Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

Rumors_newbie

macrumors newbie
Original poster
Mar 31, 2024
3
0
I recently sold a MBP with a T2 security chip hoping that my data is completely erased, beyond recovery. My understanding is that the “Erase all content and settings” feature securely erases the encryption key stored somewhere (I forgot the name).

If I didn’t use this “Erase all content and settings” feature, and just went into disk utility and erased/reformatted the partition from there, can I be sure that the encryption key was securely erased? Because as “careless” as I am I just did that and didn’t read Apple’s specific T2 chip instructions.
 

Rumors_newbie

macrumors newbie
Original poster
Mar 31, 2024
3
0
To clarify, I think I remember doing the steps this guy describes in the second part of the video:
 

ondioline

macrumors 6502
May 5, 2020
281
283
No, if you didn't use EACAS then the cryptographic key for encryption in the secure enclave is still the same.
 

Rumors_newbie

macrumors newbie
Original poster
Mar 31, 2024
3
0
No, if you didn't use EACAS then the cryptographic key for encryption in the secure enclave is still the same.
Thanks for the response. Do you have a source?

Also, if the new user sets up their computer with migration assistant, will that reset/transfer the key in the Secure Enclave?
 
Last edited:

chabig

macrumors G4
Sep 6, 2002
11,270
8,973
If I didn’t use this “Erase all content and settings” feature, and just went into disk utility and erased/reformatted the partition from there, can I be sure that the encryption key was securely erased?
I agree with ondioline. I believe the encryption key would still be in the Secure Enclave. But it wouldn't matter because you erased the data, right?

You can erase the Secure Enclave in Recovery mode using terminal.

 

ondioline

macrumors 6502
May 5, 2020
281
283
Thanks for the response. Do you have a source?

Also, if the new user sets up their computer with migration assistant, will that reset/transfer the key in the Secure Enclave?
No, the thing EACAS erases is the 'media key' which wraps all the subsequent volume keys, it has to be explicitly changed to make decryption impossible. Although I doubt you need to be this paranoid, no one is going to recover your files lol

Screenshot 2024-04-01 at 2.42.36 AM.png
 

FreakinEurekan

macrumors 603
Sep 8, 2011
5,606
2,673
Erase All Contents & Settings vs. erase via Disk Utility - either is fine. Erase All is far more convenient in that you don't have to then reinstall. But since it's done now - you're fine.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.