4 ms·
This is pretty much how it's suppose to work...
by shenenee 22d ago
This is pretty much how it's suppose to work...
- Retr0id 22d agoI'm more interested by the fact that it apparently didn't work this way before Tahoe.
- pram 22d agoIIRC there are options for exportable and un-exportable private keys when you make one in the secure enclave. Going to guess Tahoe made them un-exportable by default.
- what 21d agoAs far as I know, you have never been able to import or export keys from the Secure Enclave. It’s more likely that previously keys were stored in the keychain and now they are generated in the SE by default.
- pram 21d agoYes you can make private keys that are encrypted by the secure enclave, rather than stored inside it. The "sc_auth" tool on macos has a "ssh-exportable" variant
- kureikain 21d agoThere is no way to export data out of secure enclave. You cannot write arbitrary data to secure enclave, as well as read it out. What happen though is the ability to encrypt the data with secure enclave, store it on our own. When migrating, we decrypt with secure enclave, get back original data and re-encryp on the new device.
- winstonwinston 22d agoMaybe but this is unexpected if you need to restore from a backup..
- __MatrixMan__ 22d agoDon't backup keys, rotate them.
- gavinsyancey 21d agoI can't rotate my keys if I lose access to accounts because my computer died and my backup is useless.
- __MatrixMan__ 21d agoYeah, that's why secure enclaves embedded in complex devices are a bad idea. Hardware keys are the way: - Less likely to fail in the first place - Cheap enough to have several of so you can use one to log in and manage the others in the event of loss - Easy to move between devices - Less likely to use the auth handshake as a side channel for things you didn't consent to
- pmontra 21d agoCan you clone or sync hardware keys? Maybe they don't fail as much as computers do but they can be lost or stolen like the keys that we use to open (dumb) doors. My non hardware key is a keypass file that I update only on my laptop and I sync to my other devices. I have plenty of backups. It does also the TOTP required to login into some customers servers.
- mingus88 21d agoI have a few yubikeys and it’s a manual process to sync a new key last time I tried I keep all my TOTP keys on an encrypted usb drive in a safe. When I lose a key, I manually add all the TOTP accounts onto the new key from my safe Passkeys are a different story. Every account I need to make sure I have multiple yubikeys registered. When I lose one, I get in via a second key and then add the replacement one. It’s a pain but it’s a model that makes sense to me. Lose the key? Time to reach for my backup key.
- deleted 22d ago[deleted]
- deleted 21d ago[deleted]
- lapcat 21d ago> This is pretty much how it's suppose to work... No, it's not, and that's not how it ever worked in macOS 26.3 and earlier. This change was introduced in 26.4 for some reason.