Got a tip for us?

macOS

macOS has many privacy and security settings that can be turned off or tuned, reflecting in part how you interact with a computer versus a mobile device. Let’s start with System Settings > Privacy & Security, which collects several controls and options. I also mention settings in Users & Groups, and Lock Screen, and in the Keychain Access utility, that deserve a quick look.

There is more on FileVault separately.

Unlock the pane or setting

Apple requires you to prove your identity when accessing more sensitive elements of System Settings. First, click a setting, like changing “Allow applications from” to App Store. Now:

  • Touch ID: If you have Touch ID, you’re prompted for biometric authentication. You can also click Use Password to enter your account password, then click Unlock.
  • No Touch ID: You’re prompted to type in the administrator password. Enter it and click Unlock.

Some settings, such as Users & Groups, prompt for your administrator password even when Touch ID is enabled.

With an Apple Watch, you can also unlock many settings by using a side button double-press. Go to System Settings > Touch ID & Password and enable your Apple Watch under “Use Apple Watch to unlock your applications and your Mac.”

That option also lets your Apple Watch unlock your Mac’s screen, as described below.

Require an unlock for all preferences

You can force yourself or users of the Mac to have to unlock all preferences before using them. Click the Advanced button in Privacy & Security, and then select or enable “Require an administrator password to access system-wide preferences.” Items like Sharing settings can otherwise be used without an administrator password.

Settings > Touch ID & Password and System Settings > Lock Screen offer two additional password-related features worth examining.

Adjust password preferences

In Touch ID & Password, the top of the setting says “A login password has been set for this user” if you set one. Click Change to update it.

You should always have a password set for your Mac, even if you’re the only person in your house, because a password to access your computer is a fundamental building block of security. If someone accesses your computer without your permission or steals your computer, you want at minimum this level of protection.

Once you change your password, you can’t use the old one again. While that might seem obvious, Apple added a grace period starting in iOS 17/iPadOS 17: change the passcode on an iPhone or iPad and you can still use the old one for 72 hours. Apple never added this to macOS, possibly for unknown security reasons.

In Settings > Lock Screen, select Immediately from the “Require password after screen saver begins or display is turned off” to, you know, do what it says on the label: force your Mac to lock when it goes to sleep, or when the screen saver activates and a period of time passes. You can also set it to wait for durations from 5 seconds to 8 hours.

How to sleep or lock your Mac

Apple offers lots of ways to let or force your Mac to go to sleep or initiate its screen saver. Here are several:

  • Turn display off on…when inactive: In Settings > Lock Screen, you can set “Turn display off on [battery, power adapter] when inactive” to durations from 1 minute to 3 hours or Never. “Battery” and “power adapter” appear separately on laptops; only “power adapter” appears on desktops.
  • Screen saver: Go to System Settings > Wallpaper, click Screen Saver, and use the “Start Screen Saver” pop-up menu. Choose a duration greater than Never for how long your Mac must be idle before the screen saver activates.
  • Lock screen menu: Choose Apple menu > Lock Screen, and either the lock screen appears or the screen saver, depending on your settings. You can also press ⌘-Control-Q.
  • Hot corner: Assign Lock Screen or Start Screen Saver to an action in System Settings > Desktop & Dock > Hot Corners. Each corner may have a different action assigned from a diverse list.

When you return, you can enter the password; or, on Macs with built-in or keyboard-based Touch ID enabled, unlock with Touch ID. See how to set up Touch ID and Face ID.

Touch ID may be disabled in certain circumstances for added security. See when biometric lockout happens.

You can choose Never, but I’d suggest…never doing this. Nearly everyone should pick Immediately or a short time duration—otherwise, every time you walk away from an active Mac, anyone with physical access can jiggle the mouse or touch the trackpad and access your stuff.

You can crank that up a notch if you’re at higher risk of physical access or theft: click the Advanced button in Privacy & Security, select “Log out automatically after inactivity,” and enter a duration in minutes. The Mac logs you out of your account after that period passes, raising the bar for a physical break-in. While the lock screen should be sufficient, background apps and other settings are in effect that could make your machine slightly more at risk than if it’s in a logged-out state.

If you have an Apple Watch, an iPhone, and a Mac signed in to the same iCloud account, you will have an additional option in System Settings > Touch ID & Password: “Use your Apple Watch to unlock your applications and your Mac.” Any Apple Watch that meets the preceding criteria appears in a list, each with its own switch. Enable one (or more) if you want your Mac to be automatically unlocked when it’s locked, you’re close by, and you’re wearing your watch. This setting also lets you unlock apps that require Touch ID via your Apple Watch, including the Apple Passwords app, and some system features.

Just tap the keyboard, keypad, or mouse as if you were jostling it to get it to show you a password dialog or a Touch ID prompt, and the Apple Watch and Mac have a conversation. Bluetooth and Wi-Fi must be enabled on the Mac for it to work.

Conversely, you might find unlocking your Mac with an Apple Watch is a security risk if you are subject to targeted attacks by a government or individuals.

Optionally, you can have a message appear on a lock screen. In Settings > Lock Screen, enable “Show message when locked,” click the Set button, enter a message, and click OK. This message can be useful if other people use the same Mac and you want to alert them as to why it’s idle.

I have my Mac in a day-lit basement office. Sometimes, I’ll be walking across our main floor, and my Apple Watch lights up that the Mac was unlocked a floor below!

Control what can be plugged in

Apple has options that can prevent peripherals, computers, and other accessories from connecting over built-in ports, like USB (Type-A and USB-C), Lightning, and SD Card, depending on your device. You can prevent peripherals from connecting via Lightning, Thunderbolt/USB, or the Smart Connector (for an iPad Smart Keyboard), or allowing a card to mount via the SD Card slot without permission.

Go to Settings/System Settings > Privacy & Security > Wired Accessories (iPhone/iPad)/Accessories (Mac). Modify the Allow Accessories to Connect setting. You have four options:

  • Always ask
  • Ask for new accessories
  • Automatically allow when unlocked
  • Always allow

In any case in which you have to grant permission, you must enter your administrator permission—Touch ID or Face ID, even when available, isn’t considered a high-enough bar.

Starting in macOS 26 Tahoe, you can also choose a security policy for accessories at startup. You can use this to prevent peripherals other than drives from interacting with the system before a macOS session has started.

First, restart into recovery mode; see how macOS protects its own system files. Next, choose Utilities > Startup Security Utility. Now, choose an option as above from the “Allow accessories to connect” menu.

Find My lets you mark items as lost to help recover items you can’t find or that might be stolen. Marking something as lost puts the hardware into a special Lost Mode and lets you provide details to someone who finds it—or even to a thief you want to encourage to return it.

Apple labels the feature as Lost Device Type on the Find My sheet and Mark As Lost in macOS 26 and earlier when you Control-click/right-click a device in Find My for Mac’s device list. However, the option to turn the feature on is labeled Lost Mode.

This information is available differently (or not at all) based on the kind of thing that’s marked as lost:

  • Devices: For devices, you can enter text (such as offering a reward) and provide your phone number. Both appear on the device.
  • AirTags and other items: With a Find My item—like AirTags or a Pebblebee Card—you can provide your phone number or email address; Apple prefills the message “This item has been lost. Please call me.” This information appears on a webpage associated with the device, which a finder can retrieve as described in how to identify an AirTag you have found.
  • Audio hardware without a screen: AirPods (3rd generation), AirPods 4 with Active Noise Cancellation, AirPods Pro, and AirPods Max can provide contact info just as with a Find My item. (The 1st- and 2nd-generation AirPods, AirPods 4 without ANC, and Beats models that support the Find My network can’t be marked as lost.)

Because devices have screens, marking a device as lost puts the finder on notice that you know approximately where it is—they can see that from the lock screen. If your hardware is stolen, this is a way to tell a thief that you have their location and advise them to give it up.

With supported Apple audio hardware or a Find My item, it’s trickier, as a finder has to take additional steps to determine its status rather than looking at a screen or receiving an alert—although they will hear an item make a sound or sounds in certain circumstances: see what an “AirTag Found Moving With You” alert means for those cases.

Mark a device as lost

When a device is marked as lost, it is locked and can be unlocked only with a device passcode (iPhone, iPad, or Apple Watch) or an Apple Account password or a macOS account password (Mac). Apple Pay is disabled, and all associated cards are temporarily suspended.

Even though Apple audio hardware that can be marked as lost appears in the Devices list, the options for a lost set of earbuds or headphones are the same as a lost item, described later in this chapter.

In case you’re thinking of testing this on your Mac, be aware that your computer restarts instantly after you confirm Lost Mode. You might lose unsaved work in progress.

  1. Tap or click Lost Mode beneath Lost Device Type.
  2. Apple explains what will happen to the device in a screen labeled Lost Mode (iPhone, iPad, or Apple Watch), or “Lock this Mac?” Tap or click Continue to proceed or Cancel to back out.
  3. Enter a passcode if prompted and verify it. (This is unlikely, but it may happen. Make a note of the passcode so you aren’t locked out.)
  4. On devices other than Macs or supported audio devices, optionally set a phone number for a call back. On an iPhone, a finder can call only that number. On other devices, the call-back number is displayed. Tap or click Next.
  5. Optionally, for devices that offer it, enter a message that will appear on the device. In this step, the dialog shows that a passcode has already been set and will be used to lock the device. Tap or click Next.
  6. On the final screen for anything but a Mac, you see a summary of actions and information:
    • Notify When Found: Enable if you want device-based notifications on all your linked hardware.
    • Text you entered: The text of the phone number and messages you entered, if any, appears, but you can’t modify it.
    • Receive Email Updates: This adds email to notifications as part of how you’re alerted.

Despite Apple’s explicit promise when locking a Mac that “This message will be shown on your Mac when someone turns it on,” I can confirm in Tahoe and Golden Gate, it is not. I don’t understand why Apple doesn’t show the message, and why they document it incorrectly.

Tap or click Enable or Activate for anything but a Mac, where you tap or click Continue or Lock.

After you activate Lost Mode, the action is passed to the device if it’s online, and an email message (if enabled) is sent to the address for the Apple Account for the device, confirming what you’ve done. Devices with batteries will be placed in low-power mode. On an iPhone, emergency service calls remain available. Credit and debit cards associated with Apple Pay are disabled on the device.

When a device is locked, it appears in the Devices view with its icon overlaid with a white question mark in an orange circle. A Mac additionally shows a gray screen.

If Location Services has been turned off by you or someone with access to your devices, Lost Mode overrides that and re-enables it so you can track your device.

Turn Lost Mode off again

  1. Select the device in the Find My app.
  2. Tap or click Turn Off Lost Mode, except on an Apple Watch, where you tap the Lost Mode button and disable Lost Mode.
  3. Find My prompts you with a warning that explains the device will remain locked, but the information you entered (phone number and message) and its location history will be deleted. Tap or click Turn Off to confirm.
  4. When you recover the device, enter its passcode or password.
  5. Then, you can disable Lost Mode: Enter your passcode.

Whether you use Find My or start directly from your iPhone, iPad, or Apple Watch, your device will prompt you to re-enter your Apple Account password once or twice. If you have separate iCloud and media Apple Accounts linked, read the dialog carefully so you enter the correct password for each.

To unlock a Mac, despite Apple promising you can do so via Find My or via iCloud.com/find, the truth in testing in Tahoe and Golden Gate is that you can only unlock your Mac while in front of it, going through a separate procedure.

What happens to Apple Pay

In some cases, you may be prompted for two-factor authentication to finish regaining access; in many recent tests, I was not, but I don’t know why. For accounts using code-based verification, you will have to use a trusted device other than the one you have in hand or a trusted phone number to validate your sign-in. With a hardware security key, it’s already independent and can simply be used if you’re prompted; you may be asked to use code-based verification, however. If you’re prompted a second time for your Apple Account password, no second factor appears to be required.

Mark as Lost immediately disables Apple’s side of Apple Pay for a lost device, which prevents even someone with your passcode from using Apple Pay. (When they use the passcode, this disables Lost Mode, but you would be notified.) You may see a flurry of “card deactivated” emails and texts from your credit card companies and banks as well as an email alert from Apple.

To re-enable your cards for Apple Pay, you will be in one of two states:

  • Wallet sync active: With Wallet enabled for syncing—Settings/System Settings > Account Name > iCloud > See All—when you re-enter your Apple Account password after unlocking the device, your cards are re-synced and activated. This may result in a similar flurry of “card reactivated” messages.
  • Wallet sync inactive: Without Wallet sync, your device deletes all locally stored card information when Lost Mode is activated. You have to manually re-enter cards that you want to use for Apple Pay on that device.

Do the same from iCloud.com

The iCloud web app for Find My iPhone diverges slightly from the Find My app, and mobile devices have a different process than Macs.

Lost Mode activates immediately when you click Activate at the last step — there are no extra options or final review stage.

Here’s how to proceed for an iPhone, iPad, iPod touch, Apple Watch, AirPods Pro, or AirPods Max:

  1. Select the device.
  2. On the sheet that appears, click Lost Device Type.
  3. Read the disclosure of what will happen when it’s locked and click Next to proceed.
  4. In the unlikely event the device doesn’t have a passcode set, you have to invent one and set it at this point.
  5. Enter a phone number that will be displayed (optional). Click Next.
  6. Enter a message that will be displayed (optional). Click Activate.

You can unlock these devices using the same methods as when they are locked in a native Find My app.

Lost Mode restarts a Mac immediately when you click Lock at the last step.

Macs are handled slightly differently; here are the alternative steps:

  1. Select the Mac.
  2. Click Lost Mac.
  3. Click Next after reading the disclosure.
  4. You have an option to enter a message before you click Lock.

The Mac is now locked and powers down. See how to unlock a Mac you locked with Find My for how this appears and your next steps.

Pause sharing without telling anyone

In the version 27 releases, Apple added a way to pause sharing your location with someone without removing them from your sharing-with list—and without them knowing. Here’s how to pause sharing:

  1. Select a person with whom you’re sharing your location.
  2. Tap or click the More button, and choose Hide Location.
  3. Find My explains that you stop sending your location for the remainder of the day.
  4. The other party is not notified when you pause, stop or resume sharing. They see only that no location was found.
  5. Tap or click Hide to continue, or Not Now to keep sharing.

The Location field shows “Unhide Location” until the shown time. When I chose to Hide Location at 2:30 p.m., it displayed “tomorrow at 4:00 a.m.” as the end point. If you tap or click Unhide Location, there’s no confirmation step: your location is immediately shared again.

This addition is clearly another tool in the kit for deterring unwanted tracking in abusive situations, where someone’s partner or family member demands they leave tracking on. This allows someone being tracked to go off the radar without it being obvious. For more, see how to check whether someone is tracking you.

Stop sharing altogether

You can completely stop sharing with someone, which removes you from their People list in Find My. They can’t prevent or reverse these. Stop sharing in either of these ways:

  • In the info pane in a Messages conversation, tap or click Stop Sharing My Location or Stop Sharing.
  • In a native Find My app (or Find People in watchOS 26), tap or click Stop Sharing My Location, Stop Sharing Location, or Stop Sharing.

If you stop sharing, the person remains in your list. You can remove their entry, as below.

You can remove someone from your People list and stop sharing with them or seeing their location. This requires a native Find My app. Here’s how to remove someone:

  • In the version 27 releases, select the People view, select a person, then tap or click the More button. Tap or click Remove and confirm.
  • In earlier releases, select the People view and select the person. On an iPhone or iPad, tap Remove and confirm. On a Mac, click the Info button, then click Remove and confirm.
  • On an iPhone or iPad, you can instead swipe left on a name in the People list and tap the Remove button (iOS 27/iPadOS 27) or Trash button (earlier releases).
  • On a Mac, click the People button and Control-click/right-click the person’s entry. In macOS 27, choose Remove Friend; in earlier versions, choose Remove Name. The person is removed immediately without additional prompting.

Ask someone else to share

You can use the Messages app to request that someone share their location with you. This is handy for a less sophisticated user who doesn’t know how to initiate sharing, or in situations where you want to message someone and ask them to share at the same time: they can read your message and then tap to share without going through additional hoops.

You can prevent receiving these requests by disabling Allow Friend Requests in a native Find My app on the Me tab or pane.

On an iPhone, iPad, or Mac running Tahoe or later, in any conversation in Messages, tap or click the avatar at the top of the view; on a Mac running Sequoia or earlier, click the Info button at the upper-right corner. Tap or click Request Location. This creates a request within Messages. Tap the Send button or press Return to transfer the request, and the other person can opt to Share and choose a duration.

There’s an alternative method on an iPhone or iPad in a conversation in Messages: Tap the Plus button, choose Location, tap Request, and tap the Send button.

If you’re already sharing your location with someone who isn’t with you, you can also use a native Find My app, view the person’s details, and tap or click Send Request.

If you’re on the accepting side of that equation, Messages now mediates your response. When you select a duration, this generates another message; you can click or tap the Send icon or press Return to transmit.

When you are asked to reciprocate

The Find My app shows an entry for each person actively sharing their location with you in the People view. For time-limited sharing, their pictures are overlaid with a little clock.

When you share your location with someone else or vice versa, Find My posts an alert, but the party being shared with doesn’t have to accept it; the sharing party is just added to their Find My list.

However, if that person (you or someone else) isn’t someone the recipient already shares their location with, Find My prompts for reciprocation. (That is, if you share to someone and they don’t, they will be prompted to share with you; if they share to you and you don’t, you’ll be prompted to share with them.)

You can choose to mirror a shared location via a notification. Tap or click the notification, then choose the duration. If you ignore or dismiss the notification, you can also use the Find My app, where the notification appears in the People list with the same message. Similarly, tap or click Don’t Share or tap or click Share to choose a duration from the pop-up menu.

You can’t reciprocate on an Apple Watch.

If the person doesn’t follow you, you can use the same methods in Request Sharing from Someone to ask again.

Where to get help

There are many organizations beyond law enforcement eager to help people trapped in situations of domestic abuse or child subject to violence and an unsafe environment. For adults in the United States, that includes the National Domestic Violence Hotline; for children or those concerned about their welfare in the United States and Canada, the Childhelp National Child Abuse Hotline.

For those being stalked, one starting point is Safehope. It’s more likely you will need the help of police or federal authorities. Local police departments have their own paths to navigate, but for online or cyber stalking, it may be better to start with the FBI.

If the person you are worried about may be watching your device, use one they cannot see. Removing a tracker or turning off sharing can be noticed, and advocates warn that it can make a situation worse rather than better, so it is worth talking to someone before you act.

With all that in mind, you might wonder: what should I open for use and what’s safe? The answer depends on whether your Mac has a public IP address. I advise always turning on only the services you need. A few are worthwhile, and how you configure them depends on your circumstances.

But you should have different considerations under these sets of circumstances:

  • Privately addressed Mac on a network in which all users are trusted: If you’re by yourself or you trust your roommate and family to not attempt to access things they shouldn’t, you can enable what you like and just configure for general safety.
  • Privately addressed Mac on a network in which not all users are trusted: If you share a network with other people—which could include kids or parents who may not be as safe or honest with you as you might like—consider locking things down further and using the fewest possible services.
  • Publicly addressed Mac: You need to take more care to set passwords and configure limitations, and to consider whether to leave services active all the time or only when you know you or someone you trust needs them.
  • High-risk individual or group: People who believe themselves at elevated risk shouldn’t operate any services on public addresses, and should think strongly about not running them even on privately addressed networks. It’s very easy for so-called Internet of Things (IoT) or “embedded devices” to be compromised. That can include DVRs, routers, smart home gear, and more. A subverted device on your local network can have the same access as anyone else on the network.

With that in mind, here are the items in System Settings > General > Sharing worth enabling or disabling. Configuration options appear when you click the info button next to a service.

Don’t allow all users

Several services let you selectively enable them. Apple offers a choice of “Allow access for” either “All users” or “Only these users” for most services. File Sharing has more fiddly options. I recommend setting access for Screen Sharing and any service starting with Remote to Administrators (often prefilled), or, better, selecting users or groups you’ve created. This limits exposure in the case of an intrusion that doesn’t gain direct access to your macOS account.

Screen Sharing

If you have a “headless” Mac (one without a monitor) that you use for various services, or machines in different parts of a house or office that you want to access remotely, screen sharing is handy.

I recommend deselecting two options in the Computer Settings dialog:

  • Anyone may request permission to control screen: There’s no reason to allow this except momentarily if you want to allow someone to request access.
  • VNC viewers may control screen with password: VNC is an outdated protocol that Apple’s screen-sharing technology extends with more security and features. There’s no good reason to keep this option turned on, particularly because VNC passwords are notoriously easy to crack.

File Sharing

The File Sharing service on a Mac offers fine-grained controls to choose which folders and volumes are accessible to which people, including the type of access: read/write, read-only, or write-only (to drop items into without seeing the shared item’s contents).

In configuring File Sharing, I recommend the following:

  • Disable Full Disk Access if multiple people have accounts with administrator access to the Mac, unless you explicitly want them all to have remote access to all files on the volume.
  • In the Shared Folders list, select items you don’t need shared and click the minus button.
  • In the Users list for each shared folder in turn, click the pop-up menu and choose No Access for users and groups that can’t be removed, then select the user or group and click the minus button to remove those that can.

What you’re left with is a limited, tightly controlled set of folders and volumes that only people you have approved can interact with.

I often create a sharing account that I set up for limited access. You can use the Guest account for this purpose, but I’d rather control it more directly by name. See also how to set up safe user accounts on a shared Mac.

Remote Login, Management and Apple Events

Apple offers powerful but somewhat obscure ways to access, manage, and use a Mac remotely:

  • Remote Login lets you connect via the SSH (secure shell) protocol, commonly used in Unix/Linux, as well as access file sharing with SFTP (Secure File Transfer Protocol), which is really “FTP using SSH.” It’s rarely needed except for particular purposes, such as if you need remote command-line access. If you do enable it, keep “Allow full disk access for remote users” turned off.
  • Remote Management connects with Apple Remote Desktop (ARD), a corporate and academic tool. If you’re not using ARD, don’t enable this service.
  • Remote Apple Events or Remote Application Scripting is a tweaky thing that lets an AppleScript running on one Mac send control events to another. It’s rare you need this, and you will know if so.

Reaching your Mac from outside

If you want to have access to Macs and other devices that are behind NATs or other network protections, I highly recommend Tailscale. The company’s core product lets you create an account, install software on nearly any device, and then have those devices create VPN tunnels to a pooled central network space. This is a profoundly straightforward way to use File Sharing and Screen Sharing when away from your home network. You can install Tailscale on an Apple TV and then set it up to provide access to the entire network it’s on, too!

Tailscale offers a non-commercial account that fits most people’s personal needs.

In a TidBITS article, Evaluating Wireless Security Needs: The Three L’s, Adam Engst laid out the three factors he considered relevant to determining one’s risk when it comes to Wi-Fi security. He called them the three L’s: likelihood (the probability that someone will violate your security), liability (the cost—financial or otherwise—that you’d incur if a security breach happened), and lost opportunity (what you lose in terms of time and convenience by implementing stronger security). That article is still well worth a read almost two decades later.

Times, technologies, and threats change, but some people still face greater risks than others. If you can assess your own level of risk soberly, you’ll be able to take appropriate measures—neither too weak nor too strong.

The risk for most people

Years ago, it made more sense for nearly all Mac owners to consider their susceptibility to outside attack: how likely were you to visit sketchy sites, download applications that might contain Trojan horses, be infected by malware by visiting a site or running software, or even configure a network sharing setting that allowed people on the internet to scan and find weaknesses they could use to potentially copy data from your Mac, or worse. iPhone and then iPad users had fewer risks because of how iOS and iPadOS were constructed and locked down, but external attacks remained the central problem for them.

That profile changed considerably by the late 2010s. The biggest risk that most Apple users have faced since then—no matter their specific Apple hardware—comes from phishing and social engineering.

Phishing describes when someone impersonates a person, group, or website in the hopes you will click through and be infected by malware or enter login credentials. Phishers want your personal data, preferably financial information, such as your credit card number, expiration date, and verification code. They try to offer credible-looking security warnings and fraudulent webpages where you enter payment information or credentials they can use to access your bank and other accounts.

Social engineering is when people attempt to convince you to do something harmful to your device—and compromise your security and privacy. A common scam is that you visit a website and are redirected to another site (via malicious advertising or injected code) that claims your computer, phone, or tablet is infected and urges you to call a number. Calling that number leads you to a boiler room in which the other parties try to get you to install remote access software and sign up for expensive, hard-to-cancel tech services—or worse.

There are also more general attackers, who want to fool you into installing Mac apps that appear to be legitimate, but actually encrypt your personal files and hold them for ransom (ransomware). iOS and iPadOS don’t allow this vector because of how apps are installed and files managed. And even after over a decade into what remains rampant use of ransomware, that scourge hasn’t found a foothold on Mac.

From the mid-2020s, I would also argue that governments of democracies have increasingly chosen to enact laws or stretch the limits of existing ones to intrude into our private spaces, including accessing data that they would never previously have considered due to pushback from both ends of the political spectrum and, in some countries, a strong libertarian philosophy on the primacy of privacy.

Even if you don’t believe you fit in a category where the government of the place you reside would target you personally, you should assume your risk is elevated in any country that is sweeping away previous protections in the vague interests of “protecting children” even when no children are involved and “national security” when no national security interests are shown.

The high value of privacy violations

Some unwanted software doesn’t mess up a device or steal data, but installs adware that can display rogue ads (overlaying ones served by webpages), hijack web searches, and redirect affiliate clicks through portals controlled by the operators to make money illegitimately off you from advertisers. Other software is more insidious, tracking your location to sell it to companies that target you with ads—it’s a kind of malware, even if it doesn’t subvert the device.

The most obvious vector is a Mac, where you can install third-party software that isn’t vetted by Apple. But given that you can install extensions in Safari for the iPhone, iPad, or Mac, and that Apple has routinely failed to catch App Store apps that violate user privacy or include adware components, you can be at risk on any platform. Fortunately, so far, I have heard of no iPhone or iPad examples.

To step up protections, you can engage any or all of the following security or software integrity steps that reduce the area of attack on you that could succeed:

  • Two-factor authentication (2FA): This extra step for logging in deters attackers who have phished or otherwise obtained your password. Apple requires 2FA for Apple Accounts (with a few legacy exceptions), limiting access to iCloud-synced information, purchases, email, and much more. Most non-Apple services offer code-based 2FA (sent via SMS) or other ways to validate a password login. To compromise your account, someone has to obtain your SMS messages, your trusted devices, or your authentication app.

Some phishers perform a “two-step” attack in which they convince you not only to enter your account name and password on a site, but then also relay that information in real time to the actual site you intended to access. This causes the real site to send you a confirmation code (or the fake site requests that you generate one). The attackers capture that code when you enter it. However, that scam works only for brief periods, as short as one minute.

  • Passkey: Upgrade accounts at websites that support passkeys, a secure method of logging in that’s deeply embedded on iPhones, iPads, and Macs, and supported by Google and Microsoft. The secret part of a passkey is never transmitted over the internet, and a passkey is phishing-resistant. You can sync and share passkeys when using recent operating systems and password managers. I’ve shifted from tolerating passkeys to preferring them to a password-and-second-factor combo. See where Apple stores your passwords and passkeys.

Sounds great, right? But passkeys are, in every case I’m aware of, a supplemented to two-factor-protected accounts, not a replacement. Until you can make a passkey replace a regular login (with some kind of recovery option), they’re only as secure as the next-weakest link in the chain.

  • Hardware security key: Another form of 2FA, a relative of a passkey, is a hardware security key. These small physical objects plug into a USB or Lightning port or can connect via NFC to iPhones or iPads. The hardware key has embedded encryption circuitry that generates a unique, highly secure login key for each site you use it with. These keys are built on a standard nearly identical to the technology underlying passkeys, and most websites that support passkeys can accept a hardware security key and vice versa. (These keys also rarely fully replace access to an account yet, meaning a flaw in password and two-factor authentication could compromise access.)
  • Apple Pay: Avoid sites that don’t let you pay by Apple Pay, which prevents your credit-card number from being transmitted directly.
  • Install financial apps: Financial apps and their associated notifications make it more likely you will know immediately if any part of your financial life has been manipulated without permission. I’ve noticed a trend since 2024 for financial apps that support Face ID or Touch ID to let you log in from a desktop browser using a QR code or a push notification from the app. You then verify via biometrics, so you’re never entering any credentials in a browser.

Apple already blocks the direct installation of unsigned software on a Mac—apps that were released by people without an Apple Developer account or who bypassed Apple’s minimally involved signing system. By not allowing the easy installation of unsigned software, Apple prevents most malicious software from running at all. See how Gatekeeper decides which Mac apps can run.

  • Continuous backups: The technology for making constant, secure online backups of documents and creating local clones and backups obviates risks more present now than in the past when those options were slow, expensive, or not feasible due to cost or bandwidth limitations. Having such backups in place gives you a point to revert to if you have data corruption or loss.
  • End-to-end encryption (E2EE) for iCloud: Apple’s Advanced Data Protection lets iCloud users put media, notes, reminders, and iCloud Drive files under the gold standard of end-to-end encryption, which requires possession of a device and the means to unlock to access data. Because we may store details that can be used to exploit us in these various kinds of media, E2EE is another leg up on attackers. See how to turn on Advanced Data Protection.

By using Apple and industry technologies and safeguards and keeping backups current, you can dramatically reduce your likelihood of risks while also curtailing the liability that results. Even if you’re infected by ransomware—an unlikely event—and don’t want to pay, you might lose no files by reverting to a snapshot before the attack; or if someone guesses or obtains an account login, you’re alerted as they try to log in, so you can change the password, or they’re blocked entirely without a second factor or hardware element.

The change in our general risk profile over time, however, comes with one big flashing red light. I noted a couple of times above that most people only need to take certain default strong, reasonable measures. However, if you’re someone in particular fields of work or who engages in political advocacy, you may face targeted attacks that evade basic measures that suffice for everyone else.

A human-rights reformer in an incipient dictatorship needs to take more safeguards than a suburban online shopper in Ohio. But identity theft can sometimes lift that Ohioan—or you—into a much higher category of risk, because someone decides your assets or information are valuable to them, and they’ve acquired credentials or personal information that will let them attempt to crack your security shell.

What about children?

If your minor child has their own iPhone, iPad, or Mac, you might assume they are at very low risk. After all, their device probably contains nothing but games, educational software, a school-provided office suite, and a browser playing videos from Disney+.

But no! Sad to say, children are at greater risk than adults, all else being equal, because they’re less experienced and more trusting—and because, let’s face it, there are a lot of creeps out there who stalk children online.

If you travel to a country with severe laws or a propensity to jail people without legitimate charges, you should raise your risk profile before you travel and while there.

If you’re at higher risk, you should consider taking the most stringent measures available. Check the following criteria to see if they apply:

  • You work in the financial, legal, medical, or government sector: If you use Apple hardware for work, you are likely subject to regulatory requirements and have been briefed on them. (You might even have had to take a course on compliance!) You may be required to engage additional security, like using a VPN, blocking ports for USB/Thunderbolt and SD Cards (see the Mac settings worth changing), enabling FileVault on a Mac, and turning on Advanced Data Protection in iCloud. You may also need to enable hardware security keys for your Apple Account. If you don’t take these steps, and it’s discovered, your devices are lost or data intercepted, or online accounts are compromised, you could be sanctioned, fired, fined, or even charged with a crime, depending on the employer and locality.
  • Your device contains unusually sensitive data: This could be old love letters you don’t want your partner to see, confidential business information from your employer (even if they’re not in the financial, legal, etc., categories above), records of a delicate medical condition, or anything else that could cause you serious problems (like loss of your job, insurance, or marriage) if it were to get out.
  • You’re famous: Congratulations! You already know the price of this on social media and when dining, traveling, or walking around, depending on how well-known you are. But you’re also more of a target online, because of the obsession so many sites and people have with secrets about people who are seen to be famous.
  • You’re a journalist: Sadly, reporters are frequently targeted by criminals, people they’re writing about, and governments. For instance, Ronan Farrow reported that Harvey Weinstein hired an Israel-based private-intelligence firm to dig up dirt on him while he was researching his watershed story on Weinstein’s history of alleged and proven sexual crimes.
  • Wealthy in real terms or cryptocurrency: People with more than a little money are regular targets, especially if they have significant Bitcoin or other cryptocurrency holdings. Having an expensive house doesn’t mean much in the current real-estate market; it’s more likely that you have elevated risk if there’s coverage or securities filings that disclose your wealth, stock grants, or other assets.
  • Rough travel: You frequent any of the internet’s seedier neighborhoods, such as sites that traffic in online gambling, porn, or pirated content (like software, television shows, or movies).
  • Secret or pseudonymous identity: You have an online identity, separate from your real-life identity, that you need to keep private. A number of times in recent years, someone whose job or political position has prevented them from having a public persona have been outed for writing under another, typically fictitious name.
  • Heated online interactions: You engage in controversial discussions that might result in people being exceptionally angry with you.
  • Careless co-users (Mac): Specific to a Mac, you share it with less-sophisticated family members who may not be as careful as you would be about downloading files from unknown sites, clicking links in email messages, and using good passwords. While you can set them up with their own macOS accounts—you should!—some of their actions can affect the entire Mac and your online accounts.
  • People in particular professions and of genders other than male: It’s a sad fact of modern life that being a responsible journalist, being an advocate for vulnerable people, believing the Earth is round and evolution legitimately established in the fossil record, or having the temerity to be a gender that someone else has chosen to be angry about online can cause reactionary individuals and groups to target you.
  • You live in a country that has reduced privacy protections: Various countries have fought with Apple over allowing back-door access to iCloud data. The United States asserts the right to login to examine incoming tourists’ and students’ social media and other accounts. Many countries now think that any checkpoint, traffic stop, or other incidental encounter gives them carte blanche to demand all your data.

Now for the good news! A decade ago, my advice to you would have likely been far more extensive and stringent than for the average user. These days, however, Apple’s and other companies’ baseline security is more accessible, easier to use, and more effective.

My general advice is to do everything suggested here as the baseline, and build a bit from there.

Take a hard look at Lockdown Mode

Some people are pinpoint targeted by spyware, software that can hijack their devices, often without a single click, using previously unknown exploits. These attacks are worth a lot of money and thus typically deployed in a targeted fashion by governments and criminal syndicates against journalists, members of minority groups in a given country, human-rights activists, and opposition politicians.

To help counter these kinds of intrusions, Apple offers a Lockdown Mode you can invoke that highly restricts many forms of inbound messages and traffic. For the full rundown, see how to turn on Lockdown Mode and who needs it.

If you fall into the above categories, your biggest risks will come from how your Mac is set up, rather than your iPhone or iPad. Here’s how you could improve your Mac security:

  • Upgrade your Mac to Golden Gate: Golden Gate supports all Apple silicon Macs. A few older Intel models can upgrade to the previous release, macOS 26 Tahoe, which you should do. If you can’t run Tahoe or Golden Gate, you’re not getting the latest and best security. Consider upgrading your Mac if that’s important to you. (See which Macs can run it.)
  • Allow FileVault: Apple enables FileVault by default when you upgrade to macOS 26 or 27 and on new computers running it. Leave it on (see FileVault). Also, power down your Mac whenever it’s not in use; never leave it idle and running for more than a brief period. (A FileVault-like feature is part of iOS/iPadOS and cannot be disabled or configured.)
  • Block device and card insertion: Thunderbolt and USB devices and SD Cards plugged into your Mac can be blocked from interacting with the operating system without authentication. See the Mac settings worth changing.
  • Never make local, unencrypted copies of your data: All local copies should be on encrypted volumes that are unmounted after backup or shutdown when you regularly shut your Mac down; all hosted backups, if any, should only be with firms that offer strong, user-owned encryption. Time Machine lets you set up backups on an encrypted drive or add an encryption key for networked backups. All online backup services worth considering put the encryption key for your archived data solely in your hands.

Apple keeps upping the ante on how it makes sure that macOS’s core files—all the bits and pieces in the operating system that allows apps to run—aren’t messed about with.

What if Apple could prevent system files from being modified at all by placing them on a read-only disk, effectively blocking changes to those files at nearly the lowest level?

That was a hard task, given that system files and user data files co-existed on the same startup volume. But, hmm, wait a tick! What if you could split system files into one volume and data files into another, but have them appear seamless as a single “drive” in macOS? The system volume would be read-only; the data volume could be read/write, but would also have all the sandboxing protections already in place.

That’s exactly what Apple did starting with Catalina. Apple’s modern filesystem, APFS (Apple File System), among other improvements, added the concept of breaking a drive into containers instead of partitions. (Partitions can still be used, but there’s no advantage.)

In the long-used previous filesystem, Mac OS Extended (sometimes called HFS+), a drive was broken into partitions, and each partition could be mounted as a volume. One volume was much like another.

In APFS, a drive is broken into containers, which are like partitions in occupying a preset portion of the disk’s full capacity. Each container can contain one or more volumes, and each volume can have a role. A role defines the kind of data stored on it. Roles include data (for regular mountable data volumes), system (for system files starting in Catalina), and backup (for Time Machine backups starting in Big Sur).

Roles also include obscure and/or invisible system requirements, too: Preboot, Recovery, and VM (virtual memory).

Catalina’s system role also added another variation on containers and volumes, called a volume group. A volume group is two or more interrelated volumes that present as a single entity to the Finder and user. Behind the scenes, however, multiple volumes are managed by the system.

The reason for this was to take a previous system integrity concept to yet another level: all system files are on one volume in the startup volume group; all user data is on another volume.

Big Sur went even further. It doesn’t even mount the system volume. Instead, it uses a “snapshot” feature of APFS that allows the filesystem to capture a particular point in time. Starting in Big Sur, a snapshot of the system volume is loaded that can’t be changed, because it has no writable components—it’s like looking at a picture. In Disk Utility the system is marked as an APFS Startup Snapshot with a unique name, while the main system volume is dimmed.

On top of that, each file on a Big Sur or later system volume has a separate cryptographically generated hash that’s stored in the volume’s metadata. Whenever a file is read from the system volume, that same crypto operation is performed, and the resulting hash of the loaded file checked against the one that’s stored—any modification, however unlikely it could be to occur at all, would be immediately spotted. That’s why this approach is called a Signed System Volume. The metadata and other volume attributes are hashed and collected in something called the seal, which is verified at boot time. If the seal can’t be verified, you’re prompted to reinstall macOS.

Monterey kept the same structure, but added the capability for Apple silicon Macs to install multiple versions of macOS on a single drive. With Big Sur, an Apple silicon Mac could only have a single system because of some low-level decisions about how the Mac decided whether a system could validly start up. With Monterey, you can create additional partitions and install unique copies of macOS into each partition. (From Ventura onward, Apple doesn’t seem to have made substantial changes—or at least I couldn’t find any to report on.)

Only some people need to have multiple versions of macOS on a bootable drive, such as those who need to keep older versions of macOS running for testing or compatibility.

With Apple silicon Macs, Apple also has what’s called hardware-based memory protection. Hackers often use a system or app exploit to overflow an area reserved for pure data into an area that contains executable program code. This lets them insert malicious code that is run in place of legitimate code. Memory protection in Apple silicon processors marks memory areas as either full of executable code or full of data, but not both. In that scenario, a hacker cannot write malicious code into an area that can be executed; nor can they execute code that’s in a place only inert data is stored. An app can change the state of memory areas explicitly, and that’s a place that hackers will certainly aim for. But it’s much higher-hanging fruit.

System integrity and locked apps

Because the system volume is immutable, Apple can place only certain of its apps on that volume: ones that don’t require regular updates. These apps can be refreshed as part of a system update, as a Catalina or later system update has the rights to make changes to the system volume, including those apps.

The list of system-locked apps is reasonably long. You can find them in /System/Applications. A few examples among many are App Store, FaceTime, Mail, Photos, Preview, and Siri.

System volume apps appear within the Applications folder intermingled with Data volume apps. This is part of the seamless integration of volumes in a volume group used for macOS. You can check on the system/Data location of any app by selecting it and choosing File > Get Info. The path shows drive name > System > Applications for system volume apps, and drive name > Applications for ones installed on the Data volume.

Interestingly, Safari is not on the system volume. Apparently, it’s updated regularly enough and sometimes with significant fixes that Apple has kept it out of that fixed side of things.

In a similar but distinct bit of processor-based protection, after macOS loads on a Mac with Apple silicon, the memory its central components occupy—its kernel—is locked using “kernel integrity protection,” so they cannot be modified while macOS is running.

Do you feel safe now? You should to the extent that it’s feasible that Apple has taken every modern and many inventive measures to render the system immutable.

How to restart in recovery mode

Apple installs a special recovery volume as part of a macOS installation that you can restart from to perform actions on your Mac’s system without macOS itself running. This volume is invisible to you in your normal use of macOS.

On an Apple silicon Mac, choose Apple menu > Shut Down. When your Mac has powered down, hold down the power button; you first see a message that says “Continue holding for startup options.” Keep holding until you see the next prompt, which says “Loading startup options.” Click Options, choose an account, click Next, enter its password, and click Continue.

Apple changed the name for this form of boot a few years ago. Recovery mode generically means a special way of booting any Apple device to repair or reinstall its operating system.

When you restart into recovery mode, Apple’s Platform Security Guide says you are booting into recoveryOS. The app that appears first on an Intel Mac or after clicking Options on an Apple silicon Mac is labeled Recovery on the system menu.

Furthermore, if you choose the Utilities menu, you can launch a special Recovery Assistant! The main screen there is labeled not Recovery Assistant, but simply Recovery—see below. If you lock your Mac via Find My and then unlock it, Recovery Assistant launches on restart, and while the app menu reads “Recovery Assistant,” the main title on the screen is “macOS Recovery.”

Startup protections

This wasn’t enough? Really? Really. There’s more. Apple has several methods of further preventing your Mac from being started up in a way you don’t want and to prevent after startup in ways you don’t want.

Share a disk

As part of enhanced protections on Apple silicon Macs, Apple eliminated a simpler option long used on Intel Macs. Follow these steps to share a volume, making it appear as a networked volume on the other Mac:

  1. Restart in recovery mode. (See How to Restart in Recovery Mode.)
  2. Choose Utilities > Share Disk.
  3. Select the disk to share, and click Start Sharing.
  4. If prompted, choose an account, enter its password, click Unlock, and click Start Sharing.
  5. Connect your Mac to another one via a USB data cable (with Type-A or USB-C plugs on either or both ends) or a Thunderbolt 3 or 4 cable.
  6. On the other Mac in the Finder, click the Network link in the sidebar to view the shared Mac’s volume.
  7. Click the Mac in the main window, click Connect As in the upper-right corner, select Guest as the user, and click Connect.

You can now transfer files between the two computers. When you’re finished, eject the mounted Mac volume by selecting it and dragging it to the Eject icon in the Dock or pressing ⌘-E.

Startup Security Utility

Apple took a harder line on startup security policy when they introduced Apple silicon Macs than they previously had with Intel models. macOS offers Full Security, which locks your Mac down to either its current version of macOS or any version Apple currently supports—typically a limited set. Reduced Security lets you run older versions of macOS that Apple previously approved to run on your hardware.

Almost unrelated, the “Allow accessories to connect” option lets you set a boot policy to restrict connections. For options, see the Mac settings worth changing.

Reduced Security lets you select or deselect the option to install signed legacy (or outdated) kernel extensions; and for remote management, which is used in schools and businesses, to control these kernel extensions and software updates. Some organizations may need specific older extensions for security software and may also want to delay automatic software updates to avoid breaking them.

People at a heightened level of risk could trust Reduced Security with just user management enabled for kernel extensions, since those extensions must be signed by “identified developers” (via Apple’s process) and require user steps to install, as described in Manage System Extensions.

If you don’t have Reduced Security enabled and try to install a system extension, the app installation explains what happened.

Proceed to click Open System Settings, and you see a note in System Settings > Privacy & Security.

Click Enable System Extensions and you see a dialog that provides a shortcut and offers abbreviated and somewhat misleading steps on enabling Reduced Security. If you want to proceed, click Shut Down in that dialog and then follow from step 2, below.

Starting from scratch, follow these steps:

  1. Restart in recovery mode. (See How to Restart in Recovery Mode.)
  2. Choose Utilities > Startup Security Utility.

Note: Apple requires an internet connection when you change the security policy, and you can hit a snag if you follow step 2 too quickly. If you see the error “An internet connection is required to change security policy,” quit the app (labeled Startup Disk when launched), wait for the Wi-Fi icon to show a connection in the menu bar, and launch the utility again. (An Ethernet connection doesn’t work.)

  1. The app launches. Click Unlock to mount the disk, which will be encrypted.
  2. Select an administrator user, enter the account’s password, and click Unlock.
  3. Select the drive if it’s not already selected.
  4. Click Security Policy.
  5. Select the level of security you want to apply and click OK.
  6. When prompted, select an administrator user, enter the account password, and click OK.
  7. “Applying security policy” appears. It may take several to tens of seconds to complete.
  8. Quit the utility and choose Apple menu > Restart.

Tip: Reduced Security disables Apple Pay on a Mac with Touch ID capability. See how to set up Touch ID and Face ID.

Permissive Security (not shown in this section) is an additional option that can’t be selected without disabling an even lower-level feature: System Integrity Protection. The Startup Security Utility then adds Permissive Security as an additional radio button. However, it’s not “no security,” but rather “experimental security”: it allows a very particular kind of installation, in which researchers and other niche users create custom kernels—the heart of the operating system—outside of the Apple-signed ecosystem of macOS versions compatible with Apple silicon Macs. It is exceedingly unlikely you would ever need it.

Recovery Assistant

Apple added Recovery Assistant in Tahoe to deal with situations in which macOS couldn’t start up correctly, and some sort of repair was required that needed the startup volume unmounted. If you encounter this, you will see a Recovery screen that explains the issue. You can also launch Recovery Assistant from macOS Recovery by choosing it from the Utilities menu.

The process works like this:

  1. At the Recovery screen, click Continue.
  2. Apple asks if you are willing to send them diagnostic data, and warns you about privacy issues. Click Don’t Send Data to Apple or Send Data to Apple.
  3. Click Start, and the assistant tries to resolve the problem.
  4. The assistant reports one of three states:

1.1. Your Mac was recovered successfully. Click Restart Mac.

1.1. No known issues were found. Click Restart Mac.

1.1. Your Mac could not be recovered. Oh, boy, it’s time to look into backups, consult an independent Apple expert or the Genius Bar at an Apple Store, or call Apple Support.

If you open System Settings > General > Sharing, you’ll notice many resources your Mac can share with other devices on your local network—and, in some cases, beyond.

You can share your screen, files, printers, and internet connection, for example, and you can also enable various types of remote access to your Mac.

All these features can be handy, especially in that they enable multiple Macs in your home or office to talk to each other. You can copy a file from a Mac in the other room, or view what’s on the screen of the Mac upstairs when you’re downstairs.

However, Apple pairs easy local access with easy remote access: if your Mac is reachable from the internet, some services you share locally can be available remotely. Some may require a password, but that could be easily guessable if you haven’t been thinking about internet-based attacks. And just having certain services active, like Remote Login, could allow remote attacks if an exploit turned up in Apple’s system software, before such exploits were known and patched.

This isn’t speculative. Apple regularly patches exploits and bugs in low-level software, like sshd, the secure shell daemon, the system software that handles remote Terminal-style sessions if you have Remote Login enabled. Those flaws are usually fixed before anything terrible is unleashed in the wild, however.

How exposed you are comes first; which sharing services are safe to turn on follows from it.

What’s your risk of internet intrusion?

The most likely determinant of risk to attacks or intrusion via the internet is how directly reachable your Mac is. While the vast majority of routers have a public IP address, very few computers on local networks do. Almost always, your router receives traffic and then re-addresses it to your Mac.

A public IP address is by definition routable or reachable from the rest of the internet. The network of which it’s a part appears in routing tables traded among the devices that exchange data across this mighty global beast.

However, IP addresses can also be static or dynamic. A static address is assigned to a device and doesn’t change over time without typically manual involvement in changing settings. A dynamic address can change at will, and it’s automatic.

Private network addresses can be either static or dynamic; most of us have networks configured to assign the next available address when a computer, phone, or other device requests one. Some routers can be configured to assign static private addresses to specific devices.

If you’re not running a business network or paying extra, your broadband router typically has a dynamic public address. The ISP may rotate the address every once in a while, or if there’s a service outage or you restart the router, a new address is assigned.

The dynamic nature of these public addresses assigned to routers doesn’t aid in security in any fashion, because they’re still public. You might not be trackable by public IP, but your router is still reachable.

A public IP address is simply one that’s uniquely assigned across the internet, and can be reached from anywhere else on the internet. Your router almost certainly has a public IP address, because that’s how it interacts with the rest of the world on your behalf.

It’s a very low bar for any interested party to scan all the originally defined set of public addresses on the internet—yes, as many as hundreds of millions of them—to find open access for services that the scanner might know potential security exploits for, sometimes far out of date…but there are a lot of old, unpatched machines on the internet. Thus, with a public address, there’s no obscurity possible.

That “originally defined” part uses an addressing scheme called IPv4; a newer standard, IPv6, is more resistant to bulk scanning. See the IPv6 section below.

Most homes and businesses rely on private IP addresses for everything but their broadband connection’s router, however. These reserved ranges are only used on local networks, are managed by a router (using something called Network Address Translation or NAT), and typically assigned out automatically with DHCP (less well known as Dynamic Host Configuration Protocol).

Private addresses, which are usually in the form 10.0.1.x or 192.168.1.x, can be reached without any special effort by other devices on the same network of privately assigned addresses. However, when a device on your network makes a request outside its private network range, like viewing a webpage, the router rewrites the request to use the router’s public IP address, and sends it out; the router receives a reply and then forwards it to the locally connected device that requested it.

If you were to have a public IP address on your Mac—not just on your router—it would be like standing on a street corner instead of being inside a house with a locked door and a mail slot. Anyone can come up to and start talking to you or assault and rob you! (Unlike in the world of atoms, where violent crime is minimal and has drastically fallen in recent years, an internet mugger can attack targets wherever they are and a huge number simultaneously.)

The same effect happens if you configure your router to connect its public address with specific services on one or more devices on the local network. For instance, some people want to have a globally available web server or file server, and it’s not terribly hard to expose the correct connection. That makes that web server or file server just as exposed as if the Mac had a public IP address—but only those services, not everything else shared on the Mac.

NAT isn’t designed as a security measure: it’s just a spreadsheet the router maintains to wire requests and replies together. It’s incidentally a general security measure because it makes potentially exploitable open doors on your devices nearly impossible to reach without being specifically targeted, particularly with a router that can be subverted.

You may already be sure you don’t have a public IP address on your Mac: your ISP charges extra for public addresses you use beyond the one attached to your router, and you know you’re not paying for it; your ISP doesn’t offer public addresses; you specifically made sure you weren’t getting one from your ISP; or you’ve configured your router and you know exactly how you set things up.

If you’re not sure, walk through this list:

  • Check your Mac’s address: You can examine the IP address assigned for your active network interfaces. Go to System Settings > Network and select each of your active interfaces in the main pane:

— Ethernet and most interfaces show the address in the main pane under or next to “IP Address.”

— For a Wi-Fi interface, click Details to see the address next to IP Address.

  • Check your router: Connect using the administrative controls for your router, log in, and look at where your router shows its WAN (Wide Area Network), Modem, or Internet IP address, and how network addresses are handed out under DHCP, LAN (Local Area Network), or similar labels. The WAN side is almost always a public IP; the LAN/DHCP part almost always private.

If the IP address of your Mac or LAN/DHCP addresses on the router is in any of these ranges, it’s a private one, where x is any number from 0 to 255: 10.x.x.x, 172.16.x.x to 172.31.x.x, or 192.168.x.x. Otherwise, it’s almost assuredly public.

Type in “what’s my IP” at Google and it will tell you what it thinks your IP address is, and offer a list of sites that do the same (sometimes with more detail). However, if you’re in a DHCP/NAT scenario with private addresses, which is what nearly all home users and most business users are, the address shown on the website is the one associated with either your broadband modem or a further upstream router run by the ISP—not your Mac.

IPv6 adds a wrinkle

Technically, the IP address style x.y.z.a, like 192.168.0.1 or 36.44.0.6, is IPv4 (version four), which has been in use for decades. For nearly 30 years, internet mavens have been trying to migrate the networks that comprise the internet to IPv6, which has a lot of advantages. This includes more addresses that can be assigned, the so-called address space. Where IPv4 has billions of potentially usable addresses, IPv6 has hundreds of undecillions.

However, the trouble has been all the inertia of having billions of devices and hundreds of millions of routers and pieces of plumbing designed around IPv4. While the internet has largely retooled—after nearly 30 years—so that IPv6 works as well as IPv4, nobody wants to end the widespread use of IPv4 in residential networks and many company networks, because of private addressing. IPv6 was designed before NAT became broadly used and thought of as a quasi-security measure to prevent ingress to ISP and corporate networks.

For most of us, that means until private addressing can work in a similar way within IPv6, our ISPs have assigned our routers a public IPv4 address, and have chosen one of several paths with IPv6:

  • Ignored/disabled: Your ISP may simply not pass IPv6 traffic, and it’s not an issue for security.
  • Allow, but disabled by default: You can use IPv6, but you have to configure your router to allow it. My ISP requires a special router for its fiber-optic service, and has detailed instructions for enabling IPv6. Since I have no specific need of it, I’ve left it disabled to reduce my exposure on the public internet.
  • Turned on by default: You may have an ISP, like my editor Dave Johnson, who enables IPv6 by default through its system, and your router and devices all automatically get IPv6 addresses, just as they do IPv4 ones.

If you’re in that last situation, you may have publicly reachable IPv6 addresses—it can be hard to tell, because some ISPs use techniques that are similar to NAT. If the IPv6 addresses are truly publicly accessible, they expose the same general risk of remote attack as public IPv4 addresses and should follow the advice in the next section.

But some analysis suggests it’s not as bad as it might seem. The Internet Society has an interesting FAQ about IPv6 and security, and notes that attackers could find “infrastructure nodes” reasonably easily—the routers that form the backbone of the internet and connect ISPs, streaming services, data centers, and so forth all together.

But, the document explains, “It is generally unfeasible though to address scan a network for client devices, since their addresses are randomized over a very large address space.” Simplified, it means that it’s not a needle in a haystack, but 10,000 needles in a Nebraska-sized area of haystacks. (With IPv4, it’s a cubic foot of hay and you can see all the needles inside.)

If you’re truly concerned, you can disable IPv6, as it isn’t a mandatory or critical part of using the internet. Here are three possibilities, the first two of which will affect your entire network:

  • Disable IPv6 at the router: Find the manual for your router and follow instructions to disable IPv6. It may be as simple as selecting a radio button.
  • Ask your ISP to disable IPv6: Contact your ISP and ask them to disable IPv6 on your account or router if they control your router or have the ability to do this at a higher network level.
  • Disable IPv6 on your Mac: If you can’t or don’t want to disable IPv6 network-wide, disable IPv6 on your Mac. Go to System Settings > Network, select an interface, and click Details. Select TCP/IP and choose Link-Local Only from the Configure IPv6 pop-up menu. Click OK. This leaves other devices still reachable via IPv6, but at least locks down your Mac.

You can’t disable IPv6 on an iPhone or iPad.

If you lose your macbook you may want to locked it in find my to make sure no one would take it. When you find it, you may want to unlocked it. You can put in your passcode as normal and unlocked it. This may only allow you to use it as normal for a few minutes then it would suddenly go black and showed a lock. Whenen this happened, you won’t see any writing on the screen and entering your password won’t do anything. If you locked your macbook through find my and can’t unlock it now, here’s what you can do.

To unlock any Apple silicon Mac or an Intel Mac with a T2 Security Chip (models released starting in 2018), follow these steps:

You could be stuck if you’re using a Mac with multiple accounts that another account holder has Find My control over and that person locks it. You need them to perform the unlock in person or read you their passwords. This could be awkward.

  1. After marking the Mac as lost, it appears with a question mark overlaid in the Devices view.
  2. When the Mac restarts, it shows the macOS Recovery screen with Recovery Assistant appearing as the active app in the upper-left corner.
    • Apple claims the message you entered will appear at startup. It does not, in my testing.
  3. The account used to lock the Mac is the only one that appears. Click its icon and click Next. Only one account appears because only one account per Mac can be used for Find My.
  4. Enter the account’s password and click Continue. If you don’t remember your password or it doesn’t work, you can click the “Forgot all passwords?” link, which takes you to the FileVault Recovery process. Using that method, you can enter your Recovery Key, reset the password, then restart step 2.
  5. If you entered it correctly, “Authenticated succeeded” appears. Click Restart.
  6. The Mac restarts again into Recovery Assistant. This time the screen reads Activate Mac.
    • You reconnect with your Apple Account by entering its password.
    • You can select any macOS account that can log in to the Mac, provided you know the Apple Account shown next and its password.
    • Select the account, enter its macOS password, and click Next.
  7. You may be prompted to enter your full Apple Account email address; a Mac shows you a portion of it. Enter it and click Next.
    • Your Mac prompts you to enter the password associated with the partially displayed Apple Account address, or the one you just entered in full.
    • If you don’t have that password, click the link below the field, Use Device Password, and enter the last password used to unlock the Mac in a regular session before it was locked. In beta testing, I found I didn’t get a field to enter that password in, but this may have been fixed by the production release.
  8. On a successful entry, the Mac restarts yet again after a one-minute countdown. Enter your password when prompted to start up into a regular session. Apple Pay will have been disabled, and your iCloud sync is probably paused as well. When prompted, enter your Apple Account password (or passwords if you have multiple accounts linked to your macOS account).

The first time I tried this with macOS 27, I had to choose Apple menu > Restart after it wouldn’t proceed. Then I followed steps 5 and 6 above again, and it worked.

If your Apple Account gets locked

If you try this too often, as I did while testing, or for other security reasons only Apple knows, your Apple Account may be locked. At step 6, I was told I had to reset my Apple Account password from one of my other devices; all four of which are linked to the account were shown. I made that change. In one of the public beta versions, clicking Unlock Account did nothing before or after changing. I was able to click Cancel, complete step 6 again with the new Apple Account password, and proceed to step 7 and restart.

The alert’s title reads Update Phone Number, even though there is no opportunity to do so. This may be fixed by Apple later, though I doubt it.

Apple’s email is out of date

The process above was documented using macOS 27, and Apple has made slight tweaks and major improvements over the last few years. However, the company appears unable to shake off the vestiges of the past. Years ago, when you locked your Mac, you had to set a passcode to unlock it. While that isn’t supported with Apple silicon Macs or Intel Macs with the T2 Security Chip, the email Apple sends out still shows a thumbnail screen where you would enter that code and tells you that you can only unlock your Mac with that non-existent passcode.

Tags: Find My, macOS

To view your device’s location, those of people in a Family Sharing group, or your items, use the Find My app on an iPhone, iPad, Mac, or Apple Watch, or the Find Devices app in watchOS 26 or earlier or on iCloud.com. By activating Find My, you’re signed in to the app on all those operating systems and on iCloud.com. Each view in the iPhone, iPad, and Mac Find My app provides access to a different category of location-finding.

The map in each view includes typical actions, such as zooming in and out, switching to satellite view, and switching to 2D view. The icons, such as the Choose Map and 3D view buttons, appear the same as in Apple Maps.

Those Find My views are separate apps on an Apple Watch running watchOS 26 or earlier: Find People, Find Devices, and Find Items. If I mention a view, find the app in watchOS 26 or use Find My in watchOS 27.

You can add a Find My widget to the Home screen or Notifications Center to see people and devices without opening the app.

The three status labels

For each category—People, Devices, and Items—Find My shows the last time a location was updated in the list: to the right of the item on an iPhone/iPad and under the item on a Mac, Apple Watch, and (for devices) on iCloud.com. It also displays this information in the detail view for the selected item.

Here’s what the status messages mean:

  • Live: Devices can provide a continuous stream of location information in the right circumstances. You can watch someone walk down a street or see their train move across the landscape. (Frankly, a little creepy, even though it’s done with permission?)
  • Now: If live updates aren’t possible due to battery, location, connectivity, or operating system version, Now is the second-best. It indicates an update within the last minute.
  • Time duration: Find My shows X minutes ago or a specific date and time for the last location update.

Selecting an entry

Starting with the version 27 releases, you select an entry by tapping or clicking it. This reveals slightly more information, such as a Directions button or a Play button to play a sound. Tap or click the More button to reveal the sheet of actions for that category.

Before the version 27 releases, Apple had two distinct methods for selecting an item from the people, devices, or items list: one for the Find My apps on iPhone, iPad, and Apple Watch; another for the Mac Find My app.

In iOS 26, iPadOS 26, and watchOS 26 and earlier, tapping an entry selects it and causes its sheet to appear. In macOS 26 and earlier, click the item, then click the Info button to reveal the sheet. macOS 26 and earlier also let you Control-click/right-click an entry to reveal several menu items; macOS 27 limits these to just Remove and, for People, Add to Favorites or Remove from Favorites.

What iCloud.com cannot do

You can’t track people or items on iCloud.com, only devices (via the Find My link, which takes you to the Find Devices app). However, iCloud.com’s Find Devices web app is useful for one purpose: when a device is missing or stolen, and the person whose device it is lacks access to Find My on any of their devices. See how to find a lost iPhone or Mac.