Live data from Hacker News

Pixel sent to Google for replacement. They used it to post wife's nudes online

old.reddit.com

111–120 of 381 posts

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#111
I used to work at a att store. This is common. One particular incident involved a ring of workers at multiple stores who had a shared Dropbox they would upload anything they found to. Any time you hand your phone over to underpaid 20 year old guys you should be erasing everything sensitive

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#112
Last time I sent a phone into repair, I wiped and reset it, presumably so that techs could test it properly (broken screen and digitizer). I wish I didn’t have to; but when you’re logged into everything, your bank is there too, and your phone is the second factor in a lot of things, damn it’s too much of a risk.

I wish phones could boot into some kind of field tech/diagnostics mode where all aspects of hardware could be tested as thoroughly as needed. Maybe there exists one and I’m just ignorant?

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#113
post #74

I've lost a laptop in an airport shuttle with intimate pics on it once, and got worried sick. After that life lession, I always made sure to have a veracrypt partition for this stuff. But a separate, offline device is better of course.

Modern Android actually does support disk encryption. And the Pixels even have TPMs that should (?) safeguard the key, preventing offline brute forcing the unlock pattern. I wonder what happened here that this did not work...

Someone else here mentioned that the the reddit comments (now deleted) said that the phone had no passcode on it, so anyone would be able to unlock it.

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#114
post #74

I've lost a laptop in an airport shuttle with intimate pics on it once, and got worried sick. After that life lession, I always made sure to have a veracrypt partition for this stuff. But a separate, offline device is better of course.

Modern Android actually does support disk encryption. And the Pixels even have TPMs that should (?) safeguard the key, preventing offline brute forcing the unlock pattern. I wonder what happened here that this did not work...

Seems OP never had a password lock to begin with

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#115
It was deleted. Here is the OG Text: "Ok so this just happened. Buckle up.

About a month ago my wife broke her pixel phone. It couldn't be turned on so we couldn't wipe it.

We contact Google and used the device care to get an RMA.

Today someone posted nude pictures of my wife and I to her social media accounts. They accessed her Google account and tried to lock us out. They used her PayPal to send someone $5 (a test probably).

How could this happen? Well Facebook and Instagram show logins from Texas. The old phone still showed on our find my phone app and it was in Texas. Guess where we sent the phone for RMA? The last ping from the old phone (which was today) was the same as the place we shipped it. The exact location down to the very building. Clearly they fixed the old phone and since it wasn't wiped, was still logged into her Google account.

I called Google and they basically said "woah that's fucked up we'll get back to you". We filed a police report but I don't expect they will do anything.

What are my options here for sueing Google? I know that sounds insane but this breach of trust and privacy is egregious. Hundreds of people have now seen my penis including our friends kids. It's really fucked up.

Any advice on what to do here?"

my big question is whether this phone is password enabled. also this stinks because i know the first comment is "well do a factory reset" but if the phone doesn't turn on, etc. then i don't believe that is possible (short of possibly ADP which is out of the reach of 99% of people)

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#116
post #71

Earlier quoted context omitted.

> I feel like removable SD card is a tech person solution but... As an older person, I find this observation very interesting. Today, I would consider people in general to be much more technically knowledgeable compared to people 20+ years ago. And yet, 20 years ago, removable storage was quite common, and probably expected of most devices.

You can be older and a tech person, I'm older ;) People are more capable but security like this needs to just be a part of the usual workflow or problems will continue to occur. Moving files around on a device, extra steps, just doesn't work for the masses.

I'm young-ish, but my general observation has been that my peers forget it was our grandparents and great grandparents that invented computers in the first place.

Admittedly, the technological world is nearly impossible to avoid exposure to these days, where it was entirely optional (or downright prohibitive) to be involved with in the past.

So in general, thank you older people for creating them, I have a lot of fun with them.

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#117
post #80

Earlier quoted context omitted.

It might not be possible to wipe the data off the flash memory, due to how flash memory works. As you can only reset bits on the flash memory some amount of times, flash memory controllers try to avoid resetting bits and they try to distribute resets evenly on the memory (called wear leveling), so that it doesn't happen that parts of the memory are already worn out while other parts are healthy. So "deleting" and eve…

This is FUD. Flash is fundamentally easier to wipe than hard disk drives. You’re just using a defective mental model for the process. While magnetic recording needs to be overwritten, flash memory does not. Flash has a dedicated erase command. Flash can only be written if it was erased. You can erase an entire flash device in a split second.

Flash storage controllers which do not properly implement secure erase are extremely common and nearly impossible to verify.

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#119

I’ve taken my iPhone to a couple of repair shops. They always ask for the pin code and I always refuse and say it’s a work phone. Very much hoping the secure enclave works and my data has not left the phone.

Even the Apple store does this when you take your phone for repair. I only did it once and they did a crap job anyways (screen replacement, and they got dust in the camera lens area somehow).

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#120

We need to educate people on how to secure the data on their phones so that even the manufacturer cannot reach it. And if that is not possible for a particular device, that should be clearly understood so people can make an informed choice about what smartphone they use. Can't just tell people 'do not put nudes on your phone' because while it's good advice, it misses the point. And, of course, whoever does something…

> how to secure the data on their phones so that even the manufacturer cannot reach it If that were possible, the FBI would shut it down.

Haven't they fought Apple on that in the past? AFAIK they still have to rely on exploits to get past the pin code. If that's not true I'd like to know.
Post reply on HN