I've read a couple of stories like these and still wonder if thieves tend to format the hard-drive or not.
To avoid that, I created a "honeypot" account which is automatically logged in on my machines (OS X), so at least the machine seems usable without reformatting (and Prey remains effective).
Any other similar tips or things to take care of to secure a Mac in particular?
I wondered about this as well. If I were professionally stealing laptops, my first instinct would be to disconnect power/battery, then boot from CD and image the HDD for later identity theft. From there a reinstall would be in order. All the theives seem to just open it up and start using it.
I also password protect my laptop. I wonder if I shouldn't to encourage immediate use for information gathering.
All there theives seem to just open it up and start using it.
Every missing/recovered laptop story I've ever seen on HN has a screenshot of the thief on Facebook. I imagine there is some degree of selection bias. The story about the recovered laptop (with pictures of the thief) is much more interesting than the one about the laptop that disappeared forever. Plus, it's much easier to catch a thief when you have access to their Facebook profile. Still, it's funny to think about all these thieves running off with laptops just so they can get their Facebook fix.
I miss the old firmware PowerMacs. You could reprogram the firmware to lock the boot sequence with a password. Unlike BIOS the firmware was NVRAM so popping the battery and resetting the PRAM wouldn't change much. The only way to get past the firmware was to replace the motherboard.
I'm guessing that most thieves, like most people, don't even know what 'formatting the hard drive' means, or even how to do it if they knew it meant erase the hard drive completely. Many people think the hard drive is the actual desktop box in many cases. It probably sounds like repairing the distributor cap on a car.
if you're really worried about a wiped/new hdd, lojack for laptops will embed itself in the BIOS, which allows it to survive OS reinstalls and replaced hdds.
I have it on my thinkpad, and despite numerous windows reinstalls and a couple hard drive replacements, it's still on my system.
1. Set a Firmware password. They will be unable to reinstall the OS or flash the HD without opening the case and messing with hardware. With a MacBook Air it is essentially impossible.
2. Create a Guest Account. This prevents you from using FileVault.
I feel like in this regard, the pre-Lion FileVault that only encrypted your home folder was superior, as it left you the opportunity of creating a honey pot.
Now I have to decide between a potential thieves having access to my unencrypted files and a chance of me getting returned my laptop or knowing my files safe but having to buy a new machine
I have prey installed in stand-alone mode, but instead of having it check for a url, i just have cron running it every 30 minutes and emailing the photo and screenshot and other info to a gmail account i made. I figure if it gets stolen, I might not have time (or remember) to turn on the url before its too late.
I also have the firmware pw set (Macbook Pro) - not sure how easy this it to circumvent - if you can't circumvent it then you can't reformat that easily.
Not sure if this applies to all Intel Macs, but once the EFI firmware password is set, only Apple can break it by calling support or going to an Apple Store.
I've lost laptops before, and always called Apple to make a note of the serial number. What I'm not sure of is whether or not Apple would hold the laptop if it was flagged, or return it back.
I'm second guessing my decision to FileVault the entire disc on the MBA, because I think this prevents automated login. The honeypot account makes a ton of sense.
To avoid that, I created a "honeypot" account which is automatically logged in on my machines (OS X), so at least the machine seems usable without reformatting (and Prey remains effective).
Any other similar tips or things to take care of to secure a Mac in particular?