Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Another reason to hate #Apple We're seeing more 2018+ MacBook Pro/Air donations — but Apple's T2 chip means even after iCloud sign-out and reset, the firmware stays locked to the original account.

Another reason to hate #Apple We're seeing more 2018+ MacBook Pro/Air donations — but Apple's T2 chip means even after iCloud sign-out and reset, the firmware stays locked to the original account.

Scheduled Pinned Locked Moved Uncategorized
applerighttorepair
137 Posts 74 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • codemonkeymike@fosstodon.orgC codemonkeymike@fosstodon.org

    Another reason to hate #Apple We're seeing more 2018+ MacBook Pro/Air donations — but Apple's T2 chip means even after iCloud sign-out and reset, the firmware stays locked to the original account.

    Without donor contact, these machines are useless. 😞

    I've upcycled ~1,000 older Macs, but T2 era machines will end that. It's controlling, creates e-waste, and will only get worse. #righttorepair matters — Apple couldn't care less.

    multi_flexi@mastodon.socialM This user is from outside of this forum
    multi_flexi@mastodon.socialM This user is from outside of this forum
    multi_flexi@mastodon.social
    wrote last edited by
    #75

    @codemonkeymike Does it run Linux?

    codemonkeymike@fosstodon.orgC 1 Reply Last reply
    0
    • sgtpepere@ludosphere.frS sgtpepere@ludosphere.fr

      @codemonkeymike Can you install a Linux distro on it ?

      codemonkeymike@fosstodon.orgC This user is from outside of this forum
      codemonkeymike@fosstodon.orgC This user is from outside of this forum
      codemonkeymike@fosstodon.org
      wrote last edited by
      #76

      @sgtpepere nope. That's what I'm trying to do. But you can't boot to the usb without unlocking it.

      It's a trap

      sgtpepere@ludosphere.frS 1 Reply Last reply
      0
      • codemonkeymike@fosstodon.orgC codemonkeymike@fosstodon.org

        @sgtpepere nope. That's what I'm trying to do. But you can't boot to the usb without unlocking it.

        It's a trap

        sgtpepere@ludosphere.frS This user is from outside of this forum
        sgtpepere@ludosphere.frS This user is from outside of this forum
        sgtpepere@ludosphere.fr
        wrote last edited by
        #77

        @codemonkeymike Ah, I didn't know about that. That really sucks.

        1 Reply Last reply
        0
        • multi_flexi@mastodon.socialM multi_flexi@mastodon.social

          @codemonkeymike Does it run Linux?

          codemonkeymike@fosstodon.orgC This user is from outside of this forum
          codemonkeymike@fosstodon.orgC This user is from outside of this forum
          codemonkeymike@fosstodon.org
          wrote last edited by
          #78

          @multi_flexi the t2 chip won't let you boot from USB unless you unlock it. And you need this to unlock it.

          So nope. It's stuck

          1 Reply Last reply
          0
          • lunacolon3@blahaj.zoneL lunacolon3@blahaj.zone

            @codemonkeymike@fosstodon.org this is fucking evil. like its not just inconvenient and greedy, it is blatantly evil.

            codemonkeymike@fosstodon.orgC This user is from outside of this forum
            codemonkeymike@fosstodon.orgC This user is from outside of this forum
            codemonkeymike@fosstodon.org
            wrote last edited by
            #79

            @LunaCOLON3 I agree. There really is no excuse for this.

            Even enterprise Chromebooks can be unlocked remotely when they're decomissioned. Apple could do this too. But they won't

            1 Reply Last reply
            0
            • retrosponge@kind.socialR retrosponge@kind.social

              @codemonkeymike I had someone give me a used iPad last year and they hadn't reset it and the absolute nightmare I had getting it to work.

              They wound up having to trust me with their username and password to log into their account so I could physically deal with it on the device.

              Absolute fucking bullshit.

              codemonkeymike@fosstodon.orgC This user is from outside of this forum
              codemonkeymike@fosstodon.orgC This user is from outside of this forum
              codemonkeymike@fosstodon.org
              wrote last edited by
              #80

              @retrosponge yup. It's such crap. Apple... Good hardware killed by shit policy

              1 Reply Last reply
              0
              • R relay@relay.an.exchange shared this topic
              • N nicolas17@social.treehouse.systems

                @LoneLocust @codemonkeymike in simple terms, to activate a Mac, the T2 chip requires approval from the Apple server, which may say "OK" or it may say "you need to login first".

                lonelocust@mastodon.socialL This user is from outside of this forum
                lonelocust@mastodon.socialL This user is from outside of this forum
                lonelocust@mastodon.social
                wrote last edited by
                #81

                @nicolas17 @codemonkeymike OK, that makes a little more sense. I’ve wiped and sold a couple T2 equipped Macs and not had problems, but I can see how that might go wrong (for example, if there was no Internet access while wiping the machine.)

                1 Reply Last reply
                0
                • codemonkeymike@fosstodon.orgC codemonkeymike@fosstodon.org

                  Another reason to hate #Apple We're seeing more 2018+ MacBook Pro/Air donations — but Apple's T2 chip means even after iCloud sign-out and reset, the firmware stays locked to the original account.

                  Without donor contact, these machines are useless. 😞

                  I've upcycled ~1,000 older Macs, but T2 era machines will end that. It's controlling, creates e-waste, and will only get worse. #righttorepair matters — Apple couldn't care less.

                  richardazia@indieweb.socialR This user is from outside of this forum
                  richardazia@indieweb.socialR This user is from outside of this forum
                  richardazia@indieweb.social
                  wrote last edited by
                  #82

                  @codemonkeymike With their growing market share the problem will get worse. I would wipe the drive and install linux. The challenge is to get wifi to work correctly. I was experimenting but with Intel based macs, rather than ARM based ones.

                  codemonkeymike@fosstodon.orgC 1 Reply Last reply
                  0
                  • richardazia@indieweb.socialR richardazia@indieweb.social

                    @codemonkeymike With their growing market share the problem will get worse. I would wipe the drive and install linux. The challenge is to get wifi to work correctly. I was experimenting but with Intel based macs, rather than ARM based ones.

                    codemonkeymike@fosstodon.orgC This user is from outside of this forum
                    codemonkeymike@fosstodon.orgC This user is from outside of this forum
                    codemonkeymike@fosstodon.org
                    wrote last edited by
                    #83

                    @richardazia but you can't even boot to USB without unlocking it.

                    That's the issue. Id love to install Linux on it. But i can't

                    richardazia@indieweb.socialR 2 Replies Last reply
                    0
                    • samuraisakura@mastodon.bsd.cafeS samuraisakura@mastodon.bsd.cafe

                      @codemonkeymike You may need to dump it at the Apple Store for them to recycle it.

                      codemonkeymike@fosstodon.orgC This user is from outside of this forum
                      codemonkeymike@fosstodon.orgC This user is from outside of this forum
                      codemonkeymike@fosstodon.org
                      wrote last edited by
                      #84

                      @SamuraiSakura that's super wasteful

                      ben@social.benjaminturner.meB 1 Reply Last reply
                      0
                      • codemonkeymike@fosstodon.orgC codemonkeymike@fosstodon.org

                        @HitokiriEric @coldclimate but here's the rub for me. Even if a user logs into their iCloud account and removes the device from their account, it still won't release.

                        That should be illegal.

                        Even enterprise locked Chromebooks can be decommissioned remotely and unlocked.

                        There is no reason this cant be done with apple.

                        hitokirieric@defcon.socialH This user is from outside of this forum
                        hitokirieric@defcon.socialH This user is from outside of this forum
                        hitokirieric@defcon.social
                        wrote last edited by
                        #85

                        @codemonkeymike @coldclimate

                        Hmm… for the hardware firmware I’d still want to have to unlock it on device rather than having an attack surface/backdoor from the internet to exploit. Apple had the issue a couple years ago with thieves exploiting the remote password change to workaround the phone protections.

                        But I get how it sucks for this use case.

                        Like a lot of things, for 99% of users who don’t care they should default to a version that’s secure from most thieves but not totally secure from government and then let the users who really care opt in to the stronger lockdown mode.

                        codemonkeymike@fosstodon.orgC 0x00string@infosec.exchange0 2 Replies Last reply
                        0
                        • miked1112@fosstodon.orgM miked1112@fosstodon.org

                          @codemonkeymike Suspect you are talking about two different things. For a machine owned by an end user, removing the iCloud account and performing a factory reset absolutely makes that Mac available for activation and use by a new user, T2 or no. However, if the device is owned by the end user’s school or employer and enrolled by that organization to their device management, they would have to unenroll it.

                          codemonkeymike@fosstodon.orgC This user is from outside of this forum
                          codemonkeymike@fosstodon.orgC This user is from outside of this forum
                          codemonkeymike@fosstodon.org
                          wrote last edited by
                          #86

                          @miked1112 nope. I've seen this personally too. Where I had a t2 mac mini. I signed out of iCloud, deleted it from my account, and reformatted the machine.

                          I gave it to a friend, who wanted to open the boot security to install Linux but needed my apple password to it.

                          I've had people donate to me with the same issues. It's crap.

                          If someone deletes the device from their iCloud account, you should be able to unlock the bootloader. Google does this easily with chromebooks

                          1 Reply Last reply
                          0
                          • codemonkeymike@fosstodon.orgC codemonkeymike@fosstodon.org

                            @SamuraiSakura that's super wasteful

                            ben@social.benjaminturner.meB This user is from outside of this forum
                            ben@social.benjaminturner.meB This user is from outside of this forum
                            ben@social.benjaminturner.me
                            wrote last edited by
                            #87

                            @codemonkeymike @SamuraiSakura Apple skips right over Reduce & Reuse. The order is important.

                            codemonkeymike@fosstodon.orgC 2 Replies Last reply
                            0
                            • aaron@social.aaroncrocco.comA aaron@social.aaroncrocco.com

                              @codemonkeymike @bigzaphod Doesn’t Apple have a program that will remove activation lock if you can prove provenance of the device?

                              TBH it’s also poor educating of the donors on Apple’s part that this step must be done prior to donating.

                              codemonkeymike@fosstodon.orgC This user is from outside of this forum
                              codemonkeymike@fosstodon.orgC This user is from outside of this forum
                              codemonkeymike@fosstodon.org
                              wrote last edited by
                              #88

                              @Aaron @bigzaphod it was donated 3rd party. How am I to prove it?

                              Also, id bet you this device is absolutely removed from their iCloud account. Yet remains locked on device.

                              It's purposely confusing and hard to get around. They could make this better right now. But they won't

                              1 Reply Last reply
                              0
                              • ben@social.benjaminturner.meB ben@social.benjaminturner.me

                                @codemonkeymike @SamuraiSakura Apple skips right over Reduce & Reuse. The order is important.

                                codemonkeymike@fosstodon.orgC This user is from outside of this forum
                                codemonkeymike@fosstodon.orgC This user is from outside of this forum
                                codemonkeymike@fosstodon.org
                                wrote last edited by
                                #89

                                @ben @SamuraiSakura exactly.

                                1 Reply Last reply
                                0
                                • ben@social.benjaminturner.meB ben@social.benjaminturner.me

                                  @codemonkeymike @SamuraiSakura Apple skips right over Reduce & Reuse. The order is important.

                                  codemonkeymike@fosstodon.orgC This user is from outside of this forum
                                  codemonkeymike@fosstodon.orgC This user is from outside of this forum
                                  codemonkeymike@fosstodon.org
                                  wrote last edited by
                                  #90

                                  @ben @SamuraiSakura and you know if you have apple recycle it. All they're going to do is shred it and reclaim a bit if metal from it. Then do a victory lap about how awesome they are.

                                  Meanwhile how much energy when into reclaiming that tiny bit of metal?

                                  ben@social.benjaminturner.meB 1 Reply Last reply
                                  0
                                  • amsomniac@mastodon.mit.eduA amsomniac@mastodon.mit.edu

                                    @codemonkeymike yikes. I was just reading about imjtool and fighting edl qualcomm and some of the tools might help with T2?? I hate this shit

                                    ishaderdevicemgr@mastodon.socialI This user is from outside of this forum
                                    ishaderdevicemgr@mastodon.socialI This user is from outside of this forum
                                    ishaderdevicemgr@mastodon.social
                                    wrote last edited by
                                    #91

                                    @amsomniac @codemonkeymike
                                    Nah, those are specific to AOSP and Qualcomm devices respectively, T2 is a much different beast. There are some workarounds I've seen using checkm8 to trick bridgeOS into believing it's activated, but those are not truly permanent since machine identity and activation lock is tied to the ECID which is burned into the chip itself, and can't be changed.

                                    1 Reply Last reply
                                    0
                                    • codemonkeymike@fosstodon.orgC codemonkeymike@fosstodon.org

                                      @ben @SamuraiSakura and you know if you have apple recycle it. All they're going to do is shred it and reclaim a bit if metal from it. Then do a victory lap about how awesome they are.

                                      Meanwhile how much energy when into reclaiming that tiny bit of metal?

                                      ben@social.benjaminturner.meB This user is from outside of this forum
                                      ben@social.benjaminturner.meB This user is from outside of this forum
                                      ben@social.benjaminturner.me
                                      wrote last edited by
                                      #92

                                      @codemonkeymike @SamuraiSakura gotta get ready for another Mother Earth keynote appearance

                                      1 Reply Last reply
                                      0
                                      • hitokirieric@defcon.socialH hitokirieric@defcon.social

                                        @codemonkeymike @coldclimate

                                        Hmm… for the hardware firmware I’d still want to have to unlock it on device rather than having an attack surface/backdoor from the internet to exploit. Apple had the issue a couple years ago with thieves exploiting the remote password change to workaround the phone protections.

                                        But I get how it sucks for this use case.

                                        Like a lot of things, for 99% of users who don’t care they should default to a version that’s secure from most thieves but not totally secure from government and then let the users who really care opt in to the stronger lockdown mode.

                                        codemonkeymike@fosstodon.orgC This user is from outside of this forum
                                        codemonkeymike@fosstodon.orgC This user is from outside of this forum
                                        codemonkeymike@fosstodon.org
                                        wrote last edited by
                                        #93

                                        @HitokiriEric @coldclimate yeah. I mean look. You can unsolder the t2 chip and reprogram it etc. Motivated thiefs can still do it.

                                        But was this when a problem? I really don't think it was.

                                        Again. Look at Chromebooks. They have a firmware level lock too that can't be hacked. And yet it can be decomissioned remotely when the org releases it.

                                        You're telling me apple couldn't do this?! For regular users? Its a racket

                                        hitokirieric@defcon.socialH 1 Reply Last reply
                                        0
                                        • dalias@hachyderm.ioD dalias@hachyderm.io

                                          @oscherler @codemonkeymike IME Android tablets don't even have serious bootloader locking, unlike phones. You can basically do whatever with them.

                                          ishaderdevicemgr@mastodon.socialI This user is from outside of this forum
                                          ishaderdevicemgr@mastodon.socialI This user is from outside of this forum
                                          ishaderdevicemgr@mastodon.social
                                          wrote last edited by
                                          #94

                                          @dalias @oscherler @codemonkeymike
                                          Well, you're still probably getting dropped in EL1, so you're not truly free. The freest device you can buy is a used Chromebook, as they use Coreboot, so you can just compile and flash your own firmware. Thanks to the weird CR50 TPM thingy, if you've got a SuzyQAble, you can even get RW access to the AP firmware and a serial console without having to open the device, provided you run a command and assert your presence (once) with timed power button presses

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups