Solutions
What happens to my keys if I lose my Mac?
Updated
Nothing you were carrying opens them. Each key is sealed to the Mac holding it, so a stolen laptop yields nothing by itself. Remove that Mac from your account and the account key rotates: what it held stops working. A recovery code, generated when you set the Vault up, gets you back in if every Mac is gone.
It is the question that stops people moving credentials off a laptop in the first place. If the keys live on the machine, the machine becoming somebody else's is the worst day of the year — and the machine being at the bottom of a canal is only slightly better, because now nothing opens. Both halves have to be answered before it is reasonable to put a production key anywhere.
The two halves are separate mechanisms and it is worth knowing which does which. Removing a Mac is a revocation rather than a delisting: the account key rotates and the material is re-sealed, so the removed machine is not merely struck off a list it could be put back on. That is what makes the answer to a theft short — you remove the device, and the thing it held stops being a key. Getting back in is the other direction, and it has to be arranged before you need it, because once every Mac is gone there is nothing left to mint a way in from. So the recovery code is generated when the Vault is created, not on the day you need it. Print it, or put it somewhere that is not a Mac. Your own new Mac is admitted the ordinary way instead: an enrolled machine confirms it by comparing a short code, which is why replacing a laptop is not a recovery event at all.
How it works
- 1Write down the recovery code the day you set the Vault up, and keep it somewhere that is not one of your Macs.
- 2When you pair a second Mac, confirm the short code on the machine you already have. That is what admits it.
- 3If a Mac is lost or stolen, remove it from your account. The account key rotates and what that machine held stops working.
- 4Rotate anything that machine was actively using at the provider too, since a key it had already handed to a running command is a key that was in use.
- 5If every Mac is gone, use the recovery code on a new one and the Vault comes back.
Straight about the guarantee: The account key is deliberately split in two, so that syncing your own Macs cannot quietly defeat removing one of them: one share travels with your Apple account, the other is released only to a device you have not revoked, and one share on its own is uniformly random. The limit we publish rather than let you discover: those two parties together could reconstruct it, which is two rather than one. /security carries the full account.