Earlier quoted context omitted.
Correct, they're most likely allowing stolen computers to be used Makes me wonder if their SCBO generating system is connected to their stolen serial number db (probably not)
they're most likely allowing stolen computers to be used Also those which have been recycled, or which someone has locked out accidentally, or deliberately to scam someone ( https://news.ycombinator.com/item?id=7993435 ), etc. Used computers from companies often have BIOS passwords that no one bothered to clear before sending them off. Not every computer with a password its current owner doesn't know is a stolen one.…
Apple EFI firmware passwords and the SCBO myth
31–38 of 38 posts
Re: Apple EFI firmware passwords and the SCBO myth
#32These could be insiders working at Apple support centers or even Apple itself. It makes me somewhat happy in a weird way to think that, even in notoriously locked-down and secretive companies like Apple, there are individuals who don't believe in and subvert the company's attempts to have sole control of its products. We have these individuals to thank for schematics, parts, and a lot of other material that feeds the…
Re: Apple EFI firmware passwords and the SCBO myth
#33These could be insiders working at Apple support centers or even Apple itself. It makes me somewhat happy in a weird way to think that, even in notoriously locked-down and secretive companies like Apple, there are individuals who don't believe in and subvert the company's attempts to have sole control of its products. We have these individuals to thank for schematics, parts, and a lot of other material that feeds the…
Re: Apple EFI firmware passwords and the SCBO myth
#34Hmm... what about bugs in the USB / FireWire implementation of the EFI? Or the good old FireWire DMA trick?
Even when they did, enabling a firmware password disabled FireWire DMA, even after boot. (And I'm not sure it was ever active during preboot.)
Re: Apple EFI firmware passwords and the SCBO myth
#35TLDR? EFI password protection broken or not?
Apple has a backdoor for resetting firmware passwords via a special unlock file that must be cryptographically signed using Apple's private key(s). In theory only Apple employees can sign the unlock files. How many employees have access to sign these unlock files? 10? 100? Every low-level employee? There may be some "bad apple" employees selling the signing of unlock files, some social engineering to trick Apple into…
Re: Apple EFI firmware passwords and the SCBO myth
#36Re: Apple EFI firmware passwords and the SCBO myth
#37Earlier quoted context omitted.
Since it's likely that every apple care center can perform this unlock there is a very good chance that there is a machine in virtually everyone of them that also has a service lab that makes these files. The number of people that can unlock it is probably quite high, this isn't that different than removing an apple id from the device you need to go to the apple store with the device and proof of purchase and they do…
Last I heard, service centers have to request these files from Apple on a case-by-case basis, so that only a small number of people need the ability to generate them. All of the complexity (writing a nonce to flash when the firmware password is changed, etc.) exists to make it easy for a service provider to apply an unlock when authorized . I’d make a large bet that the same is true for removing Apple ID activation l…
To foolproof the system, you would need less than a dozen people trusted with the ability to sign the files, and require the device and proof of purchase to be shipped to them rather than allowing unlocks to be authorized remotely.
It's unfortunate that the last line of defense against a stolen machine, the firmware password, has a backdoor. I'd have expected a firmware password on a MacBook to be just as difficult to bypass as an iPhone's passcode. Apple refuses to unlock phones, but will gladly remove a firmware password on a real machine. Disappointing.
Re: Apple EFI firmware passwords and the SCBO myth
#38Earlier quoted context omitted.
Last I heard, service centers have to request these files from Apple on a case-by-case basis, so that only a small number of people need the ability to generate them. All of the complexity (writing a nonce to flash when the firmware password is changed, etc.) exists to make it easy for a service provider to apply an unlock when authorized . I’d make a large bet that the same is true for removing Apple ID activation l…
Even if the employees capable of directly signing the files make up a very small group, they would probably be authorizing over the phone or a similar indirect route. This opens the door to social engineering by anyone, employee or not, who knows what number to dial and what information to provide. The tech would be authorizing the file without seeing the customer's device and proof of purchase themselves. To foolpro…
Firmware passwords are more like Activation Lock for iOS. They make it harder to reuse a stolen computer and stop some less-invasive tampering, but don't offer any guarantees about protecting your data.