User/ Administrator Permissions and Log In.

I have a new Mac book Pro.
I am trying to find a definitive answer to my dilemma.
Currently I log on with full administrator privileges,but I have read that this is dangerous and that I should create a separate user account.
I am fairly comfortable with the system although learning all the time.
Can anyone advise what the best and safest way is to use my Mac book Pro.
Thanks
Keith

..."It is evident from this statement & the content of the document that it is not intended simply for "advanced users" but for situations that require stringent security measures"...
While it is obvious that some of the security measures covered in the guide don't apply to every situation (eg. FileVault is not appropriate for everyone), it would be flawed logic to conclude that every measure in the guide should only be applied to computers in high security situations.
Some of the topics involve basic security principles that should be applied more generally. The guide uses stronger language for important measures. For example, applying security updates is described as "essential". "Never" open a file sent to you by someone you don't know. "When transportiing the computer, never leave it in an insecure location". Clearly these steps aren't intended only for "security professionals". Similarly, when referring to an admin account, the guide uses the absolute terms "always log in as a nonadministrator user" (unless the task requires otherwise), and "never browse the web or check email" from an admin account.
..."IOW..."...
Yes, I acknowledged in my first response that a properly informed person should make their own decision whether using an admin or standard account is appropriate, and that using a standard one is no guarantee of safety.
What I find highly objectionable and fundamentally irresponsible is the frequency with which certain high level (4 & 5) posters go out of their way to blithey advocate the continued use of the "admin" account to new users seeking advice (in this case, explicitly requesting "the safest way" to use the computer), while reserving knowledge of the admin->root privilege escalation vulnerabilities to themselves.
They are denying the users the ability to make informed choices by pushing their opinions as fact, leveraging their high level status and dropping "credentials" like being a long term, veteran OS X user, or in some cases even that they are an OS X beta tester (as if that somehow gives them developer level security expertise) to give weight to their point of view.
The admin->root privilege escalation vulnerabilities are real and well known, exploits readily demonstrable, and the level of sophistication required to create an exploit is very low. I find it appalling that anyone could recommend the use of an admin account while failing to mention this fact.

Similar Messages

  • I deleted my administrator account and cannot make any changes in preferences.

    I deleted my administrator account and log my users & groups is locked. I cannot open it, with name and old password. I cannot restore as Lion was downloaded from app store and needs login to re download.
    Help

    Launch the Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ If you’re running OS X 10.7 or later, open LaunchPad. Click Utilities, then Terminal in the page that opens.
    Drag or copy — do not type — the following line into the Terminal window, then press return:
    dscl . -read /groups/admin GroupMembership
    You should get the following output below what you entered:
    GroupMembership: root admin1 admin2 ...
    where admin1, admin2, ... are the names of the admin users.

  • A mess with account, administrator PW,  permissions and privileges!

    I don't know where to start. I've tried a number of the suggestions in the other posts below, but just can't get into my HD1. I inadvertently deleted some folders from Library (but did put them back). I thought they were doubles.
    I re-booted from my Snow Leopard install DVD (hold down C). I have tried a number of times to choose a new password. But, each time I can Log-in, but notice that I can't get into my Administration PW. Now, which one do I use? The one when I installed Leopard 2~3 years ago? (That one I forgot). Or one of the few that I just created?
    Anyway, I live just outside of Tokyo, Japan and called the Apple Store in Tokyo (got an English speaker) and he directed me through the steps. But, he said to choose System Administration (root) which I did. Later I realized that shouldn't have been done from the article that he had sent me. I followed his steps, could log in and then noticed that I could use Mail (if I filled in my Mail PW etc.) but my clock couldn't be authenticated as I tried to set the time. It's on L.A. time. (but in Tokyo).
    So, next that didn't work and he e-mailed me the Apple site Help articles on re-setting the accounts. I tried a few more times and still couldn't access to authenticate. So, I re-installed my Snow Leopard disk. 10.6...
    I went to the Apple Support site and downloaded the Snow Leopard up-dates.... I've tried to install the up-dates of Snow Leopard 10.6.6 and that couldn't be authenticated either and it said I need 10.6.5 tried that and the same thing all the way down to 10.6.2 and still none of them could be installed either. Now, iTunes can't be accessed. and I just tried to install the newest Skype and that also can't be installed. (all on HD1 in applications) and my printer also... I can get online with Safari and Firefox O.K.
    I also tried to use Disk Utility and verify disk/repair disk but get, "insufficient privileges"! and can not verify permissions. The time set can't be done. I click on the Lock it shows "authenticate" for a second and stays locked...
    The Snow Leopard up-date 10.6.6 shows this....
    Even though SL 10.6.6 is installed, it keeps going back to Mac OS X (10.6.1) below....
    I wanted to post a screen shot here, but don't know how....it couldn't be copied.
    PLease...let me know...thank you
    What can I do from here? Anyone out there able to help me! thanks. I am NOT a computer wiz and not really into any type of "Terminal" lingo to understand what I'd do.

    ok, that's not normal then. then you are right and some permissions are seriously messed up. before we proceed a couple of questions. are you logged in as the user Savannah when you are experiencing these problems? were you trying to change permissions on the Mail folder while logged in as Savannah or as some other user. you should do it while logged in as Savannah. other users shouldn't have permissions to the Mail folder of user Savannah.
    if you are doing this while logged in as Savannah I suggest resetting permissions and ACLs on Savannah's whole home directory. this is much easier if that user is admin so give it admin rights temporarily in system preferences->accounts. you can remove admin rights from that user later, once we fix everything. after you've made that user admin log in as Savannah and run the following terminal commands (copy and paste please)
    sudo chflags -R 0 ~
    you'll have to enter the password of user savannah after that command. it will not be echoed on the screen. that's normal.
    Next enter
    sudo chown -R `id -un`:`id -gn` ~
    and then
    chmod -RN ~
    next, boot from the leopard install DVD and reset ACLs on Savannah's home directory as described here
    http://support.apple.com/kb/TS1334?viewlocale=en_US
    after that log in as savannah again and run
    sudo chgrp -R `id -gn` ~
    then try using Mail again. it should hopefully work now.

  • I just updated my MacBook pro early 2011 model to OSX 10.9 and was forced to create a new user(administrator) and ended up with a different configuration. If I login with my original user name everything is back. How can I get rid of the other user name?

    I have two user names with Administrator privelages and my MacBook keeps booting up to the wrong one and I have the wrong configuration since I updated to OSX 10.9. I would like to get back to my original User name which I used to boot up to. When I go to the User Groups and Preferences it doesn't allow me to delete the un-wanted user.
    Does anybody have any suggestions how I can fix this? I can't seem to recover Time Capsule back-ups prior to the OSX upgrade even though I have been faithfully backing up to a Time Machine.
    Help please.

    First of all, open System Preferences > Users & Groups > Login Options, and set your old user account in "Automatic login". By doing this, your computer will always log in with your old account.
    Then, log in your old account, where you will be able to delete the new user that OS X Mavericks forced you to create. Other users have reported the same problem

  • 1. TACAS+ Accounting and Logged in Users report is not working on ACS 4.1(1

    Hi,
    I am facing problem with ACS 4.1 accounting, TACAS+ Accounting and Logged in Users report are not working, the csv file is been generated but nothing is showened in the file.
    I have checked the documents related to ACS 4.1, it says that there is a bug related to command accounting “CSCsg97429 - TACACS+ Command Accounting does not work in ACS 4.1(1) Build 23”.
    Tried upgrading the same with the patch applAcs-4.1.1.23.3.zip, still it is not working.
    Other reports are working fine.
    1. TACAS+ Accounting - not working
    2. Logged in Users - not working
    3. TACAS+ Administration - working
    4. Passed Authentication - working
    5. Failed Attempts - working
    Any suggestions or any idea, please revert.
    Regards
    Vineet

    Hi,
    Thanks
    Yes I have configured the command “aaa accounting exec default start-stop group tacacs+”
    As I have mentioned all the other reports are working. Which user and when he has logged in and what commands he has used. Only the TACAS+ Accounting and logned user is not working.
    Regards,
    Vineet

  • Trouble with DeployManager and user administrator

    i have the following error during the task of deployment of a WD app. The user administrator isn't blocked coz' i unblocked recently. but it continue show me that error. Any idea to solve my problem. Thanx in advance
    this is the log:
    Settings
    SDM host : veccs1011
    SDM port : 50218
    URL to deploy : file:/C:/DOCUME1/Mariana/LOCALS1/Temp/temp34919MyWDproject.ear
    Result
    => deployment aborted : file:/C:/DOCUME1/Mariana/LOCALS1/Temp/temp34919MyWDproject.ear
    Aborted: development component 'MyWDproject'/'local'/'LOKAL'/'0.2006.05.09.15.43.06':
    Caught exception while checking the login credentials for SAP J2EE Engine. Check whether the SAP J2EE Engine is up and running.
    com.sap.engine.deploy.manager.DeployManagerException: ERROR: Cannot connect to Host: [veccs1011] with user name: [Administrator]                     Check your login information.                     Exception is: com.sap.engine.services.jndi.persistent.exceptions.NamingException: Exception while trying to get InitialContext. [Root exception is com.sap.engine.services.security.exceptions.BaseLoginException: Access Denied.]
    (message ID: com.sap.sdm.serverext.servertype.inqmy.extern.EngineApplOnlineDeployerImpl.checkLoginCredentials.DMEXC)
    Deployment exception : The deployment of at least one item aborted

    Hi
    WHy dont you try changing the sdm password . have a llok at this forum thread for changing the sdm password
    SDM password not working
    Hope this helps , please mark points for helpful answers.
    regards
    rajeshkr

  • I have a Win7Pro SP1 PC locked down with a Group Policy as it is a public facing PC. PDF fillable forms cannot be completed when logged on as the restricted user. The forms work as a normal user. What are the user requirements/permissions needed to fill f

    I have a Win7Pro SP1 PC locked down with a Group Policy as it is a public facing PC. PDF fillable forms cannot be completed when logged on as the restricted user. The forms work as a normal user. What are the user requirements/permissions needed to fill forms?

    Well, try this (I was able to fix my with these steps):
    Go Utilities > Disk Utility
    Select your Startup Disk, e.g. Macintosh HD
    Then, under the First Aid Tab, click Verify Disk Permissions.
    If there are errors, then click repair Disk Permissions.
    After it is done, restart the computer and see if your problem is resolved.
    I hope this help.
    Zeke
    www.ZekeYuen.com/blog/

  • User accounts have disappeared from the Sys prefs and log-in screen!

    When upgrading to 10.4 from 10.3, I used Carbon Copy Cloner to create a bootable copy of my hard disk to an external (La Cie) drive. After performing an erase and install, the Migration Assistant would not recognize the installation on the external drive. After numerous attempts, I finally re-entered all my settings and transferred most of my files by hand into the new OS. Everything seemed to be fine until I attempted to update the user settings on one of the standard accounts. When I went to the Limitations window for this account in System Preferences the computer froze completely, necessitating a forced shutdown. When I rebooted, the account I was modifying had disappeared from the log-in screen. When I attempted to restore it in Sys Prefs, the Accounts window was blank, and clicking on the resulting items in a Spotlight search gets a preferences error message. I repaired the disk and the permissions with Disk Utility to no avail, and DiskWarrior says the directory is too damaged to rebuild. I re-installed Tiger using archive and install, also with no success. I can log in as Root and access all data, including all user accounts, but still no user accounts in the log-in window or sys prepfs. Does anyone have any thoughts on this before I (aauuugghhh) erase and install again? Any idea why the Migration Asst. can't see the clone? Did I move something into the new OS I shouldn't have?
      Mac OS X (10.4.3)   700mHz G4 iMac (Flat panel)

    When upgrading to 10.4 from 10.3, I used Carbon Copy Cloner to create a bootable copy of my hard disk to an external (La Cie) drive.
    Did you boot into the clone to ensure that it was working just like the original? If so, can you still do that? If so, I'd boot into the clone, use Disk Utility to erase and reformat the internal HD. Then, clone the clone to the original and install Tiger on top of it using the upgrade earlier version option. Then, you won't have to change or migrate anything. IMHO, it's the best way to do it.

  • Restrict permissions to use the groups/users/roles in User Administration

    Hello gurus,
       I want to find out if there is a way we can restrict permissions to use the GROUPS in User administration. We want to assign the user administration role to the users, but do not want the users to have permissions to DELETE groups from User administration page.
    Please also let me know, if we can just have users use the NWA to do the user administration instead of from the Portal?
    Thank you,
    ~~MK

    Hi MariaKutty,
    Koti is right, you need to create custom User administration role from standard role and restric the access in the custom role and assgined to the users.
    >Please also let me know, if we can just have users use the NWA to do the user administration instead of from the Portal?
    Then can to do from NWA also, if the user not required to have the portal access.
    Hope it helps
    Regards
    Arun

  • I'm trying to share folder between users on a single mac.  I put the folder in "shared," set permissions so other user can read and write, enabled file sharing, but can't find the folder on the second user's account.  Any help?

    I'm trying to share a folder between users on a single mac.  I want both users to be able to read and write so the folder stays current on both accounts.  I put the folder in "shared," set permissions on folder so other user can read and write, enabled file sharing, but can't find the folder on the second user's account.  Any help?

    Did you log out of one account and into the other or just used Fast user switching?
    Is the permissions set to anyone?
    When you move data to teh Shared folder is it copied or just moved?
    If copied then it's not a folder both can access, just a way station like a USB thumb drive that things are coped too and off of likely.
    You can run this #5 on each user account to reset the user permissions once they are taken back out of the Shared folder
    Step by Step to fix your Mac

  • My Mac says i do not have sufficient permission,( though I've repaired permissions and checked that I'm an administrator of this computer) to upgrade- can you tell me what the problem is? Mac 10.5.8

    My Mac says i do not have sufficient permission,( though I've repaired permissions and checked that I'm an administrator of this computer) to upgrade- can you tell me what the problem is? Mac 10.5.8
    == This happened ==
    Every time Firefox opened
    == I attempted to upgrade from 2.0 version ==
    == User Agent ==
    Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-us) AppleWebKit/533.16 (KHTML, like Gecko) Version/5.0 Safari/533.16

    See http://kb.mozillazine.org/Installing_Firefox#Mac_OS_X
    If you have Mac OS X 10.5 or newer then do this:
    Download a new copy of the Firefox program: http://www.mozilla.com/firefox/all.html
    Trash the current Firefox application to do a clean reinstall.
    Install the new version that you have downloaded.
    Your profile data is stored elsewhere in the [http://kb.mozillazine.org/Profile_folder_-_Firefox Firefox Profile Folder], so you won't lose your bookmarks and other personal data.

  • Strange Sharing and Permissions and Admin Users question.

    I am having problems printing and need to change the permissions and ownership on a library file
    My directions were to:
    [ The fiery cups filter needs ownership changed from admin to system (root) ]
    My secondary question is I am making the assumption that when someone refers to my "system (root)" that this is the same as "my name (me)" Yes?
    But my primary mystery question is
    As I went to change the permissions on the above top topic I noticed I had four choices.
    I am the only single user of this computer. My permissions are set to Administrator status.
    I apparently had a guest account enabled but I don't remember turning this on.
    On the get info window, at the bottom, under sharing and permissions, NAME and PRIVILEGE when I add - select a new user or group, I have:
    My account "my name (me)"
    "administrators"
    and *"firebird database"?*
    "everyone" is already there as a standard default.
    *I don't know what the **** "firebird database" is. It shows as a single user account.* My guest settings were enabled to connect to my shared folders, which I have turned off. Is this "firebird" part of Apple code or has something been compromised without me knowing?
    Anyone know? Thanks in advance.

    Root or System ownership is not the same as you. You are a restricted user. Root is an unrestricted user.
    If you have installed third-party printing software with incorrect permissions, then start by using Disk Utility to repair permissions. Do not begin changing file/folder permissions when you obviously do not know what you are doing as this could screw up your entire system.
    Firebird is a third-party database program that you must have installed. Obviously there is a problem with it. Either uninstall it or contact the developer for assistance.

  • Darwin issues and administration permissions

    In an unfortunate series of mistakes I am stuck in Darwin Black Screen after boot. I do manage to login but I can't leave the Darwin interface back to the Mac OS Tiger. Strangely the other user of the MacBook Pro can't login.
    It all started after a "forced quit" while my "group" settings were in the process of mistakenly being changed from "admin" to my own login name...
    It seems I lost some of my previous administrator permissions...
    The reboot command does not work: The screen reads "Operation not permited".
    I can't Archive and Reinstall because there is a DVD inside which I did not manage to take out since the eject button can't be used in the Darwin console...
    Please, somebody help me!!!
    edison

    Hi and Welcome to Apple Discussions ...
    Try booting while holding down the Eject key. Or ... If your drive has an emergency eject hole, put the computer to sleep and insert a large, straightened paper clip in the small emergency eject hole of the drive (the location varies, depending on the drive). Push firmly until the disc ejects.
    Carolyn

  • Hello,  I have a strange file in my Users folder, named PortDetect.log I have no idea which app created it and it reappears when I delete it.  Has anyone got the same file? Or know where it may originate from?  Thanks in advance!

    Hello,
    I have a strange file in my Users folder, named PortDetect.log
    I have no idea which app created it and it reappears when I delete it.
    Has anyone got the same file? Or know where it may originate from?
    Thanks in advance!

    know where it may originate from?
    The Huawei wireless modem driver.

  • How to retrieve users logging-in and logging-out date and times in SharePoint

    At the moment I am using SherePoint 2013 with a few tenants.
    I am going to have access to the users logging-in and logging-out dates and times.
    For instance, I would like to know the detail of the dates and times which a particular user of a tenant has logged-in and logged-out during the past few months.
    Any idea?

    You can retrieve that info from the IIS log files. Maybe you can use a free IIS reporting tool that I've built and adjust it to your own needs, you can get it here:
    http://gallery.technet.microsoft.com/office/The-SharePoint-Flavored-5b03f323
    Btw, in a web environment usually there is no such thing as the log-out date and time because the end user just stops making requests. So, you've got to take a look at the last request and by default, after 20 minutes the session times out and you can assume
    the session has ended.
    Kind regards,
    Margriet Bruggeman
    Lois & Clark IT Services
    web site: http://www.loisandclark.eu
    blog: http://www.sharepointdragons.com

Maybe you are looking for

  • Iphoto crashing all the time

    Hi guys, my dad has got a problem with his new Imac, he's had it about a month or so now and since upgrading some of the software the other day it has been playing silly buggers!! Firstly after the upgrades Safari, itunes and Iphoto stopped working.

  • Connecting monitor to tv tuner

    I have a L2045W monitor,can i connect an upscaling freeview tuner box to my monitor

  • Beyond Recovery? Illustrator Ate My Project.

    I've been working on a project for about three days (on a MacBookPro).  I finished it off today ay a cafe.  When I attempted to open the file this evening the following message appeared: "Can't open the illustration.  The illustration contains an ill

  • Quality / Resolution change of pictures and videos...

    Hello, why does Windows Phone change the resolution and quality of my pictures and videos if I send them to someone by Email or to Skydrive? Normally it would be great to be asked whether I want to change the resolution and quality or not. Windows on

  • User accounts gone after Restoring disk

    Hello - I am running OS 10.4.11 on a PowerMac G4 Dual 450MHz Desktop. Recently I purchased a new IDE Hard Drive to put into my computer. I wanted to make an exact copy of my old hard drive onto the new hard drive and use the new hard drive as my main