BitLocker on Mac: is it safe? Read-only explained
Short answer: yes. When a drive is opened read-only, your Mac can’t change anything on it. This guide explains what that means in practice, what Unbit does with your password and files, and a few habits that keep your data safe.
What “read-only” means
When a drive is mounted read-only, macOS can read files from it, but every attempt to write, rename or delete something is refused. Unbit attaches the unlocked drive to macOS as read-only, so nothing is written back – not to your files, and not to the drive’s BitLocker setup. The drive stays exactly as Windows left it.
In practice that means you can’t delete or overwrite anything by accident, and because nothing is being written, an unexpected unplug can’t leave half-written changes on the drive.
Why read-only is the safer choice
Writing to a drive that was formatted and encrypted by another operating system is where things tend to go wrong, especially with tools that aren’t made by Microsoft. Most people who plug a BitLocker drive into a Mac only want their files, and reading is enough for that. Read-only removes a whole category of risk.
If you need to change files on the drive, copy them to your Mac, edit them there, and update the drive from Windows.
What Unbit does with your password and files
- Decryption happens entirely on your Mac. Your password, recovery key and files are never sent anywhere.
- The app has no accounts, analytics or tracking. The only thing it fetches from the internet is its daily update check.
- Your password is stored only if you tick “Remember this drive on this Mac”. It is then saved encrypted in your macOS keychain, and you can forget it at any time.
- No kernel extensions and no macFUSE. Unbit uses the disk image support already built into macOS.
- Only the parts of the drive macOS actually reads are decrypted, as they’re read.
- Unbit is signed with Developer ID and notarized by Apple, and updates arrive through signed automatic updates.
Why Unbit asks for Full Disk Access and your Mac password
To decrypt a drive, Unbit has to read the raw, encrypted data straight from the external drive. macOS only allows that for apps with Full Disk Access, and Unbit uses it for the drive you choose.
Reading raw drive data also needs a small read helper, which you approve once with your Mac password (Set Up Read Access). Both are standard one-time macOS permissions, and you can remove the helper again from Unbit’s gear menu.
Habits that keep your files safe
- Use Eject Safely before you unplug the drive. If the drive is unplugged anyway, Unbit closes it automatically, but ejecting first is always better. Quitting Unbit closes an open drive first as well.
- Copy anything important to your Mac, and keep a second backup. Read-only protects the drive from your Mac; it doesn’t protect against the drive itself failing.
- Keep the password and the 48-digit recovery key somewhere safe. Without one of them nobody can open the drive.
- If macOS ever offers to initialize or erase the drive, choose neither.
- Download Unbit only from its official website or its GitHub releases page.
What read-only doesn’t do
Read-only access doesn’t repair a damaged drive, recover deleted files or tell you whether a drive is about to fail. If you see read errors, copy what you can and check the drive on a Windows PC.
Unbit is an independent app and isn’t affiliated with or endorsed by Microsoft or Apple.
Ready to try it? Follow How to open a BitLocker drive on a Mac.
Frequently asked questions
Can Unbit damage my BitLocker drive?
Unbit never writes to the drive, so it can’t change your files or the drive’s BitLocker settings. As with any storage device, a drive that is physically failing can still fail.
Is my password sent anywhere?
No. Decryption happens on your Mac, and your password, recovery key and files are never sent anywhere. The app’s only network use is its daily update check.
Does Unbit make a decrypted copy of my drive?
No. Unbit decrypts on demand: only the parts macOS reads are decrypted, as they’re read, instead of first making a full copy of the drive.
Do I have to lower my Mac’s security settings?
No. Unbit uses no kernel extension and no macFUSE, so there’s nothing to enable in Recovery. It needs Full Disk Access and a one-time approval of its read helper.
Is it OK to unplug the drive without ejecting it?
Eject Safely is best. If the drive is unplugged, Unbit closes it automatically, and because it’s read-only nothing is left half-written.