TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

macOS Security and Privacy Guide

323 点作者 Nginx487超过 4 年前

15 条评论

pvg超过 4 年前
This has popped up a bunch of times before:<p><a href="https:&#x2F;&#x2F;hn.algolia.com&#x2F;?query=macOS%20Security%20and%20Privacy%20Guide&amp;sort=byDate&amp;dateRange=all&amp;type=story&amp;storyText=false&amp;prefix&amp;page=0" rel="nofollow">https:&#x2F;&#x2F;hn.algolia.com&#x2F;?query=macOS%20Security%20and%20Priva...</a><p>It&#x27;s not good. See:<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=17904304" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=17904304</a>
评论 #24247194 未加载
mindfulhack超过 4 年前
I love how this is offered fully in Chinese, and that reminds me of something. Every operating system like macOS has its place, no matter what one&#x27;s threat model is. Don&#x27;t just say &#x27;move to Linux if you&#x27;re really worried about security or privacy&#x27;.<p>Maybe someone in China or another authoritarian regime needs to look less suspicious on the outside by using macOS instead of Linux. For those people, this information is gold.<p>BTW, this is indeed the famous Github guide many of us have known for years, just now renamed and updated.<p>2016 HN discussion of it with the old title, &#x27;A practical guide to securing macOS&#x27;: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=13023823" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=13023823</a>
评论 #24244067 未加载
评论 #24246623 未加载
snazz超过 4 年前
I&#x27;m somewhat surprised that this guide recommends Homebrew. I agree that using a package manager is a good way to keep software updated from a central, trusted repository--always a good thing--but Homebrew makes a number of trade-offs for convenience instead of security. MacPorts has most of the same common packages and doesn&#x27;t mess up filesystem permissions like Homebrew does. If I remember correctly, the all-inside-the-home-directory technique used in this guide is unsupported by the Homebrew developers as well.<p>See <a href="https:&#x2F;&#x2F;saagarjha.com&#x2F;blog&#x2F;2019&#x2F;04&#x2F;26&#x2F;thoughts-on-macos-package-managers&#x2F;" rel="nofollow">https:&#x2F;&#x2F;saagarjha.com&#x2F;blog&#x2F;2019&#x2F;04&#x2F;26&#x2F;thoughts-on-macos-pack...</a> for a more nuanced take on this.
评论 #24244365 未加载
评论 #24244278 未加载
评论 #24246216 未加载
评论 #24244761 未加载
abledon超过 4 年前
I was looking at Yabai [1] as a window manager and it requires SIP[2] to be disabled for advanced features... Is SIP really needed ? I see that it didn&#x27;t even exist since &quot;since OS X 10.11 &quot;El Capitan&quot;.&quot;.<p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;koekeishiya&#x2F;yabai&#x2F;wiki" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;koekeishiya&#x2F;yabai&#x2F;wiki</a><p>[2] <a href="https:&#x2F;&#x2F;github.com&#x2F;drduh&#x2F;macOS-Security-and-Privacy-Guide#system-integrity-protection" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;drduh&#x2F;macOS-Security-and-Privacy-Guide#sy...</a>
评论 #24243851 未加载
评论 #24246052 未加载
krn超过 4 年前
As a side note: isn&#x27;t ChromeOS a <i>safer</i> alternative to macOS in 2020[1]?<p>[1] <a href="https:&#x2F;&#x2F;www.chromium.org&#x2F;chromium-os&#x2F;chromiumos-design-docs&#x2F;security-overview" rel="nofollow">https:&#x2F;&#x2F;www.chromium.org&#x2F;chromium-os&#x2F;chromiumos-design-docs&#x2F;...</a>
评论 #24243961 未加载
评论 #24248761 未加载
评论 #24244755 未加载
secfirstmd超过 4 年前
This guide is great. It&#x27;s a pity there is no easy to use (maybe GUI) tool for the average user go be able to implement a lot of the things mentioned here. There used to a few scripts around but most seem outdated. I&#x27;m thinking along the lines of Harden Tools for Windows. Great open source project for someone.<p><a href="https:&#x2F;&#x2F;securitywithoutborders.org&#x2F;tools&#x2F;hardentools.html" rel="nofollow">https:&#x2F;&#x2F;securitywithoutborders.org&#x2F;tools&#x2F;hardentools.html</a>
评论 #24243565 未加载
评论 #24243811 未加载
tptacek超过 4 年前
The thing about PRNG &quot;entropy&quot; and when to enable Filevault is almost certainly false, and based on a misconception of how PRNGs work.<p>Also, recommending libpurple-based IM clients as a security&#x2F;privacy measure, so you can run OTR over them, is probably a bad idea.<p>And it recommends Mac antivirus! Do not install antivirus on your Mac.
评论 #24247225 未加载
fouc超过 4 年前
Nice guide. I didn&#x27;t realize the security implications of iOS devices and the Touch Bar (being practically an iOS device itself).<p>I&#x27;d be interested to see an equivalent guide for Android devices. My current suspicion is that I&#x27;d be far more alarmed by Android than iOS but it would be nice to verify this.
评论 #24243891 未加载
评论 #24243814 未加载
评论 #24243522 未加载
lwouis超过 4 年前
Does anyone knows of a similar collection of tweaks, but for getting performance out of macOS?<p>Things like disabling Spotlight so it&#x27;s not indexing node_modules and other folders, or adding tools to the Developer Tools to disable network checks with apple servers when you want to run a binary
评论 #24254028 未加载
clairity超过 4 年前
i&#x27;ve increasingly been having issues with hands off![0] on my machine (intermittent high cpu usage, regular kernel panics), and was actually looking at this guide a while back to decide whether i should switch to pf instead[1].<p>but pf seems to require much more configuration and management. anyone have experience&#x2F;pointers in this regard?<p>[0] i used to use little snitch many years ago, but ran into similar issues with it over time (maybe it&#x27;s better now).<p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;drduh&#x2F;macOS-Security-and-Privacy-Guide#kernel-level-packet-filtering" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;drduh&#x2F;macOS-Security-and-Privacy-Guide#ke...</a>
评论 #24245633 未加载
jmnicolas超过 4 年前
&gt; Is your adversary a three letter agency (if so, you may want to consider using OpenBSD instead);<p>A 3 letter agency won&#x27;t be stopped by OpenBSD or any other OS.<p>There is so much security holes in the hardware itself and ultimately they can always &quot;convince&quot; you to release your data.
评论 #24243727 未加载
评论 #24244600 未加载
Simon_says超过 4 年前
It&#x27;s enough to make one want to switch to OpenBSD or Linux.
评论 #24248251 未加载
ChrisMarshallNY超过 4 年前
This is great! Thanks for sharing it. Obviously a labor of love.
Razengan超过 4 年前
Should add an explanation for what &quot;sepOS&quot; is.
t0mmyb0y超过 4 年前
This fails to make much sense overall. My macs only talk to apple when I let them and it was way simpler than this.