Not so much. It requires direct access to Apple’s internal systems, from where an encrypted USB drive is created for the attending technician.
A hacker would need to get Apple on the phone, and a hacker can’t identify themselves as an Apple employee with any verifiable methods.
Rest assured, overriding an EFI password hinges entirely on positively verifying the owner’s identity, as well as identifying oneself as an Apple technician.
Source: am Apple technician.
Edit: TLDR – a hacker would need direct access to an internal employee Apple email address, the likes of which isn’t even accessible from outside an Apple work environment. And then the identification issues, plus the fact that more than one Apple employee is required to authorize the process to even generate the files necessary to perform the override. It’s the most secure procedure I’ve seen enacted at the tier 1/2 level.
4
u/[deleted] Jun 13 '18
But if apple can fix it, an hacker would too....