Live data from Hacker News

Pixel Security

security.googleblog.com

101–110 of 152 posts

Re: Pixel Security

#101

Earlier quoted context omitted.

Your framing is disingenuous, considering that any large company will have staff ready to respond to legal / discovery demands. This is a legal process, not something Apple is doing out of their own volition.

I'm sure all large companies have staff to handle these requests for information, but this is the first time I've heard of a company creating a team that does nothing but hand over customer data 24 hours a day. Apple VP Lisa Jackson: >Please know that Apple will continue its work with law enforcement. We share law enforcement’s concerns about the threat to citizens and we work closely with authorities to comply with…

Plenty of telecoms have had 24 hour abuse desks, which generally handled this sort of thing. Even more specialized departments for law enforcement in the huge majors and you always had a 24x7 on-call legal counsel if needed. It is absolutely possible to get someone on in real time if you are Important(tm) enough and have a lawful reason that is life critical in nature.

Facebook, Google, Apple, Twitter, etc. all pretty much fall under the "telecom" label these days in what they do, so it's not surprising in the least.

Just expanding on that - not dipping my toe into any other part of this debate!

Re: Pixel Security

#102

Earlier quoted context omitted.

Have you ever tried to get something Apple branded repaired when it is out of warranty? The repairs tend to basically cost as much as it would to buy the same item refurbished regardless of the issue. SSD died on your MacBook air selling for $500 on eBay? That will be a $450 repair sir. Sure, they may have manuals and everything else at the Apple store, but there is very clearly a reason why companies like iCracked a…

This is just nonsense. In some cases the repair may cost the same as refurbished item but definitely not always. And remember that refurbished item is not new so it's not guarenteed to last for ever either. Cracked screen repairs for example aren't the same price as a new iPhone. At least with Apple I can drive to a physical store, hand my laptop or phone over and know it will be repaired properly. And in many cases…

A few points:

1. Cracked screens are incredibly easy to fix, so the one example you can give that doesn't cost an arm and a leg is the one thing that arguably any random repair shop should be able to do.

2. Not everyone even lives near an apple store, so while you might benefit from driving in to a physical store, there is a large chunk of the population who won't (at least not without driving a few hours).

PA is a great example of this - the only stores in PA are basically around Philly and around Pittsburgh. Live anywhere else in the state and you are driving to a store out of town.

That isn't so bad if prices are reasonable, but when you get there and hear "$600 to replace the battery" the stores start to feel less useful.

I understand that there is value in the Apple store. I'm not trying to say that there isn't any, but I do believe the original comment overstates that value, especially when Google (or a third party they work with) offers a pretty reasonable replacement plan as an add-on to your purchase.

Re: Pixel Security

#103

Earlier quoted context omitted.

If you bought it with a credit card, you might want to contact your card's customer service number. Most credit cards offer protection from this type of manufacturer "weaknesses".

I was thinking about it, my credit card has always been extremely good about stuff like this. However, I use google for everything , my entire life is on it. I'd rather lose the $649 I paid for the pixel, then get blackballed from google services. So for now, I'm just patiently awaiting their response and hopefully they'll give me the green light to mail it in for a replacement or something.

I think that the parent is saying that your credit-card company might be the 3rd party insurance, and you might be able to make a claim to take advantage of that insurance.

Re: Pixel Security

#104

Earlier quoted context omitted.

This is just nonsense. In some cases the repair may cost the same as refurbished item but definitely not always. And remember that refurbished item is not new so it's not guarenteed to last for ever either. Cracked screen repairs for example aren't the same price as a new iPhone. At least with Apple I can drive to a physical store, hand my laptop or phone over and know it will be repaired properly. And in many cases…

A few points: 1. Cracked screens are incredibly easy to fix, so the one example you can give that doesn't cost an arm and a leg is the one thing that arguably any random repair shop should be able to do. 2. Not everyone even lives near an apple store, so while you might benefit from driving in to a physical store, there is a large chunk of the population who won't (at least not without driving a few hours). PA is a g…

> 1. Cracked screens are incredibly easy to fix, so the one example you can give that doesn't cost an arm and a leg is the one thing that arguably any random repair shop should be able to do.

Provided you can find spare parts, good luck finding spare parts for the Pixel. For Apple products it's usually a breeze.

Re: Pixel Security

#106
post #13

Just FYI in case anyone is considering buying a Pixel: I strongly urge you not to. http://kasrarahjerdi.com/2016/11/dont-buy-anything-made-by-g... They have no Google provided support, if you drop the phone and break it your only option (if you didn't buy the third-party warranty upsell) is to take it to a repair shop. I called the ones near me, none had seen or touched the device before. Don't spend $800 on a phone…

The author needs to take responsibility for own actions. The phone stopped working correctly after the author damaged it.

heh, it's my phone, i broke it, I'm out a chunk of money. I am fully aware of that. I'm upset that I can't pay a small increment of money to a trusted source to remedy that. I have never felt the need to have a case on a phone before (I am a mobile developer and have dozens of phones) because all my other ones have been able to survive falls of that intensity.

I'm sad that I'm out some money, and I definitely think I am at fault, but I don't think I'm being unreasonable.

Re: Pixel Security

#107
"We then modified the inline encryption block driver to pass this to the hardware. As with ext4 encryption, keys are managed by the Linux keyring. To see our implementation, take a look at the source code for the Pixel kernel."

It doesn't sound like they got these changes into mainline. They link here to their source: https://android.googlesource.com/kernel/msm/+/android-msm-ma...

From that file:

    /* TODO(mhalcrow): Just for proof-of-concept */
WHOOPS!

Re: Pixel Security

#108

Earlier quoted context omitted.

> Apple of course backdoors their phones for government surveillance access. Nice job slipping a completely unfounded lie into your response. Starting with iOS 10, you can actually just mount the root filesystem disk image from iOS restore images. You are able to reverse engineer and audit any application or daemon that the OS runs. You can use open source tools (Such as idevicerestore) to perform an OS restore on yo…

How can you say you're able to audit any application or daemon without viewing the actual source code? Case in point - if the sslKeyExchange.c code had not been published the "goto fail" bug would likely still be in the wild.

Reverse engineering tools like IDA can be used to audit closed source code. However, this takes significantly longer than reading source code, and it's not exactly feasible to audit the entire operating system for something (hypothetically) intentionally hidden.

Re: Pixel Security

#109
post #14

Google security is so strong, they'll even lock you out of your own account when changing cities, with no chance to get it reinstated : https://www.reddit.com/r/Android/comments/5dif8j/psa_google_...

Somehow I feel we aren't getting the whole story there... Why would they ask for identification then close it after he provides correct identification?

> Somehow I feel we aren't getting the whole story there...

Well, yes, since Google isn't providing their part of the story.

I have no reason to think the OP of that thread is misleading, I believe from their perspective it is an accurate account. You don't have to go too far to read similar accounts from others who got suspended over Google Pay/Google Checkout fraud flags.

Unless Google comes out and says the OP missed out key information, I'm going to just assume OP is telling us everything they know from their perspective.

Re: Pixel Security

#110
post #87

Earlier quoted context omitted.

In this case, if we're comparing to cracked screens, Apple charges $129/$149 on their iPhones.

I realize you are just providing info, and I appreciate it, so I want to preface this by saying I am also just trying to add some context to the conversation. The pixel offers a $99 replacement plan, plus an additional $99 every time you replace the phone, up to 2 times. I think it lasts for 2 years. If the only thing holding you back on getting the phone is being able to get it repaired, the cost difference is $70 o…

Right, it's very similar to most plans where you break even around ~2 screen replacements. Like you said, if you have to utilize the insurance for things aside from the 2 screen replacements, then you come out even further ahead.

But that requires foresight in buying the insurance and most people just don't have that. In my case, I have only ever broken one phone, so buying insurance with the idea that I break even at ~2 incidents would not be worth it for me. In the Pixel's case, I would like the option to pay full fees for fixing rather than only the option of previously having had foresight AND having to break my phone twice.

Post reply on HN