The Mac Observer

Skip navigational links

DealsOnTheWeb Daily Deal: Free Shipping at Omaha Steaks on orders of $75 or More - Two Days Only!!!

 
Computing with Bifocals - Simple Security Steps for Average Mac Users

by
July 29th, 2008

Is the Boogy Man really coming? Now that Macs are becoming popular are we getting hit with hackers and viruses? Well...what time is it?

Mac OS X is a secure operating system, and that by itself is a challenge to some people. Rather than worry about what some snarky person is doing, it is much more productive to do everything you can do to protect your own machine.

The following are excellent suggestions that I got from a couple of friends who deal with Macs and security on a daily basis.

Don't Use The Administrator Account For Daily Use
Who ever controls the Administrator Account controls the computer. If it is locked and an unauthorized person can't get into it, they can neither retrieve information nor damage what is there.

When we learned to use our Mac most of us started with one account and concentrated on learning how to use our Macs. People who share a computer probably do have more than one account. One of the beauties of OS X is the ability to have as many personal accounts as you want. I never bothered with extra accounts except for the occasional training needs.

No more. I took a half an hour and followed the steps I am recommending below. What I did, and am recommending that you do, is take away administrator privileges from the account you use all the time. Create a separate administrator account because you do have to have one to operate your Mac.

If you are using Leopard, or Mac OS X 10.5, follow these steps exactly. For earlier versions of the OS, modify as needed.

  • Select Apple Menu > System Preferences > Accounts.
  • Click the plus button under the My Accounts Field. Unlock the preference window if needed.
  • A new Accounts window will open. Select Administrator from the pull-down menu next to New Account.
  • Name the account and enter a password. Make your password as secure as possible. To check the security level of your password, click the key symbol next to the word after you enter it into the Password field.
  • Don't turn on FileVault protection. It causes more problems than it solves.
  • Save your information.
  • If you have a MobileMe account you will be asked to enter your MobileMe user name. I entered the same name I already use and it took it with no problem.
  • Now, while you are still in the Accounts Preference Pane, click on your original account, the one you have always used.
  • When the account window opens you will see that you now have the option to uncheck the box next to Allow user to administer this computer. Do so. You will get a reminder box that tells you the change will not go into effect until you log out and log back in.
  • Don't forget to lock the preferences window as your final step.

So what is going to be different? Let us say you are working in your regular account and you decide to download the trial version of a new application. In the past you would get a window that asked for your password before you could install the application. Now you will get a window that asks for the administrator name and password before you can install the application. The one you will enter is the new one you just created. It's a small price to pay to keep anyone from getting to your locked stuff.

Keep Important Preferences Locked
The emphasis in that sentence was on your locked stuff. Most of the applications that you run on your Mac have preferences. They are things that you can set that individualize the application to meet your wants and needs. The preferences for most applications will be found in the menu under the name of the application.

As you are probably aware, your Mac has its own set of Preferences. They are called System Preferences and you find them in the Apple Menu in the top left portion of your Desktop menu bar.

A number of the System Preferences can be locked. In Leopard there are ten. Some of them are locked for convenience so that no one can change your settings. However, some of them pertain to the security of your Mac and they should always be locked. As my security minded friends point out "System Preferences are not something you use every day. The minor inconvenience of having to use a password to access one of them is far outweighed by the protection you gain by keeping them locked." In Leopard, the System Preferences with lock options are:

  • Security
  • Energy Saver
  • Print & Fax
  • Network
  • Sharing
  • Accounts
  • Date & Time
  • Parental Control
  • Startup Disk
  • Time Machine

The highlighted preferences are the ones that can make your machine the most vulnerable and therefore, the ones you should always keep locked.

Take It Down One More Level
Protecting System Preferences will only get you so far. There is another level down you can go. Go back to System Preferences and select the Security Preference Pane, then select the Firewall tab. The firewall determines what can and can not get into your computer over the Internet. For most situations you will want to choose Allow only essential services.

If you have specific reasons to allow something else you must specify it as I have done in my example. By specifying Screen Sharing, I give secure permission for someone to sign on to my Desktop and work on my computer from afar.


Firewall Security Options

The next thing you can do requires that you click on the General tab in that same Security Preference Pane. Click on any, or all, of the offered options depending on the level of security you want to achieve.


General Security Options

Taking these steps will help you stay in the driver seat when it comes to protecting both the contents of your computer and your hard drive.

More helpful tips for beginners can be found in my beginners manual, Tips, Hints, and Solutions For Seasoned Beginners Using Apple Macintosh Computers With Mac OS X 10.4 and 10.5.

The entire Table of Contents and a sample page are available for free review for anyone who wishes to see them.

I am making this book available in three formats:.
__________

The first is the more traditional printed book format, spiral bound. Cost is U.S. $17.15 each, plus shipping. All the illustrations have been printed in black and white to reduce the purchase price.

The second option is a PDF download version. This is the full version of the book available in the same format as that available in the free review The contents are hyperlinked from the Table of Contents for ease of location. This version is U.S. $9.85 After payment has been verified the purchaser will be sent a URL where they can download of the document.

The third option is a CD format. It is the PDF version saved to a CD and the contents are also hyperlinked from the Table of Contents for ease of location. This version is $10.85 plus shipping.

Payment for any version must be made using PayPal. Clicking on the Buy Now button next to the version you want to purchase will take you directly to PayPal where you can place your order and make your payment. Payment can be made through PayPal even if you are not a PayPal member.

Anyone wishing to pay with a money order or cashier check may contact me through TMO at

Talking to a generation that remembers what the world was like before there was color, covers issues for people who don't care how their computer works, but rather what their computer and the internet can do for them.

Nancy has a Master's degree in Human Services Administration and prior to her retirement she worked for almost 30 years in field of mental health and mental retardation. She has been a Mac user for 11 years, and has recently developed an avocation of teaching basic computer skills in both group and one-to-one settings.

Computing with Bifocals Archives.

Observer Comments

Show: Subjects Only | Full Comments
Close Name:Guest
Subject: How to protect passwords...

The Mac comes with a Disk Utility called "Disk Utility". You can create an encrypted, password-protected disk (which is actually a file on your hard disk that is 'mounted' [i.e. shows up on your desktop] as a hard disk.

I've done this and put my passwords in a 'locked/encrypted' file in the 'locked/encrypted' hard disk. I won't go into detail unless others respond requesting how do to this.

I also keep a copy of my important files on a secure / encrypted DVD backup and keep it offsite (in another building other than my own home).

Close Name:Guest
Subject: New Leopard firewall is insecure

If you choose the option "Set access for specific services and applications", then any application that is code-signed can automatically get through the firewall, even if you haven't allowed it in the preference pane.

Close Name:Guest
Subject: Security

My new Mac has OS10.4 & Windows XP Pro [on VMware]. Don't I need to protect my computer from the weaknesses of Windows? If so, what steps shall I take?

Close Name:acdc1174 Posts: 723 Joined: 16 Apr 2004
Subject: Re: Security

Quote
Anonymous wrote:
My new Mac has OS10.4 & Windows XP Pro [on VMware]. Don't I need to protect my computer from the weaknesses of Windows? If so, what steps shall I take?


You need to protect the Windows side just like you wold any other Windows machine if your computer is connected to the internet. The nice thing about virtual machines though, is that if you don't, and the virtual machine gets infected, you can always delete it and create another.

Comment on this Article


You cannot edit your comments.   You cannot delete your comments.
Log in | Register | Having Problems? Reset TMO Cookies & Try Again
Username:   Password:   Log me on automatically each visit   

You are not logged in, and this post will appear as "Guest." Log in with your username and password from the TMO forums. If you do not have a username, you can register here.
Please note that guests are limited to including a maximum of two URLs per post.


Post A Comment
  Subject


  Your Comments



Please enter the word exactly as you see it in the image above. Registered users aren't prompted for this. Having trouble reading the image get a new one.


Recent Headlines - Updated Saturday, November 29th, 2008

Sat., 9:00 PM
Podcast - Apple Weekly Report #135: Apple Lawsuits, Banned iPhone Ad, Green MacBook Ad
Fri., 12:45 PM
Podcast - Mac Geek Gab #178: Batch Permission Changes, Encrypting Follow-up, Re-Enabling AirPort, and GigE speeds
Thu., 1:30 PM
iPO Review - Scosche kickBACK iPhone case
7:00 AM
Happy Thanksgiving from TMO!
Wed., 6:00 PM
TMO Appearances - Nancy Gravley Joins MacJury Gift Guide
5:15 PM
TMO Visits The Bay, a Premium Apple Reseller in New Zealand
3:25 PM
iPO Oh the Games You'll Play - iPhone: The Wii of Handheld Gaming Devices?
2:15 PM
Sonnet Releases Simply Fast FireWire 800 to 400 Adapter
1:10 PM
Mac Gaming News - Disney Plans 1st Annual PotC Online Thanksgiving Event
12:05 PM
iPodObserver - UK Shuts Down iPhone 3G Ad
11:15 AM
TMO Appearances - Jeff Gamet on MacJury Gift Guide
10:30 AM
TMO Contest - TMO Announces Macworld Expo Pass Winners
9:50 AM
PhotoCopy 1.1 Adds iPhoto Event Support
9:15 AM
Acclivity Buys MYOB US
8:30 AM
Review - Bento 2 Holiday Pack
7:50 AM
Microsoft Offers Black Friday Office Discount
7:30 AM
iPO Quick Tip - iPhone: Google Street View
 

The Mac Observer Reader Specials

Apple Stock Quote

  • AAPL: $91.41. Change Today: -4.49.
  • (Prices delayed up to 20 minutes.)
  • Discuss in our Apple Finance Board

Hot Topics

Top Deals From DealsOnTheWeb