Two years later I updated my login password and then promptly forgot the exact punctuation of the new password. I ended up getting completely locked out of the laptop with no self-service options to fix anything.
That day I learned that you have to boot into a special mode to truly factory reset, not just delete the administrator accounts with other AppleIDs. I was able to get Apple to remotely unlock the computer for me, but only because I could "prove" it was mine by sending them the original invoice slip from store.apple.com with my name, email, and the serial number of the laptop on it.
But that invoice slip is literally a piece of paper in a box, and you can't access it yourself after 18 months - I had to call into Apple support and get them to email me a new copy because it had been longer than 18 months.
If I had purchased the laptop from someone else on craigslist 2 years prior and then got locked out, I would be completely shit-out-of-luck, because I wouldn't be able to prove I truly owned it.
https://support.apple.com/en-us/102664
With the way modern macOS is immutable and exactly the same on all machines thanks to signed and sealed images, no one needs to DFU to reset a Mac unless there is something very wrong.
The factory reset process is simple. Proving ownership (and transfer of ownership) for getting around anti-theft lockouts is not.
Device works completely fine and lives behind a well secured network (battery was stuffed but it lives plugged in). Apple took it upon themselves to dictate to the user that it was no longer fit for operation. Apples solution was "replace the device and send the old one to landfil.
Apple literally greenwash their entire business model. But they are one of the most wasteful companies around.
Meanwhile I'm still reformatting 8, 12 and 15 year old windows pcs with Linux and putting them back into service for email checking and basic web browsing without a single hiccup. Saving more and more from landfil, they get used once in a blue moon but it's literally all the owners want. They don't mind waiting a bit for stuff to turn on, hell plenty of them are over 60, they've spend their life being patient and a few mins to make a cuppa while something turns on is a blessing to them.
Is that your way of saying "it doesn't support any modern SSL ciphers?" I don't think there is anything built into the OS that asks Apple if it's allowed to visit websites.
Ancient software has trouble talking to modern services; modern services and devices don't want to fall back to speaking the old versions because of downgrade attacks.
And if you have an important CA certificate expire, you can't talk to anything.
(But in the same way the OS ones weren't working, you wouldn't be able to use a 12 year old version of Firefox or Chrome to access most websites either for the same reasons).
This is shite design. Let's not kid ourselves here. This is one of the wealthiest companies on earth and thy control their entire hardware and software stack from the ground up. If they can't keep stuff sorted so when an old system plugs in it atleast limp mode upgrades it to the latest offering that system was supported with, this isn't because it's something that's impossible, it's because they don't want to.
If community non profit managed linux distros can get installed on 15 year old machines and just you know, sort out the drivers for the ancient ass tech in them without the user doing any more than running the update manager to hell apple couldn't have worked out the same.
It's a load of crap sold under the guise of security. Some nefarious actor wants to dl updates from their servers for ancient tech? Why in the world should they not be able to? Their update servers shouldn't have any services attached other than being a glorified dl directory.it shouldn't even be something they care about because there is zero risk attached.
It’s an economic- and risk-based calculation based on security.
You’re trying to get a TWELVE-YEAR OLD system online. Let’s see, since 2012, TLS 1.0 and TLS 1.1 have been officially deprecated (in 2021). In 2024, companies serving TLS 1.1 do not pass certain modern compliance standards. Mountain Lion from 2012 doesn’t support TLS 1.2. Are you arguing that they should leave around a TLS 1.1-based endpoint up, with ciphers that are no longer recommended? And how many CAs can still issue a valid cert trusted by a 12-yr old system?
> [there is zero risk attached]
Community-based Linux distros also offer HTTP (insecure) mirrors. There is also zero risk attached to the mirror serving HTTP. All the risk is on the user side. They don’t care that it’s an exploitable vector. They don’t have a commercial risk/downside. They didn’t sell fleets of old devices with their name on it.
> This is one of the wealthiest corporations on earth
Well this is why. It’s because they spend their money wisely. They decided that supporting OSes over 7 year old (with god knows what unpatched critical bulbs) is not money wisely spent and poses too much risk to their user populace, so they would rather not allow it, rather than support it. They don’t want to train their support on it and they don’t want to allow the possibility of punters getting their old hardware to an older release with open CVEs.