Urgent.News

What's breaking now, across thousands of outlets.

Tech

Recovery Key storage transition hightlights Apple’s privacy and obscurity

We trust Apple with a lot of our data. In general, that hasn’t seemed like a bad idea; in particular, compared to its competitors, Apple seems to ensure that it can inspect or interact with very little of our data.…

Recovery Key storage transition hightlights Apple’s privacy and obscurity

Apple's transition from the old method of storing macOS FileVault Recovery Keys in iCloud to the new Passwords method highlights the company's commitment to privacy and security. However, the lack of transparency in Apple's documentation leaves users in the dark about the process and its implications.

The Electronic Frontier Foundation (EFF) has noted that only four fitness wearables, including Apple, Google, Whoop, and Oura, provide end-to-end encryption (E2EE) to ensure personal data remains only accessible by the user. Among these, Apple's Apple Watch is the only popular device that supports E2EE. This commitment to E2EE sets Apple apart from other wearable device makers who tend to be more secretive about their data protection measures.

The transition to the new Passwords method for storing FileVault Recovery Keys occurred months after Apple rolled out Advanced Data Protection in December 2022. While iCloud data is generally encrypted with Apple's at-rest keys and transmitted using HTTPS, this leaves synced data relatively unprotected. The only real protection for iCloud data initially was the user's Apple ID account password, which was upgraded to two-step verification in 2013 and then to two-factor authentication the following year.

These measures, however, did not extend to iCloud backups, which could still be retrieved without the second step.

Apple's move to E2EE for device-based services within iCloud marked a significant step forward in privacy and security. However, the transition to the new Passwords method for storing FileVault Recovery Keys remains shrouded in ambiguity. Apple's documentation does not clearly explain the process, leaving users uncertain whether the old keys were destroyed and new ones created or simply moved over. The lack of transparency in this matter raises concerns about potential security vulnerabilities.

Written by urgent.news from Six Colors's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at sixcolors.com →

More in Tech

More from Monday 10 August →