MakLock Secure 1.5.0
中文
本版本为未授权显示器红色警报增加所有者配置的隐藏应急重启恢复,同时保留受保护应用的正常密码锁。
- 红色警报页面只显示普通“重新启动电脑”按钮,不显示恢复阈值、时间窗口或进度
- 只有从警报按钮发起、Boot ID确实变化、显示器指纹保持一致且在所有者设定时间内完成的重启才有效
- 配置和序列状态只保存在本机Keychain,不写入普通偏好设置
- 成功恢复仅对验证后的当前Boot和相同显示器指纹有效
- 不修改可信显示器基线,不关闭MakLock总体保护
- 每次重启请求及有效恢复启动都会退出受保护应用并清除临时认证
- 恢复后打开Codex、Chrome或其他受保护应用仍需正常MakLock认证
- 下一次重启、显示器再次变化、恢复可信配置、超时或关闭保护都会清除恢复状态
- 使用固定Apple Event执行正常macOS重启,不接收外部命令参数
- 增加中英文设置、安全记录和边界测试
应急重启恢复默认关闭,只能在通过认证的“设置 → 安全性 → 显示器应急恢复”中启用。出于远程连接安全,本版本的自动验证没有执行真实系统重启。
English
This release adds an owner-configured hidden emergency restart recovery path to the unauthorized-display alert while retaining normal authentication for protected apps.
- The red alert exposes only a normal Restart Mac control and never shows recovery thresholds, deadlines, or progress
- Only alert-requested restarts with a verified new Boot ID, unchanged display digest, and owner-configured rolling deadline can advance recovery
- Configuration and sequence state stay in the local macOS Keychain, not ordinary preferences
- A successful bypass is limited to the validated current Boot ID and the same display digest
- The trusted display baseline and global MakLock protection remain unchanged
- Protected apps are closed and temporary authentication is cleared before restart requests and validated recovery boots
- Codex, Chrome, and other protected apps still require normal MakLock authentication after recovery
- Another restart, display change, trusted configuration restoration, timeout, or protection disablement clears recovery state
- Uses a fixed Apple Event for a normal macOS restart and accepts no external command parameters
- Includes bilingual settings, security history labels, and state-boundary tests
Emergency restart recovery is disabled by default and can be enabled only from the authenticated Settings → Security → Emergency Display Recovery section. Automated verification did not perform a real system restart in order to preserve remote access.
The downloadable app is ad-hoc signed and not Apple-notarized. Verify the included SHA-256 file before installation.