What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?
What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?
Part of the OSX security strategy is to minimize users installing things they shouldn't by making it difficult (enforced code signing, confirmations when opening an unsigned or new application). The other side is minimizing attack surface for exploits by staying up-to-date, not shipping crap like Java unless the user explicitly needs it, and (increasingly) sandboxing applications to user-approved subsets of the filesystem.
Bolt-on detection and resolution of malware infections is just not a part of the OSX security ecosystem like it is with Windows.
Little Snitch can help give you a picture of what's going on with regard to your network card, but at the end of the day malware can usually hide its traffic in an otherwise-trusted application to avoid that sort of detection.
You might want to check out mtree(8) then. It's serves well as the FreeBSD/OS-X Tripwire[1] equivalent.
My solution for that is to deny anything I don't recognize, and create rules for things I see more than twice, but if you're conditioned to click "OK" on everything you see, Little Snitch isn't going to to much for you...
If you really want to monitor what's going in&out of your computer you'll need to use wireshark from other computer in your network... =)
[1] https://www.blackhat.com/docs/us-15/materials/us-15-Wardle-W... [PDF Warning]
The code required for them to do their thing is so intrusive into the operating system that it has serious effects on stability.
And they are not that effective anyhow. Since they won't be able to detect exploits in existing programs over authorised channels.
I also uninstalled Flash.
1) A VPN company, who you've had the opportunity to research, who's primary business and reputation is based on handling your traffic.
2) Each and every WAP you connect to, in many cases with no real means to verify it's actually e.g. the official WAP of the hotel you're staying at, for something that likely costs the owners money rather than being seen as a profit center in and of itself. Their primary business and reputation is staked on something completely different than their handling of your traffic (be it their coffee, their accommodations, whatever.)
If you trust #2, statistics eventually comes into play - you will trust someone who shouldn't have been trusted. This also ignores that "public wifi" frequently performs MITM attacks for the... not entirely unreasonable purpose of providing login gateways, terms of use, etc. when you initially open up your web browser. But if you're already MITM traffic, it's not as big a stretch to substitute your own (poorly vetted) advertisements and affiliate links for a little extra revenue. Even if you don't do that, there's no guarantees your MITM tech isn't accidentally weakening security ala Superfish.
Not everyone can set up their own VPN endpoint. For those who can, and are willing to maintain it, great!
More: https://blog.getcloak.com/2013/03/04/why-trust-matters-when-...
(And what does AWS have to do with anything?)
http://www.macupdate.com/app/mac/35914/tcpblock
You can set it up to disallow all network traffic until you whitelist the binary. Not sure if it's actually hashing them or just checking the path though.
The two follow up contenders were ESET and Kaspersky.
http://googleprojectzero.blogspot.com/2015/06/analysis-and-e...