• @valpackett
    link
    English
    29 months ago

    IIUC Apple syncs them using the most secure way they can, i.e. when you enroll a new device to your account the existing device, the existing device’s HSM encrypts keys using the pubkey of the new one’s HSM; and for recovery from being left with 0 Apple devices there might be (?) an escrow option that’s optional (?)

    • @atheken@programming.dev
      link
      fedilink
      English
      29 months ago

      Cool. I should check it out. I tend to assume that when Apple (or Google) rolled this out that it’s not broken in any obvious way that I would recognize right away.

      But like contactless payments, which I’ve advocated my friends and family switch to, I should read up on why it’s more secure.