> An attacker could “prank” someone by wiping their MacBook, activating it with their own Apple ID, and then reporting it as lost. The victim then has no way to recover it.
When you lose physical control of a device, there's an even bigger denial-of-service vulnerability: https://media.istockphoto.com/photos/breaking-a-laptop-compu...
There is really no solving denial-of-service problems associated with losing a device. The priority in that case should be preventing unwanted disclosure of data, which is exactly what Apple did here.