Apple pays out millions to student after repair techs shared her personal images
9to5mac.com
9to5mac.com
Who the on earth gives their passwords, also all laptops should be encrypted by default. I find it absurd to give away the keys to your bank, search history, personal notes, images, whatever - it's beyond private and personal besides being economically dangerous and very bad job security wise for most jobs.
Not blaming regular people though, but it's weird that people are so lax about giving the keys to absolutely everything.
I sympathise with the young woman who was the victim here, but apart from "send your device unlocked" Apple do also recommend wiping the device before sending it.
When PINs started to become more common here, I had supermarket and continence store workers asking me to tell them the pin to my card, when paying for stuff. It didn't help that they'd ask me in Thai, I'd not understand, my wife would translate, and I'd immediately respond - in English - to the staff "Are you fucking crazy?".
Thankfully that idea didn't last long. I guess enough other people had similar reactions in their native tongue that they realised that's a really stupid way to do business.
Edit: This was during the times when even a layman could do it because drives were in a slot secured by a single screw. These days it might be more complex.
Apologies for the confusion. I should have said "Macbook" in my original comment.
And now my 2019 work MacBook requires taking out non-standard pentalobe screws, then using a suction cup to pry the lid open slightly in order to cram a wedge tool in-between to pop it open and then you need to slide it out in order to actually get it out.
It really makes me sad Apple gave up this environment-friendly policy and started to aggressively glue everything preventing upgrades.
The best way to prevent such practices is not to buy their products.
And as someone who has recently had a MacBook Pro repaired, they swapped virtually everything. Keyboard, Mboard, Touch Bar, etc. the only original thing now is the screen. I would have had to restore from backup anyway. As a plus, my SSD is now brand new so any wear on it after 2.9 years of service is gone :)
Yes, it was fine. If you are in a hurry you can even boot from a Time Machine backup.
How is a customer suppose to backup and wipe their devices?
> Apple customers would have a hard time
I took it to be implicit to the wish that hard drives be owner-serviceable.
Sadly this is not possible with a modern MacBook. When I have had to send a MacBook to Apple (or a service partner) for repair I was instructed to wipe the machine (along with ensuring I log out of iCloud to disable Activation Lock and disable Find My). While it is good to ensure my personal data is not compromised it isn't user friendly at all to have to wipe my whole machine for a battery replacement :(
For the ThinkPad, it's a 5 minute task which many people can do themselves -- certainly anyone who works in IT.
We've had less strict restrictions than France, but a couple of my colleagues replaced the batteries on their HP laptops. I sent videos, and they saw how easy it was -- less painful than a Covid test.
Which is still a step backwards. On my ThinkPad I can remove the battery in seconds without looking. Mainly because sometimes I had to disconnect it to reset it completely. If that would take 5 minutes or any kind of tool that's already hard to justify imho. What do we gain from integrated batteries? Nothing that makes up for easy replacement or, in the case of ThinkPads, the option to upgrade the capacity before the purchase.
as to "What do we gain", they claim they can make them thinner and lighter, but the T14 seems to be the same Thinkness and a T450/T460 so.......
Battery replacement is a once-in-a-few-years operation and it's OK for it to take 5 minutes.
Personally, having backup batteries is a requirement for the places I work.
Laptop being thinner is a trade off you're willing to make, I am not.
Charging a battery with another battery is extremely inefficient.
Lugging around laptop batteries is exactly the same thing as lugging around power banks, except laptop batteries don't require a dongle and a cable to tether you to a table.
Laptop batteries mean you laptop can continue to in fact work from your lap.
A powerbank for the same price will probably have a higher capacity, and be able to charge any USB-C device.
All this is not a reason for integrated batteries, but Powerbanks using a universal interface are clearly more practical.
The newest T14 is more expensive than my Thinkpad from the same series was - as extra thin, hard to repair notebooks usually are. It is a bit slimmer, but in the display part, not the base with the battery. It is a bit lighter, I'm guessing because of a plastic case? I'm not sure, but the case material is noticeably absent from marketing material and the datasheet, while in the case of mine both mentioned the magnesium case and internal metal cage.
Of course that's just a surface-level comparison. But after my really bad time with the Surface Pro I am absolutely not going to buy a laptop with integrated battery as long as I can avoid it. It's just not worth the pain if something goes wrong.
Unfortunately it's becoming more and more difficult to find removable battery equipped laptops, what current model lines do have that still?
Weight difference is minimal, size difference is minimal. Yes, there is a difference, but I don't notice it really. And I'm someone who actually lugs the laptop around, on buses and trains and while riding a bike. Most people don't even really carry their laptops, maybe from car to office and that's it.
As a person who actually carries their laptop around, I appreciate the swappable battery. Train rides are much less anxious, no need to find a seat with a plug nearby, because I know I have an extra battery.
The T14 is definitely less portable. There's less ports as well, which is quite annoying. The only downside of the T470 is the screen - I like to work outside and a higher brightness screen is crucial. If I could have the T470 with a better screen and AMD CPU, I wouldn't bother buying a new Thinkpad.
I don't know why they call ultraportables ultraportables. Are they marketed for people who sometimes lift their laptop off the table and who are bothered by the "extra weight"?
"Keep Your Drive" is now a non-free (but not that expensive) "service upgrade". Disks are still removable on most models and it's not hard, but you still have to open the bottom of the laptop. (For ThinkPads, through ultra thin models like the X1 or "unusual" models like the ThinkPad Yoga might be more problematic.)
EDIT: Through it also depends on you service/guarantee contract. If you normally have a service contract where a technician will come to you but for some reasons that currently don't work you probably can keep your drive anyway etc. Also KYD extends to some other cases.
It's almost more of a donation in my experience. Don't pay it, remove the disk, no consequence. It's also a good idea to put the OEM ram back in the machine if youve upgraded. One of the few things they may balk at and return it unfixed.
I am not sure how it easy to damage something when removing a NVMe drive, it is trivial to remove the drive and should not even come close to damaging anything
YES. THIS. I am in vehement disagreement with Apple soldering SSDs to motherboards for partially this reason (among others, including making data recovery much harder, and lack of user upgradeability).
Apple fanboys all over the world will hate on me every single time saying "What if I told you that Apple just makes the best PC". Fuck that. I want a removeable SSD so repair technicians don't need the SSD to repair other parts of the PC.
If it's a software issue then maybe they do legitimately need a password but i would never hand one over without very careful consideration. And, strange hands on the keyboard of my laptop or phone would be watched very very closely at all times.
I good app would be one that disables the network stack, bluetooth, and cell modem with a separate secure pin.
In my case, many years ago, I got asked by a phone repair shop to backup the phone and wipe it before handing it over unlocked. My understanding was, they had no good way of doing proper diagnosis and after-repair testing without full access to the system.
Phones however...
In principle, it should be possible to have a diagnostic mode the same way recovery is implemented. But there are no device I know of that have this.
https://www.ifixit.com/News/33593/heres-the-secret-repair-to...
Not entirely https://www.macrumors.com/2018/09/17/iphone-calibration-proc...
At the Apple Store, they also asked for the password, but when I said no way, the support person was just "ok, no problem".
I went through a battery replacement (out of warranty, but still covered by Apple), and I was never asked for the password. But maybe they didn't even bother to run tests, since it was literally pushing the keyboard up ever so slightly, the touch pad wouldn't click anymore (haptic feedback very weak) and the bottom plate was bulging out. It was pretty obvious what is up. The nice thing tho, I ended up with a new battery, new keyboard, new touchpad and new bottom plate. I guess every (most?) cloud has a silver lining? :)
Can we take a moment to realize how crazy this is? I'm glad they didn't fight you, but the fact that they didn't means that they know in an instant that _they never needed the password in the first place to do what you asked them to_. This means that them asking for the password is them asking you for the private key to your entire personal life for no other reason than "most people will give it to them".
Which might also be a perfectly reasonable tradeoff, but there's nothing inherently nefarious about it. And people can make different choices depending on the amount of private information on their laptop.
Most want all their problems fixed with as little action required on their part as possible, with as much certainty as possible, and do not care about security in the least.
People are hard to reach once they are out of your sight, and get very unpleasant when things take a while....even when they take a while largely because they didn't get back to you in a timely manner (because you turn out to actually need their password to troubleshoot their configuration).
"Wipe the device and start fresh" is understandably not a valid solution to most users (especially as anything other than last-resort), even though it'll rule out a large portion of potential software problems.
---------
To note on some other elements I see in this thread:
- Hardware diagnostics exist in some form on most devices. They do not catch every problem that exists, and are often especially bad with more intermittent issues. If the complaint is that Facetime drops out after 10 minutes, the most certain you can be that the issue is resolved is by running those diagnostics AND booting to their actual user account and having Facetime work for 15 minutes. No one cares that "it passed the Camera diagnostic" when they've still got a problem when they get home with their "fixed" device. Many people actively want you to be signed into their account and do exactly what they did to confirm the issue no longer happens.
- IIRC you can't actually boot a modern (T2) Mac to an external drive without an Admin password being entered at least once to change the Startup Security Utility settings.
- Whether being run as a business or as internal support in an organization (more so a college or the like with personally owned devices), time matters. Getting credentials from everyone who's willing regardless of if they turn out to be necessary is absolutely terrible security practice, but great for turning around repairs more quickly and with fewer repeats of devices coming back because the issue isn't fixed.
--------
tl;dr - Sensible security practices are at odds with everything else the average person wants from their computer repairs.
ADDED: And, indeed for a sufficient threat model, the correct answer if a laptop or phone breaks is to throw it out and get a new one. It would be rather paranoid, but it would be the safest thing.
Personally, I have backups usually so my general attitude would be no password, fine to wipe the device.
When you go to the doctor and they prescribe you pills, most people don't question it and just take them. And that leads to a lot of people taking antibiotics that they don't need. Or when you move and need to sign up for internet, phone service, power, water, electricity, gas, etc.... almost all of them will ask for your social security number. Even I don't know when it's mandatory and when it's optional, so usually I ask them first, but sometimes I don't.
The last time I witnessed this was some malware that infected an ex-roommate's laptop. The malware pretended to be an anti-virus and said she had a virus on her computer that it would fix. But first she needed to pay for the software - by putting in her credit card info & social security number. She complied because the files on her laptop were very sensitive and she didn't want lose them, and she had no idea that there was no reason to ask for a social to pay for this software.
We could probably do more as a community to educate people on keeping sensitive information secure. Part of it involves media outreach, as most people seem to get their news from the TV or Facebook.
I'm just glad they have an excellent example here of how it's fundamentally BS
Sure, you can send in a wiped device or a device without hard drive - and if you can do so yourself, this is probably fine. But for the "average" user it's quite likely a better experience, assuming you can trust the repair shop - but then again, they have full access to your hardware plus the knowledge and time to permanently bug your device. If you really don't trust them, you probably should not give them your device at all.
I can see the issue here and I'd probably err on the side of privacy given the choice, but the other side has a point.
Full disk encryption will protect your data.
Sure, it's a bit more sophisticated than Ctrl+C/Ctrl+V. But if you're running a computer repair shop, it is quite likely that you have a good amount of technical knowledge. If someone has hardware access, you can usually see your device as compromised - especially if they have a lot of time and are expected to open up the device.
That's exactly what I said in my first comment:
>> If you really don't trust them, you probably should not give them your device at all.
> And the attacks you describe are not just "a bit more sophisticated than Ctrl+C/Ctrl+V", they're most likely far beyond the abilities of most repair technicians.
The RAM one, yes. ROM chip swaps, on the other hand, are rather common. You will need to be able to solder quite well, but given the current state of macs, this is basically a given for anyone doing repairs on them. You'd of course need to get a malicious ROM chip, which might not be so easy, but probably doable - the technician only needs to be able to swap it, not to manufacture one.
And if you can't get your hands on one - your can order a keylogger right now, for just a few bucks! [0] This was just the first result; if you invest a bit more time, you can surely find a smaller one or more fitting one. The keyboard is probably connected with USB [1], so no trouble there. As a bonus, you get all the passwords of accounts that were not saved at the time.
Sure, simply unlocking is a bit easier. But it's not like this stuff is beyond anyone who is able to debug and solder on a Mac.
[0] https://de.aliexpress.com/item/1005001988834597.html?
[1] It's in my laptops; I don't know the specifics for macs, but I doubt is something more sophisticated than a strange plug.
"Trust not to source and install malicious hardware in order to potentially steal unknown to them data" is a magnitude apart from "Trust not to go snooping around through unprotected photo albums."
Do you leave all your valuables in the car when you drop it off at the shop? Or do you take them out first?
So, in keeping with my points above, I would probably move the really valuable stuff out, but for some customers taking everything out will prevent the technician from removing the issue (and they will probably be blamed for it) and if I feel the need to completely get everything saved out of the car beforehand, I would not trust that shop with my car, either.
I doubt anyone would leave an album with their nude pictures in the car hoping that the mechanic wouldn't do anything with it. Like...posting it all over the block where the customer lives.
Another possibility -- maybe the computer is so borked that you can't even log on to remove your important documents. This seems more like calling somebody because your key broke in the lock... which... I guess most people would stick around? It is a little bit of a mismatch, because it is a quick fix and it isn't like you can go anywhere anyway.
It should be standard procedure in the repair world to hand the hard drive to the user to take home and keep only the PC for servicing.
Also when wiping SSDs get something like Parted Magic (since at least 2018 likely earlier) that can properly erase SSDs. DBAN is NOT appropriate for SSDs in any way - extra wear from the writes, and wear leveling means you have zero idea where they're actually going.
Them: "what's your password"
Me: "I'm not giving that to you"
Them: "We'll have to wipe your phone then"
Me: "Fine by me"
Me: pickup phone next day, screen fixed all data still there
Lots of people try to scam repair shops bringing broken phones in.
On top of that repairs can often break fingerprint scanner connections and depending on the screen type its good to check camera functionality after screen replacement.
They could have the user unlock the phone in front of them without revealing the code to confirm this.
It’s all a balance of convenience vs privacy. Best solution is to wipe the device before repair, which is what I have done every time but it’s a hassle even when I have a backup to restore.
I refused and they eventually relented while still providing the warranty but it ended up delaying the repair by 5 days (for a 2h repair).
I think these are concepts that before would have seemed liked sci-fi, but after 2020, I think most regular people seem to have an intuitive appreciation for how damaging this can be. It's a shame that it's taken such a tragic schism to allow, but here we are and it's better late than never.
Another example would be people probably have a better intuitive understanding for motivations behind decentralized architecture, after seeing people being removed from certain platforms. Note: I'm not saying I'm for or against this in any way, but I am saying that the technological architecture is sort of the lay of the land, in a way that I think people understand better than they used to.
And no, I would never in a million years give my password to a repair technician in the past either. Hopefully others now are starting to get a sense for why.
You can't start with "It just works" and then add "As long as you spend hours backing up and restoring your data before you can send it in for repairs, just - you know - in case."
Maybe the millions that were paid out will make Apple think about a more user-oriented solution.
It's on the government have strong regulations that separate the sewage from the drinking water; strong regulations about who can connect what to the electrical power system; etc etc; require doctors to not pick their noses immediately before they perform surgery (gloves, masks, washing hands etc); encourage people to wash their hands after they poop.............
And inform people of good security practices, through public policy and school education.
I can't really see another way of educating the whole population on something they're otherwise fairly disinterested in.
I told them in no uncertain terms they cannot have my password, full disk encryption was enabled, and then pointed out if they can get the machine to the password prompt I'll be satisfied it's repaired.
I'm convinced these people are either intentionally being nefarious, or they were dropped on their fucking heads at birth.
My daughter's MacBook Pro, with lovely soldered down solid state memory died, and had to go in for repair. There was simply no way to wipe it, and no physical drive to pull.
Same thing with most phones. Soldered storage, glued shut case. If it dies under warranty, what do you do? You have to trust the repair chain, or just chuck it in the garbage.
He actually shares his findings with us here: https://www.youtube.com/watch?v=jf9I04Oa-hU
"Nothing is more powerful than an idea whose time has come."
He is probably most famous for his "Dumb Starbucks" bit, he talked to a lawyer about it and it's pretty hilarious:
https://www.youtube.com/watch?v=Y4KrdjAPohc
Since this is HN, here he is hiring a Bill Gates impersonator to help a souvenir shop in Hollywood:
https://www.youtube.com/watch?v=SBzW1xUjwew#t=7m10s
Also HN specific, convincing taxi drivers to infiltrate uber and purposely get bad reviews:
https://www.youtube.com/watch?v=N9gbdv5cXKg
at 4 minutes shows the rides they give.
Or a teacher saying "don't worry, I always wear a condom while teaching" (https://xkcd.com/463/).
If you have to take their word for it, then you may as well hire anybody and take their word for it. But also consider this: a creepy incel predator can lie and claim to be asexual, but will find it much harder to convincingly lie about being in a healthy relationship. They probably wouldn't normally do that, but given the right incentives (being trusted with other people's computers) they very well might. I don't and wouldn't distrust asexuals any more than anybody else, but neither would I trust them any more than anybody else. It just doesn't make sense.
Apologies, this line was straight out of The Simpsons and I thought you were in on the joke XD
Historically eunuchs had the reputation of playing the political game of power and influence with the best of them.
This is a gross understatement. Before being a consultant, Nathan also had a phenomenal career on CBC's On Your Side segment, it was CBC Marketplace before Marketplace. Why Nathan hasn't been awarded the Order of Canada for his hard work on behalf of the every day Canadian is beyond me.
My father was an accountant for many years and he always said if you found evidence of fraud you shouldn't be congratulatory because what you found is maybe 10% of what is actually there if you found it by chance.
It was a good gig because I could get all my homework done while working, and state law said my pay needed to be equal to full time employees.
My boss took his job very serious. He got the state to send us to security seminars.
This was the late 80's and what suprised me the most is whom steals, or commits financial fraud.
At least back then most loss in retail was committed by management. The higher up the tree, the more they stole be it cash, or merchandise. The employees, and customers stole, but the big thefts were usually committed by long term trusted management types.
The instructor said, employees/owners usually don't question management, and they have more opportunities alone, with no one watching. He also said owners were notorious for stealing their stuff, and writing it off, or claiming it as a loss through their insurance company.
He said, this is a dirty secret, that most organizations don't want leaked. It's much easier to blame the homeless, or gangs on theft.
I imagine that has changed with the proliferation of cameras everywhere, but when I gear about large scale theft in a corporation, I automatically look at those in command of the employeees.
My local Goodwill had gone through three store managers in a row for embezzlement. This was years ago though. Goodwill never prosecutes employees because they don't want to tarnish their image.
The higher you are in management, the more you have of all of those traits. Theft and fraud are so pervasive and most managers get away with it for years. Even if they are caught, at worst, they are merely fired.
The more Machiavellian-types rope in low-level employees. So while it might seem like a "gang" of 20-somethings at an electronics store made off with a shipment. The reality is, an upper-level manager provided the cover for them to do so, and knew how to leave just enough evidence that it was an inside job, but not enough for the police to bother. For example, the badge used to access the storage area might belong to a little old lady who is honest to a fault and would be readily identified by security cameras. And if anyone questions why the store greeter has such privileged access, then it was just an honest mistake.
Well there's a fun fact for any management type who's interested in a new job and some on-the-side income.
In the occasion, they didn't upload it anywhere, but she discovered because in the moment she was picking up her device back somehow (don't know the details) she saw one of her half-naked pictures in the technician computer.
I feel like everyone thinks they are entitled to being able to google something as evidence of its occurrence and don’t realize that the absence of evidence isn't the evidence of absence.
https://www.cnbc.com/2017/08/30/warren-buffett-on-wells-farg...
Keep in mind that in iOS root is rarely available, so even when servicing devices they're manipulating the OS via a restricted service interface that can only perform certain actions (e.g. wipe, re-flash, test different components, etc).
I cannot access the original article, but I am hoping criminal charges were also utilized as this is unlawful in many states (and frankly should be national).
Absolutely.
Ideally, they should not be in a situation where they can access any personal file without the owner being present.
The recording of every app opening, every site, every click being sent to organizations is lamented normally, and then desired if put into the right narrative. This is part of the reason we got where we are.
The only way to help is to make it clear that no password shall ever be given to anyone.
iOS has this in the form of apps that require Face ID to access them. Some fall back to your PIN if Face ID doesn't work but others do not, presumably a choice on the app developers behalf.
This exists. Anyone who is security conscious should store all of their sensitive files and PII in an encrypted vault that only they hold they keys to. Realistically, most people don't have the vigilance to do this, and it's pretty hard to do it perfectly. But I highly recommend to everyone at least to install something like Cryptomator to secure their most private documents and information, so that no one else has access even if they gain access to your computer or cloud storage.
One way of using the above would be to allow "logout" of the main user and login of an e.g. repair user, on logout the decryption key would be erased from memory, and this way the repair user has no access to my_butt.jpg . Actually Android already has the concept of multiple users, and each user has their own data storage, so the can open their own Facebook or Tinder and have the phone be loading their personal profile. Not sure about things stored on disk, though, and AFAIK if a user can be root then s/he can read all the files on the mounted encrypted disk.
So, the repair user would not have access to my_butt.jpg, but maybe they need access to an installed app? I guess 1 solution would be to have apps installed on a separate partition to data. Android has a system partition (I'm not familiar with iOS), so if the repair user just needs internal apps, that should be accessible from the system partition.
Full disk encryption is basically useless if the device is turned on/logged in.
I believe there was another case where the FBI was getting Best Buy’s Geek Squad repair centers to report CP.
I communicated this to Apple and while Apple apologized profusely to me, and even paid for the new battery and repair (I didn't ask for it, it was out of warranty for 5 years), but I still never trusted third-party repairers again... that put off buying new Apple stuff until I became able to move to a place with an Apple Store.
I'm happy to say however that I never had this problem going to the Apple Store in Berlin, but not everyone lives in a big city with one of those.
I visited the store in Augsburg once (although... is that an official dealership?) and they wanted to keep my work MBP for two weeks while repairing it.
As it was a new one (butterfly keyboard broken) you could not remove the HDD/SSD, I think. Took it back with me again, keyboard stayed unrepaired for as long as I worked with that company.
I just got a new M1 Air and while I have no idea how bad it is, I still keep two accounts (one empty for repair, one encrypted and backed up for me) just in case, although it seems Apple itself doesn't ask the password... since I don't think I can't remove the SSD myself :/
This sounds highly illegal. Also, why would Apple care? I can see how repair shops could want that, but I don’t get the thought process that would lead to this becoming Apple’s policy. I would not trust these people anymore either.
I'd call that a theft.
I mean, that sounds great in principle, except that I do remmeber reading about a case where they reported some older dude for having CP on his laptop, and it took him being arrested and fired from his job and obiously smeared in every newspaper possible, before prosecutor finally looked at the pictures and figured that yes, indeed, the "CP" in question was just pictures of his grandchildren in a pool with other family around.
But if your phone's broken and you know you don't have complete backups, I can understand being hesitant to hit the remote wipe button.
- The victim isn't responsible for the crime committed against them, as shown by this verdict.
- It is common because it is under-prosecuted. Hopefully we can see changes there.
The victim isn't responsible, but often the damage really is irreparable, and you don't even know who is the criminal (your private photos are online. Now what?), so it's a good idea to make the crime less likely to happen. As always, it's an effort-benefit tradeoff.
Definitely true, this is something that companies responsible for handling private data need to be more vigilant at. Whether that be finding a means to restrict access to that data (which Apple should be doing), training and supervision, restricted access to internet, or whatever, there's definitely more preventative measures that should be taken to ensure that this doesn't happen.
> The victim isn't responsible for the crime committed against them, as shown by this verdict.
No one is claiming that a victim is responsible for the crime committed against them, just that there are strategies to mitigate risk. You should prepare yourself for how things are, not how they should be.
> It is common because it is under-prosecuted. Hopefully we can see changes there.
It's hard to say how common it is, but ultimately it's a crime of opportunity. Maybe they need to stick the workers in a faraday cage so they can't connect the phones to the cell network or wifi.
Apple should implement a "send for service" option that configures the device so that service can be done without exposing the customer's information.
All Apple customers for iPhones have an Apple ID. When the phone is in service mode, all the data is backed up to iCloud (irrespective of whether the customer has paid for it) and the phone wiped. The fact that an iPhone doesn't include at least as much iCloud storage as it has local storage for backup is ridiculous.
After repair, the data is loaded back into the device before being returned to the customer.
except that doesn't solve the problem if your phone is broken and you can't enable that option.
Oh wait.
99% of the people just give the phone password to the tech. If I was a foreign intelligence service, I'd set up attractive repair shops around army bases and government offices (quick turn around, competent service, reasonable prices) and just mirror every phone that comes through. Most of it will be useless, but I'm sure that one can occasionally find some gold (in the form of documents or compromising material).
1) I would be surprised if that isn't already happening.
2) NOTHING is useless in intelligence work like that. It doesn't have to be directly and immediately useful, but you can learn an enormous amount through so called patterns or life analysis.
3) Information leakage via devices like this is an enormous problem. C.f., leaking the location of military bases through Strava logging or nuclear weapons storage information via flash card study apps
There could be a special mode accessible which allows testing of standard use cases.
Naturally I told them to wait a minute to erase my phone, but the technician told me that I shouldn't bother because the phones are kept in a safe anyways. Naturally I have still politely asked them to wait until I erase the phone, but this might not be everybody's reflex.
Edit: clarification, this was in an official Apple Store
Hmm, care to elaborate? I found the process quite easy, and done it multiple times. One thing that comes to mind is that if you don't have the iCloud backup option on for any reason, and you don't have a mac. Then you need to go through Windows iTunes which is really subpar. (no idea what to do on linux except a VM)
I don't really complain about the need to reset the phone, I'd like them to be more consistent with the messaging thouhg.
On the other hand, when I went to repair the keyboard for my MacBook Pro, they did ask for my password. I refused, and they just said they would have to wipe the hard drive and do a reset.
I guess it really depends on how responsible the individual "Apple Genius" is.
My threat model is low risk enough that I trust the full-disk encryption of my phone. So it makes sense for me to send my phone in with all of the data to avoid the reinstall.
Sure let me just give access to all my banking apps, photos, browser sessions etc...
I ended up creating a guest account for them but i was surprised they didn't have a policy not to access private user data or ask for passwords.
This another example why nudes and so forth should never make it onto a digital device. If that's your kink, then Polaroid cameras and camcorders exist.
That sounds a bit like the Onion sketch "Google allows you to opt-out of tracking by moving to remote mountain village" [1].
This case proves that the criminal justice system works to protect your personal images, we just need a better way to be notified when it happens (the kind of action you would expect Apple to take if they cared, instead of "we continued to strengthen our vendor protocols")
The only reason they got caught is because they uploaded the pictures/videos to her Facebook. If they had sent them to a porn site instead they would have gotten away with it. The grandparent is largely correct, if sexually explicit photos/videos of you make it onto a digital device controlling their distribution is difficult at best.
Why the does tech get a low bar?
Apple does tout absolute privacy:
https://appleinsider.com/articles/19/07/04/apples-iphone-pri...
This might be the only surefire way now, but it's not how it should be. How it should be is that a HIIPA-like wrath of god may descend on you if it turns out you mishandle someone's data like this.
Can be charged as a felony and can land you on the sex offender registry.
This is true, but focusing on nudes is somewhat missing the real point (and could be interpreted as victim blaming): this story is another example why your email and bank information should never make it on to a digital device. If pictures aren’t safe, then no information is safe. We all have chosen to put information on our devices that is not safe to publish.
Just to be clear: definitely not my intention. The victim is not in any way at fault here, this story is yet another warning to the rest of us.
> then no information is safe
This is definitely true. When I was still on Facebook, I intentionally changed my profile to public (because it ultimately is), and only shared information I was comfortable with the world knowing. Now that you've made this point, off the top of my head, I have realized that my digital footprint has grown more innocuous (apart from taxes and BS like that).
Assuming that focusing on nudes is victim blaming: how is focusing on email less problematic than that?
Even Apple themselves shouldn't be able to access your stuff.
Not victim shaming: according to the article this is what Apple tells you to do.
* cough cellbrite.
> iCloud secures your information by encrypting it when it's in transit, storing it in iCloud in an encrypted format, and using secure tokens for authentication. For certain sensitive information, Apple uses end-to-end encryption. This means that only you can access your information, and only on devices where you’re signed into iCloud. No one else, not even Apple, can access end-to-end encrypted information.
> End-to-end encryption requires that you have two-factor authentication turned on for your Apple ID. Keeping your software up-to-date and using two-factor authentication are the most important things that you can do to maintain the security of your devices and data.
Then it lists what is end-to-end encrypted when the criteria is met, mail, photos, messages are not listed.
It definitely isn't an argument for that. It's an argument for cleaning your device before handing it to anybody together with the password. That is the only situation when you're at risk.
I really resonate with his opening point; that somehow there's this belief that the "authorised man can't be a creep". This same logic I see paraded about across a number of other sectors to discredit small businesses and institutions.
Does this mean that she was a minor at the time, and if so was the sharing of these images as similar crime to distributing child pornography?
I'm more irritated that a Apple repair shop asked for login information then that a repair person with login information abused them (which sadly isn't surprising).
It amazes me that workplace conditions causing loss of life can be settled for much, much less (as low as $75k paid to the family).
Awards for loss of life are actually codified in case law as being vastly smaller awards than the award for loss of limbs, senses, etc.
It is somewhat logical since the primary injured (the dead) can't be made whole. Contrast this to someone injured but not dead - they will have to live with the injury for the rest of their life. Case in point - this girl.
This is why disability policies are more expensive for higher income individuals. Presumably, the injured and his/her family depends on that income to live, and the income loss must be made whole.
I’m conflicted in taking this side, but if it’s millions — with an s — given just to her, then she’s basically set for life. Never has to work again to maintain a decent middle-class life, because her FB friends saw her nudes. That seems wildly disproportionate — most everyone I know would gladly take that trade.
If it’s a class action suit, or is constructed such that not all that money goes to this one victim, that’s a different thing. The part that disturbs me is whenever being a victim can become similar to winning the lottery.
This feels a bit like the McDonald’s coffee lawsuit. On the surface it’s easy for some to take that deal (nudes for millions) but consider this: 1) she might have been Facebook friends with family or family friends. 2) this could wreck someone in high school and cause issues with dating, friends, etc. taken the wrong way it could kill your social life and cause depression 3) people jump to assuming she’s conventionally attractive. She might be very shy about her body and was taking those for herself. People might have grabbed them and made fun of her.. 4) there was no guarantee of a payout and it took five years legal distraction during prime high school and college age for a resolution 5) if she is from a small town or a highly religious town, she will now be known as the girl that had her nudes leaked. If it was a religious town, it could have brought shame on the family and in some cases ended relationships 6) if this screwed up her high school trajectory, it could have messed up her grades and limited her college choices
Lastly, I think part of this amount is to make it somewhat meaningful to Apple. If it happened once because they didn’t properly vet their 3rd party, a small fine would do nothing to prevent it from happening in the future.
Just boot from stick to test the hardware, leave my hdd/ssd alone!
What they stole here was much more intimate than that.
A few years ago, someone bought an used harddisk and got some private information of Brazil's then first lady Marcela Temer[0] and tried to blackmail her. He was later caught and imprisoned, but not everybody has the same luck.
[0] http://g1.globo.com/tecnologia/noticia/2016/10/hd-comprado-h...
or `shred` it. Probably takes longer but more secure.
Not saying it wasn't malicious, likely was, but man, seems like could also be an accident of resetting settings etc
I get that people need fancy thin phone, but storage and battery shall be removable.
The only workaround as of now is not to own a phone which I exercise. I can't trust any of them.
Yet it took us 5 years to figure out how to make this right with the victim.
This right here is the problem. Apple must not ask people to turn off passcode instead reset iPhone.
The technicians remain nameless, and suffer no reputational damage, just losing their jobs.
Put another way - how is Apple actually responsible for the activities of these individual technicians?
What should happen here is the technician should be named, there should be big billboards put up in whatever town they live in, and they should have to get "I distributed child porn" tattooed on their face. As well as not be allowed to come within 50 yards of a computer or cell phone or transistor. There are harms you can't undo and the punishment should be as permanent as the harm.
Consider that you had to send your car in for repairs to the company that produced your car, and you placed some valuables in your (locked) glove compartment. They then steal all of your valuables.
The car company (or their trained engineers) should never have to entered the glove compartment at all. The fact of the matter is that you left your valuables in your car with a trusted third party, and that trust was abused and your valuables were stolen.
The issue isn't that someone stole your stuff, it's that you trusted the company that built your car to not go snooping around and stealing your stuff.
Trusting a third party is not "careless or "reckless" behaviour, the onus is on the company to behave responsibly with your personal items/data.
EDIT: I took a look at the original article from the Telegraph[0], and it seems like the perpetrators were an Apple contractor called "Pegatron". While this isn't as bad as a BMW employee stealing stuff from a locked compartment in your BMW car, it still isn't great.
If this contractor was officially allowed to perform repairs (which it seems like they were, as Apple paid the lawsuit), then they should be held to the same standards as Apple employees when it comes to data privacy.
I said locked car but whatever. Better analogy would be you get your car cleaned, and leave cash on the seat.
> Trusting a third party is not "careless or "reckless" behavior
I disagree but maybe it's a result of being taught to be "street smart" or "common sense" as it's sometimes called. I don't jog with headphones, I don't assume someone is going to turn when driving, I don't cross crosswalks without making sure traffic is stopping, and I don't assume a technician is going to be 100% honest when working on my stuff.
Sure "it's not my fault" if I get hit by a car, or robbed but blindly trusting every "professional" you encounter is nuts.
Of course! It's more than reckless, it's disgusting, horrifying & illegal. I have kids about this age. If they left nude photos on their phone for a technician to find, I would scold them for being careless.
Apple is certainly capable to do that and I'm even sure that this exists on their devices too.
With the laptop example they can pull the storage medium (2.5" HDD/SSD, or NVMe), service it, and then reinstall. Whereas iOS devices have storage soldered onto the mainboard and there's a cryptographic sync between the T2 chip and OS installation, so you cannot simply swap the storage onto a different phone (this is actually a legitimate security feature that just happens to hurt service-ability also).
I believe there are things they can do (different levels of access, managed by iOS) but the laptop analogy doesn't help here since it is an Apples and Grapefruit kinda comparison.
This is similar to how many laptops encrypt the ssd with a TPM chip. But they can still decrypt and image the drive provided they have the owner's credentials. So yes, of course apple can swap storage in Iphone, they just don't want to.
They don’t. I’ve done it several times with my old MBP and a couple of iPhones. I never leave a device with a technician without wiping it first. If someone gets upset about that, the proper thing to do is escalate with the manager, because that would be highly irregular.
There should be safeguards either way, but it seems that most articles and posters are assuming that it was. I can imagine a number of ways to accidentally or automatically sync photo albums to Facebook, and this is one of the main reasons I don't have it on my phone.
Similarly, if the privacy breach was intentional, I would have guessed the techs would have downloaded the content and done something that was less obviously traceable to them.
I don't recall FB having a mechanism to automatically sync your camera roll to your FB feed.
Or do you mean to suppose they thought they were on there own FB account and expected to send the pics to themselves?
I'm not a FB user any more, so I can't confirm
something like this:
https://www.dpreview.com/news/5620765515/facebook-photo-sync...