6 ms·
Well I kind of did circumvent this hurdle. I got an iPhone from a relative, the relative had forgotten the passcode and the Apple ID password. I did a factory
by Zapped 3y ago
Well I kind of did circumvent this hurdle.
I got an iPhone from a relative, the relative had forgotten the passcode and the Apple ID password.
I did a factory reset of it via iTunes and of course when it started up and I started with the setup it said it was locked to *@*.com.
I contacted Apple support and they said I needed proof of purchase for them to unlock it.
I did not have any proof of purchase and neither did my relative.
But I refused to let that stop me. So I made a proof of purchase, printed it and went to an Apple store.
I told the Apple Genius about the iPhone and that it was locked but factory reset and presented the "proof of purchase".
The Apple Genius went to get a manager or something and the manager checked the "proof of purchase" and then connected the iPhone to the store Wi-Fi and did some stuff on their iPad and rebooted the iPhone. The iPhone did a reset and then it was unlocked and ready to be setup without any hurdles.
So I am guessing some thieves have figured this out.
- brookst 3y agoMakes sense. No theft deterrence is perfect, and your solution required a lot of investment of time and would not scale to a substantially large theft ring.
- kotaKat 3y agoEh, fake receipts are fairly easy to knock out. When I managed a hospital's iPhone deployment I made it a point to always back up our receipts electronically because I have... had to make quite a few emails to AppleCare Security to release a few Activation Locked devices. It's not a terribly difficult process once you've done it a couple times, and I reasonably think I could release as many phones as I wanted these days with enough fake receipts.
- no_wizard 3y agowith an MDM and Apple's Device Enrollment Program you don't even need to worry about this anymore[0] [0]: https://www.apple.com/mx/business-docs/DEP_Guide.pdf https://www.apple.com/mx/business-docs/DEP_Guide.pdf
- kotaKat 3y agoHahahah when I worked at the hospital my director's answer to any of that was "Exchange is our MDM" despite me pushing for it, so I was stuck with the receipts regardless. ... My personal stuff is enrolled into my own personal Jamf instance and because I went through a bunch of motions with Apple Business my personal phones and Macs are all DEP locked ;)
- Operyl 3y agoI would love to go this route but the entry seems blocked unless you have a business with a DUNS number. Am I right in that assumption?
- FireBeyond 3y agoHah, no. It's mind-bogglingly easy to bypass MDM/DEP on even a T2-enabled/Apple Silicon MacBook. Like three minutes, and not overly complex. Without spelling it out here, null route three DNS entries, install macOS Monterey, edit /etc/hosts similarly, and then upgrade to Sonoma. You can even remove the null routing after (it's only needed to bypass network calls in the installer). Nothing broken, no errors, 100% DEP-escaped. I suspect that the only thing you can't do at that point is reset to the OOB experience for selling it.
- Zapped 3y agoInteresting. Nothing similar for iPads and iPhones? Except jailbreak.
- brookst 3y agoThe fake receipt Is the easy part, it’s the staffing and logistics and risk to send people into lots of Apple stores to use them. One, sure. But an organized theft ring stealing 1000 iPhones a month is probably not going to work at that scale.
- gojomo 3y agoThere are lots of Apple Stores, many in jurisdictions that don't prioritize vigorous prosecution of small thefts or mere possession-of-stolen-property. There are lots of individuals who'd take the chance to make a quick buck. So it doesn't need to be one scaled organization: just a functioning black market. Imagine the false docs are often accepted, rather than triggering a criminal prosecution. The practical maximum downside may be mere impoundment of the device, rather than a conviction/jailing. (And, even that would require Apple's policy to be to assertive & confrontational: "you presented us suspicious documentation, we're holding this device – that you carried here, in your possession – until police sort it out." Does Apple want to take the risk of that backfiring on them? Or would store staff, in practice, simply say: "we can't accept that documentation, you and your device should leave.") Then Apple's lenience here will support a positive resale value of stolen devices, enough for the weakness in their systems to be exploited.
- 2OEH8eoCRo0 3y ago> The Apple Genius went to get a manager or something and the manager checked the "proof of purchase" and then connected the iPhone to the store Wi-Fi and did some stuff on their iPad and rebooted the iPhone. The iPhone did a reset and then it was unlocked and ready to be setup without any hurdles. The thieves figured out you just need to know (or be) an employee of any of the 500+ Apple stores. I assume that some theft rings have this process quite streamlined.
- deleted 3y ago[deleted]
- gojomo 3y agoA similarly-compromised front-line T-Mobile employee once enabled a "SIM-swap" on my active iPhone phone number. It was reported in T-Mobile's systems as my personal visit, with supporting documentation/ID, to one of their retail locations in Oklahoma – thousands of miles from anywhere I'd recently been. So, while remotely possible that their employee gullibily-reviewed credible false documents, it seemed far more likely to be:… - an insider abuse by a corrupt employee; - a deep hack of T-Mobile's systems, allowing such admin actions with forged audit-trails; or… - compromise of an authorized employee's credentials plus access to capable internal-system front-ends. The Apple Support person I spoke to insisted that an analogous compromise here was impossible - that no Apple employee had the power take such an action without my Apple ID password. Based on other reports in this thread, I highly suspect she was lying to me, probably in conformance with Apple policy.
- meindnoch 3y agoThey were 100% lying. It's even on Apple's website: https://support.apple.com/en-us/HT201441 https://support.apple.com/en-us/HT201441 "If you need help removing Activation Lock and have proof of purchase documentation, you can start an Activation Lock support request."