Encryption Key Storage

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on
08-09-2017
02:44 PM
- last edited on
03-04-2025
04:36 AM
by
kh-richa_mig
So, this is an odd question, but on unmanaged Macs and flash drives, where is the recovery key stored when the device is encrypted?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 08-09-2017 03:21 PM
If the Mac is unmanaged when FileVault 2 is setup, the user has the option of sending the recovery key to Apple, which gets linked with their iCloud, or writing it down on paper. If the Apple option isn't selected, the key doesn't get stored anywhere.
When the drive is mounted and unlocked, the RAM stores the 256-bit XTS-AES Key.
As far as external media, by default it's only a password and if that's lost, the data is pretty much gone.
