https://support.apple.com/en-us/HT201065
(to some of the commenters, note Step 2 carefully -- the rest of this guide is for older macs)
https://support.apple.com/en-us/HT201065
(to some of the commenters, note Step 2 carefully -- the rest of this guide is for older macs)
Ive worked with second hand devices for a long time. Ive had many come through that have activation/MDM/etc locks and have tried calling the IT dept they came from and all but about one time they pretty much just laughed at me or just played dumb about it entirely. Apple and other vendors were no help in this as they just tell you to contact the original owner.
But at the benefit of less-burdened security teams, and greatly enhanced peace of mind for users and info-sensitive organizations? You can argue it's taking something highly risky like security and shifting those man hours to something not as threatening.
As the sibling commenter points out, this should also result in less waste as those drives do not need to be destroyed if the device is properly unlocked.
It isn't necessary to destroy the physical media anymore, so that reduction in e-waste is fine with me. Just properly erase the device by clicking the button in settings.
Unless, cryptography itself is broken... which would bring much wider-scale problems than destroying information on old drives anyway.
The IT department has no idea what kind of password that user was using, and they have no idea what kind of valuable data is on that machine. If that user's password was just "password" (or sticky-noted next to the trackpad), that IT department is going to get in serious trouble once all that proprietary data ends up in the wrong hands, if they didn't wipe the machine before handing it off to a third party.
If wiping the machine before getting rid of it is "extra work", then that IT department isn't doing their jobs to begin with. I'm certain such IT departments exist, but that's not enough of a reason to make theft easier.
Source: just wiped and sent back a MacBook Air to my old workspace. My colleague finished the macOS setup and logged in with their iCloud account. After resetting it again (to re-do the setup in the way they wanted) it was locked to my account. So not even installing macOS and logging in to iCloud will bind the machine to you.
Imagine doing that with a machine you bought second hand and the original owner can’t be reached anymore.
https://support.apple.com/en-us/HT208987
"Other ways to disable Activation Lock"
"Activation Lock is disabled when you use the Erase All Content and Settings feature."
Apple confirms that the feature works exactly as I said and exactly as users expect. I've used it myself, and it does work.
Users running software that is several major versions out of date will have a more difficult experience, since that button did not exist, and they would have to first remove Activation Lock before going into Recovery Mode to manually format the Mac. Those are the remaining steps that were linked several comments up from here: https://news.ycombinator.com/item?id=34505523
Apple has made the process as easy as it possible can be now, identical to the process used to factory reset an iPhone.
I’d argue if you can wipe it (which requires your iCloud account approval), install it as someone else, login with that new iCloud account, then reset it and it suddenly reverts back to the previous owner, something is wrong or very unintuitive.
The problem on Mac it seems is that there are two official ways to do it. One proper way (the “Erase All Content and Settings”) and one other way (the way we did it, boot into recovery and format it, then go through setup with another iCloud account which apparently just temporarily lets another user use the machine). On iPhone there is no user accessible recovery mode so that can’t happen there.
If you go through recovery, you can delete the content, but when you go to reinstall, you will be prompted for the credentials for the user tied to it.
Meaning, you can delete, but you can't reinstall without being prompted for authorization by the account that currently 'owns' that computer.
If you want IT asset disposition, it'll nominally cost you -- for pickup and processing, and optional value-adds like secure data destruction certificates. If the assets have remarket value, that can begin to subsidize the cost, easily zeroing it out, or even returning profit to the IT department. Recyclers are happy to pay IT departments to pick up their old Apple equipment -- and they know to ask ahead of time, "are these activation locked?"
These recyclers often have vertical integration on the refurbishing side, running an Amazon eCommerce department so they can directly capture that remarket value. And once they've got that going, their bottleneck to growth is how much material they can bring in -- which is never enough.
So the recyclers and refurbishers invariably need to buy material from other recyclers. There's an entire economy around selling pallet-fulls of used, minimally-inspected or completely "as is", Apple and PC equipment. Specialized invite-only communities exist for selling this material in bulk, with lots of overseas actors in on the game. Every R2 recycler is involved here, along with lots of actors from India and China in particular.
Having seen inside that sausage factory, fraud and theft is a legitimate problem. There's more than a fair share of "don't ask questions". More than a fair share of "yup we're definitely R2 certified, wink wink". More than a fair share of wining and dining the R2 auditors to get that certificate under the table in the first place.
I'm gonna go with the GP comment here -- the system is working as intended. Industrialized theft of this sort is much more eminently solvable through technological means than through overstretched law enforcement, especially when a non-negligible amount of material comes from overseas.
It's on the IT departments to figure out if they have enough time to activation-unlock their assets before disposition. Do they want to pay the recycler to pick up all that material, or do they want to sell the material and pad their budget?
A quick look at the Jamf documentation suggests it's pretty easy to mass unlock these devices, so I'm not buying that it's that much of a strain.
The activation lock removal is hardly an obscure hack, this is a process failure. Good on Apple for making these machines take their secrets to the grave.
I'm not sure you're being serious. Wiping a laptop before getting rid of it is SOP for a IT department. This is hardly a new requirement.
Again, the only people impacted are those who want to leverage their ability to take over a laptop without authorization.
If it’s a legitimate sale, the original recycler will require the seller to wipe/unlock the device or they will only give a steeply discounted price. If the seller is going to get hundreds/thousands less by not wiping the device, they will do it.
Thus, the only problem for recyclers is recycling stolen laptops.
I’m sure there are plenty of court precedents around bankrupt businesses trashing assets out of spite rather than selling them.
If the problem is the financial part, just go back to the person they bought it and get the money back.
If they're taking a risk and buying it legally from, for example, a police auction, or from someone who "might have forgotten to contact the owner": it's a risk.
If it was acquired illegally, I can't say they deserve a solution to their problem.
Nobody is entitled to get money in exchange for potentially stolen goods or items acquired without due diligence.
> use Erase All Content and Settings instead of the remaining steps in this article. For any other Mac or macOS, continue to step 3.
If you're using macOS Monterey or later on a Mac with Apple silicon or a Mac with the Apple T2 Security Chip, use Erase All Content and Settings instead of the remaining steps in this article. For any other Mac or macOS, continue to step 3.
Nothing else is needed to disable activation lock.