Live data from Hacker News

Pixel sent to Google for replacement. They used it to post wife's nudes online

old.reddit.com

311–320 of 381 posts

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#311

It was deleted. Here is the OG Text: "Ok so this just happened. Buckle up. About a month ago my wife broke her pixel phone. It couldn't be turned on so we couldn't wipe it. We contact Google and used the device care to get an RMA. Today someone posted nude pictures of my wife and I to her social media accounts. They accessed her Google account and tried to lock us out. They used her PayPal to send someone $5 (a test…

> my big question is whether this phone is password enabled

I read all the comments before it was deleted. In one of the replies the OP stated the phone had a smashed screen and would not turn on*, but had no screen lock/password

*his words not mine, it is unclear if he knew the distinction between zero display output and not turning on

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#312
post #158

Earlier quoted context omitted.

> BUT, you must be pretty stupid to send a device away that contains sensitive information. Irrelevant

It is relevant because there's a massive deficit in basic infosec among the populations of the world. Why keep blaming big corporations when we need to get smarter ourselves?

Why not both? Blame the corporations, sue the heck out of them, but then also make good infosec more widespread.

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#313
Somewhat related, but not long ago my Macbook had a bulging battery issue and the Apple just flat refused to service it under warranty because I would give them the credentials to unlock the bios. The "genius" told me "but you leave your keys when you drop your car at the garage!".

I had to send the computer across the country for corporate IT to wipe it before getting it serviced, for a battery replacement..

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#315
post #51

Earlier quoted context omitted.

>> I see it every time the topic comes up I hear you, and agree wholeheartedly that there is "absolutely nothing wrong with this", but maybe if the topic keeps coming up, people should have less trust in the companies (and their respective flawed human supply chains) that keep our information.... and act accordingly. Unfortunately that's easier said than done these days.

Sure, but you probably wouldn’t ever hear someone say “maybe you should have had less trust” if Google employees snooped on your Drive account to steal financial records or something like that to use against you. Why do we tend to treat people like they’re asking for it when their nudes get compromised?

> you probably wouldn’t ever hear someone say “maybe you should have had less trust”

No you would hear the exact same thing. My sensitive data on the cloud is all encrypted. Have you ever seen anyone suggesting to do backup on any cloud platform in any other way than encrypted? That's because the data is sensitive and you can't trust whoever store it for you.

> Why do we tend to treat people like they’re asking for it when their nudes get compromised?

We do that over anything that is sensitive. It's just that nowadays, people no longer consider much of their things sensitive... except nudity.

I agree entirely that we should be able to trust companies and I agree completely that the biggest issue is on them, but the thing is, we will never be able to trust them fully, there's just too much to handle. I'm not saying not to push the responsibility on them, for sure we need to do that or it's gonna be even worse, but we also need to remind people to consider their data security and how they handle it. Both are essentials if we want to lower the number of instance of theses happenings.

I'm curious, if I upload nude picture on my Google Drive and with the password "potato", and then my picture were published by someone that guessed my password. Wouldn't you suggest a stronger password? Still a victim, but still good to suggest ways to avoid it in the future.

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#316
post #259

Earlier quoted context omitted.

It's not just about feeling smart and superior, it also helps them feel invulnerable. People victim-blame smokers who get lung cancer because they don't want to think about the chance they might get it too.

Smoking a pack a day for 30 years is not really the same thing as making a momentary error in judgement. Yes, non-smokers can get lung cancer, too. But at a far lower frequency.

You're not wrong, but you're missing how people become smokers. "Approximately 90 percent of all smokers start before age 18; the average age for a new smoker is 13." [1] A momentary error in childhood judgment (to the extent that isn't an oxymoron) quickly becomes an addition. "Inhaled smoke delivers nicotine to the brain within 20 seconds, which makes it very addictive—comparable to opioids, alcohol and cocaine." [2] Once they're hooked, it's very hard to quit [3], so it's often a life-long addiction. And that's before we even get into all tobacco companies have done to hook people.

So even as a life-long nonsmoker who absolutely hates smoking I think there's a lot of unnecessary victim-blaming for smokers.

[1] https://www.cdc.gov/tobacco/data_statistics/fact_sheets/yout...

[2] https://www.camh.ca/en/health-info/mental-illness-and-addict...

[3] https://www.heart.org/en/news/2018/10/17/why-its-so-hard-to-...

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#317

Earlier quoted context omitted.

Absolutely. "They deserved it for sending in an unwiped phone" is victim blaming. "If you need to send in your phone, you can do X and Y to protect yourself" is absolutely NOT victim blaming. I cannot wrap my mind around why people would have a problem with the second statement.

You are blaming the victim because you think you are beyond failure. Someday you might be hacked. Is it your fault for using technology at all knowing you can be hacked?

> You are blaming the victim

I am not. For you to interpret helpful advice as blame is some serious mental gymnastics. "If you need to send in your phone, you can do X and Y to protect yourself" does not assign blame to anyone.

> Someday you might be hacked. Is it your fault for using technology at all knowing you can be hacked?

Why are you so obsessed about assigning blame? Do you think everyone should ignore security best practices, since its not their fault if they get hacked?

Go ahead and set your HN password to "password", please. It wouldn't be your fault if you got hacked, so why would you care if I knew your password?

To actually answer your question, no. It would not be my fault if I got hacked. But I don't want to get hacked, so I take reasonable steps to avoid being hacked anyway. I am an adult with the responsibility and agency to take care of myself.

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#318
post #99

Earlier quoted context omitted.

I don't see a contradiction here. It's terrible that Google allowed this to happen, and the individuals responsible should be held to account. Also, it is a good idea to be very protective of nude photos. I found the original comment useful for thinking about how I could avoid this situation personally.

It's a great thing to teach your children. Not to tell adults after their privacy has been violated. Do you really find it a useful comment? Was it not an immediately obvious conclusion that none of this would have happened if they had just fired their phone into outer space rather than hope to have their warranty honored?

I actually did find it useful. Yes its obvious that destroying a phone would prevent photos leaking, but it didn't occur to me that this might be a good default position for me to take when considering sending in my phone for repairs, as horrific as that is. I would probably have just trusted google/apple too.

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#319

Earlier quoted context omitted.

Thanks for posting this. I get why people do the victim-blaming thing; it lets them feel smart and superior, two feelings I have been known to enjoy. But it's a fundamentally bad way to approach analyzing safety issues. For those who really want to dig in on the topic, I strongly recommend Dekker's "A Field Guide to Understanding 'Human Error'": https://www.amazon.com/gp/product/B00Q8XCSFI/ref=dbs_a_def_r... It's nom…

This has entered programming language design. It's not longer "educate the programmer so he doesn't make stupid mistakes", but "design the language so that stupid mistakes are detected by the compiler". Mechanical verification is far more reliable than hoping people don't make mistakes.

Yeah, the "you should wipe your phone!" and "you should never keep sensitive data on your device!" chorus seem to be missing the point entirely:

We can design devices and operating systems to be safe by default in the same way we are now designing programming languages to be safe by default. There's no reason why the data should have been recoverable from a bricked phone without the user's authentication.

We really can have our cake and eat it too - we can have devices that you can freely store nudes on without risking that some rando with a USB cord and physical access can just make off with the data, bricked device or otherwise!

Re: Pixel sent to Google for replacement. They used it to post wife's nudes online

#320

Earlier quoted context omitted.

It would have mattered because you can deauthorize a device from your Google account on a computer, like a phone and if they are saved locally as well you can remove SD card before sending it back. The only thing I'm unsure of is if thumbnails are saved in a standard image format but those should get removed as well during the notification that the device has stopped syncing, but if mobile data is turned off it may c…

Where's the SD card on a Pixel?

I'm not saying it has one, again the point was for people RMA'ing devices in the future to help prevent issues like this. A startup password with encryption could have helped prevent this.
Post reply on HN