after three weeks of being bought the seller desided that he wanted it back. He expressed this by locking it with a 4 digit PIN and a message that stated “Give me back the laptop and give you back the money”, with out calling or anything.
In other words, the seller somehow had remote control of the laptop and locked it remotely? Things like this are why you should always reformat and reinstall all the software on computers you buy...
Bruteforcing it is the long way, the fastest way would be to use an EEPROM programmer to clear the EEPROM and rewrite the BIOS. This can usually be done in-circuit without any soldering with a little clip that goes onto the chip. A lot of laptop repair shops have this setup. Some of the newer models store the password in TPM, which caused the shops to initially replace the TPM with a new blank one but some RE later revealed that many (not all) can be cleared in the same way as before.
The fact that BIOS/EFI passwords can be easily cleared must be one of the worst-kept secrets in the computer industry - the companies will often officially say that there is no way to reset them and that the whole motherboard has to be replaced in a not-so-successful attempt to propagate the myth that this protection is so secure that even they can't bypass it.
I did a low level reformat `dd if=/dev/random of=/dev/sdd` with the hard drive mounted on another machine before noticing that he seller had locked theachine EFI remotely.
>It sounds like the buyer did not re-register the device with their own Apple ID (assuming that is possible).
This is correct. You are supposed to set up your own iCloud account on the device, to make sure that no one else (except maybe Apple) has remote control over the device.
Actually, I don't remember reading about that in the Apple security whitepaper. Does Apple claim that they can't remote-lock your device without your password?
In other words, the seller somehow had remote control of the laptop and locked it remotely? Things like this are why you should always reformat and reinstall all the software on computers you buy...
Bruteforcing it is the long way, the fastest way would be to use an EEPROM programmer to clear the EEPROM and rewrite the BIOS. This can usually be done in-circuit without any soldering with a little clip that goes onto the chip. A lot of laptop repair shops have this setup. Some of the newer models store the password in TPM, which caused the shops to initially replace the TPM with a new blank one but some RE later revealed that many (not all) can be cleared in the same way as before.
The fact that BIOS/EFI passwords can be easily cleared must be one of the worst-kept secrets in the computer industry - the companies will often officially say that there is no way to reset them and that the whole motherboard has to be replaced in a not-so-successful attempt to propagate the myth that this protection is so secure that even they can't bypass it.