![]() |
| This is scary - where's my data ? |
Background
Time Machine
Data needs to be backed up and as a long time user of Time machine I rely on it for backup services. It's not the only backup I do but these are automatic and regularly saved to an external NAS storage box. Time Machine does a synthetic back up creating a new disc image that contains the entire contents of the drive based on the previous entire contents of the drive. In essence it just saves the data that belongs to new files but retains pointers to the data for older files. When restoring data the backups can be accessed either through a GUI mechanism, where you look back through previous folder listings, or by browsing the historical disk images. The crucial mechanism is that pulling a file from one of the backups should return the entire contents of that file and its attributes in the way that it was when the backup was run.So what went wrong ?
![]() |
| What should be seen when opening a password encrypted Excel document. Top version when open in Excel, bottom version when using finder "Space bar to sample" view. |
What's in the backups ?
clive@BBComp Special measures % file */*
2024-0105-225736/DoshNsav_Trackers_piv.xlsx: CDFV2 Encrypted
2024-0105-225736/DoshNsav_pivZ.xlsx: Composite Document File V2 Document, Cannot read short stream
2024-0105-225736/FinanceDocs_2024-0105-225736.sparseimage: data
2024-0201-071633/DoshNsav_Trackers_piv.xlsx: CDFV2 Encrypted
2024-0201-071633/DoshNsav_pivZ.xlsx: CDFV2 Encrypted
2024-0201-071633/FinanceDocs_2024-0201.sparseimage: data
2024-0303-085151/DoshNsav_Trackers_piv-2024-0303-08515_OK.xlsx: Microsoft Excel 2007+
2024-0303-085151/DoshNsav_Trackers_piv.xlsx: CDFV2 Encrypted
2024-0303-085151/DoshNsav_pivZ.xlsx: CDFV2 Encrypted
2024-0303-085151/FinanceDocs_2024-0303-08515.sparseimage: data
2024-0314-153641/DoshNsav_Trackers_piv.xlsx: CDFV2 Encrypted
2024-0314-153641/DoshNsav_pivZ.xlsx: Apple Desktop Services Store
2024-0314-153641/FinanceDocs-2024-0314-153641.sparseimage: data
2024-0320-065313/DoshNsav_Trackers_piv.xlsx: CDFV2 Encrypted
2024-0320-065313/DoshNsav_pivZ.xlsx: Apple Desktop Services Store
2024-0320-065313/FinanceDocs_2024-0320-065313.sparseimage: data
2024-0324-011945/DoshNsav_Trackers_piv.xlsx: Apple Desktop Services Store
2024-0324-011945/DoshNsav_pivZ.xlsx: Apple Desktop Services Store
2024-0324-011945/FinanceDocs_2024-0324-011945.sparseimage: data
2024-0327-134121/DoshNsav_Trackers_piv.xlsx: Apple Desktop Services Store
2024-0327-134121/DoshNsav_pivZ.xlsx: CDFV2 Encrypted
2024-0327-134121/FinanceDocs-2024-0327-134121.sparseimage: data
2024-0331-214023/DoshNsav_Trackers_piv.xlsx: Apple Desktop Services Store
2024-0331-214023/DoshNsav_pivZ.xlsx: CDFV2 Encrypted
2024-0331-214023/FinanceDocs_2024-0331-214023.sparseimage: data
2024-0401-211118_MMlast/DoshNsav_Trackers_piv.xlsx: Apple Desktop Services Store
2024-0401-211118_MMlast/DoshNsav_pivZ.xlsx: CDFV2 Encrypted
2024-0401-211118_MMlast/FinanceDocs-2024-0401-211118.sparseimage: data
2024-0402-082024_BBCFirst/DoshNsav_Trackers_piv.xlsx: Apple Desktop Services Store
2024-0402-082024_BBCFirst/DoshNsav_pivZ.xlsx: CDFV2 Encrypted
2024-0402-082024_BBCFirst/FinanceDocs_2404-0402-082024_BBCFIRST.sparseimage: data
2024-0415-000021/DoshNsav_Trackers_piv.xlsx: Apple Desktop Services Store
2024-0415-000021/DoshNsav_pivZ.xlsx: CDFV2 Encrypted
2024-0415-000021/FinanceDocs_2024-0415-000021.sparseimage: data
BBComp % strings 2024-0402-082024_BBCFirst/DoshNsav_pivZ.xlsx| head
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<encryption xmlns="http://schemas.microsoft.com/office/2006/encryption" xmlns:p="http://schemas.microsoft.com/office/2006/keyEncryptor/password" xmlns:c="http://schemas.microsoft.com/office/2006/keyEncryptor/certificate"><keyData saltSize="16" blockSize="16" keyBits="128" hashSize="20" cipherAlgorithm="AES" cipherChaining="ChainingModeCBC" hashAlgorithm="SHA1" saltValue="cfDF3XFob
T&,9
"&Z#
ae+B
'd/#
[)ps
Yjx5<
Y!
b
1Bi2
For one of the broken file:
BBComp % strings 2024-0402-082024_BBCFirst/DoshNsav_Trackers_piv.xlsx| head
Bud1
nIlocblob
gIlocblob
smodDdutc
sdsclbool
slsvCblob
Bbplist00
WXWY
[XiconSize_
showIconPreview_
calculateAllSizesWcolumns_
BBComp %
Further investigations
![]() |
| Disk First Aid showing errors within the directory structure that were repaired |
![]() |
| Disk First aid - a clean run |
% file /Volumes/PoundsDocsClive/Dosh*
/Volumes/PoundsDocsClive/DoshNsav_GameOver.xlsx: CDFV2 Encrypted
/Volumes/PoundsDocsClive/DoshNsav_May_2017_Copy.xlsx: CDFV2 Encrypted
/Volumes/PoundsDocsClive/DoshNsav_Trackers_piv.xlsx: Apple Desktop Services Store
/Volumes/PoundsDocsClive/DoshNsav_old.xlsx: CDFV2 Encrypted
/Volumes/PoundsDocsClive/DoshNsav_pivZ.xlsx: Apple Desktop Services Store
/Volumes/PoundsDocsClive/Dosh_Nasdaq_Pivot.xlsx: Microsoft Excel 2007+
Who needs to fix this ?
That's an interesting question and during my career in tech support I have been caught between vendors each of which say the problem belongs to the other one. For me there needs to be some kind of mechanism to see and or change the type category of the file to ensure that Excel will open them as an encrypted/password file if they are an encrypted/password file. I understand that Microsoft has used a number of different encryption schemes for their spreadsheets. Somehow coordination has been lost with the file type handling in time machine.Personally I would would love to help but I bet if I phoned up either tech support team they would say please send over your files and the passwords used and be honest because this is personal financial information that's not gonna happen. The other way is to re-create the problem, but I'm sure that would take quite a while to find the edge condition in historical backups that is causing this problem.
- This is a classic case of data corruption at the file level. The data at the start of the Excel file has been over written by data that should be in the .DS_Store file.
- It's very hard to spot when such data corruption has occurred as there is no external visible marker (except in this case the unix file type). The problem only becomes apparent when the Excel file is opened.
- I suspect, but I cannot prove that the file did not self repair or become unbroken but that I recovered it from back up after sensing some corruption within the file.
- Some file types are identified by the dot3 or four letters on the end others are identified by data markers within the file. Excel appears to use a combination of both to identify whether a file has a password encryption or not. In this case, corrupted contents of a spreadsheet prevented from being opened.
- What's needed now is a script that reliably recreates the issue.
- I logged this as a support case with Apple but unless I can recreate the issue easily - not much chance it will progress being that it occurred on previous machine.
- AAAARGH lucky I have backups and know how to use them.
- Read more about .DS_Store files and some of the problems they cause here.















