Beef Up Your Mac's Security
- 2005.09.15
Low End Mac Reader Specials
TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
Don't install Parallels to play poker online! Poker Mac will show you how
to download and install a native Mac poker application such as Full
Tilt Poker Mac.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.
Compare products like desktop computers, apple laptops, apple macs, and LCD Monitors side by side! All the information and reviews to make the best purchasing decision for new mobile phones, sat nav systems, or MP3 players. The Ciao online shopping community makes searching products easy for you.
One of the most interesting perks of using Mac OS X is benefiting from a strong amount of security that Windows users don't enjoy - and without sacrificing the "mainstream" aspect of the Mac.
On the other hand, a bit of paranoia is healthy as far as security is concerned. There are ways to satisfy your need for secure computing, and most of them are little things that can be done every day without breaking your piggy bank.
Mac OS X 10.4 Tiger, as all Unix-based systems, does not execute those dreaded .exe files, no matter where they are or what they want to do. Mac users who run Virtual PC can open .exe files, but they will only run in the emulated Windows environment.
Another thing you shouldn't worry about is virus software. As of today, there are no reported virus threats to Mac OS X.
Still, there are a few things you should be aware of to protect your security and privacy. Starting from the default system installation, you can act immediately.
When you are connected to the Internet, it is important to limit the number of open ports. Each open port is a potential security hole for hackers to exploit for invasion or file transfer. Therefore, you should only open those you need and open them only when you actually need them for file sharing, networking, etc.
OS X has an integrated
software firewall, which you can easily use. To manage it and shut
some ports down, pull down the Apple menu in the Finder and select
System Preferences. Click on the Sharing button. Under the Services
tab you will see a number of services, most of them for sharing.
Make sure that they are all turned off - except when you really
need to use them. If you use them only once in a while, turn them
on every once in a while. It's more secure than keeping them open
at all times.
Now, click on the Firewall tab. Most of the options won't be clickable because they are managed by the Services tab, but they are part of them firewall anyway. Others, such as iChat Bonjour, the network clock, and iTunes and iPhoto sharing can be turned on and off there. The iChat Bonjour port is very likely to be one that you keep turned on at all times if you use iChat every day. Otherwise, the same rule applies: turn it off.
Do the same drill with the Internet tab.
While you're still in
the System Preferences, click on Show All, and then click on
Spotlight. That's right: Spotlight can be part of your security
strategy, mostly by limiting some of its search capabilities. If
you want, for example, to make sure that your email is not
searchable, uncheck the Mail item. Do the same for all sensitive
file types.
Still in the Spotlight preference pane, click on Privacy. You can blacklist folders and directories to prevent Spotlight from searching them by clicking on the plus sign (+) button in the bottom left corner of the window.
Kick Butt with a Single Password
Mac OS X brought a solid amount of security to the Mac by coming up with a good user and password interface. By allowing a computer's owner to administrate everything with accounts, it addressed security concerns. The admin password can prevent unwanted software from installing itself, virtually eliminating any spyware threats. Of course, minimizing the number of admin accounts is always smart.
The other
advantage of accounts is that you can easily lock your computer by
logging out before leaving. Another way to lock your computer is to
make sure that the default screen saver activates when you are away
and requires the user password to authorize access again.
To set this up, go to the System Preferences and click on Desktop & Screen Saver. Click on the Screen Saver tab. Then, choose when you want the screen saver to take over when you are leaving. Click on the Hot Corners button if you want one of the screen corners to be used as a screen saver launcher. If you do that, rolling your mouse to the activated corner will launch the screen saver instantly.
Once that is done, you have
to turn on password protection. Click on Show All in the System
Preferences and choose Security. Click the checkbox besides
“Require password to wake up computer from sleep or screen
saver”. You guessed it, the setting will also ask for a
password when waking the computer up from the sleep mode.
While at it, take a look at the other checkboxes to see if any of them is interesting to you. They add some robustness to your security strategy.
Now, on top of the same Security preference pane, there is this FileVault feature.
Should you use it?
Yes and no. It provides encryption for files stored in your Home
directory, making the directory a secure place to store sensitive
data. At the same time, it poses a serious threat for data
loss!
Why? Because FileVault encrypts the files and decrypts them when you need to use them. It ties the use of your files to your account's password - even if they are copied to another medium than your hard drive. If you forget your password, you can kiss your data goodbye unless you know how to crack the encryption. Good luck....
This brings me to the importance of a good password for efficiency, for FileVault or for just any password on the Internet. Don't be naive: a four-letter word without numbers is easier to crack than a long password that combines letters and numbers. In fact, each character makes a cracker's life more difficult, especially when numbers are thrown into the mix. If "la32duh98" is harder to remember than "blah", it's also much more secure.
Internet Cleanup
Are you paranoid about security yet? Good. I am, and I have some more suggestions.
Buy Internet Cleanup from Allume, and for a relatively low price (US$29.99) you'll get more options to protect yourself against unwanted intruders and hackers.

Its NetBlockade feature will address many concerns. It will come down on browser popups like a ton of bricks, and it will also crack down on unwanted advertising. It lets you tailor your preferences for cookies that websites install to track your surfing habits. My favorite feature of all: NetBlockade can refuse to give away the last Web pages you have visited when you head to another site. I told you I was paranoid....
The NetBlockade feature be combined with (or override) your browser's privacy and security features to make browsing more secure. It is highly customizable, down to the names of servers that should be allowed to show popup windows and ads.
Network SpyAlert is another
neat feature of Internet Cleanup. It intercepts all network
activity and asks you what to do about them. Therefore, you can
decide what software can contact which server. When you first use
it, it will be quite aggressive. But don't worry, this happens
because it has no authorizations to remember when you first install
it.
Tailor its authorizations as the alerts appear, and it will remember which Internet addresses are considered safe to contact temporarily or at any time. At that point, only unwanted connections will be detected for you to block. I strongly recommend using the feature, because it prevents software from reporting activity without your authorization.

SpyAlert is another nice safeguard against intrusions. It scans your computer for spyware. Since there is no effective spyware for the Mac at the moment, it doesn't find anything yet, but since it is included in an inexpensive package, it's nice to have, especially if threats materialize.
Internet Cleanup also includes cleaning options, but in my series of tutorials about Mac maintenance, you learned how to do that kind of work. In any case, Internet Cleanup offers you another way to do it.
Awareness
The last step in computer security is awareness. Yes, your mind is important. There are some small things you can do to prevent problems.
The first tip? Use plain text email. By doing away with HTML, you get rid of JavaScript and code that execute automatically when read. You also make sure that no 'tracker' image proves that you opened a spam message.
Phishing, a technique used to fool you into giving your personal and financial information to thieves who pretend to be from your bank, PayPal, eBay, etc. is easier to avoid with plain text email. That's because HTML allows thieves to code a phishing link to make it look legitimate. Plain text strips the thief from the "clothes" he uses to hide - to let you see that the link you are supposed to follow is not legit.
Secondly, I strongly
recommend that you download security updates whenever they are
available in the System Preferences (when there, click on the
Software Update button to get them). Look for all software update
descriptions to see if there are security fixes elsewhere than in
the security updates. For instance, an AirPort update can contain
security fixes. For non-Apple software, make sure to check the
vendors' websites to find similar updates.
Using a browser with good security preferences is another smart thing to do. Most Mac browsers are good, with extra kudos for Opera, which is a gem in that department. Not using the autofill and autocomplete features also prevents Web forms from being filled in automatically.

When you browse, notice which pages are secure and which are not. Secure pages start with https instead of plain http, and browsers will change the color of the address bar as well as display a locked padlock. Another important setting is to allow your browser to display an alert that lets you know when you leave a secure browsing area right in the middle of a transaction. Don't turn this off! Sites that lie about security and encryption will be uncovered easily when the alert shows up.
It sounds stupid, but it's still true: Email attachments should always be handled with care. When they come from trusted sources, they are usually free from any threats, but you should still be careful, especially with Microsoft Word files, which can contain macro viruses. Make sure to have macro virus protection turned on in Word. Pull down the Word menu, select Preferences, and click on Security, and then check "Warn before opening files that contain macros"
One last tip: Erase file securely – by overwriting them - in the Finder by pulling down the Finder menu and choosing Secure Empty Trash. That way, nobody will be able to recuperate them.
Nobody said that you had to deal with cracking, hacking, spam and security holes just because you use a computer. Leave that to Windows users. There is nothing better to satisfy your security paranoia than using a Macintosh. :-)
Michel Munger is a journalist who lives in Montréal. He discovered the Mac in 1994, and his work on a PC reminds him every day why he embraced Apple's platform. Munger has also authored some MacDaniel columns.
You can learn more about him on his personal website.
Recent columns by Michel Munger
- Thunderbird 2.0: A simple, powerful, free email client, Macinthoughts, 04.25. Mozilla Thunderbird doesn't suffer from feature bloat like most commercial email programs. It puts the focus on doing what you need efficiently.
- A decade of progress, Macinthoughts, 04.09. 10 years ago, Windows 95 was a mess, System 7.5 was becoming unstable, and Apple's future was in doubt. Today OS X is rock solid, Vista has learned from Apple, and Apple is a runaway success.
- Entourage, the best overall email software on the market, iBasics, 12.08. Microsoft's email client is easy to use, integrates with Office, is sluggish, and can only be purchased as part of Office.
- Eudora, the Mac's most powerful email client, iBasics, 12.01. If you're looking for lots of power and don't mind an unconventional interface, give Eudora a try.
- More in the iBasics index.
Links for the Day
- Mac of the Day: Mac mini Core Solo, Feb. 2006 - The only Mac to use a Core Solo CPU, this model ran at 1.5 GHz, has integrated graphics, and includes a Combo drive
- Group of the Day: SuperMacs is for those using Umax SuperMac clones.
- November 24 in LEM history: 98: Microsoft's heavy hand - 00: Looking at the iMac - 04: The best Mac for the holidays - Picking the right replacement for a dead mouse - Better battery for 15" AlBook
- Support Low End Mac
Recent Content on Low End Mac
- Why Spaces is My Favorite Leopard (and Snow Leopard) Feature, Charles W. Moore, Miscellaneous Ramblings, 11.23. Spaces, a feature introduced with OS X 10.5, is like having several monitors on your Mac without the cost and space of using multiple displays.
- i5 iMac Benchmarked, Mac mini 'Shouldn't Be Overlooked', Twitter Client for Classic Mac OS, and More, Mac News Review, 11.20. Also why Apple leaves the low end to others, 10.6.2 fixes video playback problem in 27" iMac, 3D Leopard and Snow Leopard performance, and more.
- Apple's Tablet an End Run Beyond Netbooks, Frank Fox, Stop the Noiz, 11.20. Whatever Apple has planned will leverage existing technologies while going beyond what its competitors can offer.
- Apple #4 in Reliability, Apple Tablet a Gadget for All?, HP's i7 Notebook Outdoes Mac Rivals, and More, The 'Book Review, 11.20. Also Flash 10.1 improves video on Hackintosh netbooks, thin-and-light notebooks impress, Windows XP finally on the way out, and more.
- NASA Chemical Sensor for iPhone, Smartphone Death Match, iPhone Earrings, and More, Ian R Campbell, 11.20. Also mobile phone dangers, new apps, GPS solution for iPod touch, new iPod and iPhone cases, and more.
- Replacing the Hard Drive in a Clamshell iBook, John Hatchett, Recycled Computing, 11.19. Yes, it is one of the most difficult Apple notebooks to disassemble and reassemble, but a 10 GB hard drive just will not do.
- IBM Model F: A Great Old Keyboard with an Outdated Layout, Tommy Thomas, Welcome to Macintosh, 11.19. Although it used a different technology than the revered IBM Model M keyboard, the Model F was a great keyboard in its own right.
- More links in our archive.
Recent Deals
- Best G4 iMac Deals, 11.24. Used 15" 700 MHz CD-RW, $150; 800 MHz Combo, $229; 1 GHz, $289; 17" 1.25 GHz, $200; 20" 1.25 GHz, $509.
- Best PowerBook G3 Deals, 11.24. Used 233 MHz WallStreet, $75; 266 MHz, $160; 400 MHz Lombard, $199; 400 MHz Pismo, $289; 500 MHz, $350.
- Best MacBook Air Deals, 11.24. Used from $899; refurb from $1,099; new 1.6 GHz/120 HD, $1,150 after rebate; 1.8/64 SSD, $1,150 a/r; 1.86/128 SSD, $1,350 a/r; 2.13/128 SSD, $1,694 a/r.
- Best 12" PowerBook G4 Deals, 11.23. Used 867 MHz SuperDrive, $348; 1 GHz Combo, $379; SD, $519; 1.33 GHz, $529; 1.5 GHz Combo, $549; SuperDrive, $609.
- Best Mac Pro Deals, 11.23. Used 2.66 GHz 4-core, $1,300; 3.0 4-core. $1,919; refurb 2.66 4-core Nehalem, $2,149; 2.93, $2,549; 2.93 8-core, $4,999; new 2.26 8-core, $2,290.
- Best Time Capsule and AirPort Deals, 11.23. Used 802.11g AirPort Extreme, $49; 500 GB Time Capsule, $150; new, $190; 1 TB dual-band, $280; 2 TB, $469; 802.11n AirPort Extreme, $170.
- Best eMac Deals, 11.18. Used 1 GHz Combo, $100; SuperDrive, $269; 1.25 GHz Combo, $119; SD, $319; 1.42 GHz Combo, $289; SD, $498.
- Best Mac OS X 10.6 and Mac Box Set Deals, 11.18. "Snow Leopard", single user, $25; 5 users, $45; Mac Box Set, single user, $139; 5 users, $180; Server, $414. Shipping included.
- Best Xserve Deals, 11.18. Used 1 GHz dual G4, $649; 2.3 dual G5, $795; 3.0 4-core Xeon, $1,899; refurb 2.26 4-core, $2,499; new, $2,888; refurb 8-core, $2,999; new, $3,449; more.
- More deals in our archive.
About LEM | Support | Usage | Privacy | Contacts
Navigation
Used Mac Dealers
Apple History
Video Cards
Email Lists
Favorite Sites
MacSurfer
MacMinute
MacInTouch
MyAppleMenu
InfoMac
Macs Only!
The Mac Observer
Accelerate Your Mac
RetroMacCast
PB Central
MacWindows
The Vintage Mac
Museum
DealMac
DealsOnTheWeb
Mac2Sell
ramseeker
Mac Driver Museum
JAG's House
System
6 Heaven
System 7 Today
the pickle's Low-End
Mac FAQ
Abandonware
Petition
Mac vs. PC Info
Affiliates
The Apple
Store
Mac
Connection
B&H
MacMall
TechRestore
ExperCom
Crucial
Memory
batteries.com
Advertise
MacMinute
MacInTouch
MyAppleMenu
InfoMac
Macs Only!
The Mac Observer
Accelerate Your Mac
RetroMacCast
PB Central
MacWindows
The Vintage Mac
Museum
DealMac
DealsOnTheWeb
Mac2Sell
ramseeker
Mac Driver Museum
JAG's House
System 6 Heaven
System 7 Today
the pickle's Low-End
Mac FAQ
Abandonware
Petition
Mac vs. PC Info
Mac Connection
B&H
MacMall
TechRestore
ExperCom
Crucial Memory
batteries.com

