Live data from Hacker News

Pixel Security

security.googleblog.com

71–80 of 152 posts

Re: Pixel Security

#71
post #59

Earlier quoted context omitted.

Nothing listed is a backdoor. US law means that Apple must turn over data when demanded by authorities. These are access logs or files stored on Apple servers. A backdoor would be granting access into your device so that authorities could access your non-icloud email, or data saved locally on device.

> Nothing listed is a backdoor. I'm baffled. I like to think of the quality of HN comments as much higher. Apple had options to make this data unavailable by design to themselves and to law enforcement. They chose a design so that they could provide this information. The phone does it without the user's consent. However, I understand that there are people who would rather redefine terminology to suit their cognitive…

It's not a backdoor because there is nothing bypassing the security of your iPhone.

All the data supplied comes from Apple's records, not your phone. If your phone was destroyed one day, and law enforcement requested this information the next, Apple would have no issue supplying it. They're not going to simply "not keep" records of your iTunes transactions and account details, for example.

Your complaints regarding the inability to use their product in a meaningful manner without letting Apple collect this data have merit.

Re: Pixel Security

#72

Earlier quoted context omitted.

It's funny, I'm this exact same boat. My pixel died a little after two week (which is the requirement to get a return). I filled out their warranty claim thing, and >48 hours finally got a response, which is a trouble shooting guide. I replied that I tried all that stuff, and had to wait another 2 days for another response (asking for information I already gave). I'm extremely disappointed. I thought with their whole…

If you bought it with a credit card, you might want to contact your card's customer service number. Most credit cards offer protection from this type of manufacturer "weaknesses".

Australia has really good consumer protection laws which protect against exactly this kind of problem.

https://www.accc.gov.au/consumers/consumer-rights-guarantees...

Re: Pixel Security

#73
post #43

Earlier quoted context omitted.

Google will never do anything that involves hiring O(N) employees to support N customers. They'll always outsource things like support, repairs, etc. so that someone else can handle scaling people, while they just go on scaling machines. Given that, the only real possibility is that "some random dude" is going to end up fixing your Pixel. On the other hand, the "who's never seen the Pixel before" part? C'mon, the pho…

If an i-device breaks on the first day and you take it to an Apple Store, the tech fixing it has: * A repair manual * Parts * Tools * The ability to replace your device on-the-spot with a new one if they brick it

When has an Apple Store had spares of their hot new phone available on the first day? A month out, sure, but come on.

Re: Pixel Security

#74
post #13

Just FYI in case anyone is considering buying a Pixel: I strongly urge you not to. http://kasrarahjerdi.com/2016/11/dont-buy-anything-made-by-g... They have no Google provided support, if you drop the phone and break it your only option (if you didn't buy the third-party warranty upsell) is to take it to a repair shop. I called the ones near me, none had seen or touched the device before. Don't spend $800 on a phone…

Have you ever tried to get something Apple branded repaired when it is out of warranty?

The repairs tend to basically cost as much as it would to buy the same item refurbished regardless of the issue.

SSD died on your MacBook air selling for $500 on eBay? That will be a $450 repair sir.

Sure, they may have manuals and everything else at the Apple store, but there is very clearly a reason why companies like iCracked and iFixIt exist, and it isn't because Apple offers such a wonderful and affordable repair shop.

It would be great if Google offered a way to get the phone repaired through them, but using Apple as an example of how it should be is a bit insane to me.

Re: Pixel Security

#75

Isn't the pixel the phone that was just pwned inside 60 seconds by security researchers? And doesn't google have a terrible track record of releasing data to federal agencies? So, aside from purchasing a phone that is built by data-mining, internet advertising giant, google can't even begin to make the claim that they value user security.

"pwned in 60 seconds" is a hugely misleading statement. Every time there's a hacking competition you see "Chrome, Firefox, IE fall in seconds" - ignoring the weeks or months that it takes to find the vulnerabilities and develop exploits for them.

Re: Pixel Security

#76

Earlier quoted context omitted.

If an i-device breaks on the first day and you take it to an Apple Store, the tech fixing it has: * A repair manual * Parts * Tools * The ability to replace your device on-the-spot with a new one if they brick it

When has an Apple Store had spares of their hot new phone available on the first day? A month out, sure, but come on.

Got my iphone 7p on the 1st week, noticed some small debris in the lens, went to my local Apple Store, they had the same device ready in stock as a replacement, in&out took 10 mins. (note my device is probably one of the most wanted one, Unlocked-128 black)

Re: Pixel Security

#77

Isn't the pixel the phone that was just pwned inside 60 seconds by security researchers? And doesn't google have a terrible track record of releasing data to federal agencies? So, aside from purchasing a phone that is built by data-mining, internet advertising giant, google can't even begin to make the claim that they value user security.

Like all phones including iPhones https://www.hackread.com/hackers-get-100k-for-hacking-nexus6...

Re: Pixel Security

#78
post #43
post #23

Earlier quoted context omitted.

I called the uBreakiFix in Denver: "we've never seen that phone before, but yeah I think I could fix it". I'm not upset that they don't have an accidental damage warranty, I'm upset that I can't send it to them and pay them the $100/$200/$300 or whatever it is directly for _them_ to fix it, not some random dude who's never seen the Pixel before.

Google will never do anything that involves hiring O(N) employees to support N customers. They'll always outsource things like support, repairs, etc. so that someone else can handle scaling people, while they just go on scaling machines. Given that, the only real possibility is that "some random dude" is going to end up fixing your Pixel. On the other hand, the "who's never seen the Pixel before" part? C'mon, the pho…

So oursource it.

Send your pixel to our authorized repair shop here. They will bill you.

Re: Pixel Security

#79

Earlier quoted context omitted.

It's funny, I'm this exact same boat. My pixel died a little after two week (which is the requirement to get a return). I filled out their warranty claim thing, and >48 hours finally got a response, which is a trouble shooting guide. I replied that I tried all that stuff, and had to wait another 2 days for another response (asking for information I already gave). I'm extremely disappointed. I thought with their whole…

If you bought it with a credit card, you might want to contact your card's customer service number. Most credit cards offer protection from this type of manufacturer "weaknesses".

I was thinking about it, my credit card has always been extremely good about stuff like this. However, I use google for everything, my entire life is on it. I'd rather lose the $649 I paid for the pixel, then get blackballed from google services.

So for now, I'm just patiently awaiting their response and hopefully they'll give me the green light to mail it in for a replacement or something.

Re: Pixel Security

#80

Isn't the pixel the phone that was just pwned inside 60 seconds by security researchers? And doesn't google have a terrible track record of releasing data to federal agencies? So, aside from purchasing a phone that is built by data-mining, internet advertising giant, google can't even begin to make the claim that they value user security.

"pwned in 60 seconds" is a hugely misleading statement. Every time there's a hacking competition you see "Chrome, Firefox, IE fall in seconds" - ignoring the weeks or months that it takes to find the vulnerabilities and develop exploits for them.

It's not misleading, the issue is that your actual phone could be actually compromised in 60 seconds time, not some giant period of guessing and trying or cracking a complicated crypto scheme. The research time isn't material to the severity of the threat at the time of attack.
Post reply on HN