Description
Saving sensitive files with .noFileProtection, FileProtectionType.none, or NSFileProtectionNone does not apply access protection based on the user's passcode and the device's lock state. This class still encrypts files using the device UID, so it does not mean that files are stored as plaintext on disk. However, it weakens the protection that restricts file access while the device is locked or immediately after boot.
Potential impact
- Exposure of stored sensitive information.
- Data disclosure through backup or device extraction paths.
- Increased risk of file access on a lost or stolen device.
Remediation
- Store sensitive files with
.completeFileProtectionor another strong protection class appropriate to your requirements. - Do not set the protection class to
FileProtectionType.noneorNSFileProtectionNonethroughFileManager.setAttributes. - If background access is required, select the most restrictive protection class that supports it and store sensitive values in Keychain.
Examples
Before
swift
try data.write(to: url, options: .noFileProtection)
After
swift
try data.write(to: url, options: .completeFileProtection)
Explanation:
- Before: The file lacks passcode-based protection, weakening protection while the device is locked.
- After: A strong file protection class protects the stored data.