Security has a broad meaning in everyday life, but a more specific one when it comes to data, networks, computers, and mobile devices.
As a general rule, we talk about security when we mean a means of reducing the likelihood of harm. You go through a security checkpoint at the airport. You have a home security system. A lecture is canceled due to security concerns. An ad for a bike lock claims it offers high security.
With computing and networking, however, security is more specific: it’s the measures you take to prevent harm to you by the extraction, interception, loss, or corruption of your data.
You may also see the term exfiltration, which sounds highly technical but simply means the extraction of data from a device, often over a network, to a malicious or unwanted recipient.
It’s rare that a violation of your device’s security would result in physical harm to you or anyone else—unless someone attacks you while also stealing your equipment. That’s quite rare in a home or office, but it can happen when out and about, where an assault or threat of it could lead you to reveal your iPhone passcode or other passwords.
While it’s also rare to be attacked, or even drugged, to get your passcode, it does happen often enough that Apple added a new protection. See how to turn on Stolen Device Protection.
But even without a physical assault or fear of it, you can suffer emotional harm from the sense of invasion or damage that results from an invasion, particularly if someone violates your security to steal personal information that is then disseminated or used against you.
You can also certainly incur financial damage (theft of identity or money), waste your time (canceling credit cards, changing passwords), find yourself spending hours coping with the aftermath (removing malware, restoring deleted files), and so on. If your Mac became part of a botnet, you could also harm other people’s devices. As a result, your ISP might temporarily cut off your internet service to block attacks originating from inside its network.
Apple’s security options through the mid-2010s focused mostly on resisting attacks carried out over a network and exploits that relied on software that was downloaded and installed with or without your permission. In the new era stretching back nearly a decade now, Apple shifted to giving you tools and automatically protecting your data when someone can take physical control of your device.
The company also puts a lot of attention on blocking exploits and malware in macOS, which, because it allows any software to be installed, remains more vulnerable; the network as a vector for compromising a Mac is nearly entirely ignored. It’s different with iOS and iPadOS, as the key vector for attack there seems to be phishing text messages and attachments, which has led Apple to a constant cycle of hardening Messages and related components.
Protecting against physical attacks requires your device to resist intrusion. That intrusion might be someone merely sitting down in front of a Mac for a few minutes and extracting the contents of your drive without leaving a trace, popularized by hackers in movies. But it more frequently includes deterring a thief who has purloined your iPhone, iPad, or Mac—whether for a period of time or forever—from successfully cracking it at their leisure.
As a result, you now should think both about the digital sense of security and the physical sense:
- The digital part involves protecting your passwords and passcodes, guarding against remote attacks over the internet, and halting the delivery, installation, and deployment of malware.
- The physical part involves configuring and understanding Apple’s features that deter hands-on attacks, such as plugging in a USB or Thunderbolt device or even an SD Card that performs an exploit, and up to and including someone removing a motherboard or an SSD or hard disk drive or disassembling an iPhone or iPad. It also includes enabling Stolen Device Protection on an iPhone, Apple’s current highest level of optional physical security enhancement.
Improving your device’s security reduces the chance of certain harms:
- Loss of data
- Data taken off your device and sent elsewhere
- Degraded performance
- Malware that locks files or sends private data elsewhere
- Loss of control over your device, including being locked out
- Hijacking of your Apple Account, which could lead to permanent loss of access to the account
How security, privacy and anonymity differ
Security is closely related to privacy and anonymity, but distinct. Here’s how to keep the three terms straight:
- Security is freedom from danger or harm.
- Privacy is freedom from observation or attention.
- Anonymity is freedom from identification or recognition.
You can have security without privacy (imagine living in a house made of bulletproof glass). You can also have privacy without security (think of a changing room at a clothing store with just a curtain). And you can have both privacy and security without anonymity (think of a royal family ensconced in a castle).
When it comes to your digital life, these concepts—especially security and privacy—go together more often than not. Many of the harms or dangers that might befall you if your security is insufficient involve the exposure of personal data, so one of the biggest reasons to have better security is to maintain your privacy. Or, to put it the other way around, many of the things you can do to protect your privacy are, in fact, security measures.
Which of the three you most need shapes everything else, and that depends on your own risk profile.
