Backing up your Mac keychain is a lot more restrictive under Tahoe and Golden Gate, according to a new blog. This could be catastrophic in the event your Mac is lost, stolen, or suffers a fatal event. According to the blog, it's impossible to copy the keychain file and successfully decrypt it on a new Mac. Has anyone figured out a way to work around this?
@dangoodin My understanding is its tied to the machines SE and the only way to recover it is via iCloud sync.
@dangoodin I don't think this is new; the encrypted storage has been tied to the secure element for a good number of years. (And that is a good thing.) Migration Assistant can restore your passwords, including from a Time Machine backup (which hopefully didn't also get lost or stolen! — gotta keep ’em separated). https://support.apple.com/en-us/102613
And you can always export all your passwords from Passwords to a regular CSV file.
The people yowling in your mentions should learn before yowling, but...
@dangoodin the passwords app supports exporting.
I was surprised it was copyable this recently. I thought the keychain file had been tied to the secure element for as long as it was an option. Without the SE malware can trivially steal and decrypt the keychain (either offline brute force, or by opening a dialog asking a user for a password and get the user to provide it to them).
@ohunt @dangoodin it does not include passwords shared with you in the export, however. Still, that's a massive improvement over Keychain Access.
@fazalmajid @dangoodin I haven't used shared passwords at all, but I wonder if the assumption is that they can change so are kept distinct?
@ohunt @dangoodin I'm guessing its a policy decision that you don't own shared passwords by definition (unless you are the one sharing them). Certainly in Enterprise situations where password managers are used to share secret, that makes sense, but a bad actor always has the option of copying therm manually, the real solution is SSO secured with passkeys, or better yet, physical Yubikeys.
@dangoodin It has been my experience, for a while now, that restoring / setting up a new machine from a backup doesn’t bring the keychain passwords along. The only way I’ve ever brought passwords along (without having them in iCloud) is using migration assistant to copy data over from the old machine.
@dangoodin I had trouble taking the login keychain with me between machines even on Sonoma... What I ended up doing was creating another "custom keychain" and copying all the items from the login keychain into there (yes, lots of password prompts 😞), and then copying its backing files to the new machine and importing them. Does even that not work now, or is this all just for the login keychain?
@milomb I'm not sure. I've not tried a backup, so I'm going purely from what's described in the post.
Your respose is helpful (unlike others so far). Thanks.
@dangoodin
Presumably this means that a Time Machine backup would fail if it’s restored to a different machine, but if it was synced with iCloud, it would still work. Which is of course a totally different solution and threat model.
Please, don't reply to express personal opinions about Apple or the quality of the Passwords app. I'm looking for an answer to the question here. TiA.
@dangoodin I am being honest dan, that's the difference
@dangoodin ok, I'll take one for the team, I'll be "that guy" 🙃, "Has anyone figured out a way to work around this?" KeePass? 😉
@dangoodin they are morally bankrupt anyways, zero trust has to start somewhere
@dangoodin I know this might be outside your lane, but any insight @rmondello?