A practical guide to securing macOS
github.com
github.com
In the same vein: don't run out and sign up for a commercial OpenVPN hosting service, and for Christ's sake don't install AV software on your Mac.
I kind of love how this is like 19 pages of rubber chicken "defaults write" commands, followed by advice to use Transmission to torrent videos to watch in VLC.
(I wrote https://taoofmac.com/space/HOWTO/Switch in 2007, and over the years have always resisted contributions or “tweaks” of this sort since they often cripple the OS experience just for the sake of paranoia)
If you want to secure your Mac, install Little Snitch and don’t run stuff from outside the App Store. Period.
Privacy-wise, I'd pick Apple any day.
Can you clarify which other OSes you'd consider to be more hardened?
Looks like the author of the original Filevault paper thinks otherwise: https://github.com/drduh/macOS-Security-and-Privacy-Guide/is...
> Nor can you test the security of a CSPRNG by running "ent" on it!
Curious how then to test the PRNG output?
> In the same vein: don't run out and sign up for a commercial OpenVPN hosting service, and for Christ's sake don't install AV software on your Mac.
Ironically, the guide specifically says these exact two things ;)
> followed by advice to use Transmission to torrent videos to watch in VLC.
Transmission and VLC are better alternatives to most of the ad- and malware-ridden crapware out there, usually dominating search results. Of course, torrenting is bad for security and privacy - why don't you send a pull request with a strongly worded statement for effect?
Ent will show a perfect distribution of bits on a counter ticking 1, 2, 3, ... through MD5; that construction will to all appearances be a deterministic random bit generator, but it obviously is not. If you're at the point where you're wondering why you can't use "ent" to test if a CSPRNG is seeded, you're probably too far out from understanding the issues to resolve this in the middle of a thread.
I don’t get this. Does the author think Apple only makes laptops now? Don't the iMac and Mac Mini qualify as modern?
> Care should be taken when installing new software. Always prefer free and open source software (which macOS is not)
“Free” doesn’t have anything g to do with security and there are plenty of profound security flaws with all software — open source doesn’t make it inherently more safe.
One of the most serious security issues of the past few years came from OpenSSL/Heartbleed. Equifax was from unpatched Apache Struts — while the cause was negligence on the part of Equifax, happened due to a vulnerability in open source software. I am definitely not arguing that closed source is more secure, but I am arguing that open and closed source can have significant vulnerabilities. One is not inherently safer than another; it depends on how it is used. Apache Struts has a significant vulnerability before it was patched — which means that it was unsafe at some point. How many years was OpenSSL vulnerable before the exploit was discovered? Closed source certainly doesn’t fare much better, however implying that open source is always safer is just incorrect. I use “always” here because the author said to “always” prefer free and open source over closed source. His qualifier, not mine. Always is a very strong word. Many open source projects are often at the level of a hobby, with part time, occasionally unprofessional management and processes. Of course many closed source software also has unprofessional management and processes as well. I am simply disputing the implication that open source is always better: it’s not. Often and perhaps generally, but not always. I would trust Apple closed source more than some rubygem created and maintained by a single developer as a side project, with dependencies created by other hobbyists as a side project. A rubygem, for example, is dependent on the security competency of the weakest dependency. Often the projects are well secured — but definitely not always.
I am a big supporter of open source, but arguing that open source is always more secure is just factually incorrect. And the “free” aspect is a political benefit, not a security one.
The author also has a clear lack of understanding of how FileVault works as an example, which calls into question any other recommendations made in this guide.
Only darn problem is I can't get my speakers working so I use Bluetooth headphones, but for a workmachine it's fine.