macOS 26 Tahoe Pushes FileVault Use

Originally published at: macOS 26 Tahoe Pushes FileVault Use - TidBITS

In his review of macOS 26 Tahoe at Ars Technica, Andrew Cunningham writes:

One other tweak to the install process is the default behavior for Apple’s FileVault disk encryption. If you sign in to an Apple account as part of setting up macOS, FileVault now turns on automatically, and also automatically uses your Apple Account for recovery in the event something goes wrong. …

But if you decline to sign in with an Apple Account during setup, just creating a local account, the macOS installer offers FileVault encryption, generating a recovery key that you can write down and store elsewhere, but it’s possible to skip FileVault entirely.

It’s frustrating when Apple makes setup choices for us during installation, but in this case, the security benefits are worthwhile. While Macs with Apple Silicon or Intel-based Macs with a T2 security chip already hardware-encrypt their drives, FileVault adds boot protection that prevents unauthorized access to data on the drive even if someone has physical access to your Mac. There’s no noticeable performance hit from this encryption.

The only slight downside of enabling FileVault crops up if you lose your login password. That could happen with a long-unused Mac, for someone experiencing cognitive decline, or if there is corruption in the recovery partition where FileVault stores its password data. In these cases, the Recovery Key offers an alternative login credential. Without the login password or Recovery Key, you cannot log in to your Mac (which is also true when FileVault is disabled), and your data stays encrypted (with FileVault off, the Mac’s hardware key alone would be enough to decrypt the data).

In other words, turning off FileVault makes it more likely that a firm like DriveSavers could recover your data if you lose access to your password and have no backups. However, it also makes it easier for a hostile government agency to access your data without permission or your knowledge, something that’s less confined to the realm of thrillers than it used to be. I recommend that everyone use FileVault, but if you’re uncomfortable with extra protection from hostile governments, you can always turn it off in System Settings > Privacy & Security > FileVault.

Another new aspect of FileVault setup in macOS 26 is that Apple no longer allows you to store your Recovery Key in your iCloud account, as Glenn Fleishman explains at Six Colors. Apple likely made this change to prevent a hostile government from forcing the company to reveal a user’s Recovery Key. However, macOS 26 now automatically stores the Recovery Key in Passwords instead of showing it only once during setup, and you can still save it in another password manager or print it, as you prefer. One interesting quirk—FileVault recovery keys automatically stored in Passwords in macOS 26 sync to other devices running OS 26, but not to those running older operating system versions, which could complicate recovery.

3 Likes

Haven’t considered myself a target for “hostile governments,” but consensus on what “is” a hostile government seems to be in flux.

8 Likes

Yeah, that’s kinda annoying for sure. Fortunately some others here had tipped me off to this, so I paid attention to the rather innocuous announcement during the first use of macOS 26 that “Your computer is now protected by FileVault…”. I immediately tried to turn it off, but the little slider toggle wouldn’t. I continued with the rest of the setup process, and after that was completed (perhaps it was when I authenticated to iCloud?), I was able to turn it off.

2 Likes

Today I learned that for T2 and Apple Silicon Macs, you can ship the entire logic board or entire computer to DriveSavers for data recovery.

4 Likes

It would also be a really good idea if you had your data in human readable format on another disk. I tried restoring from a Super Duper! external disc. When I rebooted the internal disc, it wouldn’t recognize my password.

I had to completely erase the disc and reinstall then restore my data from Time Machine using migration assistant.

1 Like

The only slight downside of enabling FileVault crops up if you lose your login password. That could happen with a long-unused Mac, for someone experiencing cognitive decline…

People forget passwords all the time and it has nothing to do with cognitive decline. Estimates are that 50% of people reset at least one of their passwords monthly because they forget it. I’ve forgotten passwords after a two week vacation. The File Vault Recovery Key would seem to be a prime candidate to misplace or forget. If you use the default method, then you only need to access your Apple Passwords to get the recovery key.

Another new aspect of FileVault setup in macOS 26 is that Apple no longer allows you to store your Recovery Key in your iCloud account

If it is in Passwords, doesn’t that mean that it is in the iCloud account as long as you use iCloud Passwords?

We’re not talking about just any password, but your login password, which you have to enter regularly to use your Mac at all, even if you also use Touch ID or an Apple Watch to login. It’s hard to imagine how you’d forget the password to a device you’re actively using.

I don’t know the exact architecture of how the data was stored done before, but iCloud Keychain, the technology behind the syncing in Passwords, is end-to-end encrypted, so there’s no vulnerability to that information being in the cloud. My suspicion is that the previous approach did not use E2EE. @glennf may know more.

Previously, Apple managed the iCloud key escrow. It only required your Apple Account login to obtain. So, while unlikely, if someone gained access to your computer and had your Apple Account login, they could unlock your drive without the macOS account password.

In this configuration, the Recovery Key is always secured by device-based encryption. If you are in a macOS session, you need Touch ID or the macOS account password to view the stored Recovery Key. If using Passwords, you need Face ID, Touch ID, or a passcode or password to view the key, and to access Passwords, you need to have the device in hand and be able to able to unlock it through one of those authentication methods as well.

Because Passwords syncs using iCloud Keychain, as Adam notes, it’s end-to-end encrypted.

I believe because Apple only used account security previously, a government could subpoena access to an iCloud account and thus unlock someone’s Mac if that method were enabled.

5 Likes

If you use a password manager - Dashlane for example - and put your recovery and password in that and have the password manager on your iPhone, you should be able to access it even if one device goes down hard.
David

Unless your Mac is configured for automatic login. Or does macOS sometimes force you to authenticate even then?

If you were automatically logging in, and then the system surreptitiously turned on FileVault (effectively preventing auto-login), you might have a real problem if you didn’t have the password recorded in an off-line location.

I don’t disagree with the point you’re trying to make here, but I will point out that thanks to TouchID I in fact do enter my Mac’s login password very very rarely. Essentially, only when I need to reboot the Mac, which is, apart from upgrade palooza, quite rare actually.

2 Likes

Well, the solution to this is to put your login password or recovery password on a yellow Post-it note that you affix to your monitor as I saw in countless offices over the years.

:smiley:

Dave

4 Likes

It will still probably prompt for the password every 6.5 days regardless. I certainly hit this regularly.

The user hasn’t used their passcode or password to unlock their device for 156 hours (six and a half days), and the user hasn’t used biometric authentication to unlock their device in 4 hours.

1 Like

I sure hate this. I wish there was a way to extend that time. With several iPads, a phone, a watch, and multiple Macs, I have to type in my password on one or two devices every flipping day!

It really makes me consider using a shorter, less secure passcode for unlocking, which is the opposite of the intent.

I truly believe the intent is to make sure that users type the passphrase at some point so that they don’t forget it, as forgotten passphrases probably result in a lot of frustrating support calls and visits, and it would be worse if people weren’t prompted often enough. One week is a probably a pretty good way to do that.

That said, an option, well hidden behind one of those circle-i icons, that says, “I am a power user who will take responsibility for knowing my password, so don’t prompt me for it so often” would probably be good for many of us here.

2 Likes

I have a headless server and therefore need the server to restart without intervention (no keyboard, mouse or monitor). The only way I can find is to turnoff file vault and then the ‘Automatically login after restart’ option is shown in the Login Password Preference.

I had to permit the file vault encryption to start and then turn it off after that first MacOS 26 bootup on my M1 Mini was complete. While I admit Apple did display a message upfront that file vault was turned on, I had to scratch my head to remember why that was a potential problem …

2 Likes

This is so very familiar to me. Even for Servers, I saw people do this.

2 Likes

Very true, and why so many people re-use passwords everywhere. By forcing excessive password use it is, in essence, creating the environment for single passwords for everything.

I just did a quick check and I have over 500 passwords stored - all of them are different as I went through the process when I moved from 1Password to Apple Passwords.
I had staff members at work who used the same password for everything from their Netflix login to their bank accounts - and they openly talked about it. Truly horrifying.

Related:

It comes as a surprise to many, but the US National Institute of Standards and Technology has recommended for several years that passwords should not have mandatory expiration dates for exactly that reason. Instead, they recommend using lengthy passphrases and password managers.

For those interested in the source material, it is somewhat technical. You can find more information in NIST SP 800-63-4 (Section 3.1.1.2.6) and the more general NIST SP 800-53 (PDF).

4 Likes

It looks like this is no longer the case with MacOS 26! You can now enable FileVault and still boot remotely. A really nice change (though I no longer manage a headless server so won’t directly benefit).

4 Likes