{"id":19857,"date":"2022-08-15T06:30:09","date_gmt":"2022-08-15T14:30:09","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/08\/15\/news-13590\/"},"modified":"2022-08-15T06:30:09","modified_gmt":"2022-08-15T14:30:09","slug":"news-13590","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/08\/15\/news-13590\/","title":{"rendered":"What is USB Restricted Mode in macOS Ventura, and why do you want it?"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/idge\/imported\/imageapi\/2022\/06\/07\/12\/can-my-mac-run-macos-ventura-100928772-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Mon, 15 Aug 2022 06:35:00 -0700<\/strong><\/p>\n<p>Once upon a time, one attack vector for industrial sabotage consisted of <a href=\"https:\/\/www.orangecyberdefense.com\/uk\/blog\/ethical-hacking\/hacking-via-usb-keys-risks-and-protection\" rel=\"noopener nofollow\" target=\"_blank\">exfiltrating data\u00a0from Macs<\/a>\u00a0using a standard-issue USB storage card. Researchers have also shown that it\u2019s possible to hijack computers with <a href=\"https:\/\/9to5mac.com\/2020\/10\/13\/t2-exploit-team\/\" rel=\"noopener nofollow\" target=\"_blank\">malware-infested cables<\/a>. It\u2019s a jungle out there, so Apple has toughened up (Apple Silicon) Mac protection with USB Restricted Mode.<\/p>\n<p>Beginning with <a href=\"https:\/\/www.applemust.com\/wwdc22-whats-new-in-macos-ventura-quite-a-lot-actually\/\" rel=\"noopener nofollow\" target=\"_blank\">macOS Ventura<\/a>, the new layer of protection comes in the form of USB Restricted mode, which should provide a little reassurance to enterprise IT and is enabled by default.<\/p>\n<p>An Apple developer note <a href=\"https:\/\/developer.apple.com\/documentation\/macos-release-notes\/macos-13-release-notes\" rel=\"noopener nofollow\" target=\"_blank\">explains this protection<\/a>: \u201cOn portable Mac computers with Apple silicon, new USB and Thunderbolt accessories require user approval before the accessory can communicate with macOS for connections wired directly to the USB-C port.\u201d<\/p>\n<p>If this sounds familiar, it is. It already exists on iPads and iPhones. It&#8217;s worth noting that support for mass storage devices on both those platforms always lagged the Mac, and it\u2019s only since iOS 13 that you have been able to use external storage with those.<\/p>\n<p>On the Mac, things have kind of worked in the other direction. Macs have always supported external storage media, but Apple has now made this more secure \u2014 though Apple Silicon systems.<\/p>\n<p>The idea is that when a new USB or Thunderbolt device is connected to the Mac, the user will be asked to approve the connection. If a Mac is locked the end user must unlock it before the computer will recognize the accessory. This uses the new-to-the-Mac allowUSBRestrictedMode restriction. The protection is initiated when your Mac has been left locked for an hour or so.<\/p>\n<p>Apple says it doesn\u2019t apply to power adapters, displays, or connections to an approved hub, and devices will still charge even if you choose Do Not Allow for use of a connected accessory. The idea is that energy flows, but data does not.<\/p>\n<p>Why do you want it?\u00a0The security environment continues to deteriorate, and the idea here is that this protection provides one more wall to protect Mac users and their data. It also puts a stop to systems such as GrayKey to crack hardware security to get to the data.<\/p>\n<p>In practice, most people won\u2019t encounter a problem. They will attach a USB device, approve it, and won\u2019t need to think about it much beyond that. (They may need to approve the use intermittently, but that\u2019s it.)<\/p>\n<p>Apple\u2019s <a href=\"https:\/\/support.apple.com\/en-us\/HT208857\" rel=\"noopener nofollow\" target=\"_blank\">tech notes for the iPad\/iPhone implementation<\/a> of the feature explain:<\/p>\n<p>\u201cIf you don&#8217;t first unlock your password-protected iOS device &#8211; or you haven&#8217;t unlocked and connected it to a USB accessory within the past hour &#8211; your iOS device won&#8217;t communicate with the accessory or computer, and in some cases, it might not charge. You might also see an alert asking you to unlock your device to use accessories.&#8221;<\/p>\n<p>The new protection works well alongside the also-soon-to-debut Automated Device Enrollment feature, which forces anyone attempting to setup an enrolled Mac to engage with the enrollment process. This makes it much harder for unauthorized people to open a Mac in an attempt to get to data that is not theirs to grab.<\/p>\n<p>What about updates? Apple explains that accessories attached during software update from prior versions of macOS are allowed automatically. New accessories attached prior to rebooting the Mac might work, but won\u2019t be remembered until connected to an unlocked Mac and explicitly approved.<\/p>\n<p>This is just the latest security enhancement Apple has now managed to put in place across its platforms.<\/p>\n<p><em>Please follow me on\u00a0<a href=\"https:\/\/twitter.com\/jonnyevans_cw\" rel=\"nofollow noopener\" target=\"_blank\">Twitter<\/a>, or join me in the\u00a0<a href=\"https:\/\/mewe.com\/join\/appleholics_bar_and_grill\" rel=\"nofollow noopener\" target=\"_blank\">AppleHolic\u2019s bar &amp; grill<\/a>\u00a0and\u00a0<a href=\"https:\/\/mewe.com\/join\/apple_discussions\" rel=\"nofollow noopener\" target=\"_blank\">Apple Discussions<\/a>\u00a0groups on MeWe.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3669854\/what-is-usb-restricted-mode-in-macos-ventura-and-why-do-you-want-it.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/idge\/imported\/imageapi\/2022\/06\/07\/12\/can-my-mac-run-macos-ventura-100928772-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Mon, 15 Aug 2022 06:35:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>Once upon a time, one attack vector for industrial sabotage consisted of <a href=\"https:\/\/www.orangecyberdefense.com\/uk\/blog\/ethical-hacking\/hacking-via-usb-keys-risks-and-protection\" rel=\"noopener nofollow\" target=\"_blank\">exfiltrating data\u00a0from Macs<\/a>\u00a0using a standard-issue USB storage card. Researchers have also shown that it\u2019s possible to hijack computers with <a href=\"https:\/\/9to5mac.com\/2020\/10\/13\/t2-exploit-team\/\" rel=\"noopener nofollow\" target=\"_blank\">malware-infested cables<\/a>. It\u2019s a jungle out there, so Apple has toughened up (Apple Silicon) Mac protection with USB Restricted Mode.<\/p>\n<h2><strong>What is USB Restricted Mode?<\/strong><\/h2>\n<p>Beginning with <a href=\"https:\/\/www.applemust.com\/wwdc22-whats-new-in-macos-ventura-quite-a-lot-actually\/\" rel=\"noopener nofollow\" target=\"_blank\">macOS Ventura<\/a>, the new layer of protection comes in the form of USB Restricted mode, which should provide a little reassurance to enterprise IT and is enabled by default.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3669854\/what-is-usb-restricted-mode-in-macos-ventura-and-why-do-you-want-it.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[27286,10480,10403,714],"class_list":["post-19857","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-computers-and-peripherals","tag-ios","tag-macos","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19857","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19857"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19857\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19857"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19857"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19857"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}