And people wonder why Apple wants to try to keep control of iPhone repair processes. This is one of the big reasons why.
Apple repair nude will get you there
101–110 of 381 posts
And people wonder why Apple wants to try to keep control of iPhone repair processes. This is one of the big reasons why.
Apple repair nude will get you there
I’ve taken my iPhone to a couple of repair shops. They always ask for the pin code and I always refuse and say it’s a work phone. Very much hoping the secure enclave works and my data has not left the phone.
I've lost a laptop in an airport shuttle with intimate pics on it once, and got worried sick. After that life lession, I always made sure to have a veracrypt partition for this stuff. But a separate, offline device is better of course.
Modern Android actually does support disk encryption. And the Pixels even have TPMs that should (?) safeguard the key, preventing offline brute forcing the unlock pattern. I wonder what happened here that this did not work...
Earlier quoted context omitted.
I wonder if there is a way to connect to it through usb in order to wipe it.
It might not be possible to wipe the data off the flash memory, due to how flash memory works. As you can only reset bits on the flash memory some amount of times, flash memory controllers try to avoid resetting bits and they try to distribute resets evenly on the memory (called wear leveling), so that it doesn't happen that parts of the memory are already worn out while other parts are healthy. So "deleting" and eve…
If you're worried about a state removing the flash chips to recover data from dead/used cells, you don't send your phone in for repair. You secure the data with a drill before disposing of it. That clearly wasn't the owner's concern. They wanted a method for securing the device, but couldn't due to the screen. This is in no way the owner's fault. I can't say I blame them wanting to have a working phone and not a very expensive paper weight.
A better method for securely erasing data from a phone before service is in everyone's best interests. The customer's data isn't at risk, the manufacturer has significantly reduced liability, and the vendor doing the work doesn't have to worry about employees doing something stupid like this and risking their contract with Google. You really just have to make the process of getting the data off the phone slightly more difficult to avoid casual theft (infringement? -- I don't know the right word here).
We need to educate people on how to secure the data on their phones so that even the manufacturer cannot reach it. And if that is not possible for a particular device, that should be clearly understood so people can make an informed choice about what smartphone they use. Can't just tell people 'do not put nudes on your phone' because while it's good advice, it misses the point. And, of course, whoever does something…
I’ve taken my iPhone to a couple of repair shops. They always ask for the pin code and I always refuse and say it’s a work phone. Very much hoping the secure enclave works and my data has not left the phone.
Earlier quoted context omitted.
Factory reset Android will securly wipe the data.
That doesn't help if the phone is broken. My personal policy is to just keep all of my old devices (and hard drives, for that matter) forever.
Earlier quoted context omitted.
This is FUD. Flash is fundamentally easier to wipe than hard disk drives. You’re just using a defective mental model for the process. While magnetic recording needs to be overwritten, flash memory does not. Flash has a dedicated erase command. Flash can only be written if it was erased. You can erase an entire flash device in a split second.
I guess it is true that you can erase an entire flash device in a split second. But that doesn't help you if the erase command was not implemented correctly. And I am sure that you cannot implement an erase command from within the operating system. It has to be implemented in the flash memory controller. So if your hardware manufacturer got it wrong, you can't fix it.
We tested ATA commands for sanitizing an entire SSD, [...]. We find that while most implementations of the ATA commands are correct, others contain serious bugs that can, in some cases, result in all the data remaining intact on the drive."
M. Wei, L.M. Grupp, F.E. Spada, S. Swanson: "Reliably Erasing Data From Flash-Based Solid State Drives." https://www.usenix.org/legacy/events/fast11/tech/full_papers...>
Earlier quoted context omitted.
I feel like removable SD card is a tech person solution but ... kinda doesn't solve it for a lot of folks. Most folks are just going to take nudes and not strategize much and expect them to remain private as part of the typical photo taking and sharing workflow.
> I feel like removable SD card is a tech person solution but... As an older person, I find this observation very interesting. Today, I would consider people in general to be much more technically knowledgeable compared to people 20+ years ago. And yet, 20 years ago, removable storage was quite common, and probably expected of most devices.
I'm pretty technical (As is nearly everyone on HN), and I have no idea where my photos are stored on my Android's file system. I have no idea where the APKs are for all my installed apps, or where their saved data sits.
Earlier quoted context omitted.
Modern Android actually does support disk encryption. And the Pixels even have TPMs that should (?) safeguard the key, preventing offline brute forcing the unlock pattern. I wonder what happened here that this did not work...
I wonder what kinds of tickets, if any, justify them asking you for your unlock pattern.
Unable to help me with my problem at first (we eventually figured it out), they felt they hit a dead end and said: "ok, just send us your wallet.dat, we'll fix it".
I know those guy were the real deal. I knew they would not try to steal the money I had on this wallet, because it was so little it was not even worth the time.
Yet, the fact they asked that proves how much support can badly educate their users.
Of course, I didn't send my wallet, and found another solution since I'm tech saavy. But still...