Keybags, wrapping keys, VEKs and KEKs all explained. Did you realise how Recovery Keys are implemented? Or how the SSV protects against read errors?
encryption
Recent oddities with FileVault Recovery Keys, and a new exploit GoFetch, raise concerns over how secure FileVault protection is.
You’ve just updated to 14.4 or 14.4.1 and are prompted to set up a new Recovery Key for FileVault. What do you do next, and how should you check the key?
Sparse bundle passwords, shared folders in macOS VMs, and security updates for VMs, are all important fixes. But none for the Finder.
How to change the password for an encrypted sparse bundle, and how to use an ISO keyboard in a macOS VM on Apple silicon.
Step by step guide to passing your Mac on or recycling it. Use EACAS where available. Don’t use .AppleSetupDone which doesn’t work in macOS 14 anyway.
Two memory leaks in the Finder, inability to change password for encrypted sparse bundles, and a crashing bug in Contacts. Detailed and reported to Apple.
Why macOS may refuse to give you a very large sparse bundle, how you can’t change the password of encrypted sparse bundles, and more.
Avoid using encrypted sparse bundles for the moment, as you can’t change their password. Apple Encrypted Archives aren’t ready for normal use either.
First added to Macs in the T1 chip, the Secure Enclave makes it far harder for an attacker to gain access to secrets like the FileVault encryption key.
