Don’t format a drive of M1 Macs from recovery mode
giuliomagnifico.medium.com
giuliomagnifico.medium.com
This isn't new with the M1 Macs. This has been a thing since they introduced APFS. When they went into disk utility after the cli - Then they could delete everything and kick off the OSX Install.
If the APFS Volume Group still exists the installer will try to unencrypt and work with it. So.. In short, just make sure you delete the volume group. There's a specific button for it. I just did this yesterday on a T2 Mac.
> There's a specific button for it.
Does the button say "hi, you should pick this unless you're an expert with a really good reason not to?"
Why does the recovery not just have a button called factory reset which unlinks your apple account, deletes the volume and then sets it all up like new.
Of course this only works if you need access to the account to break this link.
"Why does the recovery not just have a button called factory reset which unlinks your apple account, deletes the volume and then sets it all up like new."
So yes, it currently does not work like that. But such a feature would allow Macbooks to be easily stolen and reused by others.
But we couldn’t figure out what they were talking about, we had reinstalled the OS. It’s embeded in there somewhere deep.
If we're not looking at the root of the problem, then we're just complicating legitimate use cases. Preventing theft is only the official argument, but it doesn't stand any form of scrutiny: as long as there's inequality (i.e. incentives to expropriate people who have too much, to serve people who have too little) there will be theft.
The truth behind iCloud lock is Apple has been involved in mafia-style dealings with national mobile phone operators (which involved promises/contracts to sell millions of units), inundating the market with operator-sponsored iPhones, and they really don't want a second-hand market at all because they are a luxury brand.
Apple investigated for "planned" obsolescence by the French government: https://www.bbc.com/news/world-europe-42615378 (they have also settled for 500M$ in a previous case)
Apple was condemned and fined for illegal clauses in France in contracts with national cellphone operators (i believe the 4 of them):
https://www.universfreebox.com/article/34513/Apple-accuse-d-...
Specifically, they were condemned for:
- forcing the operator to buy a minimum amount of devices over 3 years - preventing the operator from defining target prices - forcing the operator to give funds to a marketing agency affiliated to Apple - forcing the operator to finance the marketing of iPhones in store, mandating a minimal marketing budget - enabling Apple to use the trademarks of the operator, but not the other way around - imposes strict conditions for device orders, but lifts any responsibility on Apple's side - forces the operator to financially support device repairs - gives Apple the right to break said contract, without respecting legal delays - enables Apple to use patents from the operator
Some of this was covered on public television by "Cash Investigation", so that was quite a public outcry. But this is only for France, and i'm assuming such mafia-like practices are common in other countries, as they are common in different branches of industry (not just IT, where well-known example include Microsoft and Intel).
About the consequences for the environment and (lack of) recycling of electronic waste:
https://www.cnet.com/news/the-environmental-pitfalls-at-the-... https://techhq.com/2020/12/right-to-repair-combating-techs-d... https://www.vox.com/2017/11/8/16621512/where-does-my-smartph...
About Apple not wanting a second hand market, i obviously meant a second hand market they do not control. They do have certified programs for second hard hardware. Sorry if that was not clear.
I hope i've provided enough evidence of the facts i was presenting. Please let me know if that's not the case.
For legitimate second-hand sales, Apple even has a page on their website to explain how to check for activation lock before buying a phone, and how to disable it before it's sold or given away: https://support.apple.com/en-us/HT201365
So just stop with your crap. You believe you're some kind of Robinhood or whatever, and want to be able to steal shit without consequence. Guess what, the vast majority of people don't want their shit stolen and are happy that Apple makes your "job" harder.
No, i'm refering to the actual second-hand market, eg. second-hand stores and open markets, where a lot of less-privileged folks do their shopping anyway. In there, stolen hardware represents a tiny minority of the tons of devices, but it's still a reality.
Even hardware donated in good faith is sometimes locked. Sometimes, it's possible to find the original owner and have them unlock their device. Sometimes, this person who gave away an old phone to a local association, a "ressourcerie" or sold it for a very low price to a second-hand shop cannot be found again.
Sometimes, you find them but they have forgotten the code to a device they haven't used in years. When it's not an iPhone (think laptop), we just setup a new OS and the device is good to go for another few years. When it's an iPhone, we're left with a brick.
> So just stop with your crap. (...) Apple makes your "job" harder.
This kind of personal attack is not okay. You are assuming things that are entirely untrue based on my political opinions ("property is theft"). I do not sell anything, and i certainly do not steal iPhones, whether for money or for fun. i am a free-software person and i have avoided apple for years because of the reasons we are discussing in this thread. No economic incentives in it for me, i'm just criticizing Apple for being user-hostile, in a way that particularly affect the poorest people who rely on second-hand devices because they can't afford brand new ones.
If someone wants to sell a device second hand it's pretty easy to voluntarily wipe your device. Apple devices have very long lives, receive software updates for much longer than competing devices and keep their second hand value very well and so make excellent and very economical second hand devices. Contrary to your claims of Apple not wanting a second hand market, they support the device wiping process and even have a trade in program that channels refurbished iPhones to 3rd world countries.
If you really do care about the environment and supply chain ethics, you'll also be happy to know Apple get the highest score of any of the big tech companies from Greenpeace. In fact the only tech company at all that beats them is Fairphone, but since they get only 2 years of updates I think Greenpeace doesn't sufficiently take into account device longevity.
True in most cases, but not when it comes to owning a recent iPhone. Millions of people struggle for eating decently, and most of these folks are certainly not spending >500€ on a phone.
What may not have been clear in my original comment is most users who have a stolen device don't have knowledge of it, and are not complicit in it. So why do they have to be the ones paying the price?
> If someone wants to sell a device second hand it's pretty easy to voluntarily wipe your device.
In my experience, it's not uncommon that neighbors seek support because a relative offered them their old phone willingly but are far away and unable to remember their password over the phone. Sometimes, it's a phone/account they had not used in years. I've encountered this situation at least twice in the past year, and i'm not even working in a computer/phone shop.
> Fairphone, but since they get only 2 years of updates I think Greenpeace doesn't sufficiently take into account device longevity
Fairphone only supports updates for 2 years, but there's a growing ecosystems of distros targeting the Fairphones (LineageOS, /e/, PostmarketOS), while Apple have been condemned for pushing updates that made iPhones slower (to encourage them buying new ones).
What price?
The original price of the device? Because we all do.
Or the price of having to buy a different machine than the $200 MacBook from the shady person online which came without the original box, warranty or charger? For the same reason, and also because they're stupid.
The price of having to pay a shady black market of "icloud unlocker" (usually through legit phone stores) to unlock of phone they have already paid for in good faith.
> the $200 MacBook from the shady person online
It's not just an online thing, and the person doesn't have to be shady (they're usually just a middleperson who have little clue). You can find questionable hardware in most open markets and second-hand shops.
> without the original box, warranty or charger?
Most second-hand hardware i purchase from legit sources comes with at least two of those missing (when not three) out of three.
> also because they're stupid.
I agree it's stupid to purchase a device you have no idea how to access/use/unlock. But i strongly disagree that good-faith people, who genuinely paid for an Apple device (after being advertised into thinking they need one), should suffer because of a lack of judgement on their part.
There are over a billion iOS devices active right now, are all of those people rich exploiters who deserve to have their phones stolen? What your saying isn’t anti-capitalist, it’s advocating disproportionate oppression of the most vulnerable in society and you should be thoroughly ashamed of yourself.
How dare you come here, advocate crime and criticise owners of devices with the highest recyclability, lowest ecological impact and longest device lifetimes in the industry on moral grounds.
I’m sure your perfectly aware of what the purpose of those software updates were, to extend device lifetimes when batteries start to fail, but you’re perfectly prepared to betray your ecological ideals which should be in favour of this in order to score points. It’s absolutely disgraceful. These arguments might work against people unaware of the facts, but you’re not going to get away with this disingenuous claptrap here.
Does your fridge come with FridgeID? Or a book? Introducing such mechanisms is really hostile to users, especially poorer users of second-hand hardware who have to go through extra (shady) hoops to get a device running just because some rich Silicon Valley start-uppers thought locking hardware down was a feature.
It's great that you have a niche use case, but that doesn't make your case the priority over the main use cases.
People would steal your wallet, your jewelry... There's a lot more value to be extracted from a stolen credit card than from a "smart" phone.
> It's great that you have a niche use case, but that doesn't make your case the priority over the main use cases.
You're taking it the other way around. The common use case for first-world software developers is the niche use case for the rest of the world. In the rest of the world (i.e. the vast majority), who can't afford buying new luxury devices, people are more concerned with getting locked out after forgetting their password (or after their kids changed it) or about acquiring a second-hand device, than about "protecting" their device from thieves.
Because this "protection" doesn't protect anything. Once your iPhone is stolen, it's gone. No iCloud lock is going to bring it back, so why prevent other, less-privileged folks from using it when you can't use it? That type of "mine or noone else's" capitalist mentality is actively harming users and destroying the environment
https://www.ifixit.com/News/34072/apples-activation-lock-wil...
These locked iPhones sold for 50-200€ are acquired by users who will turn to their tech friends/neighbors to get it unlocked. When these tell them they can't help with that (no package in Debian for that yet), they end up spending 20-50€ in a shop to get it unlocked anyway, financing a very shady market.
Previous discussion on HN: https://news.ycombinator.com/item?id=19845934
Quote from the article that sparked the discussion:
> To do this, they phish the phone’s original owners, or scam employees at Apple Stores, which have the ability to override iCloud locks. Thieves, coders, and hackers participate in an underground industry designed to remove a user’s iCloud account from a phone so that they can then be resold.
At the end of the day, if the thief doesn't get the phone unlocked themselves, they will sell the phone for half (or less) the price they would have sold it unlocked, but they're still making a buck.
Thieves will not profile a person using a premium locked phone against stealing it because it might not be worth it. They don't care about that. They will take whatever they can if only for practicing their skills.
Locking phones does not deter theft but unlocking them will offset the price of unlocking from the phone-shop to the thief increasing the profitability of theft.
I personally don't care about Apple, their phones, their M1's and their ecosystem. But acting out your premise leads to a place I don't like. And others as well. And if you think you can buy a cheaper premium phone if it is unlocked, ask yourself why thieves would continue to sell you cheaper if they know they give you a usable device?
Because I would like to inflict damage back. Stealing from me cause damage. I do not believe thieves should get a free pass on causing me damages just because they are less privileged.
Ideally, a small amount of C4 and a "remote explode" taking a few fingers off the thief would be a proper deterrent, as well as a good use of Sharia law.
For Apple, there is a different set of axioms and some people seem to agree with them.
I don't think this is true for all Apple products though, or at least that was not the case in the past. To my knowledge, setting up a free OS on a second-hand Macbook has never been a problem.
However, you are correct Apple is trying to impose new axioms with the iPhones: unique app market (taking controversial posture, such as forbidding alternative browser engines), iCloud lock, non-interoperable hardware (eg. power socket)...
That was not my point. Most times, users of a stolen device are unaware and not complicit in the fact it was stolen in the first place. They usually have acquired it from legitimate second-hand markets.
It's important to note that most people are incredibly gullible when it comes to technology, and they won't hesitate to buy a second-hand iPhone (whether stolen or not) for a few bucks assuming they'll be able to use it, because that's what a phone does, only to find themselves trapped in iCloud lock.
Locking devices does not protect users (contrary to encrypting the local storage), and does not deter anyone from stealing. It simply adds one layer of mafia to deal with (iCloud unlock shady companies) when you're just trying to find a second-hand phone.
"Similar to New York City, San Francisco also provides evidence that mobile device theft prevention technologies work. In 2009, Apple smartphones constituted the vast majority (69%) of smartphones stolen in San Francisco robberies; in the six months after Apple made Activation Lock available, iPhone robberies in San Francisco declined 38%."
This statement appears to be false, which I guess is the entire point.
People absolutely should be able to sell a device second hand, so perhaps re-authentication should be easier and more obvious, but making stolen equipment harder to sell is a net win.
https://support.apple.com/en-us/HT201065
I've found the process is fast if you have a good internet connection to download macOS again. Otherwise, that's where it seems a lot of the time goes.
If you have nvme storage use blkdiscard to wipe it:
https://man7.org/linux/man-pages/man8/blkdiscard.8.html
Or
nvme format <device> with the --ses option, see available ses options here:
https://www.mankier.com/1/nvme-format
Otherwise use ATA Secure Erase with the suspend trick to unfreeze the drive:
Suspending and waking a PC to unlock a drive can be necessary for SATA or NVMe drives. SATA drives also give you the alternative of hot-swapping the drive, but that's not practical for consumer NVMe drives or consumer host systems.
Boot into recovery, when it asks for a password say youve forgotten it, you don't have a key, and click the resulting "Erase Mac" button. This will erase the drive properly removing the partitions, iirc.
I'll grant that this is poorly documented and not intuitive in the least. A secure erase and reinstall is a common task. It shouldn't require an obscure menu bar option or the use of Terminal.
It should not be possible to brick a device by pushing the wrong button. I was shocked that this wasn't caught by anyone at Apple before release.
So you think all Apple devices should be shipped without root? Or that anything disk-related should only be allowed through CLI as root?
I thought any problem encountered reinstalling an OS is something I could handle. But that was not the case. Near as I could tell when I followed up with Apple after the incident, the boot process involved the security chip reading some data off the drive and validating it before handing off control. If that data (which is on the Apple reserved partition) was wiped, the firmware would not boot. And since the security chip was configured to not boot from media (the default state, IIRC), it was effectively bricked.
So the very first generation of TouchBar MacBooks would not boot into recovery mode if you wipe the drive, nor would they boot any kind of recovery media. It's a state that required shipping to Apple for refurbishment to fix. It's my understanding that this was fixed in later models, perhaps even as a result of my incident.
State is evil!
I’m not sure if it’s fixed now, but I don’t think it was related to the volume group.
https://support.apple.com/en-us/HT201065
To be honest I’m not 100% sure if the ‘sign out of iCloud’ also removes activation lock, but I do think so. They also refer to the steps in the Activation Lock article:
Even spend hours with apple support and nothing worked, there is more to it than just that.
Similarly you can get your disks in a state where the Windows installer can’t make heads or tails of it, so you need to just write zeros over the boot sector before Windows can install.
Recovery know I have OS installed, but because it's not installed the same way it no longer able to find credentials for authentification. And yeah I don't have second Macbook to properly factory reset it.
Along the way I stuck into 3 huge bugs and experience was terrible. Fortunatelly Apple support page actually show how to bypass it's bugs with command line magic which is easy for me as Linux nerd.
https://support.apple.com/en-us/HT211983
You even have to go through "Erase Mac" twice in process. It's only work if you reboot it properly after each time which is not mentioned on support page. Such a mess.
I remember a poster on HN saying that after some exploit for the T2 security chip came out, they were making money from being paid by thieves to use the exploit to wipe the devices.
Of course they said they don't ask any questions which as we all know is an iron clad defence lol
IIRC iPods were similar. Early on, people wearing white headphones were targeted by thieves.
https://twitter.com/braincode/status/1360117171842478081
Device enrollment prompts are indeed annoying :/
Instead with ARM you can’t mount the disk as an external drive. That’s why this mess started!
Here is what you need to know to actually understand these things:
The SSD has 3 partitions. Each partition is an APFS container. Each container contains multiple APFS volumes.
Your OS, and everything you care about, is on the second partition/container.
The first partition contains boot configurations. The third partition contains the One True Recovery OS (1TR), which includes the Boot Picker menu (that thing you get when you hold down the power button). These partitions form part of system firmware, think of them as part of UEFI/BIOS. Do not touch these. If you mess up those volumes, the only way to recover the machine is via Apple Configurator 2 from another Mac (DFU mode).
Disk Utility, the GUI, is broken sometimes. If something doesn't work properly there, ditch it and use the command line.
Both Disk Utility, the GUI, and diskutil, the CLI, will hide the first and last APFS containers from you to stop you from shooting yourself in the foot. They're still there, just hidden from the main listing. You can get info for them. Be careful with that.
To do OS reinstalls, you want to be in 1TR. This is not the macOS recovery. Hold down the power button and pick Startup Options from there. Then you can use diskutil (preferably the command line version). You should delete the whole APFS container (disk0s2 usually) corresponding to your install, which will contain multiple volumes. Re-create it as APFS. That will create a container with one volume. You can then install to it and the macOS installer will create all the other volumes.
Additionally, the SEP data is stored separately from the OS (in one of the volumes of the first container). To wipe that, after wiping the partition and before reinstalling, run `xartutil --erase-all`. I've never tried that myself, and I suspect it's not really required because a reinstall should start with a fresh store, but it's probably a good idea to try if you have authentication/user-related issues after reinstalling.
There is also OS recovery, which is the recovery instance that comes with an OS install. It looks exactly the same as 1TR, but it's not the same, and this is highly confusing. For any serious digging around, you want to be in 1TR. Booting holding down the power button will get you there, usually; after a failed macOS boot I've seen it go into regular recovery anyway. To be absolutely sure, boot into 1TR (holding down power, then startup options), then do a clean shutdown, and boot again the same way.
More info on what's on the SSD of these things:
I believe the "Erase Mac" function in Recovery Assistant also erases the SEP data, based on the output of `xartutil --list` before and after. If I'm correct about that, going through Recovery Assistant should be the recommended way to fully erase an M1 Mac (short of a DFU restore through Apple Configurator which also restores firmware).
On T2 Macs, `xartutil --erase-all` would wipe all SEP data, including the encryption keys used for the drive. In other words, it was the equivalent of a secure erase and was my recommended way to fully erase a Mac before resale. I suspect Recovery Assistant is just doing the equivalent of `xartutil --erase-all`, but I haven't tried `xartutil --erase-all` on an M1 because I'm afraid to brick the machine to the point of needing a DFU restore, and I don't have another Mac at hand to run Apple Configurator with right now.
> Boot environment requirements: software-launched macOS Recovery or 1TR.
The only way I know of to get to any recovery mode is by holding down the power button, which the man page says is 1TR (though I know you mention seeing that boot into regular recovery anyway).
It also answers my question about the distinction between OS recovery and 1TR:
> Note: Apple uses the term One True recoveryOS (1TR) to indicate a boot into the primary recoveryOS which is achieved using a physical power button press. This is different from a normal recoveryOS boot, which can be achieved using NVRAM or which may happen when errors occur on startup. The physical button press increases trust that the boot environment isn’t reachable by a software-only attacker who has broken into macOS.
[1] https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app...
I think the best bet, security-wise, if you really want to do a full/complete/total OS format/reinstall, is to boot external media, force zeroize all of disk0 (including 1TR), and use DFU mode to restore the .ipsw using Apple Configurator.
This is, of course, way more of a pain in the ass, and requires another computer, and internet access, but hopefully has the added benefit of leaving very little (really, the smallest amount practically possible without disassembly/extreme measures) persistent state on the machine from before the reinstall.
* boot external USB installer media
* run `diskutil zeroDisk force /dev/disk0`
* run `nvram -c`
* power system off
* system will now fail to boot anything, including external media, because it has no firmware available
* put system in DFU mode [1]
* plug in USB-C cable to the correct port (only one usb-c port can be used for this purpose) and connect to another mac running Apple Configurator 2 (which, sadly, is only available via the App Store, so requires an Apple ID, and also requires internet access to activate the attached M1 device)
* Restore IPSW such as [2] (note that this is for 11.2.0 and is no longer current as of a week or two ago)
This is the best way to get an M1 back into as close to a "factory" state as possible. Unfortunately, it requires an Apple ID (to use the App Store), so you have to dox yourself to Apple (email and working phone number, at the minimum) to get the Apple Configurator 2 app. (If anyone knows how to copy an App Store app from one mac to another, freshly installed mac, and have it work without logging in, please email me.)
PS: If you're looking to go even deeper, following the zeroDisk you might wish to create a 100% blank/empty hfs volume on the disk0, and then "repair" it, which will TRIM the free space (99%+ of the disk) at the disk controller level as well. This may or may not have the same effect as writing all zeroes. You'll likely have to use `diskutil` to do this, as Disk Utility is mostly garbage.
[1]: https://support.apple.com/guide/apple-configurator-2/revive-...
[2]: http://updates-http.cdn-apple.com/2021WinterFCS/fullrestores...
(shasum 7315f657df2a14b838b9d51eb49cdfff5be090e7)
The recovery OS and 1TR are not data needed to be saved permanently (as in serial number and such, without which you cannot restore the device), you can recover them through DFU.
Data critical for being able to restore is in the SPI flash. (and it's assumed that some of it might be in other NVMe namespaces too)
The only portable, reliable, robust way to accomplish this is wiping the drive. If the original author had issued a secure erase, they would not have encountered any subsequent difficulties, all of which were due to partially erasing the device.
That's setting the bar too high. If we're comfortable with solutions that will work on all mainstream PC platforms including Macs, then it is sufficient to overwrite partition tables with zeros. I have never heard of an OS installer that scans for deleted partitions, and worrying about the possibility of such a thing causing problems is unreasonable.
The most usual problem with your approach is recreating a set of partition tables exactly matching the old tables, while failing to wipe out a filesystem signature buried halfway into the disk. One reboot later, and magic header bytes start to be recognized as valid filesystems by whatever OS installer or BIOS utility you happen to be using. Even worse if you're been taking some hacky shotgun approach to blowing holes in the drive by zeroing out random sectors that belong to one of those recognized filesystems.
So once again,
> The only portable, reliable, robust way to accomplish this is wiping the drive
This is not remotely accurate. GPT is at the beginning of the disk, with a backup copy at the end of the disk. Wiping the GPT makes the layout of filesystem structures within partitions completely irrelevant. Wiping the primary GPT at the beginning of the disk is usually (possibly always) sufficient to make an OS installer believe the disk to be empty. The backup GPT at the end of the disk is something I've only seen used by manual partitioning tools that are more powerful and complex than the automatic partitioning tools that are part of OS installers.
> The most usual problem with your approach is recreating a set of partition tables exactly matching the old tables, while failing to wipe out a filesystem signature buried halfway into the disk. One reboot later, and magic header bytes start to be recognized as valid filesystems by whatever OS installer or BIOS utility you happen to be using.
Rebooting and re-detecting everything between partitioning and mkfs is not part of any ordinary OS installation procedure. Do you have any evidence that this failure mode can actually occur in practice with real shipping operating systems?
Remember, for the purposes of this hypothetical, we have to assume that at least one of the user or the OS installler is actually trying to make the process work. You can't assume that they're both trying to interfere with the process and are both going out of their way to cause problems.
At least Ext4 repeats the complete superblock at the beginning of every block group, so yes, it is not only remotely accurate, but entirely accurate. In the case of GPT, Linux requires explicit command line options to enable alternative GPT use, but do you know this is true for all systems in existence and all versions of Linux?
> Rebooting and re-detecting everything between partitioning and mkfs is not part of any ordinary OS installation procedure
Yes, I've personally bumped into this on desktop and unattended server installs - numerous times.
But you're externalizing the onus to prove cases where some hacky approach won't ever break when there is a vastly simpler way to avoid this entire class of problem. This is exactly the reverse of sound logic -- I'm offering you concrete real world examples of why you should avoid the hack and you're simply ignoring them
At this point I'm considering this not only to be offering up worst-practice advice, but actively trolling. Possibly the worst case of "a little knowledge is dangerous" I've seen recently. Regards
Name and shame, please. Because your spurious complaints about SSD write endurance haven't exactly established your credibility, and you do otherwise seem to be postulating that non-standard nonsensical actions will somehow insert themselves into the process under discussion.
> I'm offering you concrete real world examples of why you should avoid the hack and you're simply ignoring them
No, you're not offering any concrete real-world examples. You're offering hypothetical examples of how a malicious user might be able to trip up a non-specific hypothetical automated OS installer.
> At this point I'm considering this not only to be offering up worst-practice advice, but actively trolling. Possibly the worst case of "a little knowledge is dangerous" I've seen recently. Regards
You are the one who called something "bad advice" but three comments later have yet to prove that it could ever fail in practice. I'm not trolling, and I'm not saying that a dd to the first 1GB of a drive is the best way to clean a drive. I'm just taking exception to your unfounded claims about what "could" go wrong.
It's back to the Apple Store for you.
While architecturally simpler (and probably more secure by allowing the network stack to be removed from the low-level boot infrastructure?), the disadvantage is that you can mess up the 1TR partition. If you do, the only way to recover the machine is to do a DFU restore from another Mac via Apple Configurator. That's not terribly convenient if you don't have another Mac around. (An Apple Store can DFU restore for you, but last I checked Apple Stores are appointment-only due to COVID and it's almost impossible to get an appointment there these days.)
That's up for debate due to certificate expiration issues, isn't it?
The SSD on these Macs contains system firmware, including the boot picker and recovery mode. Do not wipe the entire top-level block device. They cannot boot from external media, by design.
M1 Macs are not PCs, and you shouldn't blindly apply whatever you think you know from the PC world. Their low-level design is much closer to an embedded device like a Raspberry Pi, minus the SD card slot. https://github.com/AsahiLinux/docs/wiki/M1-vs.-PC-Boot
It's hard to truly brick these things (you need to wipe NOR flash for that, and even then Apple can fix it without taking them apart, but you can't, because if you wipe NOR flash calibration data is gone and it has to go back through part of the manufacturing test process), but wiping the entire SSD isn't going to help you. If you start messing at that level, you'd better be prepared with another Mac and Apple Configurator 2 to get a proper clean start.
...or like a iPhone.
From that article you linked:
Some PC motherboards implement a similar feature as part of a separate chip, which can flash the UEFI firmware from a USB stick without actually turning on the motherboard normally, but this is only common in higher-end stand alone motherboards.
That might be referring to boot-block recovery, and I haven't seen any with a "separate chip" besides the dual-BIOS type; it's in the same flash (just a normally write-protected part) as the rest of the BIOS. The older ones will look for a flashable ROM image on the first floppy drive, but I'm not surprised if the newer ones will do it with USB instead.
Because modern bios flashback does indeed read from the USB and write to one of the bios chips without even the CPU in place. Obviously there is some form of micro-controller performing this.
On intel, I suppose it would be possible for the management engine CPU in the chipset to do this, but I doubt intel lets motherboard makers run custom code on that, so if it is not some standardized feature, it could not be that. On AMD Ryzen, I'm not aware of a CPU in the chipset.
This all makes me think there is some other microcontroller somewhere that controls the bios flashback process, which would almost certainly be an extra chip.
I believe they just have some sort of extra microcontroller wired to a USB port and the SPI flash chip that stores the BIOS, probably with some sort of switch to ensure the host can't touch the SPI flash when the external microcontroller is attempting to flash it.
> Nope, this don’t work as I suspected… so, let’s check online, Apple suggests a long procedure and a short by typing “resetpassword” in terminal, that was a chance but since it founds no users, there’s no passwords to reset.
"resetpassword" opens Recovery Assistant. Recovery Assistant is primarily intended to provide a "forgot password" flow, which is why it wants to identify a user. However, in the app menu bar, there is an option called "Erase Mac." That is how you do a full secure erase of an M1 Mac. It will work without any user, and even without any OS install at all. (I have tested this myself by erasing a machine multiple times without reinstalling the OS.)
I like Macs having iPad-like performance, but I don't like the boot process is so locked down that it reminds me this computer belongs to Apple, not me.
I have no time to go through the thorns and landmines over incompatible systems or buggy system software tools from Apple as described by the blog post.
Again, I will wait until the software on Apple Silicon is mature and the developer ecosystem catches up to it which by then I'll be getting an M2 or M3 based Mac.
I was able to fully erase and install OS X from recovery 5 times. My biggest issue was time machine. I opened a support ticket and they took a bunch of logs.
It's also much quicker than Windows 10's "Reset this PC" functionality, which doesn't work at all if the OS or firmware is hosed.
I got stuck with almost the same issue even though I'm system administrator and programmer with decade of experience. I can't imagine how all this mess should feel for average Mac or Windows user.
This works from the GUI Disk Utility too, usually, though that tool is flaky sometimes. It definitely works from the command line.
Compare: this is like wiping boot, system, data, and vendor on an Android phone. You wipe the whole OS and user data. You do not wipe the bootloader and other partitions (because if you did, you'd brick the phone). This is as much of a "factory reset" as almost anyone will ever need.
If you really want to wipe the whole drive, you need Apple Configurator 2 and another Mac to re-install, as the machine is then unable to boot in anything except DFU mode if you wipe the system containers. Unlike Android phones though, this is supported by Apple, so you can't in fact brick these Macs like that - just be aware that this option does (currently) require another Mac to do the re-install.
Reminds me of the endless reinstalls I had to do of windows back in the 2000s and the anxiety of it all working again once it was back running. So glad that isn't necessary anymore.
You could fix it by hand or you could do a fresh install - which would also wipe out any errant startup programs, etc.
I genuinely still have my 25 digit windows 98 license key memorised from having to reinstall it so many times.
Just asking for a friend.
Every MacOS update is a minefield. We have a dedicated Slack channel at work where people discuss if they dare to upgrade yet, and share which software now is breaking on their computers, warning others to wait.
So this arrived in September 2020. What I want to know is if normal Apple users, i.e. not programmers, whether they can benefit from webP images yet, when using the default Safari browser.
I have no idea in this pandemic about basic things.
P.S. T2 Macs are actually the most difficult to restore to the latest OS sometimes. The installer is anal about asking local password, booting from external USB, etc. and you might end up having to go through internet restore once and then upgrade the OS. M1 is actually an improvement and simplification from clean OS install perspective.
If an issue takes less than 5 different attempts to resolve and under 1-2 hours to fix, that can't really be called painful, merely annoying. Especially when it's only a one-time problem.
If your bar is "It just works", then for me at least, if it takes me more than 1 minute I'd describe it as painful. My mother would describe anything that's not immediately obvious as painful.
When the resolution means that you need another Mac at hand it is not merely annoying if you don't.