Hardening macOS
bejarano.io
bejarano.io
FWIW, CIS level 1 will mean people get locked out of their machines very frequently. Complex 15 character passwords with 3 retries from memory. So you need a half-decent MDM to unlock quickly. There is no half-decent MDM out there. Only shit ones but workable like Jamf.
Also the username does't get auto-populated on login so the typo can be in username but the user assumes it is with password. Very fast way to get lock outs.
To pass a full security review you might want to play with Google Santa. But that is intense.
Also disabling things like AirDrop and biometric unlock is a productivity inhibitor.
Disabling Bonjour can cause strange problems for some people (e.g. using Reflector 4).
Basically I hate my mac that is hardened all the way so have a second machine (Mac Studio Ultra) in a more secure location that is less hardened and more pleasant to work with.
Can you please elaborate? What problems would you pay to see solved in MDMs?
Like using a jump box basically but with no external machine
Many of the folks who contribute to CIS come from .gov backgrounds and have a bias towards the compliance controls that state/local have to deal with. Note the word compliance vs. security. The password thing for example is driven by IRS Pub 1075 — most everyone else has moved on to more rational standards.
Out of curiosity, have you looked beyond usual suspects such as JAMF or inTune to targeted solutions like https://mosyle.com/ or ultra straightforward like Apple’s new https://www.apple.com/business/essentials/ ?
// Your last comment is interesting, I think there’s a lot to be said for a dedicated trusted-work-only machine, with no email, no web browsing other than admin panels.
> For the security enthusiast, who wants to go the extra mile.
> 16. Use a password manager
Hard disagree. Using a decent password manager ought to be considered one of the baby steps of online security.
It's a lot more effort to configure a password manager than it is to check a few radio buttons and then move on.
Plus, that's setting you up for WebAuthn passkeys to become more pervasive and that's a transformative change relative to password logins.
It costs money but it's not technical to work with either. Hopefully the day comes when password managers are effectively obsolete because we finally finally FINALLY give up on the ludicrous practice of using symmetric information for 3rd party authentication.
What? It's more, not less usable. You plug in a key and now all you need is a 4-8 digit PIN for most operations while still being secure, not a 20+char random password, and it's not tied to a specific system either. HSMs are one of the rare cases in security where they are both more secure and better UX.
>chances are the Mac they're buying has some form of Touch ID for authentication
I addressed this. That only applies to new and new-ish notebooks unless you also get a special Apple-only keyboard. Even for notebooks, it only applies if you have the notebook close, open and/or are happy to reach for it. If someone is doing the common pattern of their notebook docked at their desk to another screen and peripherals at least some of the time, now Touch ID is most decidedly not right there (again, barring sticking only to Apple keyboards). And not everyone is 100% exclusively in the Apple ecosystem, even if they have lots of Apple stuff. If website credentials are tied to keys, one can just unplug and plug it into a Linux/BSD/Windows system and still login fine.
I don't disparage making use of biometrics on Macs or iDevices a single bit, and indeed I think it's weird and silly that Apple hasn't done Face ID for the Mac. But that doesn't mean USB keys or smart cards aren't super handy for a lot of Mac usage same as they are on any other system. It's a fairly polished built-in supported feature of macOS, no reason not to consider taking advantage of it.
> Why? To prevent other apps from snooping on what you type.
> How? Go to Terminal.app > Menu bar > Terminal, click “Secure Keyboard Entry”.
I wasn’t aware of this setting. Seems like it should be enabled by default.
If I click an app in the Dock, I want it to come forward, always.
If an app launches for some other reason, I don't want it to steal the focus, ever. But that's in general, independent of Secure Keyboard Entry.
Fun side note: apps can steal focus from the lock screen password entry too (maybe this one has been fixed). Made it "fun" to log into locked screens while CI spawned dozens of windows in the background.
Agreed. I think I filed a Radar about this a dozen years ago or so.
But the new Monterey behavior doesn't solve this problem, because it only applies to very limited circumstances.
And if you click back on the old window after clicking an app icon (which is slow to load), the newly opening app perhaps should not steal focus (interrupting user interaction at an unpredictable point) once it does pop up (though I'm unsure if this is an ideal user experience, how should the new app indicate its presence?).
I can't even begin to list the number of times where I've hit the enter key in an IDE at the exact moment that a application with a crucial modal message box steals focus.
I'm not sure there's a disagreement here at all. Normally there shouldn't be any time for a context switch between launching an app and the app showing its window. If you're talking about a slow launching app, then yes, I agree that's a problem, and I commented on that here: https://news.ycombinator.com/item?id=31867084
In general, app launching is too slow nowadays. Apple used to optimize this on Mac OS X, but they seem to have completely given up. Maybe it's "security" checks. Anyway, it can be annoying.
Just no.
defaults write com.apple.terminal SecureKeyboardEntry -bool true- NIST SP 800-53r5 Low, Moderate, and High - DISA-STIG - NIST 800-171 - CNSSI-1253 - CIS macOS Benchmarks Level 1 and 2 - CIS Critical Security Controls Version 8
If you've been following the project closely you'll notice that rules that were originally written as shell scripts are going away in favor of config profiles.
[1] https://csrc.nist.gov/publications/detail/sp/800-219/final [2] https://github.com/usnistgov/macos_security
The question would become a matter of "is recovery part of security"?
Aren't backups a far better solution?
Also, I believe (on M1) that entering guest mode requires the computer to reboot into an untrusted state, so even if there's some 0-day to bypass Guest mode access control, the main encrypted filesystem won't be available.
This is underrated. There are many, many browser extensions I would love to use, but I will never install. If it's from Google or Apple or a company I pay money to, I will install it. Or if it's uBlock Origin or Privacy Badger. Otherwise, I just don't trust that a future update after the sale of the extension won't turn evil.
But, if you install an extension that from day 1 gets full dom access to all sites, it already has everything it needs to be evil.
[1] https://support.mozilla.org/en-US/kb/recommended-extensions-...
Interesting, I'd never heard of this before. "A binary authorization system for macOS". Open source.
That doesn't seem like helpful reply.
I was asking about the time/complexity/difficulty of setup. It can be somewhat painful to setup and train Little Snitch, but it's ok after that.
This is one I'm always torn about.
There are countless iOS and Android apps that forever ruined by future updates. And unless you have the older version lying around (ipa/apk) then you can never downgrade. I experienced similar with MacOS apps too and generally on other OSes as well. I'm okay with automatic software updates for the OS but for general standalone apps not so much.
So, a lot of you are probably rearing up to write me a 5000-word response essay about how unreasonable it is to expect MacOS to compete with Team Red from around the world. I know. No operating system will ever be perfect.
...but on the flip side, MacOS' security concessions really don't seem to protect the user, from where I'm standing. Apple has made it so that trusting their OS means trusting them, which frankly, I don't. Apple is part of PRISM. Apple put iCloud in Chinese government datacenters. Maybe that Chinese data is encrypted-on-disk (eg. secure), but the fact that the Chinese government has the decryption keys certainly doesn't make it very private. With any degree of likelihood, that's already happening in most first-world countries too.
The “actually scary stuff” is extremely important, should definitely worked on and improved. It’s important to advocate for that and educate the common user.
But in my opinion for the regular user, this is not an immediate problem.
They seem scarier. In reality it's not so clear what is the bigger threat. Many got a taste of this with COVID restrictions, but that is clearly tame to what would be possible with the information that was already gathered or if they had even more info about you.
> But in my opinion for the regular user, this is not an immediate problem.
At least not as obvious and many do not seem interested in privacy. Not sure if they are very afraid of being robbed, but it is a more tangible threat. One can only see what mass collection of sensitive information can lead to when looking at (relatively recent) history.* And it is as easy as ever to create lists of whatever needs to be erased by whoever can command this.
*: i.e. https://de.wikipedia.org/wiki/Rosa_Liste (can't find the English article on Wiki)
Even open-source require a level of trust, at least of the contributor ecosystem, because no one has time to read every line of code that makes up a modern operating system, let alone understand the implication of every line.
So are/were Microsoft, Yahoo!, Google, Facebook/Meta, YouTube, AOL and Skype. The Washington Post stated, after analysis 98% of PRISM production is/was based on Yahoo!, Google, and Microsoft. Not defending or apologising - merely stating fact. This is trotted out so often that it needs highlighting. Not trying to change your mind either - you do you. Just offering some balance to your opinion. I know that you are "holding a trillion dollar business accountable(tm)", but lets hold all these multi-billion dollar business accountable too.
> Apple put iCloud in Chinese government datacenters.
As does every company that has a market presence in China. iCloud is hosted in China and operated by GCBD. Effectively nothing to do with Apple and has little baring on iCloud. It's not private for local users, and that is bad. This does not mean that China legitimately has access to iCloud globally.
Oh, for sure. Microsoft is far-and-away one of the worst handlers of data, Yahoo and Google aren't much better either. This is a strawman though, and while it provides a nice bit of context around the rest of the status-quo for privacy, it doesn't absolve Apple of the fact that their security is half-theater, and the other half has convenient backdoors and workarounds for the involved parties. Given that the topic of this article is "Hardening MacOS" and not "Reviewing The Standards of Security in Big Tech", I chose to focus on Apple's particular issues, especially since the issues with those other companies are so well-documented on HN.
> It's not private for local users, and that is bad.
This is what I used that point to illustrate. Apple claims that privacy is a human right, yet apparently not all humans are created equal? It's a strange bit of hypocrisy, one they could easily avoid by refusing to negotiate with countries that take advantage of them.
The “petty threats” make up the large majority of risk for average users. Faaaar larger.
If your threat model includes worry about state level actors, Tails or QubesOS is the only thing I would recommend
The article does a fantastic job covering the fundamentals.
How do you build on that and take it further?
Is it even worthwhile or possible to have a reasonable chance of thwarting a state level actor?
All fantastic topics.
Isn't this just mental that you are a hairline away of peril if you do not do a twentysomething steps massaging every inch of the system right away?! : )
Like what?
su - admin
You can also run gui apps as admin, like: sudo -u admin /System/Applications/Utilities/Console.app/Contents/MacOS/ConsoleNeither of the above, replace a proper content blocker, like uBlock Origin (which can block much more than just DNS lookups.)
Some of its suggestions like use Tor are out of date.