Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

Sensamic

macrumors 68040
Original poster
Mar 26, 2010
3,031
656
Trying out my girlfriends iMac M1 with Magic Keyboard and TouchID I just check that I can't use my fingerprint to log in after initial boot. Is that so for everyone? Or is there a setting I have to find?
 

adrianlondon

macrumors 603
Nov 28, 2013
5,030
7,604
Switzerland
You need to log in once using a password to unlock the drive (filevault) and the area (secure enclave) that stores fingerprints.

 
  • Like
Reactions: Sensamic

casperes1996

macrumors 604
Jan 26, 2014
7,503
5,679
Horsens, Denmark
Yeah it’s a fundamental part of the security architecture. The fingerprint reader in the keyboard and the Secure Enclave have no session key to unlock with on first boot. Fingerprint is not considered a master key on the system only the password is. So after you enter the password the Secure Enclave generates a session key that the fingerprint reader can unlock with.
It can be invalidated with a timeout or find my marking the device as lost and such to reduce the threat vector
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.