Got a tip for us?

How-To

It’s a fact of life: software has bugs. And some of those bugs result in security vulnerabilities. Fortunately, most major software vendors, including Apple, have teams of programmers working constantly to identify and fix security-related bugs.

I can’t tell you how many times I’ve read breathless news reports about some newly discovered and seemingly disastrous Apple security issue, only to see a software update from Apple fix it a few days later before any damage occurs. This is Apple’s normal pattern, and it’s why you should never lose sleep about the security crisis du jour.

However, Apple security updates don’t help unless you install them! If you have automatic software updates turned off and ignore alerts or badges, you could be needlessly putting your devices and your data at risk from problems that were solved months or years ago.

Software updates fall into several categories, all of which can fix security issues:

  • Major upgrades, such as from macOS 26 Tahoe to macOS 27 Golden Gate or iOS 26 to iOS 27
  • Minor updates, which can be small increments for big fixes (27.1.0 to 27.1.1), or larger ones when they include feature changes but not a full operating system upgrade (such as 27.0.1 to 27.1)
  • Standalone security updates that fix specific pieces of system software, usually stuff deep beneath the surface (most common with a Mac)
  • Updates to individual Apple apps (Safari, Music, Books, QuickTime Player, etc.)
  • Updates to third-party apps

Which of these should you keep up with? Ideally, all of them, but at a bare minimum, install the standalone security updates. After confirming you haven’t heard of any problems others have had, install minor updates. Major updates require more planning and involve much more than security fixes.

To learn about all Apple software updates with security implications, see the Apple security releases page. Click a specific update to read the security details.

Zero-day exploits

Apple, Google, Microsoft, security firms, anti-malware software developers, independent security consultants, and “gray-hat” hackers (not criminals, but they don’t always play by the rules—or laws) are constantly on the lookout for significant flaws to fix them and release updates before they become a zero-day exploit or zero-day attack. That’s when there’s literally zero days to patch the problem.

Malicious parties—including nation-state actors, such as the security agencies of major countries—may hold zero-days in reserve or use them in such a limited fashion that they remain available for some time. It’s the job of all software developers to patch zero-days before they’re exploited.

It’s much more often the case that ugly bugs are fixed by Apple before they’re exploited in the wild; or the exploit is so tricky, it requires physical device access or incredible sophistication, timing, and targeting. Apple will flag particularly severe exploits and recommend immediate installation when necessary. This happened on April 16, 2025, when Apple pushed out updates across their operating systems to fix zero-day exploits that the company said were already used in the wild in individually targeted attacks.

Zero-day exploits that aren’t reported to Apple and other companies responsibly—sometimes for significant “bug bounties” these firms and zero-day projects pay out—are sold on the gray market and used for pinpoint government operations. These are often ones most people would feel are illegitimate or violate human rights, such as three separate zero days used allegedly by the United Arab Emirates to hijack a single human-rights advocate in their country.

In most cases, Apple releases security updates for the current version of macOS, iOS, and iPadOS, and the previous three—or even four. If you aren’t at least on the third-most-recent version of one of these operating systems, you risk being vulnerable to known security problems that Apple won’t ever fix.

Apple also looks backward quite a ways with hardware, letting you upgrade fairly old Macs, iPhones, and iPads to at least one of the third-oldest operating systems, if not the current one. With Golden Gate, support covers all Apple silicon Macs; Tahoe included four Intel models from 2019 and 2020. iOS 26 and 27 look back to the iPhone 11 series (2019), while the cutoff points for iPadOS 26 and iPadOS 27 are very complicated.

Often the initial releases of new operating system versions (27.0.0, say) have significant bugs that Apple fixes quickly. So it’s fine to wait a few weeks on major upgrades, by which time enough others will have tried out the new release that you can judge how stable it may be for you.

Apple delivers minor and major updates and security updates through Software Update: go to System Settings (Mac) or Settings (iPhone/iPad) > General > Software Update.

Configure automatic security updates

Apple wants you to install updates as soon as possible on all its operating systems. The approach you take may be different between a Mac and an iPhone or iPad.

On a Mac

Software Update shows whether you’re up to date and notes any available updates if you are not. If you’re a major system update behind (or further), it also shows an area at the top urging you to install it. In a secondary area below, the pane may read “Another update is available” for Safari and security updates, and you have to click “More info” to discover which are and proceed to install them.

It also runs in the background and displays a red badge in System Settings indicating quantity. You can’t disable this.

You can completely automate minor macOS, security, and other updates—in fact, that’s the default. (Major macOS updates require direct action.) Go to System Settings > General > Software Update and, to the right of Automatic Updates, click the info button to see settings and make changes.

  • Download new updates when available: This includes all the updates listed below. The advantage is that they are either installed automatically or available for immediate installation if you install manually. Disable this if you’re bandwidth-limited or pay for bandwidth and want to plan downloads.
  • Install macOS updates: This includes all “dot” updates, like moving from 27.0.0 to 27.0.1 and from 27.0.1 to 27.1.0.
  • Install system data files and security updates (Golden Gate) or Security Responses and System files (Tahoe): Apple used to use the term “Rapid Security Response” for these security updates; I’m guessing they now incorporate more kinds of security fixes? Previously, the company explained those updates addressed exploits that Apple discovered were already happening in the wild, not just identified by researchers. These fixes are installed automatically when this option is turned on—no reboot required.

Apple moved automatic App Store updates from Software Update to the App Store app in macOS 26.

In most cases, you can view a list of available updates, deselect or select items in the list, select items to view their contents, and click Install Now to proceed towards installation. Updates that require restarting your Mac are marked with “Restart Required” after their title in the detail section, and you’re warned when you click Install Now that you will need to let the updater restart your Mac to complete the update.

The next major operating system update past what you’re running used to appear as a short entry with a More Info link. But in Monterey, Apple transformed the upgrade notice into a full advertisement that listed all the available features. Minor updates still use the More Info link to tell you what to expect.

When preparing to install updates that require a restart, make sure you have no unsaved files, no open Terminal windows, and nothing in progress in an app. Often, this can halt a restart—particularly an issue if you walk away hoping to return with the update done. I always wait until my Mac restarts before leaving.

In addition to the Software Update setting for system data files and security updates, make sure the setting introduced in macOS 26.1 is enabled: System Settings > Privacy & Security > Background Security Improvement. With this enabled, Apple can update certain parts of the system, such as components of Safari and system libraries used by multiple apps, without requiring a full incremental update and restart.

On an iPhone or iPad

Software Update on an iPhone or iPad, in Settings > General > Software Updates > Automatic Updates, offers options similar to those on a Mac. If you enabled Automatically Install, you’re alerted that an update will happen overnight the next time the device is plugged in and idle. This option also hides the next two: Automatically Download and System Files > Automatically Install.

Even if you don’t want updates to be installed automatically, enabling downloads for iOS/iPadOS Updates lets you avoid waiting for a download to happen when you make the decision to trigger an update manually—the file is ready to go.

Everyone should leave System Files enabled for automatic updates, for the reasons given above.

As with macOS, Background Security Improvements should also be turned on. Go to Settings > Privacy & Security > Background Security Improvements, and make sure it’s enabled.

Configure App Store updates

The App Store is where you buy apps and acquire free apps, including those with in-app purchases, that have gone through additional layers of vetting by Apple. One advantage is that you don’t need to use the app or visit a website to check whether the latest version is installed.

On a Mac, the App Store has an Updates item in its left-hand navigation bar. Click that, and you can see available updates. You can also use App Store’s Preferences to control automatic updates: select or deselect Automatic Updates.

On iPhone/iPad, the default is for updates to be quietly updated in the background. You can change this in Settings > Apps > App Store, where you can disable App Updates. You can see the queue of updates waiting to happen in the App Store app: tap the account button in the upper-right corner and then tap App Updates. Any apps with pending updates appear under an Upcoming Automatic Updates label. You can force a check for updates by swiping down and releasing, and you can tap Update All to force an immediate app update.

Update everything else on a Mac

Software that didn’t come from the Mac App Store must be updated separately. Fortunately, most apps include an automatic, configurable update check whenever you launch them, and also check for updates periodically. You can disable this in nearly all apps, though I recommend keeping the feature on, or enabling it if it’s turned off by default.

If you haven’t seen update notifications lately, or aren’t sure how your favorite apps have automatic updates configured, now is the time to check. Launch each app, select its option to check, and install updates.

Some apps use “check for updates” as a way to sell you on a paid upgrade to the next version of the product. I don’t mind seeing this once or twice, but some software I use brings up a paid update available message at every launch; not cool.

How Apple numbers its releases

Starting with fall 2025 operating system releases, Apple reset their numbering system to the last two digits of the following year, starting with 26. So 2026 releases are iOS 27, iPadOS 27, macOS 27 Golden Gate, tvOS 27, and watchOS 27; and 2025 releases were iOS 26, iPadOS 26, macOS 26 Tahoe, tvOS 26, and watchOS 26.

Advanced Data Protection (ADP) is an option to enable end-to-end encryption (E2EE) for iCloud-stored data from your Mac, iPhone, or iPad. ADP covers nearly all the data for which Apple previously lacked an E2EE option. (See how to share files with end-to-end encryption for a full definition.)

You can see a full list of the items that are encrypted at rest (on servers using keys Apple possesses) and those with E2EE enabled in iCloud on Apple’s website, both with and without ADP enabled. Without ADP, these items remain encrypted at rest only: iCloud backups, Freeform (Apple’s collaborative drawing tool), iCloud Drive, Apple Invites, Messages in iCloud, Notes, Photos, Reminders, Safari bookmarks, Siri Shortcuts, Voice Memos, and Wallet passes. Enabling ADP adds E2EE to all of them. (Apple Invites has exceptions; see note on the page linked just above.)

Email, contacts, and calendar entries can only be encrypted at rest due to interoperability with third-party services and apps.

I recommend enabling ADP if you qualify, as it provides a strong additional layer of protection for private data that you might consider “local” if you never access it via iCloud.com.

What ADP requires

ADP requires two-factor authentication on your Apple Account, which most accounts already have enabled due to Apple’s nearly mandatory policy. You also have to have passcodes on all of your devices—also, nearly universal. One requirement not everyone will have met: iCloud Data Recovery has to be turned on with at least one active contact or an Apple Account Recovery Key.

All your devices must meet minimum system requirements, which nearly every current device exceeds: macOS 13.1 Ventura, iOS 16.2, iPadOS 16.2, tvOS 16.2, watchOS 9.2, and—yes—HomePod 16.2. If you have any associated Windows computers, they must have iCloud for Windows 14.1 or later installed.

Apple says managed Apple Accounts and accounts set up for children cannot enable ADP.

An Apple Account Recovery Key is entirely unrelated to the FileVault Recovery Key. See where to find your FileVault Recovery Key.

Siri AI, Private Cloud Compute and conversations

Apple introduced Siri AI with iOS 27, iPadOS 27 and macOS 27, a more full-featured chatbot version of Siri on devices that support Apple Intelligence. Conversations with Siri are stored in the new Siri app and synced via iCloud. However, these are end-to-end encrypted sync operations, such as what’s used with Messages and iCloud Passwords. You don’t need to enable ADP, as described next.

To provide these enhanced services, Apple may send portions of your queries to what they call Private Cloud Compute. Private Cloud Compute consists of both servers they own and operate and servers in Google Cloud that Apple controls every component of, even though it’s not Apple hardware or in an Apple data center. You can’t prevent these requests from leaving your hardware, but Apple says all queries are encrypted end to end, untraceable back to you, impenetrable to Apple and any partners (even when debugging servers or code), and so forth. This is covered further in what Apple Intelligence, Siri AI and Visual Intelligence actually are.

Turn on ADP

Start by going to the ADP setting section: System Settings (Mac)/Settings (iPhone/iPad) > Account Name > iCloud > Advanced Data Protection. Tap Turn On Advanced Data Protection or click Turn On.

Apple now lets you turn on ADP:

  1. Apple warns you that “you will be responsible for your data recovery.” You have to click or tap the Review Recovery Methods option or Set Up next to an Account Recovery button.
  2. If you have Recovery Contacts, they’re shown. Click or tap Contacts Up to Date if they are or select Update Recovery Contacts if they are not to revise. Then return to step 1.
  3. If you have a Recovery Key, you must enter it and click or tap Next.
  4. With your recovery methods approved, enter your macOS account password or device passcode when prompted.
  5. Finally, you’re told, “Advanced Data Protection is On.” Click Done.

You should also receive an email to your iCloud.com address that tells you ADP was enabled.

If your devices aren’t all running the minimum supported operating system versions, you’ll be told which ones require an update. You can choose to upgrade all devices or remove one or more outdated devices from your account. Go to Settings/System Settings > Account Name, select a device, click or tap Remove from Account, and follow the prompts.

Reach your data on iCloud.com

With ADP enabled, all your data except email, contacts, and calendar entries is encrypted by keys held on your devices. That would appear to count iCloud.com access out. But Apple has a workaround. They allow temporary access using in-browser encryption.

First, you have to let yourself view the data on iCloud.com: go to Settings/System Settings > Account Name > iCloud. On an iPhone or iPad, tap iCloud.com and then Allow Data Access; on a Mac, click Data Access on iCloud.com and enable Allow Data Access. Confirm your choice; in fact, you have to confirm twice.

You can disable non-ADP access via iCloud.com using that setting, too.

With that enabled, here’s how to unlock temporary access:

  1. Visit icloud.com in a browser and log in.
  2. Apple shows a banner that explains that ADP is on and how to proceed.
  3. Select an app, such as Photos.
  4. Apple sends an access request to trusted devices. (If you don’t see the prompt, you can click or tap Request New Access.)
  5. On a trusted device, click or tap Allow Access.
  6. On your trusted devices, a banner appears alerting you that you’ve enabled temporary access.

Data remains accessible for an hour from each request. Each additional data type you want to access may require another permission request and approval unless requested shortly after a previous request.

Data previously unavailable on iCloud, such as Passwords entries and Health data, remains locked on devices.

The Find My exceptions

Until mid-2021, Apple listed Find My (Devices and People) as protected by their keys. When the company started to break out “in transit & on server” and E2EE, it dropped Find My from the iCloud page. Apple then stopped documenting the relationship of Find My with iCloud. That leaves it to me to try to explain.

The Find My Device web app is available at iCloud.com when you log in with two-factor authentication or a passkey. Even if ADP is enabled, you’re not asked to start a secure, device-approved session. Apple uses secure transit and their own keys to pass your location from your devices and those of people in your Family Sharing group who have shared location with you to your iCloud account. There’s no other way for that information to appear.

Apple doesn’t pass information about other people’s location, nor do they provide AirTag and other Find My item positioning, and thus I assume there is device-based E2EE involved in sharing that information among your hardware that Apple doesn’t want to override.

Turn ADP off

Disabling ADP is straightforward. Go to Settings/System Settings > Account Name > iCloud > Advanced Data Protection. Tap Turn Off Advanced Data Protection or click Turn Off. Follow the prompts to confirm you understand you’re removing E2EE protection from many of your synced and stored data.

One of the most unsettling things that can happen to your device and your data is when you are locked out from your computer. It’s rare, and you can prepare against the possibility so that your recovery is quick—or at least feasible, if not fast.

An ounce of prevention saves a kiloton of cure when it comes to accounts and access. If you follow the following advice ahead of time, you can avoid serious downtime and loss of data.

Keep fresh backups

Backups are the strongest protection you can have against theft, destruction, and loss, including “loss of access.”

If you have daily backups of your Mac and attached drives onsite (via Time Machine or third-party software), copies of your startup volume and external drives offsite, active continuous or daily cloud-hosted backups, or use a sync service to ensure multiple copies and a version history of your active documents, losing access to your Mac still has a sting, but you likely will lose very little data, if any.

You could be like me and do all four. But that’s me.

In some cases, you might be locked out of your current Mac, such as with a FileVault failure or the loss of a Recovery Key. In those cases, you can erase the computer and restore from a full backup, putting you right back in business. Or you may be able to use an external drive or synced files to get back to work on another machine—perhaps a borrowed one—while you plot unlocking the Mac you can’t get to.

Macs that support Activation Lock and have it enabled by turning on Find My Mac require that you can log in to your Apple Account to erase the computer. See how to reset a forgotten Mac password.

With an iPhone or iPad, your biggest job is ensuring you have enough storage in your iCloud+ plan to allow iCloud backups. You can also use a Mac for device backups, but that dramatically increases the odds you’ll be out of date and missing data. With automatic iCloud backups enabled and using iCloud Photos, it’s unlikely you would lose any data—at worst, very little.

Where to keep your passwords

You should have a go-to, secure place for all passwords, passkeys, and other login and encryption keys you may need in the event of a disaster, including:

  • Passwords for one or more administrator accounts on your Mac
  • Passcodes for any iPhones or iPads
  • The Recovery Key for macOS’s FileVault; see where to find your FileVault Recovery Key
  • The account name and password or passkey (or hardware security keys) for your Apple Account (or Accounts)
  • The password for your password manager (which may be the sole item you memorize, and you may also provide a copy to a lawyer, sibling, or trusted party to hold securely)

This secure password repository should preferably be available from a device or location that isn’t tied to where you keep your hardware.

Check your trusted devices and numbers

With two-factor authentication (2FA) enabled on your Apple Account, you might be locked out permanently if you lose access to trusted devices, and trusted phone numbers for SMS and automated voice calls, or can’t find hardware security keys that can be used with an Apple Account.

If you’re using hardware security keys with your Apple Account, Apple already requires that you associate two of them with the account. Always keep one in a place you can get to in an emergency in case the other is lost or destroyed.

Any Apple device logged in to an iCloud account with 2FA active is a so-called trusted device. You can tell that this is working when you try to log in via a browser to the Apple Account website, as every trusted device will display a notification for the 2FA code needed to confirm the login.

If one of your trusted devices doesn’t show that message, check in System Settings/Settings > Account Name that you’re correctly logged in and that you see all the associated devices you expect. If you still can’t get your Apple Account to message trusted devices or the list of devices is missing, you may want to log out of your Apple Account on affected devices and then log back in.

This can take a while and prompt you to answer a lot of questions about synced data—the answer for most is “keep data stored on this device.” When you log back in to iCloud on the device, you agree to merge data, which should avoid duplication and deletion.

You should also check that trusted phone numbers are still properly registered:

  1. Log in at the Apple Account website. If you have Touch ID or Face ID active, click “Use a different Apple Account” and then enter your ID and password.
  2. Instead of entering a 2FA code, click or tap “Didn’t get a verification code?”
  3. Click or tap Text Me. (This will be labeled differently if you marked any or all trusted phone numbers as receiving automatic voice calls instead of text messages.)
  4. Select a trusted number if more than one is available; if only one, Apple texts that number.
  5. Enter the code that’s sent or use the AutoFill option in Safari.

If you never receive the code, log in with a trusted device, check the phone number, and remove and add it. I also recommend having multiple trusted phone numbers as backups.

Changing your phone number has a huge impact in the era of 2FA. You should instead try to transfer your old number to another phone temporarily so you can switch the number listed for various accounts’ 2FA and for iCloud trusted phone numbers.

If you have willing friends, colleagues, or families, having their number as a backup in case your phone isn’t available doesn’t really reduce security, as they would need to know your Apple Account username and password to compromise your security.

Put a PIN on your carrier account

Add a PIN (if you don’t already have one) for account access to your wireless carrier or enable the highest security available for an increasingly rare wired home phone line. Someone who could obtain codes from your phone number might be able to reset your Apple Account and then access iCloud information. (Enabling Advanced Data Protection is one way of preventing that.) Because of accessibility, codes can often be sent both by SMS and by an automated voice system that speaks the code.

Crackers often target people and combine social engineering and easily available online information to convince a customer-service representative that they are the legitimate account holder to get a phone number migrated to a new phone. (Are you likely to be targeted? See whether you need more security than Apple’s defaults. Yet someone may target your account at random to launch attacks.)

The PIN sets a higher bar, because a cracker might have your phone number, financial details, and other information, depending on data breaches floating around.

Keeping your security keys safe

You should treat hardware security keys as if they were irreplaceable keys to the castle—like a passphrase for a cryptocurrency wallet or a password for a vault that self-destructs when you’re one number off in a Dan Brown novel. They’re extremely secure, absolutely vital, and also can be used by other people!

Apple requires that you enroll at least two hardware security keys for an Apple Account. Most sites only require a single hardware key, or won’t let you enroll more than one. If you lose the key, most sites offer a workaround that requires more forms of validation to gain access. Apple does not.

If you can’t find your hardware security keys (or they’re irretrievable, stolen, or busted), but do have access to any of your Apple devices, you can go to Settings/System Settings > Account Name > Sign-In & Security > Two-Factor Authentication > Security Keys and remove all hardware security keys. This requires your device passcode or macOS account password if Stolen Device Protection is disabled, or Touch ID or Face ID if that feature is enabled. Then you can use code-based 2FA to log in to your Apple Account. You can choose to add new security keys if you want to re-enable that level of account security.

Apple has a significant flaw in hardware key management: you can remove all the keys from your Apple Account on an iPhone, iPad, or Mac using only the device passcode or the macOS account password. I feel Apple should demand additional information or another hardware key on the account, since the keys are meant to provide an extra-high level of security.

Enabling Stolen Device Protection requires Face ID or Touch ID to remove all keys. So if you’re concerned about someone gaining access to your device and its associated device or account secret, enable that feature. See how to turn on Stolen Device Protection.

Apple built in privacy protection for an issue adjacent to your IP address. Every Ethernet or Wi-Fi adapter, built in or plugged in, has a unique MAC address—that’s Media Access Control, not Macintosh. A MAC address appears in the form xx:xx:xx:xx:xx:xx, where each x is a value between 0 and 15 expressed in hexadecimal (0 to 9 then A to F). Apple perplexingly calls it a “Wi-Fi address”, which is the incorrect name.

A MAC address is how a device communicates over a local network, used to make sure every interface has a unique address to avoid data being delivered to the wrong location. However, because this MAC address is set in hardware, clever hackers and marketers started to use it to associate people with devices—your MAC address persisted indefinitely, so a Wi-Fi router in a public place could conceivably track you over time whenever you connected to any router that shared information with a central database, like a cell carrier or ad-targeting service. Bad!

Apple got around this by adding a “Private Wi-Fi address” option (still the wrong term) that generates a unique MAC address for each Wi-Fi network you join, changing it from time to time. This deters and potentially fully prevents MAC-based tracking.

Apple made significant changes to this several-year-old feature in iOS 18/iPadOS 18, macOS 15 Sequoia, and watchOS 11.

You can configure “Private Wi-Fi address” in one of three ways:

  • Off: The actual unique MAC address is sent to the router.
  • Fixed: Your device generates a MAC address that’s used consistently for the selected Wi-Fi network. This may be required in some places in which a MAC address is used as part of a hotspot portal’s permission system that grants you access or in corporate environments when you’re a guest. Your home router may even offer an option to set a fixed private IP address using a MAC address, so your MAC address needs to be fixed.
  • Rotating: The private address that’s generated is changed to a new, randomly created one every two weeks, whether you’re connecting in that period or after a gap of two weeks or longer.

Apple defaults to either Fixed or Rotating. It uses Fixed the first time you connect to a network with relatively modern Wi-Fi network security—WPA2 or later, to use the technical term. A network without such security, either using outdated standards or requiring no passwords, such as at an open Wi-Fi network at a café, is set to Rotating by default. You have to choose Off, read a warning, and confirm.

The options to change the type of Private Wi-Fi Address used with a network vary by operating system:

  • iPhone/iPad: Go to Settings > Wi-Fi: tap the info button next to the currently connected network or any other network that appears. You can also tap Edit, and then tap the info button next to any stored network.
  • Mac: Go to System Settings > Wi-Fi > Details for the active network. For other networks, click the More button; for Known Networks, then choose Network Settings.

To see the underlying Wi-Fi adapter’s hardware-set MAC address, go to Settings > General > About and look for Wi-Fi Address on an iPhone or iPad. On a Mac, follow the path of System Settings > Wi-Fi, click the Advanced button, and see Wi-Fi MAC Address near the top.

Biometric protection is a terrific safeguard to layer on top of other basic protections. By letting you use a fingerprint or your face to unlock your device, it increases security for your files and data while also making it easier for you to log in.

Touch ID first appeared on iPhones with the iPhone 5s in 2013, and was added to iPads starting with the iPad Air 2 model the next year. All subsequent iPhones and iPads included Touch ID until Face ID replaced fingerprint authentication on the iPhone starting with the iPhone X in 2017. Since then, it’s been part of every iPhone except the iPhone SE series, which retains Touch ID.

The sole iPad model with Face ID is the iPad Pro, starting with the 1st-generation 11-inch and 3rd-generation 12.9-inch models in 2018. All other iPads that can run iPadOS 26 or 27 have Touch ID, which dates back to 2014 in some iPad model lines.

Touch ID was extended to Mac laptops starting with two 2016 MacBook Pro models. It was later added to all new MacBook Pro models and the MacBook Air starting in 2018, when it became standard. However, that doesn’t help those of us with desktop Macs.

In May 2021, Apple released the Magic Keyboard with Touch ID (in both standard and extended versions) along with their new M1 iMac. This brought Touch ID to a desktop Mac for the first time. Apple later began selling this version of the Magic Keyboard separately, and while the keyboard part works with any Mac, the Touch ID sensor requires an Apple silicon processor.

Apple uses a secure wireless connection between the keyboard and the Secure Enclave module in an Apple silicon Mac to manage Touch ID. That technology is the Secure Enclave.

Apple requires the use of Touch ID or Face ID with its iPhone anti-theft feature, Stolen Device Protection.

Apple lets you choose to enable Touch ID or Face ID to unlock your device, use Apple Pay, pay for items in Apple’s various stores, validate that you want to automatically fill in a password field in Safari and some other locations, and switch between user accounts when fast user switching is turned on. Some third-party apps offer Touch ID or Face ID as a verification option.

Why Apple Pay turns itself off

You may find that your Mac has disabled Apple Pay without a notification, and you notice only when you attempt to use it in Safari or open System Settings > Wallet & Apple Pay.

This can happen for several reasons:

  • Security level changes: If you lower the level of security for an Apple silicon Mac, you may see the message “Apple Pay has been disabled because the security settings of this Mac were modified.” See how macOS protects its own system files.
  • Laptop lid closed: If you have a laptop, its lid must be open. The exception? If you have an Apple silicon laptop Mac paired with a Magic Keyboard with Touch ID, you can use the keyboard’s sensor.
  • System out of date: Apple says that the “Install system data files and security updates” box should be checked for automatic installation of those files in Software Update. See how to set up automatic security updates.
  • Insecure miscellany: Apple also says ambiguously it disables Apple Pay “when it detects third-party software or malware that affects its ability to keep your payment information secure.”

Enroll in Touch ID

You can enroll your device to use Touch ID via Settings/System Settings > Touch ID & Password. Click or tap Add Fingerprint, then follow the prompts to fill in the fingerprint’s main portion, and then the edges. On a Mac, click Done to finish.

I always name the fingerprint descriptively by clicking or tapping it and then typing text.

Naming fingerprints can be a security or personal safety weakness, allowing someone who wants to coerce you to know which finger to force. However, they would also need to open the Touch ID settings to find out.

You can lock your device against Touch ID by using the wrong fingertip five times in succession; see the lockout section below. This is a good trick when you want to prevent being physically coerced into unlocking your Mac.

I like to enroll at least two of my fingers, because it’s a one-time process per fingertip and it lets me avoid remembering which finger is the right one. You can have a total of three on a Mac or five with an iPhone or iPad. Add other people in your household if you want them to be able to unlock your device or use other Touch ID-required features.

Enroll in Face ID

Face ID for the iPhone and iPad Pro (models noted above) uses an infrared laser and sensor to project and measure 30,000 separate data points on a person’s face to create a profile while also capturing other flat views. Subsequent logins repeat those tasks and introduce randomization, allowing the phone to compare the current face with the stored profile and detect face forgery.

iPhone and iPads with Face ID can recognize just one face plus an “alternate appearance,” or a common secondary appearance of yourself, like with any or different makeup, hat, or glasses. Face ID has worked in portrait orientation since its introduction on all supported devices. Landscape authentication works on all supported iPads and iPhone 13 series models and later.

Enrollment uses a similar process to Touch ID: you use Settings > Face ID & Passcode, and choose Enroll Face. The process has you move your head in a circular motion framed on screen until enough information has been gathered.

Apple says they track and retain temporary updates when they find a good match that falls outside their ideal parameters. These temporary updates are good for only a “finite” number of unlocks, which is a little vague. Maybe it’s to cope with temporary clothing choices or eyebrow plucking? A change in glasses?

You can tap Set Up an Alternative Appearance, useful if you have different ways you make yourself up or attire yourself. Apple has never made fully clear how different that can be.

Face ID relies on an “attentive” expression when you log in. This prevents unlocking the phone or tablet when you’re just glancing past the Lock screen, and it requires someone to have their eyes open. Apple says you can unlock wearing sunglasses. The emitters and sensors are designed for use in all lighting conditions, both indoors and outdoors. The alternate appearance helps here, too.

Apple offers support for facial recognition while wearing a mask with iPhone 12 models and later in portrait orientation only. Here’s how to set up the Face ID with a Mask feature:

  1. Go to Settings > Face ID & Passcode.
  2. Enter your passcode.
  3. Tap Face ID with a Mask while wearing a mask typical of the kind you normally wear.
  4. Apple now informs you of the risks and nature of Face ID with a Mask. Tap Use Face ID with a Mask to continue.
  5. While wearing a typical mask, tap Get Started and walk through the facial training system you’re already familiar with for unmasked Face ID.

Apple appears to ignore most of the mask area, so if you use patterned cloth or medical-grade masks, it shouldn’t prevent you from swapping out masks.

If you wear glasses normally with a mask, wear those while setting up Face ID with a Mask; my current enrollment shows “1 pair of glasses added.” You can have a total of four sets of glasses. Add more by tapping Add Glasses.

Face ID can be delightful as you can merely raise an iPhone or iPad to wake it and, while glancing attentively, the device unlocks.

With Apple Pay at a store payment terminal or in conjunction with Apple Pay in Safari for Mac, you have an extra step even with an unlocked iPhone or iPad. A message appears requesting payment. You double-tap the side or top button, then glance to approve the payment.

For the best results when using Apple Pay with Face ID while wearing a mask, first double-press the side button and authenticate with Face ID; then, with the screen showing “Hold Near Reader,” hold your device to the terminal. I adopted this after finding the angle of terminal, mask, and Face ID sensor were often out of alignment.

Although I recommend setting a strong passcode, you may wind up entering your passcode more frequently with Face ID than with Touch ID for a few reasons:

  • Face ID is good but not perfect; bright light can prevent a match.
  • Some models and brands of sunglasses use optical filters that apparently prevent a good or reliable match.
  • When the sensors can’t perform as exact a match as required, they defer to the passcode. This happens routinely but not constantly.
  • Face ID requires a first-use step with Ask to Buy, used for parents or guardians to approve children’s purchase requests. While Touch ID may be used without any preamble, on Face ID-equipped devices, the first time there’s an Ask to Buy request, you have to enter your Apple Account password. You can then enable Face ID for future approvals.

When biometric lockout happens

Apple disables Touch ID and Face ID in a number of cases. Technically, the operating system flushes a kind of temporary permission for accessing certain data. Entering the passcode refreshes that access. Here are several cases in which you’re required to enter the passcode again:

  • After five incorrect fingerprint or facial recognition attempts. Apple notes, in a parenthetical in their security documentation: “(though for usability, the device might offer entering a passcode or password instead of using biometrics after a smaller number of failures)”.
  • After a restart.
  • When you’ve marked the device as lost via Find My.
  • When you add or remove fingerprints or refresh Face ID.
  • When you try to visit Settings/System Settings > Touch ID/Face ID & Passcode.
  • After you try to use Emergency SOS on an iPhone to make an emergency call. This can be changed in Settings > Emergency SOS.
  • After an attempt to view your Medical ID is made on your iPhone.
  • After 48 hours of a device not being unlocked with Touch ID, Face ID, or an account password.

There’s one more case that’s hard to put into a bullet point. There’s a special countdown clock with two phases. It resets each time you enter your passcode. A 156-hour countdown begins (six and a half days). After that period, a second timer starts a four-hour countdown. If, during those last four hours, you don’t use Face ID or Touch ID to unlock your iPhone or iPad, the next time you use it, you’ll be required to enter your passcode.

You’re probably thinking: “Why?! Why, Apple?! Why!!!” Apple has never made a public statement after this biometrics lockout was added several years ago. The best I can figure, they want to ensure you have to enter your password on a regular basis so it doesn’t fall out of your brain. Now, should you be expected to keep track of the above clocks? No! Not at all! However, if you’re asked for your passcode every week or so when you wake up, and wonder why, that’s probably the reason.

You can make a variety of medical information available at Settings > Health > Medical ID. Once you create this, anyone can attempt to view it via the emergency dialer screen. Understandably, this signals your iPhone or iPad is in someone else’s hands, so locking out biometrics is a logical move.

Also, if you have Face ID with a Mask enabled, Apple reduces the interval between passcode requests on your iPhone to 6.5 hours. Every time you use Face ID (with or without a mask), enter the passcode, or use your Watch to unlock your iPhone, the 6.5-hour timer resets its countdown.

Disable Touch ID or Face ID

You may choose to stop using Touch ID or Face ID or want to use it in a more limited fashion.

If you’re in a situation in which you temporarily want to disable Touch ID or Face ID, the easiest way is to hold down either volume button and the side/top button until a screen appears a few seconds later.

iPhones show you the Emergency SOS screen, including Medical ID, if set; iPads show the Slide to Power Off button. At this point, Touch ID or Face ID is disabled, no matter what action you take. Typically, tap Cancel. (For more strategies, see how to set a stronger iPhone passcode.)

You can access your iPhone or iPad after this only by entering your passcode. However, that re-enables Touch ID or Face ID. In some countries and conditions, you can refuse to enter your passcode.

If you don’t want either biometric capability available—for instance, while crossing a national border—go to Settings > Touch ID/Face ID & Passcode and disable the four “Use Touch ID/Face ID For” switches.

Apple builds in a huge array of tools that help if your device is physically compromised, as when someone gains access to your iPhone or computer without your permission, someone takes your device away without your knowledge or steals it in order to try to break into it, or when someone extracts hardware (like a drive) from your Mac.

Apple created the chip-based Secure Enclave technology for iPhones and iPads, then expanded it for Macs starting with Intel models. It’s an integral part of Apple silicon Macs. Secure Enclave was a big improvement for device security and data integrity.

Apple created the Secure Enclave coprocessor, first for the iPhone, as a way to provide a tamper-resistant one-way vault to handle encryption secrets, biometric information, and many kinds of private data. The design of the Secure Enclave prevents Apple from accessing information inside it, so the chip that contains it can’t be removed or manipulated without almost always destroying its contents.

Technically, the Secure Enclave is a component of a system-on-chip (SoC), a single piece of silicon that integrates all the functions that previously required separate silicon, such as a CPU, memory, and various I/O chips.

The Secure Enclave coprocessor is part of all Apple silicon Macs. It’s also found in Intel Macs with the T1 chip (for the Touch Bar) or T2 Security Chip; Apple’s support site lists the starting models. All Macs that can run Sonoma or later have a Secure Enclave. You can install macOS 26 Tahoe on all Apple silicon Macs, but only the last series of Intel models support it; macOS 27 Golden Gate works only on Apple silicon Macs. (Most Macs with a Secure Enclave can run macOS 14 Sonoma or later, but fewer work with Tahoe.)

All iPhones from the iPhone 5s onward have it, as do all iPad models introduced since the iPad Air in 2013.

Not surprisingly, Apple’s other devices with its A-series mobile chips also have a Secure Enclave: the Apple TV (HD and later), Apple Watch (all models), and HomePod (all models).

The Secure Enclave is used for a number of different purposes, some of which are directly relevant to this chapter:

  • Touch ID/Face ID: Fingerprints are enrolled and stored securely within, and logins send patterns to the Secure Enclave to match.

Note: The Magic Keyboard with Touch ID enables fingerprint recognition on Apple silicon Macs by pairing directly with the Secure Enclave in a proprietary secure wireless process.

  • SSD encryption: All iPhones and iPads with a Secure Enclave encrypt all data stored on their invisible “startup volume.” All Macs with a T2 chip or Apple silicon processor have an internal SSD startup volume, and that volume has always-on, hardware-based disk encryption.
  • Storage of encryption keys: Apple uses the Secure Enclave to keep the raw stuff of encryption unavailable to anyone—even Apple. Developers can also make use of the Secure Enclave for keys they want their apps to store.
  • Boot integrity (Mac): The Secure Enclave has some hardcoded information that prevents subverting a Mac when it starts up. Startup is a bootstrap process, like “pulling oneself up by one’s bootstraps.” Little bits of software get more complicated pieces of software running in a cascade until the OS is running. With the Secure Enclave, the first stage is loaded from read-only memory—instructions burned permanently into silicon—and each subsequent stage relies on encrypted validation to avoid hijacking.

Secure Enclave has no management associated with it that you have access to. It’s just neatly there carrying out cryptographic and validation operations behind the scenes.

Memory Integrity Enforcement

Starting with A19- and M5-family devices—the iPhone 17, iPhone Air, and M5-based Macs—Apple built in an extra tier of exploit protection called Memory Integrity Enforcement (MIE). Because of Apple’s system architecture and security focus, they have avoided large-scale malware attacks on their platforms that have plagued other companies. Generally, most of us are safe nearly all of the time from all but phishing attacks.

But it doesn’t mean your devices are immune! Smart companies look at the edges to see what’s missing to fill in the picture, and that’s what MIE does, although this may never have an impact on you. MIE is designed to block particular kinds of “mercenary spyware,” as Apple terms it: products designed to execute against specific targets, developed by companies and sold to governments, or created inside government agencies.

For a computing device to run software, the software must be loaded into memory. From memory, the operating system executes code, which carries out operations, including reading from and writing to memory, a video display, external storage, a network, and more. Memory is divided by the system into what used to be logical chunks—that is, the operating system defined these, but there wasn’t a particular prohibition against software writing in any place in memory. Some parts of memory help the operating system; some are drivers or code that manage interactions with hardware; and some are designed for user space, meant for user-loaded programs and data.

Over decades, that’s changed, where the operating system and hardware restrict how different components of a system and loaded software can write to memory. These restrictions have increasingly reduced the attack surface of malware by making it harder for an attacker to circumvent the operating system and run code where they want.

MIE blocks a common form of exploit, in which an attacker pushes more information into a response or request than the code executing it can handle. This can result in a buffer overflow, in which data spills past the end of the chunk of memory set aside for it and corrupts whatever sits alongside (typically values and pointers that other parts of the program rely on). Attackers use that corruption as a foothold to read secrets or take control of the program.

With MIE, these buffer overflows are blocked at the hardware level: every allocation of memory is marked with a secret tag. Malware can’t write into adjacent allocations because those carry a different tag, and the processor refuses at a hardware level to let data be written there, which stops the app from running. MIE also blocks attempts to read or write the same memory locations after an app releases them for other uses, because those locations receive a fresh tag or tags when they’re reallocated; this foils “use-after-free” exploits.

Apple spent years testing this solution and evaluated it against six real-world exploit chains, or sequences of exploited vulnerabilities strung together to gain control or access information that had previously been used against their platforms. Components of MIE blocked all of them. Apple says they couldn’t rebuild any of the chains to get around MIE, even by swapping in new exploits.

Security researchers reported in May 2026 that they had been able to work around MIE in macOS 26.4.1, and disclosed their findings to Apple.

Now, you will likely never be attacked by top-tier criminals or a government’s security agency. (See whether you need more security than Apple’s defaults; and if you are a target, see Lockdown Mode.) These exploit chains previously cost millions to develop and, if created by companies, were sold for huge sums to governments, which deployed them against high-value targets.

Nonetheless, by making such chains far more expensive to build and maintain, MIE reduces the odds that these techniques would ever trickle down to become attacks aimed at the rest of us.

Password lockout protections

On an iPhone, iPad, or Mac with a Secure Enclave, you can’t keep entering an incorrect password without the system taking notice and action. Or, more particularly, someone trying to break into your device cannot try over and over.

After your device has started up and reached a point at which you can enter an account password or passcode, and that secret is repeatedly entered incorrectly, Apple enforces certain limits and timeouts.

An iPhone, iPad, Mac, and even Apple Watch have the same initial timeout and lockout sequence. You can enter your password incorrectly at the login window or passcode entry field up to four times in a row without a delay between entries. However, after the fourth try, Apple adds a one-minute delay before you can try again. After the fifth, five minutes; after the sixth, 15 minutes; seventh, 1 hour; eighth, 3 hours; and ninth, 8 hours. If your tenth password entry fails, the path splits, as described below. Restarting a device doesn’t reduce the time you wait.

If you enabled the erase option on an iPhone or iPad, after the tenth attempt, the device is wiped. However, Apple notes that “consecutive attempts of the same incorrect password don’t count toward the limit.”

With an iPhone, iPad, or Apple Watch, you have to connect to another device: an iPhone or iPad to a Mac or Windows system; an Apple Watch to an iPhone. The device can’t be unlocked, but can be erased and restored.

With macOS, however, Apple provides up to 40 (yes, 40!) additional login attempts through other means to ensure you have the greatest possible options before permanent lockout:

  • Restart in recovery mode (see how macOS protects its own system files). You can try up to 10 times to enter a correct password for a login account after clicking the Options button.
  • If that fails, you have 10 attempts each for:

    • iCloud recovery
    • FileVault recovery
    • Use of an institutional key, if your Mac is managed by a company

If all of the above fails, Secure Enclave locks the volume: it will no longer process any effort to decrypt your startup volume or verify a password you enter. The drive’s data is unrecoverable. The Mac has to be erased and a new system installed to use it again.

You can tap or click Play Sound when you can’t find a device or item but think it may be nearby, or for a device when you’re trying to alert someone remotely to notice that it’s there—and potentially get in touch with you. This includes everything from iPhones to earbuds to AirTags.

After you tap or click Play Sound, a loud pinging noise will play on a device (if sound is active) or the device will vibrate (if muted) for two minutes. You can also tap to stop it sooner.

With a 1st-generation AirTag, the sound has an ostensibly friendly tone and lasts for about 10 seconds; the 2nd-generation AirTag may seem less so, as Apple measures it as 50% louder. They also raised the pitch one whole tone (from F to G). Other Find My items vary in the sound they produce: the Chipolo ONE Spot says it blares at up to 120 decibels during its sound pattern—the level of a chainsaw or a plane taking off.

An Apple/Google anti-stalking specification (see how Apple and Google detect an unwanted AirTag) now in effect requires devices produce sound of a “minimum 60 Phon peak loudness” at 25 cm (10 inches), a measurement which means 60 dB at 1000 hertz (Hz), a mid-range in human speech, and about 75 dB for higher-pitched tones.

Play Sound communicates differently with devices and items:

  • For an iPhone, iPad, Mac, or Apple Watch, the signal is sent via a local network or the internet.
  • AirTags, Find My items, all AirPods models, and Beats audio devices with Find My support have to be within Bluetooth range to receive the signal from a paired device. (This is true even for Apple and Beats audio devices.)

The 2nd-generation AirTag includes a newer generation of Bluetooth chip, and should be reachable at dozens to hundreds of feet (say, 10 m to 100 m) further than the 1st-generation model.

  • AirPods Pro (2nd generation) can play a sound on their charging case as well as through earbuds.

For audio hardware, you should receive a warning about the potential for hearing damage.

With Apple and Beats earbuds, you can typically pick which earbud should play a sound: either or both.

If your earbuds are in their case or haven’t been “seen” by Find My for some period of time—Apple doesn’t say how long—you won’t see the left/right option.

Apple also alerts people who discover an item traveling with them and gives them an option to play a sound on it; see what an “AirTag Found Moving With You” alert means.

If a device is unlocked, a notification appears that reads “Find My Device Alert”. If an iPhone or iPad is locked, it has to be unlocked to disable the ping or vibration. On a Mac, the dialog can be dismissed at a sign-in screen.

Ping your watch from your phone

On an iPhone, you can add an Apple Watch ping option to Control Center. Swipe to reveal the Control Center, touch and hold on the background of one of the views, tap Add a Control, search for Watch, and add Ping My Watch. Swipe to reveal Control Center and tap the icon to ping. Waking or tapping your iPhone or Watch stops the terrible sound!

Get directions to a person or item

The Maps app offers a quick way to retrieve a path to a person, a device, or an item via Directions. You can tap or click Directions on the sheet in People, Devices, or Items in a native app. You can also use an info pane for a person in Messages, where it appears as a blue-tinted button with a suggested travel method and a time estimate derived from Maps.

Selecting Directions in Find My or tapping the blue directions button in Messages opens the Maps app on your device with the destination being the current location of the person, device, or item. You can then fine-tune things in Maps, such as choose a method of transportation (walking, public transit, driving, etc.)

If someone can’t be reached by car or transit, you just see their location, of course. Maps doesn’t plot boat or air trips.

Work out when someone will arrive

While Directions takes you to someone, you can also figure out how long someone will take to get to you—though it requires a few steps. When certain relatives visit us with their families or when we’re trying to figure out when our kids are due home, my spouse and I use Directions like this:

  1. In Family Sharing, select the person or device associated with them.
  2. Bring up the actions sheet and tap Directions.
  3. In Maps on an iPhone, iPad, or Mac, reverse the direction by dragging the hamburger button to the right of the person’s name to the position above the entry labeled My Location.
  4. Select the mode of transportation the person is using.

Now you have the approximate time someone will arrive. While you can use the more direct method, this is a quick method less reliant on the accuracy and notification delivery of Find My and Apple.

The topic of passwords is huge. The key security aspect is narrower: how you secure them.

Apple devices can store and sync passwords in many ways, each with a different risk profile. What follows is how Apple and third-party apps store passwords, and the gold standard for syncing them among devices without increasing the likelihood they could be accessed—even by the company storing them for you.

Apple added passkeys in 2022, a more secure method of logging into a website without leaking secrets and while offering phishing resistance. You use them in lieu of a password plus a second factor, as they combine the same functions. Apple has integrated passkeys into their overall password-management and fill-in approach.

Starting in Sonoma and iOS 17/iPadOS 17, you can also create sharing groups with other people that include both passwords and passkeys. This solves an issue where you may share account access with family members or colleagues but still want the security of a passkey. (This is managed through the Passwords app.)

Apple lets you log in with a passkey to your account on their Apple Account website. This was added to let you log in securely when you weren’t able to use either Touch ID/Face ID or two-factor authentication. For instance, if you’re using a browser on someone else’s Mac and don’t want to enter the password, or you’re connecting via a Google browser on an Android phone.

Apple’s Passwords app can generate a verification code required for login with many two-factor authentication systems and store it as part of a website password entry. Not Apple’s, of course, just all the others.

Hardware security keys

In early 2023, Apple also added direct support for Apple Account logins on devices and their Apple Account website using a standard closely related to passkeys that stores unique login information on a removable hardware security key. These hardware security keys incorporate industry standards, making them compatible across mobile devices and desktop computers, as well as working with websites and native support built into operating systems.

Hardware security keys have to be activated, whether you’re using them with your Apple Account or on a website (Apple’s or anyone’s). On your Mac, iPhone, or iPad, you insert a key into a port (USB Type A, USB-C, or Lightning) or, with an iPhone or iPad, bring a key with NFC near your device. You then press a trigger on the key to start the interaction.

Hardware security keys are obviously physical items you need to exercise distinct precautions around. Their contents are one-way vaults, much like the Secure Enclave in Apple hardware, and can’t be backed up. Make sure you have safeguards in place to avoid losing or damaging them, and to ensure they’re not stolen. Treat them like a stack of $100 bills.

Apple requires two hardware security keys to enroll in that method for your Apple Account, for just that reason. If one is broken or lost, hey, you have a second. You can enroll more than two.

Where your secrets reside

Starting with iOS 18, iPadOS 18, and macOS 15 Sequoia, Apple made the Passwords app the primary built-in interface for accessing secrets, whether website logins or app passwords. Previously, Apple had a Settings section for Passwords in iOS and iPadOS, and a Passwords tab in Safari for macOS.

Even earlier, Apple steered you to Keychain Access, a utility that still exists, and which provides lower-level access to all manner of passwords, codes, secrets, and certificates managed on your Mac. See how the Mac keychain works. There’s no iOS/iPadOS equivalent.

On an iPhone, iPad, or Mac, you can enable Passwords via iCloud settings, which syncs all your app-based passwords and website logins across all the devices you own that are also logged in to the same iCloud account and have Passwords sync enabled.

Go to System Settings/Settings > Account Name > iCloud and choose Passwords or Passwords and Keychain. Enable “Sync this Device type.”

iOS and iPad app passwords use a mapping that associates them with a website, which can cause problems when you signed up in an app or at a website and then try to log in at the other entry point. The website address might not match the one provided by the app, or the app might not incorporate the right website domain. For instance, the website might use login.example.com while the app points to api.example.com.

You have two options to work around this when it happens. First, you can tap or click Passwords, then search for the domain, app, or site, and select the password entry. You’ll be warned about filling in the password. The better path is to open Passwords, find the entry, select it, tap or click Edit, tap or click Websites, then enter variants on the domain.

Browsers other than Safari have their own password storage systems for local storage and syncing. For example, Google Chrome can sync across all your apps linked to the same Google account and makes passwords available through a web-based password manager, which I have more to say about below. (Apple lets you use iCloud Passwords synced items with Chrome by installing an extension, described later.)

Third-party password managers are a boon for people who work across ecosystems or have more nuanced needs to share passwords and other kinds of data securely. Some offer Android, Windows, and Apple apps, plus browser-based access, and let you set up multiple shared secure vaults or storage areas with different sets of people. These third-party systems also have native plugins for Safari and other browsers.

How your secrets are secured

It’s important to know how password vaults manage the encryption and security of your data, but it can also be a bottomless well of detail. In the following entries, I explain, from a top-level view, how Apple manages these aspects for the Apple Keychain and for Passwords synced via iCloud, how other well-designed password managers do the same, and Google’s shortcomings in that regard.

Local passwords and passkeys

On an iPhone, iPad, or Mac, passwords and passkeys are stored in a system keychain. This is invisible to iPhone and iPad users, but you can view that secure information on a Mac via the Keychain Access app. When you enter your account password or device passcode, the keychain is unlocked for use across the device, though Apple requires biometric or password/passcode authentication to apply passwords for most logins even after that.

When you launch Keychain Access, Apple shows a dialog that says, “Manage Your Passwords in the new Passwords App.” You can then click Open Passwords (highlighted in blue) or Open Keychain Access. If you never want to be prompted again, check “Do not show this message again.”

Passkeys are stored in the keychain, but you can’t view their contents—only that you created them—because they’re based on long sequences of digits that form encryption keys meant to be kept strictly private; even displaying them reduces your security. A Mac makes a passkey available when required to log in to a website. Other browsers and apps that incorporate webpage views can also tap into Apple’s system framework to securely use passkeys.

In the Passwords app, you can view passkeys in their own category, although the entry also includes the login information used when you enrolled, such as username and password.

If you have a website login with a password, initially set up with two-factor code-based verification and then transitioned to a passkey, all those elements appear in a single Passwords manager entry.

You’ll also notice that, if you use Google Chrome in Sonoma or later, the browser opens its own compatible passkey validation system for Google account logins.

Keychain data on its own never leaves your machine, and when backed up, the associated files are encrypted. Locally stored keychain entries are backed up by full-disk encryption on all Apple silicon Macs. Your device passwords and passcodes are the only real weak points.

Apple and the rest of the industry agreed on a standard for passkeys, and also agreed to make passkeys securely exchangeable among ecosystems. Well, the first part was true first; the second took years to emerge, finally becoming a reality in 2025 with the version 26 operating systems. With 1Password, Bitwarden, or Dashlane installed, you can move passkeys (and other passwords) between them and Passwords; with two or more installed, they can transfer between each other.

iCloud Keychain for synced data

iCloud relies on endpoint security with locally stored encryption keys that never leave your Mac, iPhone, or iPad. Data is encrypted in transit, and the strongly encrypted data when synced or stored in iCloud is useless without these device-based keys, which are stored in the Secure Enclave on any hardware that has one.

With two-factor authentication (2FA) enabled on your iCloud account—more or less mandatory these days—it’s effectively impossible for someone in most circumstances to gain access to your synced and stored Passwords entries. They would need all three of the following:

  • Your iCloud password
  • Either, with standard code-based 2FA:

— Access to one of your trusted devices that they had the passcode or password for or could otherwise unlock to receive a 2FA token, or a trusted phone number (or hijack a phone number)

— The device password for one of your other Apple devices that’s already synced. When you add a new device to iCloud syncing of Passwords, Apple has you prove yourself by entering the password for an existing device in your set.

  • Or, with an Apple Account locked to hardware security keys for 2FA, access to one of the two or more hardware security keys associated with your Apple Account.

However, there’s one flaw in the above, which is covered in how thieves steal iPhone passcodes: if someone can obtain your iPhone and its passcode, they may be able to use the phone to trigger a reset of your Apple Account password. See how to turn on Stolen Device Protection for advice on preventing that.

Don’t worry about entering your passcode for Passwords syncing: Apple doesn’t know your passcode or store it or transmit it unencrypted. Instead, when you enable Passwords syncing on any device, part of the process bootstraps distributing a set of cryptographic elements securely to other devices. It does so by encrypting that set with the password of the device you’re using—but only the one-way encrypted form of the password is used.

On another device, if you don’t enter exactly the same password, when it’s also transformed in the same way, it won’t match the stored version, and it won’t be able to decrypt the syncing keys to add the device you’re on—and blocks a cracker who doesn’t know your other devices’ passwords, too.

A well-designed third-party manager

The system I described just above for Passwords is the same one that’s been implemented by 1Password. (I don’t recommend any other third-party password manager.)

It’s a zero-knowledge security model for syncing across the cloud, in which the parties handling data can’t actually see the secrets and have no access to keys. As you add devices to cloud syncing, you have to prove you have other devices and secrets first. This is true for both companies’ access to your data stores via their websites: all encryption happens locally in the browser; none is ever sent to the companies; and each login session requires proof of certain elevated secrets that no one can intercept.

1Password’s system syncs files blindly, with storage vaults encrypted and stored that way on 1Password’s servers. The master password for the vault is never transmitted in any way, nor are unencrypted entries.

1Password’s approach is close to Apple’s. The big difference? Apple copies all passwords to local storage and doesn’t allow web-based access to entries, even though they’re all stored with device-based encryption at iCloud.com. With 1Password, there’s no permanent local storage, but you can use a secure method for browser-based access if a native app isn’t available.

Google password encryption

If you use Google for password management—or as part of your password-management approach—I recommend upgrading to the device-based encryption option they introduced a few years ago.

Tip: You can check whether you already have it set up: you might have enabled it or been walked through it by Google already. Follow the same steps below.

Use Google Chrome (not another Chromium-based browser) for the following steps:

  1. In the top-right corner of the browser window, click the More button and choose Passwords and Autofill > Google Password Manager.
  2. Click the menu button and click Settings.
  3. If you see Set Up next to “On-device encryption,” click the link and follow the steps. If you see an open-in-new-window button, on-device encryption is already enabled.

You can avoid Google’s password system and rely on Apple’s by installing iCloud Passwords for Chrome. It’s a Chrome extension that manages the local security issues for accessing Passwords. Unlike Google’s system, it works with Chromium browsers.

You might encounter one of two situations that provide no location information—or the wrong location—for yourself (or someone you’re allowed to follow).

A router that moved house

Apple relies on a combination of satellite navigation signals, cellular tower communication, and Wi-Fi positioning to estimate the location of a given device. That’s not always the correct location when a Wi-Fi router you’re near has been moved from its previous location.

Apple continuously grabs information about the strength and publicly broadcast information of any Wi-Fi router from all its devices that have internet connectivity and from its Apple Maps capture vehicles as they drive around the world. (Some countries prohibit some or all of this information gathering.)

But there’s a scenario in which a relocated router retains its old location in Apple’s database, because every device near it connects to the router over Wi-Fi.

This happened to a friend’s mother who lives in a rural location. A router belonging to one of her kids was moved to her house and suddenly her iPhone said she was at the router’s old home.

Let’s say the router is in Utah and a person moves to rural Kentucky, far enough away from a road that their Wi-Fi router isn’t picked up in a short enough period by people or vehicles passing by.

Whenever the router’s owner connects to the internet, their cellular equipped devices default to Wi-Fi if they’re within range; this also means they don’t capture GPS or cellular tower information to update the location, which is instead derived from the most powerful Wi-Fi signal nearby.

Apple doesn’t offer any direct way to report a moved router, but there’s a way you can try to push this into their database:

  1. With Wi-Fi enabled on a cellular device, open Apple Maps.
  2. With a blue dot showing your current location in the wrong place, swipe down and tap Report an Issue.
  3. Tap Report Street Issue.
  4. Move the dot to your correct current location. Tap “Something else.”
  5. Type a comment that explains your Wi-Fi router has moved.
    • For extra points, find the BSSID (unique hardware ID) of your router and enter that, too. Hold down the Option key on a Mac while selecting the Wi-Fi menu and the router’s BSSID appears in a list of technical details.
  6. Click Send.

You can also disable Wi-Fi on a cellular device near the router for periods of time, allowing it to upload sufficient new locations about the router that Apple’s Wi-Fi positioning database updates.

No location at all

Sometimes Find My simply breaks: location isn’t provided even with all the right switches flipped. Everything will appear set up correctly on devices, and disabling and re-enabling the service doesn’t fix the problem. The only solution I’ve found is backing up an iPhone or iPad, erasing it, and performing a restore.

The People view lists everyone with whom you share your location, whom you follow, or both. The list reveals basic information, such as their current location (address or name), how far away they are, and the last update received.

With no one selected, the portion of the view with the map plots everyone you follow for whom a current location is known. This view zooms the map to show them all if they are in reasonably close proximity to one another. People are identified with their avatar.

Apple used to zoom the map in tightly, so I could see everyone near me in Seattle. However, in some update I missed, the zoom factor now encompasses my entire region. For me, that means I see my father in Port Townsend, about 56 miles away as the crow drives.

However, if your people aren’t within some reasonable distance of one another—say one of your children is in Europe, and you live as I do in Seattle—you only see the people nearest you. Apple doesn’t define this distance, but it seems to be within a few hundred miles.

You can also tap or click someone’s image or initials in the map view, and Find My zooms in to their surroundings just as if you had tapped or clicked their entry in the People list. In the version 27 releases, tapping or clicking on a zoomed-in, selected person in the map deselects them and zooms back out.

How exact the position is

Find My indicates its confidence about someone’s location by varying the diameter of the area around their profile image and the color—either blue or green. With a translucent blue circle centered on the person, the confidence could be described as high (within a few feet or a meter), medium (within about 100 feet or 30 meters), or low (about several city blocks). When the location is very precise and the person isn’t moving, you may see no blue circle—a pulsating green one appears instead.

If a person can’t be plotted that precisely, the circle of confidence can be quite large, and Find My calls out the lack of exact knowledge.

If someone is off the grid and has updated their location via satellite, you can see their location in Find My for iPhone: it appears as a tiny satellite icon next to their photo, and Satellite Location appears in the text on the sheet of actions. See how to send your location by satellite.

If you’re within about 150 to 200 feet (roughly 50 to 60 meters) of someone else who has shared their location with you and you both have an iPhone 15 series or later model, you can use Precision Finding, which gives precise directions. See how to use Precision Finding — the feature first appeared in AirTags. (This person-to-person finding relies on the UWB chip introduced in that series.)

When you use Precision Finding to locate someone else, they’re notified you’re looking for them and can likewise enable the feature (or start a game of cat and mouse).

Select a person and reveal their sheet for more ways to interact with their location or presence. You can click or tap Contact to view their contact card. You can also add them to Favorites, which sorts them to the top of the list.

Give a place your own name

You might notice an option called Location Label (the version 27 releases), Label Current Location, or Edit Location Name. This lets you assign custom labels to frequent locations—or any location—so that it appears more comprehensible when presented in a list. By default, Apple shows the best label it has, like the closest address or a building, park, or other geographical name.

You can choose to label a location your home, work, school, or gym, or add a custom label to make it more meaningful to you. For a friend I mutually follow, I’ve given his home a nickname rather than its address. These location labels appear in People, Devices, and Items.

Find someone from Messages

In the Messages app on an iPhone, iPad, or Mac, if someone has shared their location with you and their current location is known, a broad approximation appears below their profile photo, like the city and state in the United States. You can drill down further to see an inset map and bring up a larger one:

  • On an iPhone or iPad, tap the avatar in a conversation entry.
  • On a Mac, select a conversation entry and click the avatar (Tahoe or later) or the Info button in the upper-right corner (Sequoia and earlier).

Tap or click the inset map to reveal a larger one while remaining in Messages. Tap or click Open in Find My to switch to that app with the selected person. (In Sequoia or earlier, you can’t jump to Find My.)

If someone has remained at a location, the inset map shows the street name, city, and state in the United States; the larger map in Messages shows a more precise address, if available, like 5404 Ravenna Blvd NE, Seattle, WA 98115. (Not a real address!) If they’re in transit, the inset map shows more concise information, while the larger map provides more detail, such as the district or neighborhood they’re in.

In addition to the map, Messages overlays a link to get directions, showing car, transit, or walking time if close enough. A Stop Sharing My Location link appears below the map on the info pane. (See how to play a sound on a lost device or AirTag.)