Someone can be less than perfect and that can cause them to be victimized.
We should be able to talk about both aspects of this story, perhaps independently.
Some people want to discuss how the offender should be punished, and other people want to discuss how we can behave to prevent being victimized ourselves.
I don't think it's valid to argue that people discussing how to prevent victimization, are somehow "victim blaming".
"They deserved it for sending in an unwiped phone" is victim blaming.
"If you need to send in your phone, you can do X and Y to protect yourself" is absolutely NOT victim blaming.
I cannot wrap my mind around why people would have a problem with the second statement.
When the problem is that the phone was borked to the point that X and Y were not possible, it's tonedeaf at the very least.
Obviously, the phone being borked is relevant, but in that case we need to ask what preemptive measures can be taken on a phone that isn't yet borked. It may be that the only answer right now is "don't keep nudes on your phone" then that's unfortunate and should be addressed.
What boggles the mind is the overlap this group appears to more or less be a subset of people who are up in arms anytime someone doesn't take steps to de-risk their life in any other context (like using an older car seat for your kid or not putting GFCI breakers into everything under the sun).
https://arnoldkling.substack.com/p/the-moral-dyad-and-health...
Someday you might be hacked. Is it your fault for using technology at all knowing you can be hacked?
I am not. For you to interpret helpful advice as blame is some serious mental gymnastics. "If you need to send in your phone, you can do X and Y to protect yourself" does not assign blame to anyone.
> Someday you might be hacked. Is it your fault for using technology at all knowing you can be hacked?
Why are you so obsessed about assigning blame? Do you think everyone should ignore security best practices, since its not their fault if they get hacked?
Go ahead and set your HN password to "password", please. It wouldn't be your fault if you got hacked, so why would you care if I knew your password?
To actually answer your question, no. It would not be my fault if I got hacked. But I don't want to get hacked, so I take reasonable steps to avoid being hacked anyway. I am an adult with the responsibility and agency to take care of myself.
Weird also, that talking about preventative measures is only considered "victim blaming" when it comes to certain specific topics. If you say it's a good idea to wear a seat belt or helmet in your car or motorcycle, it's not victim blaming. If you say people ought to lock their doors at night, it's not victim blaming. We tell our kids not to get into strangers' cars--not victim blaming. What is it about this topic that always seems to set off the alarms?
I used to really over-share online, and reading stories like these over the years has helped a great deal to educate me about good online OpSec and privacy best practices. I have data sharing/storage habits to this very day that stem from good advice received from others.
(1) the purpose helmet is to protect you from accidents, not malicious actors. When you get hurt in a car accident, it is rarely because a criminal set out to deliberately hurt you.
(2) if you responded to an article about someone specific getting hurt in a car accident with "well they should have been wearing their seat belt", you probably wouldn’t be called out for victim blaming, but you probably would be called an asshole.
Or more precisely, in written words. And we dont seems to have a decent solution.
I have done the same with old or failed hard drives for decades.
The difference being, I didn't want these devices back. I never intended to use them again. This person obviously wanted an unbootable phone fixed, and the repair drones 'had fun with it'. Someone (Google) is going to have to pay damages, and also chase down and take down copies of those photos forever. What a mess.
I had a friend that worked at an independent film/photo processor back in the early 1970s. The walls in the process area were papered with printed nudes. Floor to ceiling. Of course, in the pre-digital era, those elicit copies never saw wide distribution, but they were there.
But it's a fundamentally bad way to approach analyzing safety issues. For those who really want to dig in on the topic, I strongly recommend Dekker's "A Field Guide to Understanding 'Human Error'": https://www.amazon.com/gp/product/B00Q8XCSFI/ref=dbs_a_def_r...
It's nominally about examining airplane crashes. But he breaks down into great detail why the default analytical model is entirely inappropriate in ways that makes real safety improvement impossible. And it's the same set of analytical mistakes you see in a lot of blame-related behavior.
While, ironically, simultaneously demonstrating the opposite.
Yes, non-smokers can get lung cancer, too. But at a far lower frequency.
So even as a life-long nonsmoker who absolutely hates smoking I think there's a lot of unnecessary victim-blaming for smokers.
[1] https://www.cdc.gov/tobacco/data_statistics/fact_sheets/yout...
[2] https://www.camh.ca/en/health-info/mental-illness-and-addict...
[3] https://www.heart.org/en/news/2018/10/17/why-its-so-hard-to-...
We can design devices and operating systems to be safe by default in the same way we are now designing programming languages to be safe by default. There's no reason why the data should have been recoverable from a bricked phone without the user's authentication.
We really can have our cake and eat it too - we can have devices that you can freely store nudes on without risking that some rando with a USB cord and physical access can just make off with the data, bricked device or otherwise!
It's also done in a way that a programming manager can mechanically verify the absence of such code. Exceptions can be flagged for special review. Often there are safe ways of doing the equivalent.
It should be harder to have your photos be unencrypted on device, accessible via any USB connection, than it is to have them to be entirely inaccessible at rest.
I don't take nudes but I tend to use my phone as an impromptu photocopier for stuff like bills and receipts, so the photos are full of private info such as account numbers. I worry about that sometimes. For photos that have to be treated with real security (typically the screen of recovery codes when enrolling a 2FA token), I use my old dedicated digital camera which has an SD card, no network connection, and never leaves my bedroom.
Most folks are just going to take nudes and not strategize much and expect them to remain private as part of the typical photo taking and sharing workflow.
But (short) pin probably isn't enough, because that means the key is still on the phone.. I'd want an extra password.
As an older person, I find this observation very interesting.
Today, I would consider people in general to be much more technically knowledgeable compared to people 20+ years ago. And yet, 20 years ago, removable storage was quite common, and probably expected of most devices.
People are more capable but security like this needs to just be a part of the usual workflow or problems will continue to occur.
Moving files around on a device, extra steps, just doesn't work for the masses.
Admittedly, the technological world is nearly impossible to avoid exposure to these days, where it was entirely optional (or downright prohibitive) to be involved with in the past.
So in general, thank you older people for creating them, I have a lot of fun with them.
Very few people know how apps actually store files on a mobile device and as people increasingly use phones / tablets instead of PCs their knowledge of PC file systems reduces. So for many people, copying photos from a phone (or cloud backup) to a computer could be quite a challenge.
BTW IDK why there are two names for the same concept
Disclaimer: I'm also an older person.
I'm pretty technical (As is nearly everyone on HN), and I have no idea where my photos are stored on my Android's file system. I have no idea where the APKs are for all my installed apps, or where their saved data sits.
Unless it comes with a card, but the card is not inserted, so the user has to do it before booting up the phone
This sounds like something that can only be mandated. It doesn't make much from a business point of view.
I had an 11 year old ask me what "right-click" was the other day. Yes, it sounds insane and it absolutely is. I blame the public school system.
They know only what they're exposed to, and no more.
Most devices don't have SD cards these days.
What's so tech about removing a physical piece that has data? It's an action pretty much everyone can understand intuitively - "this is where your pictures are, if you remove it they stay yours".
But even I struggled at times to get those pictures then onto a given pc.
I know what a filesystem and a driver is, so I can make it work, if something is missing. A layperson usually cannot.
Partly on purpose, one might say. They are supposed to stay in their walled gardens, where you transfer everything over the approved cloud way and can be thankful, if their data is accepted in another garden.
You know that 90% of the world doesn’t know what the word “data” means, right? (Including local variants)
What we need, to fix this, is to enforce felony charges against the kind of fuckers who do this, and put them in prison for 20 years, and stop victim-blaming, and stop the insane medieval attitudes about nudity, and slap every single fucking person who espouses this kind of bullshit upside the head, daily, every single day, until society is finally purged of their bullshit, and we don't need anything. fucking. else.
This isn't a product design issue. It's a punish evil people issue.
It is both. A secure design would not allow this to happen. But when it does, the perpetrator should be punished severely.
Laws discourage certain behaviours. It doesn't stop them.
Regarding victim blaming, obviously this person isn't to blame, but it seems that even suggestions to be cautious are seen as "victim blaming".
When you tell a kid to look to both sides when crossing the road even if it's green, you're not blaming them for a possible accident. It's just that sometimes people ignore traffic lights. And when you tell someone not to give their pin or send a device with sensitive content for repair, you're not blaming them. You're just telling them to be careful because sometimes stuff like this happens.
One, the correlation between "do a crime" and "do the time" is quite low. Look at the stats for sexual assault (0.25%), robbery (0.2%), and assault and battery (0.3%): https://www.rainn.org/statistics/criminal-justice-system
Even for murder, the US's clearance rate is only about half.
But even if the correlation were somehow perfect, it still wouldn't eliminate it. People just have a hard time believing in the consequences of actions until they experience them. I couldn't count the number of times I've gone through the "ooh fire pretty" -> " ow fire hot" loop in various ways.
So this is thing where we need defense in depth. We need solutions in criminal law and civil law and provider regulation and product design and user education and culture shifting. Each one of those will be fallible, but each one will bring the rate down. With enough work we can at least make the bad outcomes rare.
We punish in order to hopefully deter, in at least some cases, though. And sometimes, we punish because it's simply the right thing to do, because people deserve it. This is such a case. They busted into these phones; that was bad enough. Then they searched for the most personal and compromising stuff they could; that's crime #2. Then they posted it! That's three crimes. This sort of brazenness needs to be punished, at least occasionally, to show people and future offenders that we still have at least some semblance of a functioning justice system. That they can't just do whatever the heck they want and laugh about how it might affect people.
We do need the right Americans in prison, though. I can easily find tens of thousands of folks who need to be released. These fuckers, though, need to be incarcerated. Otherwise, why do we even have prisons?
It's fairly simple to use, and if you sometime give your phone to other people / kids / etc ... It quickly becomes absolutely necessary.
Need to remember to use the "secure folder" camera though, if you merely take the pic THEN move to secure folder, while it's super quick and easy it's usually too late as google photos, dropbox, whatever else will already have duped it.
Pixel with the latest Android should have that ("Move to Locked Folder" [1]), though as with all security things it is annoying to use in a lot of ways. Doesn't work for SMS images or Whatsapp (Signal is much nicer on this front, but images on Signal get lost if a phone is bricked - the account backup/transfer method sucks a bit).
[1] - https://support.google.com/photos/answer/10694388?hl=en
And if it's damaged a reset or wipe may be impossible for the end user.
Nothing nefarious. I'm just not very trusting with my data, and not going to just hand it over like that.
I hear you, and agree wholeheartedly that there is "absolutely nothing wrong with this", but maybe if the topic keeps coming up, people should have less trust in the companies (and their respective flawed human supply chains) that keep our information.... and act accordingly. Unfortunately that's easier said than done these days.
Because nudity is akin to sex and sexual ways, which are taboo in many societies. Upstanding citizens do not have nudes, in general. Especially women or nudes hinting at same-sex romance.
It isn't right, but it is.
Edit: I'm not saying I agree with this. But it doesn't take much to see folks putting others down for nudity. YMMV depending on where you live in the US. There is a reason most politicians (in the US) wouldn't get caught with nudes and I'm guessing that in some areas of the world, it would be even more detrimental to your life. It is the same line of thinking that punishes women for being "sluts" but are OK with men having a series of one night stands.
What makes you sure about this? What evidence do you have?
Anyway, your comment doesn't seem to have much purpose but to weirdly say "this isn't right, but it actually is right."
But come on, I'm sure you can find examples of folks putting down others for it. It isn't common for politicians to have nudes, at least not in the states. Melania trump had her nudes used against her (put as degrading her character): Janet Jackson had people outraged over a nipple. Facebook doesn't allow nipples. Heck, even further back, I remember folks in high school shaming a singing group (TLC?) for having nudes printed in another country (the cover wasn't even showing breasts as hands covered them).
If you had highly sensitive info of a non-sexual nature on Google Drive that was going to have a massive negative impact on your life if it got leaked, half of this site would still be saying "that's awful, but you can't trust Google" if that happened.
No you would hear the exact same thing. My sensitive data on the cloud is all encrypted. Have you ever seen anyone suggesting to do backup on any cloud platform in any other way than encrypted? That's because the data is sensitive and you can't trust whoever store it for you.
> Why do we tend to treat people like they’re asking for it when their nudes get compromised?
We do that over anything that is sensitive. It's just that nowadays, people no longer consider much of their things sensitive... except nudity.
I agree entirely that we should be able to trust companies and I agree completely that the biggest issue is on them, but the thing is, we will never be able to trust them fully, there's just too much to handle. I'm not saying not to push the responsibility on them, for sure we need to do that or it's gonna be even worse, but we also need to remind people to consider their data security and how they handle it. Both are essentials if we want to lower the number of instance of theses happenings.
I'm curious, if I upload nude picture on my Google Drive and with the password "potato", and then my picture were published by someone that guessed my password. Wouldn't you suggest a stronger password? Still a victim, but still good to suggest ways to avoid it in the future.
Sure, it's lurid in this case because it was nudes, but this could have just as easily been identity theft or something more mundane but equally wrong for Google to access.
No, this is what we have laws for. What Google did is wrong and if the person responsible cannot be criminally prosecuted, we should seek legislative changes to enable prosecution in cases like this in the future. This is not merely a matter of individuals trusting Google too much. The individuals don't have much choice; that's where the law can step in.
Unfortunately with snooping, we have little to no such protection, in which to many (in US) is a major erosion of constitutional rights.
Say I have a bedside table that needs repairs. I send it to a carpenter. If I am fool enough to leave my nude photos in the drawer then I should fully expect the carpenter to have seen them. I'm the fool, he's innocent.
If, however, he takes those photos and sends them to a tabloid, now he's the asshole.
Or in the phone case: if the phone/screen dies, how can you do anything with it before sending to repair?
Might seem weird, but if you explain to the person doing the work that you have sensitive data on the device they'd probably understand the precautions.
The world contains bad actors, and we should be having conversations about what are the reasonable steps people should take to protect themselves. The fact that this happened, and that it could easily happen again, suggests that we should take additional care with sensitive data on our phones. Maybe an app for encrypting sensitive photos and that requires a password to access?
Yes, people should feel safe in their tech. People should also feel safe in their homes, but most everyone still have locks, and many people additional layers of security.
I can never tell whether I'm paranoid, or worried for good reasons, but cases like these + mass leaks which happen occasionally are basically the reason why I don't have this secure feeling at all for anything which isn't on an offline device which is in my hands or device-side encypted then put online (but to a lesser extent). And I'm afraid nothing is ever going to be able to fix that feeling anymore, it just seems to late for that, and I feel like people who do feel secure lost touch with reality somewhat.
Still shouldn't have to feel that way.
On devices I trust less, like my android phone, I feel better than default (but not perfectly comfortable) about open source encryption software and the stuff stored there.
This also brings an important aspect of repairability, I've been paying for extended warranty and discount on battery replacement for years to an android manufacturer and when the time arrived(during lockdown) they wanted my device sent to the repair-center as there was no policy to send the parts to the consumer's place.
Although I don't believe for a moment that Apple is pro-repair now, I hope them sending parts directly to the consumer would be followed by android manufacturers as well.
Unless I missed something, I believe that you currently have the only top-level comment to mention victim blaming. There's one other, but it's dead, which means the HN "immune system" (as dang calls it) worked.
You're not wrong, but for future reference, there is a way to stop such a reboot loop; I did it just yesterday with my wife's phone. (Of course, it was a Pixel, so it might not be on every phone.) You do it by holding power and down volume until it says "Command not found", then you hold power and volume up until you get a menu. One of the items should be "Power off". Another one is "Factory reset" or something like it.
Once my wife's phone was off, I left it off for a couple of hours to let it cool. Then I booted it again, and all was well.
We're still getting her a new phone though.
I don't like seeing "don't victim blame" taken as gospel. Blame isn't a simple binary thing. Every time a company is hacked we don't line up to defend their shoddy security practices even though they are a victim.
Resorting to “do not do X if you don’t want Y to happen” is a cop out and demonstrates a fundamental failure of technology doing what it says on the box.
They don't say that when it's not encrypted it will remain secure.
Nudes are very rarely encrypted.
It's much less forgivable for engineers and managers that work at Google, Apple, Facebook, Microsoft, etc to be cynical and say "yeah Tech is evil what can you do" compared to the average person, and this site is full of people who are in those positions.
Even HN won't let you delete your personal comments.
Some digital activity should be considered private, and violating that privacy should have legal and social consequences.
>Some digital activity should be considered private
Yeah, the ones which are mathematically proven to be private.
Gah, what a sad, terrible world we have built.
Look, face it, actions have consequences.
My money is on nope, however.
When I have done this in the past, we did it the old fashioned way -- took the pics with a non-connected digital camera, printed the ones we liked, then kept the rest on an encrypted USB drive. Even this has the risk of leaking your photos to the cloud if your computer is set up for cloud backup.
Being able to trust your hardware/software is important, but also knowing why you can't (for now, maybe not ever) trust your hardware is also important - maybe more important.
It doesn't have to be "wrong" for it to be stupid, and trusting your private life to a device you literally do not own is. This isn't victim blaming, this is recognizing the fallacious logic that most people have when approaching this subject. Call it tech illiteracy if you want to be nice, but I'll just call it "dumb".
They are dumb, precisely because the risk is unquantifiable to them until realized, then it's too late to act.
And unfortunately, a lot of people in society don't expect this type of intrusion by a company they trust. But they should. And I don't think you can blame Google for any of this.
Irrelevant
Why do we pretend that a practical answer to anything is "well people should stop behaving like people" ?
Systems should be designed to work with people as they actually behave, not an idealized version.
However, most people wouldn't knowingly leave nude images of their spouse on the car's back seat when getting the car serviced. In many ways this is similar.
Edit: For people who think I'm blaming the victim, I am not. I thought that was clear, since I blamed the thief/poster of the photos! This is in many ways similar to leaving photos in a car. That is not to say that the person with the phone is at fault, but that this also happens in many other cases. If this happened to me (which it has), I'd do something else instead of sending my phone for repair by an unknown person.
Granted, this may be the best reason I've heard yet for why removing the option to have an SD card is bad...
I think you are asking the wrong question. It's more useful to ask how to initially safeguard the pictures instead of how to remove them after something broke. If the pictures were encrypted, then it doesn't matter who has possession of the phone.
I love car analogies (who doesn't), I think this is more like your car being on fire and asking a firefighter to put it out, while hoping they won't find and share any documents they find in the back seat.
(No, I'm not serious; this is terrible advice!)
Now, I don't store nudes on my phone. That said, it was recently suggested to me, here on HN, to use a scanner app in lieu of a flatbed scanner for all my scanning needs (primarily documents around tax time). Not so sure that's a good idea versus this.