Solutions

What happens to my keys if I lose my Mac?

Updated

Nothing you were carrying opens them. Each key is sealed to the Mac holding it, so a stolen laptop yields nothing by itself. Remove that Mac from your account and the account key rotates: what it held stops working. A recovery code, generated when you set the Vault up, gets you back in if every Mac is gone.

It is the question that stops people moving credentials off a laptop in the first place. If the keys live on the machine, the machine becoming somebody else's is the worst day of the year — and the machine being at the bottom of a canal is only slightly better, because now nothing opens. Both halves have to be answered before it is reasonable to put a production key anywhere.

The two halves are separate mechanisms and it is worth knowing which does which. Removing a Mac is a revocation rather than a delisting: the account key rotates and the material is re-sealed, so the removed machine is not merely struck off a list it could be put back on. That is what makes the answer to a theft short — you remove the device, and the thing it held stops being a key. Getting back in is the other direction, and it has to be arranged before you need it, because once every Mac is gone there is nothing left to mint a way in from. So the recovery code is generated when the Vault is created, not on the day you need it. Print it, or put it somewhere that is not a Mac. Your own new Mac is admitted the ordinary way instead: an enrolled machine confirms it by comparing a short code, which is why replacing a laptop is not a recovery event at all.

How it works

  1. 1Write down the recovery code the day you set the Vault up, and keep it somewhere that is not one of your Macs.
  2. 2When you pair a second Mac, confirm the short code on the machine you already have. That is what admits it.
  3. 3If a Mac is lost or stolen, remove it from your account. The account key rotates and what that machine held stops working.
  4. 4Rotate anything that machine was actively using at the provider too, since a key it had already handed to a running command is a key that was in use.
  5. 5If every Mac is gone, use the recovery code on a new one and the Vault comes back.

Straight about the guarantee: The account key is deliberately split in two, so that syncing your own Macs cannot quietly defeat removing one of them: one share travels with your Apple account, the other is released only to a device you have not revoked, and one share on its own is uniformly random. The limit we publish rather than let you discover: those two parties together could reconstruct it, which is two rather than one. /security carries the full account.

Sources