FileVault 2 Issues and downside?

I've been researching the downside of enabling FileVault 2 (FV2) plus my own experimentation. I am aware of the performance hit and the importance of not forgetting/losing the PW and/or creation key. Also, certain 3rd party SW requires 10.7 & 10.8 to access drives locked with FV2 such as Micromat's TechTool Pro and Protogo. And I've discovered that to mount a FV2 drive as Target Drive, the computer doing the mounting must be running 10.7 or 10.8.


Is there anything else that I'm missing?


TIA.

Posted on Feb 24, 2013 4:19 AM

Reply
16 replies

Feb 24, 2013 5:21 AM in response to barubin

You can't start up in Safe Mode if FV2 is enabled.


Also, if you have other users on your mac, they won't be able to actually start or restart the mac unless you enable them with an FV2 password. However, if you enable them then the entire disk (including your own home folder) is unencrypted. That gives them read access to your and any other users files through single user mode.


Personally, I'd stay away from FV2, but there'll be others along soon who will quickly come to its defense. As you seem to have figured out already, you'll need to weigh the pros and cons according to your own needs.

Feb 25, 2013 9:49 PM in response to barubin

Applying FileVault 2 on a computer running an SSD (solid-state drive) will apparently mark every cell on the SSD as "in-use", causing major problems for built-in algorithms designed to apply wear-levelling to the drive and thereby affecting longevity. This can be avoided by applying the FDE in a different manner. See this post (and the one it refers to) for more details.

Mar 1, 2013 5:01 AM in response to barubin

Regarding the link to a different post, I'm a computer scientist and I'm going to have to read that a few times to be sure I understand all of it

It's easy: simply format the drive as HFS (Encrypted) before you start, as opposed to populating the drive first and then turning on FileVault 2. When you boot from it it'll then ask you for a password before it even mounts the drive, and on successful entry take you straight to the login screen (and not into a user's account like FileVault 2 does).


🙂


EDIT: For additional security, you can even use the original FileVault encryption on top of FileVault 2, so that the entire drive is encrypted and therefore requires a password to mount, and then each user's individual home folder is encrypted an additional time. This is an Apple-supported measure.

Mar 19, 2013 4:30 PM in response to Scotch_Brawth

From 01MARCH2013 which was saved but not posted:


Scotch_Brawth,


Thanks A LOT, again. I started at the beginning of the post you linked to "Repairing Boot Camp after creating new partition" and didn't get to the good/applicable part: the part you added.


I have never formatted a drive HFS (Encrypted) before. I didn't even realize that it was an option! When did this feature get introduced to Disk Utility?


Does formatting a SSD HFS (Encrypted) avoid the issues applying FV2 to a SSD?


That additional security is quite a bit more than most will need but it is good to know that it is available.


From today, 19MARCH2013:


Since your posting I've used the 10.8.2 version of Disk Utility to ERASE a pair of USB thumb drives HFS Journaled ENCRYPTED (wouldn't allow me to format/partion encrypted). Pretty cool without too much overhead. However, it seems that my G5 Pro with Leopard wants to reformat them with something it can recognize. Is there a patch/plugin to enable older versions of OS X to mount and read encrypted disks? Is there a name for this type/form of encryption like there is for "FileVault" so I can search for it?

TIA.

Mar 19, 2013 5:05 PM in response to Scotch_Brawth

You cannot enable FileVault (1) on a machine running FileVault 2. You would need to migrate an old FileVault-encrypted home directory.


This is a total waste of effort on a non-shared system, FWIW. I would never recommend this.


If you have FileVault 2 enabled on a multi-user system where everyone has the FileVault password, and you have secure data you wish to hide from others, I'd say encrypted disk images for specific content make more sense than encrypting the whole home directory.


I'd consider "Filevault 1 on top of FileVault 2" to be deprecated at best.

Mar 20, 2013 3:41 PM in response to William Lloyd

You cannot enable FileVault (1) on a machine running FileVault 2. You would need to migrate an old FileVault-encrypted home directory.


Apple specifically refer to using FV 1 over FV 2 in their Apple Technical White Paper: Best Practices for Deploying FileVault 2:

Support for multiple OS authenticated users means that any FileVault- enabled user can unlock the whole volume, as would be expected. However, if the system environment warrants additional cryptographic separation and containment of user files, consider using Legacy FileVault (FileVault 1) simultaneously. Coverage of Legacy FileVault on an OS X system using FileVault FDE is out of scope of this paper. In brief, it’s the

continued use of FileVault 1, container-based encryption of the user’s home directory, on top of FileVault 2 providing full disk encryption.

(p28)

Is there a patch/plugin to enable older versions of OS X to mount and read encrypted disks?

This functionality is a core part of Mountain Lion. Apple won't be retroactively enabling it in Lion, I'm afraid.

Mar 20, 2013 9:47 PM in response to Scotch_Brawth

Scotch_Brawth wrote:


Is there a patch/plugin to enable older versions of OS X to mount and read encrypted disks?

This functionality is a core part of Mountain Lion. Apple won't be retroactively enabling it in Lion, I'm afraid.


In the famous words of Charlie Brown: "Good grief!" "I can't stand it! I just can't stand it!" "AAAUUGH!" but one word sums it up best: "RATS!"


Thanks.

Jun 10, 2013 3:27 PM in response to softwater

Softwater wrote:

You can't start up in Safe Mode if FV2 is enabled.


Well, yesterday I installed 10.8.4 and I can start up in Safe Mode now (I might have been able earlier but don't know). I held the shift key down during power up and I went into the login screen immediately. I selected a user, typed in the password, held the shift key down again and it went into the Safe Mode start up.


BTW, I just looked at the new Power Mac and I think I'm in love (at least until I see the price)! My first impression was this is the Mac Cube on gamma powered steroids. I wonder how many would have to be connected together to create a Cray class super computer?


http://www.apple.com/mac-pro/

Feb 3, 2014 6:13 PM in response to barubin

Depends more on year and common HPC offerings than on vendor. A "tightly coupled" architecture (ie., where the kernel et al is heavily modified to tie into the interconnect hardware and topology, to the extent that the kernel can't function without the interconnect) is a wildcard as such a thing would definitely not be a COTS product and could reasonably be expected to be architected per customer, if not per purchace. Given "loosely compled" (where, say, a compute node can boot and run independent of the interconnect with most or all of it's local functionality intact), and the new mac's cpu/ddr specs, that's more reasonable; I'd say you could get into the ~150TFps range (ie., current to ~2010) with around 30k cores (not nodes, or dies ie., a Nehalem would count as 16 cores). My last big system was an Altix ICE 8200 at 36k cores, and it could sustain ~162.1TF, but that was with slower cpus and memory, and only one plane of 2x Infiniband. The 2013 "norm" is more like 75k cores and later generation IB and DDR, so maybe triple the TFps target.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

FileVault 2 Issues and downside?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.