On CHOW: Easy Thanksgiving for beginners
BNET Business Network:
BNET
TechRepublic
ZDNet

June 2nd, 2008

Apple releases Mac OS X Leopard Security Guide

Posted by David Morgenstern @ 2:01 pm

Categories: Leopard, Security

Tags: Security, Apple Macintosh, Apple Mac OS X Leopard, Apple Inc., Computer, Apple Mac OS, Apple Mac OS X, Operating Systems, Desktops, Software

Developers remain in dark about Leopard GM bug fixesApple offers sys-admins almost 250 pages of security best-practices and tips to protect Mac OS X Leopard clients.

Released on Monday, the guide document is a 3.4MB PDF. The guide is aimed at experienced users, Apple says, familiar with the Terminal application and its command-line interface.

Some instructions in this guide are complex, and deviation could cause serious adverse effects on the computer and its security. These instructions should only be used by experienced Mac OS X users, and should be followed by thorough testing.

The guide spans basic “hardware” security practices as well as the new security features introduced in Leopard, such as library randomization and sandboxing.

There are all kinds of tidbits in the document. For example, I didn’t know about support for Smart Card authentication for unlocking and encrypted storage devices on Mac OS X.

Leopard supports four token modules with two-factor authentication mechanisms and Java Card 2.1 standards: Belgium National Identification Card (BELPIC), Department of Defense Common Access Card (CAC), Japanese government PKI (JPKI), and the U.S. Federal Government Personal Identity Verification, also called FIPS-201(PIV). Go figure.

Here’s the list of topics in the guide:

Chapter 1, “Introduction to Mac OS X Security Architecture,” explains the infrastructure of Mac OS X. It also discusses the layers of security in Mac OS X.
Chapter 2, “Installing Mac OS X,” describes how to securely install Mac OS X. The chapter also discusses how to securely install software updates and explains permissions and how to repair them.
Chapter 3, “Protecting System Hardware,” explains how to physically protect your hardware from attacks. This chapter also tells you how to secure settings that affect users of the computer.
Chapter 4, “Securing Global System Settings,” describes how to secure global system settings such as firmware and Mac OS X startup. There is also information on setting up system logs to monitor system activity.
Chapter 5, “Securing Accounts,” describes the types of user accounts and how to securely configure an account. This includes securing the system administrator account, using Open Directory, and using strong authentication.
Chapter 6, “Securing System Preferences,” describes recommended settings to secure Mac OS X system preferences.
Chapter 7, “Securing Data and Using Encryption,” describes how to encrypt data and how to use Secure Erase to verify that old data is completely removed.
Chapter 8, “Securing System Swap and Hibernation Storage,” describes how to secure your system swap and hibernation space of sensitive information.
Chapter 9, “Avoiding Multiple Simultaneous Account Access,” describes how to avoid fast user switching and local account access to the computer.
Chapter 10, “Ensuring Data Integrity with Backups,” describes the Time Machine architecture and how to securely backup and restore your computer and data.
Chapter 11, “Information Assurance with Applications,” describes how to protect your data while using Apple applications.
Chapter 12, “Information Assurance with Services,” describes how to secure your computer services. It also describes how to protect the computer by securely configuring services.

David MorgensternDavid Morgenstern has covered the Mac market and other technology segments for 20 years. See his full profile and disclosure of his industry affiliations.


Email David Morgenstern

Subscribe to The Apple Core via Email alerts or RSS.

  • Talkback
  • Most Recent of 11 Talkback(s)
RE: Apple releases Mac OS X Leopard Security Guide
See wirelesswall.com for the panultimate Mac Leopard security solution. Strong end-to-end seamless layer 2 encryption for wireless and wired networks that's FIPS certified and least cost. It makes networks "unsniffable".... (Read the rest)
Posted by: aphilsmith Posted on: 01/11/09 You are currently: a Guest | | Terms of Use
Sweet. OS X does include MAC.  ye | 06/02/08
I thought that Mac was secure by design  timiteh | 06/03/08
You are so right.  frgough | 06/03/08
To be fair  jshaw4343 | 06/03/08
Huge vs Tiny  BillDem | 06/03/08
That means that...  themusicmanrk | 06/03/08
Its coming smart guy  Crestview | 06/03/08
RE: Apple releases Mac OS X Leopard Security Guide  mlith35 | 06/03/08
What about the "average" user?  mikifinaz1@... | 06/03/08
They are making this up  Crestview | 06/03/08
RE: Apple releases Mac OS X Leopard Security Guide  aphilsmith | 01/11/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here