Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Which way is more secure? #230

Closed
sickamongthepure opened this issue Jun 18, 2017 · 5 comments
Closed

Which way is more secure? #230

sickamongthepure opened this issue Jun 18, 2017 · 5 comments

Comments

@sickamongthepure
Copy link

sickamongthepure commented Jun 18, 2017

I'm wondering which way of deploying FileVault is more secure:

  1. Turning on FileVault in System Preferences after installing macOS.

  2. Before installing macOS make encrypted partition in Disk Utility and then install macOS.

What do you think?

@sickamongthepure sickamongthepure changed the title Which way is the best? Which way is more secure? Jun 22, 2017
@1dotd4
Copy link

1dotd4 commented Jun 22, 2017

It should encrypt automatically the partition before to install. Or it isn't?

@ghost
Copy link

ghost commented Jun 26, 2017

I think he is asking about encrypting the drive from the recovery/bootable Installer (i.e. Disk Utility -> Erase > Mac OS (Journaled, Encrypted) versus erasing it regularly and then encrypting it during system setup (or some point later).

I actually had the same question and was wondering if anyone knew the advantages/disadvantages of both.

@felixgr
Copy link

felixgr commented Jul 31, 2017

I looked at the seeding of Apple's PRNG a few years ago. Things might have changed since then. Back then, the PRNG had more entropy available in scenario 1 because of the recent reboot. So, just based on that knowledge, scenario 1 seems more secure.

@drduh drduh closed this as completed in f2ccf95 Aug 25, 2017
@walkky
Copy link

walkky commented Feb 12, 2022

Is this still the case with Apple Silicon / M1-based MacBooks?

@Danrancan
Copy link

Danrancan commented Feb 15, 2022

I looked at the seeding of Apple's PRNG a few years ago. Things might have changed since then. Back then, the PRNG had more entropy available in scenario 1 because of the recent reboot. So, just based on that knowledge, scenario 1 seems more secure.

I actually remember reading a blog post about this just over a year ago as well. The blogger agrees with you in that scenario 1 is the best way to go about it. However, if you create the encrypted disk before installation, doesn't that allow you to create two seperate passwords? One being specifically to unlock the encrypted drive and the other being to log in to mac os after unlocking it? If thats the case, I would say that scenario 2 supersedes scenario 1 even if it has less entropy, because it allows for multiple seperate passwords. Although, I could be wrong on all of this. Its been a while since I've done a clean install of MacOS.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants