Mac (in)security: How to secure Macs in business
As Macs make their way into the enterprise, IT needs to address these six security flaws before disaster strikes
That should change. "We are starting to see early signs that some vendors are supporting Mac as a platform for those configuration management systems," Mogull says.
Solution: Consider limited deployment of third-party software to restrict configuration by administrative users if your current solution doesn't include Mac support.
Security flaw No. 3: Everybody's an administrator (or not)
Apple has a binary attitude when it comes to modifying system settings, gaining access at the command line to its Unix underpinnings,
and installing software: You're either an administrator -- or you're not.
For home users and small businesses, the distinction is probably enough. An unprivileged or normal user can be restricted via parental controls and typically can't create user accounts, enable file-sharing services, or install certain kinds of software. For that, an administrative-flagged account is needed.
But with administrator privilege set, a user can turn on features through switches in System Preferences, such as enabling Samba -- "the Mac version is typically three to six months out of date," Mogull says -- or using the Terminal application to activate any of the thousands of Unix daemons and servers that ship as part of a stock Mac OS X system.
"It's hard to enable those things on Windows," says Thomas Ptacek, a principal consultant at security firm Matasano Chargen, noting that even when such settings are available in Windows, the settings are typically obscure or complicated enough to deter average users. By contrast, a single click might be enough in Mac OS X.
Solution: Limit administrative accounts to users that require them.
Security flaw No. 4: Naïve use of Back to My Mac
Mac OS X includes one special service that sounds alarming at first glance -- and can be a real security hole in unmanaged
environments. Back to My Mac, a remote access system built into Mac OS X 10.5, requires both a MobileMe account (formerly .Mac) from Apple and administrator privileges. Back to My Mac operates like the GoToMyPC familiar to Windows administrators, although
it's less insistent about working around intentional blockades.
While Apple uses IPv6 tunnels, IPsec encryption, and Kerberos tickets to secure connections, starting up such a connection from anywhere on the Internet requires just the password to someone's MobileMe account. With that password, all computers with Back to My Mac enabled can have their files examined or screens remotely controlled.
In a managed enterprise, security experts don't believe that Back to My Mac creates any real risk, despite its feature set. "No enterprise is going to allow something like Back to My Mac unless it's running through a VPN tunnel," Mogull says, at which point it would conform to the enterprise's policy. If users are running Back to My Mac on their own, "it would mean that [IT] royally screwed up" the firewall, he adds.
-

- COMMENTS
Technology White Papers
- Frost & Sullivan Competitive Ranking Report - In this paper, Frost & Sullivan has detailed leading mobile solution deployments, products in development and new product...
- Good Mobile Messaging Product White Paper - Mobile Messaging-a standards-based, wireless messaging application and management system that connects mobile workers to...
- The Enterprise Mobile Messaging Benchmark Report - In this report Aberdeen takes an in-depth look at how best-in-class organizations are using mobile messaging to improve ...
- Choosing the Right CMDB: Smart Considerations for Strategic Decision Makers - Drawing on industry-leading research, this white paper discusses: -The strengths and limitations of CMDBs based on relational...
- Increasing ROI and Reducing the Risks of Your Application Portfolio - APM solutions help IT executives evaluate the benefits, costs, and risks associated with each application while maximizing...
- The Future of IT in a Flat World: CMDBs, Automation, and the IT Value Chain - In coming years, as IT becomes more closely aligned with business, IT will be expected to change its products and services...
-
-
- Technology White Papers
- Technology White Papers E-mail Alert
-
TOP STORIES
ADDITIONAL RESOURCES

- Virtual Machines: Sun's xVM Virtualization Portfolio
- Migrating to Vista
- Turning Information Into A Competitive Advantage

- Speeding Business Innovation with Data Center Transformation
- Security and Trust: The Backbone of Doing Business over the Internet
- Forrester Data Center Automation
- World Tech Update, November 14, 2008
-
This week's wrapup of tech news includes CEA's CES preview, MP3 players ...
more
- [+] Watch the Video
- InfoClipz: Unified Communications
-
The concept "presence" and an impending flood of new voice/data applications...
more
- [+] Watch the Video











