3 ms·
Oh fascinating. And it seems I had my terms confused. I didn't know the items themselves were called keychains.
by nmgycombinator 2y ago
Oh fascinating. And it seems I had my terms confused. I didn't know the items themselves were called keychains.
- oneplane 2y agoYeah, it's a bit overloaded. There are keychains (.keychain files) and keychain items (secrets inside of them). The keychains are visible in the Keychain Access app, but also available in the 'security' command line. And then there are modern keychains, those are more like SQLite databases and those can have anything from SQLCrypt type of management to Secure Enclave DEKs. Security is pretty difficult to get right, so many tradeoffs as well.
- nmgycombinator 2y agoIt seems I was not confused then? The secrets are the "keychain items". I got really mixed up there.
- oneplane 2y agoSo the hierarchy looks a bit like this: Top level = Keychain Access.app or the security CLI tool Mid level = keychains (in flavours of files, core storage, data protection-enabled, and iCloud) Item level = an entry inside a keychain There is a sub-level as well, some software stores encoded data as a single item so when it's decrypted it's a bunch of different data, not a single secret, but technically the keychain system isn't aware of that anyway.
- nmgycombinator 2y agoYeah I got confused there for a second based on your original message, but I'm glad to know my understanding initially was correct.