Advanced Security Trident MacBook Security Config 2023

Last updated
Dec 1, 2022
How it's used?
For home and private use
Operating system
macOS 13 Ventura
On-device encryption
macOS FileVault
Log-in security
    • Biometrics (Windows Hello PIN, TouchID, Face, Iris, Fingerprint)
    • Basic account password (insecure)
Security updates
Allow security updates and latest features
Network firewall
Enabled
Real-time security
XProtect
Check Point Harmony Advanced (now supports M1 natively).
Firewall security
Built-in Firewall for Mac/Linux
About custom security
NextDNS Deployed with all security features enabled (including blocking websites under 30 days) and several ad/tracker blocking lists
Periodic malware scanners
No periodic scanners
Malware sample testing
I do not participate in malware testing
Environment for malware testing
N/A
Browser(s) and extensions
Safari
Secure DNS
Control D
Desktop VPN
HotspotShield
Password manager
Apple Key Chain
File and Photo backup
iCloud 2 TB
System recovery
Automatic iCloud Sync
Risk factors
    • Browsing to popular websites
    • Making audio/video calls
    • Buying from online stores, entering banks card details
    • Coding and development
Computer specs
MacBook Pro 2021
M1 Pro 10-Core CPU with 16-core Neural Engine and 16-core GPU
16GB Unified Memory
512GB SSD
Notable changes
16/06/23 Replaced Norton 360 with Check Point Harmony Advanced Mac Client
What I'm looking for?

Looking for medium feedback.

Trident

Level 27
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
1,629
No Time Machine encrypted back-ups?
I am subscribed to the most expensive tier of Apple One. I’ve added 5 friends (all paid £60 for a year of it) and we all have Apple Music, Arcade, Fitness+, News+, TV+ and only I have the 2 TB cloud storage. Everything is stored in there so I will never lose any data really.

This device is the safest of all and used for general activities only, apart from that I have a Chrome OS Flex device and Windows 11 which is used for malware testing (I used to be more productive in malware testing before than now).
 

Trident

Level 27
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
1,629
09/03/22 Enabled iCloud Advanced Data Protection (End-to-End Encryption).

 

MuzzMelbourne

Level 15
Verified
Top Poster
Well-known
Mar 13, 2022
599
How do you like the M1 Pro chip? I'm jealous, couldn't raise the extra cash to get the 14". Next time maybe, M3 Pro???
 
  • Like
Reactions: Trident

Trident

Level 27
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
1,629
How do you like the M1 Pro chip? I'm jealous, couldn't raise the extra cash to get the 14". Next time maybe, M3 Pro???
The processor itself is a beast. I’ve been having this Mac for ~ a year now and I’ve never heard fans working even after hours of usage, neither I’ve felt any lag. Everything is extremely snappy. Games run well (I am a bit weird and old-fashioned in gaming and like these Arcade games that remind me of old times like Asphalt 8, shoot-em-up games and all these). Video rendering is extremely fast too.

Programs that are natively running on M1 and they are all in my case are fast in anything. In terms of benchmarks I will need to do again, don’t remember numbers.

I was considering Dell XPS 15 with 12th gen i7, HP Spectre x360 with 11th gen i7 (lower model and wattage than the XPS and hence discarded) and Mac. I went for Mac and no regrets.
 
  • Like
Reactions: MuzzMelbourne

Trident

Level 27
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
1,629
04/06/23 01:50 AM
Finished phasing out NextDNS in favour of Control D (Full Control Version). For this and 5 other devices.

Benefits of Control D over NextDNS:
  1. Provides better protection against ads, trackers and specially phishing/malware.
  2. Provides better management through more organised and easier to use interface, better statistics/log lists, easier domain blocking/unblocking, profiles management and even scheduling.
  3. Seems to be evolving way faster then NextDNS whose development has totally stagnated.
  4. May be able to bypass geo-blocks (not tested properly yet).
 

Razza

Level 4
Verified
Well-known
Aug 12, 2014
163
Benefits of Control D over NextDNS:
  1. Provides better protection against ads, trackers and specially phishing/malware.
  2. Provides better management through more organised and easier to use interface, better statistics/log lists, easier domain blocking/unblocking, profiles management and even scheduling.
I've not tested the protection, my question is about the 2nd point which way is it better then Nextdns UI wise, I tested it last year the web ui seem messy compared to Nextdns.
 
  • Like
Reactions: Trident

Trident

Level 27
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
1,629
I've not tested the protection, my question is about the 2nd point which way is it better then Nextdns UI wise, I tested it last year the web ui seem messy compared to Nextdns.
You feel it’s messy because you are used to NextDNS which is different. It takes a bit of time to readjust to Control D but once you do, it is actually easier getting around and doing what you need to do.

For example, all settings are placed under “profiles” and divided in 4 categories.
Filters, services, custom rules and profile options.
Filters is your ads, trackers and other content blocking rules. Custom rules allow you to block, unblock or redirect a website to another region. Services allows you to block specific apps/services from connecting or redirect to another region. Profile options includes the AI, DNS rebinding protection, cache lifetimes and others.

Logs and statistics includes everything you need to know about the devices, such as what was blocked (you may need to unblock something).
 
  • Like
Reactions: Razza

Razza

Level 4
Verified
Well-known
Aug 12, 2014
163
You feel it’s messy because you are used to NextDNS which is different. It takes a bit of time to readjust to Control D but once you do, it is actually easier getting around and doing what you need to do.

For example, all settings are placed under “profiles” and divided in 4 categories.
Filters, services, custom rules and profile options.
Filters is your ads, trackers and other content blocking rules. Custom rules allow you to block, unblock or redirect a website to another region. Services allows you to block specific apps/services from connecting or redirect to another region. Profile options includes the AI, DNS rebinding protection, cache lifetimes and others.

Logs and statistics includes everything you need to know about the devices, such as what was blocked (you may need to unblock something).
I might give a look again, am not that used to Nextdns I currently use AdGuard Home hosted on one of my cloud servers so it works at home and when on mobile data.
 
  • Like
Reactions: Trident

Trident

Level 27
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
1,629
I might give a look again, am not that used to Nextdns I currently use AdGuard Home hosted on one of my cloud servers so it works at home and when on mobile data.
I may find that UI messy, as I am not familiar with it 😀
It will take me a day or two.
 
  • Like
Reactions: Razza

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top