I would like to know more about the T2 security chip and exactly how it encrypts data on a Mac mini.
Specifically, I would like to know about the following scenario:
I purchased a used 2023 Mac mini M2 Pro off of eBay. I am unaware if the previous owner ever enabled FIleVault or not. I have had FileVault enabled since setting it up. Does FIleVault encrypt the entire drive, even sectors/blocks of written/deleted data from the previous owner? Or does it only encrypt data that is copied to the drive from the point onward since it was enabled? I know that data is encrypted by default due to the T2 security chip, but is there any possibility of any of the data from the previous owner being able to be recovered? I would like to make it to where all data from the previous owner is completely lost/erased/encrypted forever.
Can you “layer” cryptographic erases? For example, what happens if I purchase a used Mac mini with the T2 security chip, enable FileVault, and then erase the disk, lose the key, and reinstall MacOS? What would happen if the previous owner had done the same thing? Are there now two different “cryptographic erases” layered on the drive? Does my enabling of FileVault encrypt data that was added/deleted by the previous owner (assuming they never enabled FileVault)?
Specifically, I would like to know about the following scenario:
I purchased a used 2023 Mac mini M2 Pro off of eBay. I am unaware if the previous owner ever enabled FIleVault or not. I have had FileVault enabled since setting it up. Does FIleVault encrypt the entire drive, even sectors/blocks of written/deleted data from the previous owner? Or does it only encrypt data that is copied to the drive from the point onward since it was enabled? I know that data is encrypted by default due to the T2 security chip, but is there any possibility of any of the data from the previous owner being able to be recovered? I would like to make it to where all data from the previous owner is completely lost/erased/encrypted forever.
Can you “layer” cryptographic erases? For example, what happens if I purchase a used Mac mini with the T2 security chip, enable FileVault, and then erase the disk, lose the key, and reinstall MacOS? What would happen if the previous owner had done the same thing? Are there now two different “cryptographic erases” layered on the drive? Does my enabling of FileVault encrypt data that was added/deleted by the previous owner (assuming they never enabled FileVault)?