What can other administrators access on my machine? The 2019 Stack Overflow Developer Survey Results Are In Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern)Protect files from other administrator accountsHow secure are iCloud backups?Unwanted saving of proxy credentialsnsurlsessiond is using all my bandwidthOnly root login remains (all other users gone) and even root hangs, so can't access!How can you switch users at the login screen, without administrator access, with only one local account (the administrator) and many network accounts?Protect files from other administrator accountsCan a thief know my Apple ID without my PIN code?I have a company MacBook Pro and I no longer can see my username on the login screenFileVault and other user accounts; repairEffects of logging in to same Apple ID on multiple macOS accounts (single computer)

What happens to a Warlock's expended Spell Slots when they gain a Level?

One-dimensional Japanese puzzle

Do I have Disadvantage attacking with an off-hand weapon?

Can the DM override racial traits?

Keeping a retro style to sci-fi spaceships?

Why are PDP-7-style microprogrammed instructions out of vogue?

How to handle characters who are more educated than the author?

Sub-subscripts in strings cause different spacings than subscripts

Nested ellipses in tikzpicture: Chomsky hierarchy

Is an up-to-date browser secure on an out-of-date OS?

Mortgage adviser recommends a longer term than necessary combined with overpayments

Are spiders unable to hurt humans, especially very small spiders?

Can each chord in a progression create its own key?

ELI5: Why do they say that Israel would have been the fourth country to land a spacecraft on the Moon and why do they call it low cost?

Intergalactic human space ship encounters another ship, character gets shunted off beyond known universe, reality starts collapsing

Can withdrawing asylum be illegal?

Do warforged have souls?

should truth entail possible truth

Identify 80s or 90s comics with ripped creatures (not dwarves)

How did passengers keep warm on sail ships?

Single author papers against my advisor's will?

Didn't get enough time to take a Coding Test - what to do now?

Deal with toxic manager when you can't quit

Does Parliament hold absolute power in the UK?



What can other administrators access on my machine?



The 2019 Stack Overflow Developer Survey Results Are In
Announcing the arrival of Valued Associate #679: Cesar Manara
Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern)Protect files from other administrator accountsHow secure are iCloud backups?Unwanted saving of proxy credentialsnsurlsessiond is using all my bandwidthOnly root login remains (all other users gone) and even root hangs, so can't access!How can you switch users at the login screen, without administrator access, with only one local account (the administrator) and many network accounts?Protect files from other administrator accountsCan a thief know my Apple ID without my PIN code?I have a company MacBook Pro and I no longer can see my username on the login screenFileVault and other user accounts; repairEffects of logging in to same Apple ID on multiple macOS accounts (single computer)



.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;








6















I've been given a new MacBook Pro at work, and it has an administrator account which I assume the IT department has the credentials to. I have been created a local account which is also an administrator.



I'm just wondering, as another administrator, what of my data can they access and read? I have iCloud Drive and other services turned on, and I don't particularly like the idea that someone can go in and grab that stuff.










share|improve this question






























    6















    I've been given a new MacBook Pro at work, and it has an administrator account which I assume the IT department has the credentials to. I have been created a local account which is also an administrator.



    I'm just wondering, as another administrator, what of my data can they access and read? I have iCloud Drive and other services turned on, and I don't particularly like the idea that someone can go in and grab that stuff.










    share|improve this question


























      6












      6








      6


      1






      I've been given a new MacBook Pro at work, and it has an administrator account which I assume the IT department has the credentials to. I have been created a local account which is also an administrator.



      I'm just wondering, as another administrator, what of my data can they access and read? I have iCloud Drive and other services turned on, and I don't particularly like the idea that someone can go in and grab that stuff.










      share|improve this question
















      I've been given a new MacBook Pro at work, and it has an administrator account which I assume the IT department has the credentials to. I have been created a local account which is also an administrator.



      I'm just wondering, as another administrator, what of my data can they access and read? I have iCloud Drive and other services turned on, and I don't particularly like the idea that someone can go in and grab that stuff.







      macos security user-account






      share|improve this question















      share|improve this question













      share|improve this question




      share|improve this question








      edited 2 days ago









      bmike

      162k46291630




      162k46291630










      asked Apr 9 at 23:28









      RickyRicky

      23018




      23018




















          3 Answers
          3






          active

          oldest

          votes


















          8














          Short answer: Generally an administrator account can access and read any file on the computer. To protect files, either remove all untrusted admin accounts except for yours or encrypt the specific files you need protected with your admin password. Another admin can reset your password, but not see it to unlock things like your keychain. Of course a new password for encryption is ideal if you don’t trust another admin.



          There are certain files within your account that are encrypted and can not be read without your password.



          The main file I'm thinking of is the "Keychain" which may contain your iCloud password and any other passwords you've allowed Safari (or other apps) to remember.




          As an IT system administrator myself I would recommend not to store personal data on your work computer that you don't want anyone else to see.



          The computer may have backup software that's backing up all files on the computer - including your iCloud Drive.



          Also remember that if you're fired, the computer may be taken away before you have a chance to remove your personal files.






          share|improve this answer




















          • 4





            Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.

            – Jörg W Mittag
            2 days ago






          • 1





            Plus, not all jurisdictions are that privacy-conscious.

            – Jörg W Mittag
            2 days ago






          • 1





            This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.

            – Konrad Rudolph
            2 days ago







          • 1





            @KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.

            – nohillside
            2 days ago


















          6














          This document provided by Apple titled: Set up users, guests and groups on Mac covers the types of privileges each user type is allowed.




          Administrator: An administrator can add and manage other users, install apps and change settings. The new user you create when you first set up your Mac is an administrator. Your Mac can have multiple administrators. You can create new ones, and convert standard users to administrators. Don’t set up automatic login for an administrator. If you do, someone could simply restart your Mac and gain access with administrator privileges. To keep your Mac secure, don’t share administrator names and passwords.




          Expanding on this, basically an Administrator can access any of your files and pretty much do anything on the system.



          References



          • Protect files from other administrator accounts





          share|improve this answer






























            1














            An Administrator account should be able to install software to log keystrokes, a keylogger. With your keyboard input captured, any passwords input would be captured and could be used to open otherwise secure applications and files. I cannot say whether Apple prevents their use on macOS, but anyone sufficiently determined would be able to circumvent such restrictions.



            Also, screen capture software can often be used to determine what keystrokes have been made, especially on mobile devices where the on-screen keyboard keys pop-up as typed.



            It is not your computer. Treat it as such.






            share|improve this answer








            New contributor




            newyork10023 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
            Check out our Code of Conduct.



























              3 Answers
              3






              active

              oldest

              votes








              3 Answers
              3






              active

              oldest

              votes









              active

              oldest

              votes






              active

              oldest

              votes









              8














              Short answer: Generally an administrator account can access and read any file on the computer. To protect files, either remove all untrusted admin accounts except for yours or encrypt the specific files you need protected with your admin password. Another admin can reset your password, but not see it to unlock things like your keychain. Of course a new password for encryption is ideal if you don’t trust another admin.



              There are certain files within your account that are encrypted and can not be read without your password.



              The main file I'm thinking of is the "Keychain" which may contain your iCloud password and any other passwords you've allowed Safari (or other apps) to remember.




              As an IT system administrator myself I would recommend not to store personal data on your work computer that you don't want anyone else to see.



              The computer may have backup software that's backing up all files on the computer - including your iCloud Drive.



              Also remember that if you're fired, the computer may be taken away before you have a chance to remove your personal files.






              share|improve this answer




















              • 4





                Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.

                – Jörg W Mittag
                2 days ago






              • 1





                Plus, not all jurisdictions are that privacy-conscious.

                – Jörg W Mittag
                2 days ago






              • 1





                This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.

                – Konrad Rudolph
                2 days ago







              • 1





                @KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.

                – nohillside
                2 days ago















              8














              Short answer: Generally an administrator account can access and read any file on the computer. To protect files, either remove all untrusted admin accounts except for yours or encrypt the specific files you need protected with your admin password. Another admin can reset your password, but not see it to unlock things like your keychain. Of course a new password for encryption is ideal if you don’t trust another admin.



              There are certain files within your account that are encrypted and can not be read without your password.



              The main file I'm thinking of is the "Keychain" which may contain your iCloud password and any other passwords you've allowed Safari (or other apps) to remember.




              As an IT system administrator myself I would recommend not to store personal data on your work computer that you don't want anyone else to see.



              The computer may have backup software that's backing up all files on the computer - including your iCloud Drive.



              Also remember that if you're fired, the computer may be taken away before you have a chance to remove your personal files.






              share|improve this answer




















              • 4





                Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.

                – Jörg W Mittag
                2 days ago






              • 1





                Plus, not all jurisdictions are that privacy-conscious.

                – Jörg W Mittag
                2 days ago






              • 1





                This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.

                – Konrad Rudolph
                2 days ago







              • 1





                @KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.

                – nohillside
                2 days ago













              8












              8








              8







              Short answer: Generally an administrator account can access and read any file on the computer. To protect files, either remove all untrusted admin accounts except for yours or encrypt the specific files you need protected with your admin password. Another admin can reset your password, but not see it to unlock things like your keychain. Of course a new password for encryption is ideal if you don’t trust another admin.



              There are certain files within your account that are encrypted and can not be read without your password.



              The main file I'm thinking of is the "Keychain" which may contain your iCloud password and any other passwords you've allowed Safari (or other apps) to remember.




              As an IT system administrator myself I would recommend not to store personal data on your work computer that you don't want anyone else to see.



              The computer may have backup software that's backing up all files on the computer - including your iCloud Drive.



              Also remember that if you're fired, the computer may be taken away before you have a chance to remove your personal files.






              share|improve this answer















              Short answer: Generally an administrator account can access and read any file on the computer. To protect files, either remove all untrusted admin accounts except for yours or encrypt the specific files you need protected with your admin password. Another admin can reset your password, but not see it to unlock things like your keychain. Of course a new password for encryption is ideal if you don’t trust another admin.



              There are certain files within your account that are encrypted and can not be read without your password.



              The main file I'm thinking of is the "Keychain" which may contain your iCloud password and any other passwords you've allowed Safari (or other apps) to remember.




              As an IT system administrator myself I would recommend not to store personal data on your work computer that you don't want anyone else to see.



              The computer may have backup software that's backing up all files on the computer - including your iCloud Drive.



              Also remember that if you're fired, the computer may be taken away before you have a chance to remove your personal files.







              share|improve this answer














              share|improve this answer



              share|improve this answer








              edited 2 days ago









              bmike

              162k46291630




              162k46291630










              answered 2 days ago









              BenBen

              1963




              1963







              • 4





                Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.

                – Jörg W Mittag
                2 days ago






              • 1





                Plus, not all jurisdictions are that privacy-conscious.

                – Jörg W Mittag
                2 days ago






              • 1





                This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.

                – Konrad Rudolph
                2 days ago







              • 1





                @KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.

                – nohillside
                2 days ago












              • 4





                Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.

                – Jörg W Mittag
                2 days ago






              • 1





                Plus, not all jurisdictions are that privacy-conscious.

                – Jörg W Mittag
                2 days ago






              • 1





                This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.

                – Konrad Rudolph
                2 days ago







              • 1





                @KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.

                – nohillside
                2 days ago







              4




              4





              Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.

              – Jörg W Mittag
              2 days ago





              Even in jurisdictions that are typically very worker- and privacy-friendly, it is generally accepted that all files you store on a company device "belong to" the company, at least in the sense that they can arbitrarily delete them. While in the more privacy-conscious jurisdictions, it may be illegal for an IT admin to continue reading when he accidentally discovers private files on your device, there is a) no guarantee that he will actually do that, and b) he is allowed anyway to read anything on your device until he discovers obviously private data.

              – Jörg W Mittag
              2 days ago




              1




              1





              Plus, not all jurisdictions are that privacy-conscious.

              – Jörg W Mittag
              2 days ago





              Plus, not all jurisdictions are that privacy-conscious.

              – Jörg W Mittag
              2 days ago




              1




              1





              This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.

              – Konrad Rudolph
              2 days ago






              This answer doesn't address FileVault (nor encrypted backups). Can encrypted files inside FileVault be read by other admins? I thought the answer was no.

              – Konrad Rudolph
              2 days ago





              1




              1





              @KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.

              – nohillside
              2 days ago





              @KonradRudolph The original version of FileVault (which encrypted individual home directories) could not be read be others unless a specific user was logged in. The current version with full disk encryption does not provide that level of privacy, any user allowed to unlock will unlock the whole disk.

              – nohillside
              2 days ago













              6














              This document provided by Apple titled: Set up users, guests and groups on Mac covers the types of privileges each user type is allowed.




              Administrator: An administrator can add and manage other users, install apps and change settings. The new user you create when you first set up your Mac is an administrator. Your Mac can have multiple administrators. You can create new ones, and convert standard users to administrators. Don’t set up automatic login for an administrator. If you do, someone could simply restart your Mac and gain access with administrator privileges. To keep your Mac secure, don’t share administrator names and passwords.




              Expanding on this, basically an Administrator can access any of your files and pretty much do anything on the system.



              References



              • Protect files from other administrator accounts





              share|improve this answer



























                6














                This document provided by Apple titled: Set up users, guests and groups on Mac covers the types of privileges each user type is allowed.




                Administrator: An administrator can add and manage other users, install apps and change settings. The new user you create when you first set up your Mac is an administrator. Your Mac can have multiple administrators. You can create new ones, and convert standard users to administrators. Don’t set up automatic login for an administrator. If you do, someone could simply restart your Mac and gain access with administrator privileges. To keep your Mac secure, don’t share administrator names and passwords.




                Expanding on this, basically an Administrator can access any of your files and pretty much do anything on the system.



                References



                • Protect files from other administrator accounts





                share|improve this answer

























                  6












                  6








                  6







                  This document provided by Apple titled: Set up users, guests and groups on Mac covers the types of privileges each user type is allowed.




                  Administrator: An administrator can add and manage other users, install apps and change settings. The new user you create when you first set up your Mac is an administrator. Your Mac can have multiple administrators. You can create new ones, and convert standard users to administrators. Don’t set up automatic login for an administrator. If you do, someone could simply restart your Mac and gain access with administrator privileges. To keep your Mac secure, don’t share administrator names and passwords.




                  Expanding on this, basically an Administrator can access any of your files and pretty much do anything on the system.



                  References



                  • Protect files from other administrator accounts





                  share|improve this answer













                  This document provided by Apple titled: Set up users, guests and groups on Mac covers the types of privileges each user type is allowed.




                  Administrator: An administrator can add and manage other users, install apps and change settings. The new user you create when you first set up your Mac is an administrator. Your Mac can have multiple administrators. You can create new ones, and convert standard users to administrators. Don’t set up automatic login for an administrator. If you do, someone could simply restart your Mac and gain access with administrator privileges. To keep your Mac secure, don’t share administrator names and passwords.




                  Expanding on this, basically an Administrator can access any of your files and pretty much do anything on the system.



                  References



                  • Protect files from other administrator accounts






                  share|improve this answer












                  share|improve this answer



                  share|improve this answer










                  answered Apr 9 at 23:36









                  slmslm

                  530414




                  530414





















                      1














                      An Administrator account should be able to install software to log keystrokes, a keylogger. With your keyboard input captured, any passwords input would be captured and could be used to open otherwise secure applications and files. I cannot say whether Apple prevents their use on macOS, but anyone sufficiently determined would be able to circumvent such restrictions.



                      Also, screen capture software can often be used to determine what keystrokes have been made, especially on mobile devices where the on-screen keyboard keys pop-up as typed.



                      It is not your computer. Treat it as such.






                      share|improve this answer








                      New contributor




                      newyork10023 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                      Check out our Code of Conduct.
























                        1














                        An Administrator account should be able to install software to log keystrokes, a keylogger. With your keyboard input captured, any passwords input would be captured and could be used to open otherwise secure applications and files. I cannot say whether Apple prevents their use on macOS, but anyone sufficiently determined would be able to circumvent such restrictions.



                        Also, screen capture software can often be used to determine what keystrokes have been made, especially on mobile devices where the on-screen keyboard keys pop-up as typed.



                        It is not your computer. Treat it as such.






                        share|improve this answer








                        New contributor




                        newyork10023 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                        Check out our Code of Conduct.






















                          1












                          1








                          1







                          An Administrator account should be able to install software to log keystrokes, a keylogger. With your keyboard input captured, any passwords input would be captured and could be used to open otherwise secure applications and files. I cannot say whether Apple prevents their use on macOS, but anyone sufficiently determined would be able to circumvent such restrictions.



                          Also, screen capture software can often be used to determine what keystrokes have been made, especially on mobile devices where the on-screen keyboard keys pop-up as typed.



                          It is not your computer. Treat it as such.






                          share|improve this answer








                          New contributor




                          newyork10023 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                          Check out our Code of Conduct.










                          An Administrator account should be able to install software to log keystrokes, a keylogger. With your keyboard input captured, any passwords input would be captured and could be used to open otherwise secure applications and files. I cannot say whether Apple prevents their use on macOS, but anyone sufficiently determined would be able to circumvent such restrictions.



                          Also, screen capture software can often be used to determine what keystrokes have been made, especially on mobile devices where the on-screen keyboard keys pop-up as typed.



                          It is not your computer. Treat it as such.







                          share|improve this answer








                          New contributor




                          newyork10023 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                          Check out our Code of Conduct.









                          share|improve this answer



                          share|improve this answer






                          New contributor




                          newyork10023 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                          Check out our Code of Conduct.









                          answered yesterday









                          newyork10023newyork10023

                          111




                          111




                          New contributor




                          newyork10023 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                          Check out our Code of Conduct.





                          New contributor





                          newyork10023 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                          Check out our Code of Conduct.






                          newyork10023 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                          Check out our Code of Conduct.













                              Popular posts from this blog

                              Tamil (spriik) Luke uk diar | Nawigatjuun

                              Align equal signs while including text over equalitiesAMS align: left aligned text/math plus multicolumn alignmentMultiple alignmentsAligning equations in multiple placesNumbering and aligning an equation with multiple columnsHow to align one equation with another multline equationUsing \ in environments inside the begintabularxNumber equations and preserving alignment of equal signsHow can I align equations to the left and to the right?Double equation alignment problem within align enviromentAligned within align: Why are they right-aligned?

                              Training a classifier when some of the features are unknownWhy does Gradient Boosting regression predict negative values when there are no negative y-values in my training set?How to improve an existing (trained) classifier?What is effect when I set up some self defined predisctor variables?Why Matlab neural network classification returns decimal values on prediction dataset?Fitting and transforming text data in training, testing, and validation setsHow to quantify the performance of the classifier (multi-class SVM) using the test data?How do I control for some patients providing multiple samples in my training data?Training and Test setTraining a convolutional neural network for image denoising in MatlabShouldn't an autoencoder with #(neurons in hidden layer) = #(neurons in input layer) be “perfect”?