Alfonso wrote:
The reason I have FileVault off began when occasionally I needed to assist colleagues at school with their Macs. When FileVault was enabled, we were unable to retrieve or view their files when booting from a USB drive. When the files are not encrypted they can be accessed or viewed. But I understand that passwords and emails etc. can be accessed by a malicious player, so I would physically destroy a drive if I can't format it.
Encryption is always enabled on T2 and later and Apple silicon.
Booting from external USB requires permissive startup settings.
Usual for loaning access would be to create a user for this person, and access the USB device from there.
Guest access into the Mac is more permissive with FileVault off, and more restrictive with FileVault on.
Alternatives for USB file sharing include using AirDrop, sftp, or a File Share.
Or creating a bootable device and booting the colleague's Mac from that, or Recovery.
Physically destroying the storage here is tantamount to destroying the Mac itself.
I'd suggest enabling FileVault, and finding a different way to occasionally support the colleagues.