Apple’s Mac security is so good, it’s sending used M1 MacBooks to the scrap heap
macworld.com
macworld.com
https://news.ycombinator.com/item?id=34504752 2 days ago, 410 comments
> However, he neglects to mention that Apple already has a process to do this for legally-obtained products.
> The process is very simple. If a user has purchased an Apple product through means that will produce a receipt, like through eBay, users can request Activation Lock to be removed. All the user has to do is navigate to Apple Support and provide a receipt as proof.
> The problem Bumstead is likely running into is MDM or mobile device management. Apple will not unlock products that were previously part of an MDM system that's still attached.
So devices sent to a recycling center to be destroyed are being picked up and resold. So this whole thing seems like a non issue.
Seems to be an option at the bottom of this page.
I'm responding to parent saying it's not an actual problem:
> So this whole thing seems like a non issue.
...
Apple doesn't seem able to "produce a receipt" if you purchased the MacBook with cash or a discontinued credit card in their store.
I have a lovely pristine 2019 MacBook Pro 16" that I put firmware password on before crossing international borders, before pandemic. The Ventura update broke boot. I have to boot to recovery partition, but cannot. No idea what "this is obvious" firmware pass I came up with.
THIS IS MY FAULT. But a surprisingly expensive fault…
I have the original welcome to new Mac on your Apple ID email a couple days after purchase, the Mac is active in my Find My, the Mac is under AppleCare to me which I have. Apple will not unlock it without receipt, which I do not have, and, no longer having an account with that card provider, cannot produce.
This 2019 MacBook Pro sells used for $4,689 from Apple today:
https://www.apple.com/shop/product/G14X6LL/A/refurbished-16-...
So for me, it's an issue.
// At the same time, this is a reason we provide MacBook Pros to employees: we can take comfort losing one in NYC or Mumbai probably isn't going to compromise company data. This is worth the cost to me personally, and makes me an advocate of Apple's security work.
Apple business has told me no guarantees but as a company owner I could possibly get an exception through our company's Enterprise Support, which, as a user of that service, I have observed being more empowered than the consumer channel.
Whether that might work or not, it's likely not available to casual purchasers.
> Apple doesn't seem able to "produce a receipt" if you purchased the MacBook with cash or a discontinued credit card in their store.
I'm not sure if this is standard policy or a fluke. If true then Apple should absolutely not demand that proof of purchase back from the owner at any point. I can't imagine how it's legal to sell that in a store and not provide proof of purchase but that's a different matter.
For privacy reasons, they might not legally be allowed to keep purchase history around forever.
Surely you can see how just handing out a generic receipt to whomever shows up and asks for it is a real issue.
Lesson here is, for ANY merchant: pay with a credit card, have the receipt emailed to you if possible. If not take a picture with your cell phone of the receipt, _on the spot_. That's it, you are future proofed.
I like that I can't get into it. It gives me comfort employee machines with company IP cannot be readily compromised.
In a way, you pen-tested Apple's anti-fraud processes... although at your own expense ;)
I understand you're upset, but sadly I have to say to you that this is working as intended.
1) You bought a machine and can't prove it.
2) You enabled authentication which you lost
3) You also lost your backup to the account
How can they help you? How can anyone help you?
You've made it nearly impossible to distinguish yourself from a thief or random stranger.
I can prove it to a remarkable degree with the welcome email 3 days after this model was launched.
I didn't lose backup to account. I'd already migrated to the latest M1 MacBook, and my account is fine.
There's appears to me to be no backup to the firmware lock, there is a backup to FileVault, I have file vault.
I get it and am not complaining. But person above me said it wasn't a real problem.
My point is, it can be a $4500 problem for a legitimate purchaser.
This kind of security should be tied to something like removable storage device where the users data is stored, not the main device itself. That way when the owner dies or loses acess then said owner only loses acess to the data and not the entire device.
IMHO this is Apple trying to force people to purchase new devices and prevent reuse. It doesn't matter what is intended on the surface, but what the actual outcome is. This causes more waste and it's not helpful to the environment. If you are serious about protecting user data tie it to hardware security that can be decoupled from the device itself.
I'm in the business of repairing computers.Apple is setting bad precedence on multiple fronts, More than any other company in existence.
But most of us don't want to extend the courtesy to petty criminals.
Given Apple's staggering pile of cash, I think that we'll have decades of warning if they're going to stop existing.
Even though at any point said device can be unlocked, transferred, sold etc.
It is to stop devices being stolen, wiped and re-sold. It is an attempt to allow the legal owner of the device the ability to control who can use it, rather than the possessor of the device having full control who can use it.
Its only purpose is to protect the use of the device by people removing all the software (erasing back to factory defaults) and taking control of the physical device that way.
Assuming you know your Apple ID password, disabling Activation Lock takes less than 30 seconds. You can even do it remotely via Find My on the web.
It hasn't exactly curtailed the legitimate iPhone resale market in the ~seven years that it's been on by default, either, though it did produce a dramatic drop in people getting their phone snatched from their pocket[1].
1. https://techcrunch.com/2015/02/11/apples-activation-lock-lea...
I think that overrides any user set firmware password, so might allow you to recover it,
Just a thought maybe a little searching can validate it before you might try?
The number of people who manually set firmware passwords on their Mac (i.e. don’t have it set as the result of MDM) instead of just using FileVault these days must be vanishingly small.
Well, that's the fundamental problem. With open hardware that you fully and completely own when you buy it, such problems are impossible.
The move towards hardware (mostly by Apple but not unique to them) that remains firmly in control of the vendor even after you buy it... is not a good one. It means your ownership is relatively ephemeral, any wrong move (or bug) and it's no longer yours to use.
Not a world I want to live in.
A better problem, some may say, than having a thriving market for stolen laptops.
> Not a world I want to live in.
But a world many may prefer to the world with a thriving market for stolen laptops.
Some may say that, because having their laptop stolen is a problem they actually experienced. Having your device remain owned by a vendor, who only "licenses" it for you to use opens up a whole new world of problems, some of which average person can't even imagine.
Actually, everyone experiences this right now. Macbooks are working like this. And 99% of people are fine with it. We don't have to imagine anything
That's not true. I think you're saying that Mac users are already today in an ecosystem where this could bite them hard, that much is true. But nobody gives it any thought until they personally find their multi-thousand dollar device useless and Apple refuses to help even though they totally could if they cared. Only then do they realize what a terrible situation it is.
It is only thieves and ideologues who actually experience any difficulty. And while I’m all for righteous purity, I am also happy knowing that the thief who stole my MacBook from Spaces coworking in San Jose (do not ever use Spaces!) will get nothing for the risk they took, and/or that a buyer taking a too good to be true deal will get a brick.
Yes, I like this world better than the free-open-insecure alternative.
That might be a minor consolation, but the bigger point is that this will (hopefully) significantly disrupt the market for shady used MacBook sales and thus the incentive to target MacBooks for theft.
This is the government encryption backdoor all over again. There is no such thing as a security backdoor that can be used only by good guys. If Apple can’t determine someone is the legitimate owner of a locked device, they have two choices: allow thieves to unlock devices, resulting in more theft. Or decline to unlock for some legitimate owners who chose to lock their device and not take precautions.
It’s a tough choice, but I think Apple is making the right one here. You may disagree, and that’s fine.
Or should Apple just remove the activation lock feature, that was added specifically in response to large amounts of theft because we don’t think those thefts are going to happen any more?
He took down the details of it.
That's much more dangerous for the society than a few thieves making a buck.
I haven’t used Asahi yet but the way I understand it you can install Asahi right away and the hardware is forever yours to control.
And if you are worried about Apple one day remotely adding a lock to your Asahi laptop you can probably block those requests proactively on a network level anyways
One could convincingly argue that dead accounts are e-waste.
The main reason I guess we don't say that is because we have expiration policies.
But if you lose access to your, say, facebook account with 100GiB of uploaded content, then that content is going to be sitting consuming at least 300GiB of media (replication, backups etc;).
Thus: is that a problem?
I see a device like this as an extension of my self, having it "open for all" is not desirable; I want to knowingly give it to someone.
If someone takes it, or I do not unlock it, then I don't want the possibility for it to unlock. I paid for it, it's mine, in perpetuity until I say otherwise, even if I'm dead: since as I mentioned it's an extension of me... it is dead too.
Funny misconception, that. You paid for it, but Apple controls it. You trust Apple to do the right thing, but you cannot prove that they do. You cannot hold them accountable for doing the right thing, either.
So, how can you trust it as an extension of your self? I understand your argument, but you've based it on a misconception if you think you're the ultimate user with the greatest authority over your device. Apple makes the rules, the only thing you do as a user is agree to play by them.
Unlocking a device by apple has no bad incentives associated, at the very worst case someone else can use your owned device without access to any of your data, aka stealing. And that assumes that apple will corruptly open it for someone else which they have zero interest in and that just accounts for regular old stealing with a billion dollar company’s help?
We just have to trust their implementation, which is conveniently proprietary and unaccountable.
> And that assumes that apple will corruptly open it for someone else which they have zero interest in
Are you sure about that? They very publicly gave the Chinese government control over Chinese iCloud data a few years ago. That, and they've been part of PRISM for the better half of a decade now. When a company has a working relationship with multiple sovereign governments, I'm not sure you can strongman the "Apple will save us" argument.
This is also a problem with Google, Microsoft, Amazon, 95% of cell carriers, most cable companies and your laptop manufacturer (regardless of company). Apple knows you feel insecure about this, so they market their products/services to you with this in mind. News flash: does anyone really think the largest company in America (let alone the world) isn't in kahoots with the American government? Microsoft was. Google was. IBM was. And Apple is bigger than them all.
Encryption is great. Mixing it with snake oil isn't. People are correct to call out Apple's failures to protect their users in this conversation, because their track record isn't very benevolent.
I also have to trust Debian, as I can’t audit millions of lines of code.
You really have no choice but to trust your OS vendor. If you don’t, find another vendor.
Apple doesn't have accountability. It's not that nobody wants to prove them right, it's that their system has been deliberately designed so that no one can.
A corporation buying hardware from another corporation. The “user” here is and was never in control of the hardware. The only human beings close to that role are the IT department.
Like it or not there are legitimate reasons corps do this. HIPAA, SOC, PCI, good old fashioned responsibility, etc. Apple isn’t the only vendor that sells systems and hardware locked in this fashion.
The reason we’re talking about this and not anyone else:
1) Apple is one of the world’a most valuable companies.
2) There is a tiny but very loud minority of people who have a seething, irrational hatred of them and cannot ever acknowledge anything positive about them.
3) Their solution for this is actually implemented well and can’t be bypassed.
I understand your point but we’ve gotten here for valid reasons - “XYZ employee gets laptop with 100m SSNs stolen”, etc.
Speaking more broadly, you are aware that with Apple Silicon they had a massive opportunity to do as you say and “own” user hardware, right? It would have been trivial for them to utilize all of this to prevent alternate OS installation. Even if they did lock out alternate OS installation they’d lose what, 0.5% of sales from the people ranting about Apple on HN that were never really going to buy Apple anyway?
Yet here we are with Asahi Linux.
That's not the reason you're prevented from resetting the laptop.
I don't see why, in principle, you couldn't have open hardware that provided the same capability to brick the device for unauthorised users. In which case you would be just as SOL if you forgot the credentials to that, too.
Unless you lose the password to unlock the BIOS.
Which is not resettable via the (now very old) method of removing the CMOS battery or shorting a jumper on the motherboard for at least a decade.
(I had this issue on a HP Elitebook 8440p from 2011)
I don’t understand. If you have open hardware that you have full control over, choose to lock it down to make it impossible to factory reset the device without a password, and then forget that password, how does having open hardware help?
If you say “there always should be a way to factory reset the device without a password” you are giving up a feature that Apple provides: making it less worthwhile to steal Apple devices.
Either you have an activation lock like feature or you do not.
If your hardware has a path that allows a random person to circumvent it, then by definition it does not have an activation lock.
This isn’t an open vs closed hardware question. This “does this feature exist”, and your argument is that it should not. This is spite of the fact that activation lock was a feature introduced specifically in response to high rates of theft, and its introduction immediately reducing that theft.
Activation lock is a feature that people want, but again activation lock is either there or it is not. If your “open” hardware includes a mechanism that bypasses an ownership lock then by definition the lock is not a functional if feature.
A company can make an open laptop that has an activation system that requires an authentication in or to do a full device reset, or to replace the firmware. But if that lock is in place, it can’t let you flash a new firmware on or reset it, because again that defeats the purpose.
They literally can, but are choosing not to. If there is concern about stolen devices, then there could be a way for victims of theft to submit such information to apple and then when someone wants to purchase a used laptop they could check whether it's stolen. They could also provide a mechanism by which a laptop could be submitted for unlocking and sits in the request queue for three months pending someone saying "that's mine!"
At the end of the day it's bullshit that functional laptops are going into the trash stream for artificial reasons. There should be a tax of 10x the highest global retail price of the device assessed against the manufacturer.
They refused acknowledgement of the credit card because they say it could’ve been stolen and they refused state ID as it could’ve been stolen or forged. They refused acknowledgement of documentation from the police. They said it was my folks fault for putting the boot lock on as it warns you, but my folks weren’t the ones who did that. I didn’t even know that boot lock existed until then. This experience was in the same original Apple store my folks purchased the computer, which is why I presumed state ID and original credit card would’ve been adequate.
Unfortunately my folks had made themselves indistinguishable from foreign intelligence. The amusing thing is that if they're so worried about forged government ID's and stolen credit cards, then how on earth can they trust a receipt? Unlike a government ID, your face isn't on it.
If thieves can just list on eBay and tell user to take the receipt to Apple…
None of this is an issue if its actually real second hand.
https://twitter.com/rdklinc/status/1617541547469193217
> Wrong -- it means that 1000 of these devices were dumped from an institution to a recycler without even bothering to log out first. And these apathetic institutions don't return calls when asked to unlock because they want the machines destroyed.
On the other hand, if the original owners want the machines actually destroyed and not resold then I don't see the problem here.
I think apple should run a refurb but they wouldn't as that would depress their retail price.
The devices are recycled just for parts. Even the motherboard will have parts removed and reused.
It's a lot more work than flipping the laptop on eBay.
Like the most wrong I've ever been.
Well once I made a marmite pizza, other than that I've never been so wrong in my life
I think people should at least make a good faith effort to look this shit up before gettin' all snarky:
It's not just "unfortunate": our wildly consumptive and wasteful nature is a crime against future generations.
It's not just that our consumption and waste production are at record levels, to the point that we have damaged our climate!, but that they continue to increase at exponential rates.
All of this central control assumes the central control will still be there in the future. Someday, apple will cease to exist, and when it does, there will be millions of unverified bricks that used to be computers.
Recyclers are going to have to have to make it worthwhile to the businesses they source their product from, and be a little bit more upfront about it, if they want to recycle these devices. What they want to do is whine to Apple so they can continue to go behind their customer's backs like they do now with every other device.
So he stole those then? Because he's not the rightful owner right? Even trash belongs to someone.
I remember hearing that in certain "protests" (definitely not riots) a couple years ago, where people were looting stores, Apple was able to easily get the serial numbers of all the stolen devices and remotely brick them. The contrast of how valuable Apple products are both new and second hand, compared to how useless they are to steal is pretty wild. I can't think of any other product like that.
Whether you agree with their position or not, it's not really relevant to this discussion to draw attention to the ethics of those protests/riots.
It is not a good look.
It costs nothing to be polite. Even if your political beliefs revere rudeness, leave it at home here.
(Also, this makes it easy to delegitimize any protest: send some looters. As soon as anyone loots simultaneous with and adjacent to the protests, it is now a riot.)
This is true. The problem is, no one is doing this WRT any of the "civil disturbances" that happened over the last few years.
> this makes it easy to delegitimize any protest: send some looters
Or anyone willing to make the protest cross the line from "peaceful" to "violent."
Of course, these caveats can be just as easily applied to events in the midwest as to events in the capitol.
I wonder if they could burn a fuse when the user logs in so that Apple can no longer do that but the owner can.
If you don't trust Apple to not remotely brick your iPhone, don't buy an iPhone.
If you go into the Apple store and request a firmware reset, Apple will ask you for the original receipt before sending it off to the factory to do it, but they can. But given how expensive their laptops are, a rogue employee at a computer recycling center could still slip in a few stolen ones and pocket the gains if Apple worked with recycling centers to unlock their laptops.
Why can't I be the one in control over my own laptop if it is stolen?
Or why can't I assign a different entity to be in control over my laptop?
For example I could run my own account/password system, and lock my own phone if it is stolen. Or transfer that right to another organization.
Saying that "vendor can remotely brick the phone" is the only way to have this functionality is not true.
If your own laptop is stolen, you're no longer in physical possession of it.
So from the perspective of the laptop, some sort of interaction should brick it. What should that interaction be? It needs to happen early, before thieves have a chance to disable it. So it needs to happen before login, say. Really it needs to happen at either bootup or as soon as the laptop establishes a connection to the internet.
At which point it should... reach out to you? How? Must you own a second Apple device for that to work? Okay, let's go with that. You have an iPhone, and you use Find My to brick the laptop. So now someone can steal your phone and use it to brick your laptop? Your laptop needs to talk to your phone every time it boots up or connects to the internet?
I'm not sure you've thought this through.
It seems reasonable to me that the only entity that makes sense here is Apple. Even a savvy thief, who might block packets to anywhere unexpected--and "person's iPhone somewhere" is definitely unexpected--is going to need to let packets go to Apple, making them the only party with the means and opportunity to do this.
Just make those bytes point somewhere else (assuming Apple allows you to), and run a server at that location and you're done.
What is the problem?
Also, as I previously mentioned, sophisticated thieves can block traffic anywhere other than Apple by default.
Not really. Encrypted data on the drive, password protection to get in should be enough. If the password implementation is top notch it essentially is a brick to anyone not in the know — time will be of no use to them.
It's really not that hard to design a system that will become essentially a brick when the password is lost. E.g. just put some flash memory on the main processor chip that partakes in the encryption of the harddrive.
Yes, that is the sales scenario for remote lockout. Its kind of lame, like "if I can't have my thing then nobody else can either and it becomes e-waste," and also depends on a crook being smart enough to realize this valuable looking thing has no resale value.
Now run out the scenario where you are the Canadian truck driver or in some other politically unpopular position and getting progressively locked out of stuff. Maybe the feds start leaning on Apple like they do to debank state-level authorized herbal commerce. Maybe some other entity gets into Apple's system and holds your computer hostage. It seems like the wrong direction for computing devices.
On one side everyone wants security and privacy. But when they get it they complain when it prevents them reselling devices that are not theirs.
Over time, people learn this and it becomes routine just like people buying used cars know to check that the seller really owns it and isn’t lying about the collision history.
This could be true, but as I mentioned in another comment, as soon as it's removed from the original users iCloud account that lock will be removed.
> how can you trust that the "erase everything" works?
You can't remove it, but as long as nobody else can use the device to recover data then it's fine.
FWIW it's actually pretty easy with SATA SSD's to set a device key, which then encrypts everything on the drive at full speed: https://github.com/Drive-Trust-Alliance/sedutil
The drives are actually already doing this, it's just that the key is set to 0's.
I can imagine that, given the drive is accessed via T2, that Apples NANDS are being accessed the same way, in which case scrambling the key is enough to make it unrecoverable permanently.
There are plenty things to say about apple, but their devices do serve their lifetimes. I would be much more worried about the litany of low-end laptops and mobile phones that end up in the trash with zero value in a year.
People don't always take the time to go through everything.
Traditional disk encryption serves your protection perfectly well.
As the saying goes, "Those who give up freedom for security..."
Also industrial espionage is a thing and but I agree with you that's probably a minority of thefts.
Sometimes the data can be valuable as well (perhaps you can be blackmailed, or perhaps they can steal additional things from your bank accounts etc), but that is far from guaranteed. The hardware has a clear value though.
Full-disk encryption protects your data. Activation locking dissuades theft.
Personally, I want both.
The only time this is not true is when the previous owner has intentionally marked the device lost or stolen in the find-my App/Site.
I think a lot of this backlash is recyclers getting stolen goods.
(Also, iCloud lock is bypassed if there is an MDM, like in a corporate setting- then the icloud lock can be remotely enabled/disabled by the organisations IT department)
Exactly. I don't need Apple to protect me from thieves, I need the computer that I bought to protect my information.
You will likely get a little bit of Herd Immunity because Apple devices are known to be miserable to steal.
But otherwise it will work as you expect, just add some Filevault for FDE.
If you're advocating to remove these features for the rest of us, then as an Apple user: no thanks.
Not at all. It obviously needs to be better documented or changed since so many legitimate resales are being affected.
keeping information private and/or secret and rendering a perfectly usable device a brick are two completely orthogonal things.
My laptop is perfectly secure, without Apple having a say on what I do with it after I bought it. Including reselling it.
p.s. if someone saw my laptop and a mac laptop left alone in the same room, they would try to steal the Mac, making my laptop even safer by virtue of not being from Apple.
A lot of people around are claiming the exact opposite: thieves have learned that stealing Macs is useless, while other laptops have clear re-sale value. The retail price of Macs is irrelevant if there is no way to fence them, and if thieves are aware that there is no way to fence them.
thieves have also learned that the only easily re-sellable laptops are the $200 brandless stuff bought on Aliplay, that are probably not worth it.
every brand laptop today can be registered, has some form of "find my laptop" and supports encrypted filesystems
Macs aren't good only for re-sale, but also for spare parts and/or raw materials.
Nobody would steal a Trabant over a BMW just because the BMW has more sophisticated security.
Thieves are able to learn new tricks too.
Except this entire thing blew up because of recyclers bitching that the laptops were only worth the value of scrap, something like $13.
They are quite more valuable than the bare aluminium case.
In 2016 Apple declared that it had recovered nearly 90 million pounds of materials from Apple devices recycled through its program in 2015. Sixty-one million pounds of those materials are reusable in future products, including 2,204 pounds of gold
From an environmental POV Apple should allow people to use/re-use/resell their devices as long as possible. Of course that would not align with their interest that is selling as many new devices as possible.
OTOH e-waste should not be allowed under any circumstances when the raw materials are scarce and/or retrieving them is damaging to the environment or they are polluting.
Last but not least the device destiny should be under the control of the person in possess of the item, unless the item was stolen.
If someone brings their car to my junkyard to destroy it and I fix it and resell it or dismantle it and sell it as spare parts it's completely under my rights, I don't see why electronic devices should work differently and why the manufacturer should have the keys.
Don't let me start on non-Apple compatible replacements parts that Apple won't let you use, even if the warranty has expired.
Non sequitur.
The device is mine when I buy it, but it is sometimes impossible to unbrick something that Apple bricked.
I would rather let you pay a premium to have the features you so much want, because annoying the majority just because you want something, should cost you more.
Also the will to generate useless e-waste should be punished, we are past the times when people (especially americans) can use the entire planet as their own junkyard.
That might be true now, but it might not be as time goes on and this bricking functionality becomes common knowledge.
Just because there are criminals out there we shouldn't mandate all and every honest parties prove themselves of their innocence proactively....
I am surprised this security vs. freedom things is still something where people argue so overwhelmingly for the security part against themselves despite the many many many bad experiences throughout the history in various levels....
(there are schemes where the ownerships is strictly controlled but by a public body of the society with regulations around it - house, car, etc - but not a private business oriented organization's coined policies and online account implemented by there sole discretion and judgement who is allowed to use what, what constitutes acceptable proof in their view, and who is given access to that authoritive account and who is locked out eventually, potentially for a completely independent reason)
I can do that! I can refrain from buying for the sake of the humanity, no problem! : )
I sympathize with the resellers here. Often times the original owner cannot be contacted. Maybe they are dead and the machine came form an estate sale. Maybe it was sold on consignment or something. Maybe the original owner is just very difficult to find.
I bought a MacBook off an eBay seller, and had to deal with this shit. It took the seller forever but by some miracle he was able to track down and contact the original owner so he could unlock it. Without this hassle, a perfectly good computer would have been e-waste in a landfill somewhere.
Frustrating the legitimate second hand market and the ecological impact of all this waste is a high price to pay for mere anti-theft. Companies are very eager to kill the secondary market for their goods, and accepting this scheme plays into Apple’s hands.
A simple solution that protects both sides, it just so happens to conflict with Apple's earnings goals.
You might not give a shit about recycling but Apple says they do[1], they really love to go on about how much they care about climate change and the environment. It's important to point out clear violations of those claims so others can make informed choices.
For example, a possible solution could be the following: If a device is locked to an account, the new owner can send an anonymous request to the apple account of the previous owner of the device, asking them to authorize an unlock. This would protect stolen devices, while also making it possible to recover devices where the previous owner was simply neglectful in unlocking the device before selling it. Of course, it would not help if the previous owner is dead, but anything helps.
Look if you just want to get your 3 minute hate against Apple out I'm happy to yell and scream with you (fsck their walled garden), but scanning for CSAM on your device (which they took back and aren't oing) is not the same thing as fighting thieves. Hell, Apple recently made the move to allow iCloud backups to be fully encrypted, impervious to Apple, the local police department, the FBI, the CIA, and the NSA (unless they've broken the encryption scheme, and they didn't tell anyone, which is entirely possible, but that's like Edward Snowden levels of "they're out to get you"), so I'm not sure how they're "the police now".
Adding a similar real interface (even if delivered by Find My and not texts) would just make phishing more successful. That’s why Apple Support/2FA prompts are verbose popups on every device you own at the same time.
I get it, people are conditioned to vendor lock in because of cell phones. In reality it's incredibly wasteful. I'm still not convinced the current way of doing things is best for the consumer.
For the dead person scenario, you can get access to iCloud with a court order once they are deceased, or if they have set up their legacy contact. So that would be the procedure to unlock the device.
For the ones in the article, the people sending them to the recycler seem to be refusing to unlock the devices and want them destroyed. Perhaps Apple should take back these machines for refurb in such a case (especially since they’re quite new)
Even for important memories, has anyone heard of anyone else actually doing this? Just curious, lots of deaths in my family lately and i'm positive none of the grieving members would attempt a court order
That seems to be the obvious solution: let Apple reset them completely, wiping out anything that could possible store any data, and make the components usable again. As long as Apple doesn't pay out any more than the shipping & handling of the laptops, there's no profit motive so the theft protection is still there but the planet is just a little bit greener and happier.
Alternatively, the machines can become donor boards instead of e-waste.
Owners can now remove devices via web site I think. So if folks are saying these are just broken, have owner turn off activation lock
Give the original owner 30 days and if no response unlock it and let the thieves win? Uh, no I don't think so. It's not a far stretch to think everything got stolen and the owner is now locked out of their complete digital life.
Everything what? Do laptop theves also usually steal your sticky note with password?
For this to work and for the device to _see_ that it has been removed from an account requires that even in it's locked that it must be able to start up and allow the person with physical access to at least configure some network details right?
I expect that some means to "phone home" is required. I just had to spend an hour on the phone with Asurion to avoid a $300 fee for returning an iPhone for warranty replacement where the Activation Lock wouldn't turn off despite removing the device via the web site.
I think you used to be able to run stolen phones back through insurance claims as broken but I think that has stopped being possible as they take a harder line.
Now a common scam is for someone to sell an iPhone and then report it stolen, getting a new one on insurance and pocketing the sale.
This is still an overall better situation of course.
Stolen product still had some value via bogus warranty claims because that process didn’t always cross check lock status because item was “broken” or wouldn’t turn on and apple doesn’t always put serial number externally visible. If person fixed laptop they’d find it was locked. All that has tightened up I think?
That's the most complex set of steps to disowning the Apple.
If all buyers checked that the activation lock was disabled before sale, we wouldn't be having this discussion. I prefer the reduction in crime that activation lock promises.
That said, at least for phones activation lock was game changing. Not sure about laptops, maybe they can't ID them or fewer activate lock or there is a way to use them in a claim scam (ie, damage and "return" laptops while reselling the real one?)
> Apple encourages owners of older devices to participate in the company’s trade-in program
Which is a pretty bad program, reusing is always better than recycling. Apple will just scrap it into basic elements: metals, maybe lithium.
There are so many ways this could be resolved without destroying working equipment. Apple presumably knows who the registered owner is - they could be contacted. They could be unlocked at Apple stores, with various details taken to facilitate any potential theft investigation.
When laws were passed to require Apple to enable the feature by default on it's phones, society certainly seemed to think it was in everyone's best interests.
>The temptation of a smartphone for a thief is dropping, thanks to Apple’s decision to implement a remote kill switch via Find My Phone that can erase and disable a phone once it’s been stolen or gone missing. A new report from Reuters found that iPhone theft dropped by 50 percent in London, 40 percent in San Francisco and 25 percent in New York. The drops represent theft activity as measured during the 12 months following Apple’s introduction of the remote locking feature in September 2013 as part of iOS 7. With iOS 8, Apple made its so-called said “kill switch” active by default, in accordance with California regulation, and that should help the rates of theft continue to trend downwards.
https://techcrunch.com/2015/02/11/apples-activation-lock-lea...
We're talking about 2-year-old M1 macbooks [1], some of which are worth $1000 unlocked and approximately $0 locked.
Even with broken screens etc, the owner can unlock them online. Large institutional owners like schools can get them unlocked in bulk through device management. And even if the institutional owners messed up the device registration and it's been locked to a fired employee's personal account, Apple can unlock them using the original sales records.
In the absence of theft, it's difficult to imagine why the owner would be refusing to unlock the device, given they could share $1000 of value with the recycler. There aren't that many macbooks being repossessed by bailiffs.
But if the devices have been stolen? That easily explains what is otherwise mysterious.
[1] https://www.vice.com/en/article/xgybq7/apple-macbook-activat...
It's generally not the owner refusing to unlock. It's the owner not being able to work out how to do it. Forgetting or not knowing they needed to do it. And/or not being contactable.
Even when hundreds of dollars is at stake, which could surely pay for a few hours of phone calls walking people through the unlock procedure?
If you believe that, I've got a bridge to sell you.
What, like cars?
Anyway, doesn't Apple refurbish devices? Will they not accept these devices back?
They have a refurbished program so they definitely don't just scrap devices you trade in. Maybe they even scrap some devices for parts. In the server space this is normal. HP would regularly send us refurbished replacement parts for repairs (this is also one of the reason why they want the replaced parts back).
> Apple rejects current industry best practices by forcing the recyclers it works with to shred iPhones and MacBooks so they cannot be repaired or reused—instead, they are turned into tiny shards of metal and glass.
This is also what’s written on the agreement in the screenshot of this article but they don’t mention it in the article.
I don’t live in the US but in Switzerland you have to get the customers approval to refurbish and sell hardware that you take back from customers. This is probably similar in the US.
False: for just one counterexample, Apple employees receive refurbs from trade-in as work machines. (Source: First hand experience of years).
Ideally you should be able to take such a locked device to some official place, like a town hall, and they should be able to look up the previous owner. If they are deceased or they confirm that they no longer want the device, then after checking IDs and so on that office should be able to start the process to unlock the device. (That same department could give you recourse if your house burns down and you loose all your digital accounts, or you are locked out of Google unfairly.) Our civil institutions have not really kept up with technology here.
Edit: Of course I wouldn't give government the capability to decrypt anybodys device or something! Just have an organisation that's purpose is to clarify ownership, and wipe and reuse devices so they don't end up as in a landfill. I don't really trust the vendor alone to optimize for reusing used devices.
I do not want anyone, least of all city hall to be able to unlock my stuff under any circumstance, including the one where I’m dead.
There should be a big cerimonial thing where I go to a place with a sworn in official, show my ID, and say "I hereby lock down this device for all time with the power of cryptography" so that nobody can use it as long as I'm considered the legitimate owner.
OK I'm exaggerating. But the problem is real. If you buy a second hand device this can happen, or if you have a company and a previous employee doesn't unlock it for some reason. Yeah, ideally you should have documentation of an unbroken chain of ownership and should be able to go to Apple. But in reality that doesn't happen, and I think Apple isn't the best custodian for this. They don't have an incentive to reduce the number of thrown away producs. (To be clear, I wouldn't trust current governments either! But conceptually, this function belongs in the civil area and not in private hand.)
When you buy an Apple computer as a company you should enroll it with MDM.
MDM bypasses this issue completely, you can remotely wipe and re-use a computer if it's signed to a companies MDM.
If you buy a second hand device and this happens you bring it back to whom you bought it from and ask it to be unlocked or your money back. Same as if it does just not turn on.
> if you have a company and a previous employee doesn't unlock it for some reason
You put it into the offboarding process to check this. If it is missed or can’t be done for some reason you take it to Apple with proof of purchase and they unlock it for you.
> But in reality that doesn't happen
Yeah. Like for example you fenced a laptop from a shady guy.
Why do you think anyone here is talking about decrypting your data? What's being discussed is wiping the devices and making them usable by someone else.
I wonder if there's any organized crime groups that have tried to get someone hired into Apple support for unlocking these things.
This is already the case legally: if you lose a court case, Google will follow a legal order to turn something over to the winner. If you're suspected of some kind of crime, Google will follow a legal order granting the relevant authorities access to something like your Gmail messages.
It's also important to remember that this is a real problem affecting a lot of people: ask anyone who deals with the larger public and you'll hear that it's not uncommon for people to change email addresses after getting locked out of their old one, and that problem disproportionately affects certain groups of people (e.g. the elderly).
What would make sense in this regard is something similar to what Apple does where you can optionally set up a legacy contact who is allowed to initiate a password reset, presumably with time delays and notifications (“your password will be reset in 3 days unless you deny this request”). Imagine an option where you could do something like go to the local public library, DMV, police station, notary, etc. and they could basically login to a special Google form to attest that they did a full photo ID validation to confirm that your ID matched the ID registered to an account. That would be useful for thousands of people and if you made it optional, people who are especially worried about their government could choose not to enable it.
If you don't think both the Democrats and Republicans would love nothing more than a few easily-squeezable companies being the clearinghouse for everyone's data, then you're exhibiting some quite hard cognitive dissonance. There are already companies in existence with the sole focus being to funnel your data to anyone who asks, including the government.
So why not use that to reduce bricking?
Local governments struggle to provide basic services like roads, emergency services, and utilities. Offering a product registration service for Apple devices is so low on anyone's priorities that it might as well be in a different universe.
Yeah. Sure. You can’t wipe the drive on an M1 and have the machine still boot. Reinstalling the OS doesn’t erase the data volume.
You have to use Erase All Content and Settings. Apple documents the process pretty clearly.
...but if you forget to do that stuff, the Mac will indeed be unusable by the purchaser.
When they didn't have measures like this on the iPhone and Mac, they were lambasted by local police and DAs for not doing anything about theft.
Now they have it, and it's causing otherwise useful devices to be rendered useless. There's going to have to be a very finely-crafted compromise to be usable, enable reselling when the original owner has forgotten or is unable to do things, and prevents theft. They've made some strides towards this but cases where MDM devices are liquidated but not de-enrolled are still problematic.
No, they weren't, they just want you to think they were. They're not special vs other computer manufacturers in this context.
> and it's causing otherwise useful devices to be rendered useless
This is a win for them. They don't want you reselling devices, they want you to throw your old devices in the trash and buy brand new ones.
It was a massive campaign by New York City, SF, and other officials in the media to say Apple was not doing enough about theft and it was causing petty and violent crime.
https://www.theverge.com/2013/5/13/4326690/new-york-smartpho...
"win" can't be zero criticism, that's way too high of a bar.
The issue is the laptops are received by recyclers in an ill-gotten manner.
Companies were sending thousands of laptops to be destroyed and instead the ended up in recyclers who are attempting to wipe and then resell them, which is why recyclers could not get the original legal owners to remove the activation lock.
If the recycler had an agreement to wipe and reuse the machines, and the activation lock prevented it, then those thousands of machines should be shipped back to the company to dispose of, along with a bill for the shipping cost, and time.
> Often the previous owners are corporations or schools who buy and sell the machines in bulk and aren't interested in helping recyclers or refurbishers unlock them. "Previous owners do not return phone calls, and large corporations that dump 3000 machines assume they have been destroyed, so it is critical we have a solution that does not depend on the previous owner approving,” Bumstead said.
But if you check his website[1], the terms of sale make it clear that devices are intended for resale:
> Although RDKL, Inc., always attempts to erase hard drives and remove personal data before a device is sold to another party, RDKL, Inc., cannot guarantee that all traces of the seller's identity have been permanently removed, and it is therefore the seller's responsibility to remove personal data from a device before selling it to RDKL, Inc.
Why would he pay for devices that he would be contractually obligated to destroy, at his own expense?
[1] https://www.vice.com/en/article/xgybq7/apple-macbook-activat...
> Why would he pay for devices that he would be contractually obligated to destroy, at his own expense?
That assumes RDKL was the original service provider chosen to destroy the macbooks; it's also probable that RDKL purchased those dumped machines from another service provider, the latter collecting not only the fee to destroy the machine but revenue for reselling usable machines.
https://docs.jamf.com/jamf- now/documentation/Using_Activation_Lock_Bypass.html
Another approach is to just let employees keep or buy out their laptop when they leave as a benefit. The cost of a MacBook isn't that huge relative to a tech salary.
A neat feature Apple could maybe add is the ability for the user to have their device wiped in a way that generates a suitable certificate of destruction.
I assumed MDM might do something here but wasn't 100% positive.
I personally don't like this system, I don't want any third party to have this kind of control over my device, but I have to admit that it's a system that works today and does its job, and with one small-ish tweak it could be even better.
A conspiracy isn't required for this to increase theft. Recyclers could start advertising maybe $50-100 per Macbook if they can guarantee they'll be able to sell each mac people bring in. Next thing you know, people start stealing more of them since there's now a middleman that pays out enough per device and doesn't ask questions like "did you steal these" or "why are all of the Apple IDs different". The only way this would work is if the program had the e-waste centers submit a photo ID of the person that brought the product to match against the current Apple ID name and address.
For a time, before factory resetting, you needed to remove your account from the phone. I had no idea.
I wonder why they have this policy? They have all the necessary information to facilitate a conversation. Heck, with services like Hide My Email, they could even keep the identities of each party private.
Anyway, Apple has decided there are only two ways to determine the owner:
1. Find My Activation Lock
2. Original Proof of Purchase
Of course that cuts into their profit margins but it's not like used Apple thingies are particularly cheap...
Good. Let’s not pretend that theft isn’t a problem.
If I set up the device with my Apple ID and enable Find My, is there any way for the original owner to lock me out afterwards even after I’ve associated the device with my own Apple ID?
1. Individual sales of used devices to individual buyers.
You only get e-waste in this case if (a) the seller doesn't realize they need to unlock the device first, and (b) they buyer doesn't realize that the device needs to be unlocked by the seller, and (c) once the buyer receives the device and notices it needs to be unlocked (which they will notice the first time they try to use it) the buyer cannot make an arrangement with the seller to unlock it.
This should be very rare, because even if the seller doesn't realize the device is locked they are probably going to realize that they have plenty of personal data on it they need to erase first, and are going to Google something like "wipe Mac before selling" or "erase Mac before selling" and the first result is going to be Apple's "What to do before you sell, give away, or trade in your Mac" article.
2. Sales to entities that deal in used computers.
Similar analysis to #1, except in this case the buyer definitely should know about how locking works and the need to ensure that the seller unlocks it. If the seller cannot ensure it is unlocked the buyer should offer a lot less money.
The difference in value between an unlocked device and a locked one is large, so the seller should be willing to unlock it.
We should then only get e-waste in the case where the seller cannot unlock it.
If the seller cannot unlock it because they legitimately owned it but somehow forgot the necessary credentials, they can get Apple to unlock it if they can show Apple proof of legitimate ownership. Corporate sellers tend to keep purchase records for these kind of things so this should be no problem. Individual owners often don't keep such records, but the number of individuals selling used Apple devices who have forgotten their credentials is very likely quite low.
It would be good for Apple to have a bounty program to take the machines back and reunite them with the owner, possibly paying a reward to the finder. If the finder is the thief, they'd be taking a big risk of being fingered and arrested.
But the iCloud lock very clearly showed an @outlook.com email address, which would be absolutely bizarre for a company that's recycling a bundle of 50 or so laptops.
Not saying it's right, but it's been done before - likely because you have an IT department that's exclusively Windows-based and you have a creative department that wants all Apple products... Either ignorance, cheapness, or unwillingness to learn.