What can other administrators access on my machine? The 2019 Stack Overflow Developer Survey Results Are InProtect files from other administrator accountsHow secure are iCloud backups?Unwanted saving of proxy credentialsnsurlsessiond is using all my bandwidthOnly root login remains (all other users gone) and even root hangs, so can't access!How can you switch users at the login screen, without administrator access, with only one local account (the administrator) and many network accounts?Protect files from other administrator accountsCan a thief know my Apple ID without my PIN code?I have a company MacBook Pro and I no longer can see my username on the login screenFileVault and other user accounts; repairEffects of logging in to same Apple ID on multiple macOS accounts (single computer)
Accepted by European university, rejected by all American ones I applied to? Possible reasons?
Can there be female White Walkers?
Mathematics of imaging the black hole
If a sorcerer casts the Banishment spell on a PC while in Avernus, does the PC return to their home plane?
Why doesn't shell automatically fix "useless use of cat"?
Are there any other methods to apply to solving simultaneous equations?
How can I add encounters in the Lost Mine of Phandelver campaign without giving PCs too much XP?
What do these terms in Caesar's Gallic Wars mean?
Why does the nucleus not repel itself?
What is the meaning of Triage in Cybersec world?
Is Cinnamon a desktop environment or a window manager? (Or both?)
The difference between dialogue marks
Star Trek - X-shaped Item on Regula/Orbital Office Starbases
Will it cause any balance problems to have PCs level up and gain the benefits of a long rest mid-fight?
If I score a critical hit on an 18 or higher, what are my chances of getting a critical hit if I roll 3d20?
Is it ethical to upload a automatically generated paper to a non peer-reviewed site as part of a larger research?
Why couldn't they take pictures of a closer black hole?
What does もの mean in this sentence?
Likelihood that a superbug or lethal virus could come from a landfill
What do hard-Brexiteers want with respect to the Irish border?
Loose spokes after only a few rides
A word that means fill it to the required quantity
writing variables above the numbers in tikz picture
Deal with toxic manager when you can't quit
What can other administrators access on my machine?
The 2019 Stack Overflow Developer Survey Results Are InProtect files from other administrator accountsHow secure are iCloud backups?Unwanted saving of proxy credentialsnsurlsessiond is using all my bandwidthOnly root login remains (all other users gone) and even root hangs, so can't access!How can you switch users at the login screen, without administrator access, with only one local account (the administrator) and many network accounts?Protect files from other administrator accountsCan a thief know my Apple ID without my PIN code?I have a company MacBook Pro and I no longer can see my username on the login screenFileVault and other user accounts; repairEffects of logging in to same Apple ID on multiple macOS accounts (single computer)
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;
I've been given a new MacBook Pro at work, and it has an administrator account which I assume the IT department has the credentials to. I have been created a local account which is also an administrator.
I'm just wondering, as another administrator, what of my data can they access and read? I have iCloud Drive and other services turned on, and I don't particularly like the idea that someone can go in and grab that stuff.
macos security user-account
add a comment |
I've been given a new MacBook Pro at work, and it has an administrator account which I assume the IT department has the credentials to. I have been created a local account which is also an administrator.
I'm just wondering, as another administrator, what of my data can they access and read? I have iCloud Drive and other services turned on, and I don't particularly like the idea that someone can go in and grab that stuff.
macos security user-account
add a comment |
I've been given a new MacBook Pro at work, and it has an administrator account which I assume the IT department has the credentials to. I have been created a local account which is also an administrator.
I'm just wondering, as another administrator, what of my data can they access and read? I have iCloud Drive and other services turned on, and I don't particularly like the idea that someone can go in and grab that stuff.
macos security user-account
I've been given a new MacBook Pro at work, and it has an administrator account which I assume the IT department has the credentials to. I have been created a local account which is also an administrator.
I'm just wondering, as another administrator, what of my data can they access and read? I have iCloud Drive and other services turned on, and I don't particularly like the idea that someone can go in and grab that stuff.
macos security user-account
macos security user-account
edited yesterday
bmike♦
162k46290629
162k46290629
asked 2 days ago
RickyRicky
23017
23017
add a comment |
add a comment |
3 Answers
3
active
oldest
votes
Short answer: Generally an administrator account can access and read any file on the computer. To protect files, either remove all untrusted admin accounts except for yours or encrypt the specific files you need protected with your admin password. Another admin can reset your password, but not see it to unlock things like your keychain. Of course a new password for encryption is ideal if you don’t trust another admin.
There are certain files within your account that are encrypted and can not be read without your password.
The main file I'm thinking of is the "Keychain" which may contain your iCloud password and any other passwords you've allowed Safari (or other apps) to remember.
As an IT system administrator myself I would recommend not to store personal data on your work computer that you don't want anyone else to see.
The computer may have backup software that's backing up all files on the computer - including your iCloud Drive.
Also remember that if you're fired, the computer may be taken away before you have a chance to remove your personal files.
3
Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.
– Jörg W Mittag
yesterday
1
Plus, not all jurisdictions are that privacy-conscious.
– Jörg W Mittag
yesterday
1
This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.
– Konrad Rudolph
yesterday
@KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.
– nohillside♦
yesterday
add a comment |
This document provided by Apple titled: Set up users, guests and groups on Mac covers the types of privileges each user type is allowed.
Administrator: An administrator can add and manage other users, install apps and change settings. The new user you create when you first set up your Mac is an administrator. Your Mac can have multiple administrators. You can create new ones, and convert standard users to administrators. Don’t set up automatic login for an administrator. If you do, someone could simply restart your Mac and gain access with administrator privileges. To keep your Mac secure, don’t share administrator names and passwords.
Expanding on this, basically an Administrator can access any of your files and pretty much do anything on the system.
References
- Protect files from other administrator accounts
add a comment |
An Administrator account should be able to install software to log keystrokes, a keylogger. With your keyboard input captured, any passwords input would be captured and could be used to open otherwise secure applications and files. I cannot say whether Apple prevents their use on macOS, but anyone sufficiently determined would be able to circumvent such restrictions.
Also, screen capture software can often be used to determine what keystrokes have been made, especially on mobile devices where the on-screen keyboard keys pop-up as typed.
It is not your computer. Treat it as such.
New contributor
add a comment |
3 Answers
3
active
oldest
votes
3 Answers
3
active
oldest
votes
active
oldest
votes
active
oldest
votes
Short answer: Generally an administrator account can access and read any file on the computer. To protect files, either remove all untrusted admin accounts except for yours or encrypt the specific files you need protected with your admin password. Another admin can reset your password, but not see it to unlock things like your keychain. Of course a new password for encryption is ideal if you don’t trust another admin.
There are certain files within your account that are encrypted and can not be read without your password.
The main file I'm thinking of is the "Keychain" which may contain your iCloud password and any other passwords you've allowed Safari (or other apps) to remember.
As an IT system administrator myself I would recommend not to store personal data on your work computer that you don't want anyone else to see.
The computer may have backup software that's backing up all files on the computer - including your iCloud Drive.
Also remember that if you're fired, the computer may be taken away before you have a chance to remove your personal files.
3
Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.
– Jörg W Mittag
yesterday
1
Plus, not all jurisdictions are that privacy-conscious.
– Jörg W Mittag
yesterday
1
This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.
– Konrad Rudolph
yesterday
@KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.
– nohillside♦
yesterday
add a comment |
Short answer: Generally an administrator account can access and read any file on the computer. To protect files, either remove all untrusted admin accounts except for yours or encrypt the specific files you need protected with your admin password. Another admin can reset your password, but not see it to unlock things like your keychain. Of course a new password for encryption is ideal if you don’t trust another admin.
There are certain files within your account that are encrypted and can not be read without your password.
The main file I'm thinking of is the "Keychain" which may contain your iCloud password and any other passwords you've allowed Safari (or other apps) to remember.
As an IT system administrator myself I would recommend not to store personal data on your work computer that you don't want anyone else to see.
The computer may have backup software that's backing up all files on the computer - including your iCloud Drive.
Also remember that if you're fired, the computer may be taken away before you have a chance to remove your personal files.
3
Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.
– Jörg W Mittag
yesterday
1
Plus, not all jurisdictions are that privacy-conscious.
– Jörg W Mittag
yesterday
1
This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.
– Konrad Rudolph
yesterday
@KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.
– nohillside♦
yesterday
add a comment |
Short answer: Generally an administrator account can access and read any file on the computer. To protect files, either remove all untrusted admin accounts except for yours or encrypt the specific files you need protected with your admin password. Another admin can reset your password, but not see it to unlock things like your keychain. Of course a new password for encryption is ideal if you don’t trust another admin.
There are certain files within your account that are encrypted and can not be read without your password.
The main file I'm thinking of is the "Keychain" which may contain your iCloud password and any other passwords you've allowed Safari (or other apps) to remember.
As an IT system administrator myself I would recommend not to store personal data on your work computer that you don't want anyone else to see.
The computer may have backup software that's backing up all files on the computer - including your iCloud Drive.
Also remember that if you're fired, the computer may be taken away before you have a chance to remove your personal files.
Short answer: Generally an administrator account can access and read any file on the computer. To protect files, either remove all untrusted admin accounts except for yours or encrypt the specific files you need protected with your admin password. Another admin can reset your password, but not see it to unlock things like your keychain. Of course a new password for encryption is ideal if you don’t trust another admin.
There are certain files within your account that are encrypted and can not be read without your password.
The main file I'm thinking of is the "Keychain" which may contain your iCloud password and any other passwords you've allowed Safari (or other apps) to remember.
As an IT system administrator myself I would recommend not to store personal data on your work computer that you don't want anyone else to see.
The computer may have backup software that's backing up all files on the computer - including your iCloud Drive.
Also remember that if you're fired, the computer may be taken away before you have a chance to remove your personal files.
edited yesterday
bmike♦
162k46290629
162k46290629
answered 2 days ago
BenBen
1963
1963
3
Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.
– Jörg W Mittag
yesterday
1
Plus, not all jurisdictions are that privacy-conscious.
– Jörg W Mittag
yesterday
1
This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.
– Konrad Rudolph
yesterday
@KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.
– nohillside♦
yesterday
add a comment |
3
Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.
– Jörg W Mittag
yesterday
1
Plus, not all jurisdictions are that privacy-conscious.
– Jörg W Mittag
yesterday
1
This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.
– Konrad Rudolph
yesterday
@KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.
– nohillside♦
yesterday
3
3
Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.
– Jörg W Mittag
yesterday
Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.
– Jörg W Mittag
yesterday
1
1
Plus, not all jurisdictions are that privacy-conscious.
– Jörg W Mittag
yesterday
Plus, not all jurisdictions are that privacy-conscious.
– Jörg W Mittag
yesterday
1
1
This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.
– Konrad Rudolph
yesterday
This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.
– Konrad Rudolph
yesterday
@KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.
– nohillside♦
yesterday
@KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.
– nohillside♦
yesterday
add a comment |
This document provided by Apple titled: Set up users, guests and groups on Mac covers the types of privileges each user type is allowed.
Administrator: An administrator can add and manage other users, install apps and change settings. The new user you create when you first set up your Mac is an administrator. Your Mac can have multiple administrators. You can create new ones, and convert standard users to administrators. Don’t set up automatic login for an administrator. If you do, someone could simply restart your Mac and gain access with administrator privileges. To keep your Mac secure, don’t share administrator names and passwords.
Expanding on this, basically an Administrator can access any of your files and pretty much do anything on the system.
References
- Protect files from other administrator accounts
add a comment |
This document provided by Apple titled: Set up users, guests and groups on Mac covers the types of privileges each user type is allowed.
Administrator: An administrator can add and manage other users, install apps and change settings. The new user you create when you first set up your Mac is an administrator. Your Mac can have multiple administrators. You can create new ones, and convert standard users to administrators. Don’t set up automatic login for an administrator. If you do, someone could simply restart your Mac and gain access with administrator privileges. To keep your Mac secure, don’t share administrator names and passwords.
Expanding on this, basically an Administrator can access any of your files and pretty much do anything on the system.
References
- Protect files from other administrator accounts
add a comment |
This document provided by Apple titled: Set up users, guests and groups on Mac covers the types of privileges each user type is allowed.
Administrator: An administrator can add and manage other users, install apps and change settings. The new user you create when you first set up your Mac is an administrator. Your Mac can have multiple administrators. You can create new ones, and convert standard users to administrators. Don’t set up automatic login for an administrator. If you do, someone could simply restart your Mac and gain access with administrator privileges. To keep your Mac secure, don’t share administrator names and passwords.
Expanding on this, basically an Administrator can access any of your files and pretty much do anything on the system.
References
- Protect files from other administrator accounts
This document provided by Apple titled: Set up users, guests and groups on Mac covers the types of privileges each user type is allowed.
Administrator: An administrator can add and manage other users, install apps and change settings. The new user you create when you first set up your Mac is an administrator. Your Mac can have multiple administrators. You can create new ones, and convert standard users to administrators. Don’t set up automatic login for an administrator. If you do, someone could simply restart your Mac and gain access with administrator privileges. To keep your Mac secure, don’t share administrator names and passwords.
Expanding on this, basically an Administrator can access any of your files and pretty much do anything on the system.
References
- Protect files from other administrator accounts
answered 2 days ago
slmslm
516414
516414
add a comment |
add a comment |
An Administrator account should be able to install software to log keystrokes, a keylogger. With your keyboard input captured, any passwords input would be captured and could be used to open otherwise secure applications and files. I cannot say whether Apple prevents their use on macOS, but anyone sufficiently determined would be able to circumvent such restrictions.
Also, screen capture software can often be used to determine what keystrokes have been made, especially on mobile devices where the on-screen keyboard keys pop-up as typed.
It is not your computer. Treat it as such.
New contributor
add a comment |
An Administrator account should be able to install software to log keystrokes, a keylogger. With your keyboard input captured, any passwords input would be captured and could be used to open otherwise secure applications and files. I cannot say whether Apple prevents their use on macOS, but anyone sufficiently determined would be able to circumvent such restrictions.
Also, screen capture software can often be used to determine what keystrokes have been made, especially on mobile devices where the on-screen keyboard keys pop-up as typed.
It is not your computer. Treat it as such.
New contributor
add a comment |
An Administrator account should be able to install software to log keystrokes, a keylogger. With your keyboard input captured, any passwords input would be captured and could be used to open otherwise secure applications and files. I cannot say whether Apple prevents their use on macOS, but anyone sufficiently determined would be able to circumvent such restrictions.
Also, screen capture software can often be used to determine what keystrokes have been made, especially on mobile devices where the on-screen keyboard keys pop-up as typed.
It is not your computer. Treat it as such.
New contributor
An Administrator account should be able to install software to log keystrokes, a keylogger. With your keyboard input captured, any passwords input would be captured and could be used to open otherwise secure applications and files. I cannot say whether Apple prevents their use on macOS, but anyone sufficiently determined would be able to circumvent such restrictions.
Also, screen capture software can often be used to determine what keystrokes have been made, especially on mobile devices where the on-screen keyboard keys pop-up as typed.
It is not your computer. Treat it as such.
New contributor
New contributor
answered 8 hours ago
newyork10023newyork10023
1
1
New contributor
New contributor
add a comment |
add a comment |
-macos, security, user-account