Don't send your Google phone in for warranty repair/replacement
twitter.com
twitter.com
- standard 'loveint' at support depts (many companies with personal data have stories about abusing system access to look at personal info of SO / randos)
- illicit group operating within or adjacent to goog doing some kind of espionage or ransom model
- google-haters inventing or amplifying a pattern of behavior? (but with what motivation)
- not obvious if the phones are passwordless, or if insiders are using a 'universal unlock' feature to decrypt pixel devices -- if the latter, is that a bigger story than the stalking?
if this is only happening to passwordless phones, still an abuse of trust, but I'm okay with 'don't send passwordless phone to support' as a consumer best practice.
You can de-authorize your phone from Google security settings on their website.
(Not that it should be needed. I hope they lock up the guy and his manager for this)
https://android-developers.googleblog.com/2018/05/insider-at...
is this not true with google's encryption? how? is there a backdoor feature?
> someone else reported the same thing happened to them on Reddit recently, using the same RMA for a similar phone at the same Texas facility.
Taking the story as true, it'd seem to be case 1.
Taking the story as not true (case 3.), she's in a professional position where publicity wouldn't hurt.
Her report looks questonable (not necessarily false):
> They deleted Google security notifications in my backup email accounts.
If the accounts were backup, and she's a security-conscious person as she claims in the same post, how did they do that? They were backup, so they couldn't use the main account to reset them. I can think of the accounts being opened in different browsers, but it doesn't seem a very plausible scenario.
Really weird to immediately shoot/ad hominem the messenger
Is this satire, or did you actually mean to generalize _the entire world_ outside of the US with a statement that is still ostensibly politically controversial today (both in and out of the US)?
The assumption that anything a(n attractive) woman says is true is the real "rampant and unfortunate gender bias", to be honest. And yet somehow they never seem to be penalized even when they admit filing false reports, defamation, etc.
victims making up stories in which they are the victim are exceedingly rare, in reality.
Not in my experience working retail/hospitality jobs. And lots of people crave attention. I see no reason to give either party more credence than the other absent evidence.
It seems to me the relevant metric is false positives and false negatives.
Victims making up stories in which they are the victim is INCREDIBLY COMMON.
They said "If true, it's probably reason 1. If not true, here's a reasonable motivation." Hardly immediately shooting the messenger, more answering questions asked
I know I do!
I'm using alternative frontends now like Teddit, Nitter, Fritter, Invidious etc.
Of course Drive and Photos files are in Google servers and aren't E2E encrypted, but I don't think that's what you're talking about.
Full disclosure I work at Google but on nothing related to this.
[1] https://support.google.com/android/answer/7663172?hl=en
[2] https://www.techlicious.com/tip/what-to-do-if-you-forget-you...
The Twitter user most likely has an easy to guess password.
Sending a phone in for repair negates the shoulder-surf issue but yeah.
Perhaps Google just has a backdoor.
That kind of makes me doubt this report, at the very least part of it.
Full disclosure, I work at Google but not on anything related to this.
Complete and total duplicate of https://news.ycombinator.com/item?id=29404954 and again with absolutely no evidence even though there are apparently tons of evidence left by this person doing this with absolutely no cuation (security notifications left in trash etc).
The fact that this is possible is a weakness in itself.
Google security messages should be signed and treated differently by the client & server
On the other hand, I also see no direct connection to Google. The victim also said in the comment chain:
> also to be clear I have been on Google support and Pixel support dozens of time all week BEFORE the hack happened, asking them to investigate why my phone marked delivered by FedEx 'disappeared' at the warehouse. At any time someone could have offered me any security advice?!
This could just as easily be a delivery driver or warehouse worker stealing the phone and putting fake info on the website. I don't think Google's workers would be dumb enough to do this to their customers' phones, my suspicion is that it went wrong somewhere in the supply chain.
Either way, Google is responsible for their warranty and return policy. If the delivery driver stole her phone or if someone broke into the delivery warehouse, that's on Google picking bad logistics partners. If the repair company Google partners with is doing this, the problem is with Google. If someone over at Google itself is doing this than that's an even bigger problem.
Either way, I hope the victim can get the help she needs and that Google finds the problem and prevents it from happening to anyone else. Not that I have high hopes for Google's support team taking this seriously…
Until they do, the company is represented by its employee. The 'corporate veil' works both ways after all.
https://www.telegraph.co.uk/business/2021/06/06/apple-pays-m...
> The tech giant agreed a settlement with the 21-year-old after two employees at a repair facility uploaded the images from a phone she had sent to Apple to be fixed, resulting in “severe emotional distress”.
> The incident emerged during a legal dispute between Pegatron, which had reimbursed Apple for the settlement, and its insurers, which in turn refused to foot the bill. Apple was not directly named in the lawsuit, and was referred to simply as a “customer” throughout, in an effort to keep the matter confidential.
> And why do you need modicum when she has already mentioned fedex related thing and she is not the first one to find such issues?
Because there is plenty of wrong information, whether misinformation or disinformation, flying around the internet.
Perhaps even in your comment, when you claimed
> Apple, probably in 2016, tried to hide their malice when they paid millions to their own tech who posted a customer's nude on Facebook.
> Apple paid an unknown multimillion-dollar sum to a woman after iPhone repair technicians uploaded nude photos from her phone to Facebook. The Telegraph reported the 2016 payment based on court documents recently tied to Apple’s name, and Apple confirmed the incident in a statement to The Verge.
I think this will suffice. I read it and the verge seems to be legit thing to trust.
And you wrote that Apple paid the technicians who uploaded the woman’s media to Facebook, when that is not written anywhere.
To summarize
1: you ask otterley why they would need a modicum of evidence to believe something
2: in the same comment, you post misinformation or disinformation
3: you are presented with a request for the source of the erroneous information you posted. You are also presented with a source regarding the same incident that portrays a different sequence of events.
4: you then post another article which links back to the original source that was already presented to you, but which still does not claim what you originally claimed.
5: this is why otterley says you need a modicum of evidence
You are intentionally trying to summarize in a way that favors you tbh . Also i trust verge over some random people on internet trying to say its misinformation or disinformation. And regarding the first one I already mentioned the fedex thing.
2. You are asked to substantiate above claim.
3. You could not (your verge link says no such thing), so you simply chose not to address the misinformation or disinformation that you posted.
A simple "I was incorrect about my recollection of this event" would have sufficed.
1. "Apple paid millions after iPhone repair techs posted a customer’s nude photos to Facebook"
2. "The incident became public because Pegatron reimbursed Apple for the settlement, then sued its own insurance provider for refusing to cover the payment."
3. " The Telegraph reported the 2016 payment based on court documents recently tied to Apple’s name"
4. Apple confirmed the incident in a statement to The Verge.
Doesn't this imply
Apple, probably in 2016, tried to hide their malice when they paid millions to their own tech who posted a customer's nude on Facebook.
Ok, by 4 it is confirmed that the source (Telegraph) you have mentioned is correct right? Yes I am holding a premise that the verge is legit source. By 1 they paid millions and their tech posted a customer's nude photo on facebook. I said they hided the statement because of 2.
Where did I go wrong. I love to be corrected tho.
You continue to keep claiming Apple paid millions to the technicians who uploaded someone's nude photos to Facebook.
Both the Telegraph and Verge articles state Apple paid millions to the woman whose photos were uploaded to Facebook.
Apple, probably in 2016, tried to hide their malice when they paid millions when their own tech posted a customer's nude on Facebook
And due to two 'when' I corrected second 'when' to 'to'. And I probably messed it up after that :).
The statement you mentioned on last line is what I wanted to say.
Thats not just bad service. If the third party is an official agent of Google, then Google can be liable (monetary penalties). Now, proving that in practice is a question for the civil courts.
Now, if I was looking for a new Android device and I saw all these reports, I would definitely think twice before purchasing a Google Pixel.
All claims deserve to be followed up - and should this be false then the person will get what's coming to them.
This problem with repairs appears to happen frequently enough to not be discounted off the cuff.
How?
Magical thinking there.
I found odd that the victim is talking about class action lawsuit and accussing a man of "mansplaining" her (it could just have been a woman saying it). This is just toxic twitter behavior that takes innocuous comments from people and putting it in the bin of sexism, racism, or something that is accusatory in nature to gain a false sense of moral superiority over others.
If my phone was account was hacked and someone said this to me directly, I would take it as a personal shot.
Not sure why you are trying to detract of the alleged incident by trying to claim the victim is being "toxic".
Yeah that's not a nice thing to say as well. But I don't sense any sexist aspect in there. Personal shots can be ignored instead of adding more fuel to the fire.
> Not sure why you are trying to detract of the alleged incident by trying to claim the victim is being "toxic".
I don't think I was, just pointing out a couple of odd aspects of people going off on Twitter without proof. I did say we should take this seriously but also expect hard proof to back up their claims.
1) Victim receives unsatisfactory response from Google (or no meaningful response from Google which I have personally experienced). They seek public attention to get Google to acknowledge the issue.
ie. The victim followed the official steps for remotely wiping the phone (as it would not turn on) but appears that didn't work. https://mobile.twitter.com/avantgame/status/1467242719273631...
2) They are seeking public attention/support. They may be looking for others with similar experiences that might help.
Helpful responses include steps they can take to protect themselves right now.
3) Smear Google - We can wait and see but I do not see an indication of this at this time.
> yes it was the official Pixel warehouse, arranged directly by Google support.
I would think different if they took it to some mall phone repair stall.
(Not calling her account into question, just curious)
Stop making excuses for her. Take a moment to think critically. It's a heaping steaming pile of obvious bullshit.
Given her already public figure persona and proceeds from prior works, why EVER take the risk to ship such personal hardware to a 3rd party?!!
Just get a new phone and sync a back-up…unless it just might be beneficial PR to, apparently, do the “risky” thing and carp about it.
So far, I see ZERO corroborating evidence—even something as simple as a suitably redacted screenshot of an email to Google support.
Trust, but verify & extraordinary claims require extraordinary evidence.
She is making a case in the court of public opinion.
Granted she has more clout than the “average joe” (and the very fact that this is even being discussed is evidence for it) but ANY case without corroborating evidence is just hearsay.
She should “put up or shut-up” and the levels of “put” required are so minimal that her PR credibility before the “court” on this matter has a very short half-life.
An anonymous poster on reddit had a similar issue a few days ago [0]. Their comment got 331 points on HN while this one got 257 points so far. The anonymous one got more points.
Is it possible you're wrong about this aspect?
What if your thesis was "I expect to only see reports of sexism from people with clout because they're the only ones that can actually tell the truth without getting their lives ruined?"
Can you see that this thesis is a possibility?
I find phones amusing because of all the trouble and strife they bring.
There are pro's and cons for phones, I get it, but should I be that accessible to anyone who can dial the right number combination or use a war dialler?
Another problem with phones is you cant control when they drop from 3G or 4G back to 2G which then makes it easy to capture the conversation from the air and do a replay attack. https://www.eff.org/deeplinks/2020/06/your-phone-vulnerable-...
External influences, control when your phone drops down to 2G and I have not seen any phone manufacturer put in an option to terminate calls and prevent calls being made on 2G. Things like the PinePhone and Librem are missing a trick.
The other problem with technology is the sheer number of options or inability to access and modify in order to make secure. Whether we like it or not, our lives are in the hands of others.
I gave up a long time ago when I realised how many legal ways there are to kill people. Its quite clever really but some institutions have had hundreds of years to perfect their dark arts.
Seeing the fact that every government, company, and criminal seem(s) to be highly motivated to exfiltrate data from your phone, perhaps it's one of the less safe places to store PII/critical data in the first place. (And that's before considering that it's highly portable and can simply be lost. )
If the critical data isn't on your phone in the first place, then you can't lose it.
But since your phone has network access, and as long as you have a decent data plan, your data need only be one tap away anyway.