Apple Platform Security
- Welcome
- Intro to Apple platform security
- Hardware security and biometrics
-
System security
- System security overview
-
Secure boot
- Boot process for iPad and iPhone devices
- Memory safe iBoot implementation
- Mac computers with Apple silicon
- Intel-based Mac computers
- Signed system volume security
- Secure software updates
- Background Security Improvements
- Operating system integrity
- Device pairing and connection security
- BlastDoor for Messages and IDS
- Lockdown Mode security
- Overview of additional macOS system security capabilities
- System security for watchOS
- Random number generation
- Communicating emergency information using satellites
- Apple Security Research Device
-
Encryption and Data Protection
- Encryption and Data Protection overview
- Quantum-secure cryptography with Apple devices
- Passcodes and passwords
- Data Protection
- FileVault
- How Apple protects users personal data
- Digital signing and encryption
-
App security
- App security overview
- App code signing process
- App security in iOS, iPadOS, and visionOS
- App security in macOS
- Supporting extensions
- Secure features in the Notes app
- Secure features in the Shortcuts app
-
Services security
- Services security overview
- Apple Accounts and Managed Apple Accounts
- iCloud
- Passcode and password management
-
Apple Pay
- Apple Pay security overview
- Apple Pay component security
- How Apple Pay keeps users purchases protected
- Credit, debit, and prepaid cards
- Payment authorization with Apple Pay
- Paying with cards using Apple Pay
- Contactless passes in Apple Pay
- Rendering cards unusable with Apple Pay
- Apple Card security
- Apple Cash security
- Tap to Pay on iPhone
- Using Apple Wallet
- iMessage
- Secure Apple Messages for Business
- FaceTime security
- SharePlay security
- Nearby sharing security
- Find My
- Continuity
- Network security
- Developer kit security
-
Secure device management
- Secure device management overview
- Device management
- Apple Configurator security
- Screen Time security
- Glossary
- Document revision history
- Copyright and trademarks
[]Securing routers with HomeKit
Users can improve the security of their home network by using routers that support HomeKit. With these routers, users can manage the Wi-Fi access that HomeKit accessories have to their local network and to the internet. The routers also support Private PSK (PPSK) authentication, so accessories can be added to the Wi-Fi network using a key thats specific to the accessory and that can be revoked when needed. PPSK authentication improves security by not exposing the main Wi-Fi password to accessories, as well as by allowing the router to securely identify an accessory even if it changes its MAC address.
Using the Home app, a user can configure access restrictions for groups of accessories as follows:
No restriction: Allow unrestricted access to the internet and the local network.
Automatic: This is the default setting. Allow access to the internet and the local network based on a list of internet sites and local ports provided to Apple by the accessory manufacturer. This list includes all sites and ports needed by the accessory to function properly. (No Restriction is in place until such a list is available.)
Restrict to Home: No access to the internet or the local network except for the connections required by HomeKit to discover and control the accessory from the local network (including from the home hub to support remote control).
A PPSK is a strong, accessory-specific WPA2 Personal pass-phrase that's automatically generated by HomeKit and revoked if and when the accessory is later removed from the Home. A PPSK is used when an accessory is added to the Wi-Fi network by HomeKit in a Home that has been configured with a HomeKit router; this addition is reflected as Wi-Fi Credential: HomeKit-managed on the settings screen for the accessory in the Home app. Accessories that were added to the Wi-Fi network before adding the router are reconfigured to use a PPSK if the accessory supports this; otherwise, they retain their existing credentials.
As an additional security measure, users need to configure the HomeKit router using the router manufacturers app, so that the app can validate that users have access to the router and can add it to the Home app.
Published Date: February 18, 2021