5 ms·
Copying login keychains between Macs fails on Secure Enclave Macs with Tahoe
- shenenee 21d agoThis is pretty much how it's suppose to work...
- Retr0id 21d agoI'm more interested by the fact that it apparently didn't work this way before Tahoe.
- pram 21d agoIIRC there are options for exportable and un-exportable private keys when you make one in the secure enclave. Going to guess Tahoe made them un-exportable by default.
- what 21d agoAs far as I know, you have never been able to import or export keys from the Secure Enclave. It’s more likely that previously keys were stored in the keychain and now they are generated in the SE by default.
- pram 21d agoYes you can make private keys that are encrypted by the secure enclave, rather than stored inside it. The "sc_auth" tool on macos has a "ssh-exportable" variant
- kureikain 21d agoThere is no way to export data out of secure enclave. You cannot write arbitrary data to secure enclave, as well as read it out. What happen though is the ability to encrypt the data with secure enclave, store it on our own. When migrating, we decrypt with secure enclave, get back original data and re-encryp on the new device.
- winstonwinston 21d agoMaybe but this is unexpected if you need to restore from a backup..
- __MatrixMan__ 21d agoDon't backup keys, rotate them.
- gavinsyancey 21d agoI can't rotate my keys if I lose access to accounts because my computer died and my backup is useless.
- __MatrixMan__ 21d agoYeah, that's why secure enclaves embedded in complex devices are a bad idea. Hardware keys are the way: - Less likely to fail in the first place - Cheap enough to have several of so you can use one to log in and manage the others in the event of loss - Easy to move between devices - Less likely to use the auth handshake as a side channel for things you didn't consent to
- pmontra 21d agoCan you clone or sync hardware keys? Maybe they don't fail as much as computers do but they can be lost or stolen like the keys that we use to open (dumb) doors. My non hardware key is a keypass file that I update only on my laptop and I sync to my other devices. I have plenty of backups. It does also the TOTP required to login into some customers servers.
- mingus88 20d agoI have a few yubikeys and it’s a manual process to sync a new key last time I tried I keep all my TOTP keys on an encrypted usb drive in a safe. When I lose a key, I manually add all the TOTP accounts onto the new key from my safe Passkeys are a different story. Every account I need to make sure I have multiple yubikeys registered. When I lose one, I get in via a second key and then add the replacement one. It’s a pain but it’s a model that makes sense to me. Lose the key? Time to reach for my backup key.
- deleted 21d ago[deleted]
- deleted 21d ago[deleted]
- lapcat 21d ago> This is pretty much how it's suppose to work... No, it's not, and that's not how it ever worked in macOS 26.3 and earlier. This change was introduced in 26.4 for some reason.
- cute_boi 21d agoThis is good.
- dfabulich 21d agoDoes the macoOS login keychain get backed up by Time Machine backups in a way that could restore the keychain if the original machine's Secure Enclave is lost or destroyed?
- deleted 21d ago[deleted]
- lapcat 21d agoDoes the macoOS login keychain get backed up by Time Machine backups Yes > in a way that could restore the keychain if the original machine's Secure Enclave is lost or destroyed? Apparently not
- flyingshelf 21d agoAnd yet if you click export it will gladly print out a plaintext csv with your whole life in passwords. Doesn't even attempt to zip it with password or something.
- ImPostingOnHN 21d agothat seems reasonable, as it is the lowest common denominator for interoperability what would be unfortunate is if it was in some format that couldn't be used by most other systems without extra work, and if the user wasn't able to use their own property to export their own passwords in a different format.
- eviks 20d agoIt's not reasonable to settle on the lowest common denominator as the only denominator
- deleted 21d ago[deleted]
- xmddmx 21d agoDisturbing if true, as it suggests my "everything" backups aren't really full backups at all. I wonder, if you have enabled iCloud keychain, does that provide another way to get your passwords back? Suppose my MacBook is stolen, but I still have my iPhone. Could I use the passwords app on the iPhone to retrieve my passwords. Would that include all of them or only a subset?
- lapcat 21d agoThe iCloud keychain is separate from the login keychain. The Passwords app doesn't use the login keychain.
- xmddmx 21d agoEven more confusing. Do we know which data is in which keychain?
- lapcat 21d agoLook in the Keychain Access app.
- amluto 21d agoI have no idea which keychain is in which, but the last time I migrated from one Apple laptop to another, I couldn't get the automated tool to work at all, so I restored a physical backup, went through the sign-in process, and passwords and passkeys migrated correctly.
- frizlab 20d agoPasswords and passkeys are in the iCloud keychain. You can technically save passwords in the login keychain (not sure about passkeys), but if you’re using the Passwords app it will be in the iCloud one.
- orbital-decay 21d agoYou don't have any backups at all if you never tried restoring and testing them
- tencentshill 21d agoIt's always a good idea to plan to hang on to your old machine for a few weeks to ensure everything works properly on the new one. Apple makes that much easier to forget.
- lapcat 21d agoThis was introduced, unannounced, in macOS 26.4! See my blog post for more information: https://lapcatsoftware.com/articles/2026/9/4.html https://lapcatsoftware.com/articles/2026/9/4.html
- ok_dad 21d agoIt sounds like they are using envelope encryption and using the Secure Enclave to derive the row keys each time. Not really any easy way around that except they should provide a tool to export it, TBH. I am guessing they weren’t using envelope encryption before or they were deriving the row keys from the password. This is a secure design but more security usually means less usability these days.
- Jhsto 21d agoSwitching from macOS to Linux was quite painful because the security was so seamless on Mac. But I also realized I had no idea how my passwords are stored and under what guarantees. Learning and getting the hardware tokens to do it properly on Linux was a PITA. But reading this post made me feel a pinch better.
- neilalexander 20d agoDocumentation explaining the Keychain security model: https://support.apple.com/en-gb/guide/security/secb0694df1a/1/web/1 https://support.apple.com/en-gb/guide/security/secb0694df1a/...
- lubitelpospat 20d agoRecently tried to initialize one Mac from another - kids, never ever attempt that! Microsoft stuff doesn't get copied over properly, and refuses to behave even if you delete an account and create a new one - the only solution is re-installing the OS from scratch. And if you want to do so, and you erase the disk - surprise surprise, in recovery mode macOS doesn't work with the WPA2/WPA3 Enterprise network; you need to go and find a WPA2 network somewhere to re-install the OS. Does the recovery menu explain that somewhere? Hell no. Damn, installing a linux distro from a usb stick is a better experience than re-installing macOS these days!