill them.

Re: macOS 11’s hidden security improvements

#76

Earlier quoted context omitted.

On the other hand, Linux is getting better and better. And with the prevalence of web apps, the main obstacle to running non (MS | Apple) systems is getting smaller. With Linux, you can adjust the level of security you need and you keep the key. Security improvements appear also in BSDs, especially OpenBSD, but honestly I wouldn't recommend people used to macOS to switch to OpenBSD (yet).

You get that. And about a million tradeoffs in terms of usability. No thanks. Edit: To those downvoting. If you genueinly think running linux isn't a UIUX downgrade on macOS you are totally deluded. Its more open. Cool. It's also a UX nightmare.

Recently the hard drive in my Mac became inaccessible to MacOS even after formatting and a lot of other things. Somehow it was able to install Linux though, so I did that while waiting on the new drive to arrive. I tried a number of different distributions, and I had the experience you describe. It was death by UX papercuts and I could not wait to get back to MacOS by the second day. I hadn't used Linux in a decade outside of ssh to remote servers, and I really had high hopes for improvements in the UX since I last used it.

Re: macOS 11’s hidden security improvements

#77

Earlier quoted context omitted.

On the other hand, Linux is getting better and better. And with the prevalence of web apps, the main obstacle to running non (MS | Apple) systems is getting smaller. With Linux, you can adjust the level of security you need and you keep the key. Security improvements appear also in BSDs, especially OpenBSD, but honestly I wouldn't recommend people used to macOS to switch to OpenBSD (yet).

It's the year of the Linux desktop!

I can't even remember the last year desktop computing was relevant. Professionals absolutely use it, but the market share that has gone to phone, tablets, and chromebooks is incredible.

Re: macOS 11’s hidden security improvements

#78

Earlier quoted context omitted.

You get that. And about a million tradeoffs in terms of usability. No thanks. Edit: To those downvoting. If you genueinly think running linux isn't a UIUX downgrade on macOS you are totally deluded. Its more open. Cool. It's also a UX nightmare.

Nah. It's great. You can view hidden files in the file manager without memorizing a keyboard shortcut or terminal command. Most Window managers don't rely on track pad gestures and so the mouse feels like a first class citizen. Window management in the big DEs is better than macOS. MacOS is a frustrating mess to me.

To each their own, I guess; in case anyone else is wondering:

"keyboard shortcut": Command-Shift-period

"terminal command": defaults write com.apple.finder AppleShowAllFiles yes

Re: macOS 11’s hidden security improvements

#79

Earlier quoted context omitted.

This is a big issue - on Windows you can set services to not start up unless they are needed, and you can turn them off so they don't run at all. On macOS, the launchd configuration seems to be hard-wired and protected by SIP; there's no easy way to disable random daemons for features like remote student device management - something that most users would not need or want. And as you note even if you disable the asso…

photoanalysisd Does anyone else wonder what exactly it is analysing now, after the whole CSAM thing came to light?

The CSAM thing "came to light"? They announced it publicly and proudly, before it was even implemented! There's no reason to think they are hiding anything.

Re: macOS 11’s hidden security improvements

#80

Earlier quoted context omitted.

Back doors in the Linux kernel source code? No. Back doors in GNU/Linux distribution repositories? Maybe.

You don't think, with all the resources available to them, the intelligence community would spend just about whatever it took to sneak a vulnerability or two into the most-run piece of code on the planet? The core devs don't even have to be corrupted--there are 28 million lines of code in the kernel, you don't think a motivated adversary could sneak something past the gate keepers?

It's well known that they've already tried to insert back doors many times. On the other side is a huge amount of resources auditing and reviewing the kernel. Many reviewers, auditors, security analysts.
Post reply on HN