File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -141,7 +141,7 @@ has powered on and the SEP is satisfied with the state of iBoot and the system f
141141When FileVault is enabled for an APFS volume, the VEK and xART are wrapped with a Key Encryption Key (KEK), which is backed
142142by user credentials from the macOS container in question. The machine will be unable to read the user data volume of the
143143protected container until these credentials are provided at startup. Enabling this is instantaneous on Apple Silicon machines, since
144- the only required operation is generating the KEK and and a recovery key. The system snapshot, Preboot, and
144+ the only required operation is generating the KEK and a recovery key. The system snapshot, Preboot, and
145145recovery volumes are not protected by FileVault. These partitions are immutable, backed by the SEP, and contain no user data
146146and therefore do not particularly benefit from FileVault. All encryption keys are destroyed by the SEP
147147when the Machine Owner requests the machine to be wiped, guaranteeing that any residual data is indecipherable even to data recovery
You can’t perform that action at this time.
0 commit comments