Originally Posted By: joemikeb
Originally Posted By: artie505
Specifically, don't you mean that a CCC clone of an APFS volume to another APFS volume isn't bootable? It's already been established that a CCC clone of an APFS volume to a HFS+ volume IS bootable.

I have not personally verified that, but I will let you know when I do.

I have verifies that using CCC and cloning from an encrypted APFS drive to an HFS+ volume does create a bootable clone, but on initial examination...
  • Booting from the clone is slow — so slow that the screen blanked before the screen display came on. FWIW the test drive is USB 3.
  • The cloned drive is NOT encrypted so that protection is gone
  • The cloned drive can freely open files on the encrypted APFS volumes
This will take a lot more investigation, but it appears cloning can easily defeat any protection from APFS (encrypted) drives.

🙅‍♂️



UPDATE

See the following post. You can clone to an encrypted HFS+ volume which is good, but the venerability to an unencrypted clone is a major security gap. Time Machine won't allow you to choose an unencrypted backup volume for an APFS encrypted — but I haven't gotten that to work — yet.

Last edited by joemikeb; 07/10/17 11:08 PM. Reason: Update

If we knew what it was we were doing, it wouldn't be called research, would it?

— Albert Einstein