5 ms·
Any time I turn in a macbook for repair they demand my admin password. Fuck off. Erase it, I’ll restore, but I’ll never give you access. They are trained to ma
by mozman 4y ago
Any time I turn in a macbook for repair they demand my admin password. Fuck off. Erase it, I’ll restore, but I’ll never give you access.
They are trained to make you feel like you have something to hide.
- contingencies 4y ago
- boosteri 4y agoDon't understand the downvotes.. you gotta vote with your wallet. Anyone asking for a password immediately loses all credibility in my eyes. And besides, Apple churns out a lot of hype around their good privacy policies; it is good to know that not everything is gold dust when it comes to them.
- Godel_unicode 4y agoBecause the solution is pretty clearly “say no”. It’s a weird policy that they’re allowed to ask, but that’s about it.
- HKH2 4y agoIf you know that that is an option. How is that not a dark pattern?
- deleted 4y ago[deleted]
- stephen_g 4y agoIn my experience, They’ve always asked, but I’ve always refused and they say OK actually we can boot a test image another way (like their diagnostics thing that they boot from the network to run tests while you’re there).
- skorpeon87 4y agoSince they don't need it, they shouldn't even be asking in the first place.
- tpmoney 4y agoWhen I worked there back in the day, it was mostly a pro-active thing, especially for any repairs that weren't obvious hardware faults so that when/if something was fixed, we could validate that it was fixed for the actual user too. Customers for some reason I can't fathom (/s) absolutely hate it when they drop a machine off for repair, we "fix it" (by which I mean, do whatever or nothing and find that it works in a clean test image) and then when they take it home / turn it on at the store the problem remains because the issue was either software to begin with or a combination of hardware/software. They equally hate the "we told you your computer would be ready in 3-5 days, but we haven't been able to reach you for the last 5 days to get your password since we determined it was a software issue and we couldn't go any further so it's still going to be another few days" experience. So the default was to ask to make the experience as smooth as possible. But we were never instructed to pressure someone into giving up their password, just that we inform them upfront that without it all we can do is boot a test image to validate and that there's always the possibility software may play a part and still be a problem and we would want them to boot and confirm before leaving when they come to pick it up. Guest accounts were fine too. As was the customer giving us a formatted machine if they wanted. That was usually the best of the options because if the issue was present in a freshly formatted machine, we already rule out most / all of the software and we didn't have to deal with data loss issues (more than one customer signed the "I know I will likely lose data in this hard drive repair and I have a backup" line and then still pitched a fit when they did indeed lose data). Apple had very strong rules about customer data privacy and snooping around was a good way to get fired (and I knew one person who did get fired for it). In fact, I've worked in health care and frankly Apple's rules for data privacy and secrecy (both theirs and their customers) was far more stringent than the health care job. HIPAA says protected info is any combination of identifying information AND medical information[1]. So your address and phone number, not PHI. A list of all your medications with nothing that identifies you, also not PHI. Technically your list of medications with your "patient number" could also be "not PHI" if the only thing there is no reasonable way for the patient number to be tied to identifying information without having access to the other protected data. At Apple, all data was considered private and confidential and anything that wasn't required to be kept for record keeping was to be shredded when it was no longer needed, regardless of whether that data could have ever been connected back to a customer. Not to say that people don't abuse their access (again I knew someone who got fired for that), but at least in my time there they were very serious about only using the least access you needed and never told us to give anyone a hard time about wanting to keep their data private. [1]: https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/understanding/summary/privacysummary.pdf https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/un...
- doctor_eval 4y agoI had this experience a couple of weeks ago at an authorised repairer. They asked for my password, and I refused, but I was curious. So I said, "I'm surprised you're allowed to ask" and the guy said, "We're allowed to ask, but we're not allowed to insist". A few years ago my bank would ring me up every couple of weeks and say "Hi, I am calling from your bank, we want to talk to Doctor Eval(), can you please verify your date of birth and we can get started?". They would get so pissed off when I wouldn't tell them. I was like, "how do I know you're from my bank?". (Banks seem to have stopped doing this now). For companies which should be putting security at the centre of their business, they apparently have no idea that they're normalising phishing.
- Eisenstein 4y ago> For companies which should be putting security at the centre of their business, they apparently have no idea that they're normalising phishing. Yeah, this appears to have stopped, but was somewhat common a few years ago. My standard response was 'you called me, tell me who you are and I will call back on the official line'. They couldn't object to that. It was obviously some plan to 'ensure user privacy' that once it became known to one or two people with the authority to do something about it and the knowledge to know better it was quashed. Now if only they would allow you to enable 2FA options that aren't SMS and also disable SMS. They don't understand that SMS is a terrible 2FA system isn't mitigated by 'but you can enable other things' if you cannot remove SMS as an option.
- moring 4y agoI didn't know that. What makes SMS a terrible 2FA? (other than the fact that you can lose your phone, but that's true for any "have" factor)
- Eisenstein 4y ago"SMS-transmitted OTPs are susceptible to a variety of attacks. One is by obtaining control of a target’s cell phone number, often by calling the cellular provider or going into a retail store of the provider and impersonating the subscriber. In 2016, the chief technology officer of the US Federal Trade Commission had her number hijacked this way. In other cases, the interception is the result of compromising the mobile account because it’s protected by a password the subscriber used on a different site that was breached. Still other interceptions are the result of exploiting decade-old weaknesses in the SS7 routing protocol that carriers around the world use to ensure their networks interoperate. OTPs are also vulnerable to phishing and social engineering attacks, as long as the attackers enter the codes quickly after obtaining them." * https://arstechnica.com/information-technology/2017/05/thieves-drain-2fa-protected-bank-accounts-by-abusing-ss7-routing-protocol/ https://arstechnica.com/information-technology/2017/05/thiev... * https://arstechnica.com/information-technology/2018/08/password-breach-teaches-reddit-that-yes-phone-based-2fa-is-that-bad/ https://arstechnica.com/information-technology/2018/08/passw...
- jacobsenscott 4y agoI've had two macs repaired - once at an apple retail shop, and once at an "authorized repair" place. I either wasn't asked for a password, or they asked but made it clear they didn't need it. Of course I would never give it. Maybe that's not the norm.
- obscurette 4y agoIt probably depends. There is no official Apple repair shops here, but some partners. Some years ago I had to replace a battery on my mothers' Apple laptop and one of them refused to replace battery if I don't give them admin password. I had to make full backup, erase all data and restore it after battery replacement. I haven't had such experience with other Apple repair shop here.
- egberts1 4y agoYep, except this one 3rd party repair shop insisted on my password to my drive just for a screen clamshell assembly (MacBook) and keyboard replacement. I let him watched me type it in (on a cracked screen with a broken A key) and the proceeded to erasing all partitions before I left it with him. It was preset to "fuck you", just in case. (You do do backups, do you?)
- qwerty456127 4y agoApparently you are a very advanced user. 99% time users want, explicitly or implicitly (more often, and they get sad or mad if their implication is failed) you to return their devices with all their files intact. So the technician needs access to dump their files and put them back in after re-installing the OS. Advanced users just backup and wipe their data themselves before they handle the computer to the service.