This is a good thing. Combined with remote lock, it renders stolen devices useless.
This is a good thing. Combined with remote lock, it renders stolen devices useless.
My personal opinions on this:
Factory reset should mean 'just like when it came out of the factory brand new'. So no hidden keys, certificates, connections, locks or other dependencies. Either change the definition or do not call it factory reset. If people will not be able to factory reset a device, please explicitly state so in the TOS.
Rendering stolen devices useless may be a good thing security wise, but it is horrible for things like the ability to recycle and reuse. There are tons of procedures to make pretty sure devices are wiped completely from any sort of data. Why is this not enough?
I have had to destroy thousands of devices that could have a happy second (completely unsupported and no warranty whatosever) life at various projects. I'm not proud of it.
It sucks, but it's not enough because it doesn't remove the incentive to steal the device in the first place. If you want someone to plonk down $2k for a fancy phone, you'd better be able to (a) convince them that they'll be able to re-sell it for a good chunk of that amount, and (b) at the same time reassure them that there's no point anyone stealing their expensive new toy, which means they aren't just painting a giant target on their head.
If the thousands of devices you mention were legitimately obtained, why were they locked with account credentials that you didn't have? Or were they recovered from dumped recycling or something?
Nevertheless valid points indeed. Regarding smartphones people just forgot or died. Most of them 'assumed IT would have some way of recovering them so they did not bother'.
Which phone is this?
The Factory Reset process is defective. It SHOULD ask the user if they are selling, giving away, or otherwise disposing of the device; or otherwise just want to remove that device from their account.
I’m on iOS, so I can’t test this myself.
I’ve heard a long, long time ago that the market for stolen devices had switched to stripping them for parts rather than selling them as working replacement devices. From that perspective, activation locks don’t help much. For thieves, even if some parts won’t work, any gain is better than nothing.
Perhaps for consumer use.
However, we're talking about business use of these devices, but it is clear that these devices are not made for this context where in most cases you don't want the devices tied to a specific person (but rather a specific role).
Using Apple and Google devices for work just sucks.
Of course it's not a good thing. What Apple can do to someone else at your request, they can do to you on their own initiative.
But they don't because they're all enormous companies with thousands of employees. The negative PR would be instant and overwhelming, and the sheer amount of staff would render trying to do it secretly, ineffective.
There is cautious, and there is paranoid.
This example is unlike the others; your credit card provider already buys everything that goes on your account. For that to make any sense, they'd need to convince you to pay them "back".
> But they don't because they're all enormous companies with thousands of employees. The negative PR would be instant and overwhelming, and the sheer amount of staff would render trying to do it secretly, ineffective.
And this is just untrue. Nobody even remembers Amazon retroactively deleting sold copies of 1984 from their customers' internet-connected Kindles. We're swimming in devices that the manufacturer won't let us access right now, but the PR hit from doing what they're already doing is too large for them to... continue doing it?
That's why it's called a "credit" card.
The credit card issuer doesn't appear in the vendor's accounting system, they count the payment as having been made by the customer purchaser. It is only for relatively limited purposes (ones that approximately no one ever thinks about) that the credit card issuer is considered the payor. The merchant vendors generally don't care, don't know, and don't record. As if they are going to care whether the customer uses a Capital One credit card or one issued by his or her local bank.
I do. And the answer to "Am I the only one who..." is always "no".
Hell, it's even on Wikipedia:
https://en.wikipedia.org/wiki/Amazon_Kindle#Removal_of_Ninet...
Edit: More seriously, if they took this approach, people would regularly lose their codes, which would necessitate a backup means of obtaining it. Which would no doubt require the purchaser log into their Google account. And we're back at square one.
It might surprise you, but back before games where always online everyone had to keep track of license keys. Still have a box with all of them. Only those that required feedback from activation servers are now useless because the companies killed the servers.
Modern phones are closer to $1000.
(for single player games)