Focus on Apple
several news stories on Macs being zombies Jan 08 2007 04:03AM
kevhoy (kevhoy gmail com) (2 replies)
RE: several news stories on Macs being zombies Jan 08 2007 05:39PM
Spransy, Derek (DSPRANS emory edu) (1 replies)
Re: several news stories on Macs being zombies Jan 08 2007 06:58PM
gjgowey tmo blackberry net (3 replies)
Re: several news stories on Macs being zombies Jan 16 2007 07:32PM
David Fedoruk (david fedoruk gmail com) (2 replies)
Re: several news stories on Macs being zombies Jan 18 2007 03:23PM
Jeremy Reichman (jjracc rit edu) (1 replies)
Re: several news stories on Macs being zombies Jan 18 2007 03:34PM
Dave Schroeder (das doit wisc edu) (1 replies)
Re: several news stories on Macs being zombies Jan 18 2007 03:48PM
Jeremy Reichman (jjracc rit edu) (1 replies)
Re: several news stories on Macs being zombies Jan 18 2007 03:55PM
Philip Rinehart (philip rinehart yale edu) (1 replies)
Re: several news stories on Macs being zombies Jan 18 2007 04:05PM
Dave Schroeder (das doit wisc edu) (1 replies)
Re: several news stories on Macs being zombies Jan 18 2007 04:50PM
Jeremy Reichman (jjracc rit edu)
On 1/18/07 11:05 AM, "Dave Schroeder" <das (at) doit.wisc (dot) edu [email concealed]> wrote:

> Of course, Apple's answer would be to use managed client or OD and
> enforce password policy.
>
> Um, not going to work. Probably a good 90% of the over ten thousand
> Mac OS X machines on this campus will NEVER be "managed", in that sense.
>
> Mac OS X should be actively denying clear attacks (e.g., via the
> firewall), provide an interface to see and manage this functionality,
> and come with much stronger default configurations for services like
> ssh.
>
> We try to protect desktop environments with network level managed and
> delegated firewall controls and other practices (given how
> decentralized we are, IT-wise, the network is pretty much the ONLY
> thing central IT controls), but layered security is always the best
> model anyway. The host-based security could definitely be beefed up
> on Mac OS X from a network/external perspective, to say nothing about
> the general security of pieces of the OS from a desktop usage
> perspective.

I think that ultimately, if more policies are part of the MCX management
schema, the more beneficial it will be to run MCX in whatever directory
service is used. That should translate into more push to deploy directories
and use MCX.

I have a host of individual feature requests for policies I'd like to see
managed at the directory level, and which could also obviate the need for
sys admin scripting and/or management of config files:

* sshd_config
* Default AirPort networks
* 802.1X
* Certificates
* Password policies on local users, and all admin users
* /etc/authorization rights
* Keychain policies, and equivalent to pwpolicy for its passphrases
* New Password Assistant profiles

Some others that might be useful and help with security policy enforcement:

* Screen saver (authentication lock)
* FileVault
* sudoers
* Sharing services
* Firewall rules
* /etc/hostconfig
* Network Locations
* Launchd tasks

--
Jeremy

[ reply ]
Re: several news stories on Macs being zombies Jan 17 2007 02:02AM
david (macosxforme gmail com) (1 replies)
RE: several news stories on Macs being zombies Jan 18 2007 03:16PM
Todd Woodward (todd_woodward symantec com) (1 replies)
Re: several news stories on Macs being zombies Jan 18 2007 03:32PM
Dave Schroeder (das doit wisc edu) (1 replies)
Re: several news stories on Macs being zombies Jan 18 2007 03:52PM
Dave Schroeder (das doit wisc edu)
Re: several news stories on Macs being zombies Jan 09 2007 06:57AM
Nerijus Krukauskas (nkrukauskas gmail com)
RE: several news stories on Macs being zombies Jan 09 2007 02:56AM
Spransy, Derek (DSPRANS emory edu) (1 replies)
Re: several news stories on Macs being zombies Jan 09 2007 02:50PM
david (macosxforme gmail com) (1 replies)
Re: several news stories on Macs being zombies Jan 09 2007 07:40PM
gjgowey tmo blackberry net
Re: several news stories on Macs being zombies Jan 08 2007 04:57PM
Dave Schroeder (das doit wisc edu)


 

Privacy Statement
Copyright 2010, SecurityFocus