Does external SHA‑256 hashing combined with NSSecureCoding guarantee complete and tamper‑free restoration of NSKeyedArchiver backups?
28K reputation · 07 Jun 2023, 12:17 UTC
The goal is to confirm that a backup restored from NSKeyedArchiver is both free of tampering and semantically complete when the archiver is configured with NSSecureCoding and an external SHA‑256 hash is used to verify the archived bytes. The constraints are that NSKeyedUnarchiver’s version‑tolerant decoding will silently set missing properties to nil or default values when a newer class adds fields, and that NSSecureCoding only guards against unauthorized class substitution, not against alterations to the encoded data that keep the same class list.
Because the external hash detects any change to the NSData but cannot reveal whether the decoded object lacks expected properties, it is unclear whether the combined approach guarantees detection of all relevant failure modes. This raises the question of whether additional checks—such as version‑specific property validation or a custom checksum of the decoded object—are necessary to ensure both integrity and completeness.
Does the external SHA‑256 hash, when paired with NSSecureCoding, reliably detect both data corruption and silent property loss due to version mismatches? If not, what supplementary verification steps should be employed to confirm that restored objects contain all expected properties?