If someone were to loose their Mac, and we issue the lock command. We know that device would be locked down and inaccessible.
The question is if someone were to physically remove the SSD from the locked machine and installed it into another machine. Would the EFI still be applied? Would the OS load?
Wondering if any has come across this before. Is there a way to programatically force the user to log in using a FileVault recovery key if they removed the SSD and installed it into a new machine rather than just being prompted for the FileVault password first?
The idea that all an "attacker" would need to do is phish the local account password from the user prior to stealing the machine, remove the SSD, install it into a new machine and they can access all the data doesn't seem too secure to me.
Thoughts? Ideas?