Conversation
On macOS 26 the local `python -m findmy decrypt` path is blocked: the BeaconStoreKey is guarded by an Apple-only keychain access-group entitlement, so accessory keys can't be read locally (issue malmeloo#177). Add a README section pointing macOS 26 users to iCloud Keychain escrow export via export-findmy, which produces FindMy.py-compatible JSON with no second Mac and without disabling SIP. Also gitignore local key/session artifacts (devices/, account.json, ani_libs.bin) so users following the instructions don't accidentally commit private key material.
Owner
|
I appreciate your PR, but this method is still a bit experimental and bound to change in the future. This functionality will be built into FindMy.py directly at some point, hopefully soon. Let's reconsider this in a few weeks or so. By that point I expect I will at least have a full CI pipeline implemented with releases. That way people won't have to compile it manually. Then we add it to the docs, I'll publish an announcement and we'll see if it breaks or not. If all works fine it will then be integrated into FindMy.py. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds a README section for macOS 26 (Tahoe) users explaining how to obtain accessory keys, since the built-in
python -m findmy decryptno longer works there.Why
On macOS 26, the
BeaconStoreKeyneeded to decrypt local accessory records is guarded by an Apple-only keychain access-group entitlement (com.apple.icloud.searchpartyuseragent), sopython -m findmy decryptfails — the docs currently describe it as a dead end (#177). The iCloud Keychain escrow route works today, with no second Mac and without disabling SIP.Changes
stek29/export-findmy(iCloud escrow → FindMy.py-compatible JSON) with steps. macOS 26 support in that tool is currently in Use native macOS anisette (AOSKit); fix export on macOS 26 (Tahoe) stek29/export-findmy#1.devices/,account.json,ani_libs.bin) so users following the steps don't accidentally commit private key material.Notes
Verified end-to-end on macOS 26.5.2 (Apple Silicon): exported an AirTag's keys via the escrow route and fetched a live location with
examples/airtag.py.