No Privacy in the Electronics Repair Industry
arxiv.org
arxiv.org
The FBI suits came back about a week later and took statements from everyone. We tried to get info from them about the case, but they wouldn't give us anything. However, one suit said the computer wouldn't help much for a conviction or even making an arrest because too many hands had touched it. Depressing. However, he did say that the customer is on their radar, and an active investigation had begun. He hinted that it was only a matter of time before the dude was caught in the investigation. I felt a tiny bit better after that. But still, the only experience made me feel like shit. It still does.
Now the rental moved towards more expensive and less convenient stuff to have at home full time like servers and hosting.
Getting someone put on the FBI's radar is a great way to ruin a life. If you can target anyone you wish this way, that is a lot of destructive power to wield, akin to swatting.
Doesn't even have to be the feds. Local .gov attention is more than sufficient to make life indefinitely reasonable.
I think anonymous tipping needs to be curtailed to some degree. When simply being investigated is only slightly short of a probation sentence in practice one's right to know the evidince against them and the public's right to be privy to the proceedings should apply.
Edit: In the general case, not this specific one.
It's a travesty that a report from a jaded ex or obnoxious neighbor can result in one having CPS, the state tax authorities, etc, crawling all over somebody for however long an investigation takes. And from the point of the person being investigated and more importantly, the broader community it is anonymous. The person using the investigative process as harassment stands to lose nothing by doing so.
I don't know if you were referring to this, but it certainly was front-on-mind for me. (There's a GoFundMe for their legal troubles if you want to donate. Please consider it.)
https://reason.com/2022/11/16/suburban-mom-jailed-handcuffed...
But yeah, I definitely get your point. I actually have a friend that works for CPS, and she said bitter ex's call in bogus claims all the time. There's a protocol she's required to follow, and that protocol doesn't involve investigating if the claim is false, even if it's totally obvious that it is. And the worst part is, even if the claim is obviously fake (like, the accused moved to Florida 6 months ago with his new girlfriend; he hasn't seen his kid in months, how could he leave recent bruises on her?), there's no consequences to the accuser. Nothing. She's not allowed to do anything, just close the investigation and move on. That's it.
Continuing on the topic of CPS, she once told me that they work very closely with the local cops. Also, CPS doesn't need warrants or court approval to enter a home. If they get an accusation of child abuse, they have the right to enter and investigate, and they use the local cops to assist them. Well, the local cops know this, and they use it to get around warrants and such. She said when the cops want to get access to someone's house, but they don't have enough for a warrant or the whole case is shady (like, they just wanna harass someone), they have an anonymous idiot on the street call in a bogus child abuse claim to an address, then they call their contact at CPS and work out a date/time to enter, based on the abuse claim they initiated (through their anonymous idiot). Once the cops are inside, they can pretty much do whatever they want. She's been on "investigations" where she was told to wait in her car, meaning she had to be there as a formality, but that's it. She said CPS knows what's going on, but they can't/won't do anything about it, because they need the support of local cops for their own, legitimate investigations.
The plan? Put customers at ease by offering the world's first asexual computer repair.
I know when we were RMAing drives as a company there was an $8 option to not return the drive. As it was free shipping to return it we’d just send it back - no sensitive data.
If you really need to be secure you encrypt AND shred. But you have to encrypt before it fails of course.
The resulting computer could no longer boot Linux, or the windows factory recovery disk that came with the machine (or stock windows).
That (and the shoddy initial design with a half life of 6 months) is the reason I will never buy a Toshiba laptop again.
Cue a couple of police and prison service cars rolling up outside his house and disgorging a lot of very beardy old sysadmins, who copied everything off onto modern media and wiped the drivers. They then offered the guy a contract to maintain the VAXen they still had, and help in the project to transfer stuff onto more modern databases.
Things became interesting when the guy got jailed for a few months for a minor incident that escalated a bit, but still needed to be given access to the prison service computers...
Wow... that makes me so uncomfortable
More details in 5.2.1 in the pdf: https://arxiv.org/pdf/2211.05824.pdf
https://en.m.wikipedia.org/wiki/Quis_custodiet_ipsos_custode...
I believe you'd have to be able to show that you'd been harmed. This came up at the top of a search for "sue law standing":
> To file a lawsuit in court, you have to be someone directly affected by the legal dispute you are suing about. In legal terms, this is called having “standing” to file the lawsuit.
I think that'd be difficult to prove / show unless you had some pretty direct evidence. I don't think you'd have that unless you setup logging / monitoring software in advance, as in the article. Regular consumers wouldn't have that.
They are trained to make you feel like you have something to hide.
They equally hate the "we told you your computer would be ready in 3-5 days, but we haven't been able to reach you for the last 5 days to get your password since we determined it was a software issue and we couldn't go any further so it's still going to be another few days" experience.
So the default was to ask to make the experience as smooth as possible. But we were never instructed to pressure someone into giving up their password, just that we inform them upfront that without it all we can do is boot a test image to validate and that there's always the possibility software may play a part and still be a problem and we would want them to boot and confirm before leaving when they come to pick it up. Guest accounts were fine too. As was the customer giving us a formatted machine if they wanted. That was usually the best of the options because if the issue was present in a freshly formatted machine, we already rule out most / all of the software and we didn't have to deal with data loss issues (more than one customer signed the "I know I will likely lose data in this hard drive repair and I have a backup" line and then still pitched a fit when they did indeed lose data).
Apple had very strong rules about customer data privacy and snooping around was a good way to get fired (and I knew one person who did get fired for it). In fact, I've worked in health care and frankly Apple's rules for data privacy and secrecy (both theirs and their customers) was far more stringent than the health care job. HIPAA says protected info is any combination of identifying information AND medical information[1]. So your address and phone number, not PHI. A list of all your medications with nothing that identifies you, also not PHI. Technically your list of medications with your "patient number" could also be "not PHI" if the only thing there is no reasonable way for the patient number to be tied to identifying information without having access to the other protected data. At Apple, all data was considered private and confidential and anything that wasn't required to be kept for record keeping was to be shredded when it was no longer needed, regardless of whether that data could have ever been connected back to a customer.
Not to say that people don't abuse their access (again I knew someone who got fired for that), but at least in my time there they were very serious about only using the least access you needed and never told us to give anyone a hard time about wanting to keep their data private.
[1]: https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/un...
Whether it's still like that I couldn't say. From the outside, it certainly seems like some of that infamous secrecy has been toned dow. Though whether that's culture/company change or the nature of being so big that even the smallest parts of your supply chain make noise I couldn't say. At the size and rate they've grown the retail business, there's also the possibility of just hiring so many "warm bodies" that embedding that culture is more difficult too.
And being fair to this study's subjects, I'm not sure you can even say much about the managers themselves. This sort of thing would be exceptionally easy for any half way competent tech to do without tipping off their manager. Apple might have the power and clout to heavily restrict what devices you bring into the back rooms, but I suspect your average local tech shop isn't doing bag checks and device checks on their employees. Who's really going to question the local tech carrying one more thumb drive than normal? And since these are customer machines, it's not like you have corporate MDM software installed that can report when an external storage device is plugged in.
A few years ago my bank would ring me up every couple of weeks and say "Hi, I am calling from your bank, we want to talk to Doctor Eval(), can you please verify your date of birth and we can get started?". They would get so pissed off when I wouldn't tell them. I was like, "how do I know you're from my bank?". (Banks seem to have stopped doing this now).
For companies which should be putting security at the centre of their business, they apparently have no idea that they're normalising phishing.
Yeah, this appears to have stopped, but was somewhat common a few years ago. My standard response was 'you called me, tell me who you are and I will call back on the official line'. They couldn't object to that. It was obviously some plan to 'ensure user privacy' that once it became known to one or two people with the authority to do something about it and the knowledge to know better it was quashed.
Now if only they would allow you to enable 2FA options that aren't SMS and also disable SMS. They don't understand that SMS is a terrible 2FA system isn't mitigated by 'but you can enable other things' if you cannot remove SMS as an option.
* https://arstechnica.com/information-technology/2017/05/thiev...
* https://arstechnica.com/information-technology/2018/08/passw...
On the website:
1. you input a user ID
2. you input a password or PIN
3. you press a button that sends a SMS with an OTP code to the registered cellular number
4. you input this OTP code on the site
Even if someone can intercept the SMS, they wouldn't (shouldn't) have ID and PIN.
For another, what's the point in having 2FA if one of the factors is completely insecure? It's just an annoyance at that point, and a good way to ... tie your account to your phone number, which just coincidentally happens to be the primary key for most advertising tracking services. What a coincidence
It doesn't have any security benefit for phishing like this, it's just one additional password input field.
Not true. FIDO and prevents this. The key is bound to the site you authorized it on, so inputting the key while connected to a phishing site will do nothing.
The entire point of two-factor authentication is to provide an extra layer of security for when the first layer is compromised.
Having the possibility/capability of intercepting the SMS is only effective if the ID and PIN are already known, and while surely there are "other" ways to get them, the attacker needs all three.
From what I have read/seen, most if not all successful attempts to access someone else's bank account online go through some form of phishing.
The SIMjacking is the last barrier to access.
In most cases people reuse passwords and their login/password are known via any number of a million dumps of large websites whose dbs have been breached.
The NIST actually has great guidelines for digital identity authentication:
* https://pages.nist.gov/800-63-3/sp800-63-3.html
Don't blame the government -- they outlined an ideal way to do it on many levels of need. Blame the specific people who implemented that specific system.
"Yes, I hear you typing in the PIN"
Oho, but that's a bit of security hole, isn't it?
"It's just beeps though, I can't tell what you typed"
Yeah but someone suitably skilled *could*, is my point!
"Yeah but it's just beeps, like this <beep beep beep beep>"
Okay and you typed 1 3 5 8.
"Uhhh... oh. Yes, I did. Uh, how did you do that?"
I've got an ear for it. This is absolutely not a criticism of you in any way and thanks for helping me demonstrate it, but could you get your supervisor to play this call to their manager and get back to me, once we're done with the call?
"Yes, I'll do that"
Awesome! Now these bank transfers...
They didn't call me back, but now call handlers transfer you to a totally different service to put a PIN in.
I let him watched me type it in (on a cracked screen with a broken A key) and the proceeded to erasing all partitions before I left it with him.
It was preset to "fuck you", just in case.
(You do do backups, do you?)
Any time I've had to take my PCs in for something I pull out the hard drives before driving them over. As long as the machine can POST, I can take care of the rest. It gets a lot trickier with other devices though. I can't imagine trying to pull the storage out of laptops, tablets, cell phones, or game consoles.
First I thought it was to simplify their tests when they get it, but now I'm thinking it could be to make sure technicians don't have access to my personal data.
https://news.samsung.com/global/samsung-releases-maintenance...
If you have a broken (black) screen or touch not working or if the device doesn't boot properly it is useless.
Rebrands Chinese tools? That's most of the electronics repair industry. It's a side business for him.
Of course all those efforts are kind of hampered when authorized repair shops mess up. Like that time when an Apple repair tech uploaded a customer's selfies and sex tape on Facebook[1].
[0]: https://www.vice.com/en/article/qj4ayw/auto-industry-tv-ads-...
[1]: https://nypost.com/2021/06/07/apple-settled-after-repair-tec...
For the female persona look at how many times the local shops went digging for private data.
Sure the sample size is small but it is still a random sample so the data is worrying. Even more worrying is the shops that claimed the systems had viruses and they installed antivirus software - conveniently the paper authors weren't able to find any activity log data on those machines. That suggests that some repair techs are actively cleaning up their tracks.
This is the conclusion that the researchers imply, but keep in mind that these computers did have malware on them: the spyware the researchers planted there! As a former repair tech, if I’d seen some thing writing screenshots and activity logs to disk (we would use, among other things, sysinternals tools like procmon to look for malware) I would definitely be deleting that.
Regardless, the fact of the matter is that a negative finding in this study is meaningless, since the laptops could have had the disks removed and imaged separately, or the techs could have booted a live USB to copy off files. The researchers’ spyware would have not noticed in these cases. It is concerning to me (in terms of the quality of the overall research) that this is not mentioned in the limitations section of the paper given how obvious it is.
I don't think that you as repair tech are entitled to manipulate any software installed by the owner. Even if your order covers malware removal and you see such activity and you suspect that it isn't installed by the customer you should contact them first, simply because such software isn't malware by definition (only in case it is installed against owner's/user's will).
In light of the lacking sample size, one might possibly argue that it's just as likely to happen with vendor repair, as illustrated in this case: https://www.telegraph.co.uk/business/2021/06/06/apple-pays-m...
I would never give a repair place a password though. It is better to just buy a new device.
https://en.wikipedia.org/wiki/2014_celebrity_nude_photo_leak...
I once caught a car technician from a reputable dealership's service taking my car out for personal chores, as the guy did not even unplug my dashcam. I had a rude awakening when I realized these things aren't just urban myths but that they do happen. Some people have no qualms about taking advantage of our unattended things. Of course, this is an anecdote with a sample size of 1, and I can't speak about how often these things happen.
But I'm honestly not that surprised to read section 5 in this paper. Not even surprised to see that there was no attempt to cover tracks on most laptops.
But what does a technician get out of copying my porn collection?
Nice, now we just need EU getting together and creating a new law forcing that all hardware should have such capability /s
People disclose a lot by accident and you can not repeat what you see but it’s hard to forget what you’ve learned.
(It’s partly why I didn’t want to be a systems admin or forensics tech and focused on censorship circumvention.)
(And then by extension how large groups of people with similar backgrounds will act.)
On the other hand, I also used to joke “someone’s gotta adjust the Vanguard” back before I knew “Vanguard” was also the name of a neo-nazi group[1].
Someone has to at least pick high level things like the ratio of stocks to bonds, national to international, that sort of thing… and I’d remarked to many people in many contexts that one downside to index funds is that folks selling off shares might have a disproportionate effect on the market.
Especially if the person selling explicitly mentions they’re purposely selling over 10k’s worth to trigger a report to the feds, because they feel they’re facing persistent issues with irrational actors, so it’s time to get cash into your checking account in preparation for emigration, since the state refuses to honor its promises unless you make them think the alternative is… well go look at the returns for VASIX[2]since about October 2021 and use your imagination :-)
[1]https://en.wikipedia.org/wiki/Vanguard_America
[2]https://fundresearch.fidelity.com/mutual-funds/summary/92190...
It is a go to answer when a company is asked why their product is not user serviceable, along with safety and security.
This is why I fix my own machines, and replace phones when they break.
I don't think surprise is the primary reaction here. If anything, this study is just confirming what has always seemed likely, but difficult to prove.
Are you assuming their gender or saying if we had more females doing the work, there wouldn't have customer abuse?