logoalt Hacker News

gioboxtoday at 6:23 PM2 repliesview on HN

> Don't think Apple wouldn't do the same.

Of course Apple offers a similar feature. I know lots of people here are going to argue you should never share the key with a third party, but if Apple and Microsoft didn't offer key escrow they would be inundated with requests from ordinary users to unlock computers they have lost the key for. The average user does not understand the security model and is rarely going to store a recovery key at all, let alone safely.

> https://support.apple.com/en-om/guide/mac-help/mh35881/mac

Apple will escrow the key to allow decryption of the drive with your iCloud account if you want, much like Microsoft will optionally escrow your BitLocker drive encryption key with the equivalent Microsoft account feature. If I recall correctly it's the default option for FileVault on a new Mac too.


Replies

ezfetoday at 6:30 PM

Apple's solution is iCloud Keychain which is E2E encrypted, so would not be revealed with a court order.

show 3 replies
tokyobreakfasttoday at 6:26 PM

That's what I said. I admit the double-negative grammar is a bit confusing.