Jump to content

Recommended Posts

Posted

We've got about 20 iPads that date from 2012. We don't have any proof of ownership (because we don't keep records that long...)

Some of these were left by previous leaving staff - who have left them locked - with a PIN we don't know!

 

Is there any hope? They will probably still access internet ok - so would be useable.

 

All ideas welcome!

 

Peter

Posted
Are these activation locked or not? If they're not, you might be able to put them into DFU mode and factory reset them with Apple Configurator. That will at least wipe them, but if they were signed into an iCloud account it won't help.
Posted

Ewaste caused by a) security systems or b) lack of updates. Annoying.

 

Remember to create a procedure for staff leaving to solve the first problem.

  • Thanks 1
Posted
We have a handful of ipad 2s that are just sat here now doing nothing (also 2012 era). The latest version they will take is progressively getting older and older compared to newer versions and although they're fully unlocked, we just have no use for them. I really do need to recycle them, just seems a shame to chuck perfectly functional tablet devices away.
Posted

Probably easy to jailbreak, is there something better you can install on them after that?

 

Or use them as internal web kiosks for displaying data around the school

Posted (edited)
Ewaste caused by a) security systems or b) lack of updates. Annoying.

 

Remember to create a procedure for staff leaving to solve the first problem.

Or have a proper management solution in the first place that allows to run activation lock bypass command...

 

Whether or not they are 9 years old, when do you expect updates for iOS to stop or do you expect them forever...?

Edited by Brimstone
Posted
Just seems a shame that our stupidity has rendered these unusable - I don't need to update them - even just running as a basic internet device would be well worth it - but my predecessor didn't manage to get a good system for staff leaving their equipment. I'll try some restore / wiping kinds of ideas. Since they are basically a doorstop - I guess worth risking a jailbreak too...
Posted
I don't need to update them - even just running as a basic internet device .

 

You should be taking your security obligations more seriously...

  • Thanks 1
Posted
I don't need to update them - even just running as a basic internet device would be well worth it

 

Internet devices don’t need to be up to date? Are you a time traveller from 20 years ago? Because if you are, I hate to break it to you but out of date, unpatched devices are the last thing I’d be wanting my users to browse the internet on.

Posted

Sorry - not being very clear.

Yes - I'd want the latest patch for the iOS that the ipad was running - but running iOS 12, fully patched and "up to date" would be ok.

I guess there is a time when the iOS is too old to be supported - and the iPad won't run anything newer - and then they are a useless brick.

And maybe ours are that old now - and so disposal is the only thing we can do.

 

Maybe just serves as a warning for us - about needing a better plan when staff leave, and hand in a device - that someone actually needs to check the device is usable......

Posted

We have about 40+ ipad2s still being "used" by staff and pupils. How much of a risk are these likely to be?

 

They are running IOS9, the latest they are able to run.

 

They have no access to the App store. They are basically used as a web browser/email access (through the browser). Outlook app not supported.

Posted
You may have some luck resetting them in recovery mode with itunes? Depends if they are just locked because you don't know the pin, or if they are activiation locked in which case you are stuck and you may as well e-waste them.
Posted
We have about 40+ ipad2s still being "used" by staff and pupils. How much of a risk are these likely to be?

 

They are running IOS9, the latest they are able to run.

 

They have no access to the App store. They are basically used as a web browser/email access (through the browser). Outlook app not supported.

 

There's 2 security issues to worry about. 1) local methods of hacking the device if you don't trust the users, but you probably do. 2) browser based exploits, 3) other exploits you can't disable, maybe iMessage, bluetooth etc.

 

Browser exploits include https://www.cvedetails.com/cve/CVE-2021-30795/

https://www.cvedetails.com/cve/CVE-2020-3899/

https://www.cvedetails.com/cve/CVE-2020-3897/

https://www.cvedetails.com/cve/CVE-2020-3895/

https://www.cvedetails.com/cve/CVE-2020-3868/

https://www.cvedetails.com/cve/CVE-2019-8846/

https://www.cvedetails.com/cve/CVE-2019-8844/

https://www.cvedetails.com/cve/CVE-2019-8835/

https://www.cvedetails.com/cve/CVE-2019-8816/

https://www.cvedetails.com/cve/CVE-2019-8815/

https://www.cvedetails.com/cve/CVE-2019-8814/

 

All those need iOS 13 to fix

 

https://www.cvedetails.com/cve/CVE-2019-8689/

https://www.cvedetails.com/cve/CVE-2019-8688/

https://www.cvedetails.com/cve/CVE-2019-8685/

https://www.cvedetails.com/cve/CVE-2019-8684/

https://www.cvedetails.com/cve/CVE-2019-8676/

https://www.cvedetails.com/cve/CVE-2019-8672/

https://www.cvedetails.com/cve/CVE-2019-8669/

plus 9 more, all those require iOS 12 to fix.

 

And there's 14 more that require iOS 10.

 

Problem is if they're used for email is anyone could send you a link to a webpage that tried every one of those exploits, and then access any file on the device.

 

Not sure why Safari doesn't use a decent sandbox

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...