MacBooks from 2020 Are Being Sold for Scrap Because of Activation Lock
vice.com
vice.com
Any legitimate reseller would not have an issue because the original owner which sold the laptop to them would have wiped the device and removed the activation lock. The fact stolen goods end up as scrap and have no useful value beyond scrap value is not only okay with me, I think it's a net positive for society and one of the best things Apple has done for their customers and the world.
> Responsible recyclers and refurbishers wipe the data from used devices before selling them on. In these cases, the data is wiped, but cannot be assigned to a new user, making them effectively worthless. Instead of finding these machines a second home, Bumstead and others are dismantling them and selling the parts. These computers often end up at recycling centers after corporations go out of business or buy all new machines.
https://support.apple.com/en-us/HT201065
(to some of the commenters, note Step 2 carefully -- the rest of this guide is for older macs)
If it’s a legitimate sale, the original recycler will require the seller to wipe/unlock the device or they will only give a steeply discounted price. If the seller is going to get hundreds/thousands less by not wiping the device, they will do it.
Thus, the only problem for recyclers is recycling stolen laptops.
I’m sure there are plenty of court precedents around bankrupt businesses trashing assets out of spite rather than selling them.
If the problem is the financial part, just go back to the person they bought it and get the money back.
If they're taking a risk and buying it legally from, for example, a police auction, or from someone who "might have forgotten to contact the owner": it's a risk.
If it was acquired illegally, I can't say they deserve a solution to their problem.
Nobody is entitled to get money in exchange for potentially stolen goods or items acquired without due diligence.
> use Erase All Content and Settings instead of the remaining steps in this article. For any other Mac or macOS, continue to step 3.
If you're using macOS Monterey or later on a Mac with Apple silicon or a Mac with the Apple T2 Security Chip, use Erase All Content and Settings instead of the remaining steps in this article. For any other Mac or macOS, continue to step 3.
Nothing else is needed to disable activation lock.
Ive worked with second hand devices for a long time. Ive had many come through that have activation/MDM/etc locks and have tried calling the IT dept they came from and all but about one time they pretty much just laughed at me or just played dumb about it entirely. Apple and other vendors were no help in this as they just tell you to contact the original owner.
But at the benefit of less-burdened security teams, and greatly enhanced peace of mind for users and info-sensitive organizations? You can argue it's taking something highly risky like security and shifting those man hours to something not as threatening.
As the sibling commenter points out, this should also result in less waste as those drives do not need to be destroyed if the device is properly unlocked.
It isn't necessary to destroy the physical media anymore, so that reduction in e-waste is fine with me. Just properly erase the device by clicking the button in settings.
Unless, cryptography itself is broken... which would bring much wider-scale problems than destroying information on old drives anyway.
The IT department has no idea what kind of password that user was using, and they have no idea what kind of valuable data is on that machine. If that user's password was just "password" (or sticky-noted next to the trackpad), that IT department is going to get in serious trouble once all that proprietary data ends up in the wrong hands, if they didn't wipe the machine before handing it off to a third party.
If wiping the machine before getting rid of it is "extra work", then that IT department isn't doing their jobs to begin with. I'm certain such IT departments exist, but that's not enough of a reason to make theft easier.
Source: just wiped and sent back a MacBook Air to my old workspace. My colleague finished the macOS setup and logged in with their iCloud account. After resetting it again (to re-do the setup in the way they wanted) it was locked to my account. So not even installing macOS and logging in to iCloud will bind the machine to you.
Imagine doing that with a machine you bought second hand and the original owner can’t be reached anymore.
https://support.apple.com/en-us/HT208987
"Other ways to disable Activation Lock"
"Activation Lock is disabled when you use the Erase All Content and Settings feature."
Apple confirms that the feature works exactly as I said and exactly as users expect. I've used it myself, and it does work.
Users running software that is several major versions out of date will have a more difficult experience, since that button did not exist, and they would have to first remove Activation Lock before going into Recovery Mode to manually format the Mac. Those are the remaining steps that were linked several comments up from here: https://news.ycombinator.com/item?id=34505523
Apple has made the process as easy as it possible can be now, identical to the process used to factory reset an iPhone.
I’d argue if you can wipe it (which requires your iCloud account approval), install it as someone else, login with that new iCloud account, then reset it and it suddenly reverts back to the previous owner, something is wrong or very unintuitive.
The problem on Mac it seems is that there are two official ways to do it. One proper way (the “Erase All Content and Settings”) and one other way (the way we did it, boot into recovery and format it, then go through setup with another iCloud account which apparently just temporarily lets another user use the machine). On iPhone there is no user accessible recovery mode so that can’t happen there.
If you go through recovery, you can delete the content, but when you go to reinstall, you will be prompted for the credentials for the user tied to it.
Meaning, you can delete, but you can't reinstall without being prompted for authorization by the account that currently 'owns' that computer.
If you want IT asset disposition, it'll nominally cost you -- for pickup and processing, and optional value-adds like secure data destruction certificates. If the assets have remarket value, that can begin to subsidize the cost, easily zeroing it out, or even returning profit to the IT department. Recyclers are happy to pay IT departments to pick up their old Apple equipment -- and they know to ask ahead of time, "are these activation locked?"
These recyclers often have vertical integration on the refurbishing side, running an Amazon eCommerce department so they can directly capture that remarket value. And once they've got that going, their bottleneck to growth is how much material they can bring in -- which is never enough.
So the recyclers and refurbishers invariably need to buy material from other recyclers. There's an entire economy around selling pallet-fulls of used, minimally-inspected or completely "as is", Apple and PC equipment. Specialized invite-only communities exist for selling this material in bulk, with lots of overseas actors in on the game. Every R2 recycler is involved here, along with lots of actors from India and China in particular.
Having seen inside that sausage factory, fraud and theft is a legitimate problem. There's more than a fair share of "don't ask questions". More than a fair share of "yup we're definitely R2 certified, wink wink". More than a fair share of wining and dining the R2 auditors to get that certificate under the table in the first place.
I'm gonna go with the GP comment here -- the system is working as intended. Industrialized theft of this sort is much more eminently solvable through technological means than through overstretched law enforcement, especially when a non-negligible amount of material comes from overseas.
It's on the IT departments to figure out if they have enough time to activation-unlock their assets before disposition. Do they want to pay the recycler to pick up all that material, or do they want to sell the material and pad their budget?
A quick look at the Jamf documentation suggests it's pretty easy to mass unlock these devices, so I'm not buying that it's that much of a strain.
The activation lock removal is hardly an obscure hack, this is a process failure. Good on Apple for making these machines take their secrets to the grave.
I'm not sure you're being serious. Wiping a laptop before getting rid of it is SOP for a IT department. This is hardly a new requirement.
Again, the only people impacted are those who want to leverage their ability to take over a laptop without authorization.
All that will happen is that the second hand value of Apple devices will go down, because recyclers will assume X % are basically scrap.
In that case the value of the entire batch will be lower.
So yes it's a known issue. But for each individual MacBook, it's a potential issue.
Yes. And what is argued is that they should talk about stolen property. Because if they got the laptops legitimately they should ask the original owners to unlock them. If they can't or won't then something is suspicious. The laptops being stolen is the leading suspicion.
In fact, there was a period of time when depending on latest os version and hw version, the steps changed.
The one time I bought a mac personally, the reseller tried to follow the correct procedure... But they used an outdated one. Contacting previous owner led to threats of litigation for phone call mobbing.
Things may have been more complicated before that, but Apple has made it as easy as it possibly can be now without telling thieves to just start grabbing every Mac they see.
"Erase All Content and Settings" did not exist in macOS Catalina. Back then, you had to manually reboot into recovery and reinstall the OS that way, which unfortunately did nothing for Activation Lock, and was a confusingly advanced procedure to expect end users to perform in the first place.
Now, someone just has to go into settings and click that button and macOS will handle everything. It's exactly like wiping an iPhone, including using the same button name. Apple has done what they can to make this as user friendly as it can be now.
Then how do they know that they're not dealing in stolen goods? If they can't establish a chain of custody to a legitimate owner, then they're being irresponsible.
Did the owners just push the laptop under the door and run away? At the point where they receive the laptop they can say: "If the laptop is locked it will cost you $X to dispose it here. If it is unlocked we pay you $Y."
Set X and Y appropriately and people who can will unlock them.
I'm sorry but this is bullshit too.
I have sold my fair share of old Apple devices via so-called "responsible recyclers and refurbishers".
When submitting the form on the website, they all have statements in BIG RED CAPITAL LETTERS saying "please logout from Apple iCloud before sending us your device".
Most of them also have terms and conditions saying they won't pay out and/or will return devices where activation lock is still enabled.
Given Apple’s reluctance to sell spare parts, this isn’t a bad business.
The logic board is just one part. The keyboard, trackpad, lcd, battery and a few other boards have quite a lot of value.
Logic boards are fairly reliable in practice.
What’s going to suck is when you can’t build a Frankenstein laptop as Apple marries more and more parts together.
“Oh, this keyboard didn’t come with this lcd from the factory, no F key or red for you!”
Definitely a point in my book for buying Apple.
Plenty of companies don't care to unlock these properly before recycling and it's creating excessive waste.
I think it's perfectly fair for "legitamately acquired" to mean the original owner consented by unlocking the device. The peace of mind and security if you own a T2 device is the way it should be, and if you want to sell it, you just factory reset it, which is a quick process.
This is not true. The bankruptcy process attempts to recover as much value from assets as possible, and so creditors and the process should absolutely care to properly unlock in order to extract maximum value.
Similarly, aging out old equipment is still sold to make money, and unlocking should achieve more resale value.
The incentives are absolutely there. And the article does absolutely zero investigation as to where exactly there's a breakdown in incentives or communication, or if it's even a major issue at all. Maybe the process is working 99% of the time.
If bankcrupt, the original company may have a duty to unlock them because they will be worth more.
However, since Apple actually had full authority and cryptographic ownership of the chip, they can generate a key given serial number which will reset T2 contents.
Personally, I think the setup should be that you don't have to go to apple for it, but it should immediately wipe device identity and disk encryption then (and the disk should always be encrypted)
I don’t think that’s true, I’ve never had to do that, and this is not a part of Apple’s documented reset process for resale of a machine. If you are the device’s actual owner and you use the simple process Apple outlines, it will reset it for a new owner, period.
Been there, went with Apple support over it, the only reason I still don't have it unlocked is because I didn't have time or energy to redo the whole setup. Might redo the apple-driven unlock process, but the hw is not worth it really.
EDIT: Apparently the nice simpler procedure that does wipe FMM only arrived in Monterey.
It will unlock the device.
Any T2 Mac or newer requires only that button to be pressed, and then click through the wizard to complete the process. If someone is running outdated macOS, they won't have that button at all, since older versions of macOS required you to format computers the hard way using recovery mode, which didn't handle activation lock concerns.
You can also read this document: https://support.apple.com/en-us/HT208987
"Other ways to disable Activation Lock"
"Activation Lock is disabled when you use the Erase All Content and Settings feature."
which confirms the same thing. The experience that people have is very simple these days.
Which still leaves considerable amount of laptops with broken FMM registrations in T2. Especially since it was upgrading to Catalina, iirc, that started problems.
Given that, removing the activation lock after notifying you with a 30/60/whatever day window to respond seems like a reasonable policy to me.
Not the same thing, depending upon how the authentication is handled.
It’s one thing to forward a request. But to give unlock after 30 days? That’s gonna be abused by thieves and unscrupulous refurbishers
> “Previous owners do not return phone calls“
E-waste is going to happen regardless and it would be more proper for Apple to have a computer recycling program, which already exists, or to turn the old computers into spare parts for repair.
Eliminating the potential for theft is a massive win. I remember what it was like before activation lock existed and how high of a target iPhones were. As soon as that feature came out the thieves were screwed out of a potential payday. Now we don’t have to worry about our phones being stolen.
There is exactly that pathway. If you have the consent of the original owner, which I think is an important and required quality of "acquired legitimately", you can have the original owner remove the device from their Apple account remotely, or to wipe the device and reset it while logged in prior to physically handing it over to you.
If neither of these things have happened, on what basis do you believe the complaintant has "acquired legitimately"? Is consent of the original owner not important in your view?
In the article they outline a pretty decent way to overcome this through apple themselves which I'd be much happier with.
It’s a safety measure against laptop thieves - if you steal a macbook you cannot resell it.
The safe maker is unethical and just making waste!
Apple devices wouldn't sell at all if they tried to implement this kind of security.
A process that no user has a reason to follow / sounds like spam.
And a 30 day timeout that suddenly makes stolen devices are worth something again.
The recyclers themselves need to it worth the owners time to unlock it…
You want to bet? Theres a large body of non technical users.
1. You buy and traffic in stolen goods, you're a fence. Good thing you got fucked.
2. You don't do a good job of operationalizing your core business, and ensuring that sellers unlock devices before handing them over. Good, you suck at business and those that don't should rise to the top.
I don't see how any of this is a negative, except the environmental impact at the end, which considering most of this is aluminum and recyclable, is minimized and an acceptable trade-offs for the massive anti-theft and data protection benefits.
This is exactly what goes wrong, way too many times. After encountering this issue with various friends and family, with locked iphones, I strongly believe we've gone wrong somewhere. People simply are not aware that their device is protected like this, until it actually hits them, which for way too many people, is simply "never". And in the case they are aware, they don't know how to remove the locks either.
Contacting the previous owner isn't as simple as it may seem, as iphones will typically obscure the owner's name. If the phone has passed any reasonable amount of hands, been locked in a closet for a few years, or was set up with another relative's account, disabling any of these kinds of locks is a losing game, usually ending up in frustration and the purchase of a new device anyway. Now consider what happens when workplaces discard devices en masse.
I completely agree with wanting good protection for my data on my devices, but people should be able to give away and sell these devices without worrying that the device will end up bricked in the process.
This is not an acceptable compromise. These devices are the keys to a person’s entire existence, no compromise should be made to offset the user’s ignorance.
It's like buying a car from someone who doesn't have the keys for it or any paperwork. Sure, it's not quite common knowledge like buying a car yet, but it will be eventually.
This is a really good point, but I'd like to counter with the observation that the anti-theft features of cars don't routinely brick products the way Apple does with activation lock.
However, a car parts are not molded like an Apple laptop. Most of them can be sold for good value.
Anecdotally, sometimes in my hometown I find dumps of bags from car thieves. I go through them and try to return the remnants to their respective owners. The thieves passed up things like a $5k engagement ring in a cloth bag and a startup founder's personal notes on proprietary technology just because they were not recognizable within 2 seconds as having value. Meanwhile, every single Apple device was gone. It was kinda 50/50 regarding Android phones, but laptops (especially corporately-allocated ones) are also always taken.
So if this really is such a dealbreaker, the thieves haven't noticed yet. Which means their fences haven't noticed yet. Which means their customers haven't noticed yet. Which means what you said is probably wrong, and probably there are ways around the activation lock that the authors of the article have somehow missed out on, or perhaps they're being sold/disassembled for parts.
By making the fence value of the products less, however, it definitely creates a disincentive to work hard to steal a laptop. If it is easy, ya, its gone, but otherwise, their are much better ways to earn those five bucks.
From TFA, which you clearly did not read:
> Often the previous owners are corporations or schools who buy and sell the machines in bulk and aren't interested in helping recyclers or refurbishers unlock them. "Previous owners do not return phone calls, and large corporations that dump 3000 machines assume they have been destroyed, so it is critical we have a solution that does not depend on the previous owner approving,” Bumstead said. “And after all, we have property rights, so the original owner is not the current owner and does not technically have a right to condemn to death what is no longer their property."
Do you think this is accidental? Think again.
You clearly did not read, or comprehend, the quote you just pasted in here. This is someone committing fraud against the companies paying them to destroy decommissioned computer systems, something they may be legally obligated to do for compliance reasons. They're trying to make a buck on the backend instead of doing what their customers paid them to do.
I read, and comprehended the article, did you?
From the HN guidelines [1]:
"Please don't comment on whether someone read an article."
> From the HN guidelines [1]: "Please don't comment on whether someone read an article."
Is this supposed to be funny or ironic? I find it's neither.
> From TFA, which you clearly did not read:
It’s a fair comment and callout in response.
Clearly didn't read the article. They receive shipments of 1000s from corps, who don't bother to remove the ownership.
They received shipments that the corporations thought were /destroyed/, likely legally required for compliance purposes, and they are participating in a fraud that violates compliance regulations by attempting to recycle rather than destroy these systems. The reason they don't want to contact the corporations to remove the activation lock is because the company doesn't know the systems were not destroyed, which is a quote from the person interviewed, in the fine article, which I read and clearly comprehended more than you.
This is a business participating in fraud and assisting people who steal electronics and they are upset that their business model has been disrupted. Good. Fuck them.
Also from the HN guidelines [1]: "Please don't comment on whether someone read an article."
Except when I get activation locked out of my own devices that I bought directly from Apple, which does happen from time to time. Fortunately, that's never happened while traveling, but if it did, I'd be in trouble. Getting it removed is a pain and can take a while.
Why does it happen? I don't know. Apple doesn't know. Nobody knows. Maybe they just really like talking to me and reviewing my receipts.
How do you know? On what basis do you make this claim?
Only with the consent of the original owner can you legitimize the transfer of property, and the activation lock is the exact technical means to get that consent and legitimize that transfer.
I thought this too until I had an iPhone stolen last year.
Coordinated rings target music festivals and I’d imagine enough people’s phones AREN’T activation locked that it’s worth it to them.
Apparently they ship the locked ones to China for scrap now. And that’s exactly where mine phoned home from he final time.
And I am even happy as a second hand laptop buyer. The last thing I need is to buy a stolen laptop. At least here, I am still liable even if I don't know for a fact that it is stolen. In any case I don't want any part in stolen goods market.
I think, over time, laptop owners will learn to preserve their key so that they can unlock the laptop when they want to resell it and buyers will learn to check if the laptop is unlocked. What's the problem?
Otherwise the thief could just steal the phone, wire in a hacked Touch ID that accepts any thumbprint and resell the phone.
This way it's way too expensive to be profitable unless you're doing it on an industrial scale. Most thieves resort to trying to con the previous owner into giving their Apple ID for unlocking.
Only if the thief knows that. An organized robbery ring might. The opportunistic kid hanging around the cafeteria or coffee who has 5 seconds to swoop may not.
If my laptop gets stolen, I might have the last laugh, but it'll be a forced one.
But yeah, I wish Apple would run some ads about this feature, so that would be theives would realize they were worthless.
A device which exploded if it was ever more than 15 feet from you would also satisfy that desideratum. There are other things to take into consideration.
If you could ask Apple to pick up the laptop for free, so that they can refurbish it and sell it at a discounted price, it would be no problem. No business for thieves, no waste, and more good machines available for a budget. But they have no reason to do that as it goes against their business model.
The problem with making any exception is you open it up for thieves
I refuse to buy any expensive device without this feature.
Your trolling disguised as moralizing is not particularly welcome.
Forcing laptops to be scrapped only solves the problem of Apple's bottom line.
> it is critical we have a solution that does not depend on the previous owner approving
Personally, I don't want anyone "recycling" my old laptop without me having approved it first.
The buyer should know this and ask the seller to unlock their device(s). And if it's a legit seller, you can contact them afterwards and have them unlock it.
And iPhones still get stolen. As much as people may not like theft, it is less of a social ill than waste is.
If you want to deter theft, work towards a society that doesn't drive people to thievery, rather than trying to solve it with weak technical solutions that do nothing to address the underlying problem. Apple could be more effective at preventing theft by donating a billion dollars a year to fight poverty, although that would risk doing some good for the world.
That's... a take. It sounds like you don't personally believe in property rights, and therefore think solving global poverty (an intractable problem that has never had a meaningful solution in all of human history) is a better way to solve theft than just addressing theft directly. The weird thing is people steal even when they aren't experiencing poverty.
Theft is an unalloyed social ill, and the only examples of theft that can be remotely justified are contrived examples of theft under oppression of basic survival needs, which is not the context, socially or otherwise, of the places where iPhones and laptops are being stolen, so not really relevant. Theft is wrong. Theft is social ill that has far-reaching consequences and many second and third order effects in society. Ending theft is a good thing, and is more than worth the trade-off of the minimal additional waste (considering aluminum is very recyclable).
I allege that this is a take. It's possible to believe in property rights while also understanding that human desperation drives people to theft. The vast majority of people resorting to thievery were driven to it because of the circumstances of their life, not because they're doing it for kicks. In a battle between property rights and human rights, at some point human rights takes precedence. You don't need to go Full Communism, you just need to acknowledge that desperate societies are not polite or prosperous societies.
Property rights are human rights.
I have a human right to be secure in my person and personal effects, and a human right to enforce that security against transgressors.
Sure, then we can consider the category of human rights may contain (among other things) the right to personal property, as well as the right to be assured of your next meal, and there is no law of nature that says that rights cannot be in conflict. In a society of extreme scarcity, the latter may be unachievable. In a prosperous society like the one that I live in, the latter is entirely achievable, although sabotaged by short-sighted people who have yet to understand that treating crime at the source--human desperation--is more effective and efficient than treating the symptoms of crime.
No such right seems to exist, in my view. That said, we have a duty and obligation as a society to help out those in need, but this is not the same thing as this being a human right. That meal requires the labor of another, and there is no human right in my viewpoint that causes the enslavement of someone else.
Unfortunately, it doesn't matter whether or not we believe it to exist. If given the choice between crime and starvation, people will choose crime. One can believe in the inviolability of personal property all they want; they'll change their tune when hunger sets in.
> That meal requires the labor of another, and there is no human right in my viewpoint that causes the enslavement of someone else.
Sure. But nature is not so kind. You have food, and someone is coming for it. Your option is to either kill them or give it to them. If you would die without that food, then the moral choice is obvious. If you have so much food that it would be physically impossible for you to notice the loss of any of it, then the alternative is true.
And if they don't, they can delete the device from iCloud.com (Find My) to bypass the issue.
Then the person who buys it from them is going to send it back, and they'll know next time, or however that gets resolved. If they're selling it to a reputable commercial entity, that entity will know it needs to be done, and will ask them to do it first. Every iPhone I've sold to a company in the last x years has needed this process done...
Other non-portable macs did as well.
Accusing someone trying to keep electronics out of the trash of laundering stolen goods is not ok.
What rewards is the planet reaping from “the deal”?
The approval process needs to ensure that some enterprise IT drone can easily go through a pallet of laptops, wipe them all, and put them on eBay, without depending on Janet from sales properly following the decommissioning process, without requiring them to navigate a phone tree at Apple to read off serial numbers.
If the laptop is more valuable as scrap than as used minus costs of recycling, it will be scrapped. If scrap minus costs of disassembly and hazmat disposal is less than zero, it will end up in the landfill. In spite of all the work going into lead-free components, halide-free solder, and so on, we still don't want that.
Yeah, they seem to even admit in the article they're dealing with machines the original owners expected to be destroyed.
Admittedly, I don't love the idea of that massive scale waste, but some people or corps have legitimate opsec concerns.
You would need a combination of very high cashflow and lax/incompetent device management, plus a direct contact that grabs large amounts of these "used" computers without applying the most basic of processes for making sure the devices being repurposed can be, well, repurposed.
I want to have good faith, but this sounds a lot like "thousands of quasi-new, pricey laptops are sold to us with a 'former corporate owner' that mysteriously doesn't answer phone or email, and we would like to act like they're ours now."
It seems like this is an issue only if your business plan is to squint very hard every time you look at the source for the "used" laptops you're buying.
For legitimate transactions or ones where the data liabilities are fully disclosed, you can obviously get around this easily.
Activation lock isn't just data protection: It is Anti-theft. The concept was that bricking the hardware if it is stolen would reduce the, at the time, massive rise of theft. Activation lock on iOS (and all kinds of keying hardware to that board) basically shut down cell phone theft as they become worthless. They added the same to MacOS.
You haven't been paying attention then. In London, phone snatching (iPhones preferred) has been and remains an epidemic to the tune of tens of thousands a year - in a single city.
They might not be resold at full price, but even selling to a fence for parts is profitable if your acquisition cost is zero.
That would be extremely expensive to design. Probably impossible.
Especially when component level repair ala Louis Rossmann is possible.
You would need to add some general identifiers to parts with a GUID and at production/official repair time, register those parts to an iPhone S/N. If Activation locked, those parts would need to not be able to be registered to another iphone until the original device is unlocked, thus clearing those parts.
How are you going to lock down the phone body? Or the screen (not including the digitizer)? Which, coincidentally, are probably the 2 most damaged parts of a phone.
I suppose there's probably some way Apple could lock them down. But that seems like an expense wildly out of proportion to the potential benefit.
No thanks. The secondary repair market is extremely important to keep on life support.
If you cede all repair work to manufacturer blessed shops the amount of waste and expense skyrockets.
I want patched together laptops working 12 years from now, just like I have old T-series laptops from back in the day with various replacement parts humming away right now in my homelab. It's silly to just toss everything in the trash the moment is breaks.
Apple has started blacklisting parts associated with locked iPhones. At this point the only reusable bit is the case and possibly battery. The display, Face ID, Touch sensor, and such are all bricked. Overall the reduction is massive in any form. There isn't a 100% effective solution but you can easily cut down on 90%.
If it's your machine, it's not bricked. The owner can turn off Activation Lock though a web browser on any machine.
I'm sure some percentage of owners would allow that if it was just a click of a button and would help cut down on e-waste. As long as the machine isn't stolen and you know you're not going to expose any data then why not?
(...and if it is stolen then the owner can expect the recycler to explain where they got it from and return it.)
I actually prefer if Apple doesn't provide anyone with a way to contact me, ESPECIALLY if they have something potentially stolen from me.
I don’t mean that Apple allow a third party to contact anyone directly, I agree that that would be terrible.
Instead I could see Apple themselves contacting the last known owner to ask permission to wipe and open the laptop for reuse.
If that’s not what you want then you tell Apple the once and that’s the end of it.
Reuse won’t always be what people want but if a laptop can be repaired and securely reused then that’s much, much more energy efficient than recycling it.
so no to that. the solution to work as deterrent should be final: stolen device = brick device, no other possibility.
in the case of solving theft of devices we have to choose the price we want to pay. all solutions are based on various ways to deter the theft. there is no solution to stop the action of theft once started. thus all solutions have a price that could range from false positives (like legit owners being locked out) to waste like theft happens because they dont know that they cannot unlock it without destroying the device.
A person who is temporarily assigned the use of a company machine will not be able to prevent the legal owner of the machine from turning off activation lock.
However, Apple chooses not to do this unless they can establish that it is actually your device. Giving trade-in credit for activation locked devices would effectively be giving thieves an easy way to make money off of these otherwise useless devices, so they don't do that to avoid incentivizing theft.
It would be cool if Apple offered a program where these activation locked devices could be returned to Apple for free. Apple could contact the last known owner and let them know their device has been recovered. If Apple doesn't hear back from them, then they could wipe the device and sell it as refurbished, or recycle it (depending on how damaged it is). This avoids creating an incentive for thieves to steal, but also overcomes the e-waste argument.
I had my account on this. I formatted and that when I saw that I will not be able to re-install anything that I realized I bricked a perfectly fine machine.
Oh well.
It seems dubious to me. Shouldn’t the reseller withhold payment until the device is verified to be usable? And shouldn’t schools and businesses be incentivized to reset the devices since they want the full resale value?
I've seen businesses shred crates of completely unused and unprovisioned top of the line 16" macbook pros.
The company I work for has to do it from time to time with Apple's help. We have Mac users who, for example, return locked Macs when leaving the company... we unlock them then with Apple's help.
1. An insider (hard to get)
2. Phishing the owner (your device has been found, just sign into your Apple ID on this specific login form...)
3. Physically going to an Apple Store, with faked proof of purchase, and ideally a convincing disguise
4. Resell to some Chinese reseller (particularly because China doesn't use the same IMEI blocklist as the rest of the world), and take whatever they give you, and then it's not your problem anymore
Option #3 is surprisingly popular for petty criminals.
They are getting pissy because Apple trashed their probability game.
hardly justifies turning working technology into a brick
https://support.apple.com/guide/mac-help/erase-your-mac-mchl...
These macbooks need to be treated like a used car now. I've traded in 2 cars and they look it over and take it for a 5 minute drive to make sure it is okay then give me the money. They aren't going to take my word that the car is fine.
Anyone buying a used macbook needs to verify that the machine has been properly reset. This should probably take a minute or less.
Price for Macbook that has been properly reset = $500 - 1500
Price for Macbook that has NOT been reset = $0
Not that complicated.
If the device is marked in lost in iCloud though, it isn't happening.
Ergo if you're going to risk it, stick it on a credit card.
I've bought a number of used Thinkpads, laser printers/copiers, workstations, etc. that were previously owned by big companies. They don't go through the wiping process. If it has a removable drive caddy the whole thing comes out and goes in the trash, and you need to find a spare part that costs as much as the whole used laptop if a lookalike isn't available. They don't care whether the BIOS is locked, that doesn't have their data on it.
The intern saddled with unloading the pallet of old laptops is never going to see any of that hypothetical $500-$1500. And who would ever give an intern the local admin password to run erase assistant, potentially letting them decrypt the data of a senior employee previously logged into the Mac, just before covering their tracks by deleting the access logs?
Because of this article, I'm updating our internal employee off-boarding check list to make sure we don't end up with a lot of bricked hardware.
Does Apple or any third parties make software to do this?
Essentially the T2 security chip needs to allow 2 passwords so that both the user AND corporate IT can reset the machine etc.
If a company is leasing laptops then they need to treat this process like an apartment security deposit. When I rented my first apartment I had to pay one month's rent up front. I moved out 4 years later and they inspected my apartment for damage and after they found nothing wrong they gave me my original security deposit back.
Working as intended.
You could argue that theft would increase Apple’s sales, because the people buying stolen ones were never going to buy a new one anyway, and the relatively well off victims of theft have to buy a replacement from Apple, again and again.
So not sure what you mean.
If you mean it’s in their market interest to make sure their customers are well taken care of, I see no problem with that.
As far as I see there is also still a massive market here for second hand Apple tech despite these locks, people just follow the process to dissociate their accounts.
I'd even say that Apple laptops and phones go through more hands than others because of how long the software gets updated for. I still see iPhone 5S around and those just got an security update this week - maybe 10 years after introduction?
So this article feels quite clickbaity - trying to blow up one recycler's preference that bulk donations could skip these locks into a whole "Apple not doing enough to deal with e-waste" angle. Obviously every big company could do more on this front but I haven't heard of another device manufacturer putting as much recycled contents into new devices [1], running such a comprehensive global certified refurb program and finally keeping the software update cycles as long so the device doesn't need to be scrapped in the first place. The article should focus on the companies that are ditching thousands of perfectly good Macbooks without prepping them appropriately.
[1] https://www.macworld.com/article/229933/apple-sets-a-new-env...
That doesn’t make any sense.
1. Who is going to pay for all that?
2. That 30 day timeout just means it will be unlocked and again stolen devices will be desirable / unlocked…
Ultimately the recyclers need to make it worthwhile for the original owner to unlock these devices. Not some workaround.
Ever heard of spam? It’s one of the biggest ways to get around the iCloud lock right now: Phish the owner that their device has been found, just Sign in with Apple ID on this login form. 2FA has made it harder but they’ve got ways…
That would make it really confusing. You could get such a text from either Apple or a criminal and you’d better know which. No thanks!
Nope, not yours.
Even inside Apple Care window, with the Mac in your owned device list, with your welcome to this Mac email from launch day, Apple won't help without original receipt.
It would be quite simple for Apple to setup a rescue program that actually got people their stolen devices back and solves the recycling problem:
1. A recycler with an activation-locked device pings apple.
2. Apple pings the former owner.
3. If the former owner wants it the recycler forfeits it to the nearest apple store where it’s shipped at the owner’s expense to the former owner.
4. If the former owner doesn’t want it or doesn’t respond in 60 days, it’s wiped and unlocked.
Activation lock is nice because it deters theft, but it doesn’t get you your stuff back and results in a ton of e-waste in the long run. A solution like this balances those two conflicting problems. Legit recyclers can keep stuff out of the waste stream. Theft is still strongly discouraged, and this time you might actually get your phone/macbook back!
Only the school can remove them from the system, and although Apple's terms of service _require_ them to be in control of the device for it to be registered (i.e. not sold to a third party, me), I have been completely unable to convince the school to help me on the matter. Contacting Apple doesn't seem like much of an option either, as they don't even publicly post contact info for this kind of support.
Based on most of the comments I'm seeing, it's like people didn't fully read the article. In particular, this quote:
> Responsible recyclers and refurbishers wipe the data from used devices before selling them on. In these cases, the data is wiped, but cannot be assigned to a new user, making them effectively worthless. Instead of finding these machines a second home, Bumstead and others are dismantling them and selling the parts. These computers often end up at recycling centers after corporations go out of business or buy all new machines.
It's saying that the machines are being wiped for prior owner security, but that this removes the ability for a new user to activate the laptop.
What kind of corporations or schools hand over old computers in bill without wiping them first?
> "Bumstead offered some solutions to the problem. “When we come upon a locked machine that was legally acquired, we should be able to log into our Apple account, enter the serial and any given information, then click a button and submit the machine to Apple for unlocking,” he said. “Then Apple could explore its records, query the original owner if it wants, but then at the end of the day if there are no red flags and the original owner does not protest within 30 days, the device should be auto-unlocked.""
When the ban hammer drops there is a lot of upset people screaming in to forums that they were banned but didn't cheat! This reminds me of that. The entire thing is working as intended and there will inevitably be upset people who were just gaming the system before hand.
It seems to be a bit calmer now, but VAC is kinda a perfect example. Apple is over-implementing something in a way that prevents legitimate users from legitimately using things. Yes, their efforts here are valiant, but they're also glaringly imperfect. The thousands of unusable MDM-locked machines are evidence that Apple's process here isn't working as well as it should.
Around 2018, my 2014 Air broke down and I took it to a local guy for a logic board replacement. This guy was quick but he worked sitting on the floor of an empty house full of spare computer parts and needed to rummage or buy until he could fix it. Still, I really needed to continue the work I was doing that day, so, I drove to the Apple Store and bought a new Air, knowing they have a 30 day return policy. Went back to my repair dude and we swapped my hard drive into the new Air. I went home and worked on it for a couple days and he called and said he got the board, just need to come back and swap the drives.
So, drives swapped, 2014 upgraded to a core i7, I moseyed back to the Apple store to return my barely used 2018 laptop. No problemo, said the lady, just gotta scan the serial number off the bottom. Then she got a funny look on her face. "This isn't ah..." and before I could even ask, two security guys were standing next to her. Suddenly, I realized what had happened. The repair guy had switched the base with my old one. I made some excuse that I must've grabbed the wrong laptop from the office, took it back and ran out. About an hour later I walked into the same Apple store with the same "never booted" computer (it was a completely fresh hard drive, after all - they could see that) with the original base and serial number on it. Before I even walked in, security was tailing me (facial recognition)... but although they knew something was askew, they couldn't tell what, and they graciously took the laptop back for a full refund.
[EDIT] TO BE VERY CLEAR, I DID NOT TAKE THE I7 BOARD FROM THE NEW LAPTOP AND PUT IT IN THE 2014. That would be extremely unethical. I bought a separate used i7.
> "Previous owners do not return phone calls, and large corporations that dump 3000 machines assume they have been destroyed, so it is critical we have a solution that does not depend on the previous owner approving,” Bumstead said.
Real woe-is-me vibes in this piece.
e.g. We lied to the corporations who paid us to destroy their systems and we want to be able to unlock devices, bypass data protection, and fence them, when they are effectively stolen because they were acquired through fraud.
These people are laptop thieves and mad that Apple made their illegal activity difficult. Good for Apple, and fuck this guy.
2) If Apple had a back door to unlock these, then is there a security/crime risk that could be abused by thieves, spies, hackers, etc.?
3) Even if locked, can't these be sold for parts? Lots of people need a replacement screen or whatever.
I don't have the answers to any of these questions, but the article doesn't even attempt to ask them.
It doesn't address any risks associating with Apple having the power to unlock.
And the article disingenuously claims MacBooks are being sold for "scrap" (which implies merely recovering materials like aluminum) and the intro scarily talks about processes for a part which "ground them into carcinogenic dust". The article doesn't even mention selling for parts until halfway through, and it presents that in a negative light rather than examining why that might be a tradeoff that makes perfect sense, especially since parts availability helps enable third-party repair. (I myself have sometimes found I could get significantly more money selling something as separate parts on eBay rather than as a working whole, which means it's actually better because there's more demand.)
I sold an M1 Mac Mini, reset it beforehand, and everything worked normally for the buyer.
In my experience dealing with iphones from departed staff, if the iphone is locked to an icloud account there's essentially nothing you can do to get access to it. If you do a DFU restore of the firmware it still comes up with an activation lock. Pretty sure that's what this article is describing for the new apple silicon laptops.
Does this happen even if the iPhones are managed devices?
And that's fine. But if you (or perhaps your employer) locked the machine, and it's stolen, it can't be used by the thief.
I "own" one of those. My previous employers never asked me for the laptop back. Even after I send them email about providing me with a fedex label. It was roughtly 2 years ago.
I thought that a good old format would take care of that, but no.
I did saw T2 removal tutorial on youtube thought. You need to remove the T2 chip , implant a new one and flash it.
I'm kinda disappointed on HN to not provide more information on that process.
Previous models also have a T2 chip.
I'm not going to dig into the irony of grossly overcompensated tech workers defending anti-theft side effects. However, I will say that this also creates a lot of waste that basically forces Apple to be the main channel for resale. Go on Ebay and look at how many MDM-locked Macbooks exist that would be perfectly usable if their previous company was solvent enough to unlock them. In a world where reuse is preferable to reducing or recycling, it's hard to cheer for this from the sidelines.
The only thing that really matters is your data. If that's encrypted, there's not a small-time pickpocket on the planet that can get anything useful from it. If your data isn't backed up and your hardware isn't disposable relative to the frequency of being robbed, then you've arguably got a pretty bad disaster-recovery plan. Consider being less worrysome and more proactive.
No, a one or two thousand dollar device getting stolen also really matters. If all a thief can get out of a stolen laptop is $10 of parts, there's less reason to spend time and effort on it, and certainly less reason to, say, kill somebody over it.
You can disincentivize thievery up to a certain point, but you can't use it as an excuse to cross lines you wouldn't have otherwise. That's just capitalizing on the innate paranoia common in luxury customers, and largely illustrates my point that this is a racket.
> Obviously it's not worth killing someone for a $3k laptop though
Which has happened, and it's a lot less worth it if it's $10 of scrap.
That is not true for their laptops.
> because ultimately it's something that will happen regardless of the software or hardware.
No, it will not "happen regardless". Activation Lock has been shown to drastically reduce the amount of theft: https://techcrunch.com/2015/02/11/apples-activation-lock-lea...
This is the same problem cybersecurity people deal with: when everything is working the way it should, other people start to wonder why they even have cybersecurity people. Activation Lock reduces the number of thefts, but you can't see things that stopped happening, so you've decided it isn't doing anything. Some thefts will happen, but a lot of them aren't happening anymore, thanks to Activation Lock. An ounce of prevention is worth a pound of cure. Phone theft used to be a much bigger problem.
When criminals know ahead of time that Apple devices will be bricks if stolen, they are much less likely to try to steal them, which means that a large number of sometimes violent confrontations are being averted. That's how the math works. It's not crazy like you're trying to propose that it is. And no, no one is going to stand there trying to explain to a thief that it will be a brick. The thief either knows ahead of time (and doesn't try to steal it), or they don't and they wouldn't believe the owner anyways. After they steal one, they learn their lesson, and word gets around.
Some people continued stealing activation locked devices because they figured out they could get a few dollars for the parts, even if it is much less than for a functional phone. So, now Apple is starting to serialize those parts to the specific phones, so that those parts are also worthless. That just leaves the value of the scrap metal, which is extremely low, so there is extremely little incentive to steal these devices.
Activation Lock is an anti-thief practice, not anti-consumer, and it has nothing to do with how highly paid "tech workers" are.
Who are you to say that these people are grossly overcompensated? Why do you think it's an acceptable implication that because someone is well compensated that they do not have property rights against theft?
It seems to me this is another one of those "here's a thing that makes it harder for people to commit crimes, and criminals and criminal apologists flock to defend crime." threads.
The caloric content of a MacBook is incredible.
Yeah, right! 2c says these computers are MDM locked and still on the managed inventory. These recyclers should talk to their supplier. Just supplier saying “trust me it’s 100%” legal is not enough.
And yeah, I really don’t want Apple or any other manufacturer to make it easier to fence potentially stolen goods. Many people don’t remember the times when white earbuds (ie you have an iPod or iPhone) made you a hot mugging target! It’s not a thing anymore since Apple added reselling locked devices worthless.
However, I think we can all agree that when Apple is selling genuine replacement parts, those parts should be ready to pair with the first phone they're put into, instantly, without needing to call Apple Support to finish the repair process. You should also be able to order the parts without needing to give Apple your device's serial number ahead of time. Otherwise, repair shops can't keep genuine parts in stock, and your ability to complete a repair is entirely dependent on whether Apple is staffing their call center sufficiently, which is currently a requirement.
Optionally, maybe there would be a way where the phone could prompt the user to choose whether they want to serialize those replacement parts to this specific device, and then they would be registered with Apple, unable to be moved to a new device if this one were stolen and parted out. An automatic check for whether these parts have previously been registered would not be as onerous as a phone call.
Forget stolen, the idea that you have to go back to the original vendor to transfer a product is anathema to the prior 100 years of product purchasing experience.
Why isn't this an infringement of the "First Sale Doctrine"?
If they're recycling it, the recycling company should tell them "hit the reset button before sending it to us" and take the 2 seconds upon receiving it to verify, rather than waiting to learn a month later when the owner isn't known.
Edit: people are asking, the old iPhone 5 was left at a yoga center for over a year in the lost and found. nobody claimed it. nothing nefarious. my friend who works there gave it to me to see if i could get into it. nope. e-waste. no way to contact the original owner. ended up buying an iphone 6 with a broken screen off fb marketplace for $10... problem solved.
personally, i think they should either have some better mechanism of contacting the original owner or they should have a way to totally wipe the phone after some extended amount of time to get around the theft issue. if someone activates the device again with an icloud account, maybe the device could be restricted until apple contacts you or you provide proof of 'ownership' to the police or something.
so, they only have to detain you for 30 days before the lock expires. nice.
My oldest child, who is the only one who could have somehow taken them over, never had an iCloud account, so we are stumped. Stumped with three bricks.
It was a nightmare of two trips to the apple store and all sorts of machinations. This was a machine she bought direct from apple. They acknowledged this. There are certainly some issues with their processes which seem to make machine single owner.
I hate being held hostage to a corporation. Anti-theft mechanisms propagated from a corporation should be understood to generally benefit the corporation first (monopoly on resale market) and the user second (limited protection from petty theft).
I know I'm charmed to live in a place where petty crime is relatively low, but these sorts of "lock it to my Apple account" anti-theft tools feel awfully similar to the use of martial law. It's very helpful in limited circumstances but should never be the default state of our lives.
> Many bypassers have claimed solutions to T2 macs (I have not tried or confirmed they work…I am skeptical) but they admit they have had no success with M1.
Well... The T2 was actually based on the A10 Fusion chip, which is vulnerable to the checkm8 boot ROM exploit. Which, then makes things much easier when you can run arbitrary code. Apple partially fixed things in the A11 and fully fixed them in the A12. Meanwhile, M1 is based on A14 and impervious to the Boot ROM exploit... so no wonder they haven't had luck.
It's probably hard enough to disable when you can run whatever code you want. But when you can't even run code or get in the door...
Wiping is the right concept here. Unlocking is not.
Sure, yes, you need to unlock in order to wipe. Duh.
But unlock is not sufficient to prevent harm.
The owner of the laptop does. fucking. not. have the right to give away the private information of other people that is stored on the laptop. Photos, contact info, private communications, etc., etc.
Wipe, not just unlock. Let’s use the words that fit the end that needs to be reached, not just one step toward that end.
Maybe the true question is, why is somebody getting rid off a 2020 computer? Sounds so wasteful to me.
I took the minute to read Apple's instructions before selling so they had no issues, and it's no longer attached to my account.
My partner has an M1 MBP with very minor liquid damage on the keyboard that took out most of a row of keys. Apple wants to replace most of the computer for something that I assumed would be $75 in parts, and wants roughly $750 (most of the price of the computer).
Will these scrap macbooks help reduce the parts prices for 3rd party repair shops? Or are parts like the keyboard now locked to the computer?
As long as the machine is guaranteed to be wiped as part of the process, this is not a bad idea at all.
I did some Google-ing, but only got Asahi Linux as a first M* ported beast, without any details if it can be installed on a bricked Mac.
On the other hand as I know for Asahi you still need to boot into MacOS and have access to the Terminal.
In other words: we're buying Lenovo's next time.
Alternatively load them all with the same account with local credentials: reseller:password
And if they don’t, all they need to do is contact Apple supplier with their proof of purchase
Anything stolen should be worthless. Discourage the theft of anything with a CPU.
Love it!
You can still unlock it and sell it, this would only impact re-sale of stolen items.
Afaik you can not change a BMW headlight yourself, because it has a little chip inside to identify the part. If your car electronics does not find the headlight serial number it's looking for, that headlight won't work at all.
So you'll have to go to a BMW dealership (or licensed repair shop) and they have to reprogram the car to accept the new headlight.
Does that really stop thieves? Probably not. Does it hurt end users who want to work for themselves on their cars (or anything alike)? Yes, for sure.
I’m ok with things being useless if they are stolen.
That has nothing to do with repair status.
If something is stolen, I think it’s fine for it to be a brick.
If you find my old laptop when I’m gone, I’m fine for it to be a brick.
If I want to sell it, I can unlock it.
Since these computers are still valuable, I think we probably end up with a new dynamic where contracts are updated so the previous owners get money back for unlocking them first. That maintains their value without opening a path for thieves to unlock and resell stolen macs.
Wait. There is no way to assign a new owner to these machines? If I had an old M1 Macbook that I wanted to give to a relative I wouldn't be able to?
If you wanted to transfer ownership:
1. Ideally, you'd reset your Mac through System Settings.
2. If you forgot to do that or didn't realize, you'd sign in to your iCloud account and remove the device, unlocking it for a new owner.
This is about situations where neither apply... which >90% of the time, is going to be theft.
It only fails if you don’t log the machine out. This is to deter theft, since a reset requires the user’s password. If it’s not been reset it’s a brick.
The other thing to note is that if the computer hasn’t been signed into iCloud or had Find My Mac turned on, none of this necessary. So someone who’s paranoid about phoning home can probably resell after a simple reformat.
imagine for a moment how valuable new cars would be if you could restrict the supply of the used car market by mandatory recycling when the first owner buys a new vehicle.
Apple benefits significantly at least two ways;
1. Increasing overall demand for both new and used (unlocked) Mac Books by restricting supply.
2. Used unlocked Mac books will have a better resale value on the aftermarket thus continuing the folklore that Apple products retain their value for longer.
This begs the question… how much would a used Mac book cost if Activation Lock didn’t exist?
What is the true market price of a used Mac book? Or Apple Stock?
You missed a way Apple benefits: buyers may find devices that are unattractive to thieves more valuable, so, be willing to spend more on them.
While computers have more confidential data. The article implies that the big company sold them to be destroyed.