Turning file vault on AFTER already using iCloud desktop and documents sync

I've been using iCloud Desktop & Documents sync since I upgraded to Sierra. I've decided I'd now like to turn File Vault on on my Mac.


Do I need to first turn off iCloud sync on my Mac and then turn on File Fault (and then turn iCloud sync on again)? Or can I just turn File Vault on and somehow iCloud will encrypt all of the info in Desktop & Documents that are already uploaded and stored in iCloud?


If I do need to turn iCloud sync off first, will I need to re download all of my files from iCloud? The warning message states that "all documents on your mac will be deleted" yet they remain in iCloud. I'd really rather not do this...

Posted on Jan 16, 2017 9:52 AM

Reply
10 replies

Jan 16, 2017 7:51 PM in response to cocon

Everything in iCloud is already encrypted. Enabling File Vault will have no added benefit for your cloud content.


The encryption process for the hard drive just chews through the data and encrypts it. It does not care what the files are or if they are synced elsewhere.


When syncing with iCloud, there is no detection of "this is encrypted" and "this is not encrypted" It's all just bits and bytes and up it goes to an encrypted storage location.

User uploaded file

iCloud security and privacy overview - Apple Support

Jan 16, 2017 7:58 PM in response to LACAllen

That's a great clarification LACallen. This was half of my desire that no longer needs attention but I'm also looking to also encrypt locally. I'm not sure if the File Vault encryption is file-by-file or the as a monolithic disk and if the latter didn't know iCloud would handle it. If each file is independently encrypted I'm guessing iCloud will have to essentially re-upload all my files.

Jan 16, 2017 8:12 PM in response to cocon

Thanks.


I read the encryption is FDE, full disk encryption. Apple is, understandably, coy with the full details.


I am not sure if adding encryption would trigger an iCloud upload cycle. The file's contents to external apps are not changed. The "encrypt" "decrypt" cycle is done by the file system, not the app reading the file. Otherwise all OSX apps would need to be able to "encrypt/decrypt" to be of any value to a user. As they say, "there's people for that" I'm sure that's why you read about performance issues for encryption when an app has to "wait" for the process to finish for all read/writes.


Maybe pare down your Photo Library and test with turning Filevault on with a smallish library. Or just PAUSE uploading if it starts.

Jan 16, 2017 8:19 PM in response to LACAllen

So if I understand correctly, you're suggesting even if File Vault is doing a full disk encryption, when interacting back and forth with iCloud the process is file-by-file anyway. I imagine that under the hood the MacOS is decrypting each file on my local drive but then it is immediately re-encrypted as it's uploaded to iCloud. This is probably an over simplified way to look at it and there are other things going on to make it as efficient as possible, but if roughly right this makes it pretty clear to me.


Thanks!!

Jan 16, 2017 8:37 PM in response to LACAllen

Makes perfect sense now. Thanks!


Now if you can just solve the mystery of my 40gb iCloud sync being stuck indefinitely with about 100mb left to go (it's been a month or more since I notice)... Even stranger is I have about 10 folders that show the dotted icloud status symbols but all of the files within the folders show solid symbols. Comparing with iCloud in Safari I can see some files are not visible though. I think all of the problem files are just ones I moved between folders a while ago. I'll being watching for a few more days before reporting to Apple.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Turning file vault on AFTER already using iCloud desktop and documents sync

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.