6 ms·
>At the Apple Store, they also asked for the password, but when I said no way, the support person was just "ok, no problem". Can we take a moment to realize ho
by bussierem 5y ago
>At the Apple Store, they also asked for the password, but when I said no way, the support person was just "ok, no problem".
Can we take a moment to realize how crazy this is? I'm glad they didn't fight you, but the fact that they didn't means that they know in an instant that _they never needed the password in the first place to do what you asked them to_. This means that them asking for the password is them asking you for the private key to your entire personal life for no other reason than "most people will give it to them".
- Wowfunhappy 5y agoIt could mean that they just won't do as much testing if they don't know the password, which means there's a greater risk you'll get your computer back and discover there's still something wrong with it. Which might also be a perfectly reasonable tradeoff, but there's nothing inherently nefarious about it. And people can make different choices depending on the amount of private information on their laptop.
- onedognight 5y agoThey NetBoot in order to run diagnostics. They don’t need your password.
- Wowfunhappy 5y agoAutomated tests don't catch everything.
- michaelt 5y agoThe article is about someone's iphone being repaired - surely you can't netboot a locked iphone?
- saagarjha 5y agoIt should still be able to run diagnostics.
- patwolf 5y agoI once refused to give my MBP password to the technician at the Apple store for some hardware repair, and he said that they just wouldn't be able to verify the repair completely. I'm not sure how true that was, but it did catch me off guard that they would even ask for a password.
- volkl48 5y agoHaving done this kind of support before (mixed hardware + software), a large number of people present their computer with multiple vague problems that can very well be a set of issues with both the actual physical hardware AND with whatever they have done to their actual user account on their operating system. Most want all their problems fixed with as little action required on their part as possible, with as much certainty as possible, and do not care about security in the least. People are hard to reach once they are out of your sight, and get very unpleasant when things take a while....even when they take a while largely because they didn't get back to you in a timely manner (because you turn out to actually need their password to troubleshoot their configuration). "Wipe the device and start fresh" is understandably not a valid solution to most users (especially as anything other than last-resort), even though it'll rule out a large portion of potential software problems. --------- To note on some other elements I see in this thread: - Hardware diagnostics exist in some form on most devices. They do not catch every problem that exists, and are often especially bad with more intermittent issues. If the complaint is that Facetime drops out after 10 minutes, the most certain you can be that the issue is resolved is by running those diagnostics AND booting to their actual user account and having Facetime work for 15 minutes. No one cares that "it passed the Camera diagnostic" when they've still got a problem when they get home with their "fixed" device. Many people actively want you to be signed into their account and do exactly what they did to confirm the issue no longer happens. - IIRC you can't actually boot a modern (T2) Mac to an external drive without an Admin password being entered at least once to change the Startup Security Utility settings. - Whether being run as a business or as internal support in an organization (more so a college or the like with personally owned devices), time matters. Getting credentials from everyone who's willing regardless of if they turn out to be necessary is absolutely terrible security practice, but great for turning around repairs more quickly and with fewer repeats of devices coming back because the issue isn't fixed. -------- tl;dr - Sensible security practices are at odds with everything else the average person wants from their computer repairs.
- ghaff 5y agoSimilar with restoring account access that's been lost for some reason. Certainly, there are good practices and better practices. But somewhere between show up in Cupertino between 10am and 1pm on Friday with these notarized documents and just restoring access because someone requested it in some unverifiable way, there is a large spectrum of tradeoffs. ADDED: And, indeed for a sufficient threat model, the correct answer if a laptop or phone breaks is to throw it out and get a new one. It would be rather paranoid, but it would be the safest thing. Personally, I have backups usually so my general attitude would be no password, fine to wipe the device.