What Happens When Data Security Goes Too Far?

Katelyn Harrison
Marketing Specialist
Support circularity by partnering with an ITAD provider like HOBI for device reuse.

As technology advances, data security needs keep growing, but at what point do security measures become a hindrance? Thereโ€™s no question that data security is necessary, especially in a digitally driven world. The real question is: What is too much? Device locks have become increasingly popular, but theyโ€™re also a major challenge in the ITAD space. While protecting data is paramount, certain concepts such as activation locks, FRPs, and MDM enrollment make device reuse exceptionally difficult and even hinder the process. Todayโ€™s blog post breaks down each device lock concept and how they collectively contribute to the e-waste crisis.

A Digital Age Necessitates Digital Security Strategies 

Device locks were created to deter theft, secure enterprise data, and prevent thieves and hackers from erasing data and reselling stolen devices. However, basic lock screens are not enough to fully protect private data. Before 2013, thieves could perform a simple factory reset, wipe the device, and sell it to a new user. As a result, smartphone theft skyrocketed. 

As smartphones advanced, they required more stringent data security measures. Basic screen locks were enough to protect immediate privacy, but a deeper layer of protection was needed to curb the device-theft epidemic and prevent corporate data leaks.

The Kill Switch Initiative

In response to rising smartphone theft, government officials and law enforcement created the โ€œSecure Our Smartphonesโ€ initiative to pressure tech companies into developing a permanent solution. The initiative urged OEMs and carriers to install a built-in remote โ€œkill switchโ€ tool that would render stolen phones useless and prevent illegal resale. In response,  several tech giants developed advanced, cloud- and hardware-level locks that do exactly what was asked: render locked phones useless. The problem is, useless smartphones become e-waste the moment they are locked without an unlocking solution.

Appleโ€™s Solution: Activation Locks 

Appleโ€™s iOS 7 introduced the companyโ€™s Activation Locks, which link physical hardware to a userโ€™s iCloud account. The Activation Lock turns on automatically when users set up the โ€œFind Myโ€ app on supported devices, linking a deviceโ€™s unique serial number to the userโ€™s personal Apple Account. Without entering the exact Apple Account password, the Activation Lock prevents anyone from turning off Find My, erasing the device, or reactivating it. This means, when someone steals a phone, the device is basically useless without the exact, valid Apple credentials. While this approach does deter thieves, it also prevents any device locked to an old account from being legally repurposed through a recycling vendor.

iStock 1044646398
What Happens When Data Security Goes Too Far? 2

Googleโ€™s Approach: Factory Reset Protection (FRP)

Shortly after Appleโ€™s Activation Locks went live, Google followed suit with Android 5.1, which introduced Factory Reset Protection (FRP). Like Activation Lock, FRP turns on automatically when you add a Google account to an Android phone, and requires the original ownerโ€™s Google credentials to reboot a device after a forced reset. This feature successfully stops unauthorized people from using phones, even after a factory reset. You can turn off FRP for those planning to resell or give their device away. However, if a user recycles their phone without manually deleting their Google account first, the phone essentially becomes a useless โ€œbrickโ€ to the next user. 

The Corporate Solution: Mobile Device Management Enrollment (MDM)

When companies began giving employees corporate smartphones and laptops, or allowing them to use personal devices for work, they faced increased security risks. Lost devices containing corporate emails, client records, and employee credentials presented significant legal liabilities. Mobile Device Management Enrollment was created as a corporate solution, where devices were registered with an organizationโ€™s central management server. MDM-enabled IT departments could remotely monitor enrolled devices, enforce security policies, install software, and wipe data immediately after a device was lost or stolen. However, if an organization fails to offboard a device properly before selling or sending it to downstream vendors for recycling, the device is rendered useless. 

DMCA: The Legal Wall

While device locks help deter thieves, they also create a digital barrier, turning fully operational hardware into e-waste. For many recyclers, this prevents them from reselling the devices and decreases client ROI. The biggest issue is the legal barrier. 

The Digital Millennium Copyright Act (DMCA) was enacted in 1998 to protect media from piracy by preventing people from hacking or bypassing unique software like Appleโ€™s Activation Locks and Googleโ€™s FRPs. Section 1201 declares it illegal to bypass, crack, or turn off digital rights management (DRM) and technology controls designed to protect copyrighted works. This also restricts ITAD processors like HOBI from remarketing these devices. 

Security vs Sustainability: The Negative Environmental Impact of Device Locks

HOBIโ€™s president Craig Boswell recently discussed the importance of industry advocacy on the HOBI Conversations podcast and described device locks as both a strong data-security development tool and a major challenge to the ITAD industry. 

While device locks protect enterprise and personal data, they also present obstacles that hinder legal device reuse. When device locks prevent used or retired electronics from being reused, they essentially create more e-waste. When large shipments of devices are sent to ITAD vendors containing devices locked to OEMs or MDMs, the entire process is put on hold for that load until the right person can be contacted to unlock them. This can often take weeks or even months to resolve, while viable assets sit idle and lose value by the minute. 

Device reuse plays a key role in circularity. Repairing devices for reuse helps reduce demand for more natural resources to be mined. Hindering device reuse increases demand for new devices, which raises carbon emissions. With device locks as a major blockade, device reuse is delayed indefinitely and prevents a successful circular economic model. 

Advocacy in ITAD 

Device reuse is a crucial part of the circular economy. The ITAD industry as a whole focuses on sustainable solutions to the e-waste crisis, but it must balance security and sustainability. Boswell explained on HOBI Conversations that the people making these laws donโ€™t always understand how to make the best decisions without negatively impacting the industry. Boswell strongly advocates industry involvement and emphasizes the importance of speaking up on topics that affect the environment as well as ITAD. 

Rules exist for a reason, but industry professionals have a voice in helping shape them. 

LinkedIn
X/Twitter
Print
Facebook
Email
Scroll to Top