Data Recovery Case File · Milestone · The Keys and the Estate
Executor Access to a Late Parent's Mac: the Keys and the Estate
The seven hundredth case in this archive is not a technical frontier. It is a different kind entirely, and it is the one this library has been walking toward. "My dad died recently, very suddenly, and I am his executor. He had a small business which I am currently trying to tie up loose ends from. To do this, I need access to his computer and its hard drives. My dad was very security conscious and used Keychain Access, not just regular keychain, and as a result I have not been able to access any of the files and applications I need. I have already exhausted every avenue that I know of. I eventually spoke to someone in the Apple shop, who advised that there was nothing they could do, and suggested I try data recovery." Three external drives and his MacBook Pro. And then, disarmingly: "sorry for the long intro, I just wanted to make sure you had a picture of the situation." She should not have apologised. The context is the case — because for the first time in seven hundred files, the question is not whether the data can be read. It is whether it may be, and who says so.
| Media | A late owner's MacBook Pro and three external hard drives — account credentials and keychain contents unavailable to the estate; business records required to wind up the affairs |
| Reported situation | Sudden bereavement; enquirer is the appointed executor · account and keychain protection preventing access · manufacturer unable to assist and referring onward · business obligations outstanding |
| Fault class | No device fault — an authority and credentials case: lawful entitlement established by documentation, with access governed by whether credentials exist rather than by technique |
| Equipment used | Authority verified by documentation before any examination · external drives imaged write-blocked and assessed independently (Atola TaskForce 2) · Mac volume examined for encryption state · Passware Kit Forensic used strictly with lawfully-held credentials · findings and limits issued in writing throughout |
The decode: authority first, then keys, then what is actually reachable
Why authority comes before any technical question: a request to open a deceased person's computer is, on its face, indistinguishable from the most sensitive request this trade ever receives. The same words could be written by an executor with every legal right, or by someone with none. So the first step is not diagnostic — it is documentary: sight of the death certificate, and of the grant of probate or letters of administration naming her as executor, together with her own identification. That is not bureaucracy for its own sake, and it is not distrust of a grieving daughter. It is the protection that makes the service safe to offer at all: a laboratory that opens estates on the strength of a plausible story is a laboratory that will eventually open one for somebody who should never have been let near it. Verifying her authority protects her father's estate, and everyone else's.
What her authority does and does not do: the distinction at the heart of case 700, and it deserves stating precisely. An executor's authority is legal entitlement to the deceased's property, including the data. It is not a cryptographic capability. Being entitled to the contents does not conjure a password, and no court order compels mathematics. This is the point at which many people, entirely reasonably, expect the two to be the same thing — and they are not. Her entitlement means the work may lawfully be done; whether it can be done depends on something else entirely.
The keychain decode: what her father actually did. A Mac's keychain is an encrypted store of credentials, and it is protected by the account's login password. If the login password is known, the keychain opens with it and everything inside becomes available. If it is not, the keychain is not a lock to be picked — and if he also enabled full-disk encryption, the volume itself is sealed on the same principle. So the practical question is narrow and specific: does anyone know, or can the estate lawfully obtain, his login password? Written somewhere among his papers, held in a password manager the family can access, recorded with his solicitor or accountant. Where it exists, the machine opens and the work is ordinary. Where it does not, the honest answer is that his Mac stays shut — and this archive says so plainly rather than selling hope, because legitimately-held keys only is not a slogan here, it is the line that makes everything else trustworthy.
Why the three external drives matter more than they look: and this is the practical hope in her situation. External drives are frequently unencrypted, or protected separately and less thoroughly than a security-conscious person's main machine. In estate work they routinely hold exactly what is needed — invoices, accounts, client records, the working files of a small business — because that is what people back up. So the sensible order of work is the reverse of the obvious one: assess the three drives first, where the odds are good and the business records probably live, and treat the Mac as the harder, later question. An estate can very often be wound up without the machine ever opening.
On the bench
Authority was verified before a single device was examined, and the sequence was explained to her in writing so that nothing felt arbitrary. The three external drives were then imaged write-blocked on the Atola TaskForce 2 and assessed independently — their encryption state established, their contents catalogued, and the business records she actually needed identified and extracted first. The MacBook's volume was examined separately to establish its encryption state and what credential would open it, so that the position could be stated exactly rather than guessed: what existed, what was reachable, and what would remain closed unless a password came to light. Where lawful credentials were available, decryption ran through Passware Kit Forensic against those credentials and nothing else. Everything was reported in writing, including the limits.
The outcome — and the volume closes
Authority verified, the external drives imaged and the business records recovered and delivered, and the machine's position stated precisely in writing rather than left as a hope. Free assessment, one fixed written figure including VAT, and terms stated plainly before any work — the same as the six hundred and ninety-nine cases before it. And Volume Fourteen closes on the question this milestone finally names. At case 550 the archive praised a shop that knew not to touch a failing drive. At 600, two shops that tried, met their ceiling and pointed onward. At 650, a chain of institutions each doing its job correctly while the data question belonged to nobody. Here, at 700, the question changes shape entirely: not can it be read, but who is entitled to the answer — and the discovery that entitlement and capability are two different things that people assume are one. She had the legal right to every byte her father left and could not open a single file, because he had been careful in exactly the way we all tell each other to be, and had left no way for the person who would need it most. That is the lesson worth carrying out of seven hundred case files: security without succession is a locked door with the key inside. If you use a password manager, set up its emergency access. If you keep credentials in your head, keep one copy somewhere your executor can lawfully reach. Tell the person who will have to wind things up where to look. It costs an afternoon, and it spares somebody — as it did not spare her — the discovery that being entitled to something is not the same as being able to open it. She apologised for the length of her introduction. It was, in the end, the most important part of the enquiry.
Winding up an estate and locked out of the devices
Start with the paperwork rather than the technology: any reputable lab will need the death certificate, the grant of probate or letters of administration naming you, and your own identification before examining anything — and you should be wary of one that does not ask, because the same protection that slows you down is what stops your relative's estate being opened for somebody else. Then understand the distinction that catches almost everyone: your authority is legal entitlement to the data, not a cryptographic key. Where a password exists you can lawfully obtain, the work is ordinary; where none exists anywhere, encryption is a genuine wall and you should expect to be told so plainly. Hunt for credentials before spending on technique — papers, safes, a password manager the family can access, the solicitor or accountant. And do the external drives first: they're often unprotected and usually hold the business records you actually need, so an estate can frequently be wound up without the main machine ever opening.
Bring the paperwork — call Leeds Data Recovery on 0113 322 3083; authority verified first, drives imaged write-blocked, lawfully-held credentials only, and the limits stated in writing.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.