Earlier quoted context omitted.
Those permissions are necessary for any blocker to perform its function. And while the threat models for blockers and vpns are different, I agree that I would trust a local blocker [threat: extension hijack via auto-update; mitigation: very public source and update policy] much more than I would trust any third party vpn [threat: their 'no logging' policy is insufficient or they don't honor it; mitigation: 'we promis…
> Those permissions are necessary for any blocker to perform its function. Not blockers for Safari like Wipr that use Content Blocking Extensions: https://giorgiocalderolla.com/wipr.html
Hardening macOS
51–60 of 78 posts
Re: Hardening macOS
#52Thanks to the author for compiling and sharing this guide. Two of the recommendations have the potential to make your Mac less secure: 1. > …install an ad blocker (I recommend uBlock Origin) While uBlock Origin has a great track record, it requires these permissions: * Access your data for all websites * Read and modify privacy settings * Access browser tabs * Access browser activity during navigation That is a lot o…
Those permissions are necessary for any blocker to perform its function. And while the threat models for blockers and vpns are different, I agree that I would trust a local blocker [threat: extension hijack via auto-update; mitigation: very public source and update policy] much more than I would trust any third party vpn [threat: their 'no logging' policy is insufficient or they don't honor it; mitigation: 'we promis…
Re: Hardening macOS
#53Earlier quoted context omitted.
> Those permissions are necessary for any blocker to perform its function. Not blockers for Safari like Wipr that use Content Blocking Extensions: https://giorgiocalderolla.com/wipr.html
Content Blocking Extensions are pretty neat from a privacy perspective, but they're quite limited in functionality since they're basically glorified block lists (why you'd pay $2 for a list that's freely published is another question) and it requires support from the platform. uBlock supports a lot of features that CBE apps can't.
Re: Hardening macOS
#54Give me a good reason why defaults chosen by a macOS user would be more secure than those chosen by a security team working full time on developing the system. This article isn't even that bad if you are willing to make your system less practical, but even here you are potentially making your system less secure as suggested in some other comments.
If you understand the tradeoffs, you can do a wide variety of things to massively increase the inherent security of your Mac by changing system and app configurations.
Re: Hardening macOS
#55Or you know, you could just download the DOD profiles from their website.
Re: Hardening macOS
#56More importantly, how secure are my parents on iOS devices vs the Mac for most of the vectors described here?
Re: Hardening macOS
#57>Go to System Preferences > Security & Privacy > Firewall > Firewall Options… and check Block all incoming connections Thanks, but no, I need this one. The whole guide is for people feeling paranoid. PS: I'm not trying to say you should not make your machine more secure, but blocking\locking "all the stuff" is not a sane option either.
Re: Hardening macOS
#58>Go to System Preferences > Security & Privacy > Firewall > Firewall Options… and check Block all incoming connections Thanks, but no, I need this one. The whole guide is for people feeling paranoid. PS: I'm not trying to say you should not make your machine more secure, but blocking\locking "all the stuff" is not a sane option either.
What do you need it for that it actually prevents? I've used this for close to a decade, and it has never broken anything. Sounds like FUD mate.
Re: Hardening macOS
#59Or you know, you could just download the DOD profiles from their website.
Could you elaborate?
Re: Hardening macOS
#60>Go to System Preferences > Security & Privacy > Firewall > Firewall Options… and check Block all incoming connections Thanks, but no, I need this one. The whole guide is for people feeling paranoid. PS: I'm not trying to say you should not make your machine more secure, but blocking\locking "all the stuff" is not a sane option either.
What do you need it for that it actually prevents? I've used this for close to a decade, and it has never broken anything. Sounds like FUD mate.