Pixel Security
security.googleblog.com
security.googleblog.com
They have no Google provided support, if you drop the phone and break it your only option (if you didn't buy the third-party warranty upsell) is to take it to a repair shop. I called the ones near me, none had seen or touched the device before.
Don't spend $800 on a phone that you can't send back to the manufacturer to repair.
Edit: I originally said "they have no warranty" and people seem to have understood that as "they don't provide free repairs" -- what I'm trying to say is that this phone is supposedly a competitor to Apple, but if you break it you can't walk to the Apple Store and ask them how much it'd be for a repair. You can't send it in the mail to them either. You have to go to an authorized third-party repair shop. That does not sound like first-class flagship $800 product support to me.
I'm extremely disappointed. I thought with their whole advertising of "24 hour support" they identified customer support as a weakness of theirs, and are trying to remedy it. Nope.
BTW in your case, you can probably just buy a new screen: http://www.digitaltrends.com/mobile/google-ubreakifix-pixel/
Are you not in the US? Maybe it's different elsewhere, but my nexus 5x died a little while ago, and I only had the default warranty, not the extra protection, and it was insanely easy to get a replacement.
I filled out the form[1] (saying I had already tried the usual android-saving moves), got a call back in two minutes as promised by that form, the customer service person accepted I had already tried things and didn't ask me to do anything else, then I immediately got the email with the link to get a new phone shipped to me. Was probably less than 15 minutes of my time.
(you also seem to be talking about something else than the OP. If your phone died in two weeks that's definitely under the warranty, regardless of if you purchased extra protection).
[1] linked here: https://support.google.com/store/answer/6301527?hl=en
I was not asked to do any troubleshooting.
FWIW before it stopped working, the pixel was hands done the best phone I've ever used, in almost every category.
I'm very sorry you had that awful experience. I know it doesn't remedy your past experience, but please know myself and many other Googlers have been and still are putting a lot of work into the tools being used by the customer support reps around the globe to better help you.
Everyone on the team I'm a part of recognizes the perception you've eloquently provided, and very much care to scale with humans in the loop.
I remember once contacting Sun for info on software many years ago and received an email where they promised that someone would "reach out to me".
I didn't want to be reached out for - I just wanted some text answering my question.
So for now, I'm just patiently awaiting their response and hopefully they'll give me the green light to mail it in for a replacement or something.
https://www.accc.gov.au/consumers/consumer-rights-guarantees...
By the way: "Google and uBreakiFix offer walk-in repairs for Pixel and Pixel XL" http://www.androidauthority.com/google-ubreakifix-repairs-pi...
I'm not upset that they don't have an accidental damage warranty, I'm upset that I can't send it to them and pay them the $100/$200/$300 or whatever it is directly for _them_ to fix it, not some random dude who's never seen the Pixel before.
On the other hand, the "who's never seen the Pixel before" part? C'mon, the phone just came out—if an i-device breaks on the first day, you'd better believe that if you take it to an Apple Store someone's fixing it who has never seen that device before. That's the fundamental problem of new hardware designs (especially when coupled to bathtub curves); you can't blame Google for it. Give them a month and every repair shop around you will have fixed plenty of Pixels.
* A repair manual
* Parts
* Tools
* The ability to replace your device on-the-spot with a new one if they brick it
I went to my local Apple store on release day, showed them it wasn't working, and they swapped it out straight away, no questions asked.
Send your pixel to our authorized repair shop here. They will bill you.
If I may say so, a family member has one, and the phone itself is excellent. Much better speakers and included accessories compared to the Pixel line at around half the price.
The repairs tend to basically cost as much as it would to buy the same item refurbished regardless of the issue.
SSD died on your MacBook air selling for $500 on eBay? That will be a $450 repair sir.
Sure, they may have manuals and everything else at the Apple store, but there is very clearly a reason why companies like iCracked and iFixIt exist, and it isn't because Apple offers such a wonderful and affordable repair shop.
It would be great if Google offered a way to get the phone repaired through them, but using Apple as an example of how it should be is a bit insane to me.
I figured I could take it to Apple for a battery replacement. They said they would do it — for $900. They told me it involved replacing the entire bottom half of the computer as the battery was glued in.
So I called their support line and complained that the laptop was perfectly fine and it shouldn't cost that much to replace a battery. They ended up replacing it for free, as well as the screen (because they identified that the anti-reflective coating was starting to wear). So while the policy was ridiculous, the actual outcome was very positive.
WTF? This is nonsense.
Apple prices for battery repairs are clearly outlined on their web site[0]. This has always been what I (or relatives/friends/coworkers) paid for France[1] when I had to change a battery.
[0]: https://support.apple.com/mac-notebooks/repair/service/prici...
[1]: https://support.apple.com/fr-fr/mac-notebooks/repair/service...
They told me that those prices are the service pricing, but do not include parts. And because the entire lower-half of the laptop needed to be changed in the rMBP model, the total cost would come to about $900 AUD.
The actual item listed on the repair invoice is "Top Case Assembly with Battery" @ $562.73 and the "Hardware Repair Labor" charge is listed at $289 AUD.
Did you ever have friends or relatives change the battery in a retina MacBook Pro? Apple cannot remove the battery because it is glued into the lower case assembly. And so when I got my machine back from Apple the trackpad, keyboard, and lower aluminium chassis was brand new (however the bottom plate, logic board, and internals were the same).
When I complained in-person and through phone support I was told the same story specifically about the retina MBP model. They said that the standard charge for battery replacement in this model included the entire lower case assembly. I heard this from about four different support agents, even when it was escalated to the special support agent that was able to eventually authorise the free repair.
When I received my MacBook Pro back from battery service the keyboard, trackpad, and lower aluminium chassis were brand new. So they did change it all out just to replace the battery.
At least with Apple I can drive to a physical store, hand my laptop or phone over and know it will be repaired properly. And in many cases I've been either (a) upgraded to newer hardware or (b) just had the device swapped entirely.
1. Cracked screens are incredibly easy to fix, so the one example you can give that doesn't cost an arm and a leg is the one thing that arguably any random repair shop should be able to do.
2. Not everyone even lives near an apple store, so while you might benefit from driving in to a physical store, there is a large chunk of the population who won't (at least not without driving a few hours).
PA is a great example of this - the only stores in PA are basically around Philly and around Pittsburgh. Live anywhere else in the state and you are driving to a store out of town.
That isn't so bad if prices are reasonable, but when you get there and hear "$600 to replace the battery" the stores start to feel less useful.
I understand that there is value in the Apple store. I'm not trying to say that there isn't any, but I do believe the original comment overstates that value, especially when Google (or a third party they work with) offers a pretty reasonable replacement plan as an add-on to your purchase.
Or free if you paid $100 - $250 (depending on the class of device it covers) for AppleCare.
AppleCare is head and shoulders above other extended warranty plans in my experience. Others tend to be jokes or ripoffs or both.
Provided you can find spare parts, good luck finding spare parts for the Pixel. For Apple products it's usually a breeze.
The pixel offers a $99 replacement plan, plus an additional $99 every time you replace the phone, up to 2 times. I think it lasts for 2 years.
If the only thing holding you back on getting the phone is being able to get it repaired, the cost difference is $70 or $50 the first time you break your screen, and $40 or $0 the second time, and the plan covers more than just broken screens.
The biggest downside is that you have to front the $99.
But that requires foresight in buying the insurance and most people just don't have that. In my case, I have only ever broken one phone, so buying insurance with the idea that I break even at ~2 incidents would not be worth it for me. In the Pixel's case, I would like the option to pay full fees for fixing rather than only the option of previously having had foresight AND having to break my phone twice.
Not only did they not do it (they initially said no problem), they lied and told me I needed to replace the entire panel for $800 as it was a broken `spring` and could not be fixed.
I called bullshit and fixed it myself at home with a screw driver set.
$800 to tighten a screw?!
4+ year old iMac with dead video card. I took it to the local authorized Apple dealer, who wanted $50 to diagnose the problem.
Dealer called back and said Apple agreed to replace the video card for free and cover the $50 dealer diagnosis fee.
I had the same thing on an older MacBook Pro with dodgy graphics card. Took it in to an authorised dealer, who didn't charge me up front for diagnosis, to then get a call saying it had been replaced and no fee was due as covered by Apple under a previous recall. This was in the US.
I was burned by this and Motorola before as well here in the UK. The official repairers are just about as awful as you can get. Half the screen stopped working after a month. The official repairer cocked up the handset further and claimed water damage and sent me an invoice for £138 (handset price was £159 new) holding the handset to ransom. This was when Google/Motorola were the same company in theory.
A letter was sent back suggesting that they can insert the invoice in a body orifice of their choice and send it back now or it'd be small claims court. It arrived 5 days later by courier. Proximity sensor was dicky, so it went back again. That took a month.
Paying for an Apple product is almost worth it for the service. I prefer to go without either though.
I can't say I've ever done that with any product ever...
You could not get that phone second hand (or from any other reseller) and send it in to them for repair.
That's basically "insurance" included in the price of the phone, not a "pay for what you broke" repair center.
Source: I first heard about this program from my reseller-purchased HTC One m8.
Still, I feel like that's a silly reason to advise people never buy the phone. Especially when they do provide an "insurance" policy with a "blessed 3rd party".
It's not warranty or free repairs he is asking for isn't it? He is asking for paid support.
[1] https://support.google.com/chromecast/answer/7206638?hl=en
>I can’t send my $800 phone to the manufacturer and pay some extra money to get it repaired like I could if this was a Samsung or Apple device.
>Hey Google, if you want to pivot into a real brand: You need to provide real support. No other flagship phone tells people “well, good luck” if they have a common incident break the device.
I have two reasonably destructive young children, so it's a little extra piece of mind.
I'm sad that I'm out some money, and I definitely think I am at fault, but I don't think I'm being unreasonable.
https://www.reddit.com/r/Android/comments/5dif8j/psa_google_...
Looks like Google is reinstating accounts.
Why would they ask for identification then close it after he provides correct identification?
Well, yes, since Google isn't providing their part of the story.
I have no reason to think the OP of that thread is misleading, I believe from their perspective it is an accurate account. You don't have to go too far to read similar accounts from others who got suspended over Google Pay/Google Checkout fraud flags.
Unless Google comes out and says the OP missed out key information, I'm going to just assume OP is telling us everything they know from their perspective.
It doesn't sound like they got these changes into mainline. They link here to their source: https://android.googlesource.com/kernel/msm/+/android-msm-ma...
From that file:
/* TODO(mhalcrow): Just for proof-of-concept */
WHOOPS!And doesn't google have a terrible track record of releasing data to federal agencies?
So, aside from purchasing a phone that is built by data-mining, internet advertising giant, google can't even begin to make the claim that they value user security.
http://thehackernews.com/2016/11/google-pixel-phone-hacked.h...
Why is that a bad thing?
In my experience, a lot of closed source C projects ban goto outright, in (IMO) an overly dogmatic adherence to the idea that all goto use is spaghetti code and therefore bad.
Not that I think C should add these features, goto does these jobs okay, and there's enough stigma that it's unlikely to be used foolishly. But I think it's worth keeping in mind as we think about future languages.
In low level performance critical code where refactoring it to something more "traditional" would not only cause much more complexity, but would also be slower.
I assume these guys know a thing or two about programming, so who am I to question it?
https://plus.google.com/u/0/+DeesTroy/posts/R7V3knn3f1s
Or perhaps to this?
http://www.theregister.co.uk/2016/11/11/google_pixel_pwned_i...
Still waiting on Google to at least match, if not surpass, Apple's long-term support in regards to updates (which is about twice as much what Google offers right now, even though the Pixel has identical prices to the iPhones, at every level).
Unlike other phone manufacturers, Google does not promise potential customers that your data will be protected from Google, it's partners and from law enforcement and mass surveillance programmes.
Therein this product doesn't provide a stronger security posture that competitors - and furthermore it's threat model and security properties do not meet what are in my opinion minimal reasonable requirements.
Are you referring to Apple? Because they don't promise that either.
Apple of course backdoors their phones for government surveillance access. But they do motivate a threat model that includes government surveillance.
I know parsing my comment in this way may seem difficult, but I used the terminology I did on purpose.
There are no illusions that Apple achieved the security properties that it has motivated.
Google Pixel does not even pretend to address the security concerns of journalists, politically active citizens, IT professionals, or individuals contacting attorneys.
Nice job slipping a completely unfounded lie into your response.
Starting with iOS 10, you can actually just mount the root filesystem disk image from iOS restore images. You are able to reverse engineer and audit any application or daemon that the OS runs. You can use open source tools (Such as idevicerestore) to perform an OS restore on your device, and point it directly at the filesystem disk image that you just audited the binaries of. That way you can be sure of what is being flashed onto your device if you have any doubts that the OS you just audited is the one going onto your device. No "blackbox" at all in this process.
I am looking forward to hearing any form of evidence regarding your claim.
Definitely an issue, but seeing as it was patched in iOS (and thus discovered in the SecureTransport source code), it would most certainly not still be in the wild.
With regards to auditing: The machine code is available for review, you just need to invest some time into learning the ARM instruction set. Most users of HN have invested time into learning various programming languages and that is why the trope of "open source == more secure" is often repeated, but the truth is that ARM assembly is just another programming language and is almost never obfuscated to a point in which you would not be able to read through it and understand what is happening once you understand the instruction set.
That said, an iBoot-level backdoor may not be as useful these days, considering Data partition is still protected with passphrase (and 10-attempt limit being SEP-enforced now).
I suppose you could argue root filesydtem access would be a concern, yet you would still need multiple zero-days to get persistence, defeat CS, etc.
While the argument regarding auditing is valid (for 64-bit), we both are aware that certain parties have privately been able to decrypt those. I highly doubt they would not say something if they had discovered a backdoor in iBoot.
Oh my.
Yes Apple backdoors their phones for government surveillance access.
There's no sneaking here. I'm saying it very clearly as a central tenet of my comment.
-----------------------
Here's a list of things that Apple will provide from Apple's own Guide for Law Enforcement Access:
- Device Registration (name, address, email address, telephone number, iCloud Apple ID)
- Customer Service Records
- iTunes (name, physical address, email address, and telephone number, purchase/download transactions and connections, update/re-download connections, and iTunes Match connections, iTunes subscriber information and connection logs with IP addresses, specific content purchased or downloaded).
- Apple Retail Store Transactions (cash, credit/debit card, or gift card transactions, type of card, name of the purchaser, email address, date/time of the transaction, amount of the transaction, and store location, receipt number)
- Apple Online Store Purchases (name, shipping address, telephone number, email address, product purchased, purchase amount)
- iTunes Gift Cards (sixteen-digit alphanumeric code, nineteen-digit code, any purchases, name of the store, location, date, and time, user account
- iCloud (music, photos, documents, iCloud email, encryption keys, Subscriber Information, iCloud feature connections, connection logs with IP addresses, Mail Logs, records of incoming and outgoing communications such as time, date, sender email addresses, and recipient email addresses, Email Content, Other iCloud Content, Photo Stream, Docs, Contacts, Calendars, Bookmarks, iOS Device Backups, stored photos, documents, contacts, calendars, bookmarks and iOS device backups, photos and videos in the users’ camera roll, device settings, app data, iMessage, SMS, and MMS messages and voicemail)
- Find My iPhone (including connection logs)
- Other Available Device Information (MAC Address for Bluetooth, Ethernet, WiFi, or FireWire)
- Requests for Apple Retail Store Surveillance Videos
- Game Center (Connection logs with IP addresses, specific game(s) played)
- iOS Device Activation (including upgrades the software, IP addresses, ICCID numbers, and other device identifiers)
- Sign-on Logs (iTunes, iCloud, My Apple ID, and Apple Discussions, Connection logs with IP addresses, Sign-on transactional records)
- My Apple ID and iForgot Logs (password reset actions, Connection logs with IP addresses)
- FaceTime (logs when a FaceTime call invitation is initiated, content protected by 15 bits of entropy if secure enclave baked key is obtained from manufacturer)
And, from this thread on HN today (https://news.ycombinator.com/item?id=12977612): All call logs including contacts, timestamps, and durations including for third party applications on the phone like WhatsApp, Skype and Viber.
US law means that Apple must turn over data when demanded by authorities. These are access logs or files stored on Apple servers.
A backdoor would be granting access into your device so that authorities could access your non-icloud email, or data saved locally on device.
I'm baffled. I like to think of the quality of HN comments as much higher.
Apple had options to make this data unavailable by design to themselves and to law enforcement. They chose a design so that they could provide this information. The phone does it without the user's consent.
However, I understand that there are people who would rather redefine terminology to suit their cognitive dissonance.
In any case we can agree on the following:
-----------
Apple provides a near majority of your sensitive information to law enforcement by the design of the product, and you can not use the product in a meaningful way without that information becoming available to state surveillance and state law enforcement.
All the data supplied comes from Apple's records, not your phone. If your phone was destroyed one day, and law enforcement requested this information the next, Apple would have no issue supplying it. They're not going to simply "not keep" records of your iTunes transactions and account details, for example.
Your complaints regarding the inability to use their product in a meaningful manner without letting Apple collect this data have merit.
> Yes Apple backdoors their phones for government surveillance access.
That very specifically is referring to the phone itself. Nobody would be arguing if you had said:
"Apple hands over non-encrypted information (such as webmail and other data that cannot be encrypted at a higher level) from iCloud and iTunes Store servers, in response to a valid legal demand"
To be fair, the amount of leverage the US exerts on businesses for military purposes is astounding. This should be factored into the understanding.
Apple is just putting on a show with their tough security rhetoric, they can't resist the US government if they really want some data.
From a security standpoint, Apple wouldn't have anything to turn over, because they never had it to begin with. Google et al, hoover up everything the least bit interesting.
Apple VP Lisa Jackson:
>Please know that Apple will continue its work with law enforcement. We share law enforcement’s concerns about the threat to citizens and we work closely with authorities to comply with legal requests for data that have helped solve complex crimes. Thousands of times every month, we give governments information about Apple customers and devices, in response to warrants and other forms of legal process. We have a team that responds to those requests 24 hours a day. Strong encryption does not eliminate Apple’s ability to give law enforcement meta-data or any of a number of other very useful categories of data.
Facebook, Google, Apple, Twitter, etc. all pretty much fall under the "telecom" label these days in what they do, so it's not surprising in the least.
Just expanding on that - not dipping my toe into any other part of this debate!
For an understanding of what data Apple gives surveillance operations access to, the following list is enumerated in an older Law Enforcement Access document: https://news.ycombinator.com/item?id=12983081
It's also important to understand that the purpose for this surveillance (this following section being informed by the Snowden Disclosures) is not merely for investigative work or for tracking down terrorists. Intelligence work of this kind is used in HUMINT operations (mass propaganda), for industrial espionage, for diplomatic espionage and for signals collections (intelligence used to break into networks).
It is not clear whether Apple shares these concerns with the US government, or whether it shares lesser concerns that show up at a much lower frequency.
However, it Apple has capitulated to a combination of carrots and sticks. Today, it enables surveillance of its customers.
Can the users actually get the keys to their own stuff?
However, we reinstate the account after a few days. [1]
[1] http://www.slashgear.com/pixel-phone-flipping-scheme-googles...
#2 spot on HN, 2 comments, submitted 28 minutes ago.
Is this normal? Never seen that happen on HN before. Just curious
My only answer is that what's displayed doesn't necessarily match what's used for the ranking--that there may be some sort of lag. But yes, it could be possible too that somehow one can bump up their posts through other means.
The original commenter even mentioned this as an aside. If another reader didn't like it, they could've collapsed it.
There are a lot of pretty basic things (like ad blocking or monitoring battery usage) that require root, which severely impacts the security of the device.
EDIT: Okay, I stand corrected on ad blocking. Access to detailed battery stats however is locked behind the BATTERY_STATS permission which isn't accessible to anything except for system apps. That aside, there are other basic things like backup that also require root.
Apps can use the VPN API to do ad blocking without root, and there are tons of ways to do more battery monitoring without root, like the built in battery monitoring...
Sorry, I mean more than the built in monitor, which is largely useless.
There is no API through which I can enumerate wakelocks, CPU usage, GPS usage, mobile radio traffic and activity, wifi radio traffic and activity or screen on/off time without system level permissions (i.e. built into the ROM). Therefore, there's no way for these things to be exposed to me as a user.
There used to be a permission called BATTERY_STATS but it was removed years ago and Google has been utterly unreceptive to reinstating it: https://code.google.com/p/android/issues/detail?id=61975
And of course there's a bunch of apps on my device (Pixel) that have that permission such as Qualcomm's CNE app, Play Services (com.android.vending), another Qualcomm package (com.qualcomm.qti.auth.secureextauthservice) and a bunch of other Qualcomm packages.
If you are interested in a communications device that can be used for any of these things, Pixel's security model will not cover you and you will need to look for an alternative product.
For those curious here is the other comment in question: https://news.ycombinator.com/item?id=12982502