Apple Secure Enclave

Discussions center on Apple's Secure Enclave hardware component, its role in protecting encryption keys from extraction by Apple, the OS, or authorities, and debates about its security effectiveness against backdoors or warrants.

📉 Falling 0.4x Security
3,133
Comments
19
Years Active
5
Top Authors
#4976
Topic ID

Activity Over Time

2008
1
2009
7
2010
7
2011
24
2012
46
2013
122
2014
110
2015
71
2016
607
2017
182
2018
216
2019
148
2020
262
2021
280
2022
196
2023
379
2024
237
2025
225
2026
15

Keywords

e.g CPU TL NUC apple.com MacBooks PIN BAA mikeash.com UI enclave secure apple keys pin key stored keychain password fingerprint

Sample Comments

kbolino Feb 21, 2025 View on HN

The keys are stored only in the Secure Enclave. Encryption and decryption are handled outside the standard CPU and OS. This is hardware-level protection, not just some flag on a cloud account to be flipped. The only way for Apple to break this system is to break it for everyone, since anything else would risk bleed over or insufficient compliance.

Kluggy Mar 22, 2024 View on HN

Isn't that the entire point of the secure enclave[1]?https://support.apple.com/guide/security/secure-enclave-sec5...

ma2rten Sep 28, 2017 View on HN

This document has more information on the Secure Enclave.https://www.apple.com/business/docs/iOS_Security_Guide.pdf

keepquestioning Oct 27, 2022 View on HN

Apple has Secure Enclave. Who knows what that's doing.

kbolino Feb 22, 2025 View on HN

The hardware will not allow this, at least not without modifications. The encryption keys are not exportable from the Secure Enclave, not even to Apple's own servers.

walterbell Jun 27, 2020 View on HN

Could this be possible on iOS devices, which also have a secure enclave?

some_guy_there Feb 17, 2016 View on HN

Wouldn't Apple (or the manufacturer) know the key of the security enclave?

vlod Feb 22, 2016 View on HN

Not sure if 100% applies to the iPhone in question, but the secure enclave was designed to prevent this sort of thing. Here's an intro to it:https://www.mikeash.com/pyblog/friday-qa-2016-02-19-what-is-...

mastazi May 5, 2023 View on HN

Some devices e.g. Apple have a Secure Enclave that is not user accessible, that's what I'm referring to, I'm not suggesting that they are stored on a server.

positr0n Jun 8, 2024 View on HN

Yep: https://developer.apple.com/documentation/security/certifica...