Encryption Key Storage

duffcalifornia
Contributor

So, this is an odd question, but on unmanaged Macs and flash drives, where is the recovery key stored when the device is encrypted?

1 REPLY 1

therealmacjeezy
New Contributor III

If the Mac is unmanaged when FileVault 2 is setup, the user has the option of sending the recovery key to Apple, which gets linked with their iCloud, or writing it down on paper. If the Apple option isn't selected, the key doesn't get stored anywhere.

When the drive is mounted and unlocked, the RAM stores the 256-bit XTS-AES Key.

As far as external media, by default it's only a password and if that's lost, the data is pretty much gone.

"Saying 'uhh..' is the human equivalent to buffering."