Got a tip for us?

Security

Apple’s iCloud Drive is integrated into macOS, iOS, and iPadOS, and lets you use your free or paid iCloud space to store and share files.

A shared folder requires an Apple Account to access, and the contents are all accessible to whomever is invited or has the link, depending on the permissions you set. Up to 100 people can be invited to a folder. Only folders you create can be shared—not ones that Apple manages or that are created for apps. Storage space is occupied only in the sharing party’s iCloud account, which makes it handy if other people don’t have large iCloud storage subscriptions.

iCloud Drive appears in macOS by default as an item in the Finder window sidebar. You can select it there, or you can choose Go > iCloud Drive or press ⌘-Shift-I. On an iPhone or iPad, use the Files app.

With Advanced Data Protection enabled, iCloud data is secured end-to-end among your devices. It’s also E2EE secured with devices of anyone with whom you share if you all have ADP enabled.

Share a file or folder in iCloud Drive

  1. Select the items to share. On a Mac, Control-click or right-click any file or folder stored in iCloud Drive, or select several and Control-click one of them, then choose Share from the contextual menu. On an iPhone or iPad, touch and hold a file or folder and choose Share; or tap the More button, choose Select, tap the button beside each item, and tap the Share button.
  2. A share popover appears. Choose Send Copy or Share a Link from its pop-up menu. Send Copy sends a download link and has no further options. Apple renamed several of these labels in iOS 27, iPadOS 27 and macOS 27 Golden Gate; the functions are unchanged, and earlier releases call this Collaborate.
  3. If you choose Share a Link, set the permissions by clicking or tapping the text below that label:
    • Under Who Can Access, choose “People you choose” to limit access, or “Anyone with the link” to open it up. Earlier releases call the first option “Only invited people”.
    • From Permissions, choose “Can edit” for read and write access, or “Can view or download” for read-only. Earlier releases call these “Can make changes” and “View only”.
    • Enable or disable “Allow access requests”, called “Allow others to invite” in earlier releases.
  4. Select people or groups from recent interactions in Messages and elsewhere, or click one of the options, like Mail or AirDrop, to share the link.
  5. Complete the process in the dialog, sheet, or app prompt that appears. If you copy a link in the 27 releases, you are warned that sharing with a group means approving access for each member; you can proceed, or choose Allow Anyone with the Link instead.

Once shared, the item is marked in the Finder or the Files app:

  • In macOS, you can opt to show a Shared By column in the Finder. It may be enabled in some iCloud Drive views. If not, and you want to turn it on, choose View > Show View Options and check Shared By. With that column active, you see Me for you or the name of the sharing party for files or folders shared by others. All files that aren’t shared show Not Shared, which feels like overkill.
  • In macOS with the Shared By column disabled and in iOS/iPadOS, you see a label next to a file in the Finder or next to or beneath it in the Files app that reads Shared by Me if just a link is used or an invitation hasn’t yet been opened. The label displays With Person or People when an invitation is accepted. The last person to modify may appear instead, such as Modified by Dave Johnson.

To make changes, the easiest way to access these shared items is via the Shared view. On an iPhone or iPad, tap the Shared button in Files; on a Mac, choose Go > Shared in the Finder (⌘-Shift-S). Select the items as above either in the Shared view or by choosing the same set of original items. Touch and hold on an iPhone or iPad or Control-click/right-click to reveal the Manage Shared Folder item.

Choose Manage Shared Folder to reveal a dialog that shows the sharing details. You can see with whom the item is shared, and you can remove and add members (if you have permission), change permissions, or change invitation parameters. If and when you’re ready to stop sharing, click or tap Stop Sharing.

iCloud.com allows similar options for sharing files, although the sequence is a little different and options are far more limited:

  1. Log in to iCloud.com and click iCloud Drive.
  2. Select a single file or folder and then click the Share File or Folder button. Email and Copy Link destinations are available.
  3. Click Share Options to access permissions that are identical with those found on an iPhone, iPad, or Mac.
  4. When you’ve made your choices, click Share.

Dropbox

Dropbox is an exceedingly popular service for simple syncing across devices that offers several different ways to share files with strong controls on access. It has integrated macOS support, as well as full-featured apps for iOS/iPadOS and other major platforms, and a sophisticated web app.

On a Mac, Dropbox uses Apple’s framework for cloud-storage providers to add icons to the right of files and folders in the Finder in its folder. The Dropbox folder is the only one that’s synced, and it’s located by default in your home folder. Files and folders may be online only or online and stored locally.

Some features require a paid Dropbox subscription.

Control-click or right-click a single file or folder inside the Dropbox folder on a Mac or tap the More button to the right of a file or folder in the Dropbox app for iPhone/iPad. You can now access several options by choosing:

  • Share: This opens a dialog or sheet with extensive options to let people have access to a file or folder. You can invite people, create publicly available or password-protected links for sharing, and set an end-date for access. Use this option for sharing items that you want people to have ongoing access to, particularly for folders that you might optionally want to let people drop items into or modify. (Shared folders count against other people’s Dropbox storage limits.)
  • Transfer a Copy: Dropbox lets you send files without providing any access to your Dropbox space. The transfer can be password protected and have an expiration date. On a Mac, you use the contextual menu; in the iPhone/iPad app, you start in the files view and tap the plus button, then select files to transfer.
  • Copy Dropbox Link: Choosing this on a Mac (or via the Share > Copy link pathway on an iPhone/iPad) creates a public link that anyone who has it can use to download the particular item. For certain kinds of files, like images and PDFs, the link allows viewing inline on a website, too.

Google Drive and OneDrive

Two other major firms’ apps don’t offer file-level Finder integration, but can sync files automatically and provide Mac access via a web app. Both also have iPhone/iPad apps.

The advantage of both is that you might already have paid for storage:

  • Google Drive: Google Drive provides access to the 15 GB of free storage available for all Google individual accounts or to the larger pool of paid Google One tiers that start at 100 GB for $19.99 per year. Business accounts include a higher starting storage allocation. Google allows public and invitation-based links with varying permission, but doesn’t offer setting an expiration date.
  • Microsoft OneDrive with Microsoft 365: Anyone can get 5 GB of file storage (plus 15 GB of email storage) in Microsoft OneDrive by setting up a free Microsoft 365 account. For $1.99 a month or $19.99 a year, you can upgrade to Microsoft 365 Basic with 100 GB each for files and email. At $9.99 a month or $99.99 a year (one person) or $12.99 a month or $12.99 a year (up to six people in a family), Microsoft 365 Personal offers 1 TB of file storage and 100 GB of email per person. The Personal plan also adds access to desktop Microsoft apps. OneDrive’s sharing options are comparable to those of Dropbox, with options for sending invitations, creating a public link, and setting an expiration date for the link.

You might wonder why anti-malware software is not on the list of things to install on a Mac. After decades of using anti-malware software, some of it quite sophisticated, I don’t think any package’s benefits outweigh the cost in terms of price, false positives, and system load.

Anti-malware software has a distinct weakness: it can’t protect against unknown threats. It’s 100% designed to keep out-of-date systems protected from well-known viruses and the like, and to safeguard an up-to-date system as quickly as possible from malware that has just been discovered and characterized. If you keep your Mac up to date and never install software of any kind from the internet (besides the App Store) or software handed to you by other people, you can probably forgo anti-malware software, as it has no real path to find you.

For everyone else, it’s worth considering. While a portcullis doesn’t protect a castle when it’s open, cutting the rope and dropping it is an effective way to keep hordes from rampaging through that front door. Likewise, automatic updates and scanning are terrific ways to ensure you aren’t caught out by a prior or current exploit.

What antivirus software cannot catch

You’d think with all the AI in the world and decades of research about viruses, there should be a way to detect malicious behavior and shut it down. And yet that’s still largely a dream, with one exception for ransomware that I describe below.

Instead, anti-malware software’s virus-protection portion largely relies on the same technology it has for decades. A hash is made of a malicious payload—in just the same way that Apple creates a cryptographic summary of legitimate software—and stored in a list. When the anti-malware app scans a drive for bad actors, it generates a signature of each item it finds and compares it against its stored list, which is frequently updated.

The best current anti-malware software helps you with five distinct issues:

  • Known malware: Blocking already known and extant malware, including routinely scanning files on your Mac, volumes you mount on your Mac, and attachments that arrive via email
  • Phishing websites: Blocking phishing websites and those that host links to malicious software, either loaded in the browser or as downloads
  • Behavior alerts: Identifying dubious behavior that might be fine, but you should review to be sure, such as opening a file or accessing a folder in an unexpected location

macOS requires you to grant permission the first time an app attempts to access files in certain locations, which is a coarse but useful version of this. See how to control which apps use your Mac camera and files.

  • Ransomware: Blocking ransomware activities based on the way that ransomware functions, discussed below
  • Windows malware: Preventing you from passing Windows viruses on to someone else

Ransomware is the exception

Ransomware is the odd one out in this whole discussion. While being the biggest likely threat to Mac users, it’s also by far the easiest to track. Ransomware operates by suddenly creating a mass of new, encrypted files and deleting ones with similar names. It’s rarely sophisticated; it just has to be launched by a user or through some method that lets it insert itself and run.

Some anti-malware software can detect this broad category of behavior because it’s so specific, and can lock down folders and prompt your response before more than one or a handful of files are locked away.

Windows malware on a Mac

macOS can’t run malware that’s written for Windows machines, so even if a Windows virus appeared on your drive, it wouldn’t do any damage; it would simply be inert.

Mac anti-malware apps, however, do identify, quarantine, and remove Windows malware, because of the chance you might pass it on via email or as part of an infected Microsoft Office document to someone else who uses Windows.

And even though macOS isn’t Windows, you can run Windows via virtualization software like Parallels Desktop. Mac anti-malware software won’t protect you there, so you should absolutely run Windows anti-malware software within your Windows installation.

Because FileVault prevents direct access to your data volume at startup, turning it on requires a backup plan. That backup plan is the FileVault Recovery Key. This key is a precious object that you should treat like the gold that it is virtually made of. If anything were to go wrong with the boot portion of your Mac’s operating system, or in the unlikely event you forget the password to your computer’s account, the only way you can decrypt the drive is using the Recovery Key. Without it and any accessible backup, its contents are truly gone for good.

This Recovery Key is entirely unrelated to the Apple Account Recovery Key, used to regain access to your online account.

When you need a Recovery Key

You should only ever need to use your Recovery Key if you attempt to log in with your macOS account password or username and password, and macOS refuses to let you proceed. In such cases, you should see text that reads Reset Password with a right-pointing arrow to its left. You can also bring up that link right away by clicking the question-mark button to the right of the password field. Follow the instructions to reset your password with the Recovery Key.

Apple has historically had two different ways it manages the Recovery Key. The first lasted for several years, through Tahoe. The second, in Tahoe and later, was optional through version 26.3. It’s mandatory starting in 26.4 and Golden Gate.

The older method is worth understanding if you set up FileVault years ago; the newer one is much safer.

How to view the key

With Tahoe, Apple made three key changes:

  • View anytime: You can view the FileVault Recovery Key at any time after it is created—it’s no longer shown just once ever.
  • No iCloud account escrow: Simple iCloud escrow is no more.
  • Recovery Key in Passwords: The FileVault Recovery Key is added to Passwords. If you have Passwords syncing enabled with iCloud, the key is synced using end-to-end encryption—not simple Apple Account access—among your devices.

If you didn’t interact with FileVault when upgrading to Tahoe or installing 26.1, 26.2, or 26.3, you will be forced in a simple process when you install 26.4 or later, or upgrade from any pre-26.4 version of macOS to Golden Gate. I recommend upgrading manually in 26.0 to 26.3, using the steps below.

In System Settings > Privacy & Security > FileVault, you can click the Show button, validate with Touch ID or a password, and display the key in full.

You can also view the key in Passwords.

In the initial iOS 26/iPadOS 26 release (or maybe the first few), the Recovery Key synced to iPhones and iPads, appearing in the Passwords app, but lacking any information except the Recovery Key label and the key itself. Apple fixed this in a later update, ensuring the information appears identically on all platforms.

Even though the Recovery Key now syncs via iCloud, you could still wind up with a problem:

  • With Passwords, if you lose access to all your devices besides your Mac, and it cannot start up using your password, you need another way to access the Recovery Key. Storing it in Passwords is not enough given the consequences of not having it.
  • If you don’t use Passwords, you must use another password manager or some other secure method to make sure you can access it if your Mac becomes unavailable.

Check an older key still works

If you set up a locally stored Recovery Key before Tahoe, you can use a Mac command-line tool to validate that the Recovery Key you have on hand is truly accurate without trying to reset an account password. In Terminal, enter sudo fdesetup validaterecovery and press Return.

At the prompt, enter your administrator password, and then paste or enter the Recovery Key. If the result is anything but true, try re-entering. If it continues to produce false or an error, it’s time to reset FileVault.

If you want to disable FileVault, rotate your Recovery Key (because it was exposed), or upgrade to the new method in Tahoe 26.0–26.3, follow these steps:

  1. Go to System Settings > Privacy & Security > FileVault and disable FileVault.
  2. Click Turn Off Encryption.
  3. Use Touch ID or enter your password, as prompted.
  4. “Decryption” may take a moment; really, it’s making a few low-level changes in the startup partition. Stop here if you simply wanted to disable FileVault; otherwise, proceed.
  5. Now, re-enable the switch. If it’s been more than a moment since you carried out step 3, you may be prompted to use Touch ID or enter your administrator password.
  6. “Encrypting” may appear for a moment as macOS rewrites the startup information. There’s no additional action you need to take.

Unlocking remotely, as a last resort

Starting in Tahoe, Apple added an option to enter a Recovery Key via SSH if Remote Login is enabled on your Mac and it’s connected to a network. This could be useful in desperate circumstances, where you’re unable to type directly on the Mac, or it’s located in a hard-to-reach location. Whatever the reason, consider enabling Remote Login if you’re concerned, as described in which Mac sharing services are safe to turn on.

What Apple changed, and why

Before Tahoe, Apple let you choose between two options:

  • Store locally: The key was generated, displayed to you, and never stored anywhere. You could never retrieve it after seeing it once.
  • Use escrow: The key was securely stored in your iCloud account.

I never liked the iCloud option much, though it was less scary than a “show once, lose forever” local key. However, iCloud escrow had three implications:

  • If you somehow lost access to your iCloud account, the key was not retrievable. (If you could still log in to your Mac, you could disable FileVault and re-enable it to generate a new key you stored locally.)
  • If someone gained access to your Apple Account credentials, they could unlock a Mac you own that they have access to by using the FileVault recovery process.
  • A government agency, rightly or wrongly, could have forced Apple legally or extrajudicially to provide this key for a device they had seized or otherwise obtained. To my knowledge, this has never occurred, but it’s possible Apple would have been constrained from revealing it in any country in which it occurred; that seems unlikely given the company’s stance on encryption and privacy.

Apple’s operating system and cloud security teams must have had thoughts like this when they revamped Recovery Key access in Tahoe.

macOS has many privacy and security settings that can be turned off or tuned, reflecting in part how you interact with a computer versus a mobile device. Let’s start with System Settings > Privacy & Security, which collects several controls and options. I also mention settings in Users & Groups, and Lock Screen, and in the Keychain Access utility, that deserve a quick look.

There is more on FileVault separately.

Unlock the pane or setting

Apple requires you to prove your identity when accessing more sensitive elements of System Settings. First, click a setting, like changing “Allow applications from” to App Store. Now:

  • Touch ID: If you have Touch ID, you’re prompted for biometric authentication. You can also click Use Password to enter your account password, then click Unlock.
  • No Touch ID: You’re prompted to type in the administrator password. Enter it and click Unlock.

Some settings, such as Users & Groups, prompt for your administrator password even when Touch ID is enabled.

With an Apple Watch, you can also unlock many settings by using a side button double-press. Go to System Settings > Touch ID & Password and enable your Apple Watch under “Use Apple Watch to unlock your applications and your Mac.”

That option also lets your Apple Watch unlock your Mac’s screen, as described below.

Require an unlock for all preferences

You can force yourself or users of the Mac to have to unlock all preferences before using them. Click the Advanced button in Privacy & Security, and then select or enable “Require an administrator password to access system-wide preferences.” Items like Sharing settings can otherwise be used without an administrator password.

Settings > Touch ID & Password and System Settings > Lock Screen offer two additional password-related features worth examining.

Adjust password preferences

In Touch ID & Password, the top of the setting says “A login password has been set for this user” if you set one. Click Change to update it.

You should always have a password set for your Mac, even if you’re the only person in your house, because a password to access your computer is a fundamental building block of security. If someone accesses your computer without your permission or steals your computer, you want at minimum this level of protection.

Once you change your password, you can’t use the old one again. While that might seem obvious, Apple added a grace period starting in iOS 17/iPadOS 17: change the passcode on an iPhone or iPad and you can still use the old one for 72 hours. Apple never added this to macOS, possibly for unknown security reasons.

In Settings > Lock Screen, select Immediately from the “Require password after screen saver begins or display is turned off” to, you know, do what it says on the label: force your Mac to lock when it goes to sleep, or when the screen saver activates and a period of time passes. You can also set it to wait for durations from 5 seconds to 8 hours.

How to sleep or lock your Mac

Apple offers lots of ways to let or force your Mac to go to sleep or initiate its screen saver. Here are several:

  • Turn display off on…when inactive: In Settings > Lock Screen, you can set “Turn display off on [battery, power adapter] when inactive” to durations from 1 minute to 3 hours or Never. “Battery” and “power adapter” appear separately on laptops; only “power adapter” appears on desktops.
  • Screen saver: Go to System Settings > Wallpaper, click Screen Saver, and use the “Start Screen Saver” pop-up menu. Choose a duration greater than Never for how long your Mac must be idle before the screen saver activates.
  • Lock screen menu: Choose Apple menu > Lock Screen, and either the lock screen appears or the screen saver, depending on your settings. You can also press ⌘-Control-Q.
  • Hot corner: Assign Lock Screen or Start Screen Saver to an action in System Settings > Desktop & Dock > Hot Corners. Each corner may have a different action assigned from a diverse list.

When you return, you can enter the password; or, on Macs with built-in or keyboard-based Touch ID enabled, unlock with Touch ID. See how to set up Touch ID and Face ID.

Touch ID may be disabled in certain circumstances for added security. See when biometric lockout happens.

You can choose Never, but I’d suggest…never doing this. Nearly everyone should pick Immediately or a short time duration—otherwise, every time you walk away from an active Mac, anyone with physical access can jiggle the mouse or touch the trackpad and access your stuff.

You can crank that up a notch if you’re at higher risk of physical access or theft: click the Advanced button in Privacy & Security, select “Log out automatically after inactivity,” and enter a duration in minutes. The Mac logs you out of your account after that period passes, raising the bar for a physical break-in. While the lock screen should be sufficient, background apps and other settings are in effect that could make your machine slightly more at risk than if it’s in a logged-out state.

If you have an Apple Watch, an iPhone, and a Mac signed in to the same iCloud account, you will have an additional option in System Settings > Touch ID & Password: “Use your Apple Watch to unlock your applications and your Mac.” Any Apple Watch that meets the preceding criteria appears in a list, each with its own switch. Enable one (or more) if you want your Mac to be automatically unlocked when it’s locked, you’re close by, and you’re wearing your watch. This setting also lets you unlock apps that require Touch ID via your Apple Watch, including the Apple Passwords app, and some system features.

Just tap the keyboard, keypad, or mouse as if you were jostling it to get it to show you a password dialog or a Touch ID prompt, and the Apple Watch and Mac have a conversation. Bluetooth and Wi-Fi must be enabled on the Mac for it to work.

Conversely, you might find unlocking your Mac with an Apple Watch is a security risk if you are subject to targeted attacks by a government or individuals.

Optionally, you can have a message appear on a lock screen. In Settings > Lock Screen, enable “Show message when locked,” click the Set button, enter a message, and click OK. This message can be useful if other people use the same Mac and you want to alert them as to why it’s idle.

I have my Mac in a day-lit basement office. Sometimes, I’ll be walking across our main floor, and my Apple Watch lights up that the Mac was unlocked a floor below!

Control what can be plugged in

Apple has options that can prevent peripherals, computers, and other accessories from connecting over built-in ports, like USB (Type-A and USB-C), Lightning, and SD Card, depending on your device. You can prevent peripherals from connecting via Lightning, Thunderbolt/USB, or the Smart Connector (for an iPad Smart Keyboard), or allowing a card to mount via the SD Card slot without permission.

Go to Settings/System Settings > Privacy & Security > Wired Accessories (iPhone/iPad)/Accessories (Mac). Modify the Allow Accessories to Connect setting. You have four options:

  • Always ask
  • Ask for new accessories
  • Automatically allow when unlocked
  • Always allow

In any case in which you have to grant permission, you must enter your administrator permission—Touch ID or Face ID, even when available, isn’t considered a high-enough bar.

Starting in macOS 26 Tahoe, you can also choose a security policy for accessories at startup. You can use this to prevent peripherals other than drives from interacting with the system before a macOS session has started.

First, restart into recovery mode; see how macOS protects its own system files. Next, choose Utilities > Startup Security Utility. Now, choose an option as above from the “Allow accessories to connect” menu.

With all that in mind, you might wonder: what should I open for use and what’s safe? The answer depends on whether your Mac has a public IP address. I advise always turning on only the services you need. A few are worthwhile, and how you configure them depends on your circumstances.

But you should have different considerations under these sets of circumstances:

  • Privately addressed Mac on a network in which all users are trusted: If you’re by yourself or you trust your roommate and family to not attempt to access things they shouldn’t, you can enable what you like and just configure for general safety.
  • Privately addressed Mac on a network in which not all users are trusted: If you share a network with other people—which could include kids or parents who may not be as safe or honest with you as you might like—consider locking things down further and using the fewest possible services.
  • Publicly addressed Mac: You need to take more care to set passwords and configure limitations, and to consider whether to leave services active all the time or only when you know you or someone you trust needs them.
  • High-risk individual or group: People who believe themselves at elevated risk shouldn’t operate any services on public addresses, and should think strongly about not running them even on privately addressed networks. It’s very easy for so-called Internet of Things (IoT) or “embedded devices” to be compromised. That can include DVRs, routers, smart home gear, and more. A subverted device on your local network can have the same access as anyone else on the network.

With that in mind, here are the items in System Settings > General > Sharing worth enabling or disabling. Configuration options appear when you click the info button next to a service.

Don’t allow all users

Several services let you selectively enable them. Apple offers a choice of “Allow access for” either “All users” or “Only these users” for most services. File Sharing has more fiddly options. I recommend setting access for Screen Sharing and any service starting with Remote to Administrators (often prefilled), or, better, selecting users or groups you’ve created. This limits exposure in the case of an intrusion that doesn’t gain direct access to your macOS account.

Screen Sharing

If you have a “headless” Mac (one without a monitor) that you use for various services, or machines in different parts of a house or office that you want to access remotely, screen sharing is handy.

I recommend deselecting two options in the Computer Settings dialog:

  • Anyone may request permission to control screen: There’s no reason to allow this except momentarily if you want to allow someone to request access.
  • VNC viewers may control screen with password: VNC is an outdated protocol that Apple’s screen-sharing technology extends with more security and features. There’s no good reason to keep this option turned on, particularly because VNC passwords are notoriously easy to crack.

File Sharing

The File Sharing service on a Mac offers fine-grained controls to choose which folders and volumes are accessible to which people, including the type of access: read/write, read-only, or write-only (to drop items into without seeing the shared item’s contents).

In configuring File Sharing, I recommend the following:

  • Disable Full Disk Access if multiple people have accounts with administrator access to the Mac, unless you explicitly want them all to have remote access to all files on the volume.
  • In the Shared Folders list, select items you don’t need shared and click the minus button.
  • In the Users list for each shared folder in turn, click the pop-up menu and choose No Access for users and groups that can’t be removed, then select the user or group and click the minus button to remove those that can.

What you’re left with is a limited, tightly controlled set of folders and volumes that only people you have approved can interact with.

I often create a sharing account that I set up for limited access. You can use the Guest account for this purpose, but I’d rather control it more directly by name. See also how to set up safe user accounts on a shared Mac.

Remote Login, Management and Apple Events

Apple offers powerful but somewhat obscure ways to access, manage, and use a Mac remotely:

  • Remote Login lets you connect via the SSH (secure shell) protocol, commonly used in Unix/Linux, as well as access file sharing with SFTP (Secure File Transfer Protocol), which is really “FTP using SSH.” It’s rarely needed except for particular purposes, such as if you need remote command-line access. If you do enable it, keep “Allow full disk access for remote users” turned off.
  • Remote Management connects with Apple Remote Desktop (ARD), a corporate and academic tool. If you’re not using ARD, don’t enable this service.
  • Remote Apple Events or Remote Application Scripting is a tweaky thing that lets an AppleScript running on one Mac send control events to another. It’s rare you need this, and you will know if so.

Reaching your Mac from outside

If you want to have access to Macs and other devices that are behind NATs or other network protections, I highly recommend Tailscale. The company’s core product lets you create an account, install software on nearly any device, and then have those devices create VPN tunnels to a pooled central network space. This is a profoundly straightforward way to use File Sharing and Screen Sharing when away from your home network. You can install Tailscale on an Apple TV and then set it up to provide access to the entire network it’s on, too!

Tailscale offers a non-commercial account that fits most people’s personal needs.

In a TidBITS article, Evaluating Wireless Security Needs: The Three L’s, Adam Engst laid out the three factors he considered relevant to determining one’s risk when it comes to Wi-Fi security. He called them the three L’s: likelihood (the probability that someone will violate your security), liability (the cost—financial or otherwise—that you’d incur if a security breach happened), and lost opportunity (what you lose in terms of time and convenience by implementing stronger security). That article is still well worth a read almost two decades later.

Times, technologies, and threats change, but some people still face greater risks than others. If you can assess your own level of risk soberly, you’ll be able to take appropriate measures—neither too weak nor too strong.

The risk for most people

Years ago, it made more sense for nearly all Mac owners to consider their susceptibility to outside attack: how likely were you to visit sketchy sites, download applications that might contain Trojan horses, be infected by malware by visiting a site or running software, or even configure a network sharing setting that allowed people on the internet to scan and find weaknesses they could use to potentially copy data from your Mac, or worse. iPhone and then iPad users had fewer risks because of how iOS and iPadOS were constructed and locked down, but external attacks remained the central problem for them.

That profile changed considerably by the late 2010s. The biggest risk that most Apple users have faced since then—no matter their specific Apple hardware—comes from phishing and social engineering.

Phishing describes when someone impersonates a person, group, or website in the hopes you will click through and be infected by malware or enter login credentials. Phishers want your personal data, preferably financial information, such as your credit card number, expiration date, and verification code. They try to offer credible-looking security warnings and fraudulent webpages where you enter payment information or credentials they can use to access your bank and other accounts.

Social engineering is when people attempt to convince you to do something harmful to your device—and compromise your security and privacy. A common scam is that you visit a website and are redirected to another site (via malicious advertising or injected code) that claims your computer, phone, or tablet is infected and urges you to call a number. Calling that number leads you to a boiler room in which the other parties try to get you to install remote access software and sign up for expensive, hard-to-cancel tech services—or worse.

There are also more general attackers, who want to fool you into installing Mac apps that appear to be legitimate, but actually encrypt your personal files and hold them for ransom (ransomware). iOS and iPadOS don’t allow this vector because of how apps are installed and files managed. And even after over a decade into what remains rampant use of ransomware, that scourge hasn’t found a foothold on Mac.

From the mid-2020s, I would also argue that governments of democracies have increasingly chosen to enact laws or stretch the limits of existing ones to intrude into our private spaces, including accessing data that they would never previously have considered due to pushback from both ends of the political spectrum and, in some countries, a strong libertarian philosophy on the primacy of privacy.

Even if you don’t believe you fit in a category where the government of the place you reside would target you personally, you should assume your risk is elevated in any country that is sweeping away previous protections in the vague interests of “protecting children” even when no children are involved and “national security” when no national security interests are shown.

The high value of privacy violations

Some unwanted software doesn’t mess up a device or steal data, but installs adware that can display rogue ads (overlaying ones served by webpages), hijack web searches, and redirect affiliate clicks through portals controlled by the operators to make money illegitimately off you from advertisers. Other software is more insidious, tracking your location to sell it to companies that target you with ads—it’s a kind of malware, even if it doesn’t subvert the device.

The most obvious vector is a Mac, where you can install third-party software that isn’t vetted by Apple. But given that you can install extensions in Safari for the iPhone, iPad, or Mac, and that Apple has routinely failed to catch App Store apps that violate user privacy or include adware components, you can be at risk on any platform. Fortunately, so far, I have heard of no iPhone or iPad examples.

To step up protections, you can engage any or all of the following security or software integrity steps that reduce the area of attack on you that could succeed:

  • Two-factor authentication (2FA): This extra step for logging in deters attackers who have phished or otherwise obtained your password. Apple requires 2FA for Apple Accounts (with a few legacy exceptions), limiting access to iCloud-synced information, purchases, email, and much more. Most non-Apple services offer code-based 2FA (sent via SMS) or other ways to validate a password login. To compromise your account, someone has to obtain your SMS messages, your trusted devices, or your authentication app.

Some phishers perform a “two-step” attack in which they convince you not only to enter your account name and password on a site, but then also relay that information in real time to the actual site you intended to access. This causes the real site to send you a confirmation code (or the fake site requests that you generate one). The attackers capture that code when you enter it. However, that scam works only for brief periods, as short as one minute.

  • Passkey: Upgrade accounts at websites that support passkeys, a secure method of logging in that’s deeply embedded on iPhones, iPads, and Macs, and supported by Google and Microsoft. The secret part of a passkey is never transmitted over the internet, and a passkey is phishing-resistant. You can sync and share passkeys when using recent operating systems and password managers. I’ve shifted from tolerating passkeys to preferring them to a password-and-second-factor combo. See where Apple stores your passwords and passkeys.

Sounds great, right? But passkeys are, in every case I’m aware of, a supplemented to two-factor-protected accounts, not a replacement. Until you can make a passkey replace a regular login (with some kind of recovery option), they’re only as secure as the next-weakest link in the chain.

  • Hardware security key: Another form of 2FA, a relative of a passkey, is a hardware security key. These small physical objects plug into a USB or Lightning port or can connect via NFC to iPhones or iPads. The hardware key has embedded encryption circuitry that generates a unique, highly secure login key for each site you use it with. These keys are built on a standard nearly identical to the technology underlying passkeys, and most websites that support passkeys can accept a hardware security key and vice versa. (These keys also rarely fully replace access to an account yet, meaning a flaw in password and two-factor authentication could compromise access.)
  • Apple Pay: Avoid sites that don’t let you pay by Apple Pay, which prevents your credit-card number from being transmitted directly.
  • Install financial apps: Financial apps and their associated notifications make it more likely you will know immediately if any part of your financial life has been manipulated without permission. I’ve noticed a trend since 2024 for financial apps that support Face ID or Touch ID to let you log in from a desktop browser using a QR code or a push notification from the app. You then verify via biometrics, so you’re never entering any credentials in a browser.

Apple already blocks the direct installation of unsigned software on a Mac—apps that were released by people without an Apple Developer account or who bypassed Apple’s minimally involved signing system. By not allowing the easy installation of unsigned software, Apple prevents most malicious software from running at all. See how Gatekeeper decides which Mac apps can run.

  • Continuous backups: The technology for making constant, secure online backups of documents and creating local clones and backups obviates risks more present now than in the past when those options were slow, expensive, or not feasible due to cost or bandwidth limitations. Having such backups in place gives you a point to revert to if you have data corruption or loss.
  • End-to-end encryption (E2EE) for iCloud: Apple’s Advanced Data Protection lets iCloud users put media, notes, reminders, and iCloud Drive files under the gold standard of end-to-end encryption, which requires possession of a device and the means to unlock to access data. Because we may store details that can be used to exploit us in these various kinds of media, E2EE is another leg up on attackers. See how to turn on Advanced Data Protection.

By using Apple and industry technologies and safeguards and keeping backups current, you can dramatically reduce your likelihood of risks while also curtailing the liability that results. Even if you’re infected by ransomware—an unlikely event—and don’t want to pay, you might lose no files by reverting to a snapshot before the attack; or if someone guesses or obtains an account login, you’re alerted as they try to log in, so you can change the password, or they’re blocked entirely without a second factor or hardware element.

The change in our general risk profile over time, however, comes with one big flashing red light. I noted a couple of times above that most people only need to take certain default strong, reasonable measures. However, if you’re someone in particular fields of work or who engages in political advocacy, you may face targeted attacks that evade basic measures that suffice for everyone else.

A human-rights reformer in an incipient dictatorship needs to take more safeguards than a suburban online shopper in Ohio. But identity theft can sometimes lift that Ohioan—or you—into a much higher category of risk, because someone decides your assets or information are valuable to them, and they’ve acquired credentials or personal information that will let them attempt to crack your security shell.

What about children?

If your minor child has their own iPhone, iPad, or Mac, you might assume they are at very low risk. After all, their device probably contains nothing but games, educational software, a school-provided office suite, and a browser playing videos from Disney+.

But no! Sad to say, children are at greater risk than adults, all else being equal, because they’re less experienced and more trusting—and because, let’s face it, there are a lot of creeps out there who stalk children online.

If you travel to a country with severe laws or a propensity to jail people without legitimate charges, you should raise your risk profile before you travel and while there.

If you’re at higher risk, you should consider taking the most stringent measures available. Check the following criteria to see if they apply:

  • You work in the financial, legal, medical, or government sector: If you use Apple hardware for work, you are likely subject to regulatory requirements and have been briefed on them. (You might even have had to take a course on compliance!) You may be required to engage additional security, like using a VPN, blocking ports for USB/Thunderbolt and SD Cards (see the Mac settings worth changing), enabling FileVault on a Mac, and turning on Advanced Data Protection in iCloud. You may also need to enable hardware security keys for your Apple Account. If you don’t take these steps, and it’s discovered, your devices are lost or data intercepted, or online accounts are compromised, you could be sanctioned, fired, fined, or even charged with a crime, depending on the employer and locality.
  • Your device contains unusually sensitive data: This could be old love letters you don’t want your partner to see, confidential business information from your employer (even if they’re not in the financial, legal, etc., categories above), records of a delicate medical condition, or anything else that could cause you serious problems (like loss of your job, insurance, or marriage) if it were to get out.
  • You’re famous: Congratulations! You already know the price of this on social media and when dining, traveling, or walking around, depending on how well-known you are. But you’re also more of a target online, because of the obsession so many sites and people have with secrets about people who are seen to be famous.
  • You’re a journalist: Sadly, reporters are frequently targeted by criminals, people they’re writing about, and governments. For instance, Ronan Farrow reported that Harvey Weinstein hired an Israel-based private-intelligence firm to dig up dirt on him while he was researching his watershed story on Weinstein’s history of alleged and proven sexual crimes.
  • Wealthy in real terms or cryptocurrency: People with more than a little money are regular targets, especially if they have significant Bitcoin or other cryptocurrency holdings. Having an expensive house doesn’t mean much in the current real-estate market; it’s more likely that you have elevated risk if there’s coverage or securities filings that disclose your wealth, stock grants, or other assets.
  • Rough travel: You frequent any of the internet’s seedier neighborhoods, such as sites that traffic in online gambling, porn, or pirated content (like software, television shows, or movies).
  • Secret or pseudonymous identity: You have an online identity, separate from your real-life identity, that you need to keep private. A number of times in recent years, someone whose job or political position has prevented them from having a public persona have been outed for writing under another, typically fictitious name.
  • Heated online interactions: You engage in controversial discussions that might result in people being exceptionally angry with you.
  • Careless co-users (Mac): Specific to a Mac, you share it with less-sophisticated family members who may not be as careful as you would be about downloading files from unknown sites, clicking links in email messages, and using good passwords. While you can set them up with their own macOS accounts—you should!—some of their actions can affect the entire Mac and your online accounts.
  • People in particular professions and of genders other than male: It’s a sad fact of modern life that being a responsible journalist, being an advocate for vulnerable people, believing the Earth is round and evolution legitimately established in the fossil record, or having the temerity to be a gender that someone else has chosen to be angry about online can cause reactionary individuals and groups to target you.
  • You live in a country that has reduced privacy protections: Various countries have fought with Apple over allowing back-door access to iCloud data. The United States asserts the right to login to examine incoming tourists’ and students’ social media and other accounts. Many countries now think that any checkpoint, traffic stop, or other incidental encounter gives them carte blanche to demand all your data.

Now for the good news! A decade ago, my advice to you would have likely been far more extensive and stringent than for the average user. These days, however, Apple’s and other companies’ baseline security is more accessible, easier to use, and more effective.

My general advice is to do everything suggested here as the baseline, and build a bit from there.

Take a hard look at Lockdown Mode

Some people are pinpoint targeted by spyware, software that can hijack their devices, often without a single click, using previously unknown exploits. These attacks are worth a lot of money and thus typically deployed in a targeted fashion by governments and criminal syndicates against journalists, members of minority groups in a given country, human-rights activists, and opposition politicians.

To help counter these kinds of intrusions, Apple offers a Lockdown Mode you can invoke that highly restricts many forms of inbound messages and traffic. For the full rundown, see how to turn on Lockdown Mode and who needs it.

If you fall into the above categories, your biggest risks will come from how your Mac is set up, rather than your iPhone or iPad. Here’s how you could improve your Mac security:

  • Upgrade your Mac to Golden Gate: Golden Gate supports all Apple silicon Macs. A few older Intel models can upgrade to the previous release, macOS 26 Tahoe, which you should do. If you can’t run Tahoe or Golden Gate, you’re not getting the latest and best security. Consider upgrading your Mac if that’s important to you. (See which Macs can run it.)
  • Allow FileVault: Apple enables FileVault by default when you upgrade to macOS 26 or 27 and on new computers running it. Leave it on (see FileVault). Also, power down your Mac whenever it’s not in use; never leave it idle and running for more than a brief period. (A FileVault-like feature is part of iOS/iPadOS and cannot be disabled or configured.)
  • Block device and card insertion: Thunderbolt and USB devices and SD Cards plugged into your Mac can be blocked from interacting with the operating system without authentication. See the Mac settings worth changing.
  • Never make local, unencrypted copies of your data: All local copies should be on encrypted volumes that are unmounted after backup or shutdown when you regularly shut your Mac down; all hosted backups, if any, should only be with firms that offer strong, user-owned encryption. Time Machine lets you set up backups on an encrypted drive or add an encryption key for networked backups. All online backup services worth considering put the encryption key for your archived data solely in your hands.

Apple keeps upping the ante on how it makes sure that macOS’s core files—all the bits and pieces in the operating system that allows apps to run—aren’t messed about with.

What if Apple could prevent system files from being modified at all by placing them on a read-only disk, effectively blocking changes to those files at nearly the lowest level?

That was a hard task, given that system files and user data files co-existed on the same startup volume. But, hmm, wait a tick! What if you could split system files into one volume and data files into another, but have them appear seamless as a single “drive” in macOS? The system volume would be read-only; the data volume could be read/write, but would also have all the sandboxing protections already in place.

That’s exactly what Apple did starting with Catalina. Apple’s modern filesystem, APFS (Apple File System), among other improvements, added the concept of breaking a drive into containers instead of partitions. (Partitions can still be used, but there’s no advantage.)

In the long-used previous filesystem, Mac OS Extended (sometimes called HFS+), a drive was broken into partitions, and each partition could be mounted as a volume. One volume was much like another.

In APFS, a drive is broken into containers, which are like partitions in occupying a preset portion of the disk’s full capacity. Each container can contain one or more volumes, and each volume can have a role. A role defines the kind of data stored on it. Roles include data (for regular mountable data volumes), system (for system files starting in Catalina), and backup (for Time Machine backups starting in Big Sur).

Roles also include obscure and/or invisible system requirements, too: Preboot, Recovery, and VM (virtual memory).

Catalina’s system role also added another variation on containers and volumes, called a volume group. A volume group is two or more interrelated volumes that present as a single entity to the Finder and user. Behind the scenes, however, multiple volumes are managed by the system.

The reason for this was to take a previous system integrity concept to yet another level: all system files are on one volume in the startup volume group; all user data is on another volume.

Big Sur went even further. It doesn’t even mount the system volume. Instead, it uses a “snapshot” feature of APFS that allows the filesystem to capture a particular point in time. Starting in Big Sur, a snapshot of the system volume is loaded that can’t be changed, because it has no writable components—it’s like looking at a picture. In Disk Utility the system is marked as an APFS Startup Snapshot with a unique name, while the main system volume is dimmed.

On top of that, each file on a Big Sur or later system volume has a separate cryptographically generated hash that’s stored in the volume’s metadata. Whenever a file is read from the system volume, that same crypto operation is performed, and the resulting hash of the loaded file checked against the one that’s stored—any modification, however unlikely it could be to occur at all, would be immediately spotted. That’s why this approach is called a Signed System Volume. The metadata and other volume attributes are hashed and collected in something called the seal, which is verified at boot time. If the seal can’t be verified, you’re prompted to reinstall macOS.

Monterey kept the same structure, but added the capability for Apple silicon Macs to install multiple versions of macOS on a single drive. With Big Sur, an Apple silicon Mac could only have a single system because of some low-level decisions about how the Mac decided whether a system could validly start up. With Monterey, you can create additional partitions and install unique copies of macOS into each partition. (From Ventura onward, Apple doesn’t seem to have made substantial changes—or at least I couldn’t find any to report on.)

Only some people need to have multiple versions of macOS on a bootable drive, such as those who need to keep older versions of macOS running for testing or compatibility.

With Apple silicon Macs, Apple also has what’s called hardware-based memory protection. Hackers often use a system or app exploit to overflow an area reserved for pure data into an area that contains executable program code. This lets them insert malicious code that is run in place of legitimate code. Memory protection in Apple silicon processors marks memory areas as either full of executable code or full of data, but not both. In that scenario, a hacker cannot write malicious code into an area that can be executed; nor can they execute code that’s in a place only inert data is stored. An app can change the state of memory areas explicitly, and that’s a place that hackers will certainly aim for. But it’s much higher-hanging fruit.

System integrity and locked apps

Because the system volume is immutable, Apple can place only certain of its apps on that volume: ones that don’t require regular updates. These apps can be refreshed as part of a system update, as a Catalina or later system update has the rights to make changes to the system volume, including those apps.

The list of system-locked apps is reasonably long. You can find them in /System/Applications. A few examples among many are App Store, FaceTime, Mail, Photos, Preview, and Siri.

System volume apps appear within the Applications folder intermingled with Data volume apps. This is part of the seamless integration of volumes in a volume group used for macOS. You can check on the system/Data location of any app by selecting it and choosing File > Get Info. The path shows drive name > System > Applications for system volume apps, and drive name > Applications for ones installed on the Data volume.

Interestingly, Safari is not on the system volume. Apparently, it’s updated regularly enough and sometimes with significant fixes that Apple has kept it out of that fixed side of things.

In a similar but distinct bit of processor-based protection, after macOS loads on a Mac with Apple silicon, the memory its central components occupy—its kernel—is locked using “kernel integrity protection,” so they cannot be modified while macOS is running.

Do you feel safe now? You should to the extent that it’s feasible that Apple has taken every modern and many inventive measures to render the system immutable.

How to restart in recovery mode

Apple installs a special recovery volume as part of a macOS installation that you can restart from to perform actions on your Mac’s system without macOS itself running. This volume is invisible to you in your normal use of macOS.

On an Apple silicon Mac, choose Apple menu > Shut Down. When your Mac has powered down, hold down the power button; you first see a message that says “Continue holding for startup options.” Keep holding until you see the next prompt, which says “Loading startup options.” Click Options, choose an account, click Next, enter its password, and click Continue.

Apple changed the name for this form of boot a few years ago. Recovery mode generically means a special way of booting any Apple device to repair or reinstall its operating system.

When you restart into recovery mode, Apple’s Platform Security Guide says you are booting into recoveryOS. The app that appears first on an Intel Mac or after clicking Options on an Apple silicon Mac is labeled Recovery on the system menu.

Furthermore, if you choose the Utilities menu, you can launch a special Recovery Assistant! The main screen there is labeled not Recovery Assistant, but simply Recovery—see below. If you lock your Mac via Find My and then unlock it, Recovery Assistant launches on restart, and while the app menu reads “Recovery Assistant,” the main title on the screen is “macOS Recovery.”

Startup protections

This wasn’t enough? Really? Really. There’s more. Apple has several methods of further preventing your Mac from being started up in a way you don’t want and to prevent after startup in ways you don’t want.

Share a disk

As part of enhanced protections on Apple silicon Macs, Apple eliminated a simpler option long used on Intel Macs. Follow these steps to share a volume, making it appear as a networked volume on the other Mac:

  1. Restart in recovery mode. (See How to Restart in Recovery Mode.)
  2. Choose Utilities > Share Disk.
  3. Select the disk to share, and click Start Sharing.
  4. If prompted, choose an account, enter its password, click Unlock, and click Start Sharing.
  5. Connect your Mac to another one via a USB data cable (with Type-A or USB-C plugs on either or both ends) or a Thunderbolt 3 or 4 cable.
  6. On the other Mac in the Finder, click the Network link in the sidebar to view the shared Mac’s volume.
  7. Click the Mac in the main window, click Connect As in the upper-right corner, select Guest as the user, and click Connect.

You can now transfer files between the two computers. When you’re finished, eject the mounted Mac volume by selecting it and dragging it to the Eject icon in the Dock or pressing ⌘-E.

Startup Security Utility

Apple took a harder line on startup security policy when they introduced Apple silicon Macs than they previously had with Intel models. macOS offers Full Security, which locks your Mac down to either its current version of macOS or any version Apple currently supports—typically a limited set. Reduced Security lets you run older versions of macOS that Apple previously approved to run on your hardware.

Almost unrelated, the “Allow accessories to connect” option lets you set a boot policy to restrict connections. For options, see the Mac settings worth changing.

Reduced Security lets you select or deselect the option to install signed legacy (or outdated) kernel extensions; and for remote management, which is used in schools and businesses, to control these kernel extensions and software updates. Some organizations may need specific older extensions for security software and may also want to delay automatic software updates to avoid breaking them.

People at a heightened level of risk could trust Reduced Security with just user management enabled for kernel extensions, since those extensions must be signed by “identified developers” (via Apple’s process) and require user steps to install, as described in Manage System Extensions.

If you don’t have Reduced Security enabled and try to install a system extension, the app installation explains what happened.

Proceed to click Open System Settings, and you see a note in System Settings > Privacy & Security.

Click Enable System Extensions and you see a dialog that provides a shortcut and offers abbreviated and somewhat misleading steps on enabling Reduced Security. If you want to proceed, click Shut Down in that dialog and then follow from step 2, below.

Starting from scratch, follow these steps:

  1. Restart in recovery mode. (See How to Restart in Recovery Mode.)
  2. Choose Utilities > Startup Security Utility.

Note: Apple requires an internet connection when you change the security policy, and you can hit a snag if you follow step 2 too quickly. If you see the error “An internet connection is required to change security policy,” quit the app (labeled Startup Disk when launched), wait for the Wi-Fi icon to show a connection in the menu bar, and launch the utility again. (An Ethernet connection doesn’t work.)

  1. The app launches. Click Unlock to mount the disk, which will be encrypted.
  2. Select an administrator user, enter the account’s password, and click Unlock.
  3. Select the drive if it’s not already selected.
  4. Click Security Policy.
  5. Select the level of security you want to apply and click OK.
  6. When prompted, select an administrator user, enter the account password, and click OK.
  7. “Applying security policy” appears. It may take several to tens of seconds to complete.
  8. Quit the utility and choose Apple menu > Restart.

Tip: Reduced Security disables Apple Pay on a Mac with Touch ID capability. See how to set up Touch ID and Face ID.

Permissive Security (not shown in this section) is an additional option that can’t be selected without disabling an even lower-level feature: System Integrity Protection. The Startup Security Utility then adds Permissive Security as an additional radio button. However, it’s not “no security,” but rather “experimental security”: it allows a very particular kind of installation, in which researchers and other niche users create custom kernels—the heart of the operating system—outside of the Apple-signed ecosystem of macOS versions compatible with Apple silicon Macs. It is exceedingly unlikely you would ever need it.

Recovery Assistant

Apple added Recovery Assistant in Tahoe to deal with situations in which macOS couldn’t start up correctly, and some sort of repair was required that needed the startup volume unmounted. If you encounter this, you will see a Recovery screen that explains the issue. You can also launch Recovery Assistant from macOS Recovery by choosing it from the Utilities menu.

The process works like this:

  1. At the Recovery screen, click Continue.
  2. Apple asks if you are willing to send them diagnostic data, and warns you about privacy issues. Click Don’t Send Data to Apple or Send Data to Apple.
  3. Click Start, and the assistant tries to resolve the problem.
  4. The assistant reports one of three states:

1.1. Your Mac was recovered successfully. Click Restart Mac.

1.1. No known issues were found. Click Restart Mac.

1.1. Your Mac could not be recovered. Oh, boy, it’s time to look into backups, consult an independent Apple expert or the Genius Bar at an Apple Store, or call Apple Support.

If you open System Settings > General > Sharing, you’ll notice many resources your Mac can share with other devices on your local network—and, in some cases, beyond.

You can share your screen, files, printers, and internet connection, for example, and you can also enable various types of remote access to your Mac.

All these features can be handy, especially in that they enable multiple Macs in your home or office to talk to each other. You can copy a file from a Mac in the other room, or view what’s on the screen of the Mac upstairs when you’re downstairs.

However, Apple pairs easy local access with easy remote access: if your Mac is reachable from the internet, some services you share locally can be available remotely. Some may require a password, but that could be easily guessable if you haven’t been thinking about internet-based attacks. And just having certain services active, like Remote Login, could allow remote attacks if an exploit turned up in Apple’s system software, before such exploits were known and patched.

This isn’t speculative. Apple regularly patches exploits and bugs in low-level software, like sshd, the secure shell daemon, the system software that handles remote Terminal-style sessions if you have Remote Login enabled. Those flaws are usually fixed before anything terrible is unleashed in the wild, however.

How exposed you are comes first; which sharing services are safe to turn on follows from it.

What’s your risk of internet intrusion?

The most likely determinant of risk to attacks or intrusion via the internet is how directly reachable your Mac is. While the vast majority of routers have a public IP address, very few computers on local networks do. Almost always, your router receives traffic and then re-addresses it to your Mac.

A public IP address is by definition routable or reachable from the rest of the internet. The network of which it’s a part appears in routing tables traded among the devices that exchange data across this mighty global beast.

However, IP addresses can also be static or dynamic. A static address is assigned to a device and doesn’t change over time without typically manual involvement in changing settings. A dynamic address can change at will, and it’s automatic.

Private network addresses can be either static or dynamic; most of us have networks configured to assign the next available address when a computer, phone, or other device requests one. Some routers can be configured to assign static private addresses to specific devices.

If you’re not running a business network or paying extra, your broadband router typically has a dynamic public address. The ISP may rotate the address every once in a while, or if there’s a service outage or you restart the router, a new address is assigned.

The dynamic nature of these public addresses assigned to routers doesn’t aid in security in any fashion, because they’re still public. You might not be trackable by public IP, but your router is still reachable.

A public IP address is simply one that’s uniquely assigned across the internet, and can be reached from anywhere else on the internet. Your router almost certainly has a public IP address, because that’s how it interacts with the rest of the world on your behalf.

It’s a very low bar for any interested party to scan all the originally defined set of public addresses on the internet—yes, as many as hundreds of millions of them—to find open access for services that the scanner might know potential security exploits for, sometimes far out of date…but there are a lot of old, unpatched machines on the internet. Thus, with a public address, there’s no obscurity possible.

That “originally defined” part uses an addressing scheme called IPv4; a newer standard, IPv6, is more resistant to bulk scanning. See the IPv6 section below.

Most homes and businesses rely on private IP addresses for everything but their broadband connection’s router, however. These reserved ranges are only used on local networks, are managed by a router (using something called Network Address Translation or NAT), and typically assigned out automatically with DHCP (less well known as Dynamic Host Configuration Protocol).

Private addresses, which are usually in the form 10.0.1.x or 192.168.1.x, can be reached without any special effort by other devices on the same network of privately assigned addresses. However, when a device on your network makes a request outside its private network range, like viewing a webpage, the router rewrites the request to use the router’s public IP address, and sends it out; the router receives a reply and then forwards it to the locally connected device that requested it.

If you were to have a public IP address on your Mac—not just on your router—it would be like standing on a street corner instead of being inside a house with a locked door and a mail slot. Anyone can come up to and start talking to you or assault and rob you! (Unlike in the world of atoms, where violent crime is minimal and has drastically fallen in recent years, an internet mugger can attack targets wherever they are and a huge number simultaneously.)

The same effect happens if you configure your router to connect its public address with specific services on one or more devices on the local network. For instance, some people want to have a globally available web server or file server, and it’s not terribly hard to expose the correct connection. That makes that web server or file server just as exposed as if the Mac had a public IP address—but only those services, not everything else shared on the Mac.

NAT isn’t designed as a security measure: it’s just a spreadsheet the router maintains to wire requests and replies together. It’s incidentally a general security measure because it makes potentially exploitable open doors on your devices nearly impossible to reach without being specifically targeted, particularly with a router that can be subverted.

You may already be sure you don’t have a public IP address on your Mac: your ISP charges extra for public addresses you use beyond the one attached to your router, and you know you’re not paying for it; your ISP doesn’t offer public addresses; you specifically made sure you weren’t getting one from your ISP; or you’ve configured your router and you know exactly how you set things up.

If you’re not sure, walk through this list:

  • Check your Mac’s address: You can examine the IP address assigned for your active network interfaces. Go to System Settings > Network and select each of your active interfaces in the main pane:

— Ethernet and most interfaces show the address in the main pane under or next to “IP Address.”

— For a Wi-Fi interface, click Details to see the address next to IP Address.

  • Check your router: Connect using the administrative controls for your router, log in, and look at where your router shows its WAN (Wide Area Network), Modem, or Internet IP address, and how network addresses are handed out under DHCP, LAN (Local Area Network), or similar labels. The WAN side is almost always a public IP; the LAN/DHCP part almost always private.

If the IP address of your Mac or LAN/DHCP addresses on the router is in any of these ranges, it’s a private one, where x is any number from 0 to 255: 10.x.x.x, 172.16.x.x to 172.31.x.x, or 192.168.x.x. Otherwise, it’s almost assuredly public.

Type in “what’s my IP” at Google and it will tell you what it thinks your IP address is, and offer a list of sites that do the same (sometimes with more detail). However, if you’re in a DHCP/NAT scenario with private addresses, which is what nearly all home users and most business users are, the address shown on the website is the one associated with either your broadband modem or a further upstream router run by the ISP—not your Mac.

IPv6 adds a wrinkle

Technically, the IP address style x.y.z.a, like 192.168.0.1 or 36.44.0.6, is IPv4 (version four), which has been in use for decades. For nearly 30 years, internet mavens have been trying to migrate the networks that comprise the internet to IPv6, which has a lot of advantages. This includes more addresses that can be assigned, the so-called address space. Where IPv4 has billions of potentially usable addresses, IPv6 has hundreds of undecillions.

However, the trouble has been all the inertia of having billions of devices and hundreds of millions of routers and pieces of plumbing designed around IPv4. While the internet has largely retooled—after nearly 30 years—so that IPv6 works as well as IPv4, nobody wants to end the widespread use of IPv4 in residential networks and many company networks, because of private addressing. IPv6 was designed before NAT became broadly used and thought of as a quasi-security measure to prevent ingress to ISP and corporate networks.

For most of us, that means until private addressing can work in a similar way within IPv6, our ISPs have assigned our routers a public IPv4 address, and have chosen one of several paths with IPv6:

  • Ignored/disabled: Your ISP may simply not pass IPv6 traffic, and it’s not an issue for security.
  • Allow, but disabled by default: You can use IPv6, but you have to configure your router to allow it. My ISP requires a special router for its fiber-optic service, and has detailed instructions for enabling IPv6. Since I have no specific need of it, I’ve left it disabled to reduce my exposure on the public internet.
  • Turned on by default: You may have an ISP, like my editor Dave Johnson, who enables IPv6 by default through its system, and your router and devices all automatically get IPv6 addresses, just as they do IPv4 ones.

If you’re in that last situation, you may have publicly reachable IPv6 addresses—it can be hard to tell, because some ISPs use techniques that are similar to NAT. If the IPv6 addresses are truly publicly accessible, they expose the same general risk of remote attack as public IPv4 addresses and should follow the advice in the next section.

But some analysis suggests it’s not as bad as it might seem. The Internet Society has an interesting FAQ about IPv6 and security, and notes that attackers could find “infrastructure nodes” reasonably easily—the routers that form the backbone of the internet and connect ISPs, streaming services, data centers, and so forth all together.

But, the document explains, “It is generally unfeasible though to address scan a network for client devices, since their addresses are randomized over a very large address space.” Simplified, it means that it’s not a needle in a haystack, but 10,000 needles in a Nebraska-sized area of haystacks. (With IPv4, it’s a cubic foot of hay and you can see all the needles inside.)

If you’re truly concerned, you can disable IPv6, as it isn’t a mandatory or critical part of using the internet. Here are three possibilities, the first two of which will affect your entire network:

  • Disable IPv6 at the router: Find the manual for your router and follow instructions to disable IPv6. It may be as simple as selecting a radio button.
  • Ask your ISP to disable IPv6: Contact your ISP and ask them to disable IPv6 on your account or router if they control your router or have the ability to do this at a higher network level.
  • Disable IPv6 on your Mac: If you can’t or don’t want to disable IPv6 network-wide, disable IPv6 on your Mac. Go to System Settings > Network, select an interface, and click Details. Select TCP/IP and choose Link-Local Only from the Configure IPv6 pop-up menu. Click OK. This leaves other devices still reachable via IPv6, but at least locks down your Mac.

You can’t disable IPv6 on an iPhone or iPad.

Because of the fraught nature of putting your devices or services on them directly in the path of the entire internet, it’s almost always the case that you can share files more easily, with more control, and more securely using a cloud-based sharing service, with a lot of provisos that I describe along with each service.

Each of these services partitions access, so you know precisely what you are letting someone view or download, and whether they can modify, delete, or upload files. You can set a time limit that a link will work, and usually restrict whether something can be downloaded or just viewed online. You may also be able to tell when they access or view files and see exactly what changes they make, if they have permission to modify files.

All the major tech companies offer them, and you may already have free access to substantial storage, or already be paying for a subscription plan or higher level of storage for other purposes.

All these services encrypt data at rest and use encrypted transport (HTTPS, primarily) for uploads, downloads, and link creation. However, if someone can access your account, they can view, delete, modify, download, and add files without restriction.

If you want to share files in a truly secure, end-to-end manner, however, the gold standard is end-to-end encryption (often abbreviated E2EE). With E2EE, the ecosystem you use generates and retains keys only at endpoints, on devices under your control. (Sometimes you’re involved in generating them, but usually the key creation and management is silently handled by the software.)

iCloud.com was never protected by E2EE before December 2022; after that, it became optional for some services if you enabled Advanced Data Protection (ADP). With ADP, iCloud Drive and other items synced, shared, and available via iCloud.com are protected by E2EE for you and with people with whom you share—so long as they also have ADP enabled. See how to turn on Advanced Data Protection.

Layer your own encryption on top

If you or your shared partners don’t have ADP enabled or can’t turn it on, you can layer E2EE on top of standard secure cloud services, because data that’s encrypted before transfer and stored in these locations remains encrypted, and is only decrypted by endpoints that have the keys.

That is, if you have an encrypted disk image and upload it, that integral encryption isn’t stripped off. If someone downloads the disk image, they still have to break the encryption applied to that data to access what’s inside.

But you can be more sophisticated than a disk image. Software that handles its own encryption—say, the password-management app 1Password—can safely hold and sync its separately encrypted data on a sync service. Someone stealing your 1Password vault has stolen trash.

As of 1Password 8, the app works only with its own syncing system. It used to work with Dropbox and iCloud.

Beyond software that uses E2EE for its internal format are packages that allow generic file sync by effectively tunneling the end-to-end encryption across a sync service! From your perspective, the files are readily available; to everyone in between you and your devices, including the sync services, it’s just a bunch of garbage-looking data. This is a nifty workaround.

I can’t recommend a service, as I don’t use any, but there are two options you can test for this purpose that are Mac compatible:

  • Cryptomator is an open-source solution to create an encrypted package, called a vault. It’s free to use on Mac, Windows, and Linux. The Android and iPhone/iPad apps have a one-time €19.99 (about US$23) purchase price to cover development costs.
  • VeraCrypt is also free, open-source software for creating virtual encrypted disks or partitions. However, the project supports desktop operating systems only: Linux, macOS, and Windows.

Cloud sync services usually reduce data transfer required by syncing only changed portions of files. (Unix folks call it the diff after a command-line tool; delta encoding is a more exact technical term.)

With encrypted files you upload, large portions of the file or the entire file change whenever it’s modified, resulting in a lot of data synced. However, Apple’s bundle form of disk images and some third-party software breaks large files into smaller ones to solve this problem. Only those sub-portions are changed, resulting in less syncing.

Encrypted messaging with others

Apple enabled E2EE with Android users for messaging over RCS, an industry standard Google championed. However, be sure to check when you start messaging with someone using RCS that their Android device has RCS encryption enabled. You can see whether it’s enabled in Messages: an Encrypted label appears at the top of the conversation, or inline if the encryption method changes. (If you had an ongoing conversation with someone over RCS, upgraded your device, and they have encryption enabled, an inline message in the conversation would appear.)

If you want to use E2EE to exchange data with others, you can use options like GPG Suite ($23.90 per year, 30-day trial, Mac only), which manages public-key encryption data for you, and lets you exchange encrypted files via email with anyone else who uses PGP- or GPG-compatible software. (PGP is a decades-old implementation of public-key encryption; GPG is the GNU, free-software version.)

If you trust other parties to manage the process, you can use iMessage or Signal. In early 2021, Apple quietly overhauled iMessage’s innards to make it more robust, but still needs to publish its spec and allow outside auditing. The company quickly had to patch major exploits found in their update in September 2021, making an even better case for allowing more eyes on the problem.

In May 2025, people were baffled that they couldn’t type “Dave & Buster’s” and similar ampersand-containing names into Messages. Turns out, Messages transformed the ampersand into something that triggered the protection! Apple fixed it, but it showed it worked?

Despite Apple’s lack of full transparency, iMessage remains trustworthy. Signal is created by an organization devoted to privacy, and has proven itself a great way to avoid interception.