Does FileVault encrypt the disk instantly?












1















I have recently found that FileVault is disabled on my machine. Although I remember that I set "encrypt" option when I was setting the machine up.



I opened System Preferences and enabled FileVault. To my surprise it didn't take any time. I didn't have to wait while the data is encrypted. It just got instantly enabled.



My configuration: MacBook Air 2018, 256Gb SSD, macOS Mojave 10.14.1



I understood that the disk is not encrypted because I was able to access the content from my home directory from a guest session.



How does it possible that turning on FileVault doesn't take any time?










share|improve this question




















  • 1





    There are 3 main implementations of FV. Can you specify what machine you have (model year ideally) and what version of macOS? We'll need to know if you have an SSD or HDD. We might even need to know if you have diskutil cs list or diskutil apfs list to know if the conversion is still happening in the background.

    – bmike
    Jan 19 at 13:40











  • Excellent edit! That’s a great Mac. I will edit my answer to make it very specific to your situation. I really appreciate the test you made - super good to check on and understand when encryption won’t help you and when it will.

    – bmike
    Jan 19 at 22:05


















1















I have recently found that FileVault is disabled on my machine. Although I remember that I set "encrypt" option when I was setting the machine up.



I opened System Preferences and enabled FileVault. To my surprise it didn't take any time. I didn't have to wait while the data is encrypted. It just got instantly enabled.



My configuration: MacBook Air 2018, 256Gb SSD, macOS Mojave 10.14.1



I understood that the disk is not encrypted because I was able to access the content from my home directory from a guest session.



How does it possible that turning on FileVault doesn't take any time?










share|improve this question




















  • 1





    There are 3 main implementations of FV. Can you specify what machine you have (model year ideally) and what version of macOS? We'll need to know if you have an SSD or HDD. We might even need to know if you have diskutil cs list or diskutil apfs list to know if the conversion is still happening in the background.

    – bmike
    Jan 19 at 13:40











  • Excellent edit! That’s a great Mac. I will edit my answer to make it very specific to your situation. I really appreciate the test you made - super good to check on and understand when encryption won’t help you and when it will.

    – bmike
    Jan 19 at 22:05
















1












1








1








I have recently found that FileVault is disabled on my machine. Although I remember that I set "encrypt" option when I was setting the machine up.



I opened System Preferences and enabled FileVault. To my surprise it didn't take any time. I didn't have to wait while the data is encrypted. It just got instantly enabled.



My configuration: MacBook Air 2018, 256Gb SSD, macOS Mojave 10.14.1



I understood that the disk is not encrypted because I was able to access the content from my home directory from a guest session.



How does it possible that turning on FileVault doesn't take any time?










share|improve this question
















I have recently found that FileVault is disabled on my machine. Although I remember that I set "encrypt" option when I was setting the machine up.



I opened System Preferences and enabled FileVault. To my surprise it didn't take any time. I didn't have to wait while the data is encrypted. It just got instantly enabled.



My configuration: MacBook Air 2018, 256Gb SSD, macOS Mojave 10.14.1



I understood that the disk is not encrypted because I was able to access the content from my home directory from a guest session.



How does it possible that turning on FileVault doesn't take any time?







macos encryption filevault






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Jan 19 at 22:10









bmike

159k46285619




159k46285619










asked Jan 19 at 12:39









Oleksandr ShpotaOleksandr Shpota

182418




182418








  • 1





    There are 3 main implementations of FV. Can you specify what machine you have (model year ideally) and what version of macOS? We'll need to know if you have an SSD or HDD. We might even need to know if you have diskutil cs list or diskutil apfs list to know if the conversion is still happening in the background.

    – bmike
    Jan 19 at 13:40











  • Excellent edit! That’s a great Mac. I will edit my answer to make it very specific to your situation. I really appreciate the test you made - super good to check on and understand when encryption won’t help you and when it will.

    – bmike
    Jan 19 at 22:05
















  • 1





    There are 3 main implementations of FV. Can you specify what machine you have (model year ideally) and what version of macOS? We'll need to know if you have an SSD or HDD. We might even need to know if you have diskutil cs list or diskutil apfs list to know if the conversion is still happening in the background.

    – bmike
    Jan 19 at 13:40











  • Excellent edit! That’s a great Mac. I will edit my answer to make it very specific to your situation. I really appreciate the test you made - super good to check on and understand when encryption won’t help you and when it will.

    – bmike
    Jan 19 at 22:05










1




1





There are 3 main implementations of FV. Can you specify what machine you have (model year ideally) and what version of macOS? We'll need to know if you have an SSD or HDD. We might even need to know if you have diskutil cs list or diskutil apfs list to know if the conversion is still happening in the background.

– bmike
Jan 19 at 13:40





There are 3 main implementations of FV. Can you specify what machine you have (model year ideally) and what version of macOS? We'll need to know if you have an SSD or HDD. We might even need to know if you have diskutil cs list or diskutil apfs list to know if the conversion is still happening in the background.

– bmike
Jan 19 at 13:40













Excellent edit! That’s a great Mac. I will edit my answer to make it very specific to your situation. I really appreciate the test you made - super good to check on and understand when encryption won’t help you and when it will.

– bmike
Jan 19 at 22:05







Excellent edit! That’s a great Mac. I will edit my answer to make it very specific to your situation. I really appreciate the test you made - super good to check on and understand when encryption won’t help you and when it will.

– bmike
Jan 19 at 22:05












2 Answers
2






active

oldest

votes


















3














You have a new Mac with an SSD and T2 chip so all data on it is encrypted always. Any election you make in FileVault just adds and removes user keys from the trust chain so that happens basically instantly. However, when a FileVault credentialed user isn’t created, the system unlocks itself so the encryption door is always wide open.



The next time you restart, the system will notice that the first per-user key is now active and change the boot process so that the system won't unlock that storage and start the OS until your key unlocks the storage. Keep in mind, FileVault by default on APFS is all or nothing. When you unlock the storage, any account can read any files it has permission and you need your password to keep other users (guests) off your files and session.



You can inspect this by looking at diskutil apfs list to examine each APFS containers and synthesized volume encryption and lock status.



mac:~ me$ diskutil list
/dev/disk0 (internal):
#: TYPE NAME SIZE IDENTIFIER
0: GUID_partition_scheme 251.0 GB disk0
1: EFI EFI 314.6 MB disk0s1
2: Apple_APFS Container disk1 250.0 GB disk0s2

/dev/disk1 (synthesized):
#: TYPE NAME SIZE IDENTIFIER
0: APFS Container Scheme - +250.0 GB disk1
Physical Store disk0s2
1: APFS Volume Mac 191.7 GB disk1s1
2: APFS Volume Preboot 65.4 MB disk1s2
3: APFS Volume Recovery 1.0 GB disk1s3
4: APFS Volume VM 3.2 GB disk1s4


Be sure to restart your machine and test the guest session scenario again. Only a full “Guest account” that’s set up in user preferences will keep your data marginally protected when you have an unlocked / unencrypted synthesized Macintosh HD boot / OS / user volume.






share|improve this answer


























  • Thank you for the answer. My laptop does have T2 chip (please find an update in the description). By marking "encrypt" checkbox during system setup I thought it would already turn on FileVault and protect my system. If that is not the case I doubt such protection worth anything (as I said I was able to access my home directory content from a guest session which is a frightening fact). Am I missing something?

    – Oleksandr Shpota
    Jan 19 at 20:42











  • @OleksandrShpota That is by design. Filevault (in its current implementation, Lion and later) and Windows Bitlocker are called "full disk encrpytion". They lock the entire disk as a single entity. Once they are unlocked, FDE allows the OS to read the entire disk. It is the responsibility of the OS to enforce permissions on individual users.

    – user71659
    Jan 19 at 21:12



















2














I didn't set "encryption" on while installing my System, but turning on Encryption with FileVault afterwards definitely takes time (about 45 min with a 512 Go SSD).



Decrypting the disk will take time with a background process as well.



You can check if your disk is encrypted or not (or in progress) through the Terminal with entering this command:



sudo fdesetup status


From your experience, it looks like enabling encryption during setup does the work, but doesn't show up in the "System Preferences" until you explicitly turn it on?



enter image description here






share|improve this answer
























  • Excellent answer covering the non APFS and non-T2 situation. This dialog will show for APFS (lacking T2) and all CoreStorage FileVault situations other than the original FV that made a sparse disk image instead of encrypting the whole volume.

    – bmike
    Jan 19 at 13:49











  • I'm just guessing - you could still be right for this case. We don't have enough data from OP yet to tell. I do know this answer will help other people +1 for that

    – bmike
    Jan 19 at 13:59













  • Thank you for the answer. Please find an update in the description.

    – Oleksandr Shpota
    Jan 19 at 20:44











Your Answer








StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "118"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: false,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fapple.stackexchange.com%2fquestions%2f349028%2fdoes-filevault-encrypt-the-disk-instantly%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























2 Answers
2






active

oldest

votes








2 Answers
2






active

oldest

votes









active

oldest

votes






active

oldest

votes









3














You have a new Mac with an SSD and T2 chip so all data on it is encrypted always. Any election you make in FileVault just adds and removes user keys from the trust chain so that happens basically instantly. However, when a FileVault credentialed user isn’t created, the system unlocks itself so the encryption door is always wide open.



The next time you restart, the system will notice that the first per-user key is now active and change the boot process so that the system won't unlock that storage and start the OS until your key unlocks the storage. Keep in mind, FileVault by default on APFS is all or nothing. When you unlock the storage, any account can read any files it has permission and you need your password to keep other users (guests) off your files and session.



You can inspect this by looking at diskutil apfs list to examine each APFS containers and synthesized volume encryption and lock status.



mac:~ me$ diskutil list
/dev/disk0 (internal):
#: TYPE NAME SIZE IDENTIFIER
0: GUID_partition_scheme 251.0 GB disk0
1: EFI EFI 314.6 MB disk0s1
2: Apple_APFS Container disk1 250.0 GB disk0s2

/dev/disk1 (synthesized):
#: TYPE NAME SIZE IDENTIFIER
0: APFS Container Scheme - +250.0 GB disk1
Physical Store disk0s2
1: APFS Volume Mac 191.7 GB disk1s1
2: APFS Volume Preboot 65.4 MB disk1s2
3: APFS Volume Recovery 1.0 GB disk1s3
4: APFS Volume VM 3.2 GB disk1s4


Be sure to restart your machine and test the guest session scenario again. Only a full “Guest account” that’s set up in user preferences will keep your data marginally protected when you have an unlocked / unencrypted synthesized Macintosh HD boot / OS / user volume.






share|improve this answer


























  • Thank you for the answer. My laptop does have T2 chip (please find an update in the description). By marking "encrypt" checkbox during system setup I thought it would already turn on FileVault and protect my system. If that is not the case I doubt such protection worth anything (as I said I was able to access my home directory content from a guest session which is a frightening fact). Am I missing something?

    – Oleksandr Shpota
    Jan 19 at 20:42











  • @OleksandrShpota That is by design. Filevault (in its current implementation, Lion and later) and Windows Bitlocker are called "full disk encrpytion". They lock the entire disk as a single entity. Once they are unlocked, FDE allows the OS to read the entire disk. It is the responsibility of the OS to enforce permissions on individual users.

    – user71659
    Jan 19 at 21:12
















3














You have a new Mac with an SSD and T2 chip so all data on it is encrypted always. Any election you make in FileVault just adds and removes user keys from the trust chain so that happens basically instantly. However, when a FileVault credentialed user isn’t created, the system unlocks itself so the encryption door is always wide open.



The next time you restart, the system will notice that the first per-user key is now active and change the boot process so that the system won't unlock that storage and start the OS until your key unlocks the storage. Keep in mind, FileVault by default on APFS is all or nothing. When you unlock the storage, any account can read any files it has permission and you need your password to keep other users (guests) off your files and session.



You can inspect this by looking at diskutil apfs list to examine each APFS containers and synthesized volume encryption and lock status.



mac:~ me$ diskutil list
/dev/disk0 (internal):
#: TYPE NAME SIZE IDENTIFIER
0: GUID_partition_scheme 251.0 GB disk0
1: EFI EFI 314.6 MB disk0s1
2: Apple_APFS Container disk1 250.0 GB disk0s2

/dev/disk1 (synthesized):
#: TYPE NAME SIZE IDENTIFIER
0: APFS Container Scheme - +250.0 GB disk1
Physical Store disk0s2
1: APFS Volume Mac 191.7 GB disk1s1
2: APFS Volume Preboot 65.4 MB disk1s2
3: APFS Volume Recovery 1.0 GB disk1s3
4: APFS Volume VM 3.2 GB disk1s4


Be sure to restart your machine and test the guest session scenario again. Only a full “Guest account” that’s set up in user preferences will keep your data marginally protected when you have an unlocked / unencrypted synthesized Macintosh HD boot / OS / user volume.






share|improve this answer


























  • Thank you for the answer. My laptop does have T2 chip (please find an update in the description). By marking "encrypt" checkbox during system setup I thought it would already turn on FileVault and protect my system. If that is not the case I doubt such protection worth anything (as I said I was able to access my home directory content from a guest session which is a frightening fact). Am I missing something?

    – Oleksandr Shpota
    Jan 19 at 20:42











  • @OleksandrShpota That is by design. Filevault (in its current implementation, Lion and later) and Windows Bitlocker are called "full disk encrpytion". They lock the entire disk as a single entity. Once they are unlocked, FDE allows the OS to read the entire disk. It is the responsibility of the OS to enforce permissions on individual users.

    – user71659
    Jan 19 at 21:12














3












3








3







You have a new Mac with an SSD and T2 chip so all data on it is encrypted always. Any election you make in FileVault just adds and removes user keys from the trust chain so that happens basically instantly. However, when a FileVault credentialed user isn’t created, the system unlocks itself so the encryption door is always wide open.



The next time you restart, the system will notice that the first per-user key is now active and change the boot process so that the system won't unlock that storage and start the OS until your key unlocks the storage. Keep in mind, FileVault by default on APFS is all or nothing. When you unlock the storage, any account can read any files it has permission and you need your password to keep other users (guests) off your files and session.



You can inspect this by looking at diskutil apfs list to examine each APFS containers and synthesized volume encryption and lock status.



mac:~ me$ diskutil list
/dev/disk0 (internal):
#: TYPE NAME SIZE IDENTIFIER
0: GUID_partition_scheme 251.0 GB disk0
1: EFI EFI 314.6 MB disk0s1
2: Apple_APFS Container disk1 250.0 GB disk0s2

/dev/disk1 (synthesized):
#: TYPE NAME SIZE IDENTIFIER
0: APFS Container Scheme - +250.0 GB disk1
Physical Store disk0s2
1: APFS Volume Mac 191.7 GB disk1s1
2: APFS Volume Preboot 65.4 MB disk1s2
3: APFS Volume Recovery 1.0 GB disk1s3
4: APFS Volume VM 3.2 GB disk1s4


Be sure to restart your machine and test the guest session scenario again. Only a full “Guest account” that’s set up in user preferences will keep your data marginally protected when you have an unlocked / unencrypted synthesized Macintosh HD boot / OS / user volume.






share|improve this answer















You have a new Mac with an SSD and T2 chip so all data on it is encrypted always. Any election you make in FileVault just adds and removes user keys from the trust chain so that happens basically instantly. However, when a FileVault credentialed user isn’t created, the system unlocks itself so the encryption door is always wide open.



The next time you restart, the system will notice that the first per-user key is now active and change the boot process so that the system won't unlock that storage and start the OS until your key unlocks the storage. Keep in mind, FileVault by default on APFS is all or nothing. When you unlock the storage, any account can read any files it has permission and you need your password to keep other users (guests) off your files and session.



You can inspect this by looking at diskutil apfs list to examine each APFS containers and synthesized volume encryption and lock status.



mac:~ me$ diskutil list
/dev/disk0 (internal):
#: TYPE NAME SIZE IDENTIFIER
0: GUID_partition_scheme 251.0 GB disk0
1: EFI EFI 314.6 MB disk0s1
2: Apple_APFS Container disk1 250.0 GB disk0s2

/dev/disk1 (synthesized):
#: TYPE NAME SIZE IDENTIFIER
0: APFS Container Scheme - +250.0 GB disk1
Physical Store disk0s2
1: APFS Volume Mac 191.7 GB disk1s1
2: APFS Volume Preboot 65.4 MB disk1s2
3: APFS Volume Recovery 1.0 GB disk1s3
4: APFS Volume VM 3.2 GB disk1s4


Be sure to restart your machine and test the guest session scenario again. Only a full “Guest account” that’s set up in user preferences will keep your data marginally protected when you have an unlocked / unencrypted synthesized Macintosh HD boot / OS / user volume.







share|improve this answer














share|improve this answer



share|improve this answer








edited Jan 19 at 22:14

























answered Jan 19 at 13:48









bmikebmike

159k46285619




159k46285619













  • Thank you for the answer. My laptop does have T2 chip (please find an update in the description). By marking "encrypt" checkbox during system setup I thought it would already turn on FileVault and protect my system. If that is not the case I doubt such protection worth anything (as I said I was able to access my home directory content from a guest session which is a frightening fact). Am I missing something?

    – Oleksandr Shpota
    Jan 19 at 20:42











  • @OleksandrShpota That is by design. Filevault (in its current implementation, Lion and later) and Windows Bitlocker are called "full disk encrpytion". They lock the entire disk as a single entity. Once they are unlocked, FDE allows the OS to read the entire disk. It is the responsibility of the OS to enforce permissions on individual users.

    – user71659
    Jan 19 at 21:12



















  • Thank you for the answer. My laptop does have T2 chip (please find an update in the description). By marking "encrypt" checkbox during system setup I thought it would already turn on FileVault and protect my system. If that is not the case I doubt such protection worth anything (as I said I was able to access my home directory content from a guest session which is a frightening fact). Am I missing something?

    – Oleksandr Shpota
    Jan 19 at 20:42











  • @OleksandrShpota That is by design. Filevault (in its current implementation, Lion and later) and Windows Bitlocker are called "full disk encrpytion". They lock the entire disk as a single entity. Once they are unlocked, FDE allows the OS to read the entire disk. It is the responsibility of the OS to enforce permissions on individual users.

    – user71659
    Jan 19 at 21:12

















Thank you for the answer. My laptop does have T2 chip (please find an update in the description). By marking "encrypt" checkbox during system setup I thought it would already turn on FileVault and protect my system. If that is not the case I doubt such protection worth anything (as I said I was able to access my home directory content from a guest session which is a frightening fact). Am I missing something?

– Oleksandr Shpota
Jan 19 at 20:42





Thank you for the answer. My laptop does have T2 chip (please find an update in the description). By marking "encrypt" checkbox during system setup I thought it would already turn on FileVault and protect my system. If that is not the case I doubt such protection worth anything (as I said I was able to access my home directory content from a guest session which is a frightening fact). Am I missing something?

– Oleksandr Shpota
Jan 19 at 20:42













@OleksandrShpota That is by design. Filevault (in its current implementation, Lion and later) and Windows Bitlocker are called "full disk encrpytion". They lock the entire disk as a single entity. Once they are unlocked, FDE allows the OS to read the entire disk. It is the responsibility of the OS to enforce permissions on individual users.

– user71659
Jan 19 at 21:12





@OleksandrShpota That is by design. Filevault (in its current implementation, Lion and later) and Windows Bitlocker are called "full disk encrpytion". They lock the entire disk as a single entity. Once they are unlocked, FDE allows the OS to read the entire disk. It is the responsibility of the OS to enforce permissions on individual users.

– user71659
Jan 19 at 21:12













2














I didn't set "encryption" on while installing my System, but turning on Encryption with FileVault afterwards definitely takes time (about 45 min with a 512 Go SSD).



Decrypting the disk will take time with a background process as well.



You can check if your disk is encrypted or not (or in progress) through the Terminal with entering this command:



sudo fdesetup status


From your experience, it looks like enabling encryption during setup does the work, but doesn't show up in the "System Preferences" until you explicitly turn it on?



enter image description here






share|improve this answer
























  • Excellent answer covering the non APFS and non-T2 situation. This dialog will show for APFS (lacking T2) and all CoreStorage FileVault situations other than the original FV that made a sparse disk image instead of encrypting the whole volume.

    – bmike
    Jan 19 at 13:49











  • I'm just guessing - you could still be right for this case. We don't have enough data from OP yet to tell. I do know this answer will help other people +1 for that

    – bmike
    Jan 19 at 13:59













  • Thank you for the answer. Please find an update in the description.

    – Oleksandr Shpota
    Jan 19 at 20:44
















2














I didn't set "encryption" on while installing my System, but turning on Encryption with FileVault afterwards definitely takes time (about 45 min with a 512 Go SSD).



Decrypting the disk will take time with a background process as well.



You can check if your disk is encrypted or not (or in progress) through the Terminal with entering this command:



sudo fdesetup status


From your experience, it looks like enabling encryption during setup does the work, but doesn't show up in the "System Preferences" until you explicitly turn it on?



enter image description here






share|improve this answer
























  • Excellent answer covering the non APFS and non-T2 situation. This dialog will show for APFS (lacking T2) and all CoreStorage FileVault situations other than the original FV that made a sparse disk image instead of encrypting the whole volume.

    – bmike
    Jan 19 at 13:49











  • I'm just guessing - you could still be right for this case. We don't have enough data from OP yet to tell. I do know this answer will help other people +1 for that

    – bmike
    Jan 19 at 13:59













  • Thank you for the answer. Please find an update in the description.

    – Oleksandr Shpota
    Jan 19 at 20:44














2












2








2







I didn't set "encryption" on while installing my System, but turning on Encryption with FileVault afterwards definitely takes time (about 45 min with a 512 Go SSD).



Decrypting the disk will take time with a background process as well.



You can check if your disk is encrypted or not (or in progress) through the Terminal with entering this command:



sudo fdesetup status


From your experience, it looks like enabling encryption during setup does the work, but doesn't show up in the "System Preferences" until you explicitly turn it on?



enter image description here






share|improve this answer













I didn't set "encryption" on while installing my System, but turning on Encryption with FileVault afterwards definitely takes time (about 45 min with a 512 Go SSD).



Decrypting the disk will take time with a background process as well.



You can check if your disk is encrypted or not (or in progress) through the Terminal with entering this command:



sudo fdesetup status


From your experience, it looks like enabling encryption during setup does the work, but doesn't show up in the "System Preferences" until you explicitly turn it on?



enter image description here







share|improve this answer












share|improve this answer



share|improve this answer










answered Jan 19 at 13:47









YoricYoric

5439




5439













  • Excellent answer covering the non APFS and non-T2 situation. This dialog will show for APFS (lacking T2) and all CoreStorage FileVault situations other than the original FV that made a sparse disk image instead of encrypting the whole volume.

    – bmike
    Jan 19 at 13:49











  • I'm just guessing - you could still be right for this case. We don't have enough data from OP yet to tell. I do know this answer will help other people +1 for that

    – bmike
    Jan 19 at 13:59













  • Thank you for the answer. Please find an update in the description.

    – Oleksandr Shpota
    Jan 19 at 20:44



















  • Excellent answer covering the non APFS and non-T2 situation. This dialog will show for APFS (lacking T2) and all CoreStorage FileVault situations other than the original FV that made a sparse disk image instead of encrypting the whole volume.

    – bmike
    Jan 19 at 13:49











  • I'm just guessing - you could still be right for this case. We don't have enough data from OP yet to tell. I do know this answer will help other people +1 for that

    – bmike
    Jan 19 at 13:59













  • Thank you for the answer. Please find an update in the description.

    – Oleksandr Shpota
    Jan 19 at 20:44

















Excellent answer covering the non APFS and non-T2 situation. This dialog will show for APFS (lacking T2) and all CoreStorage FileVault situations other than the original FV that made a sparse disk image instead of encrypting the whole volume.

– bmike
Jan 19 at 13:49





Excellent answer covering the non APFS and non-T2 situation. This dialog will show for APFS (lacking T2) and all CoreStorage FileVault situations other than the original FV that made a sparse disk image instead of encrypting the whole volume.

– bmike
Jan 19 at 13:49













I'm just guessing - you could still be right for this case. We don't have enough data from OP yet to tell. I do know this answer will help other people +1 for that

– bmike
Jan 19 at 13:59







I'm just guessing - you could still be right for this case. We don't have enough data from OP yet to tell. I do know this answer will help other people +1 for that

– bmike
Jan 19 at 13:59















Thank you for the answer. Please find an update in the description.

– Oleksandr Shpota
Jan 19 at 20:44





Thank you for the answer. Please find an update in the description.

– Oleksandr Shpota
Jan 19 at 20:44


















draft saved

draft discarded




















































Thanks for contributing an answer to Ask Different!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fapple.stackexchange.com%2fquestions%2f349028%2fdoes-filevault-encrypt-the-disk-instantly%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Mario Kart Wii

What does “Dominus providebit” mean?

Antonio Litta Visconti Arese