Data Recovery Case File · Mac & Apple Systems · One Question Decides It
Whether a Reset Erased Content or a Key Depends Entirely on the Machine's Generation
This enquiry is relayed by someone acting on an employer's behalf, and it turns on a single unknown. A desktop machine that "crashed whilst attempting to update the operating system and has now been reset to factory settings", with all avenues exhausted through the manufacturer, and everything from before the wipe wanted back. The answer is either quite good or entirely final, and the deciding factor is not the reset but the machine.
| Media | Desktop computer reset to factory settings following a failed operating system update — storage type and encryption architecture determining recoverability; enquiry made on the owner's behalf |
| Reported situation | Desktop machine crashing during an operating system update · manufacturer support avenues exhausted · recovery environment reportedly unreachable · machine subsequently reset to factory settings · content from before the reset sought · enquiry submitted by a representative of the owner |
| Fault class | Factory reset performed with outcome determined by storage architecture — key destruction rendering content final on later designs; conventional reinstallation leaving content retained on earlier ones |
| Equipment used | Machine generation and storage architecture established before prospects were stated · authority to instruct confirmed with the owner directly · machine removed from use before any examination · storage imaged write-blocked where removable, or addressed in place where integrated · pre-reset structures recovered from residual copies where content was not key-protected |
The decode: the one question, and why the manufacturer could not help
What a reset does on an earlier machine: reinstalls. The system is written over the beginning of the drive and the volume marked empty, leaving prior content physically present beyond that region.
What it does on a later one: destroys a key. Where storage is encrypted by default, a reset discards the key rather than the data, and content becomes permanently uninterpretable in an instant.
Why that difference is absolute rather than a matter of degree: there is no partial outcome. Content without its key cannot be recovered by anyone, however intact the storage.
Why the generation must therefore be established first: everything follows from it. No assessment is meaningful until it is known which kind of reset occurred.
What can be said honestly before that: a straightforward statement of both outcomes. Presenting the good case as likely would be misleading, and presenting the bad one as certain would be wrong.
Why the manufacturer could not help, and this is not a criticism: a recovery environment repairs and reinstalls. It is designed to return a machine to service, not to retrieve content, and it has no facility for reading a volume it cannot mount.
Why exhausting those avenues is nonetheless informative: it establishes what was tried. Reinstallation and reset are the tools available there, and they have both been used.
Why the failed update is worth noting: it may have been the original fault. An interrupted update leaves system structures inconsistent, which is a recoverable condition that the reset then acted upon.
Why authority is confirmed directly rather than assumed: the enquiry is relayed. Instructions to read a machine's contents are taken from its owner, which is a matter of course rather than a doubt about anyone.
What must happen immediately either way: the machine out of use. If the favourable case applies, everything written since the reset is consuming what survived.
On the bench
Machine generation and storage architecture were established before prospects were stated — resets on earlier designs reinstalling over the start of the drive and leaving prior content present beyond that region, while later designs encrypt by default and discard the key, rendering content permanently uninterpretable regardless of storage condition. Manufacturer recovery environments repair and reinstall rather than retrieve. Authority to instruct was confirmed with the owner directly.
The outcome
Generation and architecture established before prospects were stated, authority confirmed with the owner, and the machine removed from use. Free assessment, one fixed written figure including VAT; where recovery is not possible, nothing is charged. The decode: one question decides this, and it is not about the reset. On earlier machines a reset reinstalls over the drive; on later ones it discards an encryption key — and those outcomes have nothing in common.
A machine reset after an update failed
Take it out of use immediately — if the recoverable case applies, everything written since is consuming what survived. Then establish the machine's generation before drawing any conclusion, because that decides everything: an earlier reset reinstalls over the start of the drive and leaves prior content beyond it, while a later one discards an encryption key and makes the content permanently uninterpretable. A manufacturer's recovery environment can't help either way — it repairs and reinstalls rather than retrieving.
Take it out of use — call Cambridge Data Recovery on 01223 655015; generation and architecture established before prospects are stated, authority confirmed with the owner, assessment free either way.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.