[HN Gopher] Google Pixel mail-in repairs have allegedly twice re...
       ___________________________________________________________________
        
       Google Pixel mail-in repairs have allegedly twice resulted in
       leaked pics
        
       Author : arkadiyt
       Score  : 21 points
       Date   : 2021-12-05 20:12 UTC (2 hours ago)
        
 (HTM) web link (www.theverge.com)
 (TXT) w3m dump (www.theverge.com)
        
       | vecinu wrote:
       | Serious question brought up in the article but say my Pixel phone
       | died and I can't turn it on at all, how do I delete all my local
       | data on it without being able to flash it or connect it to my PC?
        
         | foepys wrote:
         | That's why I don't buy phones without an SD card slot and put
         | everything on an SD card. If only everybody were doing this...
         | I hate all those upselling tactics where they want you to pay
         | for more storage.
        
         | ddingus wrote:
         | You probably don't. I had that happen.
         | 
         | In my case it was the charging chip. I took it apart, installed
         | charged battery and got the data, then wiped it.
         | 
         | Had that not worked, I would have just kept the phone.
        
       | throwaway81523 wrote:
       | All built-in storage in the phone should be erased as part of the
       | intake process, the minute the phone arrives at the repair center
       | and they take it out of the box.
       | 
       | If microsd cards didn't suck so much, I'd prefer phones to have
       | no built-in storage at all. The Raspberry Pi is nice that way.
       | You have to insert a card in order to use it. Phones could be the
       | same way. Then the phone's RMA instructions would tell you to
       | remove the card before sending the phone in for repairs.
        
       | kadoban wrote:
       | How was the phone accessed? Don't Pixels enforce passwords and an
       | encrypted drive?
        
       | dredmorbius wrote:
       | Is there any indication that the unauthorised access occurred at
       | the repair facility, or was the package diverted and accessed
       | elsewhere, perhaps by the package delivery service?
       | 
       | The levels of trust and potentials for betrayal are high here.
       | 
       | It's also worth considering that an old-school camera, in which
       | storage media (film) and the device itself (the camera) were
       | entirely separate posed a different privacy and surveillance
       | threat profile. On the one hand, one could provide a camera to a
       | repair facility with no fear of information disclosure. On the
       | other, film-processing labs themselves could view the images
       | taken, and there are at the very least anecdotal stories of both
       | voyeurism and identification of crimes and abuse which occurred
       | as a result.
       | 
       | With digital devices, there's a potential insulation against the
       | latter case (usually for single-purpose devices, e.g., a
       | dedicated digital camera without any networking capabilities ---
       | a smartphone is a security risk regardless of use), but if you're
       | submitting a device with integrated storage for service, your
       | privacy is at risk.
        
       ___________________________________________________________________
       (page generated 2021-12-05 23:02 UTC)