Locked Down Passkey and Keychain Backups
7 hours ago
- Apple's passkey and keychain backup system has significant flaws: no automatic versioned backups, and syncing does not protect against human error or attacks.
- Restoring a Time Machine backup to the same Mac requires logging into iCloud, which is problematic if the account is locked or compromised.
- Restoring to a different Mac is impossible because login keychain decryption keys are stored in the original Mac's Secure Enclave, even though the keychain is already encrypted with a password.
- The Passwords app can export passkeys but only to third-party managers on the same Mac, and Apple service passkeys are excluded; export files cannot be re-imported to another Mac.
- macOS Tahoe (26.4) extended these problems to regular passwords; manually copying the login keychain file between Macs no longer works due to Secure Enclave binding.
- If a Mac is stolen or fails, the login keychain is unrecoverable even with a backup file—a change Apple did not publicly announce.
- Migration Assistant can transfer login keychain contents successfully when the old Mac acts as a server over a network, but not via Target Disk Mode or third-party cloning.
- Many apps (Chrome, MailMate, Vienna, Zoom, Xcode) rely on the login keychain, and users may lose credentials, certificates, and manually added items.
- Apple's documentation for macOS Tahoe is outdated; exporting via Keychain Access only works for certificates and keys, not passwords.
- Users who avoid iCloud Keychain have no disaster recovery for the Local Items keychain; the login keychain change undermines manual password backup procedures.
- The issue is a blocker for upgrading to macOS Golden Gate for some users, and Apple's lack of communication and documentation is heavily criticized.