FileVault: what it protects you from and what it does not
· 5 min read
FileVault is full-disk encryption. It has one job, it does it well, and the confusion around it comes from expecting it to do others.
What it protects
Someone who has the machine and not your password.
Without FileVault, an unencrypted drive can be read by starting the Mac from another disk, or by removing the drive. Your files, your mail, your browser data, all readable. A password on your account does not prevent this; it only gates the normal login.
With FileVault, the contents are encrypted with a key derived from your password. Take the drive out and you have unreadable data.
That is the whole protection: a lost or stolen Mac, a machine sold without being erased properly, a laptop left in a hotel room.
What it does not protect
Anything while you are logged in. Once you unlock the machine, the disk is decrypted for everything running on it. FileVault does not stop malware, does not stop an application reading your files, does not stop someone using the machine while you are at lunch.
Files you send elsewhere. Encryption stops at the disk. A file emailed or uploaded is not covered.
Your iCloud data, which is protected separately by your account.
Someone who knows your password.
So FileVault answers “someone stole my laptop” and answers nothing else. For the rest, screen locking, account separation and ordinary caution are what matter. Keeping a Mac secure without making it unusable covers the wider picture.
Should you turn it on?
Yes. On any laptop, without hesitation. On a desktop that never leaves a locked building, the case is weaker and still positive.
On Apple silicon and Intel Macs with a T2 chip, the drive is always encrypted at the hardware level regardless. What FileVault adds is tying decryption to your password rather than to the machine alone. Without it, an attacker with the hardware has an easier route.
The performance cost on modern hardware is not measurable in ordinary use. The old advice about FileVault slowing a machine down predates hardware encryption.
Turning it on
System Settings, Privacy & Security, FileVault, Turn On.
It asks how you want to be able to recover if you forget your password: through your Apple Account, or with a recovery key.
The recovery key is the more secure choice and puts the responsibility on you. If you lose both the password and the key, the data is gone. Not “gone until support helps”; mathematically gone.
Apple Account recovery is more forgiving and means Apple can help you back in, which also means the route exists for anyone who compromises your Apple Account.
For most people, Apple Account recovery with strong two-factor is the sensible balance. For anything genuinely sensitive, a recovery key stored somewhere physical is better. Two-factor authentication done properly covers securing the account either way.
Initial encryption runs in the background and takes a while on a full drive. You can use the Mac throughout.
Where the recovery key should live
Not on the Mac. That is the one rule.
A password manager on another device, a printed copy in a drawer, or with whoever administers your machines if it is a work Mac. Somewhere you will find it in three years when you have forgotten this ever happened.
The consequences worth knowing
Automatic login is disabled. Someone must type a password at startup before the machine can finish booting. That is the point, and it matters for a Mac you want to restart unattended. Setting up a Mac mini as a machine you never sit in front of covers working around it.
Guest access is limited at the login screen.
A forgotten password is serious. Without the recovery route, there is no way in.
Questions
Does FileVault slow down my Mac? Not measurably on any Mac from the last several years. Encryption is handled in hardware.
Is my Mac already encrypted without it? On Apple silicon and T2 Macs, the storage is encrypted at rest, and the key is available to the machine itself. FileVault ties it to your password, which is the meaningful difference.
Can I turn it off later? Yes, in the same settings panel. Decryption runs in the background.
Does it protect against someone using my Mac while I am away from the desk? No. Lock the screen for that. A Hot Corner set to Lock Screen makes it reflexive. The Mac settings worth changing in the first ten minutes covers setting one up.