Are "Back to My Mac" FTP and SSH services visible to "everyone"?

With the MobileMe "Back to my Mac" service, I can establish SSH terminal and SFTP connections from my Mac Mini at home to my Mac Pro at my work.  The SSH (Remote Login) and SFTP (File Sharing) services are enabled under System Preferences -->  Sharing.
Does this make the SFTP and SSH services on my Mac visible/accessible to anyone else?  I like using "Back to my Mac" because it is simple and it uses key exchange for authentication when connecting.  However, I'm concerned that by enabling the SFTP and SSH services under Sharing, I'm also opening these services up to anyone who can see them.  Is this true, and if so, how can I maintain the security of my computers?
Thanks in advance,
jjw

OK, besides putting me to sleep, the BTMM description seems to indicate that it is your MobileMe password that is important when making BTMM connections through a home NAT router.
BTMM does open a port through the router, but if I understand correctly, it does not listen for ssh, or vnc, or afp protocols, but rather for the BTMM IPsec secure tunnel to be established, and then all the BTMM supported servers travel over the IPsec secure tunnel.  NOTE: the paper was putting me to sleep, so I could have this wrong.
Kerberos is used for authentication of the IPsec tunnel.
What I'm thinking is that if your Mac stays behind a home NAT router, or corporate firewall (that allows BTMM to work), then the important password is your MobileMe password.   If the Mac goes out in public, then all your Mac OS X user account (and guest) passwords need to be strong (where longer is better).
A GRC Shields-UP probe will not check all possible ports.  If BTMM is running and all the standard ports are marked as stealth, then BTMM is using a non-standard port (as in one GRC does not check by default).  That makes it more difficult for someone to find your NAT router and then your Mac.  While this is NOT security, it does add some difficulty to the intruder's attempts at finding you.
AGAIN, I did not fully understand the BTMM paper, so "Your Mileage May Vary" with respect to my analysis acccuracy.

Similar Messages

  • Are "Back to my MAC" and "Port Forwarding" mutually exclusive?

    I have been using APExtreme and Port Forwarding successfully for several weeks now. The PF is to allow access to game players on a PC which acts as a server on the web. All Good.
    One more thing, I have a ISP provided wireless modem/router to talk to the cable and the world. It seems to work either bridged or un-bridged.
    I have disabled the wireless on the ISP's modem/router. (Actually the ISP's device doesn't hold a candle to the APE.)
    Still all good.
    So the firewall is on in the APExtreme and none on the modem router, and I have a port defined for my gamers to get access to my server in the APExtreme.
    I now want to implement Back to my MAC on my MBP and my other Apple devices. I believe these use iCloud for which I have an account and it seems to be working well with my iPhone.
    In Properties, when I select BtmM, iCloud says communications will be slow if I have port forwarding on. Also I will not be able to use the router function in my Modem/router.
    I'd really like to have the modem/router firewall up, and do the port forwarding there, but the BtmM will likely not get through.
    So what does anyone suggest?
    Can I use BtmM and port forwarding without too much degradation?
    Please advise.
    Thanks
    Barry

    To best answer your question on whether the two are "mutually exclusive," let take a look at how Back to My Mac (BTMM) basically works.
    BTMM - General Requirements
    OS X Leopard 10.7.3+
    Active iCloud account. Each Mac & the AirPort router, that will be relying on BTMM, needs to be configured with the same account.
    A publicly reachable IP address for your router.
    A router that supports either NAT-PMP or UPnP. For AirPorts, be sure it is running 7.6.1+ firmware.
    BTMM uses TCP port 5354 and UDP ports 4500 & 5353 for communications.
    BTMM - Basic Communication Flow
    For a computer connected to the Internet via a router, BTMM "asks" the router for its configuration information. For a router, like your AirPort, that uses NAT-PMP, BTMM will ask the router to assign arbitrary public ports. In turn, the router will provide these port assignments (& the router's Public IP address) back to BTMM.
    BTMM then sends this information to the iCloud account. In background iCloud updates a special set of DNS entries to be used by BTMM. These entries are then made available to all BTMM clients using your iCloud account. When a computer, with BTMM enabled, uses your iCloud credentials, it automatically retrieves a list of all other computers/routers that are registered with the same account. All these devices should then appear under the SHARED section of the Finder.
    When attempting to connect to a remote computer (or router), BTMM creates a secure connection to that remote device using the information from the iCloud account.
    Once the connection is established, the devices can then communicate with each other.
    So potentially, unless you are using Port Mapping for any of the ports BTMM uses, they should not conflict.

  • Back to My Mac, iCloud and Windows 7

    I just got my first personal Mac and set up a Time Capsule for my backups and storing some data.  I turned on Back to My Mac in the manual setup because I want to be able to connect at work.  The problem is I'm running Windows 7 at the office.  I also found instructions for setting up DynDNS with the Time Capsule (which I went through) but it still doesn't seem to be working.  I found other discussions about a VNC client but I'm only interested in getting the files from the Time Capsule.  Am I mising a step somewhere?

    Back to My Mac for iCloud and Back to My Mac for MobileMe are seperate services, and systems on one will not be able to connect to systems on the other.
    http://support.apple.com/kb/HT4907

  • Slow Connection with FTP and SSH after a migration from 10.3.9 to 10.4.6

    Hi all,
    I just move my server from 10.3.9 to 10.4.6.
    I import all my users and settings.
    When i try to connect to my server using FTP or SSH, the connexion is slow.
    I have to wait arround 45 sec before connecting to the server ( i never wait with the old 10.3.9 )
    ex of connexion + delay
    I enter : ssh myuser@myserverip
    server : Password: ( 26 sec after i hit the return key !! )
    server : Last login: Tue May 9 11:57:03 2006 from XX.XX.XX.XX ( 2 sec after )
    server : Welcome to Darwin!
    It is faster than the first time because the server must store some datas of recent connected users.
    I have the same problem with FTP
    Thx for help

    I have this same problem.
    I'm not sure how to set up or tweak DNS. Could someone point to where this is accomplished?
    I'm not using a DNS server inside our firewall because I'm not sure how it works. I have DNS service turned off on the OS X Server.

  • Do I still need to use the old mobile me backup system for backing up a mac desktop and if I delete it will it affect the memory of my system which has now Maverics

    Do I still need to use the old mobile me backup system for backing up all my data and having it able to get at in case of a crash, or can the icloud reset everything? Because I can not find any structured refrence, as to how it would be done. I am updated to Maverics. Also does the icloud continue if I uninstall the backup to free up space?

    MobileMe was discontinued in 2012 and all the data stored on it was deleted, and iCloud can't make backups of Macs.
    What I recommend you to make backups is to get an external drive and use Time Machine or an application like Carbon Copy Cloner. With this, you can access to your data everywhere and safely, and then, if you want, use a cloud storage service like CrashPlan. You can keep on using iCloud without backups

  • How do you connect "back to my mac" from and ipod touch?

    Does anyone know how to use the back to my mac function with the iphone or ipod touch? This would be really great to get access to the computer like you can with a laptop when on the road.

    Hi kclarke2000,
    The Apple official feature *Back to My Mac* is only supported from a Mac computer to another Mac! So, this means you won't be able to use this functionality with your iPhone or iPod Touch yet!
    However, you may want to leave feedback for Apple, by using filling out [this form|http://www.apple.com/feedback/mobileme.html].
    Hope this helps!
    Francisco

  • How are permissions applied between Web Applications and from Service Applications?

    I'm quite confused about how permissions are applied to Content Databases in relation to service accounts. So, as an example, I have two web applications - Intranet whose service account is DOMAIN\sps_webapp_default - and My Sites whose service account is
    DOMAIN\sps_webapp_social.  The "sps_webapp_social" account has full control (through User Policy) to the Intranet web app.
    When I go to My Sites> Sites> Suggested Links and click on any suggestions I get the below error and the site is not "followed".  This Content Database sits under the Intranet web app which the sps_webapp_social has full control to.
    I'm also getting similar permission issues when the account that runs various service applications tries to connect to the DB (such as workflow service).  This is happening to new or migrated sites.  I know permissions can be applied directly
    in SQL but this can't be the way to do it? 
    Is there a simple reason why these permissions aren't propagating through?

    I resolved my issue. I deleted the Work Management Service Application and created it again - this time, I made sure the IIS Pool (I created its own application pool) service account running this was the same as the My Site service account. 
    So, running under DOMAIN\sps_webapp_social.  This seemed to clear up all of my permissions issues being thrown up in Event Viewer too.
    My Sites really is a complicated beast...  I'm getting there.  Hopefully this helps somebody else!

  • Get back to my mac up and running

    Hi Guys,
    A while a go I got a new modem/router from my internet provider and since that moment my "Back to Mac" option of my Time Capsule is not working anymore. What I have is an Experiabox V8 Arcadyan VGV7519 and connect to this modem a Time Capsule.
    I put the Experiabox in bridge mode. And turned of the DHCP functionality.
    Time Cupsule settings are:
    Internet -> DHCP
    Network -> Bridge Mode
    At this stage the internet is working but the "Back to Mac" isn't
    Now I set Network to DHCP - NAT and the internet is gone. I don't get any error's. Only a orange light at the internet connection in my Airport Utility. What am I doing wrong and how can I get the "Back to Mac" function up running again?
    I hope you have enough information, if not please let me know and I'll provide you with more info and screenshots of what ever you need.
    Thanks in advance,
    Joost

    The TC must be in router mode for BTMM to work.
    You are therefore in the wrong mode.
    Your internet is via TC in bridge mode.. yet you also state you have the
    I put the Experiabox in bridge mode. And turned of the DHCP functionality.
    It simply cannot be right.. If you did the above you have both units in bridge.. there is nothing that can work as a router.
    Now I set Network to DHCP - NAT and the internet is gone.
    Just makes it more confusing as you now have no router and you cannot even use one.
    Let me guess.. your ISP is using 10.x.x.x private IP address range.. that will kill the operation of the TC in router mode.
    Although you should get an error.
    So.. please can you give me the IP of all the computer and devices in the network.
    And do a traceroute in terminal from one of the computers.
    eg
    MacProie-5:~ Ray$ traceroute 8.8.8.8
    traceroute to 8.8.8.8 (8.8.8.8), 64 hops max, 52 byte packets
    1  192.168.0.1 (192.168.0.1)  0.532 ms  0.268 ms  0.224 ms
    2  adsl1.mel02.eftel.com (203.123.69.176)  6.337 ms  6.460 ms  6.623 ms
    3  te0-1-0-308.core0.mel02.eftel.com (203.123.72.73)  6.191 ms  6.477 ms  7.122 ms
    4  ve420.er01.mel01.eftel.com (14.137.114.25)  7.190 ms  6.849 ms  11.045 ms
    5  eth2-1.bdr01.syd02.eftel.com (202.62.143.121)  20.457 ms  21.830 ms  25.382 ms
    6  as15169.eth1-3.bdr01.syd02.eftel.com (202.62.143.65)  19.689 ms  19.523 ms  26.807 ms
    7  72.14.237.21 (72.14.237.21)  19.972 ms  20.097 ms  20.674 ms
    8  google-public-dns-a.google.com (8.8.8.8)  19.532 ms  19.672 ms  19.650 ms
    Use a familiar website or just the google DNS is the easiest.
    You must get the TC into router mode for this to work.
    BUT you bridge the modem and you will lose other functionality of the box.. like voip.
    There are other ways to access the TC in bridge behind a modem router.. and it isn't hard.. use a direct AFP connection and setup portforwarding a ddns in the modem.. and you will be nearly there. Plenty of info about remote access in to the TC.

  • What are the differences between Mac Air and Mac Pro?

    What are really the main differences between the Macbook Air and the MacBook Pro?
    I am thinking of getting a laptop by mac. I like the prices of the Air but the Pro seems better performance.
    However my needs are internet, email, word processing and some photos, pictures etc.
    would i still be able to do many good applications on the Air vs the Pro?
    suggestions please?
    thanks

    The base model current 2013 Air will perform faster and better in general than the base model 13" non-Retina Macbook Pro.
    Ive got both of them. 
    On the Air:
    Faster wifi (by far) 802ac
    Faster boot and read/ write due to SSD
    Much longer battery life due to Haswell upgrade made in June
    Crisper sharper screen, better to stare at for long periods
    MUCH FEWER parts to go bad,.....also only one moving part, the Fan
    No HD to crash from mechanical failure
    Packing the AIr around is a dream since is nearly the weight of an Ipad.
    Dont get fooled like most do in seeing the super-skinny AIr as less than a full power machine, ....thats always someones first huge mistake when they see one.
    Here is an excellent video comparison between the 11” I5 vs. I7 2013 Macbook Air.
    http://www.apple-tubes.com/apple-macbook-air-11-mid-2013-haswell-i5-vs-i7-compar ison/
    http://www.anandtech.com/show/7113/2013-macbook-air-core-i5-4250u-vs-core-i7-465 0u/2
    I5 vs. I7 performance 13” Macbook Air 2013
    Boot performance
    11.7 I5 ……11.4 I7
    Cinebench
    1.1 I5….1.41 I7
    IMovie Import and Opt.
    6.69 I5….5.35 I7
    IMovie Export
    10.33 I5…8.20 I7
    Final Cut Pro X
    21.47 I5…17.71 I7
    Adobe Lightroom 3 Export
    25.8 I5….31.8 I7
    Adobe Photoshop CS5 Performance
    27.3 I5…22.6 I7

  • When my photos are backed up to my iCloud, and i delete them from my camera roll and then back up my photos again, the pics i deleted are still on my icloud taking up space?

    im trying to free up space on my iCloud from pics i had on my camera roll that i dont need or want that did get backed up to my iCloud. i wasnt aware that pics stay there after i delete them from my camera roll. if thats correct.

    You don't need to delete photos from your camera roll to save on backup sizes, you can turn individual items on and off for back up in your iCloud back up settings.
    Apple States that the last 3 back ups are accessible, which means the photos from your back up may not be removed immediately.
    Being able to back up to the cloud can be very useful, especially if you don't have access to a computer or have infrequent access to one, however unless you specifically need to use iCloud for back up, you will find backing up to iTunes significantly more convenient and possibly more reliable.
    More about iCloud v iTunes Back Up

  • How are contact photos in Mac Mail and Address book used?

    I am trying to understand who will see my photo (user account picture) that I can see in my contact listing from address book. Will other mac users see this photo when I email them? Will PC users see it? I think it showed up on my blackberry in an email I sent myself. Is that possible?

    Nobody can see that picture but you. If you assign pictures to contacts, they will show up as a badge on e-mails from that contact.

  • ICloud sync: Contacts are not syncing from Mac to iCloud, other services OK.

    Notes and calendar data are syncing fine. Syncing between iPhone and iCloud on all 3 appears to work fine. I have toggled syncing through the control panel; did not help.

    Go to System Preferences>iCloud, click Sign Out, choose Delete at all of the prompts, restart your Mac, then go back and sign back in.  (This deletes the account and iCloud data from your Mac, but not from iCloud.  Your data will reappear on your Mac when you sign back in.)

  • Mac book and Apple Service - a secret

    My middle row of letters from g,h,j,k,l, have stopped working.  Went to Apple Store and they said "no worries, its a hardware problem. We'll replace the keyboard but because your model is from 2009, we have to replace the entire top. $300."  I said OK. Got a call yesterday, and it will be $1200 dollars. "We must repair your cracked screen as a matter of liability. Now it's $1200."  YIKES. 
    FYI:  I then called an approved Apple Repair store. "We'll fix whatever you want fixed. No, we won't replace the screen if you don't want us to." $200 to replace the keyboard. 
    Although Apple Store didn't say anything about an alternative, there ARE alternatives. 

    Sorry to hear this experience. I recommend you to complain to Apple about this Apple Retail Store > http://www.apple.com/retail/feedback Apple takes note of your feedback about Apple Retail Stores to get the best experience, and of course, take it to the reseller to get it repaired

  • Back to My Mac and remote servers?

    Hello --
    I'm trying to figure out if there's a way to connect to servers mounted on my Mac at work while accessing it from home via Back to My Mac. I don't control port mapping on the router at work, which apparently doesn't support UPnP or NAT-PMP. But I am able to connect to either machine from either location.
    When I connect to the work Mac, though, I'm only able to see the local hard drive, not servers mounted on that computer. Is there any way to extend the connection to the rest of the network? I can also use LogMeIn Hamachi, but I run into the same issue there.
    Any advice is welcome. Thanks.

    well I know when I had back to my mac, I could  ssh into a computer using the address format computerName.userName.members.mac.com. So if my mobileme name was [email protected] and the computer's name in sharing was imac. the address would be imac.bob.members.mac.com.  If you have ARD I could be worth a shot, see if it works.
    What's are you missing with back to my mac? copy/paste? terminal? Remote install?

  • Back To My Mac and L2TP

    Hi,
    In version 7.5+ firmware for the AEBS if you used "Back To My Mac" the base station
    would silently ignore any user attempts to redirect the L2TP ports.
    This of course would screw up any attempt to use the VPN software included in
    Snow Leopard and Lion.
    I was stuck at the 7.4 firmware level for almost a year until I found the knowledge
    base article that noted this bizarre behavior.
    I removed my name from the back to my mac panel and I was able to use the
    system VPN with firmware versions >= 7.5 ;(
    I never was able to get back to my mac to work at hotspots, I suspect that both
    ends of the network need to support Apple's PMP protocol.
    Does anyone know if the 'new' Back To My Mac implemenation still disallows
    users from redirecting the L2TP ports?
    Jerry

    So I've found the offical word burried in an Apple Document... 
    http://support.apple.com/kb/TS1629
    scroll down to Port 4500 which is used for IPSec VPN and Back to My Mac...
    4500
    UDP
    IKE NAT Traversal
    ipsec-msft
    Mac OS X Server VPN service, Back to My Mac (MobileMe, Mac OS X v10.5 or later).
    Note: VPN and MobileMe are mutually exclusive when configured through an Apple access point (such as an AirPort Base Station); MobileMe will take precedence.
    NOTE TO APPLE:
    1) Do NOT create network services that conflict with well known and used TCP and UDP ports.
    2) If you create two conflicting services. Please MAKE A NOTE IN THE MANUAL for OS X Server so Admins are aware of the problem.

Maybe you are looking for

  • Can't burn DVDs? Try this first...

    Like a number of other folks, I had an unexplained failure to burn DVDs and thought something Very Bad had happened to my drive. However, doing some research before buying a new drive (if I had to buy one, might as well get the Latest and Greatest ri

  • My purchased music won't download when I click on the cloud icon

    I bought a few songs on my iPad and synced it on my computer.  After syncing it shows on my iPad that I need to download the songs.  When I click to download it doesn't.  I synced my iPod and iPhone from my computer after I synced my iPad to update m

  • URM How to set default value in the "New Check-in" - "Folder" field

    Hello everyone, I'm trying to find out how to set the default value for the "folder" field in a check-in profile created using the Configuration Manager. If I browse to the folder in the "Browse Content -> Folders" menu and check-in a file inside the

  • JDBC Error: ORA-01000: maximum open cursors exceeded

    Post Author: prashant CA Forum: Information OnDemand I successfully created reports using CR4E on windows, deployed JSPS to Websphere running on windows and was able to view a large reports for a using JNDI connection resources to Oracle 10g. Every t

  • QSM (Producer/Consumer) Template

    Hello everyone. Before I start with my project (instrument control and data acquisition) I made a template using the JKI State machine template and converted to queued based state machine with producer/consumer loop. Basically, I wanted to separate t