On macOS Tahoe and later, use the "secret enclave" to create and store the key securely, so it can't be exported. See: * https://gist.github.com/arianvp/5f59f1783e3eaf1a2d4cd8e952bb4acf * https://news.ycombinator.com/item?id=46025721