Hasty Briefsbeta

Bilingual

Locked Down Passkey and Keychain Backups

7 hours ago
  • Apple's passkey and keychain backup system has significant flaws: no automatic versioned backups, and syncing does not protect against human error or attacks.
  • Restoring a Time Machine backup to the same Mac requires logging into iCloud, which is problematic if the account is locked or compromised.
  • Restoring to a different Mac is impossible because login keychain decryption keys are stored in the original Mac's Secure Enclave, even though the keychain is already encrypted with a password.
  • The Passwords app can export passkeys but only to third-party managers on the same Mac, and Apple service passkeys are excluded; export files cannot be re-imported to another Mac.
  • macOS Tahoe (26.4) extended these problems to regular passwords; manually copying the login keychain file between Macs no longer works due to Secure Enclave binding.
  • If a Mac is stolen or fails, the login keychain is unrecoverable even with a backup file—a change Apple did not publicly announce.
  • Migration Assistant can transfer login keychain contents successfully when the old Mac acts as a server over a network, but not via Target Disk Mode or third-party cloning.
  • Many apps (Chrome, MailMate, Vienna, Zoom, Xcode) rely on the login keychain, and users may lose credentials, certificates, and manually added items.
  • Apple's documentation for macOS Tahoe is outdated; exporting via Keychain Access only works for certificates and keys, not passwords.
  • Users who avoid iCloud Keychain have no disaster recovery for the Local Items keychain; the login keychain change undermines manual password backup procedures.
  • The issue is a blocker for upgrading to macOS Golden Gate for some users, and Apple's lack of communication and documentation is heavily criticized.