Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Agree to all of the above, which is why im certain it will be widespread. What now?


This would be fairly easy for Apple to fix as a middle-ground.

Some (presumably not all) MDMs delete the escrowed Activation Lock bypass code when you drop the machine from MDM. Jamf _suggests_ that this is because Apple won’t validate the bypass code unless the machine still exists in the last associated MDM, but I’ve never found crystal clear documentation on the underlying theory.

If Apple already knows the last enrolled MDM server (which isn’t guaranteed), then they could change the implementation so that the last valid bypass code is always preserved and valid. This could then be made available via some channel.

I’ve been long saddened that they don’t want to work with industry more expansively to deal with the waste problem the current implementation creates.

At the same time, it’s my hardware. If it gets lost or stolen, I still feel entitled to control whether it’s useful. On the other hand, I’d rather wipe it and let it be used than a resource sink.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: