AMITIAE - Wednesday 29 August 2012
System Preferences in OS X 10.8, Mountain Lion: Security & Privacy |
|
By Graham K. Rogers
Recently updated to version 10.8, Mountain Lion, Apple's OS X has had many changes to System Preferences. The Security & Privacy preferences has had several changes and it is here that the way apps may be downloaded and installed is controlled as well as other features concerning access from outside.
The Security & Privacy Preferences section works with other parts of System Preferences (like Users & Groups and Sharing) for a safer environment if used properly. The Security Preference pane has four sections: General, FileVault, Firewall and Privacy. There are several changes here, particularly to the General pane.
GeneralAn immediately noticeable change here concerns the ability to change the user's login password for the account. A button marked, Change Password is available and using this does not need Admin account privileges: users may change this on their own.
A major change in this panel is to the way a user may add a message that can be viewed when the screen is locked. Before 10.7 this was only possible with a third-party utility like Onyx. With the latest update to OS X, the feature has been moved up the panel and the text box is no longer visible. A button, marked Set Lock Message opens a drop-down text box. On my computer, the same message entered using Onyx (pre-10.7) is still shown. A further check box prevents automatic log-in. Used with the screen-saver lock, Firmware Password Utility (available now by starting up in the Rescue partition, by using Command + R) this may prevent unauthorized use of a computer.
Allow applications downloaded from:
The settings reflect Apple's take on security. With App Store only apps, there is a built-in secure process for developers to follow before their apps can be authorised for sale: in this case, these apps are supposed to be completely secure for users to install. Identified Developers have registered with Apple and while they may not wish to have their apps sold via the Mac App Store, the registration with Apple should give users a relative peace of mind as to the safety of their products. This may apply also to developers who sell via the Mac App Store but who make available trial or beta versions of their software. All the rest, may or may not be trusted and this is the user's decision. By selecting the third option, it is possible to install anything and this may have unacceptable levels of risk for some. However, there are certain developers whose products are worthy but who have not registered with Apple for this. Users may still want to download and install these while maintaining a higher level of security. If a user tries to install such an App from an unrecognised developer this will be stopped by the system and a warning panel will appear. To install, the user should find the icon in the Applications folder. Control click on the application's icon and select Open. If you work in a user account like I do, this does need Admin privileges, but I entered the password and now the app opens and will for evermore.
At the bottom right of all panels in Security & Privacy preferences there is now a button marked "Advanced...". This has a number of checkbox options that were previously on the General pane:
Text below the last checkbox item tells users that the computer will work with any available remote. There is a Pair button that makes sure only a specific remote control may be used with the computer. If the box is checked, the text below reads, "This computer will not work with any remote" and the Pair button is greyed out.
FileVaultThe second panel in Security Preferences focuses on FileVault. The icon (a house with a safe dial superimposed) signifies the ability to lock the users Home folder by way of encryption. If activated, files are decrypted and encrypted while working. A user enters the account as normal, using the password. To start this, users press the single button, "Turn On FileVault"The button has now been moved to the top of the pane and the text description to its left has been changed: "FileVault secures the data on your disk by encrypting its contents automatically." [Previously: FileVault secures the data on your disk by encrypting its contents. It automatically encrypts and decrypts your files while you're using them.]
Text beneath indicates if the feature is on or off for the disk.
FirewallAnyone who does not use a firewall these days is asking for trouble. There were significant changes to the firewall in OS X Leopard and the panel in Mountain Lion seems to be similar. It is application-focussed rather than port-focussed. The Firewall pane has basic information for the user and two buttons: Turn On Firewall (or Turn Off Firewall if it is ON) and Firewall Options... The advanced panel can be accessed only if the security padlock icon is open.
An applications list panel allows a feature or program the correct access instead of specifying port numbers as was the case before Leopard. A checkbox when active will Automatically allow signed software to receive incoming connections. Above the application list are several OS X features that may have been activated in other preferences, such as DVD or CD Sharing or Screen Sharing.
One more check box in the Options panel allows activation of Stealth mode, so that any outside probing that occurs (such as that shown in logs) will have no response: the computer will not even appear to exist.
PrivacyThe final pane in Security & Privacy preferences has been completely redesigned.To the left is a panel that shows any apps or services that are permitted to access specific types of data. Highlighting each will show in the main panel any apps affected and the type of access allowed. A user will be asked to permit such access when setting up OS X or after installing some applications.
Graham K. Rogers teaches at the Faculty of Engineering, Mahidol University in Thailand. He wrote in the Bangkok Post, Database supplement on IT subjects. For the last seven years of Database he wrote a column on Apple and Macs. |
|
For further information, e-mail to