3 ms·
More people definitely need to be aware of this; the fact that Time Machine doesn't make this super obvious to the user needs to be corrected by Apple since it
by vin047 6y ago
More people definitely need to be aware of this; the fact that Time Machine doesn't make this super obvious to the user needs to be corrected by Apple since it would be very frustrating if you relied on it and had to discover this the hard way (as you, unfortunately, did). However, I disagree with your assessment that this is "broken". Here's my reasoning:
I think this actually works "as intended". Since keychain items serve as the root for your credentials to various services, it makes sense to protect them with two factors; in this case it's "something I know" (password) with "something I have" (device). A loss of either should render the encrypted data useless.
Local keychain is precisely that; local. It is not intended to be something that is by default transferable, as opposed to say, iCloud Keychain.
I emphasise by default because yes, a user should be allowed to easily export/backup the local keychain if they want. The fact that its a PITA and requires a workaround via AppleScripts is very frustrating. And, as I said, lack of clarity by Apple/Time Machine of this fact.
- DavidSJ 6y agoWhy don’t my Time Machine backups count as something I have? Why should that only be the behavior for the Local Items keychain and not also the Login keychain? From the user’s perspective, what’s the meaningful difference between the two?
- DavidSJ 6y agoI’ll add: the default behavior should be the right thing for most users, assuming it won’t be disastrous for a significant minority of other users. The right thing for most users is to have an encrypted backup of the keychain that’s part of the rest of the computer backup. In fact, for most users, it could easily be disastrous not to. Also, migrations to new devices are a fact of life. It should be possible to migrate to a new device and bring your keychain along.