Skip to content

Releases: supervking/MakLock-Secure

Maclock Secure MacOS 1.5.3

Choose a tag to compare

@supervking supervking released this 11 Sep 18:55
04c294d

中文

本版本新增受 macOS 所有者认证保护的应用密码恢复,并修复系统认证中断后锁屏无法继续输入的严重问题。

  • 在主可信显示器的锁屏中新增“忘记应用密码?”入口
  • 使用 Touch ID 或 Mac 登录密码完成系统认证后,允许设置新的应用密码
  • 重置成功后受保护应用继续保持锁定,必须使用新密码重新解锁
  • 区分密码不匹配、Keychain 项目缺失、访问失败和数据损坏;只有真实密码错误才进入限流
  • 使用原子 Keychain 更新,写入失败时保留原密码
  • 系统认证取消、超时或回调丢失后恢复锁屏输入,不再需要重启电脑
  • 阻止旧认证回调覆盖新请求,并避免认证期间焦点恢复抢走系统密码框
  • 修复密码框失焦触发提交、提交时读取旧值以及普通按键引发表单刷新的问题
  • 增加 Caps Lock 提示、主可信显示器限制,以及中英文界面说明
  • 将五组密码、认证和安全状态回归测试加入 GitHub Actions

已验证密码重置、重置后保持锁定、新密码登录、系统认证连续取消后重新操作,以及通用 Release 构建和签名完整性。

English

This release adds app-password recovery protected by macOS owner authentication and fixes a severe lock-screen input failure after interrupted native authentication.

  • adds “Forgot App Password?” on the primary trusted lock screen
  • requires Touch ID or the Mac login password before setting a new app password
  • keeps protected apps locked after reset and requires the new password to unlock
  • separates password mismatch, missing Keychain item, access failure, and invalid stored data
  • counts only real mismatches toward password throttling
  • updates the Keychain item atomically and preserves the old password on failure
  • restores lock-screen input after native-authentication cancellation, timeout, or a missing callback
  • rejects stale authentication callbacks and prevents focus recovery from stealing the native dialog
  • fixes blur-triggered submission, stale secure-field values, and unnecessary per-keystroke view refreshes
  • adds Caps Lock guidance, trusted-display recovery restrictions, bilingual copy, and CI regression coverage

The downloadable application remains ad-hoc signed and non-notarized. Verify the matching SHA-256 file before installation.

Maclock Secure MacOS 1.5.2

Choose a tag to compare

@supervking supervking released this 09 Sep 23:10
890c215

中文

本版本将公开英文品牌更新为 Maclock Secure MacOS,简体中文名称更新为 MAC锁屏加密应用,并重写 GitHub 中英文介绍,重点说明远程电脑防偷窥、无人值守 Mac 隐私保护和实际安全边界。

  • 新增 Mac锁屏、macOS应用锁、Mac应用加密、远程电脑防偷窥和显示器防窥等自然中文检索入口
  • 新增远程控制断线、闲置、睡眠、现场人员打开敏感应用和未授权显示器接入等场景说明
  • 新增菜单栏、通用、应用、安全性、Apple Watch、关于、密码锁定和显示器警报共 8 张中文 Release 页面截图
  • 更新中英文可见名称、权限提示、菜单栏提示、设置、关于和欢迎页面
  • 更新应用图标文字为 Maclock,同时保持 MakLock.app、Bundle ID com.makmak.MakLock、仓库 URL 和本机配置兼容
  • 修复关闭“关于”窗口后 AppKit 在窗口释放动画中发生 SIGSEGV、导致菜单栏进程退出的问题
  • GitHub Actions 不再通过 || true 掩盖 xcodebuild 失败

本软件保护当前已登录 macOS 账户内的应用可见内容,不加密远程控制协议,不替代 FileVault、系统锁屏、独立用户账户或现场物理管理。

English

This release adopts the public English brand Maclock Secure MacOS and the Simplified Chinese name MAC锁屏加密应用, then rebuilds the repository presentation around remote-computer privacy, unattended Mac protection, and explicit security boundaries.

  • Adds a dedicated remote-computer privacy and shoulder-surfing section
  • Adds eight privacy-safe Simplified Chinese Release screenshots
  • Refreshes visible names, permission messages, menu-bar labels, settings, About, onboarding, and the app icon
  • Preserves MakLock.app, com.makmak.MakLock, the repository URL, Keychain data, and existing settings
  • Fixes the AppKit SIGSEGV that could occur after closing the About window by retaining and reusing one non-released window with animations disabled
  • Makes GitHub Actions fail when xcodebuild fails instead of masking the result

The downloadable application is ad-hoc signed and not Apple-notarized. Verify the matching SHA-256 file before installation. GitHub and external search reindexing may take time.

MakLock Secure 1.5.1

Choose a tag to compare

@supervking supervking released this 09 Sep 18:03
881444e

中文

本版本补齐未授权显示器快速接入后立即拔出的持续取证与警报,并修复ad-hoc签名更新可能阻塞应急恢复配置读取的问题。

  • 新增显示器add/remove/mirror/unmirror结构事件锁存
  • 即使最终显示器配置在约0.35秒稳定评估前已经恢复可信,红色全屏警报仍保持显示
  • 警报明确提示:检测到未授权显示器曾接入,当前已拔出,请电脑所有者确认
  • 必须完成MakLock认证才能解除,拔掉显示器不会自动清除
  • 继续保留静音时效性macOS通知、红色菜单栏状态和12小时安全记录
  • 红色警报未解除期间再次发生快速插拔,会增加新的时间记录并刷新通知
  • 显示器睡眠、唤醒、分辨率、刷新率、显示模式和桌面尺寸变化不会进入持续防篡改锁存
  • 原有持续连接显示器警报及隐藏应急重启恢复继续有效
  • 应急恢复配置与序列改为重启前同步写入本机应用状态,避免ad-hoc版本签名变化触发Keychain授权框
  • MakLock密码及密码错误限制状态仍保存在Keychain

没有自动执行真实显示器插拔或系统重启。极快到macOS完全没有识别和上报的硬件行为仍无法由普通应用检测。

English

This release preserves evidence and warning state when an unauthorized display is connected and removed before the stabilized evaluation finishes, and prevents ad-hoc signature updates from blocking emergency recovery configuration reads.

  • Latches add, remove, mirror, and unmirror display topology signals
  • Keeps the red full-screen alert even when the trusted configuration has already returned before the debounce evaluation completes
  • Requires MakLock authentication; removing the display never clears the alert automatically
  • Retains the silent time-sensitive macOS notification, red menu-bar status, and 12-hour security history
  • Records repeated brief structural tamper events while an alert is still active
  • Excludes display sleep, wake, resolution, refresh-rate, mode, and desktop-shape-only changes from the persistent latch
  • Preserves the existing connected-display alert and hidden emergency restart recovery
  • Synchronizes non-secret emergency recovery configuration and sequence state to local application storage before restart, avoiding Keychain ACL prompts after ad-hoc signature changes
  • Keeps MakLock passwords and password attempt throttling state in Keychain

No real display insertion or system restart was automatically performed. Hardware activity that macOS never detects or reports cannot be observed by an ordinary application.

The downloadable app is ad-hoc signed and not Apple-notarized. Verify the included SHA-256 file before installation.

MakLock Secure 1.5.0

Choose a tag to compare

@supervking supervking released this 09 Sep 17:21
83f459f

中文

本版本为未授权显示器红色警报增加所有者配置的隐藏应急重启恢复,同时保留受保护应用的正常密码锁。

  • 红色警报页面只显示普通“重新启动电脑”按钮,不显示恢复阈值、时间窗口或进度
  • 只有从警报按钮发起、Boot ID确实变化、显示器指纹保持一致且在所有者设定时间内完成的重启才有效
  • 配置和序列状态只保存在本机Keychain,不写入普通偏好设置
  • 成功恢复仅对验证后的当前Boot和相同显示器指纹有效
  • 不修改可信显示器基线,不关闭MakLock总体保护
  • 每次重启请求及有效恢复启动都会退出受保护应用并清除临时认证
  • 恢复后打开Codex、Chrome或其他受保护应用仍需正常MakLock认证
  • 下一次重启、显示器再次变化、恢复可信配置、超时或关闭保护都会清除恢复状态
  • 使用固定Apple Event执行正常macOS重启,不接收外部命令参数
  • 增加中英文设置、安全记录和边界测试

应急重启恢复默认关闭,只能在通过认证的“设置 → 安全性 → 显示器应急恢复”中启用。出于远程连接安全,本版本的自动验证没有执行真实系统重启。

English

This release adds an owner-configured hidden emergency restart recovery path to the unauthorized-display alert while retaining normal authentication for protected apps.

  • The red alert exposes only a normal Restart Mac control and never shows recovery thresholds, deadlines, or progress
  • Only alert-requested restarts with a verified new Boot ID, unchanged display digest, and owner-configured rolling deadline can advance recovery
  • Configuration and sequence state stay in the local macOS Keychain, not ordinary preferences
  • A successful bypass is limited to the validated current Boot ID and the same display digest
  • The trusted display baseline and global MakLock protection remain unchanged
  • Protected apps are closed and temporary authentication is cleared before restart requests and validated recovery boots
  • Codex, Chrome, and other protected apps still require normal MakLock authentication after recovery
  • Another restart, display change, trusted configuration restoration, timeout, or protection disablement clears recovery state
  • Uses a fixed Apple Event for a normal macOS restart and accepts no external command parameters
  • Includes bilingual settings, security history labels, and state-boundary tests

Emergency restart recovery is disabled by default and can be enabled only from the authenticated Settings → Security → Emergency Display Recovery section. Automated verification did not perform a real system restart in order to preserve remote access.

The downloadable app is ad-hoc signed and not Apple-notarized. Verify the included SHA-256 file before installation.

MakLock Secure 1.4.0

Choose a tag to compare

@supervking supervking released this 09 Sep 15:10
3ed2653

中文

本版本新增静音的未授权显示器强警报,面向无人在场和远程管理的 Mac mini。

  • 显示器结构开始变化时立即用全屏遮罩隐藏桌面
  • 确认出现陌生、额外、镜像或被替换显示器后,在所有屏幕显示红色安全警报
  • 明确提示:非法接入显示器,请立即拔出
  • 警报期间阻止键盘和鼠标输入传给遮罩后的应用
  • 同时发送静音的时效性 macOS 通知,并把菜单栏图标切换为红色警报盾牌
  • 必须先恢复可信显示器配置,再通过密码或系统认证才能恢复桌面
  • 显示器恢复不会自动解锁受保护应用
  • 修改可信显示器基线前必须完成系统认证和二次确认
  • 保留 12 小时非敏感安全记录以及现有密码防暴力猜测机制
  • 不退出 RustDesk,不断网,不进入系统锁屏,也不终止受保护应用的后台任务

普通显示器新增、移除、镜像和替换可以被检测。被动 HDMI 分配器或完整复制可信 EDID 且不改变 macOS 显示器拓扑的硬件可能无法识别。

English

This release adds a silent, prominent unauthorized-display alert for unattended and remotely managed Mac minis.

  • Immediately covers the desktop while structural display changes are evaluated
  • Shows a red full-screen security warning across all screens when an unknown, additional, mirrored, or replacement display is confirmed
  • Prevents keyboard and mouse input from reaching applications behind the warning
  • Posts a silent time-sensitive macOS notification and switches the menu-bar icon to a red alert shield
  • Requires the trusted display setup to return and authentication to succeed before the desktop is restored
  • Never auto-unlocks protected apps after display recovery
  • Requires system authentication and confirmation before replacing the trusted display baseline
  • Keeps the 12-hour non-sensitive security log and existing password throttling
  • Does not stop remote-access software, disconnect networking, invoke the macOS lock screen, or terminate protected-app background work

Passive HDMI splitters or devices that perfectly clone a trusted EDID without changing the macOS display topology may not be detectable.

The downloadable app is ad-hoc signed and not Apple-notarized. Verify the included SHA-256 file before installation.

MakLock Secure 1.3.2

Choose a tag to compare

@supervking supervking released this 09 Sep 11:54
3e317b2

中文

本版本修复远程解锁后必须点击密码框,以及密码可能输入到受保护应用的问题。

  • 密码模式改用可激活的锁屏窗口,进入桌面即可直接输入密码
  • 密码输入期间临时隐藏当前受保护应用,但不退出、不终止其后台任务
  • macOS 会话恢复、屏幕唤醒或其他应用抢占焦点后,持续重新确认密码栏焦点
  • 正确密码按回车即可解锁,无需再点击解锁按钮
  • 保留 Touch ID 作为可选方式

English

This release prevents password keystrokes from reaching a protected app after remote session restore.

  • Uses an activating lock overlay for password entry
  • Temporarily hides, but never terminates, the protected app while typing a password
  • Reasserts secure-field focus after session restore, screen wake, or competing app activation
  • Pressing Return after the correct password unlocks immediately
  • Keeps Touch ID available as an optional fallback

The downloadable app is ad-hoc signed and not Apple-notarized. Verify the included SHA-256 file before installation.

MakLock Secure 1.3.1

Choose a tag to compare

@supervking supervking released this 09 Sep 10:23
fe1d5db

Native password focus recovery / 原生密码框焦点恢复

  • Replaces SwiftUI-only focus handling with a native AppKit NSSecureTextField.
  • Verifies the actual field editor/first responder rather than only the window key state.
  • macOS session recovery retries at 0, 0.5, 1.5, 3, and 5 seconds and stops immediately after success.
  • Dynamically chooses the password field on the current main display after display changes.
  • Preserves password throttling, Touch ID isolation, and Return-to-unlock behavior.
  • 使用原生 AppKit 安全密码框替代单纯 SwiftUI 焦点状态。
  • 直接验证真实第一响应者;系统解锁后在 0、0.5、1.5、3、5 秒有限重试,成功即停止。
  • 显示器变化后动态选择当前主屏密码框。
  • 保留密码防破解、Touch ID 隔离和按 Return 解锁。

Universal build: Apple Silicon + Intel. Ad-hoc signed; not notarized.

MakLock Secure 1.3.0

Choose a tag to compare

@supervking supervking released this 08 Sep 23:51
b1d36e5

Remote-safe advanced protection / 远程安全高级保护

  • After a real Mac restart, automatically restored protected apps are closed during a one-time 90-second startup window. Remote-access and system apps are permanently excluded.
  • Password fields recover focus after the macOS session becomes active or screens wake, with bounded retries up to 4 seconds.
  • Wrong passwords receive progressive delays of 2 seconds, 4 seconds, 30 seconds, and 5 minutes. A fifth failure within 30 minutes blocks password unlock for 3 hours.
  • Password throttling is stored in the macOS Keychain and survives MakLock and Mac restarts. Touch ID and Apple Watch remain available.
  • Non-sensitive security history is retained for only 12 hours and capped at 200 records.
  • Idle timeout now records and triggers only once per idle period.
  • Mac 真正重启后,在单次 90 秒保护期内关闭系统自动恢复的受保护应用;远程控制和系统应用永久排除。
  • macOS 会话恢复或屏幕唤醒后,密码框在最多 4 秒内进行有限焦点恢复。
  • 密码错误依次限制 2 秒、4 秒、30 秒和 5 分钟;30 分钟内第五次错误后封锁密码解锁 3 小时。
  • 密码限制保存在 Keychain,重启 MakLock 或 Mac 不会清除;Touch ID 和 Apple Watch 仍可使用。
  • 非敏感安全记录只保留 12 小时、最多 200 条。

Universal build: Apple Silicon + Intel. Ad-hoc signed; not notarized.

MakLock Secure 1.2.0

Choose a tag to compare

@supervking supervking released this 08 Sep 20:35
9fe0e01

Security-event locking / 安全事件锁定

  • Optional lock after all three independent internet probes fail continuously for 1, 2, or 5 minutes.
  • Network recovery never unlocks protected apps automatically.
  • Optional immediate lock when the trusted display fingerprint list changes.
  • Display additions, removals, replacements, and duplicate-fingerprint count changes are detected; resolution-only changes are ignored.
  • Security-event locks clear all authentication sessions but never invoke per-app auto-close.
  • 可在全部三个独立联网探测持续失败 1、2 或 5 分钟后锁定受保护应用。
  • 网络恢复后绝不自动解锁。
  • 可信显示器指纹列表变化时立即锁定;检测新增、拔除、替换及同指纹数量变化,仅分辨率变化不触发。
  • 安全事件只清除认证和锁定,不会退出受保护应用。

Universal build: Apple Silicon + Intel. Ad-hoc signed; not notarized.

MakLock Secure 1.1.5

Choose a tag to compare

@supervking supervking released this 30 Aug 12:05
a93e724

Password focus recovery / 密码框焦点恢复

  • Fixes a password field that could stop accepting keyboard input after a long lock period or remote-session focus change.
  • Clicking the password overlay now restores the panel as the key window before delivering the click.
  • SwiftUI password focus is rebuilt when the field is clicked or MakLock becomes active again.
  • Touch ID behavior is unchanged because recovery runs only while password input is enabled.
  • 修复长时间锁定或远程会话焦点变化后,密码框看似选中但无法输入的问题。
  • 点击密码界面会先恢复锁屏键盘窗口,并重新建立密码框焦点。
  • Touch ID 流程保持不变。

Universal build: Apple Silicon + Intel. Ad-hoc signed; not notarized.