Apple iMac Pro and Secure Storage
duo.com
duo.com
Yet more sadness for data recovery companies and those who've lost files and want their services. Full disk encryption has been around for a long time and, well-implemented, will let you recover the encrypted data to transfer to new media (so the DR company can't see your secrets either, but you haven't lost anything.)
IMHO encryption should be opt-in --- contrary to what those advocating it think, not every piece of data I have needs to be encrypted, and I certainly have plenty more personal files that I would rather have become publicly accessible than lost forever. It's a tradeoff between "if someone hacks in, they can read my data too" and "if something goes wrong, no one can read my data, including myself" and I think this tradeoff needs to be a more explicit choice.
> If you're using OS X Yosemite or later, you can choose to use your iCloud account to unlock your disk and reset your password
> If you're using OS X Mavericks, you can choose to store a FileVault recovery key with Apple by providing the questions and answers to three security questions. Choose answers that you're sure to remember
> If you don't want to use iCloud FileVault recovery, you can create a local recovery key. Keep the letters and numbers of the key somewhere safe—other than on your encrypted startup disk
Which is exactly what it's supposed to feel like, and that's fine if you were aiming for it, but when that isn't what you signed up for, it's pretty much the worst thing ever.
It can also feel like a truly nefarious form of vendor lock-in, if you ever try to migrate to another system, and just happen to notice that now, your disk is totally unmountable for some unexplainable reason. This kind of thing can happen when crossing over to an older version of an alternative OS that doesn't know how to negotiate authentication for proprietary encryption formats, or newer formats that weren't supported at the time of the older OS's install.
So, for consumer hardware that might be received as a birthday gift, I'd say encrypted by default is a terrible idea. For those not carefully and explicitly warned, storing their stuff on an encrypted disk gone wrong, can be like unintentionally throwing it in the trash, setting it on fire and then flushing it down the toilet, except the toilet is a black hole of no return.
We're talking about an Apple iMac Pro here... this isn't a computer that is designed to allow you to move components to a different system. Yes, it is a fully locked-in system, purposefully designed to be as secure as possible. I'm not going to give Apple much grief about that, because it's not like they say you can migrate hardware from one system to the next.
It would be more interesting to know how the T2 chip interacts with external storage and/or alternative (Windows/Bootcamp) operating systems. In both of these cases, one would expect more low-level data portability, which is a more interesting use-case than trying to pull out the NVMe SSDs from a glued together iMac.
This is largely similar for MacOS with Time-Machine backup (largely encouraged) or iCloud backup (still recent and for now advertised as secondary backup) or a full disk dump by any software you deem appropriate.
I both case the iCloud back-up seems to be the backup method Apple want to promote moving forward. And while I was very reticent for a while, this ultimately is a good move on their part IMHO (tho I’ll personally never stop full disk physical backup). Yes it’s pricy but keeping external hard-drive to date with tech also have a cost beyond initial buying cost (FW->USB2->USB-C HD->SSD) also it’s off site wich need some discipline if you do it yourself. For most users paying a monthly fee to have you mind worry free will be a blessing.
The odds of your local backup and cloud provider going down simultaneously are slim to none, and at that point I'd start looking out for the Four Horsemen.
But I suspect most of the file types that land in iCloud Document containers, Photo Library, and the rest cover 90% of what most people consider important.
So the thinking goes, You can always re-download the OS and applications if necessary. Internet Recovery is a godsend on a machine that fails to boot.
(Insert 80-90's Mac user rant about the Startup "chime" going away - because POST - and Target Disk Mode being more obscure than it should be)
The fact that home internet connections are just now getting to the point now where this is viable makes iCloud backup less of a pain in the butt than it used to be. Still, I don't trust it entirely because of the hacking risks and the fact that it doesn't grab everything by default.
But it’s the logic Apple is pushing for years now. iOS devices never got the possibility to be shared because they are considered "personal". And this is also a no go for some people (I think this logic is ok for phone but more discutable for iPad).
By this logic a backup fall into the personal category for Apple so you need an undividual account. Which again make senses in some way. Because with physical backup, if not encrypted, anybody that put his hand on the disk get access to all the data of all the users.
Usually you trust people you share a computer with more that any company, so maybe it’s pushing the logic too far to force use to get an iCloud account.
But from a practical standpoint you can’t either say it’s useless. Kid grow and get his own computer? Just setup iCloud on the new one and he get back all it’s stuff painlessly. Your shared computer crash and you decide to buy two laptops to replace it? Easy to split accounts. Everything is already easily doable using the migration assistant, assuming you have a backup, but can be easier in the futur for the proverbial layman.
Encrypt and back-up your data, and don't lose the key.
Same goes for 2FA, if you lose your 2nd factor thing and didn't store the recovery in a safe place, your data should be lost. If there's an option to recover it anyway, your data was insecure anyway and 2FA was a waste of effort.
If we want to reduce pain points for average users, the best case scenario would be to have intuitive means to allow users to ensure their data is safe and secure, and handled with an appropriate level of privacy (i.e. Tax documents should not be public.) If you can't accomplish that, it feels like all you can do is go back and forth between bad trade-offs.
I agree. Backblaze is $50/yr for unlimited backup. If your expressed behaviour is that your data isn't worth $50 then I have pretty limited sympathy when you lose it...
I had to recover data for a friend whose MacBook Air failed halfway through the macOS update that reformatted her drive to APFS. I wrote up the process on Medium. If the drive weren't encrypted, it would've been possible to recover from more serious problems (e.g. partial flash memory failure) instead of just the OS issue. Thankfully her files were safe, but the fail-deadly default option for users' data is going to cause a lot of problems for Apple's reputation in future.
https://medium.com/@peterburkimsher/saving-a-friend-with-apf...
To erase the drive; securely delete the key and all copies.
Like disk encryption with Linux, you select a robust password, or you can store a key in whatever way you want, you enter your password on boot and unlock the disk, if you PC broke, fine remove the disk from the computer and put it in another. The security lies only in the password you choose, not your particular PC having some kind of closed hardware in which somewhere lies the key (of course).
I'm not a security specialist though -- so I'm curious how valuable these extra hardware protections are to the security community at-large.
does the fingerprint sensor API return a signed response from the fingerprint sensor or SE? or is it a simple yes/no?. if it's the latter, the whole thing is security theater.
If it's a signed response, at some point there's another piece of code that checks that the signature is valid and returns a yes/no.
I think the reason Apple's sensor was mentioned in this instance was due to how Apple handled storage and usage of biometrics as described in here https://www.apple.com/business/docs/iOS_Security_Guide.pdf
Compare that to, say, other laptop vendors: https://support.lenovo.com/us/en/product_security/len-15999
Kinda surprised that this needed an Apple-specific explanation. I mean, didn't all board manufacturers move toward NVMe simply because it's faster than ATA?
PS: And for the company one less dependency to manage?
This key is "tangled" with user-supplied keys for per-device access to data.
I assume the T2 offers this same feature.
See UID in the glossary (page 80) or under Hardware security features (page 12) of the iOS 11 Security Guide
[and before someone says it, yes, in the iMac Pro you can read the data off the NVMe lanes to check if it indeed is encrypted]
How about when your device is locked in sleep mode. The main processor should lose the key to a certain set of files, as does on iOS.
The dedicated T2 chip gives Apple more flexibility for the future and control over the present. Both of these things Apple values.