Got a tip for us?

Security

FileVault prevents access to your Mac at startup without the password for an account with permission to boot the computer. Instead of loading macOS, enabling FileVault has your Mac pass control after startup to a very simple program that resembles the standard macOS login window. Entering a valid account password on this screen allows that program to access the encryption key to unlock the startup disk and proceed seamlessly (and invisibly) into your regular Mac session. Because FileVault is integrated into macOS at such a deep level, there’s only an on/off button. You don’t need to manage any of the parts.

On Macs without a T2 chip or Apple silicon processor, FileVault also performs full-disk encryption (often called FDE). But that’s automatic and cannot be turned off on T2/Apple silicon Macs.

Starting in macOS 26 Tahoe, FileVault is automatically enabled for all users in new installations and via upgrades. It can be disabled; read on to find out if you have a reason to do so. If you didn’t previously have FileVault enabled, the first time you start up in Tahoe, you will see a message that “Your Mac is [sic] Protected by FileVault.” The dialog further explains that the Passwords app has the critical Recovery Key (see where to find your FileVault Recovery Key).

Apple also got rid of a lingering potential path for crackers and government intrusion by switching from relatively insecure storage in iCloud to fully secure storage. This is welcome!

Should you ever disable FileVault?

FileVault is an additional protection for all users that prevents unwanted access to their data. However, despite my strong recommendation to enable it, it is overkill for some people that could result in them losing access to their data in specific circumstances.

What are those circumstances?

First, they would have to either be unable to remember or find their macOS account password, or the FileVault login data for accounts would have to become corrupt and reject a legitimate password.

Second, they then couldn’t find or gain access to their FileVault Recovery Key, discussed in where to find your FileVault Recovery Key.

Most people enter their macOS account password routinely and are unlikely to forget it. But it is the case that you can experience a problem that scrambles the normal startup FileVault login. If so, your FileVault Recovery Key is your only hope. If that becomes irretrievable, you’re sunk.

So before you proceed, consider if protection for your data when the computer is turned off is worth the risk of disabling FileVault.

How startup encryption works

Full-disk encryption puts a layer between the operating system and a storage drive that automatically decrypts all information coming off the drive and encrypts it as it’s written. This means all information on the drive “at rest” is fully encrypted.

Only while a Mac is active is stored information vulnerable to interception: macOS holds the encryption key in memory to allow it to encrypt and decrypt data on the fly. This allows a Mac to treat an encrypted volume as if it were effectively not encrypted at all while the volume is in use, including letting you share the volume over a network and back it up to an external drive, a networked volume, or an internet service, and use sync services like Dropbox, iCloud Drive, and OneDrive.

Whenever a Mac is shut down, a drive is an inaccessible vault, with no more information accessible than a lump of solid metal. The key material necessary to decrypt its data can’t be accessed.

The introduction of the T2 chip, and, later, Apple silicon, removed all overhead, and Apple made the decision for security reasons that FDE is always enabled on T2/Apple silicon Macs, even if FileVault is not. This also means T2/Apple silicon Macs can enable or disable FileVault in seconds, if desired.

However, without FileVault enabled, the drive is automatically decrypted on startup even before an account password is entered! That’s the piece that FileVault fills in.

With an Apple silicon Mac, the startup process without FileVault begins with operations that retrieve the security key, which is mediated by the Secure Enclave. If the SSD drive is removed from the Mac, which in modern Macs is difficult enough to be infeasible, the decryption information remains in the Secure Enclave left behind. It seems unlikely a thief or corporate or government spy would take the drive and not the whole computer, however.

Additional protections available in Apple silicon, combined with changes in macOS (starting back in Big Sur), allow that Mac to unlock the system files to boot directly into macOS without exposing any user data files.

Your data and Mac remain protected until a valid account password is entered, at which point the key protecting the data is made available for use, and startup proceeds. This may feel like enough for you. However, Apple seems to think it isn’t, and thus enables FileVault by default in Tahoe.

Encrypt external drives

You can also encrypt any mountable SSD, HDD, or disk image that is not configured as a macOS startup drive.

There are two primary ways to encrypt non-startup volumes:

  • Control-click or right-click in the Finder: This is the easiest method, and will take place in the background. Control-click or right-click the volume and choose Encrypt. Enter and verify a strong password, preferably one you generated in a password-management app. Add a hint if you think it will help. Click Encrypt Disk. This converts the drives in the Finder without losing any data. (Disk Utility, by contrast, can change a volume’s format type to the encrypted flavor, but it always erases the volume—and warns you before you proceed.)
  • Disk Utility for disk images: Disk Utility can also create encrypted disk images, though it uses a different method. Choose New Image > Blank Image, then choose 256-bit AES from the Encryption menu. You’re prompted to enter and verify a password, but not store a reminder tip. Set other parameters as needed and click Save to create the image.

In the future, you have to enter the password for a volume to mount an encrypted volume or disk image in the Finder or to access it via Disk Utility. When mounted, the drive appears as fully decrypted to the Finder, just like a startup volume with FileVault, and can be shared, synced, and backed up.

Apple notes carefully that passwords created for any encrypted drive other than the startup volume aren’t managed in the Secure Enclave. You have to manage them yourself, and they don’t come with the same high level of protection.

Apple will no longer support Encrypted HFS+ after Golden Gate. If you have an HFS+ volume you encrypted in a previous macOS release, this is the time to remove encryption or upgrade the volume to APFS. You can perform both operations in Disk Utility.

If you’re the only person who ever uses your Mac, none of this applies. Otherwise, you should know a few things about what sorts of access other people may have to your data.

First, if everyone uses the Mac via a single account—without having to log in and enter a separate username and password—all bets are off. Whatever’s available to you is available to everyone else. I’m not a fan of that arrangement. Ideally, every human who uses your Mac should have a unique username and password. (I might make exceptions for kids too young to type their own passwords. See how to set up safe user accounts on a shared Mac.)

But let’s say each person does have a separate account and password, and each one diligently logs out (or shuts down the Mac) after every session before the next person logs in. Then what?

How ownership and permissions work

macOS, as a variety of Unix, relies on the properties of ownership and permissions for each file. To oversimplify a bit, each file and folder has a designated owner—usually one of the individual account holders or the system itself—and a set of attributes assigned to it that specify who can access it, modify it, delete it, or execute it, in the case of files. (Apple adds a number of Mac-specific attributes on top of that.)

But there are owners and there are owners. macOS Standard account owners can access files, apps, and folders in all public places, like the system-wide Applications folder, but they can modify and add items only in specific locations: their own home folder (/Users/username) and the Shared folder in the main /Users folder. No other standard user can view files in any other users’ home folders, except the default Public folder, which is read-only and has a Drop Box item (not Dropbox, the service) that other users can drag items into, but then not see afterwards (write-only). For day-to-day segregation of one person’s data from another, this system provides a reasonable barrier.

An administrator can assign additional access to all non-system files and folders by changing ownership to a user, creating a group and providing group read/write access to a folder, or changing permissions to make things readable and modifiable by anyone with an account.

Where the barrier breaks down

But that reveals the weakness, no? An administrator has “root” access, which is the top-level permission holder in Unix. Anyone with an administrator account and working knowledge of the Unix command line can access everyone else’s files by opening the Terminal app in /Applications/Utilities, entering sudo -s, and supplying the administrator account’s password.

They can also restart in recovery mode, and use Terminal there to avoid any safeguards or monitoring tools that might be installed in macOS. With an Apple silicon Mac, an administrator can share the entire Mac as a volume on another Mac via macOS Recovery, too.

Standard users also have some options to get around the protections that should prevent them from seeing other files:

  • Filching your password: Anyone who knows or can guess your login password can log in as you and access all your files. Of course, you have a terrific password that you’ve kept completely safe from everyone else, right? Fine, but there are still other problems.
  • Attach your Mac’s startup drive to another Mac as an external drive: If you start up your Mac from an external drive someone could attach that drive to another Mac to which they have administrator permissions and access all the files on it. If it’s protected with FileVault, they only have to have an account enabled for FileVault on the original Mac and know the password. While other users’ files appear locked when the Mac’s drive is mounted, they can be copied over and unlocked by entering an administrator account password on the destination Mac.
  • Can’t attach volumes and other stuff while locked: Apple lets you require approval to attach new peripherals, SD cards, and other accessories to your Mac. See the Mac settings worth changing. If your Mac is locked, nothing can be approved.
  • Connect your Apple silicon Mac to another Mac: Mac Sharing Mode is a feature introduced with Apple silicon Macs to let you mount one Mac as a volume on another Mac. Mac Sharing Mode turns a Mac into a file-sharing volume, instead of appearing as an externally connected drive. (This is functionally equivalent to, but less risky than, the Target Disk Mode available on Intel Macs.)

To use Mac Sharing Mode, connect an Apple silicon Mac to another Mac of any vintage with a USB or Thunderbolt cable. Restart your Mac in recovery mode, choose Utilities > Share Disk, and then select the volume to share. On the other Mac, the sharing Mac appears as a network volume.

In addition, someone who has access to backups of your files on mounted or unencrypted volumes or drives can likely access all of them without file ownership and permission getting in the way.

For all these reasons, the only safe assumption is that anyone else who has an account on your Mac or physical access to it could conceivably access your files. Although your data is fairly safe from casual access by nontechnical users, you should not think of ownership and permissions as a significant roadblock.

Moral of the story: Don’t give other people’s accounts administrator access if you don’t trust them and you can prevent giving them such privileges.

If you can’t, another option is to use encrypted disk images or volumes in which you keep the password to yourself. You can use the Finder to encrypt volumes and Disk Utility to create encrypted disk images; see how to turn on FileVault and encrypt your Mac. Unmount these disks when they’re not in use.

Security has a broad meaning in everyday life, but a more specific one when it comes to data, networks, computers, and mobile devices.

As a general rule, we talk about security when we mean a means of reducing the likelihood of harm. You go through a security checkpoint at the airport. You have a home security system. A lecture is canceled due to security concerns. An ad for a bike lock claims it offers high security.

With computing and networking, however, security is more specific: it’s the measures you take to prevent harm to you by the extraction, interception, loss, or corruption of your data.

You may also see the term exfiltration, which sounds highly technical but simply means the extraction of data from a device, often over a network, to a malicious or unwanted recipient.

It’s rare that a violation of your device’s security would result in physical harm to you or anyone else—unless someone attacks you while also stealing your equipment. That’s quite rare in a home or office, but it can happen when out and about, where an assault or threat of it could lead you to reveal your iPhone passcode or other passwords.

While it’s also rare to be attacked, or even drugged, to get your passcode, it does happen often enough that Apple added a new protection. See how to turn on Stolen Device Protection.

But even without a physical assault or fear of it, you can suffer emotional harm from the sense of invasion or damage that results from an invasion, particularly if someone violates your security to steal personal information that is then disseminated or used against you.

You can also certainly incur financial damage (theft of identity or money), waste your time (canceling credit cards, changing passwords), find yourself spending hours coping with the aftermath (removing malware, restoring deleted files), and so on. If your Mac became part of a botnet, you could also harm other people’s devices. As a result, your ISP might temporarily cut off your internet service to block attacks originating from inside its network.

Apple’s security options through the mid-2010s focused mostly on resisting attacks carried out over a network and exploits that relied on software that was downloaded and installed with or without your permission. In the new era stretching back nearly a decade now, Apple shifted to giving you tools and automatically protecting your data when someone can take physical control of your device.

The company also puts a lot of attention on blocking exploits and malware in macOS, which, because it allows any software to be installed, remains more vulnerable; the network as a vector for compromising a Mac is nearly entirely ignored. It’s different with iOS and iPadOS, as the key vector for attack there seems to be phishing text messages and attachments, which has led Apple to a constant cycle of hardening Messages and related components.

Protecting against physical attacks requires your device to resist intrusion. That intrusion might be someone merely sitting down in front of a Mac for a few minutes and extracting the contents of your drive without leaving a trace, popularized by hackers in movies. But it more frequently includes deterring a thief who has purloined your iPhone, iPad, or Mac—whether for a period of time or forever—from successfully cracking it at their leisure.

As a result, you now should think both about the digital sense of security and the physical sense:

  • The digital part involves protecting your passwords and passcodes, guarding against remote attacks over the internet, and halting the delivery, installation, and deployment of malware.
  • The physical part involves configuring and understanding Apple’s features that deter hands-on attacks, such as plugging in a USB or Thunderbolt device or even an SD Card that performs an exploit, and up to and including someone removing a motherboard or an SSD or hard disk drive or disassembling an iPhone or iPad. It also includes enabling Stolen Device Protection on an iPhone, Apple’s current highest level of optional physical security enhancement.

Improving your device’s security reduces the chance of certain harms:

  • Loss of data
  • Data taken off your device and sent elsewhere
  • Degraded performance
  • Malware that locks files or sends private data elsewhere
  • Loss of control over your device, including being locked out
  • Hijacking of your Apple Account, which could lead to permanent loss of access to the account

How security, privacy and anonymity differ

Security is closely related to privacy and anonymity, but distinct. Here’s how to keep the three terms straight:

  • Security is freedom from danger or harm.
  • Privacy is freedom from observation or attention.
  • Anonymity is freedom from identification or recognition.

You can have security without privacy (imagine living in a house made of bulletproof glass). You can also have privacy without security (think of a changing room at a clothing store with just a curtain). And you can have both privacy and security without anonymity (think of a royal family ensconced in a castle).

When it comes to your digital life, these concepts—especially security and privacy—go together more often than not. Many of the harms or dangers that might befall you if your security is insufficient involve the exposure of personal data, so one of the biggest reasons to have better security is to maintain your privacy. Or, to put it the other way around, many of the things you can do to protect your privacy are, in fact, security measures.

Which of the three you most need shapes everything else, and that depends on your own risk profile.

It’s a fact of life: software has bugs. And some of those bugs result in security vulnerabilities. Fortunately, most major software vendors, including Apple, have teams of programmers working constantly to identify and fix security-related bugs.

I can’t tell you how many times I’ve read breathless news reports about some newly discovered and seemingly disastrous Apple security issue, only to see a software update from Apple fix it a few days later before any damage occurs. This is Apple’s normal pattern, and it’s why you should never lose sleep about the security crisis du jour.

However, Apple security updates don’t help unless you install them! If you have automatic software updates turned off and ignore alerts or badges, you could be needlessly putting your devices and your data at risk from problems that were solved months or years ago.

Software updates fall into several categories, all of which can fix security issues:

  • Major upgrades, such as from macOS 26 Tahoe to macOS 27 Golden Gate or iOS 26 to iOS 27
  • Minor updates, which can be small increments for big fixes (27.1.0 to 27.1.1), or larger ones when they include feature changes but not a full operating system upgrade (such as 27.0.1 to 27.1)
  • Standalone security updates that fix specific pieces of system software, usually stuff deep beneath the surface (most common with a Mac)
  • Updates to individual Apple apps (Safari, Music, Books, QuickTime Player, etc.)
  • Updates to third-party apps

Which of these should you keep up with? Ideally, all of them, but at a bare minimum, install the standalone security updates. After confirming you haven’t heard of any problems others have had, install minor updates. Major updates require more planning and involve much more than security fixes.

To learn about all Apple software updates with security implications, see the Apple security releases page. Click a specific update to read the security details.

Zero-day exploits

Apple, Google, Microsoft, security firms, anti-malware software developers, independent security consultants, and “gray-hat” hackers (not criminals, but they don’t always play by the rules—or laws) are constantly on the lookout for significant flaws to fix them and release updates before they become a zero-day exploit or zero-day attack. That’s when there’s literally zero days to patch the problem.

Malicious parties—including nation-state actors, such as the security agencies of major countries—may hold zero-days in reserve or use them in such a limited fashion that they remain available for some time. It’s the job of all software developers to patch zero-days before they’re exploited.

It’s much more often the case that ugly bugs are fixed by Apple before they’re exploited in the wild; or the exploit is so tricky, it requires physical device access or incredible sophistication, timing, and targeting. Apple will flag particularly severe exploits and recommend immediate installation when necessary. This happened on April 16, 2025, when Apple pushed out updates across their operating systems to fix zero-day exploits that the company said were already used in the wild in individually targeted attacks.

Zero-day exploits that aren’t reported to Apple and other companies responsibly—sometimes for significant “bug bounties” these firms and zero-day projects pay out—are sold on the gray market and used for pinpoint government operations. These are often ones most people would feel are illegitimate or violate human rights, such as three separate zero days used allegedly by the United Arab Emirates to hijack a single human-rights advocate in their country.

In most cases, Apple releases security updates for the current version of macOS, iOS, and iPadOS, and the previous three—or even four. If you aren’t at least on the third-most-recent version of one of these operating systems, you risk being vulnerable to known security problems that Apple won’t ever fix.

Apple also looks backward quite a ways with hardware, letting you upgrade fairly old Macs, iPhones, and iPads to at least one of the third-oldest operating systems, if not the current one. With Golden Gate, support covers all Apple silicon Macs; Tahoe included four Intel models from 2019 and 2020. iOS 26 and 27 look back to the iPhone 11 series (2019), while the cutoff points for iPadOS 26 and iPadOS 27 are very complicated.

Often the initial releases of new operating system versions (27.0.0, say) have significant bugs that Apple fixes quickly. So it’s fine to wait a few weeks on major upgrades, by which time enough others will have tried out the new release that you can judge how stable it may be for you.

Apple delivers minor and major updates and security updates through Software Update: go to System Settings (Mac) or Settings (iPhone/iPad) > General > Software Update.

Configure automatic security updates

Apple wants you to install updates as soon as possible on all its operating systems. The approach you take may be different between a Mac and an iPhone or iPad.

On a Mac

Software Update shows whether you’re up to date and notes any available updates if you are not. If you’re a major system update behind (or further), it also shows an area at the top urging you to install it. In a secondary area below, the pane may read “Another update is available” for Safari and security updates, and you have to click “More info” to discover which are and proceed to install them.

It also runs in the background and displays a red badge in System Settings indicating quantity. You can’t disable this.

You can completely automate minor macOS, security, and other updates—in fact, that’s the default. (Major macOS updates require direct action.) Go to System Settings > General > Software Update and, to the right of Automatic Updates, click the info button to see settings and make changes.

  • Download new updates when available: This includes all the updates listed below. The advantage is that they are either installed automatically or available for immediate installation if you install manually. Disable this if you’re bandwidth-limited or pay for bandwidth and want to plan downloads.
  • Install macOS updates: This includes all “dot” updates, like moving from 27.0.0 to 27.0.1 and from 27.0.1 to 27.1.0.
  • Install system data files and security updates (Golden Gate) or Security Responses and System files (Tahoe): Apple used to use the term “Rapid Security Response” for these security updates; I’m guessing they now incorporate more kinds of security fixes? Previously, the company explained those updates addressed exploits that Apple discovered were already happening in the wild, not just identified by researchers. These fixes are installed automatically when this option is turned on—no reboot required.

Apple moved automatic App Store updates from Software Update to the App Store app in macOS 26.

In most cases, you can view a list of available updates, deselect or select items in the list, select items to view their contents, and click Install Now to proceed towards installation. Updates that require restarting your Mac are marked with “Restart Required” after their title in the detail section, and you’re warned when you click Install Now that you will need to let the updater restart your Mac to complete the update.

The next major operating system update past what you’re running used to appear as a short entry with a More Info link. But in Monterey, Apple transformed the upgrade notice into a full advertisement that listed all the available features. Minor updates still use the More Info link to tell you what to expect.

When preparing to install updates that require a restart, make sure you have no unsaved files, no open Terminal windows, and nothing in progress in an app. Often, this can halt a restart—particularly an issue if you walk away hoping to return with the update done. I always wait until my Mac restarts before leaving.

In addition to the Software Update setting for system data files and security updates, make sure the setting introduced in macOS 26.1 is enabled: System Settings > Privacy & Security > Background Security Improvement. With this enabled, Apple can update certain parts of the system, such as components of Safari and system libraries used by multiple apps, without requiring a full incremental update and restart.

On an iPhone or iPad

Software Update on an iPhone or iPad, in Settings > General > Software Updates > Automatic Updates, offers options similar to those on a Mac. If you enabled Automatically Install, you’re alerted that an update will happen overnight the next time the device is plugged in and idle. This option also hides the next two: Automatically Download and System Files > Automatically Install.

Even if you don’t want updates to be installed automatically, enabling downloads for iOS/iPadOS Updates lets you avoid waiting for a download to happen when you make the decision to trigger an update manually—the file is ready to go.

Everyone should leave System Files enabled for automatic updates, for the reasons given above.

As with macOS, Background Security Improvements should also be turned on. Go to Settings > Privacy & Security > Background Security Improvements, and make sure it’s enabled.

Configure App Store updates

The App Store is where you buy apps and acquire free apps, including those with in-app purchases, that have gone through additional layers of vetting by Apple. One advantage is that you don’t need to use the app or visit a website to check whether the latest version is installed.

On a Mac, the App Store has an Updates item in its left-hand navigation bar. Click that, and you can see available updates. You can also use App Store’s Preferences to control automatic updates: select or deselect Automatic Updates.

On iPhone/iPad, the default is for updates to be quietly updated in the background. You can change this in Settings > Apps > App Store, where you can disable App Updates. You can see the queue of updates waiting to happen in the App Store app: tap the account button in the upper-right corner and then tap App Updates. Any apps with pending updates appear under an Upcoming Automatic Updates label. You can force a check for updates by swiping down and releasing, and you can tap Update All to force an immediate app update.

Update everything else on a Mac

Software that didn’t come from the Mac App Store must be updated separately. Fortunately, most apps include an automatic, configurable update check whenever you launch them, and also check for updates periodically. You can disable this in nearly all apps, though I recommend keeping the feature on, or enabling it if it’s turned off by default.

If you haven’t seen update notifications lately, or aren’t sure how your favorite apps have automatic updates configured, now is the time to check. Launch each app, select its option to check, and install updates.

Some apps use “check for updates” as a way to sell you on a paid upgrade to the next version of the product. I don’t mind seeing this once or twice, but some software I use brings up a paid update available message at every launch; not cool.

How Apple numbers its releases

Starting with fall 2025 operating system releases, Apple reset their numbering system to the last two digits of the following year, starting with 26. So 2026 releases are iOS 27, iPadOS 27, macOS 27 Golden Gate, tvOS 27, and watchOS 27; and 2025 releases were iOS 26, iPadOS 26, macOS 26 Tahoe, tvOS 26, and watchOS 26.

The reason for the above change appears to stem from some extraordinary articles in the Wall Street Journal. In February 2023, the Journal published a story with an alarming headline: “A Basic iPhone Feature Helps Criminals Steal Your Entire Digital Life” by Joanna Stern and Nicole Nguyen. The article noted that individuals were reporting and police departments confirming that an increasing number of thieves were stealing people’s iPhones and coercing or extracting the corresponding passcodes through in-person methods. With the iPhone and its passcode, the thief could unlock an Apple Account using a loophole.

If you don’t enable Stolen Device Protection, you remain susceptible to this real-world exploit, and should read on.

How physical passcode theft happens

The Journal article details multiple kinds of attacks, the most prevalent of which is shoulder-surfing criminal teams, which involve one thief interacting with you and another surreptitiously watching you or recording you.

For instance, one ne’er-do-well might offer to take a couple’s photo. They take the picture, but then sneakily press and hold the volume up/standby button on the phone and tap Cancel (see how to set a stronger iPhone passcode) This requires a passcode to unlock, which someone might naturally enter. However, Stern explained on a podcast that tests with 4K iPhone video indicate someone could easily record your passcode entry from nearly across a room. Then it’s just a snatch-and-grab operation.

Even more disturbingly, the reporters interviewed a number of people who said they were physically assaulted and coerced into revealing their passcode and giving up their phones, or waking up believing they were drugged with their phone missing and later account issues. (The prevalence of druggings at bars has become something awful.)

The reporters explained a criminal can reset an Apple Account password with nothing more than an iPhone passcode and possession of the iPhone. At that point, if someone uses iCloud email with their financial and other accounts, the thief can send password resets and receive second factor SMS and device-based tokens to validate changes and logins. One victim, an economist, lost access to her Apple Account and everything attached to it, and told the reporters that about $10,000 vanished from her bank account within a day.

While Face ID and Touch ID can’t be used to extract your passcode and then reset your Apple Account, they can be used against you if you’re drugged, threatened, or in custody of a government that compels their use. See how to set a stronger iPhone passcode for how to disable Face ID or Touch ID quickly.

We don’t know the scale of these attacks, as there’s no comprehensive accounting and Apple hasn’t made a statement. Does it happen to hundreds of people a year in the United States—the article’s geographical focus—or tens of thousands? Because of that two-thief passcode approach, I’d put my money on hundreds to thousands where the passcode is obtained when an iPhone is stolen.

The Journal raised important questions about how tightly Apple has linked a passcode to the ability to log in to an Apple Account. That led Apple to create Stolen Device Protection.

None of this is the fault of crime victims entering their passcode in public or…being drugged or mugged. Rather, the person who stole from you—I mean, it shouldn’t even have to be said that it’s that person who did wrong.

Before venturing forth into the world:

  • Set a longer or more complicated passcode. This makes it harder for a thief to see or capture what you’re entering.
  • Enable Face ID or Touch ID. This prevents unsophisticated shoulder-surfer snoops. Coupled with the Stolen Device Protection option, it dramatically reduces your exposure to Apple Account and other data hijacking.
  • If you need to enter your passcode in public, make sure there’s no direct line of sight other than your own. Holding your hand over your phone or peering through your fingers is unfortunately not a ridiculous strategy. (I never enter my ATM PIN without holding my hand over the keypad.)

ATMs are also a prime spot for “skimmers” to be attached where thieves have a camera and sensor to grab your card number and PIN. Never use an ATM if anything around the keypad looks suspect, such as a raised external surface around any part.

  • Make sure Find My is turned on. This will help you later if you need to erase your device remotely.
  • Remove from your Photos library any images that show your passport, driver’s license, or Social Security number, or any other cards or information that contain numbers useful for information theft. (“Surely the writer of this book hasn’t left his…oh, no.” Deletes many images.)

This might deter most instances. But for best results, if you consider yourself possibly at risk, read on to enable Stolen Device Protection.

What to do after a theft

Stolen Device Protection doesn’t prevent robberies. If your device is brazenly or violently stolen, here’s what else you can do:

  • Access Find My: If you have access to Find My from one of your other devices right away, use a native app. Otherwise, you can use the Find My app on someone else’s device or log in to iCloud.com and use Find My there. (You have to have your iCloud password memorized or available through some backup method or other device, of course.)

Next, consider doing one or all of the following:

— Put the device in Lost Mode: If you have Stolen Device Protection enabled, putting your iPhone in Lost Mode could make it more recoverable as the thieves won’t be able to do anything useful with it. If the thieves haven’t powered down the iPhone or put it into Airplane Mode, it might immediately enter Lost Mode, or enter it the next time it has even the briefest internet connection. Because Find My is on, and the thieves can’t disable it, your iPhone retains Activation Lock, making it difficult or impossible to resell or reuse the phone.

— Erase the device remotely if it’s online: You can opt instead to try to erase your phone. If it’s online at any point, erasure is immediate, and Activation Lock remains on. In fact, it’s still trackable even after being erased with iOS 15 or later.

— Remove the device from your account if it’s offline: I recommend that if you don’t have Stolen Device Protection enabled and your iPhone is showing as offline, consider whether to remove the iPhone from your Apple Account on another device or via iCloud.com. This prevents Find My tracking, but it also halts iCloud syncing, so there’s a tradeoff.

  • Change your Apple Account password immediately: You may, ironically, need another trusted device connected to your account to do so.
  • Change important financial and email account passwords: If you don’t have Stolen Device Protection enabled, you should change critical passwords elsewhere; with it on, you might consider doing so anyway. After erasing or disconnecting your device, you can create new passwords they won’t have access to. (If you can’t erase or disconnect your device, turn off Passwords syncing in iCloud on your remaining devices.)
  • Call your phone company: If you haven’t enabled Stolen Device Protection, you can block your device from receiving SMS messages by calling your carrier. Have them remove the phone number from the SIM and disable the line temporarily at least. (If you wisely set a PIN for your cellular account, you’ll need that PIN to get the account locked, too.)

This experience can be scary. Theft and assault always is. If you can summon the strength to act quickly, you can minimize harm.

Automatic restart after three days

In late 2024, law-enforcement departments began to exchange stories of iPhones that had been unlocked and were kept carefully in that state in locked, shielded storage areas had spontaneously rebooted. While Apple didn’t make an announcement, iOS 18.1 apparently included a “reboot after inactivity” timer, according to reporting by 404 Media.

iPhones have two general states: Before First Unlock (BFU), which happens after a restart, and After First Unlock (AFU). An iPhone is easier to rummage through for investigative or illicit purposes in the AFU state, when its internal storage has been unlocked and other kinds of access remain available, even if some data remains protected by a passcode or biometrics.

Apple now apparently starts a three-day timer (as of 2026) when an iPhone is in the AFU state. If it’s inactive for that period of time, it restarts, putting it back into the harder-to-crack BFU state. Security researcher Matthew Green told 404 Media it wasn’t about blocking police access—but criminal use. He told them, “This feature means that if your phone gets stolen, the thieves can’t nurse it along for months until they develop the tech to crack it.”

Tags: iOS, Security

Many apps have startup activities you can manage. This includes launching an app when you log in and components of apps launching to run in the background continuously. From a security perspective, you should know what’s launching and occasionally check to see whether anything new has appeared that you’re unaware of.

Login items

Apps can add themselves to a list of items that open when you log in to your account. You can also add items manually. This Login Items list is unique to the current user logged in. It’s located in System Settings > General > Login Items & Extensions.

Your Mac uses a notification to let you know whenever an app adds itself or a component to the Login Items list.

You can take several actions on the items in this list:

  • Control-click/right-click: This reveals the Show in Finder option. Choose it, and the enclosing folder appears with the item selected.
  • Remove: Select one or more apps and click the minus button to remove them. There’s no prompt—it just happens.
  • Add: Click the plus button and then select one or more apps, documents, or network servers to open or mount at launch.

With Siri AI active in Golden Gate, the top item is Ask Siri, as with some other contextual menus, where you can ask or type in something like “What is Pastebot?” to know what a particular login item does or is. Unfortunately, you can’t just ask “What is this?” even though it’s on a contextual menu—Siri just replies with details about Login Items.

If you want to prevent all login items from launching, you can do so temporarily in one of two ways:

  • With a required user login: On the login screen, hold down the Shift key when clicking the login button. Keep holding down Shift until you see the Dock appear.
  • With an automatically logged-in user: Restart your Mac. Hold down the Shift key when the progress bar starts and release after you see the desktop appear.

Background activity

macOS also gives you insight into and control over components of apps that are set to run in the background. First, you’re alerted when an app installs them.

Then, you can find a list of these items in System Settings > General > Login Items & Extensions under the Background App Activity heading (or App Background Activity in Tahoe and earlier). The list provides additional information under each item that can be useful. In Golden Gate, the labels explain the item’s status, noting whether it is currently running in the background. If it ran in the background within the last week, the label notes how long ago that was.

In Tahoe, the label provided one of three pieces of information: how many components the background item represented (typically “1 item”), how many accounts it affected on multi-account Macs with an item breakdown (“5 items: 2 items affect all users” as one example), or whether it was from an unknown developer, typically the case when the app that installed it was no longer installed and the background item was orphaned.

Items that are installed without the full information required by Apple are shown with a magnifying glass button. Click it, and it opens the component in the system or user Library folder where it lives.

While you can’t remove background items via this interface, you can enable and disable them. When you disable background items, you’re prompted to authenticate with Touch ID or your password.

Launch components are divided into daemons, which run at system startup before an account login, and agents, which launch after login. They’re found in folders named LaunchAgents and LaunchDaemons in /System/Library/ and ~/Library/.

If you want more insight into and control over what’s automatically running on any release of macOS, do yourself a favor and get Lingon X. The app shows everything that launches automatically—apps, scripts, daemons, agents, and the like. A free version lets you view all that; paying $23.99 unlocks editing and saving.

Automatic login

When you set up a new Mac, one of the first things you are prompted to do is create a user account for yourself by picking a username and a password. (Your Mac can have many such accounts, but it must have at least one.) By default, macOS logs in that initial user account automatically when you turn on or restart your Mac. That means you can get right to work without entering a password, and it’s the most convenient arrangement for Macs with a single user—especially if the Mac is kept in a secure place.

However, if anyone else (including a thief!) can get to your Mac, that automatic login becomes a problem, because your keychain unlocks automatically (see how the Mac keychain works) and all the files on your Mac are readily available.

If there’s a risk of someone gaining access to your Mac, you should disable this option by selecting Off. It’s found in System Settings > Users & Groups as a pop-up menu next to “Automatically log in as.”

Automatic login is incompatible with the FileVault security model and can’t be enabled when FileVault is turned on, which is by default starting in macOS 26. See how to turn on FileVault.

Which apps are allowed to launch

Apple hides their powerful Gatekeeper technology behind a menu selection. Gatekeeper prevents malicious software from easily taking root on a Mac, even on a naïve user’s computer (not you, to be sure). You can find the setting “Allow applications downloaded from” in System Settings > Privacy & Security. The options are App Store & Known Developers (the default) and App Store, which is “App Store Only” but not labeled that way explicitly.

I recommend leaving App Store & Known Developers selected unless you’re setting up a computer for someone who needs more handholding and protection. For a full explanation of how Gatekeeper works, see how Gatekeeper decides which Mac apps can run.

Limiting your apps to the App Store may also be the right choice at a very high level of risk, where people or organizations may expend substantial resources to subvert someone’s computer. Few people fall into that category.

You can select a different option whenever you like, but it only affects apps launching after that point. Switch from App Store & Known Developers to App Store, and you can still launch any third-party apps you had previously run, but no new non-App Store apps will validate.

If you have the launch option set to App Store and attempt to mount a disk image with a third-party app, or open a downloaded third-party app or one copied from a disk image you’ve approved, a Mac first tells you why it can’t mount or launch it.

However, if you then return to the “Allow applications from” location in your version of macOS, you see a helpful Open Anyway button along with an explanation of why the app didn’t launch in the Finder. That’s a little informal, but it makes sense: you made this choice, so why not?

An administrative macOS user can lock settings to App Store here, and a regular macOS user won’t be able to override it. See how to set up safe user accounts on a shared Mac.

Manage system extensions

Apple lets developers extend the system with, er, the appropriately named system extensions, which run with relatively few privileges, but give developers controlled capabilities. Apple mediates access to system extensions through System Settings > Privacy & Security.

Up until a few years ago, Apple allowed a deeper way to modify core functions, but removed that method seemingly because of security concerns.

If you have no extensions installed and never install software that requires them, you will never see extra information there, and you don’t have to interact with those parts of the pane.

If you have an Apple silicon Mac, you’re blocked from using system extensions without first enabling Reduced Security for your system as described in how macOS protects its own system files. Read that first: the mode changes your Mac’s risk profile.

After you run the installer, a note appears with a button in System Settings > Privacy & Security. Click Details and you see a list of all system extensions.

Note that all the switches are disabled—you can’t take action here. Click OK, and, despite not seeming to have done anything, a system extensions cache rebuilding dialog appears. Finally, you’re typically prompted to restart in a non-modal dialog: you can’t opt out of restarting.

Because Apple requires no standard for removing a system extension, you could wind up with old ones littering your Mac and no sure way of what to do next. Sequoia added a distinct improvement in System Settings > General > Login Items & Extensions. You can view the list using By App or By Category. In both cases, the list mixes simpler macOS extenders (like additions to the contextual menu in the Finder or Quick Look) with system extensions. To disable an extension, click the info button for an app or a category, like Fantastical or Network Extensions, and then disable it.

However, if you want to uninstall a system extension, first choose By Category. Then, for a category with system extensions, like Camera Extensions, a More button appears for each item. Click that to reveal a menu from which you can choose Delete Extension. You’re warned when you disable or delete an extension that the extension may continue to operate until after a restart.

If you can’t find the item you’re looking for in that list, open Terminal and enter systemextensionsctl list and press Return.

The resulting output shows all system extensions and where you need to go to find them in the Extensions list. This list tells you exactly which Extensions category contains each component.

to find extensions’ configuration location.

Start by trying to find an app’s uninstaller or instruction on its website. Failing that, turn to Lingon X to dig out old agents, daemons, and extensions. It may not be able to help with all system extensions.

When you delete a file by putting it in the Trash and then emptying the Trash, you might think it’s somehow gone forever. But file deletion ironically doesn’t erase the file from your drive. It simply makes a change to the disk’s catalog indicating that the space occupied by that file is available and can be overwritten with something else if and when necessary.

As a result, even if you’ve deleted a file, someone using file-recovery software could potentially undelete it later, as long as no other file has been stored in exactly the same spot since then. (That someone may be you if you accidentally deleted the file and don’t have a backup.)

Hard drives may eventually overwrite the deleted file’s freed-up storage with new data, but that isn’t a guarantee that the previous file can’t be recovered. With specialized equipment, it’s sometimes possible to retrieve old versions of files that have been overwritten one or more times with new data. It’s painstaking, technically challenging, and expensive work—which means it would happen only when the stakes are quite high—but it can be done.

With an SSD, it’s even harder to ensure data is gone for good: SSDs use wear leveling, which spreads your data out all over an SSD, as opposed to the specific physical locations that are mapped on an HDD. Each memory cell in an SSD has a maximum number of times in its usable life that it can be erased and rewritten before it fails. Wear leveling ensures that the last previously written-to location is the least likely to be overwritten soon relative to any other location that’s available on the drive. SSDs also employ trim, which tells the controller that a given location is no longer able to be erased. With even more expensive gear than required for HDDs, data can be retrieved to an alarming extent from SSDs.

The good news is that with an Apple silicon Mac, all data on the startup volume is also encrypted by default. You only need to consider external SSDs that you use for storage.

If you’re still using external hard drives, you could conceivably securely delete removed file portions, but Apple dropped a feature for that years ago. However, you can encrypt external HDDs and you can securely erase them before getting rid of them using Disk Utility:

  1. Open Disk Utility, select the drive or volume, and click Erase.
  2. Click Security Options.
  3. Move the slider to the desired level of security and click OK, then click Erase. The slider has four notches:
    • Fastest: Regular erase, which doesn’t overwrite the data.
    • One-pass: Overwrite the data once with zeroes.
    • Three-pass: Overwrite the data three times, twice with random data and once with non-random data.
    • Most Secure: Overwrite the data seven times, meeting a U.S. Department of Defense standard.

The three-pass and Most Secure options can take a long time, and are necessary only in extreme cases, but if you want to make it all but impossible for someone to recover a file, you can.

Have the drive destroyed instead

Removable and external SSDs and HDDs can be sent out for secure destruction to outfits that receive licenses or certifications from various organizations. This includes some electronics recyclers who will use a drive crusher right in front of you. Some will give you a certificate that confirms the drive was destroyed. This is bad for the environment, but may be a valid choice if you have any concern about non-FileVault-encrypted drives’ data.

Apple Pay on a second volume

Apple allows Macs with a Secure Enclave and Touch ID enabled to store Apple Pay card information, so you can make purchases in apps and via Safari directly with your fingerprint. There’s no need to use a separate device. Setting up Apple Pay is straightforward, and handled via System Settings > Wallet & Apple Pay.

The security situation you may encounter, however, is when you set up Apple Pay either with another account on the same Mac or on an external startup drive! In the former case, Apple warns you in a notification. In the latter case, when you restart from your primary startup volume, your Mac also alerts you.

I saw both the above errors after restarting from an external bootable clone, because macOS interpreted both conditions as true.

Whether you set it up with a separate macOS user or an external volume, you can reset Apple Pay to work with your current main account with your current volume. However, it involves several steps:

  1. Open System Settings > Wallet & Apple Pay.
  2. Click the Add Card button.
  3. The Mac prompts you about changing back. When prompted, enter your password or use Touch ID to proceed.
  4. Select the cards you want to use and click Next.
  5. For each card, you will have to confirm details, such as entering your Apple Account password or the security code on the card. You will also have to accept terms and conditions for many cards, and receive two-factor authentication for some.

Even if Apple Pay is disabled, you can still use it in Safari by approving purchases on your iPhone or Apple Watch. Enable this option in Safari > Settings > Advanced, where you can select “Allow websites to check for Apple Pay and Apple Card.”

Advanced Data Protection (ADP) is an option to enable end-to-end encryption (E2EE) for iCloud-stored data from your Mac, iPhone, or iPad. ADP covers nearly all the data for which Apple previously lacked an E2EE option. (See how to share files with end-to-end encryption for a full definition.)

You can see a full list of the items that are encrypted at rest (on servers using keys Apple possesses) and those with E2EE enabled in iCloud on Apple’s website, both with and without ADP enabled. Without ADP, these items remain encrypted at rest only: iCloud backups, Freeform (Apple’s collaborative drawing tool), iCloud Drive, Apple Invites, Messages in iCloud, Notes, Photos, Reminders, Safari bookmarks, Siri Shortcuts, Voice Memos, and Wallet passes. Enabling ADP adds E2EE to all of them. (Apple Invites has exceptions; see note on the page linked just above.)

Email, contacts, and calendar entries can only be encrypted at rest due to interoperability with third-party services and apps.

I recommend enabling ADP if you qualify, as it provides a strong additional layer of protection for private data that you might consider “local” if you never access it via iCloud.com.

What ADP requires

ADP requires two-factor authentication on your Apple Account, which most accounts already have enabled due to Apple’s nearly mandatory policy. You also have to have passcodes on all of your devices—also, nearly universal. One requirement not everyone will have met: iCloud Data Recovery has to be turned on with at least one active contact or an Apple Account Recovery Key.

All your devices must meet minimum system requirements, which nearly every current device exceeds: macOS 13.1 Ventura, iOS 16.2, iPadOS 16.2, tvOS 16.2, watchOS 9.2, and—yes—HomePod 16.2. If you have any associated Windows computers, they must have iCloud for Windows 14.1 or later installed.

Apple says managed Apple Accounts and accounts set up for children cannot enable ADP.

An Apple Account Recovery Key is entirely unrelated to the FileVault Recovery Key. See where to find your FileVault Recovery Key.

Siri AI, Private Cloud Compute and conversations

Apple introduced Siri AI with iOS 27, iPadOS 27 and macOS 27, a more full-featured chatbot version of Siri on devices that support Apple Intelligence. Conversations with Siri are stored in the new Siri app and synced via iCloud. However, these are end-to-end encrypted sync operations, such as what’s used with Messages and iCloud Passwords. You don’t need to enable ADP, as described next.

To provide these enhanced services, Apple may send portions of your queries to what they call Private Cloud Compute. Private Cloud Compute consists of both servers they own and operate and servers in Google Cloud that Apple controls every component of, even though it’s not Apple hardware or in an Apple data center. You can’t prevent these requests from leaving your hardware, but Apple says all queries are encrypted end to end, untraceable back to you, impenetrable to Apple and any partners (even when debugging servers or code), and so forth. This is covered further in what Apple Intelligence, Siri AI and Visual Intelligence actually are.

Turn on ADP

Start by going to the ADP setting section: System Settings (Mac)/Settings (iPhone/iPad) > Account Name > iCloud > Advanced Data Protection. Tap Turn On Advanced Data Protection or click Turn On.

Apple now lets you turn on ADP:

  1. Apple warns you that “you will be responsible for your data recovery.” You have to click or tap the Review Recovery Methods option or Set Up next to an Account Recovery button.
  2. If you have Recovery Contacts, they’re shown. Click or tap Contacts Up to Date if they are or select Update Recovery Contacts if they are not to revise. Then return to step 1.
  3. If you have a Recovery Key, you must enter it and click or tap Next.
  4. With your recovery methods approved, enter your macOS account password or device passcode when prompted.
  5. Finally, you’re told, “Advanced Data Protection is On.” Click Done.

You should also receive an email to your iCloud.com address that tells you ADP was enabled.

If your devices aren’t all running the minimum supported operating system versions, you’ll be told which ones require an update. You can choose to upgrade all devices or remove one or more outdated devices from your account. Go to Settings/System Settings > Account Name, select a device, click or tap Remove from Account, and follow the prompts.

Reach your data on iCloud.com

With ADP enabled, all your data except email, contacts, and calendar entries is encrypted by keys held on your devices. That would appear to count iCloud.com access out. But Apple has a workaround. They allow temporary access using in-browser encryption.

First, you have to let yourself view the data on iCloud.com: go to Settings/System Settings > Account Name > iCloud. On an iPhone or iPad, tap iCloud.com and then Allow Data Access; on a Mac, click Data Access on iCloud.com and enable Allow Data Access. Confirm your choice; in fact, you have to confirm twice.

You can disable non-ADP access via iCloud.com using that setting, too.

With that enabled, here’s how to unlock temporary access:

  1. Visit icloud.com in a browser and log in.
  2. Apple shows a banner that explains that ADP is on and how to proceed.
  3. Select an app, such as Photos.
  4. Apple sends an access request to trusted devices. (If you don’t see the prompt, you can click or tap Request New Access.)
  5. On a trusted device, click or tap Allow Access.
  6. On your trusted devices, a banner appears alerting you that you’ve enabled temporary access.

Data remains accessible for an hour from each request. Each additional data type you want to access may require another permission request and approval unless requested shortly after a previous request.

Data previously unavailable on iCloud, such as Passwords entries and Health data, remains locked on devices.

The Find My exceptions

Until mid-2021, Apple listed Find My (Devices and People) as protected by their keys. When the company started to break out “in transit & on server” and E2EE, it dropped Find My from the iCloud page. Apple then stopped documenting the relationship of Find My with iCloud. That leaves it to me to try to explain.

The Find My Device web app is available at iCloud.com when you log in with two-factor authentication or a passkey. Even if ADP is enabled, you’re not asked to start a secure, device-approved session. Apple uses secure transit and their own keys to pass your location from your devices and those of people in your Family Sharing group who have shared location with you to your iCloud account. There’s no other way for that information to appear.

Apple doesn’t pass information about other people’s location, nor do they provide AirTag and other Find My item positioning, and thus I assume there is device-based E2EE involved in sharing that information among your hardware that Apple doesn’t want to override.

Turn ADP off

Disabling ADP is straightforward. Go to Settings/System Settings > Account Name > iCloud > Advanced Data Protection. Tap Turn Off Advanced Data Protection or click Turn Off. Follow the prompts to confirm you understand you’re removing E2EE protection from many of your synced and stored data.

Apple hides a powerful feature behind a menu in System Settings > Privacy & Security. That menu is the visible part. Behind it, Apple manages a good deal more to protect you against malicious software.

The point of knowing more is twofold: First, to recognize when something’s gone wrong. Second, to bypass protections in the limited cases in which you need to.

Manage app sources

The Gatekeeper feature was introduced years ago, and affects how you install and use software. Gatekeeper examines downloaded apps when they are first launched, including custom installers from a developer. (Apple has a generic installer that most apps rely on.) If you have set your app launch preference to App Store only, macOS tells you that you can’t open a given app. Click Show in Finder to reveal the app.

However, there’s a workaround if you want to be able to open just some of these apps. With Gatekeeper set to App Store only, go to System Settings > Privacy & Security. You will see this message: “‘App Name’ was blocked from use because it is not from an identified developer.” That much we know. But there’s also an Open Anyway button to the right of this message.

Click the button. Once that’s clicked, your Mac launches the app with a dialog that asks you to confirm you really, really want to open it. Click Open to proceed.

This App Store bypass seems clunky, but it’s consistent. If you have locked a Mac account down (for a kid, say, or a client or parent) without administrative permissions to make changes, this workflow for launching a non–App Store app still won’t let them. However, if you’re the captain of your own ship, this is a simpler set of steps than switching your Gatekeeper App Store preference to allow identified developers and then switching it back again.

Gatekeeper can also reject launching an app in these circumstances:

  • The app wasn’t notarized, an extra security check (explained below) that Apple made mandatory years ago.
  • You allow non–App Store apps to launch, but this app is unsigned, which means it hasn’t gone through the extra pass of validation described below, including notarization.
  • The app is or contains known malware or other harmful software, and Apple blocks it from running altogether.
  • Something is wrong with the app, such as it having been tampered with, so it won’t launch, and you will be warned.

Gatekeeper’s point is to prevent apps from running that, more or less, don’t digitally smell right according to multiple characteristics. It is worth understanding app signing and notarization to see what that buys you. If everything’s OK, your Mac launches the software.

Apple software and components always launch unless macOS detects they were tampered with. There’s no step to approve them.

For apps outside the App Store with Gatekeeper set to allow apps from identified developers, you still have one more step: you’re informed the app was downloaded from the internet and told that it was cleared for takeoff, but you must click Open to proceed. This may seem like overkill, but it’s one additional way that Apple ensures you haven’t been tricked into running software you didn’t intend to.

Apple also lets you know when an app is on a disk image instead of copied to your Applications folder, in case the disk image window tries to mislead you about its contents.

But wait! There’s more! If you do not check “Don’t warn me when opening applications on this disk image,” macOS…warns you when you open the application, requiring yet another click of Open.

If the app you try to run contains malware, Apple provides a unique warning, one I’ve never seen, and had to source from an Apple support note. This dialog also lets you report the item to Apple.

App signing and notarization

Each developer who has joined Apple’s $99-per-year Apple Developer Program receives a unique digital certificate that binds their identity with cryptography to prevent tampering and impersonation. When building an app in Apple’s Xcode development environment, the creator can use that certificate to sign the app.

This signature results from feeding the compiled binary version of the app—the actual code package you install and that runs—through a hashing routine, an iterative cryptographic process that produces a modest-length number (the hash) that appears innocuous. However, hashing is designed so that if even a single byte is changed in the entire source material (here, the app)—even if the number 8 becomes the number 9—the resulting hash is dramatically different. With modern hashing algorithms, there’s no way for a malicious party to modify an app, sign it, and get the same signature as the valid app.

Neat, huh? Hashing underpins a shockingly vast part of internet and real-world encryption, including all HTTPS web connections, secure email, and vastly more.

That hash is then countersigned by secret keys tied to certificates only Apple possesses, which lets macOS validate the signature and makes it impossible to forge the hash—otherwise, that would be a gaping loophole.

Notarization is a separate and distinct step that applies both to an app and any third-party components and libraries it makes use of. Notarized apps, non-Apple installers, kernel extensions, and other bits of code have been scanned by Apple for known malware and none was found. But it also includes other security scanning, such as ensuring apps and components are hardened, which means there’s no way for parts of the app to be swapped out by malicious software while they’re running.

The text that appears in the launch dialog for non-App Store apps confirms notarization: “Apple checked it for malicious software and none was detected.”

Apple requires signing and notarization for apps in the App Store and those distributed directly by developers. App Store apps also go through review by human beings for content and purpose, which is separate from these automated scanning and signing operations.

A signed and notarized app doesn’t look any different to us, as users, from an unsigned app (whether notarized in part or whole), but it contains extra data that lets macOS determine:

  • Integrity: Whether the app has been changed since it was built
  • Identity: Which developer created (and signed) an app
  • Access: Which system resources the app may access

Each of these attributes helps to protect your security.

Let’s start with integrity. If an attacker were to modify an app after it was signed—for example, inserting malicious code while it sat on the developer’s web server or even after you started using it—Gatekeeper would notice the change, as the hash wouldn’t match, and it would prevent the app from running.

Gatekeeper always prevents signed apps that have been altered from running, even if they ran fine before.

Next, suppose someone signed up for the Apple Developer Program and started delivering malicious software, signed with their certificate. The identity feature kicks in—once Apple discovers that the developer is distributing dangerous software, Apple can revoke that certificate, telling Gatekeeper not to let any software signed with that certificate launch. Gatekeeper checks Apple’s revocation list every time an app launches to make sure it’s still valid.

A malicious party using a legitimate certificate isn’t a hypothetical situation, though it’s rare in practice. In 2017, a phishing message convinced people to download and open a ZIP file, then launch an app inside it, and further conned them into entering an administrative password. The ne’er-do-wells had signed up for a developer account, and the app was signed. Apple revoked the certificate, defusing its potential.

The third aspect, access, involves system resources such as the keychain. If you grant an app permission to store information in the keychain or access it afterward, you don’t want to have to keep doing so every time you update the app.

But if you install a new version of an app that was signed with the same certificate, Gatekeeper treats it as the “same” app for the purpose of granting access to system resources, and you won’t be prompted for keychain access again.

Conversely, if someone altered the app or gave you an unsigned and therefore unauthorized version, it wouldn’t be able to access your keychain without your permission—in fact, Gatekeeper should prevent it from launching at all, because it won’t pass the signing test.

All of this reduces your risk of inadvertently running malicious software. If an app is not in the App Store and has not been signed and notarized, there is one way to bypass Gatekeeper.

Beware bundled adware

A slimy practice that peaked a few years ago was for download sites to take otherwise safe and trustworthy software from someone else and wrap it in their own custom installer with a type of malware known as adware—which, among other things, displays intrusive ads, even if you block pop-up windows and use ad-blocking browser extensions in your web browser. Here’s how to protect yourself:

  • Avoid free software download sites. If the app isn’t in the Mac App Store, download it directly from the developer. (The sole exception is Setapp, a multi-developer subscription service that has a single app that can install multiple apps for you.)
  • Don’t override Gatekeeper unless you’re sure it’s from an absolutely trustworthy source.
  • If an installer asks if you want to install any extra software (especially if it’s “sponsored”) or browser extensions, or make changes to your browser settings, say no.

While the problem seems to have waned for many years, I still receive scattered emails messages from readers who have installed adware without intending to. Be vigilant about the source of your software.

One of the most unsettling things that can happen to your device and your data is when you are locked out from your computer. It’s rare, and you can prepare against the possibility so that your recovery is quick—or at least feasible, if not fast.

An ounce of prevention saves a kiloton of cure when it comes to accounts and access. If you follow the following advice ahead of time, you can avoid serious downtime and loss of data.

Keep fresh backups

Backups are the strongest protection you can have against theft, destruction, and loss, including “loss of access.”

If you have daily backups of your Mac and attached drives onsite (via Time Machine or third-party software), copies of your startup volume and external drives offsite, active continuous or daily cloud-hosted backups, or use a sync service to ensure multiple copies and a version history of your active documents, losing access to your Mac still has a sting, but you likely will lose very little data, if any.

You could be like me and do all four. But that’s me.

In some cases, you might be locked out of your current Mac, such as with a FileVault failure or the loss of a Recovery Key. In those cases, you can erase the computer and restore from a full backup, putting you right back in business. Or you may be able to use an external drive or synced files to get back to work on another machine—perhaps a borrowed one—while you plot unlocking the Mac you can’t get to.

Macs that support Activation Lock and have it enabled by turning on Find My Mac require that you can log in to your Apple Account to erase the computer. See how to reset a forgotten Mac password.

With an iPhone or iPad, your biggest job is ensuring you have enough storage in your iCloud+ plan to allow iCloud backups. You can also use a Mac for device backups, but that dramatically increases the odds you’ll be out of date and missing data. With automatic iCloud backups enabled and using iCloud Photos, it’s unlikely you would lose any data—at worst, very little.

Where to keep your passwords

You should have a go-to, secure place for all passwords, passkeys, and other login and encryption keys you may need in the event of a disaster, including:

  • Passwords for one or more administrator accounts on your Mac
  • Passcodes for any iPhones or iPads
  • The Recovery Key for macOS’s FileVault; see where to find your FileVault Recovery Key
  • The account name and password or passkey (or hardware security keys) for your Apple Account (or Accounts)
  • The password for your password manager (which may be the sole item you memorize, and you may also provide a copy to a lawyer, sibling, or trusted party to hold securely)

This secure password repository should preferably be available from a device or location that isn’t tied to where you keep your hardware.

Check your trusted devices and numbers

With two-factor authentication (2FA) enabled on your Apple Account, you might be locked out permanently if you lose access to trusted devices, and trusted phone numbers for SMS and automated voice calls, or can’t find hardware security keys that can be used with an Apple Account.

If you’re using hardware security keys with your Apple Account, Apple already requires that you associate two of them with the account. Always keep one in a place you can get to in an emergency in case the other is lost or destroyed.

Any Apple device logged in to an iCloud account with 2FA active is a so-called trusted device. You can tell that this is working when you try to log in via a browser to the Apple Account website, as every trusted device will display a notification for the 2FA code needed to confirm the login.

If one of your trusted devices doesn’t show that message, check in System Settings/Settings > Account Name that you’re correctly logged in and that you see all the associated devices you expect. If you still can’t get your Apple Account to message trusted devices or the list of devices is missing, you may want to log out of your Apple Account on affected devices and then log back in.

This can take a while and prompt you to answer a lot of questions about synced data—the answer for most is “keep data stored on this device.” When you log back in to iCloud on the device, you agree to merge data, which should avoid duplication and deletion.

You should also check that trusted phone numbers are still properly registered:

  1. Log in at the Apple Account website. If you have Touch ID or Face ID active, click “Use a different Apple Account” and then enter your ID and password.
  2. Instead of entering a 2FA code, click or tap “Didn’t get a verification code?”
  3. Click or tap Text Me. (This will be labeled differently if you marked any or all trusted phone numbers as receiving automatic voice calls instead of text messages.)
  4. Select a trusted number if more than one is available; if only one, Apple texts that number.
  5. Enter the code that’s sent or use the AutoFill option in Safari.

If you never receive the code, log in with a trusted device, check the phone number, and remove and add it. I also recommend having multiple trusted phone numbers as backups.

Changing your phone number has a huge impact in the era of 2FA. You should instead try to transfer your old number to another phone temporarily so you can switch the number listed for various accounts’ 2FA and for iCloud trusted phone numbers.

If you have willing friends, colleagues, or families, having their number as a backup in case your phone isn’t available doesn’t really reduce security, as they would need to know your Apple Account username and password to compromise your security.

Put a PIN on your carrier account

Add a PIN (if you don’t already have one) for account access to your wireless carrier or enable the highest security available for an increasingly rare wired home phone line. Someone who could obtain codes from your phone number might be able to reset your Apple Account and then access iCloud information. (Enabling Advanced Data Protection is one way of preventing that.) Because of accessibility, codes can often be sent both by SMS and by an automated voice system that speaks the code.

Crackers often target people and combine social engineering and easily available online information to convince a customer-service representative that they are the legitimate account holder to get a phone number migrated to a new phone. (Are you likely to be targeted? See whether you need more security than Apple’s defaults. Yet someone may target your account at random to launch attacks.)

The PIN sets a higher bar, because a cracker might have your phone number, financial details, and other information, depending on data breaches floating around.

Keeping your security keys safe

You should treat hardware security keys as if they were irreplaceable keys to the castle—like a passphrase for a cryptocurrency wallet or a password for a vault that self-destructs when you’re one number off in a Dan Brown novel. They’re extremely secure, absolutely vital, and also can be used by other people!

Apple requires that you enroll at least two hardware security keys for an Apple Account. Most sites only require a single hardware key, or won’t let you enroll more than one. If you lose the key, most sites offer a workaround that requires more forms of validation to gain access. Apple does not.

If you can’t find your hardware security keys (or they’re irretrievable, stolen, or busted), but do have access to any of your Apple devices, you can go to Settings/System Settings > Account Name > Sign-In & Security > Two-Factor Authentication > Security Keys and remove all hardware security keys. This requires your device passcode or macOS account password if Stolen Device Protection is disabled, or Touch ID or Face ID if that feature is enabled. Then you can use code-based 2FA to log in to your Apple Account. You can choose to add new security keys if you want to re-enable that level of account security.

Apple has a significant flaw in hardware key management: you can remove all the keys from your Apple Account on an iPhone, iPad, or Mac using only the device passcode or the macOS account password. I feel Apple should demand additional information or another hardware key on the account, since the keys are meant to provide an extra-high level of security.

Enabling Stolen Device Protection requires Face ID or Touch ID to remove all keys. So if you’re concerned about someone gaining access to your device and its associated device or account secret, enable that feature. See how to turn on Stolen Device Protection.