Why is firmware lock option not available on apple silicon

What’s the difference between setting up as a security option, firmware lock in intel Mac’s and not now having the same option on apple silicon Mac’s?



MacBook Pro (M1, 2020)

Posted on Oct 15, 2023 2:03 AM

Reply
Question marked as Top-ranking reply

Posted on Oct 15, 2023 7:34 PM

The Apple Silicon Macs ALWAYS encrypt the boot disk. Enabling FileVault just requires a password for the Secure Enclave to start decoding the boot disk.


If the boot drive is removed from Mac, it cannot be read by another computer because it does not have the Secure Enclave chip that did the encryption.


Basically, once you enable FileVault, it is impossible to access the data on the boot volume.


Granted the boot volume can be totally erased, and a new System put on the Mac, but on a FileVault enabled Mac the user data is never accessible to anyone that does not have the password.


And if you use "Find My" to mark the Mac as lost or stolen, it should lock up should it be allowed to access the internet.


Basically, the technology has moved on from firmware passwords. Also firmware passwords created support issues.

5 replies
Question marked as Top-ranking reply

Oct 15, 2023 7:34 PM in response to Bertil007

The Apple Silicon Macs ALWAYS encrypt the boot disk. Enabling FileVault just requires a password for the Secure Enclave to start decoding the boot disk.


If the boot drive is removed from Mac, it cannot be read by another computer because it does not have the Secure Enclave chip that did the encryption.


Basically, once you enable FileVault, it is impossible to access the data on the boot volume.


Granted the boot volume can be totally erased, and a new System put on the Mac, but on a FileVault enabled Mac the user data is never accessible to anyone that does not have the password.


And if you use "Find My" to mark the Mac as lost or stolen, it should lock up should it be allowed to access the internet.


Basically, the technology has moved on from firmware passwords. Also firmware passwords created support issues.

Oct 16, 2023 10:24 AM in response to BobHarris


BobHarris wrote:

But someone could not take the internal storage from an Apple Silicon (or T2) based Mac and boot it as an external drive, because they do not have the encryption key. The most they could do would be to erase the storage, and write their own stuff on it. Whether they encrypt it or not is a function of the hardware and software they use. But they do not have access to your data.


On many of those Macs, the internal SSDs are soldered in, so it would not be easy to take them and put them into an external drive with or without encryption.


On a few, like the Mac Studios and M2 Ultra Mac Pro desktops, you could actually remove the flash modules – but then, as you say, separating the modules from the decryption key would block anybody from making head or tails out of the data. Including you – thus making "pulling the SSD out of a failed Mac, to try to make up for a failure to back up the machine while you still could" a thing of the past.


Oct 16, 2023 4:24 AM in response to Servant of Cats

But someone could not take the internal storage from an Apple Silicon (or T2) based Mac and boot it as an external drive, because they do not have the encryption key. The most they could do would be to erase the storage, and write their own stuff on it. Whether they encrypt it or not is a function of the hardware and software they use. But they do not have access to your data.

Oct 15, 2023 7:52 PM in response to BobHarris

BobHarris wrote:

The Apple Silicon Macs ALWAYS encrypt the boot disk.


It might be more accurate to say that Macs with Apple Silicon chips, or T2 security chips, ALWAYS encrypt the contents of the internal SSD. I could be mistaken, but I believe that the real-time, whole-disk encryption is tied into the way these chips implement part of the SSD controller.


Thus if you were booting from an external drive, it would not automatically be encrypted in real-time.


This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Why is firmware lock option not available on apple silicon

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.