Copying login keychains between Macs fails on Secure Enclave Macs with Tahoe

(derflounder.wordpress.com)

35 points | by zdw 19 hours ago

5 comments

  • dfabulich 59 minutes ago
    Does the macoOS login keychain get backed up by Time Machine backups in a way that could restore the keychain if the original machine's Secure Enclave is lost or destroyed?
    • lapcat 28 minutes ago
      Does the macoOS login keychain get backed up by Time Machine backups

      Yes

      > in a way that could restore the keychain if the original machine's Secure Enclave is lost or destroyed?

      Apparently not

  • shenenee 1 hour ago
    This is pretty much how it's suppose to work...
    • winstonwinston 1 hour ago
      Maybe but this is unexpected if you need to restore from a backup..
      • ryandrake 44 minutes ago
        It's unexpected to anyone with intuition about how a computer traditionally is supposed to work. As a general principle, as a user, I expect a file on one computer to be usable on another computer. Or, at the very least, if I need to obtain some other thing from the original computer to "unlock" that file, I should be able to do it. The idea of a file that is only usable on a particular computer feels weird.
        • GeekyBear 2 minutes ago
          > As a general principle, as a user, I expect a file on one computer to be usable on another computer.

          As a general rule, I expect a file on an encrypted disk to be inaccessible to anyone who lacks the encryption key(s).

      • petronic 1 hour ago
        I've done Tahoe-to-Tahoe migration assistant moves between machines in recent months. No issues with login keychain migration.
        • winstonwinston 54 minutes ago
          But that’s not backup restore? I’m thinking Time Machine restore on a new Mac when old one is no longer working. Or when the old one had to be wiped and restored.
        • lapcat 26 minutes ago
          Migration Assistant uses the old Mac, which can unlock its login keychain and allow the keychain items to be copied.
      • __MatrixMan__ 1 hour ago
        Don't backup keys, rotate them.
        • gavinsyancey 50 minutes ago
          I can't rotate my keys if I lose access to accounts because my computer died and my backup is useless.
          • __MatrixMan__ 24 minutes ago
            Yeah, that's why secure enclaves embedded in complex devices are a bad idea.

            Hardware keys are the way:

            - Less likely to fail in the first place

            - Cheap enough to have several of so you can use one to log in and manage the others in the event of loss

            - Easy to move between devices

            - Less likely to use the auth handshake as a side channel for things you didn't consent to

    • Retr0id 1 hour ago
      I'm more interested by the fact that it apparently didn't work this way before Tahoe.
      • pram 1 hour ago
        IIRC there are options for exportable and un-exportable private keys when you make one in the secure enclave. Going to guess Tahoe made them un-exportable by default.
        • what 32 minutes ago
          As far as I know, you have never been able to import or export keys from the Secure Enclave. It’s more likely that previously keys were stored in the keychain and now they are generated in the SE by default.
    • lapcat 23 minutes ago
      > This is pretty much how it's suppose to work...

      No, it's not, and that's not how it ever worked in macOS 26.3 and earlier.

      This change was introduced in 26.4 for some reason.

  • lapcat 28 minutes ago
    This was introduced, unannounced, in macOS 26.4! See my blog post for more information: https://lapcatsoftware.com/articles/2026/9/4.html
  • flyingshelf 47 minutes ago
    And yet if you click export it will gladly print out a plaintext csv with your whole life in passwords. Doesn't even attempt to zip it with password or something.
    • ImPostingOnHN 45 minutes ago
      that seems reasonable, as it is the lowest common denominator for interoperability

      what would be unfortunate is if it was in some format that couldn't be used by most other systems without extra work, and if the user wasn't able to use their own property to export their own passwords in a different format.

  • cute_boi 1 hour ago
    This is good.