Anyone can turn off Find my Mac” without knowing Apple ID password

Expert computer security will Mayal found dangerous vulnerability in the operating system OS X. the Feature to search for missing or stolen computer Find my Mac can be disabled by any user without a password to iCloud.

On Apple computers provides the analogue of the function Find my iPhone and Find my iPad, thanks to which the computer owner can track a lost or stolen device, send a message to it and remotely erase all the data. In order to disable the option, you must enter the password. However, experts managed to circumvent the system.

In fact, to disable “Find my Mac” was enough to press four keys. If the user resets PRAM, the safety feature of “Apple” computers will not work. Enough to shut down the computer and when turning on press P+R+Option+Command until the welcome sound of three sounds. After that Find my Mac is disabled.

Thus, attackers can easily reset the MacBook and untie it from your Apple ID account. Experts recommend all users to set a password on the Mac’s firmware.

In order to protect the “Find my Mac” from dump you need to:

  • Turn off the Mac.
  • Restart the Mac computer. Immediately after you hear the startup sound, press and hold the Command and R keys to start the download with OS X.
  • When the window POPs up “Recovery”, select “firmware password Utility” in the menu “Utilities”.
  • In the “firmware password Utility” click “Enable firmware password”.
  • Enter a new password and then enter it again in the Verify field.
  • Click “Set password”.
  • Click Complete Utility firmware password” to close the utility firmware password.
  • Click the Apple menu and select “Restart” or “Shut down”. The firmware password will be activated the next time the Mac is started.
  • Clifton Nichols

    Clifton Nichols

    Hi! Iā€™m Clifton and I am a full-stack engineer with a passion for building performant and scalable applications that are beautiful and easy to use.

    You may also like...

    Leave a Reply

    Your email address will not be published. Required fields are marked *