3 ms·
Yes I agree. It should be OOB like it is with MacOS. But you can set the PIN (they call it PIN, but you can enter any password) the same as your PW.
by k8sToGo 2y ago
Yes I agree. It should be OOB like it is with MacOS. But you can set the PIN (they call it PIN, but you can enter any password) the same as your PW.
- wat10000 2y agoAh hah, terrible naming strikes again. I’m guessing that means you now have to change your password in two places if you ever change it? Not great, but then again people probably never change their passwords.
- p_ing 2y agomacOS has two things going on -- FDE (i.e., same as BL) which is auto-unlocked on boot up. What is protected by the user's password is FileVault encryption, but that's home directory protection only. https://support.apple.com/guide/mac-help/protect-data-on-your-mac-with-filevault-mh11785/mac https://support.apple.com/guide/mac-help/protect-data-on-you...
- wat10000 2y agoFileVault 1 was home directory encryption. That hasn’t been current in ages. The current FileVault 2 is FDE using the users’ passwords as the keys.
- dunham 2y agoNote in page that you linked: > When you turn on FileVault, you choose how you want to _unlock your startup disk_ if you ever forget your password: The password now locks the entire startup disk (as of FileVault2, which has been around a while) and needs to be entered into a pre-os screen. There is a place in the UI (once booted) to designate which users can do this. This is useful for securing lost devices (since they don't have enough key material to decrypt the disk), but probably still susceptible to evil maid attacks (hacking the login screen). You can read details on pages 119 and 120 of this document (in particular, page 120 has a diagram of how the volume encryption key is derived): https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf https://help.apple.com/pdf/security/en_US/apple-platform-sec...
- wat10000 2y agoBasic evil maid attacks are prevented by signing that login screen software (and everything leading up to it) so it can’t be altered. Of course there’s still the possibility of vulnerabilities in that software, hardware key loggers, etc.