We caught technicians snooping on our personal devices
cbc.ca
cbc.ca
The only safe way to do this is to 1) be present during service if it’s a software issue, 2) backup your data somewhere else, and wipe the device clean before handing it in.
[1] safe to assume that people who take their laptops to service shops know _nothing_ about security
> backup your data somewhere else, and wipe the device clean before handing it in.
Well over half the devices going in for repair cannot do that, that's why they're going in for repair.
> safe to assume that people who take their laptops to service shops know _nothing_ about security
Safe to assume that the people being judgmental online know nothing about the technical expertise of the average device owner.
I'd never take a device into somewhere with personal/sensitive information on it, but I recognize I am in an extremely privileged position in having the knowledge and expertise to do so. Even a fully broken screen wouldn't stop me from backing up/wiping. That isn't typical at all.
That needs to change. We create two user accounts for all of the laptops we give out. Someone working on the device only needs to have access to one of the accounts. Windows is still too stupid to hide user data from other users. But at least it's something.
All computers and phones should have such a recovery/repair mode.
I would not be surprised that if this continues to be a problem, then EU will mandate that repair should not be allowed to ask for password and that all devices must have a repair mode. It seems like a straightforward extension of GDPR.
I do not understand how this is being judgmental? How much do you know about the operation of a nuclear plant, or knee surgery? You are not expected to, same with cybersecurity where knowing to not share your password over a random phone call is already complicated to teach.
The technical guy you went to for help asking you "the numbers you type when the computer starts" sound completely legit.
In corporate settings key escrow may be used. Windows for example can store bitlocker credentials in AD.
Yes and no. Even the least-skilled young repair tech can ogle Hot_Bikini.jpg on impulse, with ~zero expectation of being caught, and an easy "victimless" rationalization. Vs. doing things you allude to would require a very different (and far rarer) sort of perp.
Given the CBC's limited resources, need for clicks, and (if they're sane) aversion to getting involved in serious crimes - using sexy pictures for their story was the right way to go.
CBC has been getting well over a billion dollars of taxpayer money each year lately, and they also have advertising revenue on top of that.
CBC does not have "limited resources".
FWIW, this looks to be CBC's latest quarterly financials -
https://site-cbc.radio-canada.ca/documents/impact-and-accoun...
- and I notice that both the taxpayer funding and advertising revenue have fallen year-on-year.
It's just hard for the mind to grasp how such a physically small device can grant access to so many things.
Maybe once we move more explicitly to phones as bionic extensions of ourselves, people will understand the access they're granting on a visceral, gut level.
Definition #1 vs. definition #2.
You're not born with any particular moral standard. You are taught one by the people around you. In fact I would say that it's likely there is a sizable population of earth that would consider you to be a piece of shit for things that you think are perfectly ok.
At the end of the day trusting random people means you're just rolling the dice.
https://cis-india.org/internet-governance/blog/revenge-porn-...
https://www.bankofcanada.ca/rates/related/inflation-calculat... says that $30 in 1999 is $50.80 in 2023. That doesn't sound underpaid to me.
I'd rather not get into it any more, they were cruel and unusual employers and did systemic mental abuse. My next employer at least paid minimum wage.
Vs. a "don't trust repair, just replace it" conclusion...
I'm personally more likely to trust Marketplace than not.
In January 2022, for example, a long-time former journalist with CBC discussed some objectivity and quality concerns:
https://tarahenley.substack.com/p/speaking-freely
Among the mainstream news organizations in Canada, CBC is, in my opinion and experience, the least-trustworthy and lowest-quality of them.
If you've got data or research that supports your argument that the CBC is, as a whole, deserving of such low quality and trust, I'm genuinely interested to hear it.
Otherwise, it just reads as ideological opposition as opposed to genuine criticism.
FYI, your source now contributes to the Daily Mail and Fox News. By her own admission she is staunchly against the "woke" agenda (whatever that is). Here's an interview with her that balances out your provided link - https://www.canadaland.com/tara-henley-cbc/
Some would tell me they had teenage boys who may have gone to porn sites and they were afraid that's how they were infected. I would tell them to please get their personal stuff off the machine, because I would be looking for anything out of order. I explained I may have to reinstall windows and I didn't want them to lose their files. They never would! So I would burn their stuff to CD-ROM and then reload it all and give them the CDs.
I was a friend, not a business. If we expect businesses to be decent or prudent with what's on our devices we are naive. Get your stuff off first, then bring in the device! Human nature is always unpredictable.
Human nature is always -un-predictable.
And then it's like, what do you expect? You're giving them your device with full access to troubleshoot problems, they're going to look around in the process. And in many cases of course there's some kind of NDA 'assumed'. The copying instances and what not are violations no question, but again, you're giving them full access. I'm not sure a good chunk of the 'my device needs fixing' public cares about this. As long as their device gets fixed and stuff isn't obviously, like, shared out.
That wasn't my read at all -- which bits specifically?
The sting operation they set in play seemed like really trapping the employees when in 8/10 cases they were probably just trying ot figure out what the problem was on the machines? USB and wifi disabled? but what issues did they report to the stores when submitting the cases?
Only when it is necessary to solve the problem, it does not excuse the tech looking for or even copying personal images.
How would you feel if you hired a plumber to fix a leak in your home, and you found them in the master bedroom rifling through the lingerie drawer? Or making copies of your family photo book they pulled out of a cabinet? Sure, they need access to the entire home to find the leak, but that does not give them blanket permission to just do whatever they want.
Or, a tool that encrypts the user's primary homedir for "service mode."
The average person is WAY more in danger of getting locked out than needing to protect against a theft or attack.
If a user comes in with a virus I would expect the technician to explain in educate where the virus came from. That would involve browser history and downloads.
If a technician worked on my device I would expect them to back it up in case of data loss. That data should be held until the end user is satisfied, then securely deleted.
You have to trust that your mechanic isnt going to make up some bogus shit to extract money from you.
You have to trust your plumber isn't making up bullshit and overcharging you.
You have to trust your doctor to not prescribe you unnecessary drugs. And your dentist to not toss in a few extra fillings.
Turns out you also have to trust your computer repair guy to not snoop on your shit.
The employee asked for a password but my kid is connected with his Microsoft account.
I created a 'bestbuy' account on the spot with some classic luggage pin because the employee had no idea what to do.
I guess that if my kid went alone, he would have given the ms account password and the employee would have been able to access everything on that account.
I do. All the time.
"It's as bad as it gets", he says, uploading his photos with GPS location data to iCloud, sync'ing his browser history to Microsoft, using keylogger-as-a-service Grammarly to write his article, having his online shopping history emailed to his GMail full of itemised shopping details and delivery addresses, leaving Google services to gather his GPS location in realtime on his trip home for live traffic data updates. "Those are personal photos!" he uploads to Facebook alongside an innocent group picture taken earlier, which Facebook does face recognition on and matches the people in the photo against the contacts list it stole from his phone. His drive home picked up on numberplate recognition cameras, and on neighbour's Ring doorbells. His phone scans the surrounding wifi SSIDs and reports them back to HQ. He enters the front door - "I had the weirdest experience just now", says his partner, "I got an advert on my laptop for something I was talking about with a friend, do you think Alexa or Facebook listen in to our conversations?". "I've been told that can't happen" he says, sitting down at his computer, which prompts him again to login with a Microsoft cloud account, then freezes momentarily as "Microsoft Compatibility Telemetry" takes all the available CPU. "Millions of personal details leaked from 23andMe" he saw in the news headlines[1]. An email arrives from a shop he walked past earlier which picked up his phone's bluetooth ID. His Kindle idles on the table, sending details of every book, every page turn, every passage highlighted, every note made. His car uploading the latest route and tracking data back to the manufacturer. His cloud password vault slowly leaking[2].
"The worst thing in the world would be if someone found out we were naked under our clothes" they both said in unison. "That's as bad as it gets". "Or if someone knew we went on holiday", she said. "Or had a bank account", he said.
----
Each of these companies told Marketplace in separate email statements that they are committed to protecting customers' privacy.". Yes, tech companies say that too. This article is a reminder that if we don't red-team, smoke-test, trial run, our business policies and regulations, we end up with words about how great they are while they aren't functioning or aren't existing.
[1] https://www.theverge.com/2023/10/7/23907330/23andme-leak-hac...
[2] https://duckduckgo.com/?t=ffab&q=lastpass+hacked+again&ia=we...
From a user experience point of view it's easier, and you get 'free' picture and video messages. From a tech / privacy / informed consent point of view it's horrible. That was 15 years ago and it's only got worse in terms of tech companies taking what they want and claiming they got consent after by pointing to a line of legalese buried deep in a page nobody reads.