Got a tip for us?

macOS

The topic of passwords is huge. The key security aspect is narrower: how you secure them.

Apple devices can store and sync passwords in many ways, each with a different risk profile. What follows is how Apple and third-party apps store passwords, and the gold standard for syncing them among devices without increasing the likelihood they could be accessed—even by the company storing them for you.

Apple added passkeys in 2022, a more secure method of logging into a website without leaking secrets and while offering phishing resistance. You use them in lieu of a password plus a second factor, as they combine the same functions. Apple has integrated passkeys into their overall password-management and fill-in approach.

Starting in Sonoma and iOS 17/iPadOS 17, you can also create sharing groups with other people that include both passwords and passkeys. This solves an issue where you may share account access with family members or colleagues but still want the security of a passkey. (This is managed through the Passwords app.)

Apple lets you log in with a passkey to your account on their Apple Account website. This was added to let you log in securely when you weren’t able to use either Touch ID/Face ID or two-factor authentication. For instance, if you’re using a browser on someone else’s Mac and don’t want to enter the password, or you’re connecting via a Google browser on an Android phone.

Apple’s Passwords app can generate a verification code required for login with many two-factor authentication systems and store it as part of a website password entry. Not Apple’s, of course, just all the others.

Hardware security keys

In early 2023, Apple also added direct support for Apple Account logins on devices and their Apple Account website using a standard closely related to passkeys that stores unique login information on a removable hardware security key. These hardware security keys incorporate industry standards, making them compatible across mobile devices and desktop computers, as well as working with websites and native support built into operating systems.

Hardware security keys have to be activated, whether you’re using them with your Apple Account or on a website (Apple’s or anyone’s). On your Mac, iPhone, or iPad, you insert a key into a port (USB Type A, USB-C, or Lightning) or, with an iPhone or iPad, bring a key with NFC near your device. You then press a trigger on the key to start the interaction.

Hardware security keys are obviously physical items you need to exercise distinct precautions around. Their contents are one-way vaults, much like the Secure Enclave in Apple hardware, and can’t be backed up. Make sure you have safeguards in place to avoid losing or damaging them, and to ensure they’re not stolen. Treat them like a stack of $100 bills.

Apple requires two hardware security keys to enroll in that method for your Apple Account, for just that reason. If one is broken or lost, hey, you have a second. You can enroll more than two.

Where your secrets reside

Starting with iOS 18, iPadOS 18, and macOS 15 Sequoia, Apple made the Passwords app the primary built-in interface for accessing secrets, whether website logins or app passwords. Previously, Apple had a Settings section for Passwords in iOS and iPadOS, and a Passwords tab in Safari for macOS.

Even earlier, Apple steered you to Keychain Access, a utility that still exists, and which provides lower-level access to all manner of passwords, codes, secrets, and certificates managed on your Mac. See how the Mac keychain works. There’s no iOS/iPadOS equivalent.

On an iPhone, iPad, or Mac, you can enable Passwords via iCloud settings, which syncs all your app-based passwords and website logins across all the devices you own that are also logged in to the same iCloud account and have Passwords sync enabled.

Go to System Settings/Settings > Account Name > iCloud and choose Passwords or Passwords and Keychain. Enable “Sync this Device type.”

iOS and iPad app passwords use a mapping that associates them with a website, which can cause problems when you signed up in an app or at a website and then try to log in at the other entry point. The website address might not match the one provided by the app, or the app might not incorporate the right website domain. For instance, the website might use login.example.com while the app points to api.example.com.

You have two options to work around this when it happens. First, you can tap or click Passwords, then search for the domain, app, or site, and select the password entry. You’ll be warned about filling in the password. The better path is to open Passwords, find the entry, select it, tap or click Edit, tap or click Websites, then enter variants on the domain.

Browsers other than Safari have their own password storage systems for local storage and syncing. For example, Google Chrome can sync across all your apps linked to the same Google account and makes passwords available through a web-based password manager, which I have more to say about below. (Apple lets you use iCloud Passwords synced items with Chrome by installing an extension, described later.)

Third-party password managers are a boon for people who work across ecosystems or have more nuanced needs to share passwords and other kinds of data securely. Some offer Android, Windows, and Apple apps, plus browser-based access, and let you set up multiple shared secure vaults or storage areas with different sets of people. These third-party systems also have native plugins for Safari and other browsers.

How your secrets are secured

It’s important to know how password vaults manage the encryption and security of your data, but it can also be a bottomless well of detail. In the following entries, I explain, from a top-level view, how Apple manages these aspects for the Apple Keychain and for Passwords synced via iCloud, how other well-designed password managers do the same, and Google’s shortcomings in that regard.

Local passwords and passkeys

On an iPhone, iPad, or Mac, passwords and passkeys are stored in a system keychain. This is invisible to iPhone and iPad users, but you can view that secure information on a Mac via the Keychain Access app. When you enter your account password or device passcode, the keychain is unlocked for use across the device, though Apple requires biometric or password/passcode authentication to apply passwords for most logins even after that.

When you launch Keychain Access, Apple shows a dialog that says, “Manage Your Passwords in the new Passwords App.” You can then click Open Passwords (highlighted in blue) or Open Keychain Access. If you never want to be prompted again, check “Do not show this message again.”

Passkeys are stored in the keychain, but you can’t view their contents—only that you created them—because they’re based on long sequences of digits that form encryption keys meant to be kept strictly private; even displaying them reduces your security. A Mac makes a passkey available when required to log in to a website. Other browsers and apps that incorporate webpage views can also tap into Apple’s system framework to securely use passkeys.

In the Passwords app, you can view passkeys in their own category, although the entry also includes the login information used when you enrolled, such as username and password.

If you have a website login with a password, initially set up with two-factor code-based verification and then transitioned to a passkey, all those elements appear in a single Passwords manager entry.

You’ll also notice that, if you use Google Chrome in Sonoma or later, the browser opens its own compatible passkey validation system for Google account logins.

Keychain data on its own never leaves your machine, and when backed up, the associated files are encrypted. Locally stored keychain entries are backed up by full-disk encryption on all Apple silicon Macs. Your device passwords and passcodes are the only real weak points.

Apple and the rest of the industry agreed on a standard for passkeys, and also agreed to make passkeys securely exchangeable among ecosystems. Well, the first part was true first; the second took years to emerge, finally becoming a reality in 2025 with the version 26 operating systems. With 1Password, Bitwarden, or Dashlane installed, you can move passkeys (and other passwords) between them and Passwords; with two or more installed, they can transfer between each other.

iCloud Keychain for synced data

iCloud relies on endpoint security with locally stored encryption keys that never leave your Mac, iPhone, or iPad. Data is encrypted in transit, and the strongly encrypted data when synced or stored in iCloud is useless without these device-based keys, which are stored in the Secure Enclave on any hardware that has one.

With two-factor authentication (2FA) enabled on your iCloud account—more or less mandatory these days—it’s effectively impossible for someone in most circumstances to gain access to your synced and stored Passwords entries. They would need all three of the following:

  • Your iCloud password
  • Either, with standard code-based 2FA:

— Access to one of your trusted devices that they had the passcode or password for or could otherwise unlock to receive a 2FA token, or a trusted phone number (or hijack a phone number)

— The device password for one of your other Apple devices that’s already synced. When you add a new device to iCloud syncing of Passwords, Apple has you prove yourself by entering the password for an existing device in your set.

  • Or, with an Apple Account locked to hardware security keys for 2FA, access to one of the two or more hardware security keys associated with your Apple Account.

However, there’s one flaw in the above, which is covered in how thieves steal iPhone passcodes: if someone can obtain your iPhone and its passcode, they may be able to use the phone to trigger a reset of your Apple Account password. See how to turn on Stolen Device Protection for advice on preventing that.

Don’t worry about entering your passcode for Passwords syncing: Apple doesn’t know your passcode or store it or transmit it unencrypted. Instead, when you enable Passwords syncing on any device, part of the process bootstraps distributing a set of cryptographic elements securely to other devices. It does so by encrypting that set with the password of the device you’re using—but only the one-way encrypted form of the password is used.

On another device, if you don’t enter exactly the same password, when it’s also transformed in the same way, it won’t match the stored version, and it won’t be able to decrypt the syncing keys to add the device you’re on—and blocks a cracker who doesn’t know your other devices’ passwords, too.

A well-designed third-party manager

The system I described just above for Passwords is the same one that’s been implemented by 1Password. (I don’t recommend any other third-party password manager.)

It’s a zero-knowledge security model for syncing across the cloud, in which the parties handling data can’t actually see the secrets and have no access to keys. As you add devices to cloud syncing, you have to prove you have other devices and secrets first. This is true for both companies’ access to your data stores via their websites: all encryption happens locally in the browser; none is ever sent to the companies; and each login session requires proof of certain elevated secrets that no one can intercept.

1Password’s system syncs files blindly, with storage vaults encrypted and stored that way on 1Password’s servers. The master password for the vault is never transmitted in any way, nor are unencrypted entries.

1Password’s approach is close to Apple’s. The big difference? Apple copies all passwords to local storage and doesn’t allow web-based access to entries, even though they’re all stored with device-based encryption at iCloud.com. With 1Password, there’s no permanent local storage, but you can use a secure method for browser-based access if a native app isn’t available.

Google password encryption

If you use Google for password management—or as part of your password-management approach—I recommend upgrading to the device-based encryption option they introduced a few years ago.

Tip: You can check whether you already have it set up: you might have enabled it or been walked through it by Google already. Follow the same steps below.

Use Google Chrome (not another Chromium-based browser) for the following steps:

  1. In the top-right corner of the browser window, click the More button and choose Passwords and Autofill > Google Password Manager.
  2. Click the menu button and click Settings.
  3. If you see Set Up next to “On-device encryption,” click the link and follow the steps. If you see an open-in-new-window button, on-device encryption is already enabled.

You can avoid Google’s password system and rely on Apple’s by installing iCloud Passwords for Chrome. It’s a Chrome extension that manages the local security issues for accessing Passwords. Unlike Google’s system, it works with Chromium browsers.

You might encounter one of two situations that provide no location information—or the wrong location—for yourself (or someone you’re allowed to follow).

A router that moved house

Apple relies on a combination of satellite navigation signals, cellular tower communication, and Wi-Fi positioning to estimate the location of a given device. That’s not always the correct location when a Wi-Fi router you’re near has been moved from its previous location.

Apple continuously grabs information about the strength and publicly broadcast information of any Wi-Fi router from all its devices that have internet connectivity and from its Apple Maps capture vehicles as they drive around the world. (Some countries prohibit some or all of this information gathering.)

But there’s a scenario in which a relocated router retains its old location in Apple’s database, because every device near it connects to the router over Wi-Fi.

This happened to a friend’s mother who lives in a rural location. A router belonging to one of her kids was moved to her house and suddenly her iPhone said she was at the router’s old home.

Let’s say the router is in Utah and a person moves to rural Kentucky, far enough away from a road that their Wi-Fi router isn’t picked up in a short enough period by people or vehicles passing by.

Whenever the router’s owner connects to the internet, their cellular equipped devices default to Wi-Fi if they’re within range; this also means they don’t capture GPS or cellular tower information to update the location, which is instead derived from the most powerful Wi-Fi signal nearby.

Apple doesn’t offer any direct way to report a moved router, but there’s a way you can try to push this into their database:

  1. With Wi-Fi enabled on a cellular device, open Apple Maps.
  2. With a blue dot showing your current location in the wrong place, swipe down and tap Report an Issue.
  3. Tap Report Street Issue.
  4. Move the dot to your correct current location. Tap “Something else.”
  5. Type a comment that explains your Wi-Fi router has moved.
    • For extra points, find the BSSID (unique hardware ID) of your router and enter that, too. Hold down the Option key on a Mac while selecting the Wi-Fi menu and the router’s BSSID appears in a list of technical details.
  6. Click Send.

You can also disable Wi-Fi on a cellular device near the router for periods of time, allowing it to upload sufficient new locations about the router that Apple’s Wi-Fi positioning database updates.

No location at all

Sometimes Find My simply breaks: location isn’t provided even with all the right switches flipped. Everything will appear set up correctly on devices, and disabling and re-enabling the service doesn’t fix the problem. The only solution I’ve found is backing up an iPhone or iPad, erasing it, and performing a restore.

The People view lists everyone with whom you share your location, whom you follow, or both. The list reveals basic information, such as their current location (address or name), how far away they are, and the last update received.

With no one selected, the portion of the view with the map plots everyone you follow for whom a current location is known. This view zooms the map to show them all if they are in reasonably close proximity to one another. People are identified with their avatar.

Apple used to zoom the map in tightly, so I could see everyone near me in Seattle. However, in some update I missed, the zoom factor now encompasses my entire region. For me, that means I see my father in Port Townsend, about 56 miles away as the crow drives.

However, if your people aren’t within some reasonable distance of one another—say one of your children is in Europe, and you live as I do in Seattle—you only see the people nearest you. Apple doesn’t define this distance, but it seems to be within a few hundred miles.

You can also tap or click someone’s image or initials in the map view, and Find My zooms in to their surroundings just as if you had tapped or clicked their entry in the People list. In the version 27 releases, tapping or clicking on a zoomed-in, selected person in the map deselects them and zooms back out.

How exact the position is

Find My indicates its confidence about someone’s location by varying the diameter of the area around their profile image and the color—either blue or green. With a translucent blue circle centered on the person, the confidence could be described as high (within a few feet or a meter), medium (within about 100 feet or 30 meters), or low (about several city blocks). When the location is very precise and the person isn’t moving, you may see no blue circle—a pulsating green one appears instead.

If a person can’t be plotted that precisely, the circle of confidence can be quite large, and Find My calls out the lack of exact knowledge.

If someone is off the grid and has updated their location via satellite, you can see their location in Find My for iPhone: it appears as a tiny satellite icon next to their photo, and Satellite Location appears in the text on the sheet of actions. See how to send your location by satellite.

If you’re within about 150 to 200 feet (roughly 50 to 60 meters) of someone else who has shared their location with you and you both have an iPhone 15 series or later model, you can use Precision Finding, which gives precise directions. See how to use Precision Finding — the feature first appeared in AirTags. (This person-to-person finding relies on the UWB chip introduced in that series.)

When you use Precision Finding to locate someone else, they’re notified you’re looking for them and can likewise enable the feature (or start a game of cat and mouse).

Select a person and reveal their sheet for more ways to interact with their location or presence. You can click or tap Contact to view their contact card. You can also add them to Favorites, which sorts them to the top of the list.

Give a place your own name

You might notice an option called Location Label (the version 27 releases), Label Current Location, or Edit Location Name. This lets you assign custom labels to frequent locations—or any location—so that it appears more comprehensible when presented in a list. By default, Apple shows the best label it has, like the closest address or a building, park, or other geographical name.

You can choose to label a location your home, work, school, or gym, or add a custom label to make it more meaningful to you. For a friend I mutually follow, I’ve given his home a nickname rather than its address. These location labels appear in People, Devices, and Items.

Find someone from Messages

In the Messages app on an iPhone, iPad, or Mac, if someone has shared their location with you and their current location is known, a broad approximation appears below their profile photo, like the city and state in the United States. You can drill down further to see an inset map and bring up a larger one:

  • On an iPhone or iPad, tap the avatar in a conversation entry.
  • On a Mac, select a conversation entry and click the avatar (Tahoe or later) or the Info button in the upper-right corner (Sequoia and earlier).

Tap or click the inset map to reveal a larger one while remaining in Messages. Tap or click Open in Find My to switch to that app with the selected person. (In Sequoia or earlier, you can’t jump to Find My.)

If someone has remained at a location, the inset map shows the street name, city, and state in the United States; the larger map in Messages shows a more precise address, if available, like 5404 Ravenna Blvd NE, Seattle, WA 98115. (Not a real address!) If they’re in transit, the inset map shows more concise information, while the larger map provides more detail, such as the district or neighborhood they’re in.

In addition to the map, Messages overlays a link to get directions, showing car, transit, or walking time if close enough. A Stop Sharing My Location link appears below the map on the info pane. (See how to play a sound on a lost device or AirTag.)

Apple’s iCloud Drive is integrated into macOS, iOS, and iPadOS, and lets you use your free or paid iCloud space to store and share files.

A shared folder requires an Apple Account to access, and the contents are all accessible to whomever is invited or has the link, depending on the permissions you set. Up to 100 people can be invited to a folder. Only folders you create can be shared—not ones that Apple manages or that are created for apps. Storage space is occupied only in the sharing party’s iCloud account, which makes it handy if other people don’t have large iCloud storage subscriptions.

iCloud Drive appears in macOS by default as an item in the Finder window sidebar. You can select it there, or you can choose Go > iCloud Drive or press ⌘-Shift-I. On an iPhone or iPad, use the Files app.

With Advanced Data Protection enabled, iCloud data is secured end-to-end among your devices. It’s also E2EE secured with devices of anyone with whom you share if you all have ADP enabled.

Share a file or folder in iCloud Drive

  1. Select the items to share. On a Mac, Control-click or right-click any file or folder stored in iCloud Drive, or select several and Control-click one of them, then choose Share from the contextual menu. On an iPhone or iPad, touch and hold a file or folder and choose Share; or tap the More button, choose Select, tap the button beside each item, and tap the Share button.
  2. A share popover appears. Choose Send Copy or Share a Link from its pop-up menu. Send Copy sends a download link and has no further options. Apple renamed several of these labels in iOS 27, iPadOS 27 and macOS 27 Golden Gate; the functions are unchanged, and earlier releases call this Collaborate.
  3. If you choose Share a Link, set the permissions by clicking or tapping the text below that label:
    • Under Who Can Access, choose “People you choose” to limit access, or “Anyone with the link” to open it up. Earlier releases call the first option “Only invited people”.
    • From Permissions, choose “Can edit” for read and write access, or “Can view or download” for read-only. Earlier releases call these “Can make changes” and “View only”.
    • Enable or disable “Allow access requests”, called “Allow others to invite” in earlier releases.
  4. Select people or groups from recent interactions in Messages and elsewhere, or click one of the options, like Mail or AirDrop, to share the link.
  5. Complete the process in the dialog, sheet, or app prompt that appears. If you copy a link in the 27 releases, you are warned that sharing with a group means approving access for each member; you can proceed, or choose Allow Anyone with the Link instead.

Once shared, the item is marked in the Finder or the Files app:

  • In macOS, you can opt to show a Shared By column in the Finder. It may be enabled in some iCloud Drive views. If not, and you want to turn it on, choose View > Show View Options and check Shared By. With that column active, you see Me for you or the name of the sharing party for files or folders shared by others. All files that aren’t shared show Not Shared, which feels like overkill.
  • In macOS with the Shared By column disabled and in iOS/iPadOS, you see a label next to a file in the Finder or next to or beneath it in the Files app that reads Shared by Me if just a link is used or an invitation hasn’t yet been opened. The label displays With Person or People when an invitation is accepted. The last person to modify may appear instead, such as Modified by Dave Johnson.

To make changes, the easiest way to access these shared items is via the Shared view. On an iPhone or iPad, tap the Shared button in Files; on a Mac, choose Go > Shared in the Finder (⌘-Shift-S). Select the items as above either in the Shared view or by choosing the same set of original items. Touch and hold on an iPhone or iPad or Control-click/right-click to reveal the Manage Shared Folder item.

Choose Manage Shared Folder to reveal a dialog that shows the sharing details. You can see with whom the item is shared, and you can remove and add members (if you have permission), change permissions, or change invitation parameters. If and when you’re ready to stop sharing, click or tap Stop Sharing.

iCloud.com allows similar options for sharing files, although the sequence is a little different and options are far more limited:

  1. Log in to iCloud.com and click iCloud Drive.
  2. Select a single file or folder and then click the Share File or Folder button. Email and Copy Link destinations are available.
  3. Click Share Options to access permissions that are identical with those found on an iPhone, iPad, or Mac.
  4. When you’ve made your choices, click Share.

Dropbox

Dropbox is an exceedingly popular service for simple syncing across devices that offers several different ways to share files with strong controls on access. It has integrated macOS support, as well as full-featured apps for iOS/iPadOS and other major platforms, and a sophisticated web app.

On a Mac, Dropbox uses Apple’s framework for cloud-storage providers to add icons to the right of files and folders in the Finder in its folder. The Dropbox folder is the only one that’s synced, and it’s located by default in your home folder. Files and folders may be online only or online and stored locally.

Some features require a paid Dropbox subscription.

Control-click or right-click a single file or folder inside the Dropbox folder on a Mac or tap the More button to the right of a file or folder in the Dropbox app for iPhone/iPad. You can now access several options by choosing:

  • Share: This opens a dialog or sheet with extensive options to let people have access to a file or folder. You can invite people, create publicly available or password-protected links for sharing, and set an end-date for access. Use this option for sharing items that you want people to have ongoing access to, particularly for folders that you might optionally want to let people drop items into or modify. (Shared folders count against other people’s Dropbox storage limits.)
  • Transfer a Copy: Dropbox lets you send files without providing any access to your Dropbox space. The transfer can be password protected and have an expiration date. On a Mac, you use the contextual menu; in the iPhone/iPad app, you start in the files view and tap the plus button, then select files to transfer.
  • Copy Dropbox Link: Choosing this on a Mac (or via the Share > Copy link pathway on an iPhone/iPad) creates a public link that anyone who has it can use to download the particular item. For certain kinds of files, like images and PDFs, the link allows viewing inline on a website, too.

Google Drive and OneDrive

Two other major firms’ apps don’t offer file-level Finder integration, but can sync files automatically and provide Mac access via a web app. Both also have iPhone/iPad apps.

The advantage of both is that you might already have paid for storage:

  • Google Drive: Google Drive provides access to the 15 GB of free storage available for all Google individual accounts or to the larger pool of paid Google One tiers that start at 100 GB for $19.99 per year. Business accounts include a higher starting storage allocation. Google allows public and invitation-based links with varying permission, but doesn’t offer setting an expiration date.
  • Microsoft OneDrive with Microsoft 365: Anyone can get 5 GB of file storage (plus 15 GB of email storage) in Microsoft OneDrive by setting up a free Microsoft 365 account. For $1.99 a month or $19.99 a year, you can upgrade to Microsoft 365 Basic with 100 GB each for files and email. At $9.99 a month or $99.99 a year (one person) or $12.99 a month or $12.99 a year (up to six people in a family), Microsoft 365 Personal offers 1 TB of file storage and 100 GB of email per person. The Personal plan also adds access to desktop Microsoft apps. OneDrive’s sharing options are comparable to those of Dropbox, with options for sending invitations, creating a public link, and setting an expiration date for the link.

Find My comes in three flavors:

  • Device-based, two-way short-range and internet: This version is the original and better understood, and can be enabled on devices: an iPhone, iPad, or Mac, and, by extension, an Apple Watch paired with an iPhone. The device actively sends its location over the internet whenever the internet is available. Find My Device allows the owner of a device to send remote events, like playing a sound or triggering erasure, to a device. Apple and Beats audio devices near their paired device act like this as well.
  • Find My notification network: The Find My network is a one-way notification system that relays location via other people’s internet-connected devices. It can be enabled on an iPhone, iPad, or Mac, and is an inherent attribute of “items”: AirTags and third-party Find My products. Audio devices like AirPods Pro, AirPods Max, and several models of Beats earbuds and headphones act like Find My items when away from their paired device. An owner can’t send commands via the Find My network.

The AirTag, some audio devices, and other items can receive a command to play a sound via Bluetooth from a nearby device. This allows either an owner or someone whose device has been relaying Find My network location data to play a sound on an AirTag.

  • Device-based, Bluetooth range: For Apple AirPods, you can track location only when they’re near their paired iPhone or iPad. They use Bluetooth and don’t participate in the broader Find My network, but their current or last-known location appears in the Devices view in Find My (and the Apple Watch Find Devices app in watchOS 26 or earlier). An owner can trigger a sound when they are near these audio devices.

Because devices can connect to either the two-way or notification network, the other way to look at it is this way:

  • Devices can use both networks: An owner of a device can perform a remote action whenever it’s connected to the internet (or its paired device is and is nearby, with audio hardware), but can see its location when it’s picked up via either form of Find My.
  • Items can use only the Find My network: Items can only ever report their location.

Turn on Find My for a device

Local- and internet-based Find My on an iPhone, iPad, or Mac requires an active Apple Account associated with iCloud. You likely already set up Find My when upgrading or setting up your device.

To enable Find My on an iPhone, iPad, or Mac, if you haven’t signed in with an Apple Account yet, go to System Settings/Settings > Account Name > iCloud and enter your credentials.

On an iPhone or iPad, tap Settings > Account Name > Find My to view and make changes in settings; these settings also affect any paired Apple Watch. On a Mac, go to System Settings > iCloud > Show All. If Find My isn’t enabled, turn it on. Once Find My is active, you can tap or click the Find My item to access additional settings, like the Find My network or, on an iPhone/iPad, Send Last Location.

Enabled devices are automatically added to your iCloud account’s list of devices. For supported devices, Apple enables Activation Lock.

Turn on the Find My network

Find My network tracking has distinctly different options depending on whether you’re enabling it on devices or using it with items. Here’s the breakdown for those categories.

Apple enables the Find My network on iPhone, iPad, and Mac by default. Any Apple Watch, AirPods (3rd generation), AirPods 4 with Active Noise Cancellation, AirPods Pro or Max, or supported Beats audio device paired with an iPhone is similarly tracked. You can toggle this setting as follows:

  • iPhone (plus Apple Watch)/iPad: Change the Find My network option in Settings > Account Name > Find My > Find My iPhone/iPad.
  • Mac: Go to System Settings > Account Name > iCloud, click Show More Apps, and click Find My Mac.

Disabling the Find My network also removes your device’s participation in finding other people’s lost items.

There’s one hidden requirement that Apple doesn’t document, because it’s implicit; the company has spoken about it publicly. Because finding devices over the Find My network requires the use of encryption secrets stored only on devices, you have to have two devices enabled on the network in order for one to find the other. That way, they exchange the necessary secrets using Apple’s privacy-preserving framework without Apple possessing any of your encryption keys. (This is quite similar to how iCloud Keychain works.)

In other words, if you have a single device that’s lost and it can connect to the internet, you’re using the two-way Find My system. A single lost device that can’t connect to the internet also cannot use the Find My network to find it, because there’s no other trusted device that can query Apple for the secret Find My network details. You can’t use iCloud.com for crowdsourced device location, as iCloud.com doesn’t store the Find My network secrets, much as it doesn’t store iCloud Keychain password entries and other secrets.

This requirement isn’t in place with items, because you can already discover the location of items that aren’t nearby only by using the Find My network from a device.

Powering off no longer hides a phone

When an iPhone series 11 or later model is in the extremely low-power “power reserve mode” or “powered off,” as long as your device has any battery power available (or is plugged in), it will continue to send Bluetooth beacons for location discovery if the Find My network setting is turned on as described above; you can also disable the network temporarily, as described next.

In this power reserve mode, you should be able to use Express Mode for transit system payment even if your iPhone (or Apple Watch) can’t do anything else.

Powering down a device offers up a warning in small type that highlights this change. Tap the warning to get the full details. You can tap Temporarily Turn Off Finding, enter your device passcode, and then power down; on the next power up, Find My is reactivated.

Items are always on

AirTags are designed to work both via short-range networking directly with a paired iPhone or iPad and through the crowdsourced system. When you set up an AirTag, it’s enabled for use on the Find My network, as described in how to set up an AirTag.

Third-party Find My network items have a slightly different pairing process, but remain active at all times, too; see how third-party Find My trackers differ.

Apple and Beats audio devices appear under the Devices view in the Find My or Find Devices app because they report their location via a paired device when in range (which is almost certainly often). When not in range, they rely on the Find My network. AirPods can only be tracked via the paired device, while all the other Apple and Beats hardware can use the Find My network. (I guess Apple didn’t want to confuse audio device owners by classifying these higher-end devices with single-function trackers.)

You can reset a Find My item, remove its battery, or use a special disable sequence to stop it sending out a stream of location data. See how to reset or disable an AirTag.

You might wonder why anti-malware software is not on the list of things to install on a Mac. After decades of using anti-malware software, some of it quite sophisticated, I don’t think any package’s benefits outweigh the cost in terms of price, false positives, and system load.

Anti-malware software has a distinct weakness: it can’t protect against unknown threats. It’s 100% designed to keep out-of-date systems protected from well-known viruses and the like, and to safeguard an up-to-date system as quickly as possible from malware that has just been discovered and characterized. If you keep your Mac up to date and never install software of any kind from the internet (besides the App Store) or software handed to you by other people, you can probably forgo anti-malware software, as it has no real path to find you.

For everyone else, it’s worth considering. While a portcullis doesn’t protect a castle when it’s open, cutting the rope and dropping it is an effective way to keep hordes from rampaging through that front door. Likewise, automatic updates and scanning are terrific ways to ensure you aren’t caught out by a prior or current exploit.

What antivirus software cannot catch

You’d think with all the AI in the world and decades of research about viruses, there should be a way to detect malicious behavior and shut it down. And yet that’s still largely a dream, with one exception for ransomware that I describe below.

Instead, anti-malware software’s virus-protection portion largely relies on the same technology it has for decades. A hash is made of a malicious payload—in just the same way that Apple creates a cryptographic summary of legitimate software—and stored in a list. When the anti-malware app scans a drive for bad actors, it generates a signature of each item it finds and compares it against its stored list, which is frequently updated.

The best current anti-malware software helps you with five distinct issues:

  • Known malware: Blocking already known and extant malware, including routinely scanning files on your Mac, volumes you mount on your Mac, and attachments that arrive via email
  • Phishing websites: Blocking phishing websites and those that host links to malicious software, either loaded in the browser or as downloads
  • Behavior alerts: Identifying dubious behavior that might be fine, but you should review to be sure, such as opening a file or accessing a folder in an unexpected location

macOS requires you to grant permission the first time an app attempts to access files in certain locations, which is a coarse but useful version of this. See how to control which apps use your Mac camera and files.

  • Ransomware: Blocking ransomware activities based on the way that ransomware functions, discussed below
  • Windows malware: Preventing you from passing Windows viruses on to someone else

Ransomware is the exception

Ransomware is the odd one out in this whole discussion. While being the biggest likely threat to Mac users, it’s also by far the easiest to track. Ransomware operates by suddenly creating a mass of new, encrypted files and deleting ones with similar names. It’s rarely sophisticated; it just has to be launched by a user or through some method that lets it insert itself and run.

Some anti-malware software can detect this broad category of behavior because it’s so specific, and can lock down folders and prompt your response before more than one or a handful of files are locked away.

Windows malware on a Mac

macOS can’t run malware that’s written for Windows machines, so even if a Windows virus appeared on your drive, it wouldn’t do any damage; it would simply be inert.

Mac anti-malware apps, however, do identify, quarantine, and remove Windows malware, because of the chance you might pass it on via email or as part of an infected Microsoft Office document to someone else who uses Windows.

And even though macOS isn’t Windows, you can run Windows via virtualization software like Parallels Desktop. Mac anti-malware software won’t protect you there, so you should absolutely run Windows anti-malware software within your Windows installation.

Notify When Left Behind helps with absent-mindedness, exhaustion, and theft. Using your presence, whenever you move a certain distance away from a device or item—Apple doesn’t define how far—you receive a notification on that device.

Found on the sheet for any device or item in native Find My apps, it’s enabled by default under Notifications. You can choose to disable it on a per-item basis. Apple also excludes the place you defined as Home or Apple inferred was your Home.

The device on which you would be notified is listed as part of the explanation when you tap or click Notify When Left Behind.

Your Apple Watch doesn’t alert you when something is left behind (and the Find My app explains this); instead, the alert comes only when the item is separated from your primary presence device, typically an iPhone. (See how Find My works.)

Notify When Left Behind helps in a bunch of scenarios I can imagine:

  • Forgetting you placed an iPad in the seat-back pocket on an airplane. (This is certainly a main cause of loss for iPads and Kindles.)
  • Leaving an iPhone, iPad, or Mac in a coffee shop or restaurant.
  • Forgetting your backpack that has an AirTag in its pocket at someone’s house.
  • Checking your luggage at an airport or train station for a trip.
  • Leaving items at a hotel room, hostel, Airbnb, or the like after checking in during a trip, such as in a hotel safe.
  • Not packing your laptop in a bag you’re carrying with you before leaving for school or work—or vice versa!
  • Locking up a bike that you’ve attached a Find My item to at your destination—then forgetting you biked there and taking a bus home. (Folks, if you bike regularly and you haven’t made or almost made this mistake, count yourself lucky.)

Trust a place

When you’re notified, you can tap Don’t Notify Me, and the location where your Find My item or device was left will be added as a location. If you have an Apple Watch, a notification on the watch also lets you tap Trust Location or Dismiss.

You can also suppress this notification in a Find My app on an iPhone, iPad, or Mac by selecting the item or device, which then shows where it was last seen. You can tap or click Don’t Notify Me Here.

When you add a location through this method, the operating system prompts you, “Don’t notify at map description of location?” You can then tap or click “For all Items or Devices,” “For this Item/Device,” or Cancel.

You can also manually add other locations to exclude by tapping or clicking Notify When Left Behind, then New Location. The map interface for location selection is identical to the one for People. You have the additional option when you click Done to add the location to select “For all Items and Devices” or “For this Device.”

You can accumulate a list over time of places that you don’t want to be notified about items being left behind at. For me, this has become an interesting travelogue of all the hotels, homes, and workplaces I’ve been at.

You can clean this list up by removing locations. On an iPhone, iPad, or Mac, tap or click the remove button to a location’s right. The exception is the Home location, which can be removed only on the device that establishes presence. You can view those locations on an Apple Watch, but not remove them.

It is not an anti-theft feature

Because the notification occurs only when the device remains static and you’ve left it behind, it is not an anti-theft feature. Conceivably, we need Apple to add the opposite case, too: Notify When Moves Away. Perhaps this could cause both the device that’s taken and the hardware that notifies to both squeal uncontrollably until reunited?

A bag in a hotel safe

As I was revising this edition, I received a text from a friend. After a trip out of state, he’d realized he’d forgotten to retrieve a small bag in the hotel safe. He didn’t care much about the bag—except that it contained his passport! The bag also contained an AirTag, but he wasn’t alerted that it was left behind for several hours.

He could see the AirTag in what appeared to be the parking lot. A few slightly clueless hotel front-desk people seemed helpless, although one walked out into the parking lot and said the location appeared to be a grate. Maybe a thief had thrown the AirTag down its openings? But that would mean someone had stolen it from the room safe or lost and found after he had checked out.

After a day or so, a more clued-in staffer called back: it was in the lost-and-found safe, which apparently other people hadn’t checked. For $60, the hotel used a third-party service to return the bag. And then he watched as it didn’t move for days—requiring three more calls to the hotel—before it finally landed at the airport near us. And then sat there for a day before UPS put it on a truck.

The related setting: Notify When Found

Device notifications don’t let you see when something comes or goes, but instead provide you useful feedback related to losing something or having it stolen.

Find My enhances its Lost Mode/Mark as Lost option by providing a notification option after you mark a device as lost. This notification can occur when that device is “found”—that is, when it’s back online, however briefly (see what someone sees when they find your lost device).

Notify When Found is disabled by default on the sheet of actions for a device or item in a native Find My app unless it’s been marked as lost. Then you have just the option to turn it on or off. If enabled, a notification appears on your devices in one of two cases: a piece of your equipment detects the missing item; or the device or item reports its location through Find My or the Find My network.

Disclosing your location is a two-edged sword—or maybe a multi-bladed throwing star. It can be incredibly handy to let other people know where you are for travel, safety, timing, and even accountability. However, letting others know where you are means they know where you are, which even for close friends, family, and partners can feel like too much knowledge and the expectation of you sharing your position can feel invasive. (You also may feel it’s excessive that, when you launch Find My, you can see the precise location of everyone who has shared with you, even though they did so willingly!)

Apple tries to strike a balance with location sharing just as it does with nearly all other aspects of digital privacy that they mediate and let you choose your comfort level with.

Find My is the interface through which the location you share from an iPhone, iPad, Mac, or Apple Watch gets viewed, but it’s only partly the way in which you choose what is shared! That split is left over from when Apple introduced the previous standalone app, Find My Friends, and relied on preferences buried in Settings to manage all the details.

When you share your location, the other person cannot see your devices, but only your presence: the device marked as showing where you are. Only people in a Family Sharing group can see each other’s devices, and only if the person is sharing their location with them. Items don’t pick up Family Sharing settings. You can share them with up to five people.

Location has two interrelated components: how you share your location and how you choose to accept seeing other people’s locations. Let’s start with you.

You can use the native Find My app to view and change personal settings, even if you’re part of a Family Sharing group:

  • On an iPhone/iPad, watchOS 27, and macOS 27: Go to the Find My app > Me button.
  • In macOS 26 and earlier: In the Find My app’s People view, click Me and click the Info button.
  • In watchOS 26 and earlier: In the Find People app, tap the Me entry.

Here is what appears in the My Location section on all these devices:

  • Share My Location: A single tap, and you let yourself be seen by those you’ve shared with; another tap, and you run silent—your location isn’t sent again until it’s re-enabled.
  • Sharing From: Often called presence, this defines which devices are shared in Find My as being your location as a human if you own multiple devices. My Location reads This Device if you’re on the one defining your location; otherwise, it shows the name of that device. (See how Find My works.)
  • Location Label: At the top of the Me view, you see the current inferred address. However, Find My tries to offer something more descriptive. If you’ve defined your home or work location in Contacts or Phone, it should show Home or Work as the label. You can also create your own names for other addresses; see how to see someone’s location in Find My.

Share with someone

You can share your location in more than one way, and the interface is essentially the same with slight differences.

Here’s how to share in various ways across your Apple devices, from most universal to most specific; how to set the duration option is discussed after these instructions:

  • On an iPhone or iPad, or in macOS 26 or later:

— Find My app: Click or tap the add button at the upper-right corner of the list in whatever view you’re in. Enter names or select people. Click the checkmark button. Now choose a duration.

— Messages: In any conversation in Messages, tap or click the avatar or avatars. On an iPhone or iPad, tap the Plus button, choose Location, tap Share, choose the duration (see below), and tap the Send button. On a Mac, click Share My Location, choose a duration, and press Return to send.

Tip: If your recipient or group isn’t all Apple users, you can still send an image that embeds a link to a map; instead of Send or Share, the button reads Send Pin.

  • In macOS Sequoia or earlier:

— Find My app: In the Find My app, click the People button, then click Share My Location. Enter names or select people. Click Send, and choose a duration.

— Messages: In any conversation in Messages, click the Info button in the upper-right corner. Click Share My Location and choose a duration. Press Return to send the location message.

  • On an Apple Watch:

— Find My app (watchOS 27) or Find People app (watchOS 26 or earlier): In watchOS 27 only, first tap People. Scroll to find Share My Location. Tap it to either dictate a name, choose a contact, or enter a contact’s phone number.

— Messages app: In the Messages app in watchOS 26 or later, choose a conversation, tap the add button, choose Location, tap Share, and choose a duration.

Note: When someone requests your location, as explained ahead in If You’re Asked to Reciprocate, you can’t use a single tap from an Apple Watch. You have to use one of the above methods.

Note: You can’t share your location with others or see their location in the Find Devices app on iCloud.com.

Choose how long it lasts

No matter which path, platform, or version you’re using from the above list, you’re asked to pick or set a duration: Always (formerly Indefinitely), End of Day, One Hour, or Custom. (These options are worded slightly differently across apps.) The Custom choice is new in the version 27 releases. Selecting that option lets you set a duration from 15 minutes to 30 days.

If you shared via Messages, you see a note in the conversation that says “You started sharing location with person name.” The recipient sees “Person name started sharing location with you.”

I’m guessing Apple switched in the version 27 releases to the simpler word “always” after years of using “indefinitely” because more people can easily parse “always.” Indefinitely has the ring of “inflammable” about it: does it mean forever or for a period of time? (Inflammable items are just as easy to set on fire as flammable ones.)

If you choose anything but Always/Indefinitely, a countdown clock appears when you view the details for that person’s entry in Find My: it reads “Sharing for X time units” in the version 27 releases and “X time units remaining in previous operating systems. Messages displays a map tile with an inset yellow countdown clock for the remaining time. In Apple Watch’s Find People app, the contact’s avatar is overlaid with a timer; tap the entry to see the remaining time as text.

Family Sharing is a separate switch

For greater flexibility, Apple also lets you use Family Sharing settings to enable to disable location sharing among group members. Go to Settings/System Settings > Family > Location Sharing to see family settings.

In Location Sharing, you see all the other members of your family sharing group and your current sharing status with them and theirs with you—sort of!

If you used this interface to share your location, or used the Automatically Share Location option (enabled by default) for new members, you see sharing enabled next to the group member. However, if you used the Find My app to start sharing your location, it may appear that you are not sharing with them! You’re just not “family” sharing with them! Yes, it’s as straightforward as a bent nail.

Under the Share Your Location With section, you can also see which of the group members are sharing with you. Again, this is dependent on how you shared. In the figure, you see “person name is sharing your location with you,” even though four members of my family group are sharing their locations with me. Oy!

See who can currently find you

Once you start sharing your location with other people, you might lose track of precisely who that is. Fortunately, you can see a list in a few different places:

  • Native Find My app: Use the Find My app’s People view or the Find People app on an Apple Watch (watchOS 26 or earlier). Everyone in the list who reciprocally follows you appears with location information; everyone else you share with has the label “Can see your location” beneath their name.
  • Find My settings: On an iPhone or iPad, go to Settings > Your Name > iCloud > Find My, and you can see Family (if you’re in a Family Sharing group) and Friends. This doesn’t show reciprocal sharing status, however.
  • Family settings: If you’re part of a Family Sharing group, Settings/System Settings > Family > Location Sharing reveals any group member with whom you’ve shared using Family Sharing settings. See that befuddling situation above in Share Location with Family.

Because FileVault prevents direct access to your data volume at startup, turning it on requires a backup plan. That backup plan is the FileVault Recovery Key. This key is a precious object that you should treat like the gold that it is virtually made of. If anything were to go wrong with the boot portion of your Mac’s operating system, or in the unlikely event you forget the password to your computer’s account, the only way you can decrypt the drive is using the Recovery Key. Without it and any accessible backup, its contents are truly gone for good.

This Recovery Key is entirely unrelated to the Apple Account Recovery Key, used to regain access to your online account.

When you need a Recovery Key

You should only ever need to use your Recovery Key if you attempt to log in with your macOS account password or username and password, and macOS refuses to let you proceed. In such cases, you should see text that reads Reset Password with a right-pointing arrow to its left. You can also bring up that link right away by clicking the question-mark button to the right of the password field. Follow the instructions to reset your password with the Recovery Key.

Apple has historically had two different ways it manages the Recovery Key. The first lasted for several years, through Tahoe. The second, in Tahoe and later, was optional through version 26.3. It’s mandatory starting in 26.4 and Golden Gate.

The older method is worth understanding if you set up FileVault years ago; the newer one is much safer.

How to view the key

With Tahoe, Apple made three key changes:

  • View anytime: You can view the FileVault Recovery Key at any time after it is created—it’s no longer shown just once ever.
  • No iCloud account escrow: Simple iCloud escrow is no more.
  • Recovery Key in Passwords: The FileVault Recovery Key is added to Passwords. If you have Passwords syncing enabled with iCloud, the key is synced using end-to-end encryption—not simple Apple Account access—among your devices.

If you didn’t interact with FileVault when upgrading to Tahoe or installing 26.1, 26.2, or 26.3, you will be forced in a simple process when you install 26.4 or later, or upgrade from any pre-26.4 version of macOS to Golden Gate. I recommend upgrading manually in 26.0 to 26.3, using the steps below.

In System Settings > Privacy & Security > FileVault, you can click the Show button, validate with Touch ID or a password, and display the key in full.

You can also view the key in Passwords.

In the initial iOS 26/iPadOS 26 release (or maybe the first few), the Recovery Key synced to iPhones and iPads, appearing in the Passwords app, but lacking any information except the Recovery Key label and the key itself. Apple fixed this in a later update, ensuring the information appears identically on all platforms.

Even though the Recovery Key now syncs via iCloud, you could still wind up with a problem:

  • With Passwords, if you lose access to all your devices besides your Mac, and it cannot start up using your password, you need another way to access the Recovery Key. Storing it in Passwords is not enough given the consequences of not having it.
  • If you don’t use Passwords, you must use another password manager or some other secure method to make sure you can access it if your Mac becomes unavailable.

Check an older key still works

If you set up a locally stored Recovery Key before Tahoe, you can use a Mac command-line tool to validate that the Recovery Key you have on hand is truly accurate without trying to reset an account password. In Terminal, enter sudo fdesetup validaterecovery and press Return.

At the prompt, enter your administrator password, and then paste or enter the Recovery Key. If the result is anything but true, try re-entering. If it continues to produce false or an error, it’s time to reset FileVault.

If you want to disable FileVault, rotate your Recovery Key (because it was exposed), or upgrade to the new method in Tahoe 26.0–26.3, follow these steps:

  1. Go to System Settings > Privacy & Security > FileVault and disable FileVault.
  2. Click Turn Off Encryption.
  3. Use Touch ID or enter your password, as prompted.
  4. “Decryption” may take a moment; really, it’s making a few low-level changes in the startup partition. Stop here if you simply wanted to disable FileVault; otherwise, proceed.
  5. Now, re-enable the switch. If it’s been more than a moment since you carried out step 3, you may be prompted to use Touch ID or enter your administrator password.
  6. “Encrypting” may appear for a moment as macOS rewrites the startup information. There’s no additional action you need to take.

Unlocking remotely, as a last resort

Starting in Tahoe, Apple added an option to enter a Recovery Key via SSH if Remote Login is enabled on your Mac and it’s connected to a network. This could be useful in desperate circumstances, where you’re unable to type directly on the Mac, or it’s located in a hard-to-reach location. Whatever the reason, consider enabling Remote Login if you’re concerned, as described in which Mac sharing services are safe to turn on.

What Apple changed, and why

Before Tahoe, Apple let you choose between two options:

  • Store locally: The key was generated, displayed to you, and never stored anywhere. You could never retrieve it after seeing it once.
  • Use escrow: The key was securely stored in your iCloud account.

I never liked the iCloud option much, though it was less scary than a “show once, lose forever” local key. However, iCloud escrow had three implications:

  • If you somehow lost access to your iCloud account, the key was not retrievable. (If you could still log in to your Mac, you could disable FileVault and re-enable it to generate a new key you stored locally.)
  • If someone gained access to your Apple Account credentials, they could unlock a Mac you own that they have access to by using the FileVault recovery process.
  • A government agency, rightly or wrongly, could have forced Apple legally or extrajudicially to provide this key for a device they had seized or otherwise obtained. To my knowledge, this has never occurred, but it’s possible Apple would have been constrained from revealing it in any country in which it occurred; that seems unlikely given the company’s stance on encryption and privacy.

Apple’s operating system and cloud security teams must have had thoughts like this when they revamped Recovery Key access in Tahoe.

We’re all quite rightly concerned about our private data stored on our most personal devices—the ones we carry with us all the time. Apple has done a stellar job in locking down access to an iPhone, iPad, Mac, or Apple Watch. But there’s still a fear: what if someone guesses our passcode or passphrase, or uses some new cracking technology to break in?

Apple offers an excellent option that can assuage some fears. You can remote erase your device by sending it an irreversible command that takes place immediately if it’s connected to the internet, or as soon as it’s next connected—if it ever connects again.

What happens when you erase a device in Find My?

  • A confirmation email is sent to your Apple Account email address.
  • When you erase a device remotely using Find My, Activation Lock remains on to protect it. Your Apple Account password is required to reactivate it.
  • If you erase a device that had iOS 15, iPadOS 15, or later installed, you can use Find My to locate or play a sound on the device. Otherwise, you won’t be able to locate or play a sound on it. You may still be able to locate your Mac or Apple Watch if it’s near a previously used Wi-Fi network.

Erase an iPhone or iPad

The last resort in some cases (or first in others) is a remote wipe, in which all the user data on an iPhone or iPad is erased.

An erased device that has Find My enabled before erasure and remains associated with an Apple Account cannot be unlocked without the account password due to Activation Lock.

The erase option lets you provide a phone number and message so that a person who found (or stole) your device can get in touch. The device is essentially useless to them without the password.

Once you erase a device (or if someone else has), Find My can find its location only if it’s an iPhone or iPad running iOS 15/iPadOS 15 or later. Before that release, erasing a device disables its ability to send Find My tracking data when connected to the internet.

You can remove a device from your Find My list; see how Activation Lock protects a lost or stolen device.

It’s a multi-step process to prevent accidental erasure; you can cancel at any stage until the last step:

The device will be erased immediately at the last step. If you’re using two-factor authentication, it is also removed from your trusted devices at once.

  1. Go to the Find My app 3ef46077881e8558ba33ff4dc013dbbe.
  2. Tap or click Devices at the bottom of the screen, then tap or click the name of the iPhone you want to erase.
  3. Tap or click Erase or Erase This Device.
  4. You’re warned that everything is about to be erased. Tap or click Continue.
  5. Optionally enter a phone number at which you can be reached after it’s erased, and tap or click Erase.
  6. Enter your Apple Account password and tap or click Erase. If this is another member’s device, accessible via Family Sharing, enter their Apple Account password.

If the device is online, the Erase action immediately wipes all your data. It’s fast because it throws away encryption keys that are used to secure your iPhone or iPad data—it doesn’t have to write zeros over all the data. If the device is offline, the erase begins as soon as it next comes online through any networking method.

What you actually lose

Wiping your device isn’t as bad for your stored data as it sounds. All iPhones and iPads are set by default to back up the unique data that’s stored on them, like settings, passwords, and documents created by or associated with apps. These backups can be either local to a Mac on a particular computer or remote to iCloud.

Apps are stored centrally, not in a backup, and restored from Apple’s servers; the same is true with synced books and purchased music, movies and TV programs. If you use iCloud Photos and Sync Library (for Music), that media is stored in the cloud and synced. (If you’re not using either, you probably sync music with a Mac or Windows system. This is a good time to check that you’re up to date with syncing.)

If you erase your device, and then either recover it or obtain a new device, you can restore from your most recent backup. If you were syncing any items to your device through Photos, Music, or other apps or tools on a Mac, you can then sync them back to the device. For items stored in iCloud, the restore process downloads them again.

You can accelerate restoring an iPhone or iPad with Apple’s Quick Start. Place one of your iPhones or iPads near another and follow the steps provided. This streamlines setup. In a final step, you can choose to restore from an iCloud or other backup.

If any unique data was syncing from your iPad or iPhone to iCloud, Dropbox, Exchange, or another service, you should retain changes up to the moment the device disconnected from a cellular or Wi-Fi network. You will lose only changes made on the device between the last sync (push, fetch, or manual) for each account and the remote wipe.

Erase a Mac

The process of starting is nearly the same as with a mobile device:

Macs can’t be tracked after erasure. The device will be erased immediately at the last step. Two-factor authentication will also drop it from your trusted devices.

  1. Select the device in any Find My app and reveal its sheet.
  2. Tap or click Erase This Device.
  3. Review Apple’s warning. Click Continue.
  4. Enter a message that will be displayed to someone who has or finds the machine and click Erase.
  5. Enter your Apple Account password and tap Erase. If this is another member’s device, accessible via Family Sharing, enter their Apple Account password.

The selected Mac will now be erased. How long that will take depends on hardware features. Erasure is nearly instantaneous.

Be sure you always have a current backup that you can restore from in case your Mac dies, there’s a natural or house disaster (fire, flood, collapse), you lose it, or someone breaks it or steals it.