Data Recovery Case File · Mac & Apple Systems · The Drive May Need Its Machine
Storage That Encrypts to Its Host Does Not Travel Alone
His enquiry contains a detail whose importance is easy to miss. A machine whose drive was faulty, where a repairer "replaced the faulty drive but could not access the data due to restrictions on their equipment" — and where he now holds the old drive externally and has had the machine repaired. On many machines of this kind the storage is encrypted to the computer itself, so what happened to the machine after the drive came out may matter a great deal.
| Media | Solid-state drive removed from a desktop Apple machine — held externally following replacement; original machine subsequently repaired |
| Reported situation | Machine developing a drive fault · repairer replacing the faulty drive · repairer unable to access the data citing equipment limitations · original drive retained and held externally · machine repaired subsequently · content sought |
| Fault class | Drive removed from a host that may hold its encryption key — content potentially uninterpretable without the original machine's hardware; repair history of that machine determinative |
| Equipment used | Host-bound encryption assessed before any extraction approach was chosen · repair history of the original machine established · drive imaged write-blocked at the block level regardless of interpretability · volume structures examined for encryption in use · content decrypted with the original machine's hardware where required |
The decode: what the machine may have been holding, and why the repair matters
What many machines of this generation do: encrypt their storage as a matter of course, with the key held in dedicated hardware on the machine's own board rather than on the drive. The drive holds encrypted content and not the means of reading it, and the pairing is normally invisible because the two are always together.
Why that changes what removing a drive means: the drive taken out of such a machine is a set of encrypted blocks. Read on any other equipment it yields nothing interpretable, however healthy it is — which is very likely what the repairer meant by restrictions on their equipment.
Why that phrasing is worth translating: it sounds like a limitation of their tools and is more often a property of the system. No ordinary equipment reads a host-encrypted drive without its host, so their inability was not a shortfall on their part.
Why the repair to the machine is now the critical question: if the board carrying the key was replaced, the key went with it. A repaired machine with a new board is not the machine that encrypted the drive, and the pairing is broken permanently.
What needs establishing before anything else, and it costs nothing: what the repair involved. A replaced drive alone leaves the key intact; a replaced board does not — and the repairer's record of the work answers it.
Why the original machine should not be treated as disposable: if the key is still on it, that machine is part of the recovery. Reuniting the drive with the computer it came from is the route, and it is straightforward where the hardware is unchanged.
Why the drive is imaged regardless: a block-level image captures the encrypted content exactly as it stands. Interpretation is a separate question that can be answered afterwards, and capturing first means the drive is read once and set aside whatever the outcome.
Why it is worth checking whether encryption is actually in use: not every configuration encrypts, and some machines of this era do not. Examining the volume structures establishes it immediately, and if the content is unencrypted this becomes an ordinary recovery.
What the honest position is if the key has gone: the content is not recoverable. Encrypted blocks without their key are not a difficult problem, they are an impossible one, and that should be established quickly rather than pursued.
What must not happen meanwhile: no formatting or initialising the old drive, and no further repairs to the original machine. Until the key question is settled, that machine may be the thing this depends on.
On the bench
Host-bound encryption was assessed before any extraction approach was chosen — machines of this class encrypting storage with the key held in dedicated hardware on the machine's board rather than on the drive, so a removed drive presents encrypted blocks uninterpretable on other equipment regardless of its health. The repair history of the original machine was established, board replacement severing the pairing permanently. Imaging ran write-blocked at the block level regardless of interpretability.
The outcome
Host-bound encryption assessed before any approach was chosen, the machine's repair history established, and the drive imaged regardless. Free assessment, one fixed written figure including VAT; where a chip has to be removed, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: the repairer's equipment was probably not the limitation. Many machines of this kind encrypt storage with the key on the machine's own board — so what the repair replaced is now the question that decides this.
A drive removed from a machine that has since been repaired
Find out exactly what the repair replaced before anything else, and don't have the original machine worked on further meanwhile. Many machines encrypt their storage with the key held in hardware on the machine's own board rather than on the drive, so a removed drive is a set of encrypted blocks that no equipment reads without its host. If the repair replaced only the drive, the key is intact and the original machine is part of the recovery. If a board was replaced, the pairing is severed permanently. That's also usually what "restrictions on our equipment" means — a property of the system rather than a shortfall.
Check what was replaced — call Easy Data Recovery on 028 9002 0144; host-bound encryption assessed before any approach is chosen, repair history established, drive imaged at the block level regardless.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.