Recovery Key storage transition highlights Apple’s privacy and obscurity – Six Colors
MENU
Become a Member!
Become a Six Colors member to read exclusive posts, get our weekly podcast and regular newsletters, and much more!
By
Glenn Fleishman
August 10, 2026 11:00 AM PT
■ filevault<br>■ help me glenn<br>■ security
Recovery Key storage transition highlights Apple’s privacy and obscurity
We trust Apple with a lot of our data. In general, that hasn’t seemed like a bad idea; in particular, compared to its competitors, Apple seems to ensure that it can inspect or interact with very little of our data. The company has built its platform and its reputation on being an elegant, frictionless, hands-off conduit. While we can make many complaints about Liquid Glass, its increased focus on invasive (and poor) advertising, its software quality, and much else, Apple has kept its corporate nose cleaner than anybody else. Its transparency and documentation are, oddly, worse than its actions and clear intent.
The Apple Watch is the only wearable with end-to-end encryption for first-party health data. (Image: Apple)<br>I was thinking about this when I received an email from an anonymized iCloud Hide My Email account, asking for more detail about how Apple managed the transition from the old method of presenting or escrowing (in iCloud) your macOS FileVault Recovery Key to the new method, in which the key is stored in Passwords. This transition, which I’ve documented in a few places, was a step forward in privacy and security.
But not transparency! I’ll explain, but you can’t find an explanation on Apple’s site about the transition. The support documentation remains out of sync with Tahoe. That leaves it to yours truly to explicate.
Don’t trust and verify
The Electronic Frontier Foundation recently published a newsletter with a round-up of how fitness wearables, like rings, watches, and bands, preserve your privacy from government intrusion, as well as whether they protect you from unwanted security invasions by using end-to-end encryption (E2EE). (The former often requires the latter: governments typically can’t break through E2EE.)
I want to quote two full paragraphs to make this point:
In the end, we found that only four of these companies (Apple, Google, Whoop, and Oura) promise to notify users of law enforcement requests in publicly available documentation. And just two of those companies, Apple and Google (which also owns Fitbit), currently publish transparency reports on how often they hand users’ data to the government.
Support for end-to-end encryption—a method that ensures your personal data is only accessible by you, and not the company who makes the device and manages the cloud storage—is more rare than transparency reports among wearable device makers. The Apple Watch is the only popular fitness wearable that supports end-to-end encryption.1
Apple wasn’t an early player with E2EE. Really, it was seen as the kind of thing only true security geeks cared about, even while people like EFF and other digital privacy advocacy groups and individuals warned us that our data was only lightly protected. Over time, as the criminal, exploitative, and political monitoring and extraction of our secrets became clear, Apple kept stepping up.
I don’t understand every part of this flowchart, but it shows how Apple uses the Secure Enclave to ensure the integrity of device-based end-to-end encryption. (Image: Apple)<br>The Secure Enclave is a keystone of those moves, as the tamper-resistant silicon subsystem allows devices to keep locally generated security keys entirely private. Most of these keys never leave the Secure Enclave! Rather, it’s the encryption hub.2
iCloud initially had a fairly cursory level of protection, with the then-Apple ID account password serving as the only real bar. Two-step verification in March 2013 provided better account protection, but didn’t cover iCloud backups, which could be retrieved without that second step. A rash of celebrity account leaks in late summer 2014 led Apple to extend two-step to iCloud data within a couple of weeks. The next year, it upgraded security to the more rigorous two-factor authentication, which later became mandatory.
As part of its response to the iCloud data hijacks, Apple began to beef up iCloud. It began rolling out E2EE for all the device-based services it could, leaving synced data still relatively lightly protected. (iCloud data is always encrypted with Apple’s at-rest keys, which only it ostensibly has access to, and in transit with HTTPS. However, a security breach at Apple or someone able to hijack one end of an in-progress HTTPS sync allows access to that unencrypted data.)
Then, suddenly, months after shipping major updates to its operating systems, Apple announced Advanced Data Protection in December 2022. Enabling this feature put the E2EE aegis over nearly all synced or stored data at iCloud; mail, contacts, and calendar entries remain an exception...