17 ms·
macOS Security and Privacy Guide
- fouc 6y agoNice guide. I didn't realize the security implications of iOS devices and the Touch Bar (being practically an iOS device itself). I'd be interested to see an equivalent guide for Android devices. My current suspicion is that I'd be far more alarmed by Android than iOS but it would be nice to verify this.
- throWaythxMod 6y agoYou can pretty much do anything with Android, the same cannot be said about Apple's dictatorship. I am not even sure about stock installs given Apple's poor security record.
- jabirali 6y ago> You can pretty much do anything with Android, the same cannot be said about Apple's dictatorship. The problem is that app developers can also do anything with Android, often against the users‘ will. Before I switched to iPhone, my choices for location access on Android apps were basically “access location 24/7”, or “no location support at all”; and even that was an improvement upon the earlier “the app will get these permissions, don’t install it if you disagree” model. iPhone, in contrast, had a sensible “only access location when the app is open” option. Similarly, uploading a single photo to Facebook on Android required the app to get full access to your whole SD card; on iPhone, I can send a photo without the app getting access to my storage at all (that single photo is copied into the Facebook sandbox by the OS). Perhaps Android has improved since, but so has iOS (see e.g. the feature list for iOS 14). For some of us, controlling our data without turning the phone into a full-time hobby is more important than having full system access. > I am not even sure about stock installs given Apple's poor security record. Do you have a link supporting that Apple’s security record is worse than other systems, relative to market share? As far as I know, the macOS permission system provides better sandboxing than either Windows or Linux by default. (Though if you work for it, you can harden Linux more.) And although there is a lot of malware for macOS, last I checked nearly all of it was in the form of Trojans and similar vectors, where a user has to download and execute untrusted code. That is an issue on any platform; a user running a malicious bash-script with sudo shouldn’t count the same as remote exploits in my opinion.
- shazow 6y agoYou're correct, both Android and iOS have improved. Both have the features you described today, neither had them several years ago.
- jabirali 6y agoIt’s good to hear that Android supports this as well now, but I think you understate the difference in when these features arrived. From a quick search, the location example was fixed in iOS 8 in 2014 [1], and in Android 10 in 2019 [2], putting Apple 5 years ahead of Google on privacy features. Based on the list of privacy features being introduced in iOS 14, my impression is that this is still the case? [1]: https://9to5mac.com/2014/06/04/apple-improves-location-services-in-ios-8-with-when-in-use-mode-visit-monitoring/ https://9to5mac.com/2014/06/04/apple-improves-location-servi... [2]: https://en.m.wikipedia.org/wiki/Android_10 https://en.m.wikipedia.org/wiki/Android_10
- shazow 6y agoThanks for looking up the timeline, I was not sure. Also full disk encryption on phones is another thing Apple did way earlier. I agree it's not exactly apples to Apples. Does Apple still have special permissions for their own apps which allows them to run unobstructed, but other apps need to jump hoops with callbacks and other workarounds? Are we expecting for Apple to always be 5 years ahead of Google on privacy features? Or did Google shift priorities with Android 10? Honestly if we're talking about buying an iOS device or an Android device in 2014, I'd lean towards iOS for sure. I don't feel the same way about it today.
- jabirali 6y ago> Are we expecting for Apple to always be 5 years ahead of Google on privacy features? Or did Google shift priorities with Android 10? Good question! My personal impression is that Google, being primarily a tracking company, reluctantly added just enough privacy features for people not to flock to Apple. (I think people have grown more privacy-conscious over the past few years, and Apple has marketed their privacy features heavily.) Links like this [1], listing the iOS 14 privacy features that will arrive in late 2020, appear to still be ahead of what Google has done yet – and e.g. Facebook’s reaction to the cross-app tracking block appear to indicate that this isn’t something they’ve encountered from Google. But being an iPhone user now, I of course notice more easily what’s happening in the Apple world than Google world. If you have an overview of new privacy features in Android, which aren’t in iOS, I’d be very happy to be proven wrong. I’d love to see a full arms race between Google and Apple on privacy, with both parties introducing novel features. [1]: https://www.macrumors.com/guide/ios-14-privacy/ https://www.macrumors.com/guide/ios-14-privacy/ > Does Apple still have special permissions for their own apps which allows them to run unobstructed, but other apps need to jump hoops with callbacks and other workarounds? Unfortunately, yes. There is e.g. no way to get as reliable background sync with things like Nextcloud and Resilio as you do with iCloud, since there’s no “run in the background” permission. Not sure about this, but I don’t think any other app can take over the lock screen in the same way as Apple Maps. You can’t set a default browser than Safari, but I believe this is changing in iOS 14. While I respect Apple for their stance on privacy and therefore use an iPhone, I do disagree with some of these missing permissions, and hope that a new round of anti-trust investigations may force them to open up on this.
- ignoramous 6y ago> I'd be interested to see an equivalent guide for Android devices. Recently shared: https://news.ycombinator.com/item?id=24091709 https://news.ycombinator.com/item?id=24091709
- jmull 6y agoThat part about iOS is confused. The focus on activation is weirdly myopic. If Apple wants to track your identity, location, and activities and send it to the Chinese government, they are going to be able to do that with or without that specific activation mechanism. They can do this in iOS or in macOS. The fear of the potential iOS-ification of macOS due to the use of Apple silicon in macs also has some logic holes. Apple can iOS-ify macOS with or without Apple silicon, and vice-versa. This is conflating hardware with the software it runs.
- secfirstmd 6y agoThis guide is great. It's a pity there is no easy to use (maybe GUI) tool for the average user go be able to implement a lot of the things mentioned here. There used to a few scripts around but most seem outdated. I'm thinking along the lines of Harden Tools for Windows. Great open source project for someone. https://securitywithoutborders.org/tools/hardentools.html https://securitywithoutborders.org/tools/hardentools.html
- djeiasbsbo 6y agohttps://objective-see.com https://objective-see.com have pretty good security related GUI tools for macOS. Things like ransomware protection, firewalls, task explorers. They also do malware analysis for macOS, definitely an interesting website.
- secfirstmd 6y agoTotally I'm a huge fan of the stuff on there
- throwaway13281 6y agoIronically, it's way more difficult to harden OS X compared to hardening W10, due to the lack of community. Although OS X is more secure by default, there are pretty glaring security holes that aren't easy to fix without tools.
- deleted 6y ago[deleted]
- jmnicolas 6y ago> Is your adversary a three letter agency (if so, you may want to consider using OpenBSD instead); A 3 letter agency won't be stopped by OpenBSD or any other OS. There is so much security holes in the hardware itself and ultimately they can always "convince" you to release your data.
- mikece 6y agoNo, you can’t stop “an agency” but you can make their job harder and slow them down. Using a hardened O/S is part of the mix but not connecting to the net if you can avoid it is another. A good overview of how to configure you computer for privacy can also be found on episode 177 of Michael Bazzel’s “Privacy, Security, and OSINT Podcast”: https://overcast.fm/+Hbyfl32i0 https://overcast.fm/+Hbyfl32i0
- Batman8675309 6y agoIf your adversary is a three letter agency, you might want to consider a Qubes/Whonix combo. It's the closest you're gonna get.
- mindfulhack 6y agoI love how this is offered fully in Chinese, and that reminds me of something. Every operating system like macOS has its place, no matter what one's threat model is. Don't just say 'move to Linux if you're really worried about security or privacy'. Maybe someone in China or another authoritarian regime needs to look less suspicious on the outside by using macOS instead of Linux. For those people, this information is gold. BTW, this is indeed the famous Github guide many of us have known for years, just now renamed and updated. 2016 HN discussion of it with the old title, 'A practical guide to securing macOS': https://news.ycombinator.com/item?id=13023823 https://news.ycombinator.com/item?id=13023823
- AsyncAwait 6y ago> Maybe someone in China or another authoritarian regime needs to look less suspicious on the outside by using macOS instead of Linux. There's even an official Chinese Ubuntu spin. You're probably more suspicious with macOS, since these tend to be in the hands of high-profile businessmen and such.
- beenBoutIT 6y agoIn an authoritarian regime everyone with a computer looks suspicious.
- seniorivn 6y agoquite the opposite, in a mass surveillance state anyone without virtual personality fingerprint and tracking data is suspicious
- Shared404 6y agoHow about: In an authoritarian regime/mass surveillance state everyone is suspicious?
- stjohnswarts 6y agoIn an authoritarian regime everyone looks suspicious because by definition the government trusts no one except themselves and even then it's not very true.
- abledon 6y agoI was looking at Yabai [1] as a window manager and it requires SIP[2] to be disabled for advanced features... Is SIP really needed ? I see that it didn't even exist since "since OS X 10.11 "El Capitan".". [1] https://github.com/koekeishiya/yabai/wiki https://github.com/koekeishiya/yabai/wiki [2] https://github.com/drduh/macOS-Security-and-Privacy-Guide#system-integrity-protection https://github.com/drduh/macOS-Security-and-Privacy-Guide#sy...
- twhb 6y agoHere’s an instance of SIP preventing a Chrome update from bricking computers. https://arstechnica.com/information-technology/2019/09/no-it-wasnt-a-virus-it-was-chrome-that-stopped-macs-from-booting/ https://arstechnica.com/information-technology/2019/09/no-it...
- SahAssar 6y agoBricking means that the computer is no more useful for computing than a brick (or that you might as well use it as a brick). Don't use it for stuff that can be fixed with software.
- VRay 6y agoWhere do you draw the line, though? Something that might be a brick to a web developer would probably be perfectly serviceable to me as a firmware engineer Meanwhile, something that's a brick to me is often perfectly serviceable to someone who can operate a soldering iron Something that's a brick to a competent hardware tech might still be serviceable to a 3 letter agency
- krn 6y agoAs a side note: isn't ChromeOS a safer alternative to macOS in 2020[1]? [1] https://www.chromium.org/chromium-os/chromiumos-design-docs/security-overview https://www.chromium.org/chromium-os/chromiumos-design-docs/...
- jmnicolas 6y agoAfaik ChromeOS phones home to Google, so if Google is among your threat model (privacy) it's not good. Las time I checked, installing ChromiumOS wasn't easy and i'm not even sure there's a "ungoogled" version like there is for the Chromium web browser.
- krn 6y agoI meant, ChromeOS migth be a more secure, not necessarily a more private option. If macOS had a way higher likehood of zero-day attacks, ChromeOS phoning home wouldn't be the biggest concern to most users. Because in the first case the threat would be the entire world, and in the second case – only the US government.
- Shared404 6y ago> and in the second case – only the US government. And some percentage of Google employees. Probably not really a big deal, but still there.
- stjohnswarts 6y agoSecure is a very vague word, I think you're looking for "less hackable by hostile actors" then definitely chromeOS has a smaller footprint.
- extra88 6y agoI don’t know how ungoogled it is but it’s pretty damn easy to install CloudReady from Neverware.
- harpratap 6y ago
- ChrisMarshallNY 6y agoThis is great! Thanks for sharing it. Obviously a labor of love.
- clairity 6y agoi've increasingly been having issues with hands off![0] on my machine (intermittent high cpu usage, regular kernel panics), and was actually looking at this guide a while back to decide whether i should switch to pf instead[1]. but pf seems to require much more configuration and management. anyone have experience/pointers in this regard? [0] i used to use little snitch many years ago, but ran into similar issues with it over time (maybe it's better now). [1] https://github.com/drduh/macOS-Security-and-Privacy-Guide#kernel-level-packet-filtering https://github.com/drduh/macOS-Security-and-Privacy-Guide#ke...
- celias 6y agoI use Murus to manage pf on a couple of Macs. They also have an application-layer firewall named Vallum. https://www.murusfirewall.com https://www.murusfirewall.com
- snazz 6y agoI'm somewhat surprised that this guide recommends Homebrew. I agree that using a package manager is a good way to keep software updated from a central, trusted repository--always a good thing--but Homebrew makes a number of trade-offs for convenience instead of security. MacPorts has most of the same common packages and doesn't mess up filesystem permissions like Homebrew does. If I remember correctly, the all-inside-the-home-directory technique used in this guide is unsupported by the Homebrew developers as well. See https://saagarjha.com/blog/2019/04/26/thoughts-on-macos-package-managers/ https://saagarjha.com/blog/2019/04/26/thoughts-on-macos-pack... for a more nuanced take on this.
- jabirali 6y ago> MacPorts has most of the same common packages and doesn't mess up filesystem permissions like Homebrew does. This is more a convenience than security question. I understand that Homebrew can install not only open source command-line tools, but also third-party binaries (via `cask`) and Mac App Store apps (via `mas`), and that all three types of software can be installed, updated, or removed via the same `brew` command or synced `Brewfile`. Does MacPorts offer something similar? In that case, how is its coverage compared to the systems above? (Context: I’m a long-time Linux user in the process of migrating to macOS.)
- snazz 6y agoAs I understand it, MacPorts is a fair bit more limited in that regard. For my purposes, I haven't found a need for the ability to install third-party binaries and Mac App Store apps through my package manager, since every third-party binary I have installed includes its own updater and the Mac App Store updates apps as well. I can see how setting up everything in one place could be useful, but I haven't run into a situation where it has been useful in my macOS usage quite yet. Homebrew and MacPorts are philosophically pretty different from each other and neither can be directly compared to Linux package managers. I think you'll find the solution of MacPorts for OSS command-line tools + Mac App Store for Xcode and other random stuff + third-party installers for things like Sublime Text and Microsoft Office works pretty well in practice, although it's not quite as clean as using one package manager for everything.
- Simon_says 6y agoIt's enough to make one want to switch to OpenBSD or Linux.
- jabirali 6y agoI think most of that guide would require roughly the same amount of work on Linux though (e.g. setting up firewalls, DNS, VPN, and FDE).
- Simon_says 6y agoAre you kidding? You still have to do work, but a third party doesn't get to decide if you can boot and what image you boot. > What is particularly worrying about this process is that it is a network-linked secure boot process where centralized external servers have the power to dictate what the device should boot. This is an abomination.
- jabirali 6y agoFirstly, your quote is about iOS not macOS as far as I can tell, so the competitor here would be Android not OpenBSD. Secondly, I interpreted your comment as “that list is long enough to make one want to switch to Linux”. I then stand by my comment that most of the suggestions on the list require at least the same amount of work on Linux. (Source: I’m a Linux user that has setup things like fscrypt, ufw, openvpn on my devices.)
- tptacek 6y agoThe thing about PRNG "entropy" and when to enable Filevault is almost certainly false, and based on a misconception of how PRNGs work. Also, recommending libpurple-based IM clients as a security/privacy measure, so you can run OTR over them, is probably a bad idea. And it recommends Mac antivirus! Do not install antivirus on your Mac.
- draebek 6y agoThe guide seems to say, "the best anti-virus is Common Sense 2020. See discussion in issue #44." I take this to mean that they recommend common sense instead of anti-virus software. It does also say, "Anti-virus programs are [...] possibly useful for catching 'garden variety' malware on novice users' Macs", so maybe that's what you disagree with, which is reasonable. I just wanted to point out that their main recommendation does not, to my reading, suggest to use AV.
- t0mmyb0y 6y agoThis fails to make much sense overall. My macs only talk to apple when I let them and it was way simpler than this.
- pvg 6y agoThis has popped up a bunch of times before: https://hn.algolia.com/?query=macOS%20Security%20and%20Privacy%20Guide&sort=byDate&dateRange=all&type=story&storyText=false&prefix&page=0 https://hn.algolia.com/?query=macOS%20Security%20and%20Priva... It's not good. See: https://news.ycombinator.com/item?id=17904304 https://news.ycombinator.com/item?id=17904304
- draebek 6y agotptacek's criticisms are quite valid. However, "it's not good" seems oversimplified to me? I found lots of interesting information in this. For example: information about the activation process for Macs, importance of setting a firmware password, disable some of the Spotlight services, and binary whitelisting through Santa. The repo also has the most comprehensive discussion I've seen about evicting FileVault keys from RAM on sleep: https://github.com/drduh/macOS-Security-and-Privacy-Guide/issues/124 https://github.com/drduh/macOS-Security-and-Privacy-Guide/is... Also, I'm not sure if this has been changed more recently than the comment you linked, but it seems like they actually don't recommend AV software anymore: "Therefore, the best anti-virus is Common Sense 2020. See discussion in issue #44." I grant you that having someone follow this top to bottom might be bad, but to say "it's not good" seems to both lack nuance and also to discard some useful, hard work done in good faith.
- pvg 6y agoA guide that can't be used safely by non-specialists while being aimed at them is not a good guide. It is a very simple conclusion with the added benefit of also being almost tautologically true. The thing probably does contain a bunch of interesting information but it's not good at its stated purpose.
- Razengan 6y agoShould add an explanation for what "sepOS" is.
- lwouis 6y agoDoes anyone knows of a similar collection of tweaks, but for getting performance out of macOS? Things like disabling Spotlight so it's not indexing node_modules and other folders, or adding tools to the Developer Tools to disable network checks with apple servers when you want to run a binary
- neilalexander 6y agoYou can already exclude things from Spotlight’s index in System Preferences.
- lwouis 6y agoI know, i'm doing it. I was saying I would love for a list of tweaks of that nature. Things I don't know about that I could do to improve performance