<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>macos Archives | nerdsmodo</title>
	<atom:link href="https://nerdsmodo.com/tag/macos/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Apple Blog: iPhone • iPad • Mac • iOS</description>
	<lastBuildDate>Wed, 23 Sep 2026 17:53:51 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://nerdsmodo.com/wp-content/uploads/2026/02/cropped-img_5063-32x32.png</url>
	<title>macos Archives | nerdsmodo</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">252786843</site>	<item>
		<title>The Kinds of Mac Malware, and How Infection Happens</title>
		<link>https://nerdsmodo.com/mac-malware-types/</link>
					<comments>https://nerdsmodo.com/mac-malware-types/#respond</comments>
		
		<dc:creator><![CDATA[Moses Johnson]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 17:53:51 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4842</guid>

					<description><![CDATA[<p>Ransomware is the biggest worry on a Mac and remains nearly non-existent.</p>
<p>The post <a href="https://nerdsmodo.com/mac-malware-types/">The Kinds of Mac Malware, and How Infection Happens</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Malware describes a broad category of unwanted software that is installed without your explicit knowledge, and which carries out tasks beneficial to the operator and creator of the malware, and detrimental to you, your local network, your friends, family, and colleagues, and potentially strangers and even the whole of the internet.</p>
<p>Malicious software can be as “benign” as adware, which is bundled with software you intended to install, and which redirects your browser to a portal through which the adware’s creator earns commissions when you search or make purchases; or which overlays or replaces ads on pages you view to earn income on your stolen time (also effectively stolen from the sites you visit).</p>
<p>But it can also be quite hostile: it might encrypt all your files and demand a ransom (more on that below), delete your files, or use your computer to launch attacks. Malware often tries to find other devices reachable on the same network—often which are more susceptible to network infiltration than from attacks launched over the internet—to infect them with the same software.</p>
<p>The main point is that you don’t want any software to run on your Mac that you aren’t aware of and haven’t given approval to run. What follows is the threats. <a href="https://nerdsmodo.com/mac-malware-protection/">What Apple does</a> and <a href="https://nerdsmodo.com/do-macs-need-antivirus/">whether to run anti-malware</a> are separate.</p>
<h2>Why Apple avoids the worst of it</h2>
<p>While the first widespread malware appeared on Macintoshes many, many years ago, Apple’s choices over the last 25 years have meant that Macs have been generally resistant to the most common vectors of attack that afflicted and still plague Android and Windows users, as well as people running servers of all types.</p>
<p>There are a lot of reasons for this, some of it due to system choices and some due to obscurity—the number of devices running each operating system.</p>
<p>Windows wasn’t designed with the internet in mind, nor the receipt of arbitrary emails from people outside an organization. For too many years, a successful exploit could hijack a machine by someone merely receiving (not even viewing) an email message or passively viewing a webpage. Microsoft has improved its security dramatically in Windows 10, the first release of which was 2015, but older versions—still in use on hundreds of millions of devices—still suffer from many attacks.</p>
<p>While Google built Android as a modern, Unix-based, internet-connected operating system, they made multiple interconnected errors that led to Android being highly insecure. Among other issues, they handed control to handset makers and carrier networks, making it difficult to push out security updates directly. They also rapidly revised and abandoned older versions, no longer releasing security updates, even while handsets were still being sold as new in the box that ran those versions. And despite the dangerous world into which Android was first launched in 2009, the OS seemed full of easily exploitable flaws that took years to move past. As with Windows, even if newer versions of Android are fairly secure (in relative terms), a billion older Android devices still remain on the market.</p>
<p>It’s in this space that Apple finds itself, with both iOS/iPadOS and macOS. Frankly, there are billions of better targets than any of those Apple operating systems. Apple didn’t have to engineer a system that was 10 times better than Windows, but just enough—better coupled with the substantially fewer numbers of Macs in use in the world—that malware creators targeted the low-hanging fruit instead.</p>
<p>While Apple has sold a lot of iPhones and iPads (and some iPod touches), the user base for Android and forked-Android phones and tablets (forked ones use open-source-derived variants) outweighs iOS and iPadOS copies by a bit under three to one—and Apple patches security flaws quickly. (Apple has closed that gap in recent years, but it’s the mass of older devices that remains the concern.)</p>
<p>Remember the old joke about a bear rushing toward two campers woken from slumber: one stops to put on his shoes. The other says, “You can’t outrun the bear!” The first replies, “I only have to outrun you.” Apple always ties their shoes.</p>
<h2>The kinds of malware</h2>
<p>Malware and its enablers come in a lot of varieties, and it’s worth knowing the terminology. Here’s a primer:</p>
<ul>
<li><strong>Virus:</strong> Malware that injects itself inside existing software, and executes whenever that software runs. It can spread by software being copied, such as an app being corrupted by a virus on a download site, so everyone who downloads it receives and runs an infected version. A virus can be a payload of a worm or Trojan horse, which install the virus.</li>
<li><strong>Worm:</strong> Worms are free-standing malware that can spread themselves across a network, and may install other malware, such as viruses. The world’s first widespread malware was a worm.</li>
<li><strong>Trojan horse:</strong> Malware masquerading as legitimate or desirable software that a user installs. It may result in freestanding malignant software or a virus inserted into otherwise valid software.</li>
<li><strong>Phishing:</strong> A technique of convincing someone, typically via email, to hand over personal details, particularly payment information, by sending them to a malicious webpage that’s a close copy of a credible site.</li>
<li><strong>Ransomware:</strong> Malware that targets user document files and encrypts them with a key that is discarded and only the attacker has access to. The attacker demands money to provide the key.</li>
<li><strong>Bots:</strong> A bot is not a “robot,” but automated software that performs automated activity on behalf of its owner, which can include coordinated attacks against websites or servers, illegitimately clicking ads, sending spam email.</li>
</ul>
<p>The most likely scenario for a Mac user to be infected by malware is through a series of seemingly innocent, chained actions: phishing, Trojan horse, virus, and ransomware. Often this has to be coupled with a form of understandable naïveté: bypassing Apple’s warnings and installing seemingly unknown software.</p>
<h2>How an infection actually happens</h2>
<p>Because I don’t want you to feel targeted in this story, let’s call the victim Bob. Bob is checking his email in Apple Mail or a third-party email app. Because Apple Mail has always been quite resistant to in-mailer attacks and most other mail clients are the same, Bob’s not at risk by reading messages.</p>
<p>But Bob sees a message about a piece of software he uses regularly. “Get a free 90-day trial of the new version of AliceDrawPlus! Click this link, and download and install. Because this is a special trial version, right-click the installer and click Open to make sure it runs!” (Real phishing email is often not that grammatically correct or well targeted, but some is.)</p>
<p>Bob isn’t thinking about <a href="https://nerdsmodo.com/unsigned-app-wont-open-mac/">unsigned software</a>. Instead, he looks carefully at the email, which absolutely looks like other messages he’s received from Alice Corp. He downloads the file, bypasses Gatekeeper protections, and the Trojan horse he was phished to download runs and installs a virus.</p>
<p>Lest you think this is a problem I know about only secondhand, several years ago, one of my kids was having problems with their computer. I checked, and they had been fooled into installing an Adobe Flash “updater.” I had accidentally enabled administrator privileges on their account, and I had apparently never had the malware talk with them. We installed some anti-malware software, and fortunately the thing they’d installed was fairly benign.</p>
<p>But because the installer is running in Bob’s home folder, and not accessing or trying to install in a privileged location or make similar changes, it doesn’t trigger a request for an administrator password—although Bob might have entered that without worrying, too.</p>
<p>The software appears to install, but instead of launching, it claims there was a license problem, and the file was corrupted. “Check back in four weeks for another update!”</p>
<p>Meanwhile, as Bob continues to work, every file in his home folder, starting with Documents, is being encrypted and copied to a new file and then the original deleted. He may have no notion it’s happening, particularly if he has an SSD and can’t hear a hard drive working away like mad, though his fan might spin up unexpectedly.</p>
<p>macOS requires users to agree to allow apps access to certain folder locations, but because we have been trained to click OK most of the time, it might not raise Bob’s hackles or most of ours. See <a href="https://nerdsmodo.com/mac-app-permissions/">how to control which apps use your Mac camera and files</a>.</p>
<p>A few hours pass and Bob tries to open a file. It has a strange extension. It won’t open in the app that created it, but when he double-clicks the file, he gets a message that explains all his files are encrypted, he needs to pay up, or the decryption key will be thrown away and his files lost forever.</p>
<p>Bob’s been attacked by ransomware, and his only way out may come if he has a backup history—or wants to pay the Bitcoin or other cryptocurrency the criminal demands.</p>
<p>If Bob were as credulous as depicted, he could just as easily have been phished, where he was presented with a website that absolutely looked like AliceCorp and told to enter his serial number and payment details for a huge discount. Phishing is a virus of the mind, and your Mac can’t help much against that.</p>
<h2>ClickFix, the fake CAPTCHA</h2>
<p>Bob is too clever to fall for the above, but he visits a website that flashes up a CAPTCHA, which is typically some text you are using your human eyeballs to perform OCR on or identify squares containing the same object (they are stealing our brain’s processing power here), or to solve a simple puzzle. Bob performs the sequence of actions he’s told to perform in the “CAPTCHA,” and he falls to phishing.</p>
<p>This technique, ClickFix, has been around since 2024, but apparently dramatically accelerated how often malware fighters detect it.</p>
<p>Why? Fiendishly simple. We’re so used to following the “orders” of a CAPTCHA, clicking images or solving puzzles, that this doesn’t seem <em>that</em> weird if we’re on autopilot.</p>
<p>However, it should go without saying—but I’ll say it—never paste anything into Terminal from a random source on the internet, whether it appears to have authority or not. I try to avoid it even here, because of the consequences of a Terminal-based command going wrong and taking a lot of your time to reverse.</p>
<p>Apple agrees, and rolled out an anti-paste warning in Terminal! Starting in Tahoe, if you have something on the clipboard that macOS deems could be harmful, you receive a warning that might cause you to think twice.</p>
<p>Apple can escalate further than a warning, blocking paste entirely if they’re sure there’s malware involved. Your Mac may also block a script from running for the same reason.</p>
<h2>Ransomware is your biggest worry</h2>
<p>While our theoretical friend Bob was fooled into installing malicious software and bypassing protections in the examples above, the risk to many people isn’t quite as straightforward as the above.</p>
<p>Before I dig in, I want to note that <em>ransomware is your biggest worry</em>, but <em>ransomware remains nearly non-existent on Macs</em> as Apple continues to crank up protections that make it increasingly unlikely to thrive—particularly while it’s easy to infect users of other platforms. See <a href="https://nerdsmodo.com/gatekeeper-mac/">Gatekeeper</a> and <a href="https://nerdsmodo.com/mac-system-integrity/">system file protection</a> for several of those.</p>
<p>The reason I characterize it as the biggest worry is that it’s so blessedly simple to create and provides easy rewards for those who deploy it. Macs aren’t inherently resistant to it, but it feels <em>as if</em> they were. That luck could change with the right (“wrong,” really) exploit and timing.</p>
<p>You can see how with a phishing attempt like the above or email messages that tell someone a sequence of commands to perform, ransomware could be rolled out en masse to millions of people. Payments are quasi-anonymous to avoid easy tracking, and ransomware is effective against naïve and some more experienced users because it doesn’t seem like the way in which malware gets delivered and runs.</p>
<p>As noted above, when a ransomware app is launched, it encrypts all user files. The operation typically passes a file through an encryption algorithm, writes a new file with a new extension, and then deletes the source file.</p>
<p>Depending on the attack, you may get a message on screen when it’s done, explaining what happened. Some ransomware embeds the message into every file, so double-clicking provides the same text.</p>
<p>Send hundreds to thousands of dollars (or, as an organization, up to tens of millions of dollars) in Bitcoin to a specified address—kind of like a semi-anonymous post-office box—by the specified date and the hijacker will give you the key to decrypt it. Fail to comply, and they throw away the key.</p>
<p>Occasionally, white-hat hackers, who use their coding and online prowess for good, will crack open a ransomware scam and distribute passwords or a generic decrypting tool to victims!</p>
<p>Ransomware works on the portion of macOS (and any afflicted operating system) that contains user files and for which file and folder permissions more or less all belong to the logged-in user, as well as the partitioned-off part of memory that runs programs, called <em>user space</em>.</p>
<p>This is distinct from the system files and <em>kernel space</em> that contains all the components of macOS and in which the operating system itself runs. While crackers want to subvert system files and have software run with the highest permissions, that’s a hard lift—and why bother, when you can just use ransomware instead?</p>
<p>Here’s the other thing that should reduce your blood pressure if I just raised it: it’s also remarkably easy to mitigate the effects of ransomware (or any malware) with a little prep and ongoing work that’s not likely to exhaust your patience or wallet. <a href="https://nerdsmodo.com/mac-malware-protection/">The built-in measures</a> come first, and then the question of <a href="https://nerdsmodo.com/do-macs-need-antivirus/">third-party anti-malware software</a>.</p>
<p>The post <a href="https://nerdsmodo.com/mac-malware-types/">The Kinds of Mac Malware, and How Infection Happens</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/mac-malware-types/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4842</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/02/img_5047.jpg" />	</item>
		<item>
		<title>How Gatekeeper Decides Which Mac Apps Can Run</title>
		<link>https://nerdsmodo.com/gatekeeper-mac/</link>
					<comments>https://nerdsmodo.com/gatekeeper-mac/#respond</comments>
		
		<dc:creator><![CDATA[Moses Johnson]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 17:02:28 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4841</guid>

					<description><![CDATA[<p>Gatekeeper checks Apple’s revocation list every single time an app launches.</p>
<p>The post <a href="https://nerdsmodo.com/gatekeeper-mac/">How Gatekeeper Decides Which Mac Apps Can Run</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Apple hides a powerful feature behind a menu in System Settings &gt; Privacy &amp; Security. <a href="https://nerdsmodo.com/mac-login-items-extensions/">That menu</a> is the visible part. Behind it, Apple manages a good deal more to protect you against malicious software.</p>
<p>The point of knowing more is twofold: First, to recognize when something’s gone wrong. Second, to bypass protections in the limited cases in which you need to.</p>
<h2>Manage app sources</h2>
<p>The Gatekeeper feature was introduced years ago, and affects how you install and use software. Gatekeeper examines downloaded apps when they are first launched, including custom installers from a developer. (Apple has a generic installer that most apps rely on.) If you have set your app launch preference to App Store only, macOS tells you that you can’t open a given app. Click Show in Finder to reveal the app.</p>
<p>However, there’s a workaround if you want to be able to open just some of these apps. With Gatekeeper set to App Store only, go to System Settings &gt; Privacy &amp; Security. You will see this message: “‘<em>App Name</em>’ was blocked from use because it is not from an identified developer.” That much we know. But there’s also an Open Anyway button to the right of this message.</p>
<p>Click the button. Once that’s clicked, your Mac launches the app with a dialog that asks you to confirm you really, <em>really</em> want to open it. Click Open to proceed.</p>
<p>This App Store bypass seems clunky, but it’s consistent. If you have locked a Mac account down (for a kid, say, or a client or parent) without administrative permissions to make changes, this workflow for launching a non–App Store app still won’t let them. However, if you’re the captain of your own ship, this is a simpler set of steps than switching your Gatekeeper App Store preference to allow identified developers and then switching it back again.</p>
<p>Gatekeeper can also reject launching an app in these circumstances:</p>
<ul>
<li>The app wasn’t <em>notarized</em>, an extra security check (explained below) that Apple made mandatory years ago.</li>
<li>You allow non–App Store apps to launch, but this app is <em>unsigned</em>, which means it hasn’t gone through the extra pass of validation described below, including notarization.</li>
<li>The app is or contains known malware or other harmful software, and Apple blocks it from running altogether.</li>
<li>Something is <em>wrong</em> with the app, such as it having been tampered with, so it won’t launch, and you will be warned.</li>
</ul>
<p>Gatekeeper’s point is to prevent apps from running that, more or less, don’t digitally smell right according to multiple characteristics. It is worth understanding <em>app signing</em> and <em>notarization</em> to see what that buys you. If everything’s OK, your Mac launches the software.</p>
<p>Apple software and components always launch unless macOS detects they were tampered with. There’s no step to approve them.</p>
<p>For apps outside the App Store with Gatekeeper set to allow apps from identified developers, you still have one more step: you’re informed the app was downloaded from the internet and told that it was cleared for takeoff, but you must click Open to proceed. This may seem like overkill, but it’s one additional way that Apple ensures you haven’t been tricked into running software you didn’t intend to.</p>
<p>Apple also lets you know when an app is on a disk image instead of copied to your Applications folder, in case the disk image window tries to mislead you about its contents.</p>
<p>But wait! There’s more! If you <em>do not</em> check “Don’t warn me when opening applications on this disk image,” macOS…warns you when you open the application, requiring yet another click of Open.</p>
<p>If the app you try to run contains malware, Apple provides a unique warning, one I’ve never seen, and had to source from an Apple support note. This dialog also lets you report the item to Apple.</p>
<h2>App signing and notarization</h2>
<p>Each developer who has joined Apple’s $99-per-year Apple Developer Program receives a unique digital certificate that binds their identity with cryptography to prevent tampering and impersonation. When building an app in Apple’s Xcode development environment, the creator can use that certificate to <em>sign</em> the app.</p>
<p>This <em>signature</em> results from feeding the compiled binary version of the app—the actual code package you install and that runs—through a hashing routine, an iterative cryptographic process that produces a modest-length number (the <em>hash</em>) that appears innocuous. However, hashing is designed so that if even a <em>single</em> byte is changed in the entire source material (here, the app)—even if the number 8 becomes the number 9—the resulting hash is dramatically different. With modern hashing algorithms, there’s no way for a malicious party to modify an app, sign it, and get the same signature as the valid app.</p>
<p>Neat, huh? Hashing underpins a shockingly vast part of internet and real-world encryption, including all HTTPS web connections, secure email, and vastly more.</p>
<p>That hash is then countersigned by secret keys tied to certificates only Apple possesses, which lets macOS validate the signature and makes it impossible to forge the hash—otherwise, that would be a gaping loophole.</p>
<p><em>Notarization</em> is a separate and distinct step that applies both to an app and any third-party components and libraries it makes use of. Notarized apps, non-Apple installers, kernel extensions, and other bits of code have been scanned by Apple for known malware and none was found. But it also includes other security scanning, such as ensuring apps and components are <em>hardened</em>, which means there’s no way for parts of the app to be swapped out by malicious software while they’re running.</p>
<p>The text that appears in the launch dialog for non-App Store apps confirms notarization: “Apple checked it for malicious software and none was detected.”</p>
<p>Apple requires signing and notarization for apps in the App Store and those distributed directly by developers. App Store apps also go through review by human beings for content and purpose, which is separate from these automated scanning and signing operations.</p>
<p>A signed and notarized app doesn’t look any different to us, as users, from an unsigned app (whether notarized in part or whole), but it contains extra data that lets macOS determine:</p>
<ul>
<li><strong>Integrity:</strong> Whether the app has been changed since it was built</li>
<li><strong>Identity:</strong> Which developer created (and signed) an app</li>
<li><strong>Access:</strong> Which system resources the app may access</li>
</ul>
<p>Each of these attributes helps to protect your security.</p>
<p>Let’s start with integrity. If an attacker were to modify an app after it was signed—for example, inserting malicious code while it sat on the developer’s web server or even after you started using it—Gatekeeper would notice the change, as the hash wouldn’t match, and it would prevent the app from running.</p>
<p>Gatekeeper <em>always</em> prevents signed apps that have been altered from running, even if they ran fine before.</p>
<p>Next, suppose someone signed up for the Apple Developer Program and started delivering malicious software, signed with their certificate. The identity feature kicks in—once Apple discovers that the developer is distributing dangerous software, Apple can revoke that certificate, telling Gatekeeper not to let any software signed with that certificate launch. Gatekeeper checks Apple’s revocation list every time an app launches to make sure it’s still valid.</p>
<p>A malicious party using a legitimate certificate isn’t a hypothetical situation, though it’s rare in practice. In 2017, a phishing message convinced people to download and open a ZIP file, then launch an app inside it, and further conned them into entering an administrative password. The ne’er-do-wells had signed up for a developer account, and the app was signed. Apple revoked the certificate, defusing its potential.</p>
<p>The third aspect, access, involves system resources such as the keychain. If you grant an app permission to store information in the keychain or access it afterward, you don’t want to have to keep doing so every time you update the app.</p>
<p>But if you install a new version of an app that was signed with the same certificate, Gatekeeper treats it as the “same” app for the purpose of granting access to system resources, and you won’t be prompted for keychain access again.</p>
<p>Conversely, if someone altered the app or gave you an unsigned and therefore unauthorized version, it wouldn’t be able to access your keychain without your permission—in fact, Gatekeeper should prevent it from launching at all, because it won’t pass the signing test.</p>
<p>All of this reduces your risk of inadvertently running malicious software. If an app is not in the App Store and has not been signed and notarized, there is <a href="https://nerdsmodo.com/unsigned-app-wont-open-mac/">one way to bypass Gatekeeper</a>.</p>
<h2>Beware bundled adware</h2>
<p>A slimy practice that peaked a few years ago was for download sites to take otherwise safe and trustworthy software from someone else and wrap it in their own custom installer with a type of malware known as adware—which, among other things, displays intrusive ads, even if you block pop-up windows and use ad-blocking browser extensions in your web browser. Here’s how to protect yourself:</p>
<ul>
<li>Avoid free software download sites. If the app isn’t in the Mac App Store, download it directly from the developer. (The sole exception is Setapp, a multi-developer subscription service that has a single app that can install multiple apps for you.)</li>
<li>Don’t <a href="https://nerdsmodo.com/unsigned-app-wont-open-mac/">override Gatekeeper</a> unless you’re sure it’s from an absolutely trustworthy source.</li>
<li>If an installer asks if you want to install any extra software (especially if it’s “sponsored”) or browser extensions, or make changes to your browser settings, say no.</li>
</ul>
<p>While the problem seems to have waned for many years, I still receive scattered emails messages from readers who have installed adware without intending to. Be vigilant about the source of your software.</p>
<p>The post <a href="https://nerdsmodo.com/gatekeeper-mac/">How Gatekeeper Decides Which Mac Apps Can Run</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/gatekeeper-mac/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4841</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2023/04/img_2098.jpg" />	</item>
		<item>
		<title>How to Set Up Safe User Accounts on a Shared Mac</title>
		<link>https://nerdsmodo.com/mac-user-accounts-security/</link>
					<comments>https://nerdsmodo.com/mac-user-accounts-security/#respond</comments>
		
		<dc:creator><![CDATA[Dave Johnson]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 16:35:26 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4840</guid>

					<description><![CDATA[<p>An administrator account can open any file on the Mac, belonging to anyone.</p>
<p>The post <a href="https://nerdsmodo.com/mac-user-accounts-security/">How to Set Up Safe User Accounts on a Shared Mac</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>While macOS is a friendly operating system, it’s all Unix under the hood, which means it runs by partitioning access to files and apps by users and groups, selectively providing permission based on who you are and what groups you belong to.</p>
<p>If your Mac has only one user—you!—it’s all very simple, because you don’t need to secure yourself from yourself. However, you still need the following information, as it relates to how you manage a single-user Mac, too.</p>
<p>Several principles about user accounts matter here, and <a href="https://nerdsmodo.com/mac-shared-computer-privacy/">how private your files are</a> covers the other side:</p>
<ul>
<li><strong>There are four main types of Mac user accounts: administrator, standard, guest user, and sharing-only.</strong> Of these, administrator and standard are by far the most common. The usual reason to have more than one account is so that each person who uses a particular Mac can have a separate space for files and settings. But accounts can also be used to restrict access to certain files or resources in order to improve your security.</li>
<li><strong>Every Mac needs at least one administrator account.</strong> When you set up a new Mac or perform a clean installation of macOS, you’ll be prompted to create an administrator account before you can do anything else. That’s because only administrators can perform certain crucial tasks (see the next bullet point). You can have more than one administrator account, and in fact, it isn’t a bad idea to set up an extra one to use for testing and troubleshooting.</li>
</ul>
<p>When something fails for me on one account, such as a software app or Safari extension, I often log in to a second administrator account on the same Mac to determine whether it’s a problem with my account or the software—or the whole Mac.</p>
<ul>
<li><strong>Administrator accounts are all-powerful.</strong> Administrators can create, modify, and delete other user accounts. They can unlock any pane of System Settings, and authorize any type of software installation. They can (with a quick trip to the Terminal utility) open any file on the Mac, belonging to any user—and can change any non–system file’s permissions. They can upgrade macOS to a new version. The list goes on and on.</li>
<li><strong>Standard accounts can do most ordinary things.</strong> Standard users can run apps, work with files, and perform most ordinary day-to-day tasks. When a user with a standard account tries to do something that only an administrator is allowed to do, simply entering an administrator’s username and password (or having an administrator do so) does the trick—there’s no need to log out or switch accounts first.</li>
<li><strong>Apps get their privileges from the user who opens them.</strong> If someone with a standard account launches an app, that app can access only the files and folders available to that user. If someone with an administrator account launches an app, that app has more expansive access to files on the Mac, although <em>sandboxing</em> limits that scope somewhat; see <a href="https://nerdsmodo.com/mac-app-permissions/">how to control which apps use your Mac camera and files</a>. A malicious or compromised app launched by someone with an administrator account might be able to do serious damage across the Mac.</li>
</ul>
<p>You can create as many user accounts as you need, and switch between them easily. To keep your Mac secure, you should make sure you have the right number and types of accounts, as below.</p>
<h2>Set up a standard account for others</h2>
<p>A <em>standard</em> account has permission mostly to affect files and applications installed within the Home &gt; <em>Username</em> folder. It’s the right kind of account to set up for people using a Mac who aren’t sophisticated users, don’t need system-level access or the ability to install apps for all users, or shouldn’t be given the same level of trust on a shared computer as its owner or administrator.</p>
<p>At one point many Mac experts recommended a <em>standard</em> account for day-to-day use even by its main user or owner, and to use the credentials for an administrator account only when you’re installing software or engaged in other tasks that require access to the depths of your system.</p>
<p>However, macOS has changed significantly over the last several years. System files are now locked down and can’t be accidentally deleted or overwritten. Many actions you take require a Touch ID or password confirmation. To be frank: I’ve never used a standard account as my regular login, and I don’t see a reason for anyone else to do so at this juncture, either. (I have <em>great</em> backups that I can fall back on if I do anything epically poorly thought out.)</p>
<p>If your main account is currently an administrator account but you want to make it a standard account, you can create a new administrator account (for occasional use only) and then remove the administrative privileges from your main account.</p>
<ol>
<li>Go to <strong>System Settings &gt; Users &amp; Groups</strong>.</li>
<li>Click the Add User button.</li>
<li>Enter your password if prompted.</li>
<li>Choose Administrator from the New User pop-up menu.</li>
<li>Fill in the fields for Full Name and Account Name (that is, a short username, such as your initials). They can be anything you like, but they must be different from those used for other accounts on your Mac. Every account, especially an administrator account, should have a password that is both strong and unique.</li>
<li>Create a strong password and enter it in the Password and Verify fields; optionally enter a password hint.</li>
<li>Click Create User. If you had automatic login enabled, an alert appears, asking if you want to keep it on or turn it off. Click Turn Off Automatic Login. (This won’t appear with FileVault enabled.)</li>
<li>Choose Apple menu &gt; Log Out <em>Username</em> to log out of your <em>old</em> administrator account.</li>
<li>Select or enter the name of the <em>new</em> administrator account you just created, enter its password, and click the arrow button or press Return.</li>
<li>Once again, go to <strong>System Settings &gt; Users &amp; Groups</strong>.</li>
<li>Click the info button next to the old administrator account, then use the credentials for your new administrator account to authenticate.</li>
<li>Deselect or disable &#8220;Allow this user to administer this computer&#8221;; this turns your erstwhile administrator account into a standard account. An alert appears, claiming that you must restart for the changes to take effect. That’s not entirely true (you need only log out), but click OK anyway.</li>
<li>Choose Apple menu &gt; Log Out <em>username</em>, then log in to your old account, now a standard one, with your password.</li>
</ol>
<p>At this point, you may be prompted to enter the Apple Account for the new account. Since this administrator account will be for occasional use only, I suggest selecting the Don’t Sign In radio button, clicking Continue, and then confirming by clicking Skip again. If it turns out you need iCloud services with your new administrator account, you can always set them up later.</p>
<h2>Screen Time for a child account</h2>
<p>Screen Time is Apple’s cross-device, Apple Account-linked system for monitoring device usage and, for kids and other people one serves as a guardian for, controlling access. You can use Screen Time to track your behavior and set alerts about limits.</p>
<p>Screen Time isn’t strictly a security feature, and Apple overhauled it in the 27 releases; <a href="https://nerdsmodo.com/screen-time-parental-controls/">the parental controls</a> are covered separately.</p>
<h2>Set up a guest account</h2>
<p>As long as you’re making changes in Users &amp; Groups, you should think about whether you want to have a guest user account. It’s enabled by default starting way back in Yosemite. That’s usually a good idea, but if it doesn’t suit your needs, you can disable it.</p>
<p>With a guest user account enabled, you have a spare—and, importantly, <em>non-administrator</em>—account that anyone can log in to without a password. When logged in, they can run apps installed for all users, browse the web, or perform any other task that doesn’t require saving private information to disk permanently. (Guest users can, however, save data to publicly shared locations.)</p>
<p>If you prefer to not have a guest account, you can also restart your computer in recovery mode and choose Safari as an option. This lets a guest use Safari with zero access to locally stored files. See <a href="https://nerdsmodo.com/mac-system-integrity/">how macOS protects its own system files</a>.</p>
<p>As soon as the guest logs out, macOS deletes the guest’s temporary home folder, leaving everything just as it was beforehand. If you ever need to give someone temporary access to your computer, using the guest account is simpler than having to set up and later delete a conventional account for that person, and more secure than letting them use your account.</p>
<p>If you have <a href="https://nerdsmodo.com/filevault-mac/">FileVault</a> enabled, the Guest user can access only Safari.</p>
<ol>
<li>Go to <strong>System Settings &gt; Users &amp; Groups</strong>.</li>
<li>Click the info button to the right of the Guest User entry.</li>
<li>Enter your administrator password if prompted.</li>
<li>Enable or disable &#8220;Allow guests to log in to this computer&#8221;.</li>
</ol>
<p>With guest access enabled, you can optionally select either or both of the following checkboxes in the Guest User settings:</p>
<ul>
<li><strong>Limit adult websites:</strong> Apple blocks risqué-and-beyond sites.</li>
<li><strong>Allow guest users to connect to shared folders:</strong> This doesn’t affect the way someone logged in as a guest can access shared folders on this Mac, as you might expect. Rather, when selected, people on other devices on the network can connect to <em>this</em> Mac’s shared folders without supplying a username and password.</li>
</ul>
<h2>Give every user their own account</h2>
<p>If you’re the only person who uses your Mac, you can skip this topic. But if you share your Mac with family members, coworkers, or friends, do yourself—and them—a favor and create a separate (standard) account for each person. And then, insist that everyone log in to their user-specific accounts when using the Mac. That way, any damage (accidentally deleted files, changed preferences, and so on) will be restricted to that user’s space and not affect the entire Mac.</p>
<p>To enable switching from one user to another without having to log out (and thus quit all your apps):</p>
<ol>
<li>Click the Control Center button.</li>
<li>Click Edit Controls.</li>
<li>Enter &#8220;fast&#8221; in the search field.</li>
<li>Click the Fast User Switching icon.</li>
<li>Choose either Add to Control Center or Add to Menu Bar. You can choose one and then the other.</li>
</ol>
<p>If you add it to Control Center, you can drag to put it where you want among other controls.</p>
<p>To switch users, access the list of users by clicking the account button, account name, or full name from the menu bar or opening Control Center and clicking the Fast User Switching control. Choose the name of the user you want to log in as. That list also includes Login Window: select it to drop into the Login Window screen.</p>
<p>The post <a href="https://nerdsmodo.com/mac-user-accounts-security/">How to Set Up Safe User Accounts on a Shared Mac</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/mac-user-accounts-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4840</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/02/img_5048.jpg" />	</item>
		<item>
		<title>The Mac Privacy and Security Settings Worth Changing</title>
		<link>https://nerdsmodo.com/mac-privacy-security-settings/</link>
					<comments>https://nerdsmodo.com/mac-privacy-security-settings/#respond</comments>
		
		<dc:creator><![CDATA[Stacey Butler]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 16:21:36 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4839</guid>

					<description><![CDATA[<p>Set the lock to Immediately, or anyone can jiggle the mouse and read your files.</p>
<p>The post <a href="https://nerdsmodo.com/mac-privacy-security-settings/">The Mac Privacy and Security Settings Worth Changing</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>macOS has many privacy and security settings that can be turned off or tuned, reflecting in part how you interact with a computer versus a mobile device. Let’s start with System Settings &gt; Privacy &amp; Security, which collects several controls and options. I also mention settings in Users &amp; Groups, and Lock Screen, and in the Keychain Access utility, that deserve a quick look.</p>
<p>There is more on <a href="https://nerdsmodo.com/filevault-mac/">FileVault</a> separately.</p>
<h2>Unlock the pane or setting</h2>
<p>Apple requires you to prove your identity when accessing more sensitive elements of System Settings. First, click a setting, like changing “Allow applications from” to App Store. Now:</p>
<ul>
<li><strong>Touch ID:</strong> If you have Touch ID, you’re prompted for biometric authentication. You can also click Use Password to enter your account password, then click Unlock.</li>
<li><strong>No Touch ID:</strong> You’re prompted to type in the administrator password. Enter it and click Unlock.</li>
</ul>
<p>Some settings, such as Users &amp; Groups, prompt for your administrator password even when Touch ID is enabled.</p>
<p>With an Apple Watch, you can also unlock many settings by using a side button double-press. Go to System Settings &gt; Touch ID &amp; Password and enable your Apple Watch under “Use Apple Watch to unlock your applications and your Mac.”</p>
<p>That option also lets your Apple Watch unlock your Mac’s screen, as described below.</p>
<h2>Require an unlock for all preferences</h2>
<p>You can force yourself or users of the Mac to have to unlock <em>all</em> preferences before using them. Click the Advanced button in Privacy &amp; Security, and then select or enable “Require an administrator password to access system-wide preferences.” Items like Sharing settings can otherwise be used without an administrator password.</p>
<p>Settings &gt; Touch ID &amp; Password and System Settings &gt; Lock Screen offer two additional password-related features worth examining.</p>
<h2>Adjust password preferences</h2>
<p>In Touch ID &amp; Password, the top of the setting says “A login password has been set for this user” if you set one. Click Change to update it.</p>
<p>You should always have a password set for your Mac, even if you’re the only person in your house, because a password to access your computer is a fundamental building block of security. If someone accesses your computer without your permission or steals your computer, you want at minimum this level of protection.</p>
<p>Once you change your password, you can’t use the old one again. While that might seem obvious, Apple added a grace period starting in iOS 17/iPadOS 17: change the passcode on an iPhone or iPad and you can still use the old one for 72 hours. Apple never added this to macOS, possibly for unknown security reasons.</p>
<p>In Settings &gt; Lock Screen, select Immediately from the “Require password after screen saver begins or display is turned off” to, you know, do what it says on the label: force your Mac to lock when it goes to sleep, or when the screen saver activates and a period of time passes. You can also set it to wait for durations from 5 seconds to 8 hours.</p>
<h2>How to sleep or lock your Mac</h2>
<p>Apple offers lots of ways to let or force your Mac to go to sleep or initiate its screen saver. Here are several:</p>
<ul>
<li><strong>Turn display off on…when inactive:</strong> In Settings &gt; Lock Screen, you can set “Turn display off on [battery, power adapter] when inactive” to durations from 1 minute to 3 hours or Never. “Battery” and “power adapter” appear separately on laptops; only “power adapter” appears on desktops.</li>
<li><strong>Screen saver:</strong> Go to System Settings &gt; Wallpaper, click Screen Saver, and use the “Start Screen Saver” pop-up menu. Choose a duration greater than Never for how long your Mac must be idle before the screen saver activates.</li>
<li><strong>Lock screen menu:</strong> Choose Apple menu &gt; Lock Screen, and either the lock screen appears or the screen saver, depending on your settings. You can also press ⌘-Control-Q.</li>
<li><strong>Hot corner:</strong> Assign Lock Screen or Start Screen Saver to an action in System Settings &gt; Desktop &amp; Dock &gt; Hot Corners. Each corner may have a different action assigned from a diverse list.</li>
</ul>
<p>When you return, you can enter the password; or, on Macs with built-in or keyboard-based Touch ID enabled, unlock with Touch ID. See <a href="https://nerdsmodo.com/touch-id-face-id-setup/">how to set up Touch ID and Face ID</a>.</p>
<p>Touch ID may be disabled in certain circumstances for added security. See <a href="https://nerdsmodo.com/touch-id-face-id-setup/">when biometric lockout happens</a>.</p>
<p>You can choose Never, but I’d suggest…never doing this. Nearly everyone should pick Immediately or a short time duration—otherwise, every time you walk away from an active Mac, anyone with physical access can jiggle the mouse or touch the trackpad and access your stuff.</p>
<p>You can crank that up a notch if you’re at <a href="https://nerdsmodo.com/elevated-security-risk/">higher risk</a> of physical access or theft: click the Advanced button in Privacy &amp; Security, select “Log out automatically after inactivity,” and enter a duration in minutes. The Mac logs you out of your account after that period passes, raising the bar for a physical break-in. While the lock screen should be sufficient, background apps and other settings are in effect that could make your machine slightly more at risk than if it’s in a logged-out state.</p>
<p>If you have an Apple Watch, an iPhone, and a Mac signed in to the same iCloud account, you will have an additional option in System Settings &gt; Touch ID &amp; Password: “Use your Apple Watch to unlock your applications and your Mac.” Any Apple Watch that meets the preceding criteria appears in a list, each with its own switch. Enable one (or more) if you want your Mac to be automatically <em>unlocked</em> when it’s <em>locked</em>, you’re close by, and you’re wearing your watch. This setting also lets you unlock apps that require Touch ID via your Apple Watch, including the Apple Passwords app, and some system features.</p>
<p>Just tap the keyboard, keypad, or mouse as if you were jostling it to get it to show you a password dialog or a Touch ID prompt, and the Apple Watch and Mac have a conversation. Bluetooth and Wi-Fi must be enabled on the Mac for it to work.</p>
<p>Conversely, you might find unlocking your Mac with an Apple Watch is a security risk if you are subject to <a href="https://nerdsmodo.com/elevated-security-risk/">targeted attacks</a> by a government or individuals.</p>
<p>Optionally, you can have a message appear on a lock screen. In Settings &gt; Lock Screen, enable “Show message when locked,” click the Set button, enter a message, and click OK. This message can be useful if other people use the same Mac and you want to alert them as to why it’s idle.</p>
<p>I have my Mac in a day-lit basement office. Sometimes, I’ll be walking across our main floor, and my Apple Watch lights up that the Mac was unlocked a floor below!</p>
<h2>Control what can be plugged in</h2>
<p>Apple has options that can prevent peripherals, computers, and other accessories from connecting over built-in ports, like USB (Type-A and USB-C), Lightning, and SD Card, depending on your device. You can prevent peripherals from connecting via Lightning, Thunderbolt/USB, or the Smart Connector (for an iPad Smart Keyboard), or allowing a card to mount via the SD Card slot without permission.</p>
<p>Go to Settings/System Settings &gt; Privacy &amp; Security &gt; Wired Accessories (iPhone/iPad)/Accessories (Mac). Modify the Allow Accessories to Connect setting. You have four options:</p>
<ul>
<li>Always ask</li>
<li>Ask for new accessories</li>
<li>Automatically allow when unlocked</li>
<li>Always allow</li>
</ul>
<p>In any case in which you have to grant permission, you must enter your administrator permission—Touch ID or Face ID, even when available, isn’t considered a high-enough bar.</p>
<p>Starting in macOS 26 Tahoe, you can also choose a security policy for accessories at startup. You can use this to prevent peripherals other than drives from interacting with the system before a macOS session has started.</p>
<p>First, restart into recovery mode; see <a href="https://nerdsmodo.com/mac-system-integrity/">how macOS protects its own system files</a>. Next, choose Utilities &gt; Startup Security Utility. Now, choose an option as above from the “Allow accessories to connect” menu.</p>
<p>The post <a href="https://nerdsmodo.com/mac-privacy-security-settings/">The Mac Privacy and Security Settings Worth Changing</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/mac-privacy-security-settings/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4839</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/02/img_5047.jpg" />	</item>
		<item>
		<title>How to Share Files With End-to-End Encryption</title>
		<link>https://nerdsmodo.com/e2ee-file-sharing/</link>
					<comments>https://nerdsmodo.com/e2ee-file-sharing/#respond</comments>
		
		<dc:creator><![CDATA[Dave Johnson]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 16:03:44 +0000</pubDate>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4838</guid>

					<description><![CDATA[<p>Someone who steals an encrypted vault from a sync service has stolen trash.</p>
<p>The post <a href="https://nerdsmodo.com/e2ee-file-sharing/">How to Share Files With End-to-End Encryption</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Because of the fraught nature of putting your devices or services on them directly in the path of the entire internet, it’s almost always the case that you can share files more easily, with more control, and more securely using a cloud-based sharing service, with a lot of provisos that I describe along with each service.</p>
<p>Each of these services <em>partitions</em> access, so you know precisely what you are letting someone view or download, and whether they can modify, delete, or upload files. You can set a time limit that a link will work, and usually restrict whether something can be downloaded or just viewed online. You may also be able to tell when they access or view files and see exactly what changes they make, if they have permission to modify files.</p>
<p>All the major tech companies offer them, and you may already have free access to substantial storage, or already be paying for a subscription plan or higher level of storage for other purposes.</p>
<p>All these services encrypt data at rest and use encrypted transport (HTTPS, primarily) for uploads, downloads, and link creation. However, if someone can access your account, they can view, delete, modify, download, and add files without restriction.</p>
<p>If you want to share files in a truly secure, end-to-end manner, however, the gold standard is end-to-end encryption (often abbreviated E2EE). With E2EE, the ecosystem you use generates and retains keys only at endpoints, on devices under your control. (Sometimes you’re involved in generating them, but usually the key creation and management is silently handled by the software.)</p>
<p>iCloud.com was never protected by E2EE before December 2022; after that, it became optional for some services if you enabled Advanced Data Protection (ADP). With ADP, <a href="https://nerdsmodo.com/icloud-dropbox-sharing/">iCloud Drive</a> and other items synced, shared, and available via iCloud.com are protected by E2EE for you and with people with whom you share—so long as they also have ADP enabled. See <a href="https://nerdsmodo.com/advanced-data-protection/">how to turn on Advanced Data Protection</a>.</p>
<h2>Layer your own encryption on top</h2>
<p>If you or your shared partners don’t have ADP enabled or can’t turn it on, you can layer E2EE on top of standard secure cloud services, because data that’s encrypted before transfer and stored in these locations remains encrypted, and is only decrypted by endpoints that have the keys.</p>
<p>That is, if you have an encrypted disk image and upload it, that integral encryption isn’t stripped off. If someone downloads the disk image, they still have to break the encryption applied to that data to access what’s inside.</p>
<p>But you can be more sophisticated than a disk image. Software that handles its own encryption—say, the password-management app 1Password—can safely hold and sync its separately encrypted data on a sync service. Someone stealing your 1Password vault has stolen trash.</p>
<p>As of 1Password 8, the app works only with its own syncing system. It used to work with Dropbox and iCloud.</p>
<p>Beyond software that uses E2EE for its internal format are packages that allow generic file sync by effectively tunneling the end-to-end encryption across a sync service! From your perspective, the files are readily available; to everyone in between you and your devices, including the sync services, it’s just a bunch of garbage-looking data. This is a nifty workaround.</p>
<p>I can’t recommend a service, as I don’t use any, but there are two options you can test for this purpose that are Mac compatible:</p>
<ul>
<li>Cryptomator is an open-source solution to create an encrypted package, called a vault. It’s free to use on Mac, Windows, and Linux. The Android and iPhone/iPad apps have a one-time €19.99 (about US$23) purchase price to cover development costs.</li>
<li>VeraCrypt is also free, open-source software for creating virtual encrypted disks or partitions. However, the project supports desktop operating systems only: Linux, macOS, and Windows.</li>
</ul>
<p>Cloud sync services usually reduce data transfer required by syncing only changed portions of files. (Unix folks call it the <em>diff</em> after a command-line tool; <em>delta encoding</em> is a more exact technical term.)</p>
<p>With encrypted files you upload, large portions of the file or the entire file change whenever it’s modified, resulting in a lot of data synced. However, Apple’s bundle form of disk images and some third-party software breaks large files into smaller ones to solve this problem. Only those sub-portions are changed, resulting in less syncing.</p>
<h2>Encrypted messaging with others</h2>
<p>Apple enabled E2EE with Android users for messaging over RCS, an industry standard Google championed. However, be sure to check when you start messaging with someone using RCS that their Android device has RCS encryption enabled. You can see whether it’s enabled in Messages: an Encrypted label appears at the top of the conversation, or inline if the encryption method changes. (If you had an ongoing conversation with someone over RCS, upgraded your device, and they have encryption enabled, an inline message in the conversation would appear.)</p>
<p>If you want to use E2EE to exchange data with others, you can use options like GPG Suite ($23.90 per year, 30-day trial, Mac only), which manages public-key encryption data for you, and lets you exchange encrypted files via email with anyone else who uses PGP- or GPG-compatible software. (PGP is a decades-old implementation of public-key encryption; GPG is the GNU, free-software version.)</p>
<p>If you trust other parties to manage the process, you can use iMessage or Signal. In early 2021, Apple quietly overhauled iMessage’s innards to make it more robust, but still needs to publish its spec and allow outside auditing. The company quickly had to patch major exploits found in their update in September 2021, making an even better case for allowing more eyes on the problem.</p>
<p>In May 2025, people were baffled that they couldn’t type “Dave &amp; Buster’s” and similar ampersand-containing names into Messages. Turns out, Messages transformed the ampersand into something that triggered the protection! Apple fixed it, but it showed it worked?</p>
<p>Despite Apple’s lack of full transparency, iMessage remains trustworthy. Signal is created by an organization devoted to privacy, and has proven itself a great way to avoid interception.</p>
<p>The post <a href="https://nerdsmodo.com/e2ee-file-sharing/">How to Share Files With End-to-End Encryption</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/e2ee-file-sharing/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4838</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/09/img_5614-2.jpg" />	</item>
		<item>
		<title>Do You Need More Security Than Apple’s Defaults?</title>
		<link>https://nerdsmodo.com/security-risk-profile/</link>
					<comments>https://nerdsmodo.com/security-risk-profile/#respond</comments>
		
		<dc:creator><![CDATA[Chris Smith]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 15:49:07 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4837</guid>

					<description><![CDATA[<p>Phishing and social engineering overtook malware as the main risk years ago.</p>
<p>The post <a href="https://nerdsmodo.com/security-risk-profile/">Do You Need More Security Than Apple’s Defaults?</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In a TidBITS article, Evaluating Wireless Security Needs: The Three L’s, Adam Engst laid out the three factors he considered relevant to determining one’s risk when it comes to Wi-Fi security. He called them the three L’s: <em>likelihood</em> (the probability that someone will violate your security), <em>liability</em> (the cost—financial or otherwise—that you’d incur if a security breach happened), and <em>lost opportunity</em> (what you lose in terms of time and convenience by implementing stronger security). That article is still well worth a read almost two decades later.</p>
<p>Times, technologies, and threats change, but some people still face greater risks than others. If you can assess your own level of risk soberly, you’ll be able to take appropriate measures—neither too weak nor too strong.</p>
<h2>The risk for most people</h2>
<p>Years ago, it made more sense for nearly all Mac owners to consider their susceptibility to outside attack: how likely were you to visit sketchy sites, download applications that might contain Trojan horses, be infected by malware by visiting a site or running software, or even configure a network sharing setting that allowed people on the internet to scan and find weaknesses they could use to potentially copy data from your Mac, or worse. iPhone and then iPad users had fewer risks because of how iOS and iPadOS were constructed and locked down, but external attacks remained the central problem for them.</p>
<p>That profile changed considerably by the late 2010s. The biggest risk that most Apple users have faced since then—no matter their specific Apple hardware—comes from phishing and <em>social engineering</em>.</p>
<p>Phishing describes when someone impersonates a person, group, or website in the hopes you will click through and be infected by malware or enter login credentials. Phishers want your personal data, preferably financial information, such as your credit card number, expiration date, and verification code. They try to offer credible-looking security warnings and fraudulent webpages where you enter payment information or credentials they can use to access your bank and other accounts.</p>
<p>Social engineering is when people attempt to convince you to do something harmful to your device—and compromise your security and privacy. A common scam is that you visit a website and are redirected to another site (via malicious advertising or injected code) that claims your computer, phone, or tablet is infected and urges you to call a number. Calling that number leads you to a boiler room in which the other parties try to get you to install remote access software and sign up for expensive, hard-to-cancel tech services—or worse.</p>
<p>There are also more general attackers, who want to fool you into installing Mac apps that appear to be legitimate, but actually encrypt your personal files and hold them for ransom (<em>ransomware</em>). iOS and iPadOS don’t allow this vector because of how apps are installed and files managed. And even after over a decade into what remains rampant use of ransomware, that scourge hasn’t found a foothold on Mac.</p>
<p>From the mid-2020s, I would also argue that governments of democracies have increasingly chosen to enact laws or stretch the limits of existing ones to intrude into our private spaces, including accessing data that they would never previously have considered due to pushback from both ends of the political spectrum and, in some countries, a strong libertarian philosophy on the primacy of privacy.</p>
<p>Even if you don’t believe you fit in a category where the government of the place you reside would target you personally, you should assume your risk is elevated in any country that is sweeping away previous protections in the vague interests of “protecting children” even when no children are involved and “national security” when no national security interests are shown.</p>
<h2>The high value of privacy violations</h2>
<p>Some unwanted software doesn’t mess up a device or steal data, but installs <em>adware</em> that can display rogue ads (overlaying ones served by webpages), hijack web searches, and redirect affiliate clicks through portals controlled by the operators to make money illegitimately off you from advertisers. Other software is more insidious, tracking your location to sell it to companies that target you with ads—it’s a kind of malware, even if it doesn’t subvert the device.</p>
<p>The most obvious vector is a Mac, where you can install third-party software that isn’t vetted by Apple. But given that you can install extensions in Safari for the iPhone, iPad, or Mac, and that Apple has routinely failed to catch App Store apps that violate user privacy or include adware components, you can be at risk on any platform. Fortunately, so far, I have heard of no iPhone or iPad examples.</p>
<p>To step up protections, you can engage any or all of the following security or software integrity steps that reduce the area of attack on you that could succeed:</p>
<ul>
<li><strong>Two-factor authentication (2FA):</strong> This extra step for logging in deters attackers who have phished or otherwise obtained your password. Apple requires 2FA for Apple Accounts (with a few legacy exceptions), limiting access to iCloud-synced information, purchases, email, and much more. Most non-Apple services offer code-based 2FA (sent via SMS) or other ways to validate a password login. To compromise your account, someone has to obtain your SMS messages, your trusted devices, or your authentication app.</li>
</ul>
<p>Some phishers perform a “two-step” attack in which they convince you not only to enter your account name and password on a site, but then also relay that information in real time to the actual site you intended to access. This causes the real site to send you a confirmation code (or the fake site requests that you generate one). The attackers capture that code when you enter it. However, that scam works only for brief periods, as short as one minute.</p>
<ul>
<li><strong>Passkey:</strong> Upgrade accounts at websites that support <em>passkeys</em>, a secure method of logging in that’s deeply embedded on iPhones, iPads, and Macs, and supported by Google and Microsoft. The secret part of a passkey is never transmitted over the internet, and a passkey is phishing-resistant. You can sync and share passkeys when using recent operating systems and password managers. I’ve shifted from tolerating passkeys to preferring them to a password-and-second-factor combo. See <a href="https://nerdsmodo.com/apple-passwords-passkeys/">where Apple stores your passwords and passkeys</a>.</li>
</ul>
<p>Sounds great, right? But passkeys are, in every case I’m aware of, a supplemented to two-factor-protected accounts, not a replacement. Until you can make a passkey replace a regular login (with some kind of recovery option), they’re only as secure as the next-weakest link in the chain.</p>
<ul>
<li>
<strong>Hardware security key:</strong> Another form of 2FA, a relative of a passkey, is a hardware security key. These small physical objects plug into a USB or Lightning port or can connect via NFC to iPhones or iPads. The hardware key has embedded encryption circuitry that generates a unique, highly secure login key for each site you use it with. These keys are built on a standard nearly identical to the technology underlying passkeys, and most websites that support passkeys can accept a hardware security key and vice versa. (These keys also rarely fully replace access to an account yet, meaning a flaw in password and two-factor authentication could compromise access.)
</li>
<li>
<strong>Apple Pay:</strong> Avoid sites that don’t let you pay by Apple Pay, which prevents your credit-card number from being transmitted directly.
</li>
<li>
<strong>Install financial apps:</strong> Financial apps and their associated notifications make it more likely you will know immediately if any part of your financial life has been manipulated without permission. I’ve noticed a trend since 2024 for financial apps that support Face ID or Touch ID to let you log in from a desktop browser using a QR code or a push notification from the app. You then verify via biometrics, so you’re never entering any credentials in a browser.
</li>
</ul>
<p>Apple already blocks the direct installation of unsigned software on a Mac—apps that were released by people without an Apple Developer account or who bypassed Apple’s minimally involved signing system. By not allowing the easy installation of unsigned software, Apple prevents most malicious software from running at all. See <a href="https://nerdsmodo.com/gatekeeper-mac/">how Gatekeeper decides which Mac apps can run</a>.</p>
<ul>
<li><strong>Continuous backups:</strong> The technology for making constant, secure online backups of documents and creating local clones and backups obviates risks more present now than in the past when those options were slow, expensive, or not feasible due to cost or bandwidth limitations. Having such backups in place gives you a point to revert to if you have data corruption or loss.</li>
<li><strong>End-to-end encryption (E2EE) for iCloud:</strong> Apple’s Advanced Data Protection lets iCloud users put media, notes, reminders, and iCloud Drive files under the gold standard of end-to-end encryption, which requires possession of a device and the means to unlock to access data. Because we may store details that can be used to exploit us in these various kinds of media, E2EE is another leg up on attackers. See <a href="https://nerdsmodo.com/advanced-data-protection/">how to turn on Advanced Data Protection</a>.</li>
</ul>
<p>By using Apple and industry technologies and safeguards and keeping backups current, you can dramatically reduce your likelihood of risks while also curtailing the liability that results. Even if you’re infected by ransomware—an unlikely event—and don’t want to pay, you might lose <em>no</em> files by reverting to a snapshot before the attack; or if someone guesses or obtains an account login, you’re alerted as they try to log in, so you can change the password, or they’re blocked entirely without a second factor or hardware element.</p>
<p>The change in our general risk profile over time, however, comes with one big flashing red light. I noted a couple of times above that most people only need to take certain default strong, reasonable measures. However, if you’re someone in particular fields of work or who engages in political advocacy, you may face <a href="https://nerdsmodo.com/elevated-security-risk/">targeted attacks</a> that evade basic measures that suffice for everyone else.</p>
<p>A human-rights reformer in an incipient dictatorship needs to take more safeguards than a suburban online shopper in Ohio. But identity theft can sometimes lift that Ohioan—or you—into a much higher category of risk, because someone decides your assets or information are valuable to them, and they’ve acquired credentials or personal information that will let them attempt to crack your security shell.</p>
<h2>What about children?</h2>
<p>If your minor child has their own iPhone, iPad, or Mac, you might assume they are at very low risk. After all, their device probably contains nothing but games, educational software, a school-provided office suite, and a browser playing videos from Disney+.</p>
<p>But no! Sad to say, children are at greater risk than adults, all else being equal, because they’re less experienced and more trusting—and because, let’s face it, there are a lot of creeps out there who stalk children online.</p>
<p>If you travel to a country with severe laws or a propensity to jail people without legitimate charges, you should raise your risk profile before you travel and while there.</p>
<p>The post <a href="https://nerdsmodo.com/security-risk-profile/">Do You Need More Security Than Apple’s Defaults?</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/security-risk-profile/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4837</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/02/img_5048.jpg" />	</item>
		<item>
		<title>How to Set Up Automatic Security Updates on Apple Devices</title>
		<link>https://nerdsmodo.com/apple-security-updates/</link>
					<comments>https://nerdsmodo.com/apple-security-updates/#respond</comments>
		
		<dc:creator><![CDATA[Chris Smith]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 15:22:50 +0000</pubDate>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4835</guid>

					<description><![CDATA[<p>Apple patches most flaws before they are exploited, if you let it.</p>
<p>The post <a href="https://nerdsmodo.com/apple-security-updates/">How to Set Up Automatic Security Updates on Apple Devices</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>It’s a fact of life: software has bugs. And some of those bugs result in security vulnerabilities. Fortunately, most major software vendors, including Apple, have teams of programmers working constantly to identify and fix security-related bugs.</p>
<p>I can’t tell you how many times I’ve read breathless news reports about some newly discovered and seemingly disastrous Apple security issue, only to see a software update from Apple fix it a few days later before any damage occurs. This is Apple’s normal pattern, and it’s why you should never lose sleep about the security crisis <em>du jour</em>.</p>
<p>However, Apple security updates don’t help unless you install them! If you have automatic software updates turned off and ignore alerts or badges, you could be needlessly putting your devices and your data at risk from problems that were solved months or years ago.</p>
<p>Software updates fall into several categories, <em>all</em> of which can fix security issues:</p>
<ul>
<li>Major upgrades, such as from <a href="https://nerdsmodo.com/how-to-install-macos/">macOS 26 Tahoe to macOS 27 Golden Gate</a> or <a href="https://nerdsmodo.com/how-to-install-ios/">iOS 26 to iOS 27</a></li>
<li>Minor updates, which can be small increments for big fixes (27.1.0 to 27.1.1), or larger ones when they include feature changes but not a full operating system upgrade (such as 27.0.1 to 27.1)</li>
<li>Standalone security updates that fix specific pieces of system software, usually stuff deep beneath the surface (most common with a Mac)</li>
<li>Updates to individual Apple apps (Safari, Music, Books, QuickTime Player, etc.)</li>
<li>Updates to third-party apps</li>
</ul>
<p>Which of these should you keep up with? Ideally, all of them, but at a bare minimum, install the standalone security updates. After confirming you haven’t heard of any problems others have had, install minor updates. Major updates require more planning and involve much more than security fixes.</p>
<p>To learn about all Apple software updates with security implications, see the Apple security releases page. Click a specific update to read the security details.</p>
<h2>Zero-day exploits</h2>
<p>Apple, Google, Microsoft, security firms, anti-malware software developers, independent security consultants, and “gray-hat” hackers (not criminals, but they don’t always play by the rules—or laws) are constantly on the lookout for significant flaws to fix them and release updates before they become a <em>zero-day exploit</em> or <em>zero-day attack</em>. That’s when there’s literally <em>zero days</em> to patch the problem.</p>
<p>Malicious parties—including nation-state actors, such as the security agencies of major countries—may hold zero-days in reserve or use them in such a limited fashion that they remain available for some time. It’s the job of all software developers to patch zero-days before they’re exploited.</p>
<p>It’s much more often the case that ugly bugs are fixed by Apple before they’re exploited in the wild; or the exploit is so tricky, it requires physical device access or incredible sophistication, timing, and targeting. Apple will flag particularly severe exploits and recommend immediate installation when necessary. This happened on April 16, 2025, when Apple pushed out updates across their operating systems to fix zero-day exploits that the company said were already used in the wild in individually targeted attacks.</p>
<p>Zero-day exploits that aren’t reported to Apple and other companies responsibly—sometimes for significant “bug bounties” these firms and zero-day projects pay out—are sold on the gray market and used for pinpoint government operations. These are often ones most people would feel are illegitimate or violate human rights, such as three separate zero days used allegedly by the United Arab Emirates to hijack a single human-rights advocate in their country.</p>
<p>In most cases, Apple releases security updates for the current version of macOS, iOS, and iPadOS, and the previous three—or even four. If you aren’t at least on the third-most-recent version of one of these operating systems, you risk being vulnerable to known security problems that Apple won’t ever fix.</p>
<p>Apple also looks backward quite a ways with hardware, letting you upgrade fairly old Macs, iPhones, and iPads to at least one of the third-oldest operating systems, if not the current one. With Golden Gate, support covers all Apple silicon Macs; Tahoe included four Intel models from 2019 and 2020. iOS 26 and 27 look back to the iPhone 11 series (2019), while the cutoff points for iPadOS 26 and iPadOS 27 are very complicated.</p>
<p>Often the initial releases of new operating system versions (27.0.0, say) have significant bugs that Apple fixes quickly. So it’s fine to wait a few weeks on major upgrades, by which time enough others will have tried out the new release that you can judge how stable it may be for you.</p>
<p>Apple delivers minor and major updates and security updates through Software Update: go to System Settings (Mac) or Settings (iPhone/iPad) &gt; General &gt; Software Update.</p>
<h2>Configure automatic security updates</h2>
<p>Apple wants you to install updates as soon as possible on all its operating systems. The approach you take may be different between a Mac and an iPhone or iPad.</p>
<h3>On a Mac</h3>
<p>Software Update shows whether you’re up to date and notes any available updates if you are not. If you’re a major system update behind (or further), it also shows an area at the top urging you to install it. In a secondary area below, the pane may read “Another update is available” for Safari and security updates, and you have to click “More info” to discover which are and proceed to install them.</p>
<p>It also runs in the background and displays a red badge in System Settings indicating quantity. You can’t disable this.</p>
<p>You can completely automate minor macOS, security, and other updates—in fact, that’s the default. (Major macOS updates require direct action.) Go to System Settings &gt; General &gt; Software Update and, to the right of Automatic Updates, click the info button to see settings and make changes.</p>
<ul>
<li><strong>Download new updates when available:</strong> This includes all the updates listed below. The advantage is that they are either installed automatically or available for immediate installation if you install manually. Disable this if you’re bandwidth-limited or pay for bandwidth and want to plan downloads.</li>
<li><strong>Install macOS updates:</strong> This includes all “dot” updates, like moving from 27.0.0 to 27.0.1 <em>and</em> from 27.0.1 to 27.1.0.</li>
<li><strong>Install system data files and security updates (Golden Gate) or Security Responses and System files (Tahoe):</strong> Apple used to use the term “Rapid Security Response” for these security updates; I’m guessing they now incorporate more kinds of security fixes? Previously, the company explained those updates addressed exploits that Apple discovered were already happening in the wild, not just identified by researchers. These fixes are installed automatically when this option is turned on—no reboot required.</li>
</ul>
<p>Apple moved automatic App Store updates from Software Update to the App Store app in macOS 26.</p>
<p>In most cases, you can view a list of available updates, deselect or select items in the list, select items to view their contents, and click Install Now to proceed towards installation. Updates that require restarting your Mac are marked with “Restart Required” after their title in the detail section, and you’re warned when you click Install Now that you will need to let the updater restart your Mac to complete the update.</p>
<p>The next major operating system update past what you’re running used to appear as a short entry with a More Info link. But in Monterey, Apple transformed the upgrade notice into a full advertisement that listed all the available features. Minor updates still use the More Info link to tell you what to expect.</p>
<p>When preparing to install updates that require a restart, make sure you have no unsaved files, no open Terminal windows, and nothing in progress in an app. Often, this can halt a restart—particularly an issue if you walk away hoping to return with the update done. I always wait until my Mac restarts before leaving.</p>
<p>In addition to the Software Update setting for system data files and security updates, make sure the setting introduced in macOS 26.1 is enabled: System Settings &gt; Privacy &amp; Security &gt; Background Security Improvement. With this enabled, Apple can update certain parts of the system, such as components of Safari and system libraries used by multiple apps, without requiring a full incremental update and restart.</p>
<h3>On an iPhone or iPad</h3>
<p>Software Update on an iPhone or iPad, in Settings &gt; General &gt; Software Updates &gt; Automatic Updates, offers options similar to those on a Mac. If you enabled Automatically Install, you’re alerted that an update will happen overnight the next time the device is plugged in and idle. This option also hides the next two: Automatically Download and System Files &gt; Automatically Install.</p>
<p>Even if you don’t want updates to be installed automatically, enabling downloads for iOS/iPadOS Updates lets you avoid waiting for a download to happen when you make the decision to trigger an update manually—the file is ready to go.</p>
<p>Everyone should leave System Files enabled for automatic updates, for the reasons given above.</p>
<p>As with macOS, Background Security Improvements should also be turned on. Go to Settings &gt; Privacy &amp; Security &gt; Background Security Improvements, and make sure it’s enabled.</p>
<h2>Configure App Store updates</h2>
<p>The App Store is where you buy apps and acquire free apps, including those with in-app purchases, that have gone through additional layers of vetting by Apple. One advantage is that you don’t need to use the app or visit a website to check whether the latest version is installed.</p>
<p>On a Mac, the App Store has an Updates item in its left-hand navigation bar. Click that, and you can see available updates. You can also use App Store’s Preferences to control automatic updates: select or deselect Automatic Updates.</p>
<p>On iPhone/iPad, the default is for updates to be quietly updated in the background. You can change this in Settings &gt; Apps &gt; App Store, where you can disable App Updates. You can see the queue of updates waiting to happen in the App Store app: tap the account button in the upper-right corner and then tap App Updates. Any apps with pending updates appear under an Upcoming Automatic Updates label. You can force a check for updates by swiping down and releasing, and you can tap Update All to force an immediate app update.</p>
<h2>Update everything else on a Mac</h2>
<p>Software that didn’t come from the Mac App Store must be updated separately. Fortunately, most apps include an automatic, configurable update check whenever you launch them, and also check for updates periodically. You can disable this in nearly all apps, though I recommend keeping the feature on, or enabling it if it’s turned off by default.</p>
<p>If you haven’t seen update notifications lately, or aren’t sure how your favorite apps have automatic updates configured, now is the time to check. Launch each app, select its option to check, and install updates.</p>
<p>Some apps use “check for updates” as a way to sell you on a paid <em>upgrade</em> to the next version of the product. I don’t mind seeing this once or twice, but some software I use brings up a paid update available message at every launch; not cool.</p>
<h2>How Apple numbers its releases</h2>
<p>Starting with fall 2025 operating system releases, Apple reset their numbering system to the last two digits of the following year, starting with 26. So 2026 releases are iOS 27, iPadOS 27, macOS 27 Golden Gate, tvOS 27, and watchOS 27; and 2025 releases were iOS 26, iPadOS 26, macOS 26 Tahoe, tvOS 26, and watchOS 26.</p>
<p>The post <a href="https://nerdsmodo.com/apple-security-updates/">How to Set Up Automatic Security Updates on Apple Devices</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/apple-security-updates/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4835</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/09/img_5613.jpg" />	</item>
		<item>
		<title>What Private Wi-Fi Address Does, and When to Change It</title>
		<link>https://nerdsmodo.com/private-wifi-address/</link>
					<comments>https://nerdsmodo.com/private-wifi-address/#respond</comments>
		
		<dc:creator><![CDATA[Dave Johnson]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 15:12:10 +0000</pubDate>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4834</guid>

					<description><![CDATA[<p>A hardware address that never changes lets a network recognise you for years.</p>
<p>The post <a href="https://nerdsmodo.com/private-wifi-address/">What Private Wi-Fi Address Does, and When to Change It</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Apple built in privacy protection for an issue adjacent to <a href="https://nerdsmodo.com/mac-public-ip-address/">your IP address</a>. Every Ethernet or Wi-Fi adapter, built in or plugged in, has a unique MAC address—that’s Media Access Control, not Macintosh. A MAC address appears in the form <code>xx:xx:xx:xx:xx:xx</code>, where each <code>x</code> is a value between 0 and 15 expressed in hexadecimal (0 to 9 then A to F). Apple perplexingly calls it a “Wi-Fi address”, which is the incorrect name.</p>
<p>A MAC address is how a device communicates over a local network, used to make sure every interface has a unique address to avoid data being delivered to the wrong location. However, because this MAC address is set in hardware, clever hackers and marketers started to use it to associate people with devices—your MAC address persisted indefinitely, so a Wi-Fi router in a public place could conceivably track you over time whenever you connected to any router that shared information with a central database, like a cell carrier or ad-targeting service. Bad!</p>
<p>Apple got around this by adding a “Private Wi-Fi address” option (still the wrong term) that generates a unique MAC address for each Wi-Fi network you join, changing it from time to time. This deters and potentially fully prevents MAC-based tracking.</p>
<p>Apple made significant changes to this several-year-old feature in iOS 18/iPadOS 18, macOS 15 Sequoia, and watchOS 11.</p>
<p>You can configure “Private Wi-Fi address” in one of three ways:</p>
<ul>
<li><strong>Off:</strong> The actual unique MAC address is sent to the router.</li>
<li><strong>Fixed:</strong> Your device generates a MAC address that’s used consistently for the selected Wi-Fi network. This may be required in some places in which a MAC address is used as part of a hotspot portal’s permission system that grants you access or in corporate environments when you’re a guest. Your home router may even offer an option to set a fixed private IP address using a MAC address, so your MAC address needs to be fixed.</li>
<li><strong>Rotating:</strong> The private address that’s generated is changed to a new, randomly created one every two weeks, whether you’re connecting in that period or after a gap of two weeks or longer.</li>
</ul>
<p>Apple defaults to either Fixed or Rotating. It uses Fixed the first time you connect to a network with relatively modern Wi-Fi network security—WPA2 or later, to use the technical term. A network without such security, either using outdated standards or requiring no passwords, such as at an open Wi-Fi network at a café, is set to Rotating by default. You have to choose Off, read a warning, and confirm.</p>
<p>The options to change the type of Private Wi-Fi Address used with a network vary by operating system:</p>
<ul>
<li>
<strong>iPhone/iPad:</strong> Go to Settings &gt; Wi-Fi: tap the info button next to the currently connected network or any other network that appears. You can also tap Edit, and then tap the info button next to any stored network.
</li>
<li>
<strong>Mac:</strong> Go to System Settings &gt; Wi-Fi &gt; Details for the active network. For other networks, click the More button; for Known Networks, then choose Network Settings.
</li>
</ul>
<p>To see the underlying Wi-Fi adapter’s hardware-set MAC address, go to Settings &gt; General &gt; About and look for Wi-Fi Address on an iPhone or iPad. On a Mac, follow the path of System Settings &gt; Wi-Fi, click the Advanced button, and see Wi-Fi MAC Address near the top.</p>
<p>The post <a href="https://nerdsmodo.com/private-wifi-address/">What Private Wi-Fi Address Does, and When to Change It</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/private-wifi-address/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4834</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2023/04/img_2098.jpg" />	</item>
		<item>
		<title>Why an App Won’t Open on Your Mac, and What to Do</title>
		<link>https://nerdsmodo.com/unsigned-app-wont-open-mac/</link>
					<comments>https://nerdsmodo.com/unsigned-app-wont-open-mac/#respond</comments>
		
		<dc:creator><![CDATA[Chris Smith]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 14:35:06 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4833</guid>

					<description><![CDATA[<p>Unsigned software is usually harmless, and occasionally it is malware.</p>
<p>The post <a href="https://nerdsmodo.com/unsigned-app-wont-open-mac/">Why an App Won’t Open on Your Mac, and What to Do</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>It is rare to find an app that hasn’t gone through <a href="https://nerdsmodo.com/gatekeeper-mac/">notarization</a>. But you may still encounter software you can download from an open source project’s site—typically free and often developed by a group of volunteers—that isn’t signed and notarized.</p>
<p>While most developers consider Apple’s annual developer program fee and company oversight affordable and reasonable, some folks do not. They may be creating a small piece of utility software that’s maintained, but nobody in the group that produces it wants to either ask for donations or cough up the dough. Or they may find Apple’s oversight irksome and invasive, despite the advantage to users. Or they may have interpreted copyright in a way that doesn’t match Apple’s policies.</p>
<p>If it’s not the above case, there are a few other reasons that you might encounter an app Gatekeeper balks at:</p>
<ul>
<li>You run a preliminary version of a new app that the developer simply hasn’t gotten around to signing yet.</li>
<li>You create your own app or standalone script (perhaps using Script Editor) and don’t want to (or don’t know how to) sign it.</li>
<li>You’ve downloaded malware. It isn’t signed because the developer doesn’t want to risk exposing their identity—and enabling Apple to revoke the certificate, thus preventing the app from being installed in the future.</li>
</ul>
<p>Whatever the reason, if you launch an app that isn’t signed or is signed but not notarized, macOS explains the problem. The dialog may say that it’s by an unidentified developer, or by a developer whose identity can’t be verified. Click OK—the only choice—and the app never completes launching.</p>
<p>Apple does let you install Mac software like this, but they don’t make it easy. There used to be an option in the Gatekeeper settings to disable Gatekeeper altogether; now, you have to use a manual bypass for any such app you want to launch on its first use, which Apple made more complicated in Sequoia to deter people even further.</p>
<p>Before you override Gatekeeper, give a lot of thought to what you’re trying to run and where you got it. As battle-scarred and cynical as I am, I always take additional effort and make additional scrutiny before bypassing Gatekeeper for an app I know I need and know its source.</p>
<h2>Check it before you run it</h2>
<p>The most excellent developers who forswear Apple’s process always offer out-of-band methods you can use to check the integrity of their downloads. So if you trust the project and want to make sure an app hasn’t been fiddled with, the site might post hashes it makes of its disk image files at the time of creation, or use its own signing process that can be validated with publicly available encryption keys. The best of these apps will then also provide pointers on how to perform validation and authentication without you having to take a two-hour cryptography course.</p>
<p>With all that in mind, here’s how to bypass Gatekeeper.</p>
<ol>
<li>Open the application. You see a dialog saying the app can’t be opened, with no suggestion of what to do next. Click Done.</li>
<li>Go to <strong>System Settings &gt; Privacy &amp; Security</strong>. As with a signed app when you have Gatekeeper set to App Store, you have identical text and an Open Anyway button.</li>
<li>Click Open Anyway.</li>
</ol>
<p>I’m not sure Apple made the right call here, equating signed apps from developers and unsigned apps as the same kind of problematic item based on the Gatekeeper setting. But I suppose both are now considered suspect in the context of each setting choice.</p>
<p>The post <a href="https://nerdsmodo.com/unsigned-app-wont-open-mac/">Why an App Won’t Open on Your Mac, and What to Do</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/unsigned-app-wont-open-mac/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4833</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/02/img_5047.jpg" />	</item>
		<item>
		<title>How the Mac Keychain Works, and How to Lock It</title>
		<link>https://nerdsmodo.com/mac-keychain-security/</link>
					<comments>https://nerdsmodo.com/mac-keychain-security/#respond</comments>
		
		<dc:creator><![CDATA[Chris Smith]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 13:58:36 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4832</guid>

					<description><![CDATA[<p>Turning on your Mac can be enough to unlock every password you have saved.</p>
<p>The post <a href="https://nerdsmodo.com/mac-keychain-security/">How the Mac Keychain Works, and How to Lock It</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Your Mac has a low-level secret-managing system called Keychain, which is covered more fully in <a href="https://nerdsmodo.com/apple-passwords-passkeys/">where Apple stores your passwords and passkeys</a>. Keychain contains passwords for lots of different things that need to be both available on demand and secured against unauthorized access. This includes passwords to log in to apps and Wi-Fi networks, passkeys for websites at which you’ve enrolled to use them, credentials for local network servers, encryption certificates, and other important information your Mac needs to function securely.</p>
<p>If you sync Passwords with iCloud, Keychain also contains credentials for websites where you have accounts and may include your credit card details, separate from the stored Apple Pay payment card information on Macs with Touch ID or an Apple silicon Mac paired with a Magic Keyboard with Touch ID.</p>
<p>Because this information is valuable and potentially sensitive, a Mac encrypts the contents of your keychain. However, whenever your Keychain is unlocked, your credentials can be passed to apps, websites, and network services without any intervention on your part.</p>
<p>And how do you unlock your keychain? That’s the wild part: all you have to do is log in to your Mac’s user account. And—as covered in <a href="https://nerdsmodo.com/mac-login-items-extensions/">what launches on your Mac</a>—another default setting is to log you in to your account automatically.</p>
<p>As noted earlier, if you have FileVault enabled, you can’t log in automatically. However, <em>after</em> you manually log in, you’re in the same boat as anyone else. See <a href="https://nerdsmodo.com/filevault-mac/">how to turn on FileVault</a>.</p>
<p>In other words, unless you take steps to change the defaults, merely turning on your Mac might unlock your keychain!</p>
<p>Anyone else who might have physical access to your Mac could then log in to all your web accounts (like your bank, Amazon, or PayPal), file servers, and other resources where you’ve saved credentials (like Music or the App Store).</p>
<p>There are a few bright spots:</p>
<ul>
<li>No one can <em>see</em> the actual keychain entry’s secure text without knowing your macOS account login password.</li>
<li>Within Safari, an unwanted party can’t get a list of all the sites at which you have passwords stored from Safari, Keychain, or the Passwords app without your password.</li>
<li>Even when a password is autofilled in Safari or in an app, there’s typically no way to copy the password to view it as text.</li>
<li>Macs with active Touch ID hardware and password autofill enabled will drop in your password <em>only</em> when you use a valid fingerprint or enter your password (System Settings &gt; Touch ID &amp; Password &gt; “Use Touch ID for autofilling passwords”).</li>
</ul>
<p>Touch ID can be built in, as with a laptop model, or for an Apple silicon Mac, provided via a paired Magic Keyboard with Touch ID. See <a href="https://nerdsmodo.com/touch-id-face-id-setup/">how to set up Touch ID and Face ID</a>.</p>
<p>Yet the storm cloud lingers: someone can <em>use</em> all your passwords when the conditions above aren’t true. These actions will help prevent that:</p>
<ul>
<li><strong>Leave FileVault enabled:</strong> Because FileVault is a high-value way to prevent power-up access to your computer, most people should leave it enabled, and it is on by default starting in macOS 26. Some people may find it more trouble than the potential of losing access to their files; see <a href="https://nerdsmodo.com/filevault-mac/">how to turn on FileVault</a> for both sides.</li>
<li><strong>Turn off automatic login, if you don’t have FileVault enabled:</strong> See <a href="https://nerdsmodo.com/mac-login-items-extensions/">what launches on your Mac</a> for how to disable it.</li>
<li><strong>Enable Touch ID and AutoFill:</strong> This blocks access to autofilled passwords without your fingerprint or password.</li>
<li><strong>Lock your Mac after a duration:</strong> See <a href="https://nerdsmodo.com/mac-privacy-security-settings/">the Mac settings worth changing</a>.</li>
</ul>
<h2>Lock the keychain separately</h2>
<p>For most people, setting their Mac to lock when it sleeps, when the display is off, or after a screen-saver duration has passed, as described in <a href="https://nerdsmodo.com/mac-privacy-security-settings/">the Mac settings worth changing</a>, is enough. But macOS also lets you lock the keychain after a set period, even if your Mac remains unlocked.</p>
<p>First, open Keychain Access, located at <code>/System/Library/CoreServices/Applications</code>. Click Open Keychain Access at the prompt.</p>
<p>Select your login keychain, and choose Edit &gt; Change Settings for Keychain “login”. You can select “Lock after <em>X</em> minutes of inactivity,” pick a time delay, and click Save. (The “Lock when sleeping” option makes little sense—you should set your <em>Mac</em> to lock when sleeping, as that locks the Keychain and your session.)</p>
<p>Note that you can only change settings for the login keychain and your custom keychains, if any. You cannot change these settings for the System, System Roots, or iCloud (if enabled).</p>
<p>The post <a href="https://nerdsmodo.com/mac-keychain-security/">How the Mac Keychain Works, and How to Lock It</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/mac-keychain-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4832</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/09/img_5614-2.jpg" />	</item>
	</channel>
</rss>
