Whole disk encryption is far superior in most respects to encrypting individual files and folders. If your Mac has a T2 chip, like it or not, your internal storage will be fully encrypted. But if your Mac has to perform encryption in software – as it will for any external storage even when it does have a T2 chip – you may not want the whole disk encrypted. As few of us have no documents with sensitive contents, you may still want some to be suitably protected.

Cast your mind back to when Apple first announced APFS and its wonderful new features. Do you remember it referring to both whole-disk and individual file and folder encryption? Look as hard as you like in the Finder, its Quick Actions, contextual menus, and so on, and it’s nowhere to be found. Has Apple not yet got round to implementing this?

It has, but perhaps not in the direct way that you expected. It’s all done with Disk Utility (hdiutil if you prefer), and once set up works rather well.

Setting up an encrypted harbour for your files is straightforward. I’ll do it here using a sparse bundle, although if you prefer you can use a disk image instead. Sparse bundles have the advantage that they store the encrypted contents in chunks or bands, which can minimise the amount of backup space they require as they are modified. They also only use the space they require.

Read more at EclecticLight.co

Leave a Reply

Discover more from

Subscribe now to keep reading and get access to the full archive.

Continue reading