There’s no room for complacency when it comes to security

Written by Admin on Tuesday, September 2nd, 2008

EXTENSIONS

There’s no room for when it comes to security

GRAHAM K. ROGERS

I am working through the in OS X, and am now at the letter S, which means Security, Sharing, , Sound, Speech, Spotlight and . For now, I will skip Q (for ).

Security is a for all users. While Mac users claim that OS X is more secure than other operating systems, there is no room for . The section is there to be used. It works with other parts of (like Accounts and Sharing) for a safer environment if used properly. The Security Preference pane has three sections: General, and Firewall.

In the General panel is a check box for a password if the computer is in or the screensaver active. This is a simple and effective first . I use this in conjunction with Active - moving the cursor to (in my case) the of the screen turns on the screensaver and the computer is safe from . The only way to circumvent this (if, for example, the computer is stolen) is to restart the computer.

The FileVault panel of the in OS X, 10.5, Leopard.

The second checkbox prevents . Used with the screensaver lock, Firmware Password Utility and tracking software, this may help us recover a stolen computer.

OS X allows a multi-user environment, although some prefer a single user account. A check box locking each preference pane will prevent other users changing the OS settings.

If essential tasks are not running, activating the next check box will automatically log the user out after a certain time. The time can be selected in a small panel. The default is 60 minutes. Secure is used to ensure that any data, such as passwords, in is erased.

Finally, in this panel, is a box to disable the used by the remote control. This prevents others using another remote control and accessing media (music, photos, movies). For additional security, the remote device itself can be paired with the computer, also ensuring that others do not have access.

The second panel in focuses on what Apple calls FileVault. The icon (a house with a safe dial superimposed) signifies the ability to lock the user’s Home folder by way of encryption. If users have this activated, files are decrypted and encrypted while working. A user enters the account as normal, using the password. There are two parts to this feature - the protection itself, which needs a considerable amount of hard disk space for the file swapping that will occur; and the Master Password. Apple calls this a “safety net” as it will allow unlocking of any account. If this master password is lost, then you can kiss goodbye to your data, and not even Apple can help. An extended discussion of FileVault by F. J. de Kermadec can be found at the O’Reilly, MacDev Centre at http://www.macdevcenter.com/pub/a/mac/2003/12/19/filevault.html.

Anyone who does not use a firewall these days is asking for trouble. There were significant changes to the firewall in OS X Leopard. It is now application-focused rather than port-focused. It allows a program the correct access instead of specifying port numbers. There are three settings: Allow all incoming connections; Allow only essential services; and Set access. The first is too open for proper security. The second is too harsh limiting operations to only a small list of allowed connections. Updating from 10.4 will default to this setting. The third option is right for most users although may need a little fine-tuning to optimise operations.

As new applications are installed, they will access the internet and many will need incoming connections to be allowed. Examples are Safari and Firefox. It is safe to block some applications. I prevent Skype from making incoming connections but I am still able to call out. It is easy to change this if required with a click in the panel that lists the applications and their status. We can also add an application if it does not make an automatic request. For outgoing connections, a third-party utility like Little Snitch is essential.

The Firewall panel also has a button marked Advanced. This reveals a further panel with two additional settings. The first enables firewall logging; and the log, if we ever take the time to read it, can reveal some interesting or disturbing information. I see this morning that CAT, a local ISP and my web host have all probed my Mac. The log may only be accessed by an Admin user.

The other check box in the Advanced panel allows activation of Stealth mode, so that any outside probing that occurs (such as that shown in the logs) will have no response. The computer will not even appear to exist. Anyone who ignores security is taking a gamble.

Graham K. Rogers has OS X-flavoured web pages, with links to an RSS feed and a weekly podcast at http://www.extensions.in.th/index4.html.

News Topics Related Posts :

News Topics : , , , , , , , , , , , , , , , , , , ,

This entry was posted on Tuesday, September 2nd, 2008 and is filed under Thailand Features. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Asia News Reports

News Headlines

Advertisement

Bookmarks Me

del.icio.us Digg Furl Reddit Ask BlinkList Bloglines blogmarks BUMPzee Blogg-Buzz DZone Facebook Google Ma.gnolia Mixx MisterWong muti Newsvine PlugIM ppnow Propeller Rojo Shadows Simpy Slashdot Socializer Sphere Sphinn Spurl StumbleUpon Tailrank Technorati ThisNext Twitter Windows Live Wists YahooMyWeb

Thailand News Update

Asia News Update

World News Update