back

by LazyMans·3y ago·view on hn ↗
I don't think it's working as intended. Like the article states, there should be a path for machines acquired legitimately to be unlocked. The example given is a registered recycler can submit the serial for unlock, then apple attempts to contact the registered owner. If no answer is received within 30 days, the machine is unlocked.

Plenty of companies don't care to unlock these properly before recycling and it's creating excessive waste.

9 comments
That registered recycler very quickly becomes an Apple sanctioned fence for stolen goods.

E-waste is going to happen regardless and it would be more proper for Apple to have a computer recycling program, which already exists, or to turn the old computers into spare parts for repair.

Eliminating the potential for theft is a massive win. I remember what it was like before activation lock existed and how high of a target iPhones were. As soon as that feature came out the thieves were screwed out of a potential payday. Now we don’t have to worry about our phones being stolen.

This feels similar to backdooring encrypted systems. The upsides are similar: some trusted entity has the ability to act in a supposed best interest - national security in the case of encryption, reducing e-waste in the latter. Unfortunately, the downsides are also similar: it's necessary to put an outsized amount of trust in an entity (government, Apple, or whomever) that not everyone wants to place that trust in.
The backdoor is already there, is it not? According to Apple's support site, you can remove the lock remotely [1], which means they can remove the lock remotely. You're already trusting Apple.

Given that, removing the activation lock after notifying you with a 30/60/whatever day window to respond seems like a reasonable policy to me.

[1] https://support.apple.com/en-us/HT201441

>you can remove the lock remotely [1], which means they can remove the lock remotely

Not the same thing, depending upon how the authentication is handled.

Similar, maybe. You're not backdooring file vault though. Just the ability to resell a machine. Personally, I feel pretty good as long as my data can't be accessed.
> there should be a path for machines acquired legitimately to be unlocked

I think it's perfectly fair for "legitamately acquired" to mean the original owner consented by unlocking the device. The peace of mind and security if you own a T2 device is the way it should be, and if you want to sell it, you just factory reset it, which is a quick process.

That's not the case though, they are finding. A person like you or me might follow the process correctly, but a company going bankrupt or aging out old equipment doesn't care nor have any incentive to properly unlock their machines before shipping to a recycler. Thus contributing to massive waste.
> but a company going bankrupt or aging out old equipment doesn't care nor have any incentive to properly unlock

This is not true. The bankruptcy process attempts to recover as much value from assets as possible, and so creditors and the process should absolutely care to properly unlock in order to extract maximum value.

Similarly, aging out old equipment is still sold to make money, and unlocking should achieve more resale value.

The incentives are absolutely there. And the article does absolutely zero investigation as to where exactly there's a breakdown in incentives or communication, or if it's even a major issue at all. Maybe the process is working 99% of the time.

The user who refused to unlock it before selling and/or the purchaser who did not check that it was unlocked before purchasing are the ones contributing to massive waste here, not Apple.
When that user has died or otherwise doesn't exist, then it's hard to blame them. The only remaining thread of blame leads to Apple.
Unless this is what's happening in the majority of cases I don't think it's fair to focus on it. My hunch is that most of the laptops in that article are either stolen or dumped by users/corps who couldn't be bothered to unlock them.
only due to the systemic waste apple has created by designing the system in this way
Recyclers will quickly find that they should not accept the machines unless the seller has unlucked them.

If bankcrupt, the original company may have a duty to unlock them because they will be worth more.

If you had enabled Find My Mac on a T2 equipped mac, factory reset WON'T unlock the device.

However, since Apple actually had full authority and cryptographic ownership of the chip, they can generate a key given serial number which will reset T2 contents.

Personally, I think the setup should be that you don't have to go to apple for it, but it should immediately wipe device identity and disk encryption then (and the disk should always be encrypted)

> If you had enabled Find My Mac on a T2 equipped mac, factory reset WON'T unlock the device.

I don’t think that’s true, I’ve never had to do that, and this is not a part of Apple’s documented reset process for resale of a machine. If you are the device’s actual owner and you use the simple process Apple outlines, it will reset it for a new owner, period.

At the time I bought, the documented process included "manually disassociate FMM from the device in iCloud settings"... except it wasn't well propagated information and the previous owner and reseller just tried factory reset.

Been there, went with Apple support over it, the only reason I still don't have it unlocked is because I didn't have time or energy to redo the whole setup. Might redo the apple-driven unlock process, but the hw is not worth it really.

EDIT: Apparently the nice simpler procedure that does wipe FMM only arrived in Monterey.

"Erase All Contents and Settings" is the only button you need to push on a T2 (or later) Mac, and it is the factory reset button.

It will unlock the device.

I have physical proof on my hands. It's possible that they fixed it in later version of the OS, but factory reset is what the reseller did with previous owner, and it did not wipe FMM registration, leaving the laptop half-stuck in terms of ownership - I only figured it out trying to register FMM to myself.
Things were harder in older versions of macOS, but you can read step 2 yourself: https://support.apple.com/en-us/HT201065

Any T2 Mac or newer requires only that button to be pressed, and then click through the wizard to complete the process. If someone is running outdated macOS, they won't have that button at all, since older versions of macOS required you to format computers the hard way using recovery mode, which didn't handle activation lock concerns.

You can also read this document: https://support.apple.com/en-us/HT208987

"Other ways to disable Activation Lock"

"Activation Lock is disabled when you use the Erase All Content and Settings feature."

which confirms the same thing. The experience that people have is very simple these days.

Yeah, this was fixed, supposedly, on Monterey.

Which still leaves considerable amount of laptops with broken FMM registrations in T2. Especially since it was upgrading to Catalina, iirc, that started problems.

> there should be a path for machines acquired legitimately to be unlocked.

There is exactly that pathway. If you have the consent of the original owner, which I think is an important and required quality of "acquired legitimately", you can have the original owner remove the device from their Apple account remotely, or to wipe the device and reset it while logged in prior to physically handing it over to you.

If neither of these things have happened, on what basis do you believe the complaintant has "acquired legitimately"? Is consent of the original owner not important in your view?

This is exactly the same thing as the Feds saying they should be able to have a backdoor that works for them and nobody else. The whole point of this lock is that only the owner can unlock it. If Apple (or anyone else) can, it’s backdoored and therefore broken.
The answer to why this isn’t a good idea is given by the recycler themselves:

> “Previous owners do not return phone calls“

The point to Apple’s security is that nobody can unlock these machines but the owner, even Apple.
Apple obviously can, but they won't. And their front end retail staff aren't given that power. Apple as a company however can obviously just do whatever they want to them.
This is quite complicated. For example, it assumes that Apple has to have contacts of every device owner, which is not just unrealistic, but could also be impossible to ensure in some countries due to privacy laws.
Yeah, however. If a machine is activation locked, it's associated with an Apple ID. That Apple ID in itself is a contact point. Like the article states, a system where you have 30 days to deny an unlock would be nice. Or you could just report to Apple right away the machine was stolen, which blacklists the machine from an unlock request.
And what if the person is travelling for months? It working and not able to check email? Or miss the emails?

It’s one thing to forward a request. But to give unlock after 30 days? That’s gonna be abused by thieves and unscrupulous refurbishers

They don't have to, since they can generate a reset sequence based on serial number of the machine.
Ugh that would be horrible.