iCloud Flaw Lets ANYONE LOCK Your iPad or iPod If They Know Your Serial Number - Protect Yourself

Sdílet
Vložit
  • čas přidán 5. 01. 2024
  • Apple's Activation Lock can be abused to lock out other Apple devices without physical acquisition of the target device, requiring only its serial number, Wifi and Bluetooth addresses.
    This video was created using publicly available information, certain software and procedures have been redacted or not included.
    This video is ONLY to provide education for protecting yourself from this major iCloud flaw.
    I DO NOT in any circumstances advise changing serial numbers or attempting to circumvent Activation Lock.
    -------------------------------------Socials------------------------------------
    Website: www.hughjeffreys.com
    Store: www.hughjeffreys.com/store
    Instagram: / hughjeffreys
    --------------------------------------Links--------------------------------------
    Get parts, tools and repair guides at iFixit:
    Shop US: iFixit.com/hughjeffreys
    Shop AU: ifix.gd/hughjeffreysau
    Tools I Use: www.hughjeffreys.com/tools
    ---------------------------------------------------------------------------------------
    (DISCLAIMER: This description contains affiliate links, which means that if you click on one of the product links, l will receive a small commission.)
  • Věda a technologie

Komentáře • 667

  • @HughJeffreys
    @HughJeffreys  Před 4 měsíci +250

    To clarify this appears to only affect devices without IMEI numbers, such as iPads and iPods. Although cellular iPads can be modified physically to preform the reprogram. Wether someone can use a cellular iPad or iPhones information to unlock a non cellular device (therefore locking the cellular device) remains to be seen.

    • @alexeinars
      @alexeinars Před 4 měsíci +1

      What about Macs?

    • @thomasspence-king3339
      @thomasspence-king3339 Před 4 měsíci +44

      Feels like you should pull the whole video as your title is factually incorrect and content likewise.

    • @sssyt4837
      @sssyt4837 Před 4 měsíci +10

      A new video would be appreciated.
      The title messed up.
      I understand what you said, BUT this is only theoretically possible on newer devices.

    • @FurryTwT
      @FurryTwT Před 4 měsíci +8

      Honestly as a person who has experimented with this there are major flaws,
      Icloud activation needs the imei, Serial, ECID ETC, So even if you were too change the Serial it will throw out a activation error. And even if someone did use a vaild serial/info depending on the device the serial came from, (ipad 2 Serial for a ipad pro 1) It will also throw out a error as apple activation servers are giving a IOS 9 Activation Ticket vs a IOS 15 Ticket. This also only effects ipads and even if Iphones have a dead baseband. It still wouldent work.

    • @FurryTwT
      @FurryTwT Před 4 měsíci +5

      So no, Only Ipads have the major flaw. And even then Apple servers are smart about knowing if its a faked serial vs a valid device as there are muiltple checks in place such as checking what device type it is, (A2847 For a iphone15+) ECID,IMEI, ETC

  • @blar2112
    @blar2112 Před 4 měsíci +81

    Apple's "security" features are not for the users, are for the shareholders

    • @flashx4526
      @flashx4526 Před 4 měsíci

      Apple no longer cares about old checkm8 vulnerable phones even tho they are still supported they only care about money 💰💰🤑🤑

    • @MainInternetUser
      @MainInternetUser Před 4 měsíci +2

      Truth spoken

  • @MayaPosch
    @MayaPosch Před 4 měsíci +791

    But Apple says everything they do is for your own protection. Apple wouldn't lie, would they?

    • @lucaspanebianco6860
      @lucaspanebianco6860 Před 4 měsíci

      fr and nothing else @@arkvsi8142

    • @Boogie_the_cat
      @Boogie_the_cat Před 4 měsíci +85

      Yes they also lie about being eco friendly

    • @harryroesser3916
      @harryroesser3916 Před 4 měsíci

      ​@@arkvsi8142Correct

    • @harryroesser3916
      @harryroesser3916 Před 4 měsíci +44

      And besides It's creating a ton of e-waste.
      Wow, thanks for 38 Likes :]

    • @gravelrecords-us
      @gravelrecords-us Před 4 měsíci +16

      your own protection of freely giving money away (to apple, ofc, not to supporting people in need, apple is in need of money from you)

  • @Tiger1Tanker
    @Tiger1Tanker Před 4 měsíci +460

    If EU regs forced Apple to put USB-C on the 15, then we need more regs to make phones more repairable and force Apple to change their stupid activation lock bs.

    • @suddenlyacat
      @suddenlyacat Před 4 měsíci +63

      i got locked out of my galaxy phone because of knox and google frp so i don’t see why the eu should only strike apple for that 🤷

    • @dylanlindsay1993
      @dylanlindsay1993 Před 4 měsíci +6

      ya the EU should do that!

    • @username-mb2qh
      @username-mb2qh Před 4 měsíci +55

      ⁠@@suddenlyacatThey should strike everyone for that.
      Apple is typically the leading company in anti-consumer bs while Android makers follow suit which mind you makes them just as bad.

    • @darthraider450
      @darthraider450 Před 4 měsíci +9

      Arguably it's this USB-C implementation that has now opened up the use of insecure USB-C cables and devices to enter the iPhone ecosystem and enable a myriad of security risks and Apple now has to do a lot of extra due diligence to avoid this that they didn't need to do before. A copy of the security patches and fixes from MacOS and iPadOS to iOS is not enough, it's only a matter of time before iOS as open as Android, O-MG cables are already causing havoc on USB-C iPhones for the unaware but it's not anywhere near as prevalent or widespread as it could soon become.

    • @username-mb2qh
      @username-mb2qh Před 4 měsíci +26

      @@darthraider450 Idk about iOS becoming as open as Android when it’s still closed source. Though I guess most Android devices typically run a bunch of bundled closed source software often combined with a locked bootloader nowadays.
      Google themselves have recently been locking down more file system elements like obb folder being root access.

  • @myrmeko
    @myrmeko Před 4 měsíci +98

    The biggest problem is iCloud locking itself.
    Literally nobody else other than the user is hurt by it.
    If somebody steals your phone, they are going to sell it as a scam to somebody else, without telling them it's iCloud locked.
    Now both the original owner has lost their phone and the new owner has a very expensive paperweight and 1000$ less in their pocket.
    Whoever stole it is the only one who won anything out of this.
    Imo, iCloud locking should be made illegal.

    • @Unspeakable_Edits
      @Unspeakable_Edits Před 4 měsíci +7

      Bro who tf buys a iPhone without checking the phone bruh

    • @myrmeko
      @myrmeko Před 4 měsíci +7

      @@Unspeakable_Edits A very high number of people. Especially people that don't know much about phones.
      Even if they "check" the phone, you have to first go through the whole setup process to get to the iCloud screen, which most people don't do.
      Also, until iOS 12, you also had to have a SIM card in order to set up the phone.
      As i said before. The only one who wins out of this is the robber. 🤦🏻‍♂️

    • @M4TTYN
      @M4TTYN Před 4 měsíci

      Yea lots i've seen with icloud locks saw one with few devices one in what i assume was thai or some language i went "hope these ain't stolen devices" and a huge shame Apples market share literally won't tank or budge!
      And iOS lacks so many features and options to iOS die hards hate when we say "we had x since 2013 or so" to having the basic of micro SD card support lmao can't wait for apple to "invent" it tho!

    • @lowellthoerner1209
      @lowellthoerner1209 Před 4 měsíci +2

      Theoretically it deters theft in the first place. This is obviously impossible to measure accurately but I do suspect it stops the more organized criminals for targeting phones rather than other valuables. Petty thieves are, by and large, pretty stupid, so it doesn't necessarily deter them to nearly the same extent.

    • @myrmeko
      @myrmeko Před 4 měsíci

      @@lowellthoerner1209 Theoreticaly... In reality, the salvageable components are worth almost just as much as the whole phone. Even the board itself, even if it cannot be used directly, it has so many chips that can be used for repairs, since Apple doesn't make them available for purchase. Broken boards are essential for repairs.
      It doesn't deter anything and thieves know damn well how valuable every single piece of an iPhone truly is.

  • @MrRicky6796
    @MrRicky6796 Před 4 měsíci +183

    If Apple really cared, they could ask you for example after 1 year without activity, if the device in your iCloud Account should exist. People who throwed their phone away could remove it, people who lost it or got it stolen could still let it in their accounts.

    • @Prod.blimdxqe2024
      @Prod.blimdxqe2024 Před 4 měsíci +5

      I don’t think android does this even though?

    • @MrRicky6796
      @MrRicky6796 Před 4 měsíci

      @@Prod.blimdxqe2024 because as in the Video mentioned, Android devices are not affected by such a lock.
      An FRP is on the software of the devices only, meanwhile every iOS device needs to get "approved" by Apples activatiom before it becomes useable

    • @rayanking4773
      @rayanking4773 Před 4 měsíci

      @@Prod.blimdxqe2024it does

    • @Tiger1Tanker
      @Tiger1Tanker Před 4 měsíci

      @@Prod.blimdxqe2024 google does I think. you have to go into your account to see it bc you don't get a notification.

    • @MatWilson2612
      @MatWilson2612 Před 4 měsíci

      ​@@Prod.blimdxqe2024it doesn't, but it's easier to circumvent is my understanding.

  • @APR2kNSP1
    @APR2kNSP1 Před 4 měsíci +116

    I have many devices for sale on my eBay store and after seeing this video, need to go back and change all my listings to not include the SN. Thank you for making me aware of this issue. Especially since several of those phones are iPhone 7, 8, 8+ and SE 2016 which are all affected.

    • @amidconstant4285
      @amidconstant4285 Před 4 měsíci +11

      It doesn't affect iphones. Only wifi only devices.

    • @BillAnt
      @BillAnt Před 4 měsíci

      Serial or IMEI is fine, just don't show it along with the Bluetooth and WiFi address since those are requires too.

    • @mjc0961
      @mjc0961 Před 4 měsíci +7

      @@BillAnt IMEI is not fine. Even if it doesn't have anything to do with the flaw in this video, it's bad to share that information for several other reasons. And serial number has never been fine for other reasons too.

    • @BillAnt
      @BillAnt Před 4 měsíci

      ​@@mjc0961- When selling a phone online most sellers provide the IMEI so you as a buyer can check it for being blacklisted or clear. Yes it's a necessary evil.

    • @soupdrinker72
      @soupdrinker72 Před 4 měsíci

      This is only an issue that affects wifi only devices and not cellular ones

  • @rafaelappleseed8140
    @rafaelappleseed8140 Před 4 měsíci +93

    This serial swapping doesn’t affect iPhones and cellular iPads as their imeis are brunt into the baseband chip thus will cause a mismatch and prevent activation

    • @amidconstant4285
      @amidconstant4285 Před 4 měsíci +40

      Exactly. I don't understand why he didn't clarify that as iphones are by a huge majority, the most prevalent apple devices

    • @rafaelappleseed8140
      @rafaelappleseed8140 Před 4 měsíci

      @@amidconstant4285 not enough research?

    • @JimmyRussle
      @JimmyRussle Před 4 měsíci

      @@amidconstant4285because his title is clickbait

    • @rafaelappleseed8140
      @rafaelappleseed8140 Před 4 měsíci +1

      @@chlorophyllphile cheers for the update :)

    • @phr3ui559
      @phr3ui559 Před 4 měsíci

      @@chlorophyllphile oh alright

  • @nottimothy5994
    @nottimothy5994 Před 4 měsíci +170

    Just note that systems similar to Apple's activation lock system are also implemented on the android side, just not as universally.
    The original owner's Google accounts can be required to setup an Android phone that was wiped the 'wrong' way - it's 'Factory Reset Protection (FRP)'.
    Samsung also has 'Knox' which can do a similar thing (although is designed to do a lot more, for enterprises)

    • @saifalmaaytah636
      @saifalmaaytah636 Před 4 měsíci +62

      But frp can be easily bypassed not like apple activation lock which is server based

    • @hx0d
      @hx0d Před 4 měsíci +27

      Don't tell them that - it goes against their heavily android bias!

    • @lucaspanebianco6860
      @lucaspanebianco6860 Před 4 měsíci

      fr they shouldn't make it that hard@@saifalmaaytah636

    • @BillAnt
      @BillAnt Před 4 měsíci

      ​@@saifalmaaytah636 - Well, the "can be easily bypassed" FRP lock on devices with newer than June 2023 firmware/security update is not possible anymore without paying for a gray market unlocking service. And yes, that's server based. On older devices and/or firmware yes.

    • @username-mb2qh
      @username-mb2qh Před 4 měsíci +10

      @@BillAntIs it possible to get rid of FRP and Knox or are they as enforced as hard as the iCloud lock?
      I really hope at least Google and Samsung could take note from this issue though nowadays they tend to copy Apple in all the worst ways.

  • @its_argho
    @its_argho Před 4 měsíci +8

    My programming teacher in college used to say this - “The more functions and variables and features you add to your code, the more edge cases and loopholes you create - some of which you wouldn’t even know exists”
    Seems to be the same case here, apple has so many security checks and functions in place that there are several loopholes.

  • @blueberrytigerfox
    @blueberrytigerfox Před 4 měsíci +88

    I'm glad to not be an apple user

    • @Insertdisks_101
      @Insertdisks_101 Před 4 měsíci +8

      I used to use an iPhone, but I didn't like it, and I switched to an Android

    • @Boogie_the_cat
      @Boogie_the_cat Před 4 měsíci

      Apple blows. You pay more for a supposedly "easier" experience that is incredibly locked down and proprietary. You pay extra for less functionality and for someone (like me) who knows how to operate a PC since 1992, DOS days, apples are harder to use because they're not LOGICAL, they want you to only be able to perform actions ONE WAY, you have to learn how they expect you to operate the device. It's f*cking dumb .and they're the biggest e-waste producer

    • @100paulius_
      @100paulius_ Před 4 měsíci

      Bruh

    • @lewisl4594
      @lewisl4594 Před 4 měsíci +3

      Androids could be stolen and reset since the beginning of android and still just as easy present . Dunno what you’re glad about .

    • @ozzelot3349
      @ozzelot3349 Před 4 měsíci

      ​@@lewisl4594If my device gets stolen anyway, at least the thief can get utility out of it. Also, the majority of iCloud locked devices out there are not stolen, only abandoned by their previous owners, sometimes in large quantities by schools and other organizations.

  • @CaseyDplays
    @CaseyDplays Před 4 měsíci +31

    You need serial numbers on phones to verify if the phone is "unlocked" for a network (not the phone or apple account lock ) This means if you buy a phone without seeing the serial number you take a risk on it not working. Like the person owes money on it for example. But, in turn if you share the number to prove it is unlocked and can be put on any network you risk someone using the exploit in this video. All in all, this makes owning, buying, or, selling an iPhone risky business.

    • @BillAnt
      @BillAnt Před 4 měsíci +1

      Serial or IMEI is fine, just don't show it along with the Bluetooth and WiFi address since those are required too for cloning.

    • @Mr.Unacceptable
      @Mr.Unacceptable Před 4 měsíci +8

      DRM and other software security is made intentionally to hurt the consumer way more than a criminal. Every single time. Even movie and game software DRM makes the pirates experience better then the consumers in many ways. better load times. plays better. Play on the device of your choice etc.

    • @Joshtheweatherman
      @Joshtheweatherman Před 4 měsíci +1

      And that's why I use Android lol. I have a bricked iPhone XS, because of this very reason. I bought it off of Amazon 3 years ago, and it worked good for about three months. But then all of the sudden, an activation lock appeared, and it wasn't my email. So either the previous owner was still paying on the phone (which I highly doubt because the phone was over 3 years old then), or they wrote my serial number down to write onto another iPhone XS.

    • @My_Old_YT_Account
      @My_Old_YT_Account Před 4 měsíci

      ​@@Joshtheweathermanyou're a victim of this exploit, unpaid phones don't get icloud locked, they simply become unable to connect to cell towers for anything but 911 calls

    • @tOSdude
      @tOSdude Před 4 měsíci

      iOS 15 introduced the spot in the "about" tab that lists carrier restrictions.

  • @thelightbrigadef4172
    @thelightbrigadef4172 Před 4 měsíci +37

    Imagine if that happens on iMac and Macbook. It's the biggest nightmare that someone spends on $4999 if for one day they didn't write the important apple ID, it's a giant pain.

    • @ytbeste123
      @ytbeste123 Před 4 měsíci +1

      if it doesnt effect mac i´m not screwed

    • @hx0d
      @hx0d Před 4 měsíci +4

      Or its almost like any device running any OS can be exploited because vulnerabilities are found all the time 🤯🤯🤯

    • @laurentiurosianu
      @laurentiurosianu Před 4 měsíci +3

      even newer macbooks can be activation locked

    • @prayhe
      @prayhe Před 4 měsíci

      @@laurentiurosianuhe was talking about serial swapping being possible on those devices

    • @WantBadtime
      @WantBadtime Před 4 měsíci

      Remember local accounts being the primary thing? I sure missed having those.

  • @thomashammond5666
    @thomashammond5666 Před 4 měsíci +19

    0:37 This exploit also affects Apple Watch models from the Series 0 to Series 3. In fact, I used this exploit to make my old Series 3 watch think it’s a Nike+ model, allowing me to have access to those faces on my non-Nike watch running watchOS 8, the last version the Series 3 supports. Those Nike watch faces became available on all Apple Watch models (Series 4 and later) in watchOS 9.

    • @megatronskneecap
      @megatronskneecap Před 4 měsíci

      That’s not really an “exploit” as it doesn’t harm anyone more than a stupid glitchy oversight.

    • @adkodiyan
      @adkodiyan Před 4 měsíci

      How do you do this?

    • @superNova5837
      @superNova5837 Před 4 měsíci

      @@megatronskneecapI guess easier to just have them exist in the code and only S/N that say it’s a Nike+ model enable it then have those run a separate version

  • @PiratCarribean
    @PiratCarribean Před 4 měsíci +42

    This also applies to samsung devices. What I see happening is that people get a phone with a subscription. Then they don't pay and sell the phone in the mean time. After that the phone company locks the phone and it becomes completely useless.

    • @Vedant9710
      @Vedant9710 Před 4 měsíci +11

      On Android it's pretty easy to bypass this however by just resetting your phone again through the Android Recovery or you can literally also re-flash the entire ROM using a computer which is a little more complex and you'll have to do some research depending on your device.
      Apple has made it so that all their older phones become E-Waste due to this, maybe even usable ones like iPhone X with a replaced battery. If they really love the environment so much, why don't they remove these measures?

    • @PiratCarribean
      @PiratCarribean Před 4 měsíci +6

      @@Vedant9710 Doesn't work this way. Serial number is blocked.

    • @Vedant9710
      @Vedant9710 Před 4 měsíci +9

      @@PiratCarribean it's clear you've never used an Android phone or actually reset a used Android phone. I've done several and I'm speaking this from personal experience. It's better than Apple's terrible "security" E-Waste creating measures

    • @gamecuber6
      @gamecuber6 Před 4 měsíci +3

      to bypass this, you could just flash a custom rom that doesnt have any of samsung's stuff

    • @FAB1150
      @FAB1150 Před 4 měsíci +12

      ​​​@@Vedant9710you've never heard of FRP, have you? You can't just do that anymore, it will lock the phone and you need to input the credentials of the owner's Google account.
      Additionally recovery mode is now encrypted for almost every newer phone, and you need the phone's password to get into it in the first place.
      It's a way better system than Apple's as it's not tied to the S/N or anything that can be stolen and if you're the owner of the phone you'll always be able to unlock it, but you can't just reset a random phone anymore. Sometimes and for some manufacturers there are ways around the lock, but they get patched quickly.

  • @turbyoulance
    @turbyoulance Před 4 měsíci

    Great Video Hugh

  • @Mr.Unacceptable
    @Mr.Unacceptable Před 4 měsíci +75

    Apples security claims ALWAYS hurt the consumer more than the thief. ALWAYS.

    • @antononononon
      @antononononon Před 4 měsíci +4

      Does having to carry keys and locking doors and windows hurt the dweller more than a thief?

    • @Nami-x
      @Nami-x Před 4 měsíci +22

      ​@@antonononononImagine if when you lose your house keys (it can happen of course), you are now permanently locked out of your house forever. No locksmith to help you out (even if you have all the documentation to prove you own the house).
      That's what Activation Lock does.

    • @JoBot__
      @JoBot__ Před 4 měsíci +4

      @@Nami-x Exactly.

    • @LaciDoszka
      @LaciDoszka Před 4 měsíci +4

      @@Nami-x ..and while you're out, someome else can use your house (the other phone with your stolen serial)

    • @teamredstudio7012
      @teamredstudio7012 Před 4 měsíci

      @@antononononon Keys and window's aren't impossible to bypass.

  • @lenshibo
    @lenshibo Před 4 měsíci +9

    Im just blown away by the range of devices this effects. how could something this crippling go unfixed for 6 years??

    • @amidconstant4285
      @amidconstant4285 Před 4 měsíci +3

      Because it can't be fixed

    • @BillAnt
      @BillAnt Před 4 měsíci +6

      All they have to do to stop this, is to require the IMEI along with the Serial, Bluetooth and WiFi info. The IMEI cannot be easily modified if at all, therefore it would stop this craziness.

    • @ozzelot3349
      @ozzelot3349 Před 4 měsíci

      It might just have gone unnoticed. Bootroms are not the simplest thing in the world. Also the checkm8 exploit was only discovered in 2019, by which time many of the affected chipsets were already getting old.

    • @jasonhe54
      @jasonhe54 Před 4 měsíci

      because it's not patchable on those older devices which are susceptible to CheckM8

    • @pankoza2
      @pankoza2 Před 4 měsíci

      apple should just give up on the activation lock systems and make the server always report "not locked"
      and then make a system more similar to the one in stock android in newer iDevices

  • @Amathegoat
    @Amathegoat Před 4 měsíci +2

    So on a different note, I have wrecked potentially beyond repair phones, but with clean info, could I use those to put life Into devices that have an actual shot at being used? Ones I own though, I have no intention on locking people out of their own devices. I do repairs etc hence having devices on hand

  • @nikitazaycev8636
    @nikitazaycev8636 Před 4 měsíci +32

    The other major concern about the current icloud fmi logic is how they introduced “unlock with passcode” option starting with iOS 13, which makes any iphone with failed Face ID extremely vulnerable: the thief only needs to see the passcode you type in and then they can just steal it and do a 3utools restore command (easy to do on the go, only requires a laptop and takes less than 5 minutes to execute), and then fully unlock the phone using just the password. Yes you can lock the phone by IMEI, but that would only block the cellular ability. Imagine its a 14 Pro (but only works in “ipod mode”) it can still be sold for $300 just fine.

    • @mirror71
      @mirror71 Před 4 měsíci +13

      What a derp here. "the thief only needs to know your password."
      Well, yeah, no shit Sherlock. That's not a hack. That's the entire point of a password.

    • @jaycqc8136
      @jaycqc8136 Před 4 měsíci

      No shit you slow asf if someone can catch your password if I own a iphone without face id I'm definitely getting a privacy screen protector

    • @jaycqc8136
      @jaycqc8136 Před 4 měsíci

      I think that option actually restore the phone so you be still signed in

    • @DavideDavini
      @DavideDavini Před 4 měsíci +3

      Dude, the fallback to passcode is a good feature. If Face ID fails you prefer to get locked out of your phone? I do not.
      Check if there’s the option to do what you want. Maybe it just doesn’t do it by default.
      Security has to be balanced against usability and cost. The cost and usability loss of not having access to your phone because Face ID doesn’t work is too high risk for the vast majority of people. If for you that’s acceptable I’m sure it’s achievable somehow, maybe look into other manufacturers if iPhone is not allowing it.
      Cheers mate.

  • @AlexeyFilippenkoPlummet
    @AlexeyFilippenkoPlummet Před 4 měsíci +4

    Well if you have been locked out of your own device, there's a way to unlock it - just change the serial number yourself lol. Of course it's likely to lock someone else out, but you alternative is to create e-waste and spend big money on a new Apple device. Also there is a chance that the serial number you buy is associated with a device that's not in use and won't hurt anyone, but still, you didn't choose to hurt yourself either. Of course this will not work with the newer models though, tough luck there.

  • @rodentartmouse
    @rodentartmouse Před 4 měsíci

    I'm an Android user! It seems after watching your channel as a newer subscriber that apple mobiles are a heavy risk buying one😯

  • @Mee33342
    @Mee33342 Před 4 měsíci +10

    As an Android user, I find this video very informative. Thanks.

    • @gabriledyt
      @gabriledyt Před 4 měsíci

      This thing works only on iPhone X max and iPad 7th,quite old

  • @newecreator
    @newecreator Před 4 měsíci

    Thanks, man for letting me know.

  • @senkensu
    @senkensu Před 4 měsíci +2

    I hope this actually gets used in a court case

  • @kennethpaulcalangi4122
    @kennethpaulcalangi4122 Před 4 měsíci

    Question: how are these thieves able to obtain those unlocked serial numbers? regardless if this does only affect devices w/o IMEIs, still scary as they can for sure be able to do it to iPhones as well.

  • @joli22
    @joli22 Před 4 měsíci +2

    I did infact *not* like what I saw, but thanks for bringing it to me, still gave it a like 👍

  • @80sTechKid
    @80sTechKid Před 4 měsíci +1

    I believe that Apple uses software paired parts to prevent motherboard replacement, so you can’t steal a $800 iPhone with FMI on and put a $90 replacement motherboard in it and resell it

  • @themastereal8345
    @themastereal8345 Před 4 měsíci +3

    doing this for my school presentation thanks

  • @ninjastechheaven
    @ninjastechheaven Před 4 měsíci

    Hey Hugh, I have my grandpas old iPhone that I would like to give you to fix. I can’t do anything more with it. Thanks!

  • @tcode3564
    @tcode3564 Před 4 měsíci +1

    So I have my doubts about there not being such a lock an android. I recently rested my old phone through the Samsungs boot menu. After trying to set it back up, it now always asks for the original Google account and I can't set it up without logging in with the original Google account first.

  • @thisislilraskal
    @thisislilraskal Před 4 měsíci +1

    Glad I made the switch years ago and I've never looked back. Probably never be an apple customer again for this and other reasons

  • @xoblackparade
    @xoblackparade Před 4 měsíci +1

    honestly very confused as to how this even works; activation lock turns on when an apple id is signed into the device and find my is turned on and each device knows it’s own serial number even if there’s no power at all to the device, you can use an SNR through the charging port & retrieve the serial number

  • @scotttrongkaew
    @scotttrongkaew Před 4 měsíci

    It does If iOS10 and lower,Applie changed activation method since iOS10 as I know they also use UDID number also, and on cellular ipad and iphone are relative to imei and will cause unable to activation error.

  • @GINETTA-GAMING988
    @GINETTA-GAMING988 Před měsícem

    Your the best Hugh one day I will make a video about my technology shed and I think you will like it but some phones are bad btw I don’t charge my techs so yeah

  • @monsterinfamous6267
    @monsterinfamous6267 Před 4 měsíci +1

    Hello thanks for the warning, what happened if you apple device is not link with an icloud account ? (using the iphone without an icloud account) ?

  • @PhilXavierSierraJones
    @PhilXavierSierraJones Před 4 měsíci +2

    If I had my way, I would set the activation server to reply "yes" to any activation request, because this system is flawed and Apple is not going to fix it because it lines their pocket. Why fix something that's bringing in even more cash than when you do? Their "environmentally conscious approach" is a complete baloney and they must be slapped with a 999 trillion dollar fine unless they completely remove that system.

  • @paprocgaming5039
    @paprocgaming5039 Před 4 měsíci +4

    As far as I know in some countries modifying such data as IMEIs and Serial numbers is illegal. At least thats how it is in Poland.

    • @lucasmarsula7924
      @lucasmarsula7924 Před 4 měsíci

      Well then there's no problem

    • @teamredstudio7012
      @teamredstudio7012 Před 4 měsíci +1

      And locking you out of your own deivce using software should be considered stealing. These thins cost a thousand or more.

  • @eieiw32424
    @eieiw32424 Před 4 měsíci +2

    this is genuinely terrifying

  • @nidulaperera
    @nidulaperera Před 2 měsíci

    Hugh Jeffreys information is correct, however this specifically affects Wifi Only devices like iPad’s and iPods. iPhones won’t work, as there is no way to change the IMEI on a device yet in 2024. Which means this won’t work for iPhones.
    This tool though is very useful in a whole for the repair industry. You can use Serial Numbers from an iPad 2nd generation, and write it to a iPad Air 2nd Gen or iPad 5th Gen, and for company iPads with employee iCloud Locks, this is useful, and keeps this iPad’s going to ewaste.
    But like shown in the video, it can be used for malicious intent, which is not good, but it’s not perfect, because whoever copies your SN they cannot use facetime and iCloud Services due to the wrong eMac Address.

  • @darthraider450
    @darthraider450 Před 4 měsíci +4

    What's to stop someone from taking a note of the details, selling the device, then posting the details or selling them about a month later leading to the sold device being bricked?

    • @YingLui305
      @YingLui305 Před 4 měsíci +1

      This why you should buy a new device in a sealed box. I guess

    • @prodbydanai
      @prodbydanai Před 4 měsíci

      ​@@YingLui305that wouldn't work either.

    • @Joshtheweatherman
      @Joshtheweatherman Před 4 měsíci

      @@YingLui305 New in box Apple products can have their serial numbers stolen too, because it's on the back of the box.

    • @Kevin-mx4vm
      @Kevin-mx4vm Před 3 měsíci

      Thank you for the idea gonna extract more money from isheep 😂

  • @fixer_of_everything
    @fixer_of_everything Před 4 měsíci

    This method has been revealed few years ago and already has been patched. I bought serial numbers for few iPods Touch 6/7 Gen, edited underlying data but they will not activate anyway. Except serial number, WiFi address and Bluetooth address,, Config File is binded to CPU or Motherboard number. This method works well when you want to upgrade memory on your iPod/iPad.

  • @Mr.Nabil.Belhaj
    @Mr.Nabil.Belhaj Před 4 měsíci +2

    And on that note this is one of sooo many reasons I would never give my money to Apple

  • @robsquared2
    @robsquared2 Před 4 měsíci +9

    This is great news for apple and its shareholders: more sales!

  • @jyzic
    @jyzic Před 4 měsíci

    should do this to a locked device but by using details from a faulty one that still turns on etc, be an interesting video, could save a fair few units you've got pointlessly locked with ones that cannot be saved

  • @xenos17
    @xenos17 Před 4 měsíci +10

    As far as I know, Android has Factory reset protection as well, but instead of iCloud, it's linked to a Google account. Same thing there, if you factory reset, you won't be able to use your device without the Google account that was used for it. This is only for devices that ship with Google services tho.
    There were ways to bypass FRP, but I don't know if they still work.

    • @TheMoon_Follow
      @TheMoon_Follow Před 4 měsíci

      I had one serviced that has an FRP lock, and yes there were ways to deal with it without requiring root permissions
      ~ thebelovedmoon 🌙

    • @prodbydanai
      @prodbydanai Před 4 měsíci +1

      Yeah they still work, but you'll have to pay some money.

    • @computergenius2121
      @computergenius2121 Před 4 měsíci +1

      Yeah, I used to use a galaxy s8 and I found it and it was google account locked to one of my old google accounts which I don’t remember the password of

    • @gary_rumain_you_peons
      @gary_rumain_you_peons Před 4 měsíci

      So Android users are dependent on the fascists at Google not deleting your Google account (try 'spamming' on YT and watch how long it takes them to delete your whole account).

    • @Prod.blimdxqe2024
      @Prod.blimdxqe2024 Před 4 měsíci

      It would especially be healthy people who use android if they Google accounts don’t work no more

  • @sanjxz
    @sanjxz Před 4 měsíci

    In fact, samsung has somewhat same exploit, with their LDU devices, but it only works one way (you can flash a normal SN on LDU Device to unlock it, but you cant remotely LDU other device).

  • @electromega3077
    @electromega3077 Před 4 měsíci +13

    Probably soon Apple will lock your devices automatically after few years of use. You need to buy a new one in order to prevent the old one to be stolen.

  • @Green_House
    @Green_House Před 4 měsíci +11

    Apple knows what's best for us! 🤔

  • @Wildcatchigga11
    @Wildcatchigga11 Před 4 měsíci +1

    Taught of sharing this video, guess what? No one owns apple products in my circle 😶🤣🤣

  • @TheUltimateRecycler
    @TheUltimateRecycler Před 4 měsíci +21

    Man, the amount of unnecessary ewaste that Apple creates really annoys me!! 😟

    • @dominic7012
      @dominic7012 Před 4 měsíci +4

      Not just Apple.

    • @partoftheworlD
      @partoftheworlD Před 4 měsíci +2

      It's eco friendly ewaste lol. A bundled charger is bad for planet, and a phone turned into a brick is good for planet. Sometimes this kind of double standard shocks me.

    • @pankoza2
      @pankoza2 Před 4 měsíci +1

      this is why old Androids are Goated for me

    • @partoftheworlD
      @partoftheworlD Před 4 měsíci

      Old androids were terrible after a year of using the phone started to be laggy, I think before android 11 everything on android was bad and only custom firmware saved. @@pankoza2

  • @solothebest1850
    @solothebest1850 Před 4 měsíci +1

    I think he should've started the video by stating that these issues benefits apple themselves more than the criminals, users or anyone else simply by turning their devices into unusable bricks forcing them to get a new one.

  • @CreepSoldier
    @CreepSoldier Před 4 měsíci

    What if an random update just maybe trigger your phone to unfortunately id lock, just when the next iphone launch looms nearby, wouldn't that be interesting

  • @brianbuddy2ACP
    @brianbuddy2ACP Před 5 dny

    Oh, and also, don't use a blur for a censor. AI can unblur it and reveal the number. Instead, use a solid color box, or even better, forgo a digital censor entirely and cover it when you take the photo with something like opaque tape or an index card.

  • @HoraceHD_
    @HoraceHD_ Před 4 měsíci

    My new iPhone 14 pro max I purchased in 2023 still got me locked out and apple couldn't do anything, I bet if it was android I would be having less issues with my device, the fact I need internet to setup my phone 'an idea apple created just right before you can access anything on the device' is crazy, too much e-waste if activation lock still continues

  • @Aviation1787
    @Aviation1787 Před 4 měsíci

    so does that mean having a locked iphone, changing the serial number with my iphone will activate that locked iphone, then logging into my icloud and unlocked the other idevice with my icloud will leave me with 2 unlocked iphones?

  • @Kurazaybo
    @Kurazaybo Před 4 měsíci +1

    There is an inminent rework of apple serial number authentication following the beeper mini fiasco

  • @mimijester
    @mimijester Před 4 měsíci

    Ah If I understand correctly, if you use the same method that they did to swap the serial numbers. Could you retake the serial number? Ideally before that new serial number is iCloud locked?

    • @Prod.blimdxqe2024
      @Prod.blimdxqe2024 Před 4 měsíci

      Fight up the serial numbers. In today’s game we have one person trying to steal the opposition plays serial Number whilst the opposition plays serial number is being stolen by the other opposition players.

  • @teh_supar_hackr
    @teh_supar_hackr Před 4 měsíci +2

    Apple's whole way of managing there iCloud services is the pure reason why I'll never use an iOS device. I'd like to since the newer models have many advanced features not on Android, but I don't want to be locked out of my own iPhone just because someone got the serial number from a database of leaked numbers.
    BTW yes I know the irony in my username and stating this comment lol

  • @LukanSpellweaver
    @LukanSpellweaver Před 4 měsíci +2

    If apple cared at all about their users, y'all wouldn't have to sue them for USB-C or repair parts. I don't understand the cult that keeps them in business....

  • @WillM.
    @WillM. Před 4 měsíci +1

    Does it effect Apple Watch of any series?

  • @celiske
    @celiske Před 4 měsíci +2

    I have an iPhone 8 that I’ve had for years and am still going to use for the foreseeable future as it still does everything I need. But man, when the time comes for an upgrade, will almost certainly be going android. I just can’t support apple with all these issues around e-waste and repairability.

    • @alittlepickle8632
      @alittlepickle8632 Před 4 měsíci +1

      dw bro. This is only a flaw with iPods and old iPads . Your phone is fine. He’s just over reacting- all cellular iPhones and iPads have something called imeis and they can’t be changed AT ALL as the number is literally burnt physically on the nand chip . The imei is the important part and there’s nothing people can do to take it from you .
      What’s funny is that the guy in the video showed a iPhone 11 being reset like he’s demonstrating the sn swap , when he’s actually just creating click bait 😅

    • @alittlepickle8632
      @alittlepickle8632 Před 4 měsíci

      But he’s right about ic locked devices being ewaste

    • @celiske
      @celiske Před 4 měsíci

      Yeah I read that in another comment about cellular devices not being vulnerable. But thanks for letting me know. That’s not the reason alone for not wanting to stick with apple though, other reasons too, though could always change depending if apple changes. I’ve just got a battery replacement kit for my iPhone 8 so I’m certainly not even upgrading anytime soon to anything. Hopefully manufacturers start implementing swappable batteries by the EU regulation by the time I need to upgrade lol. I can hope.

  • @AboringFordSedan
    @AboringFordSedan Před 4 měsíci

    400TH VIDEO LES GO

  • @Techlifeandmore
    @Techlifeandmore Před 4 měsíci +1

    Does this mean that I could take the serial number from my iPad mini 4, swap it with that of the serial number of my friends iPod touch seventh generation, and get it activated for him?

    • @amidconstant4285
      @amidconstant4285 Před 4 měsíci +1

      Yes and no. Not all serials work with every checkm8 vulnerable SOC.

  • @GotNoLoveForYou
    @GotNoLoveForYou Před 4 měsíci +1

    Story about a huge flaw ;
    I found a iPad 6th gen recently, I randomly guessed the password which was 0000 (very difficult🤣) than I was m able to remove the previous owners iCloud and put my own! Not sure if it’s a fluke or a flaw.

    • @Void_Rudster
      @Void_Rudster Před 4 měsíci +1

      how did you do this ?
      I currently have an icloud lock on an ipad 2

    • @GotNoLoveForYou
      @GotNoLoveForYou Před 4 měsíci

      @@Void_Rudster i literally turned it on thinking there wouldn’t be a password but I assumed it would be for parts etc. I guessed a few times then it was disabled for 1 minute, when I tried 0000 after it unlocked! I than used it for a few days with the previous owners things installed (including iCloud account) and after a while I thought about removing the account so I went to settings, clicked on the account and removed it without entering anything! It’s iOS 15.5 iPad 6th generation
      Edit : again ,not sure if it’s fluke or flaw

  • @Radkeyboard7984
    @Radkeyboard7984 Před 4 měsíci

    Hi Hugh I happen to see Apple and they say this flaw is unpatchable

  • @daigo.castillo
    @daigo.castillo Před 4 měsíci +1

    This is one of the reasons why I don't like Apple that much. If you buy an iPhone, it should gonna be your property. But it feels like not. The only features I like about the iPhone are its processor and camera.

  • @lokelaufeyson9931
    @lokelaufeyson9931 Před 4 měsíci

    apple is apple, a tiger never change its stripes

  • @80spodcastchannel
    @80spodcastchannel Před 4 měsíci +4

    yet another reason I will continue to rock android..

    • @SantiagoAragort
      @SantiagoAragort Před 4 měsíci +1

      @80spodcastchannel. Yeah, Apple sucks crap a lot. I own an Android Smartphone, from a Chinese smartphone brand.

  • @deinmutter323
    @deinmutter323 Před 4 měsíci

    just hope that the EU is making a law that is making activation lock illegal and still when your device is stolen the thief can still sell the parts of the phone exept of the mainboard

  • @ejonesss
    @ejonesss Před 4 měsíci

    a catch 22 unless your device is stolen how is someone to know the serial number?
    is there a way to exploit something like pegasis or equivalent to steal a serial number from someone?

  • @ThePandaPhotographer
    @ThePandaPhotographer Před 4 měsíci

    And also on Craigslist in the states 0:59

  • @deathsyth8888
    @deathsyth8888 Před 4 měsíci

    Apple: There's a simple solution to this problem. Just by another Apple product!

  • @IMDYT420
    @IMDYT420 Před 4 měsíci +1

    UNPATCHABLE? Oh okay thankfully only older iPhones so my 11 is okay hopefully. Not that I’m gonna be giving my serial number to anyone but good to know the newer iPhones should be safe.

  • @adminiptelkaisback
    @adminiptelkaisback Před 2 měsíci

    Wait dose that mean that I can use the serial number from my iPad 2 to unlock my iCloud locked iPhone 6 on iOS 8.4 (not stolen)

  • @NTTE_YT
    @NTTE_YT Před měsícem

    Can replacing the logic board fix the issue?

  • @just_me_fr
    @just_me_fr Před 4 měsíci +1

    i was buy ipod 5th from secend hand website and it was work good for some weeks, but after that i wasnt able to use it because it was activation lock (this is my first apple device and I dont know anything abaut icloud). Is there something i can do? (sorry for my bad english)

    • @pankoza2
      @pankoza2 Před 4 měsíci +1

      you need a serial number of another iPod Touch 5th gen that doesn't have the lock

    • @Kevin-mx4vm
      @Kevin-mx4vm Před 3 měsíci

      Yes, you can throw it in the trash

  • @OakBlox
    @OakBlox Před 4 měsíci +1

    for iphone, when you say 4s - x, does "x" include xs, xr and xs max?

    • @anianii
      @anianii Před 4 měsíci

      No, they have the A12 chip which is not affected anymore

  • @6StringPassion.
    @6StringPassion. Před 4 měsíci +8

    Apple's revenue is tanking. Four consecutive quarters - on weak demand for iPhone. This kind of nonsense is why. Tim Cooke needs to be shown the door.

    • @baneq105
      @baneq105 Před 4 měsíci +1

      Not really. Way bigger issue is people realising they can use their phone for 5 years, change battery and pass it down to grandma for example. I know some people still using 1st gen se and iphone 6 and 7. I also know people who buy new iphone after a year for some reason, but they're in minority.

    • @proallnighter
      @proallnighter Před 4 měsíci

      @@baneq105 I am still using my iPhone 8 as of today. No reason to upgrade. All the extra features on the new updates are not useful to me.

  • @iamn4m3l3ss7
    @iamn4m3l3ss7 Před 4 měsíci

    You should not hand out serials for any product ever. People will use these to scam companies by requesting a false refund/replacement which they sell for a profit. Recently a huge group doing this with amazon insiders where arrested.

  • @frimmbits
    @frimmbits Před 4 měsíci +1

    04:20 is music to my ears

  • @Wildcatchigga11
    @Wildcatchigga11 Před 4 měsíci

    Most of the scams happen in Facebook market place, so where people buy phones why are already activation lock. They specially old people don't know this. Always let old people be informed about this.

  • @techosarusrex
    @techosarusrex Před 4 měsíci +2

    While Windows has something similar to Activation Lock, it is only for business devices managed by a company and enrolled with a company, not consumers.

    • @insertusernamehere69
      @insertusernamehere69 Před 4 měsíci +3

      Better yet, if you have good intentions, you can just wipe the hard drive and reinstall windows

    • @techosarusrex
      @techosarusrex Před 4 měsíci

      @@insertusernamehere69 true but depends on the config a reset won't bypass that.
      It's down to the company provisioning the device.

    • @insertusernamehere69
      @insertusernamehere69 Před 4 měsíci +1

      @@techosarusrex oh so its an optional hardware lock in the device?

    • @techosarusrex
      @techosarusrex Před 4 měsíci

      @@insertusernamehere69 yep. Only for business and enterprises (nothing for consumers)

    • @pankoza2
      @pankoza2 Před 4 měsíci +1

      It's nice that somebody else also knows this, also it's only in Pro and Enterprise edition of Windows, Home Edition users can sleep safely

  • @ps5gamepl4ys
    @ps5gamepl4ys Před 4 měsíci +1

    It ca affect to an iPhone 13 Pro MAX?

  • @Bowhoe09
    @Bowhoe09 Před 4 měsíci

    Smart I am going to do this

  • @tbud3734
    @tbud3734 Před 3 měsíci +1

    This company creates so much e-waste which it can avoid easily and then advertises itself as eco-friendly. Amazing that no government seems to bother.

  • @radvilasshimkus
    @radvilasshimkus Před 4 měsíci

    I’m glad I have a newer iPhone.

  • @pokemongamer1587
    @pokemongamer1587 Před 4 měsíci +1

    Yeah, Apple takes security way to seriously.

  • @Anonymous-bk6eq
    @Anonymous-bk6eq Před 4 měsíci

    this kinda reminds me of what they used to do back in the early 2000's called "ESN cloning " or "IMEI cloning"

  • @Dwall44
    @Dwall44 Před 4 měsíci +1

    Wow, I’m lost for words. This is unbelievable!…
    Who am I kidding, at this point I should be used to this stuff from now coming from Apple.

    • @anianii
      @anianii Před 4 měsíci

      This is literally based on a hardware bug… that is not intentional at all

  • @AkoTamakii
    @AkoTamakii Před 4 měsíci

    Thanks dude now i can buy that icloud locked iphone😂

  • @MatWilson2612
    @MatWilson2612 Před 4 měsíci +6

    So does Tesla.. And everyone else.
    This vulnerability is obviously an issue and they've fixed it with hardware which is great. Activation lock is a good thing, since people are more likely to ditch an iPhone and find it again or have it anonymously handed in as opposed to someone just wiping it and selling it.

  • @Radkeyboard7984
    @Radkeyboard7984 Před 4 měsíci

    Hugh I have talked to apple and found that apple did not know about this

  • @joshromero2718
    @joshromero2718 Před 3 měsíci +1

    I did this at my school all the time I would go around just writing down iPads serial numbers

  • @RealM12Gyt
    @RealM12Gyt Před 4 měsíci +1

    there is a lock system for android that if you have android 5.1.1 (some devives or up then you have the frp lock and have to login with google

    • @pankoza2
      @pankoza2 Před 4 měsíci

      but the data is stored in a partition in the Flash memory instead of HWID or Serial-based, that on most devices can be removed using tools

  • @dholaholics
    @dholaholics Před 4 měsíci +1

    Well.. the more you know…

  • @davidnguyen6473
    @davidnguyen6473 Před 4 měsíci

    Hey quick question, what was the website that you were using to check if the device was lost?

  • @artemromankov6116
    @artemromankov6116 Před 4 měsíci +1

    What's that rewriting program called?

    • @charlesgyening
      @charlesgyening Před 4 měsíci +1

      Looking through the comments trying to find this

  • @thunderglitcher
    @thunderglitcher Před 4 měsíci +1

    This is disgusting and I’m looking for an alternative to iPads now.

  • @amidconstant4285
    @amidconstant4285 Před 4 měsíci +6

    I think you should clarify that the serial change doesn't work on iphones or cellular apple devices because you can't change the IMEI.

    • @leebeeskee
      @leebeeskee Před 4 měsíci +8

      He won't say that because he only hates on Apple and will be as sensationalist as possible. This guy should seriously work for a newspaper!

    • @AndrewMackoul
      @AndrewMackoul Před 4 měsíci +6

      They still do. You won't be able to use the cellular function, but changing the S/N will still bypass activation lock.