hn.today

Locked Down Passkey and Keychain Backups

mjtsai.com5 points0 comments
Screenshot of Locked Down Passkey and Keychain Backups

Apple’s passkey and keychain backup design is under sharp criticism for removing practical recovery options and tying encrypted credentials to hardware. There are no automatic, versioned backups for passkeys; syncing via iCloud does not protect against human error, bugs, or attacks; Time Machine backups cannot be restored on the same Mac without signing into iCloud; and decrypted key material is bound to the Secure Enclave so copying login.keychain-db to another Mac or restoring from a clone does not yield usable secrets. The Passwords app can export passkeys only to third-party password managers on the same Mac and cannot export passkeys for Apple services, while passkey and sign‑in handling has additional restrictions for shared items and Sign In with Apple.

Multiple testers and developers confirm the change introduced in macOS 26.4 / Tahoe and persisting into macOS 27 Golden Gate: Keychain files copied between machines or VMs refuse to unlock because the required keys live in the source device’s Secure Enclave. Migration Assistant transfers work only when the old Mac acts as a live server and can decrypt and re-encrypt entries during migration; manual cloning, Target Disk Mode, or hardware replacement can render login keychains irrecoverable even from backups. The practical consequence is catastrophic data loss for stored passwords, certificates, developer keys, and app credentials unless users deliberately verify their login keychain contents and accept dependence on Apple’s migration and iCloud mechanisms.

Read on mjtsai.com0 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.