{"repo":"beerisgood/macOS_Hardening","free":true,"listed":false,"github":"https://github.com/beerisgood/macOS_Hardening","clone":"git clone https://github.com/beerisgood/macOS_Hardening.git","description":"a collection about macOS","language":null,"stars":185,"topics":["macos","security","apple","hardening","privacy","arm","mac"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"🍏 macOS Hardening Guide Secure your macOS system with this comprehensive hardening guide. Ideal for users who value privacy , security , and performance . --- 📚 Table of Contents (click to expand) - 🖥️ Device Recommendations - 🛠️ Preparation - ⚙️ System Settings - 🧑‍🤝‍🧑 Users & Groups - 🌐 Network and Firewall - 🛡️ Secure Browsing - 🧰 Software - 📋 General Tips - 💪 Advanced users/special use case - 📚 Resources 🖥️ Device Recommendations - Mac with Apple Silicon Chip (M1 or newer) because of it's secure ARM architecture. - Newer chips , starting with M2 have better security features like Secure Page Table Monitor (SPTM) & Trusted Execution Monitor (TXM). - M4 adds the Secure Exclave. So it's best to stick with the most recent ones . - Older devices (with T2 or T1 chips) are no longer recommended because they are vulnerable to checkm8, Passware Kit Forensic T2 Add-on, and lack some hardware security features. 🛠️ Preparation - create/ use an iCloud.com email address for your Apple-ID at first start. - Check for updates and enable automatic updates for all options. - Keep a record of the settings you modify. ⚙️ System Settings - Enable FileVault (Full Disk Encryption) and backup the recovery key. You can check for an recovery key and verify if your saved key is valid. - (Encrypted) disk images can be created for sensitive files . The integrity of these images can be verified with checksums. - Also encrypt external media. - Set Gatekeeper to \"App Store and identified d","default_branch":null,"files":null,"tree":[],"storefront":"/r/beerisgood","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/beerisgood/macOS_Hardening/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}