Remove Google Account After Factory Reset (2019)
support.google.com
support.google.com
This is a good thing. Combined with remote lock, it renders stolen devices useless.
Edit: More seriously, if they took this approach, people would regularly lose their codes, which would necessitate a backup means of obtaining it. Which would no doubt require the purchaser log into their Google account. And we're back at square one.
It might surprise you, but back before games where always online everyone had to keep track of license keys. Still have a box with all of them. Only those that required feedback from activation servers are now useless because the companies killed the servers.
Modern phones are closer to $1000.
(for single player games)
The Factory Reset process is defective. It SHOULD ask the user if they are selling, giving away, or otherwise disposing of the device; or otherwise just want to remove that device from their account.
I’m on iOS, so I can’t test this myself.
Of course it's not a good thing. What Apple can do to someone else at your request, they can do to you on their own initiative.
But they don't because they're all enormous companies with thousands of employees. The negative PR would be instant and overwhelming, and the sheer amount of staff would render trying to do it secretly, ineffective.
There is cautious, and there is paranoid.
This example is unlike the others; your credit card provider already buys everything that goes on your account. For that to make any sense, they'd need to convince you to pay them "back".
> But they don't because they're all enormous companies with thousands of employees. The negative PR would be instant and overwhelming, and the sheer amount of staff would render trying to do it secretly, ineffective.
And this is just untrue. Nobody even remembers Amazon retroactively deleting sold copies of 1984 from their customers' internet-connected Kindles. We're swimming in devices that the manufacturer won't let us access right now, but the PR hit from doing what they're already doing is too large for them to... continue doing it?
That's why it's called a "credit" card.
The credit card issuer doesn't appear in the vendor's accounting system, they count the payment as having been made by the customer purchaser. It is only for relatively limited purposes (ones that approximately no one ever thinks about) that the credit card issuer is considered the payor. The merchant vendors generally don't care, don't know, and don't record. As if they are going to care whether the customer uses a Capital One credit card or one issued by his or her local bank.
I do. And the answer to "Am I the only one who..." is always "no".
Hell, it's even on Wikipedia:
https://en.wikipedia.org/wiki/Amazon_Kindle#Removal_of_Ninet...
My personal opinions on this:
Factory reset should mean 'just like when it came out of the factory brand new'. So no hidden keys, certificates, connections, locks or other dependencies. Either change the definition or do not call it factory reset. If people will not be able to factory reset a device, please explicitly state so in the TOS.
Rendering stolen devices useless may be a good thing security wise, but it is horrible for things like the ability to recycle and reuse. There are tons of procedures to make pretty sure devices are wiped completely from any sort of data. Why is this not enough?
I have had to destroy thousands of devices that could have a happy second (completely unsupported and no warranty whatosever) life at various projects. I'm not proud of it.
It sucks, but it's not enough because it doesn't remove the incentive to steal the device in the first place. If you want someone to plonk down $2k for a fancy phone, you'd better be able to (a) convince them that they'll be able to re-sell it for a good chunk of that amount, and (b) at the same time reassure them that there's no point anyone stealing their expensive new toy, which means they aren't just painting a giant target on their head.
If the thousands of devices you mention were legitimately obtained, why were they locked with account credentials that you didn't have? Or were they recovered from dumped recycling or something?
Nevertheless valid points indeed. Regarding smartphones people just forgot or died. Most of them 'assumed IT would have some way of recovering them so they did not bother'.
Which phone is this?
Perhaps for consumer use.
However, we're talking about business use of these devices, but it is clear that these devices are not made for this context where in most cases you don't want the devices tied to a specific person (but rather a specific role).
Using Apple and Google devices for work just sucks.
I’ve heard a long, long time ago that the market for stolen devices had switched to stripping them for parts rather than selling them as working replacement devices. From that perspective, activation locks don’t help much. For thieves, even if some parts won’t work, any gain is better than nothing.
https://developers.google.com/android/work/requirements/full... https://developers.google.com/android/work/play/emm-api/prov...
It works very well to prevent theft. Phone models locked in this way are barely worth anything on markets of stolen goods.
Unfortunately some devices have exploits which allow relatively easy unlocking, and those models are still stolen quite a lot.
Not disputing your claim, just finding it difficult to find evidence either way.
https://ag.ny.gov/press-release/2015/ag-schneiderman-london-...
Theft is just the marketing gimmick
Differentiating between the intentional re-selling of the device, and the selling of a stolen device does seem like a tricky problem, and personally I think this solution seems reasonable. If the device manufacturers are at fault of something it would be poor UX for not making this more clear, otherwise I believe these companies are acting honestly here.
All that would be needed is for anyone selling a phone to provide the imei and some id to a govt service to assert that they are the current owner and intend to sell it for x price on y day. If you don't do this check and buy a phone, you're held liable if it is stolen. If you do, and it passes but later turns out to be stolen, automatically reimburse the buyer when you return it to the owner and make the seller liable to cover all associated costs in addition to the handling stolen property.
Most of this is already implemented for cars via vin, and doesn't require that an unelected central power has carte blanche to do whatever they want to it at any time.
Have a central database of registered owners.
Allow current owner to assert that they own a given imei in a way that the buyer can check on said database.
Register the transfer of ownership during sale.
The inverse is also true, have strong policies that prevent private accounts on work devices.
Work have zero right to your private data, and you really really don't want to take any liability for work data.
Often times we receive phones that are completely locked, but depending on the version, you can bypass it by using Android manipulation tricks. If a phone has FRP (factory reset protection) enabled, then it is locked to the original account, and the phone setup process, even after a factory reset, is a lot different. The phone requires that WiFi is enabled and connected to a network, as opposed to optional, and that the original account owner signs into it in order to set it up.
The bypass trick is going into either emergency phone call mode, or by going into TalkBack settings and bringing up the global context menu to do what I call are break-outs. You can dial an emergency phone number (I hate doing this) and hop to the Bluetooth Android settings, which then lets you navigate to Backup&Reset, and from that you can completely wipe the phone and get rid of FRP. You must enter the settings before the phone hangs up.
Or you can go into TalkBack, activate it, go through help docs, and try to find a help doc that links you to an exterior site like YouTube through Chrome (not the app). From the browser, download any kind of APK, then head into APK installation settings where you have to grant security permissions to install APKs from unknown sources, which then takes you to Android settings, which you can then do a full factory reset to remove FRP.
I've also seen on Android 8 or newer that you can use the Google assistant type-text modes to do break-outs as well from inside the locked phone setup process. YMMV, but these are things I've done in practice on some slightly older phones.
"Allows the specified administrator accounts to sign in to a company-owned device after it’s reset to its factory settings. Who can sign in after a factory reset depends on how the device is company-owned and its management client"
[0] - https://support.google.com/a/answer/6328708?hl=en_GB#dev_fac...
But I still wonder why this is implementen on a factory reset. The only thing I can think of is to discourage theft.
Vendors like Apple should be required to take back phones and devices that are in such a locked state for free. They should then unlock devices that can be sold as refurbished, used or even part out the devices.