Using Spotlight from the OS X Commandline
0xfe.blogspot.com
0xfe.blogspot.com
Spotlight peeks inside files to create an index, and Version-supported apps maintain a changelog of file diffs. These OS X features save data in hidden locations, separate from the file.
This means that:
(a) it is very difficult to delete a file and be certain it's really gone,
(b) you can't have a public area, a private area, and a highly confidential area on the same system; it's all commingled to the same level of privacy,
(c) you can't make a backup of the non-confidential files without risk of getting the confidential files too,
(d) pieces of an encrypted file (if you use TrueCrypt for example) might get saved unencrypted in Spotlight's and Version's hidden locations,
I could go on, but you get the idea. It breaks down the notion of a file having a distinct level of security or privacy, and doesn't replace it with a better notion.
We already had the following problems:
(1) deleting a file doesn't really remove it on any major OS, including OS X, unless you use a special shredding program, and these days even shredding may be ineffective on solid-state drives because of wear-leveling and caching,
(2) the swap space can contain pieces of a file,
(3) temporary files created by editors, word processors, and other apps might retain parts of file.
Now Spotlight and Versions make the problem even worse for Mac users who care strongly about privacy and security.
We're getting to the point--or probably well past the point--where you have to maintain at least 2 or 3 separate systems: one for public work, another for personal or private work, and a third for highly confidential work.
All what you said is completely irrelevant for the vast majority of people. So Apple doesn’t trade it off against the increased convenience both Spotlight and Versions give you.
In real life people do think of pieces of paper as having different levels of security or privacy. Some pieces of paper you can leave out on the coffee table, others get locked in a desk, and still others in a safety-deposit box.
Also, as separate point, your use of the word "trade-off" assumes that there is no alternative other than giving the user some complex privacy-aware UI or complicated procedures.
But using whole-disk encryption doesn't invalidate my comments about Spotlight and Versions. When you've logged in (i.e., mounted the encrypted volume), Spotlight and Versions will still be storing pieces of yours files in hidden locations, you still can't truly delete a file without a lot of know-how, etc.
System Preferences -> Spotlight -> privacy tab
to overwrite then delete the spotlight indices, disable spotlight then overwrite and delete:
$ sudo srm --simple -rf /.Spotlight-V100/
There's also whole disk encryption (unfortunately not particularly robust -- I don't understand the reason but something about how the login password is stored seems to make this somewhat weak to eg the government) built in, as well as encrypted disk images and truecrypt.My broader point is that it is becoming impossible to truly delete a file or maintain separation between different parts of your data unless you are very technical and meticulous.
How many other features are there in OS X like Spotlight or Versions that we need to be aware of?
The OS should be designed so that we don't need to be constantly on guard for these privacy gotchas.
As far as I understand it, with FileVault 2:
- encryption is full disk AES128 (with optional AES256) with XTS.
- the AES key is apparently [1] stored in the keychain on the recovery partiton, which is itself encrypted with 3DES, and unlocked with the login passwords. The login passwords are not stored anywhere, they are used as the encryption passphrase: decryption failure means that the provided password is wrong.
People have been able to retrieve the AES key with DMA attacks via special Firewire devices on a running system in less than a hour (I guess they could have used the PCIe slot, and maybe Thunderbolt) by dumping and scanning the memory, and this impacts just about any system out there, not just Macs and FileVault, but TrueCrypt also [0].
If you strongly need full privacy separation between contexts, set up a virtual machine for your confidential work, and encrypt that. Then you can monitor what crosses the security boundary yourself, and deleting the VM means the data and any possible fragments of that data generated by nosy operating system features are gone.
Side note: Check out Finder's advanced preferences for 'Empty Trash Securely'. Additionally, I believe the swap space is now encrypted by default on Lion (at least for laptops), even if you don't have full disk encryption enabled.
One of my favorite is pbpaste/pbcopy.
What's yours?
Not sure if it'll carry across to ML, what with updates going through the Mac App Store there.
softwareupdate -d -a
downloads all updates to /Library/Updates. For each update, you get a .pkg file to install and a metadata file that includes this description.`say` lets you do text-to-speech in command line.
For example, if I want to install mercurial and git with homebrew:
brew install git mercurial; say "The task is finished, Master."
This will cause the terminal to bounce and add a little badge with the number of tasks that require your attention if it's out of focus :)
Tip: `open .` opens the current directory in the Finder.
open vnc://[user@]host[:port]
connects as user to host on port with Screen Sharing, and, more generally, "open URL" works for any URL scheme registered with Launch Services, including, but not limited to, the obvious ones. osascript
of course: it lets you control the UI of Cocoa applications, and even more for scriptable ones: osascript -e 'tell application "Safari" to close every document ¬
whose url contains "news.ycombinator.com"'
(¬, option-(lowercase L), is the AppleScript line continuation character)alias locate='mdfind'
is in order (on my system).