Chapter 1: Secure by Design.
About Cocoa Security.
Profiling Your Application's Security Risks.
Defining the Security Environment.
Defining and Mitigating Vulnerabilities.
Chapter 2: Managing Multiple Users.
Caveat for iPhone Developers.
Why We Have Multiple Users.
Understanding Directory Services.
Accessing User Preferences and Managed Preferences.
Chapter 3: Using the Filesystem Securely.
Access Control Lists.
FileVault and Other Encryption Options.
Layout and Security of a Typical Mac OS X Filesystem.
Aliases and Bookmarks.
Quarantining Downloaded Files.
Securely Deleting Files.
Chapter 4: Handling Multiple Processes.
Designing Multiple-Process Systems.
Managing Process Lifecycles with Launchd.
How to Use Setuid and Setgid.
Communication between Processes.
Playing in the Sandbox.
Guaranteeing Code's Origin.
Chapter 5: Storing Confidential Data in the Keychain.
What Is the Keychain?
Why Should I Use the Keychain?
How to Take Advantage of the Keychain.
Keychain on the iPhone.
Performing Chapter 6: Privileged Tasks.
How to Acquire Rights.
Factored Applications with Authorization Services.
The Authorization Database.
Why Not to Launch Privileged Tasks with Authorization Services.
Chapter 7: Auditing Im portant Operations.
Examples of Auditing.
Using Apple System Logger.
Basic Security Module.
Chapter 8: Securing Network Connections.
Privilege Boundaries in Networked Applications.
Does 'Bonjour' Mean It's Adieu to Network Security?
Working with the Firewall.
Network Configuration with SystemConfiguration.
Taking Advantage of SSL.
Chapter 9: Writing Secure Application Code.
Secure Objective-C Coding.
Secure C Coding.
Code Reviews and Other Bug-Finding Techniques.
Deploying Chapter 10: Software Securely.
Writing Security Documentation.
Identify Yourself with Code Signing.
Giving Your Code to Your Users.
Rolling Your Own Installer.
Deploying Privileged Helpers without Installers.
Responding to Security Problems.
Chapter 11: Kernel Extensions.
The Kernel Environment.
Filesystem Access Authorization with Kauth.
Chapter 12: Conclusion and Further Reading.