Apple offers different ways to manage Time Machine encryption for local and network backups.
Concerned about your Mac’s startup SSD or hard disk drive falling into someone else’s hands? Encrypting the startup volume prevents access to that drive unless they know an account password password or, in some cases, possess the correct hardware to unlock the contents.
Apple automatically enables drive encryption for the startup volume on any Intel Mac with a T2 Security Chip and on all M1-based Macs. For other Intel Macs, when you enable FileVault the startup volume becomes encrypted, too. (FileVault on all Macs also enables boot protection, which keeps your encrypted drive locked down until you validate your login with an authorized account.)
But what of backups? If you use Time Machine via a local or networked drive, your backed-up files are easily accessible if someone detaches the drive and plugs it into another computer.
Time Machine encompasses data encryption in one of two ways:
- Encrypt the backup: Time Machine lets you choose to encrypt a backup when you begin the backup process for the first time on a volume. After selecting a listed volume in the Time Machine preference pane’s Select Disk dialog, you can check “Encrypt backups.” When you click Use Disk, you’re prompted to enter a password. This can be useful if you want each backup to have a separate password, or each person backing up over a network wants to select and retain a private password. (If you want to enable encryption later, the backup has to start from scratch; Time Machine won’t encrypt a non-encrypted archive.)
Read more at MacWorld.com
