Got a tip for us?

Do You Need More Security Than Apple’s Defaults?

In a TidBITS article, Evaluating Wireless Security Needs: The Three L’s, Adam Engst laid out the three factors he considered relevant to determining one’s risk when it comes to Wi-Fi security. He called them the three L’s: likelihood (the probability that someone will violate your security), liability (the cost—financial or otherwise—that you’d incur if a security breach happened), and lost opportunity (what you lose in terms of time and convenience by implementing stronger security). That article is still well worth a read almost two decades later.

Times, technologies, and threats change, but some people still face greater risks than others. If you can assess your own level of risk soberly, you’ll be able to take appropriate measures—neither too weak nor too strong.

The risk for most people

Years ago, it made more sense for nearly all Mac owners to consider their susceptibility to outside attack: how likely were you to visit sketchy sites, download applications that might contain Trojan horses, be infected by malware by visiting a site or running software, or even configure a network sharing setting that allowed people on the internet to scan and find weaknesses they could use to potentially copy data from your Mac, or worse. iPhone and then iPad users had fewer risks because of how iOS and iPadOS were constructed and locked down, but external attacks remained the central problem for them.

That profile changed considerably by the late 2010s. The biggest risk that most Apple users have faced since then—no matter their specific Apple hardware—comes from phishing and social engineering.

Phishing describes when someone impersonates a person, group, or website in the hopes you will click through and be infected by malware or enter login credentials. Phishers want your personal data, preferably financial information, such as your credit card number, expiration date, and verification code. They try to offer credible-looking security warnings and fraudulent webpages where you enter payment information or credentials they can use to access your bank and other accounts.

Social engineering is when people attempt to convince you to do something harmful to your device—and compromise your security and privacy. A common scam is that you visit a website and are redirected to another site (via malicious advertising or injected code) that claims your computer, phone, or tablet is infected and urges you to call a number. Calling that number leads you to a boiler room in which the other parties try to get you to install remote access software and sign up for expensive, hard-to-cancel tech services—or worse.

There are also more general attackers, who want to fool you into installing Mac apps that appear to be legitimate, but actually encrypt your personal files and hold them for ransom (ransomware). iOS and iPadOS don’t allow this vector because of how apps are installed and files managed. And even after over a decade into what remains rampant use of ransomware, that scourge hasn’t found a foothold on Mac.

From the mid-2020s, I would also argue that governments of democracies have increasingly chosen to enact laws or stretch the limits of existing ones to intrude into our private spaces, including accessing data that they would never previously have considered due to pushback from both ends of the political spectrum and, in some countries, a strong libertarian philosophy on the primacy of privacy.

Even if you don’t believe you fit in a category where the government of the place you reside would target you personally, you should assume your risk is elevated in any country that is sweeping away previous protections in the vague interests of “protecting children” even when no children are involved and “national security” when no national security interests are shown.

The high value of privacy violations

Some unwanted software doesn’t mess up a device or steal data, but installs adware that can display rogue ads (overlaying ones served by webpages), hijack web searches, and redirect affiliate clicks through portals controlled by the operators to make money illegitimately off you from advertisers. Other software is more insidious, tracking your location to sell it to companies that target you with ads—it’s a kind of malware, even if it doesn’t subvert the device.

The most obvious vector is a Mac, where you can install third-party software that isn’t vetted by Apple. But given that you can install extensions in Safari for the iPhone, iPad, or Mac, and that Apple has routinely failed to catch App Store apps that violate user privacy or include adware components, you can be at risk on any platform. Fortunately, so far, I have heard of no iPhone or iPad examples.

To step up protections, you can engage any or all of the following security or software integrity steps that reduce the area of attack on you that could succeed:

  • Two-factor authentication (2FA): This extra step for logging in deters attackers who have phished or otherwise obtained your password. Apple requires 2FA for Apple Accounts (with a few legacy exceptions), limiting access to iCloud-synced information, purchases, email, and much more. Most non-Apple services offer code-based 2FA (sent via SMS) or other ways to validate a password login. To compromise your account, someone has to obtain your SMS messages, your trusted devices, or your authentication app.

Some phishers perform a “two-step” attack in which they convince you not only to enter your account name and password on a site, but then also relay that information in real time to the actual site you intended to access. This causes the real site to send you a confirmation code (or the fake site requests that you generate one). The attackers capture that code when you enter it. However, that scam works only for brief periods, as short as one minute.

  • Passkey: Upgrade accounts at websites that support passkeys, a secure method of logging in that’s deeply embedded on iPhones, iPads, and Macs, and supported by Google and Microsoft. The secret part of a passkey is never transmitted over the internet, and a passkey is phishing-resistant. You can sync and share passkeys when using recent operating systems and password managers. I’ve shifted from tolerating passkeys to preferring them to a password-and-second-factor combo. See where Apple stores your passwords and passkeys.

Sounds great, right? But passkeys are, in every case I’m aware of, a supplemented to two-factor-protected accounts, not a replacement. Until you can make a passkey replace a regular login (with some kind of recovery option), they’re only as secure as the next-weakest link in the chain.

  • Hardware security key: Another form of 2FA, a relative of a passkey, is a hardware security key. These small physical objects plug into a USB or Lightning port or can connect via NFC to iPhones or iPads. The hardware key has embedded encryption circuitry that generates a unique, highly secure login key for each site you use it with. These keys are built on a standard nearly identical to the technology underlying passkeys, and most websites that support passkeys can accept a hardware security key and vice versa. (These keys also rarely fully replace access to an account yet, meaning a flaw in password and two-factor authentication could compromise access.)
  • Apple Pay: Avoid sites that don’t let you pay by Apple Pay, which prevents your credit-card number from being transmitted directly.
  • Install financial apps: Financial apps and their associated notifications make it more likely you will know immediately if any part of your financial life has been manipulated without permission. I’ve noticed a trend since 2024 for financial apps that support Face ID or Touch ID to let you log in from a desktop browser using a QR code or a push notification from the app. You then verify via biometrics, so you’re never entering any credentials in a browser.

Apple already blocks the direct installation of unsigned software on a Mac—apps that were released by people without an Apple Developer account or who bypassed Apple’s minimally involved signing system. By not allowing the easy installation of unsigned software, Apple prevents most malicious software from running at all. See how Gatekeeper decides which Mac apps can run.

  • Continuous backups: The technology for making constant, secure online backups of documents and creating local clones and backups obviates risks more present now than in the past when those options were slow, expensive, or not feasible due to cost or bandwidth limitations. Having such backups in place gives you a point to revert to if you have data corruption or loss.
  • End-to-end encryption (E2EE) for iCloud: Apple’s Advanced Data Protection lets iCloud users put media, notes, reminders, and iCloud Drive files under the gold standard of end-to-end encryption, which requires possession of a device and the means to unlock to access data. Because we may store details that can be used to exploit us in these various kinds of media, E2EE is another leg up on attackers. See how to turn on Advanced Data Protection.

By using Apple and industry technologies and safeguards and keeping backups current, you can dramatically reduce your likelihood of risks while also curtailing the liability that results. Even if you’re infected by ransomware—an unlikely event—and don’t want to pay, you might lose no files by reverting to a snapshot before the attack; or if someone guesses or obtains an account login, you’re alerted as they try to log in, so you can change the password, or they’re blocked entirely without a second factor or hardware element.

The change in our general risk profile over time, however, comes with one big flashing red light. I noted a couple of times above that most people only need to take certain default strong, reasonable measures. However, if you’re someone in particular fields of work or who engages in political advocacy, you may face targeted attacks that evade basic measures that suffice for everyone else.

A human-rights reformer in an incipient dictatorship needs to take more safeguards than a suburban online shopper in Ohio. But identity theft can sometimes lift that Ohioan—or you—into a much higher category of risk, because someone decides your assets or information are valuable to them, and they’ve acquired credentials or personal information that will let them attempt to crack your security shell.

What about children?

If your minor child has their own iPhone, iPad, or Mac, you might assume they are at very low risk. After all, their device probably contains nothing but games, educational software, a school-provided office suite, and a browser playing videos from Disney+.

But no! Sad to say, children are at greater risk than adults, all else being equal, because they’re less experienced and more trusting—and because, let’s face it, there are a lot of creeps out there who stalk children online.

If you travel to a country with severe laws or a propensity to jail people without legitimate charges, you should raise your risk profile before you travel and while there.