TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

A practical guide to securing macOS

62 pointsby migueldemouraover 6 years ago

5 comments

tptacekover 6 years ago
There is some seriously folkloric jibber-jabber in here. For instance, you do not need to wait until after installation to enable FileVault because &quot;there is more entropy available to the system&quot;. Nor can you test the security of a CSPRNG by running &quot;ent&quot; on it!<p>In the same vein: <i>don&#x27;t</i> run out and sign up for a commercial OpenVPN hosting service, and for Christ&#x27;s sake don&#x27;t install AV software on your Mac.<p>I kind of love how this is like 19 pages of rubber chicken &quot;defaults write&quot; commands, followed by advice to use Transmission to torrent videos to watch in VLC.
评论 #17907266 未加载
评论 #17904416 未加载
评论 #17904366 未加载
评论 #17904374 未加载
评论 #17904592 未加载
评论 #17910642 未加载
tambourine_manover 6 years ago
<i>&gt;a modern Apple Macintosh computer (&quot;MacBook&quot;)</i><p>I don’t get this. Does the author think Apple only makes laptops now? Don&#x27;t the iMac and Mac Mini qualify as modern?
评论 #17904241 未加载
briandearover 6 years ago
Ridiculous guide.<p>&gt; Care should be taken when installing new software. Always prefer free and open source software (which macOS is not)<p>“Free” doesn’t have anything g to do with security and there are plenty of profound security flaws with all software — open source doesn’t make it inherently more safe.<p>One of the most serious security issues of the past few years came from OpenSSL&#x2F;Heartbleed. Equifax was from unpatched Apache Struts — while the cause was negligence on the part of Equifax, happened due to a vulnerability in open source software. I am definitely not arguing that closed source is more secure, but I am arguing that open and closed source can have significant vulnerabilities. One is not inherently safer than another; it depends on how it is used. Apache Struts has a significant vulnerability before it was patched — which means that it was unsafe at some point. How many years was OpenSSL vulnerable before the exploit was discovered? Closed source certainly doesn’t fare much better, however implying that open source is always safer is just incorrect. I use “always” here because the author said to “always” prefer free and open source over closed source. His qualifier, not mine. Always is a very strong word. Many open source projects are often at the level of a hobby, with part time, occasionally unprofessional management and processes. Of course many closed source software also has unprofessional management and processes as well. I am simply disputing the implication that open source is always better: it’s not. Often and perhaps generally, but not always. I would trust Apple closed source more than some rubygem created and maintained by a single developer as a side project, with dependencies created by other hobbyists as a side project. A rubygem, for example, is dependent on the security competency of the weakest dependency. Often the projects are well secured — but definitely not always.<p>I am a big supporter of open source, but arguing that open source is always more secure is just factually incorrect. And the “free” aspect is a political benefit, not a security one.<p>The author also has a clear lack of understanding of how FileVault works as an example, which calls into question any other recommendations made in this guide.
评论 #17910507 未加载
kjullienover 6 years ago
I have been running Linux for some months now on my workplace MPB ever since the whole root with empty password fiasco. I don&#x27;t trust macOS in any manner no matter how many fixes you try and apply to it, for some reason I feel like I simply can&#x27;t trust macOS security wise for my part.<p>Only darn problem is I can&#x27;t get my speakers working so I use Bluetooth headphones, but for a workmachine it&#x27;s fine.
评论 #17904780 未加载
评论 #17904530 未加载
andrewmcwattersover 6 years ago
Goodness, I&#x27;m floored. There&#x27;s an absolutely incredible amount of insight in that document. I can only imagine how many years of collective experiences and digging have resulted in this compilation.
评论 #17904324 未加载