How to Use Apple’s Built-in Features to Encrypt Files and Folders

The best way to protect your data is to encrypt your files, ensuring that, even if they get into the hands of hackers or cybercriminals, your personal data is safe. macOS provides a suite of tools to protect you, and, in this article, I’ll discuss the many ways you can use built-in macOS features to provide unbreakable encryption. (Unbreakable with current computing power; it’s possible that?future quantum computers will be able to break the robust encryption algorithms?that macOS uses.)

In this article, I’ll explain how to encrypt your startup disk with FileVault; how to encrypt other disks; and how to create encrypted disk images to store files securely in the cloud or send by email; and how to encrypt PDF files.

Encrypt Your Startup Disk with FileVault

When Apple first added FileVault to Mac OS X in 2003, the feature was clunky; it slowed down Macs, and I didn’t recommend using it at the time. But over the years, Apple has improved FileVault, and processors have gotten much faster. Now in its second iteration – FileVault 2 was released in 2011 – FileVault is secure and doesn’t noticeably affect the performance of your Mac. While there were good reasons to avoid the first implementation of FileVault, there are no reasons to not use it any more.

FileVault provides?full-disk encryption: when it is active, every file on your drive is encrypted, and as you write new files, they are encrypted too. No one can access that drive, or even start up your Mac, without the FileVault password. And if someone removes the drive and attempts to access the files it contains, they won’t be able to. FileVault uses uses XTS-AES-128 encryption with a 256-bit key; that’s a simple way of saying that it is extremely robust.

In addition, FileVault 2 allows you to use Find My Mac to remotely erase your drive if your Mac is lost or stolen. And if you decide to sell, give away, or destroy your Mac,?you don’t need to worry about securely erasing the disk. Since it is password protected, anyone who recovers the disk will not be able to access your files. It’s a good idea to erase it anyway, but there is no longer a "secure erase" feature for SSDs on macOS, so it’s really important to use FileVault on an SSD.

Activating FileVault

To turn on FileVault, go to System Preferences > Security & Privacy, unlock the preference pane by clicking the padlock and entering your administrator’s user name and password, then click FileVault.

The best way to protect your data is to encrypt your files, ensuring that, even if they get into the hands of hackers or cybercriminals, your personal data is safe. macOS provides a suite of tools to protect you, and, in this article, I’ll discuss the many ways you can use built-in macOS features to provide unbreakable encryption. (Unbreakable with current computing power; it’s possible that?future quantum computers will be able to break the robust encryption algorithms?that macOS uses.)

In this article, I’ll explain how to encrypt your startup disk with FileVault; how to encrypt other disks; and how to create encrypted disk images to store files securely in the cloud or send by email; and how to encrypt PDF files.

Encrypt Your Startup Disk with FileVault

When Apple first added FileVault to Mac OS X in 2003, the feature was clunky; it slowed down Macs, and I didn’t recommend using it at the time. But over the years, Apple has improved FileVault, and processors have gotten much faster. Now in its second iteration – FileVault 2 was released in 2011 – FileVault is secure and doesn’t noticeably affect the performance of your Mac. While there were good reasons to avoid the first implementation of FileVault, there are no reasons to not use it any more.

FileVault provides?full-disk encryption: when it is active, every file on your drive is encrypted, and as you write new files, they are encrypted too. No one can access that drive, or even start up your Mac, without the FileVault password. And if someone removes the drive and attempts to access the files it contains, they won’t be able to. FileVault uses uses XTS-AES-128 encryption with a 256-bit key; that’s a simple way of saying that it is extremely robust.

In addition, FileVault 2 allows you to use Find My Mac to remotely erase your drive if your Mac is lost or stolen. And if you decide to sell, give away, or destroy your Mac,?you don’t need to worry about securely erasing the disk. Since it is password protected, anyone who recovers the disk will not be able to access your files. It’s a good idea to erase it anyway, but there is no longer a "secure erase" feature for SSDs on macOS, so it’s really important to use FileVault on an SSD.

Activating FileVault

To turn on FileVault, go to System Preferences > Security & Privacy, unlock the preference pane by clicking the padlock and entering your administrator’s user name and password, then click FileVault.


Click Turn On FileVault. By default, your login password unlocks the disk, but if you forget that, you need another way to access your data. You are asked whether you want to be able to use your iCloud account the unlock your disk if you forget your password, or if you want to save a recovery key.

If you store your recovery key on your iCloud account, you’ll need access to that account to unlock your disk. So if you don’t have internet access, you won’t be able to unlock the disk. And if, perchance, you get locked out of your iCloud account, then you could be in trouble.

The recovery key is a string of 20 characters, such as TH3E-T829-ELOW-34BD-LMJ9. If you do opt for saving the recovery key, you will need to save it securely. You could store it in a password manager, or print it and save it in a secure location, such as a safe deposit box. If you do choose the recovery key, you can double-click it in the dialog, copy it, and paste it into a document. Or, you can take a screenshot and save that. (To take a screenshot of your Mac’s screen, press Command-Shift-3. The screenshot is saved to the Desktop.)

Click Continue, and FileVault begins encrypting your disk. Note that your computer must be connected to power for this to work; if you disconnect a laptop from its power source, FileVault will pause until it is reconnected.

The initial encryption takes from a couple of hours to a couple of days, depending on the size of your disk, and SSDs encrypt more quickly. However, any new files you create or download are automatically encrypted during this period. It can seem like a long time, but you can continue working with your Mac, and you won’t notice much of a performance hit as FileVault does its initial encryption.

You can turn off FileVault at any time in this preference pane, and if you wish to change your recovery key, you’ll need to turn off FileVault and turn it on again.

Encrypting Other Disks

macOS offers a similar feature to encrypt any drive that you connect to your Mac. For example, if you use a thumb drive to shuttle files between home and work, it’s a good idea to encrypt it in case you lose it.

Encrypting Empty Disks

To do this, mount the drive, then open Disk Utility (it’s in the Utilities folder in your Applications folder). Select the drive, then click Erase in the toolbar. In the Format menu, select APFS (Encrypted).


Enter a password, then enter it again. It’s a good idea to enter a password hint. Click Choose, then click Erase. Disk Utility erases the drive and creates a new encrypted volume; any files you write to that drive are encrypted, and when you mount it on a Mac, you need to enter its password. You can, however, choose to store the password in your Mac’s keychain, but you probably don’t want to do this on any Mac that doesn’t belong to you, such as one in your office.

Encrypting Disks Containing Data

If you have a drive that already contains data, and you don’t want to erase it, you can still encrypt it, but not in Disk Utility. Mount the drive, then right-click it in the Finder, and you’ll see an Encrypt option.

Choose that option, then enter and verify a password, and enter a password hint (it’s required here). If you click the key icon, you can have macOS suggest a password.


The Finder unmounts your drive, and it may take a few minutes for it to be remounted, and then the encryption process may take some time, as with FileVault.

Encrypt Time Machine Backups

If you use Time Machine to back up your Mac, you have the option to encrypt the drive you use for backups, and you should definitely to this. To enable encryption, you need to choose the option when you set up your disk for Time Machine. If you are already using a disk with Time Machine, you can stop using it, turn on encryption, then add it again.

Open the Time Machine preference pane (in System Preferences). Click Add or Remove Backup Disk. Choose a disk, and check Encrypt Backups at the bottom of the dialog.

If you want to turn on encryption for a disk you’re already using, select that disk, then click Remove Disk. Click Select Disk in the Time Machine preference pane, select that disk, then click Use Disk; make sure to check Encrypt Disk.

No data is lost when you do this with a local disk, but if you’re backing up to a network drive, then your backups will be erased, so it’s best to ensure that you have a full backup of your Mac before making this change.

Store Files on an Encrypted Disk Image

Another way to encrypt files is to store them on an encrypted?disk image. A disk image is a special file that acts as a container for other files; you can create one that is encrypted, so the container and all its contents are protected. Encrypted disk images let you store files securely on cloud servers, and you can?even use them to send sensitive files via email. Just give the receiver the password – by telephone or secure messaging – and they’ll be able to open the disk image and access the files, or add their own files to it.

To do this, open Disk Utility, and choose File > New Image > Blank Image. (If you want to take a folder and create an encrypted disk image with its contents, choose File > New Image > Image from Folder, and select the folder you want to use.)


Enter a name for the disk image file in the Save As field, then you have a number of options at the bottom of the dialog.

Name: This is the name of the disk image that mounts in the Finder, rather than the name of the actual file. Enter anything you want here; you’ll only see this name when the disk image is mounted in the Finder.

Size: Enter an appropriate size. You may only want this disk image to store a handful of documents, so perhaps 10 MB might be enough. But if you want to put a lot of files on it, maybe you want it to be 1 GB. If you’re not sure, see below in Image Format for other options.

Format: Choose Mac OS Extended (Journaled), or, if it’s only going to be used with Macs running macOS 10.13 or later, choose APFS.

Encryption: Choose 256-bit encryption. It’s more secure, and, while Disk Utility tells you that it’s slower, you generally don’t need to worry about speed unless your disk image is huge. You’ll be asked to set a password at this point.

Partitions: Choose Single partition – GUID Partition Map.

Image Format: If you’re not sure of the size you need, choose sparse disk image. Disk Utility will set its size to 100 MB, which is the maximum size for the disk image, but you can go back to the Size field and enter another size, such as 1 GB, or even 1 TB. A sparse image is a special format that will grow as needed until it reaches that maximum. The initial disk image file will be very small – about 7.5 MB – but will grow as you add files to it.

Sparse images are the best option when you don’t know what you want to store on the disk image. When you add files to a sparse image, the size of the disk image file increases. When you delete files, however, the disk image file doesn’t get any smaller. There is a way to compact sparse images. If you are familiar with Terminal, you can run this command:

hdiutil compact <disk path>

Type the first two words in Terminal, then drag the disk image file to the Terminal window and press Return. You’ll see something like this:

$ hdiutil compact /Users/kirk/Documents/My\ Disk\ Image.sparsebundle

Starting to compact…

Reclaiming free space…

...............................................

Finishing compaction…

Reclaimed 772.8 MB out of 948.2 MB possible.

Encrypt PDF files

You can also use macOS’s built-in Preview app to encrypt PDF files. Open a PDF in Preview, then choose File > Export as PDF. Click Show Details, check Encrypt, and enter a password.


Click Save, and Preview will export the encrypted PDF. When you open the PDF, you’ll see a dialog asking for the password.

Make sure to note this password in a secure location, so you can read these files later. Most of the time, you’ll encrypt a PDF file to send it to someone over the internet. So you’ll need to give them the password in a secure way, such as using secure messaging, like with Apple’s Messages app, or over the phone.

Remember, that only this exported copy is protected by a password. If this is the only copy you want to keep, you can delete the original.

Summing Up

With all these options, you can safely encrypt your disks and even create encrypted disk images that you can send via email, store in the cloud, or save on network servers. Your data is protected by encryption algorithms that are robust and secure. Also, using the built-in macOS encryption features means that you don’t depend on third-party software, and these disks and files will be compatible on any Mac. Just don’t forget (or lose) your passwords.

?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請(qǐng)聯(lián)系作者
  • 序言:七十年代末僚害,一起剝皮案震驚了整個(gè)濱河市物喷,隨后出現(xiàn)的幾起案子绅你,更是在濱河造成了極大的恐慌,老刑警劉巖,帶你破解...
    沈念sama閱讀 218,525評(píng)論 6 507
  • 序言:濱河連續(xù)發(fā)生了三起死亡事件排监,死亡現(xiàn)場(chǎng)離奇詭異,居然都是意外死亡,警方通過查閱死者的電腦和手機(jī)旗吁,發(fā)現(xiàn)死者居然都...
    沈念sama閱讀 93,203評(píng)論 3 395
  • 文/潘曉璐 我一進(jìn)店門,熙熙樓的掌柜王于貴愁眉苦臉地迎上來停局,“玉大人很钓,你說我怎么就攤上這事香府。” “怎么了码倦?”我有些...
    開封第一講書人閱讀 164,862評(píng)論 0 354
  • 文/不壞的土叔 我叫張陵企孩,是天一觀的道長(zhǎng)。 經(jīng)常有香客問我袁稽,道長(zhǎng)勿璃,這世上最難降的妖魔是什么? 我笑而不...
    開封第一講書人閱讀 58,728評(píng)論 1 294
  • 正文 為了忘掉前任推汽,我火速辦了婚禮蝗柔,結(jié)果婚禮上,老公的妹妹穿的比我還像新娘民泵。我一直安慰自己癣丧,他們只是感情好,可當(dāng)我...
    茶點(diǎn)故事閱讀 67,743評(píng)論 6 392
  • 文/花漫 我一把揭開白布栈妆。 她就那樣靜靜地躺著胁编,像睡著了一般。 火紅的嫁衣襯著肌膚如雪鳞尔。 梳的紋絲不亂的頭發(fā)上嬉橙,一...
    開封第一講書人閱讀 51,590評(píng)論 1 305
  • 那天,我揣著相機(jī)與錄音寥假,去河邊找鬼市框。 笑死,一個(gè)胖子當(dāng)著我的面吹牛糕韧,可吹牛的內(nèi)容都是我干的枫振。 我是一名探鬼主播,決...
    沈念sama閱讀 40,330評(píng)論 3 418
  • 文/蒼蘭香墨 我猛地睜開眼萤彩,長(zhǎng)吁一口氣:“原來是場(chǎng)噩夢(mèng)啊……” “哼粪滤!你這毒婦竟也來了?” 一聲冷哼從身側(cè)響起雀扶,我...
    開封第一講書人閱讀 39,244評(píng)論 0 276
  • 序言:老撾萬榮一對(duì)情侶失蹤杖小,失蹤者是張志新(化名)和其女友劉穎,沒想到半個(gè)月后愚墓,有當(dāng)?shù)厝嗽跇淞掷锇l(fā)現(xiàn)了一具尸體予权,經(jīng)...
    沈念sama閱讀 45,693評(píng)論 1 314
  • 正文 獨(dú)居荒郊野嶺守林人離奇死亡,尸身上長(zhǎng)有42處帶血的膿包…… 初始之章·張勛 以下內(nèi)容為張勛視角 年9月15日...
    茶點(diǎn)故事閱讀 37,885評(píng)論 3 336
  • 正文 我和宋清朗相戀三年浪册,在試婚紗的時(shí)候發(fā)現(xiàn)自己被綠了扫腺。 大學(xué)時(shí)的朋友給我發(fā)了我未婚夫和他白月光在一起吃飯的照片。...
    茶點(diǎn)故事閱讀 40,001評(píng)論 1 348
  • 序言:一個(gè)原本活蹦亂跳的男人離奇死亡议经,死狀恐怖斧账,靈堂內(nèi)的尸體忽然破棺而出谴返,到底是詐尸還是另有隱情煞肾,我是刑警寧澤咧织,帶...
    沈念sama閱讀 35,723評(píng)論 5 346
  • 正文 年R本政府宣布,位于F島的核電站籍救,受9級(jí)特大地震影響习绢,放射性物質(zhì)發(fā)生泄漏。R本人自食惡果不足惜蝙昙,卻給世界環(huán)境...
    茶點(diǎn)故事閱讀 41,343評(píng)論 3 330
  • 文/蒙蒙 一闪萄、第九天 我趴在偏房一處隱蔽的房頂上張望。 院中可真熱鬧奇颠,春花似錦败去、人聲如沸。這莊子的主人今日做“春日...
    開封第一講書人閱讀 31,919評(píng)論 0 22
  • 文/蒼蘭香墨 我抬頭看了看天上的太陽。三九已至荆几,卻和暖如春吓妆,著一層夾襖步出監(jiān)牢的瞬間,已是汗流浹背吨铸。 一陣腳步聲響...
    開封第一講書人閱讀 33,042評(píng)論 1 270
  • 我被黑心中介騙來泰國(guó)打工行拢, 沒想到剛下飛機(jī)就差點(diǎn)兒被人妖公主榨干…… 1. 我叫王不留,地道東北人诞吱。 一個(gè)月前我還...
    沈念sama閱讀 48,191評(píng)論 3 370
  • 正文 我出身青樓舟奠,卻偏偏與公主長(zhǎng)得像,于是被迫代替她去往敵國(guó)和親房维。 傳聞我的和親對(duì)象是個(gè)殘疾皇子鸭栖,可洞房花燭夜當(dāng)晚...
    茶點(diǎn)故事閱讀 44,955評(píng)論 2 355

推薦閱讀更多精彩內(nèi)容