4 ms·
Making a speech is easy, compared to actually doing the right thing. Just a month ago, I was asked by an employee of an Apple Certified Service Provider to dec
by QuantumRoar 11y ago
Making a speech is easy, compared to actually doing the right thing.
Just a month ago, I was asked by an employee of an Apple Certified Service Provider to decrypt my hard drive in order for Apple to make a "hardware test". There was an issue with my display, but they insisted that Apple's hardware test needed to have access to the data on my hard drive and send information back to Apple via the Internet. What about privacy, now?
So, don't believe anything they tell you. If you want to be secure, you need to take care of it yourself.
Edit: Just to make it clear, the employees were asking me, to hand over my administrator password, which should be added to their database, in order for the technician to successfully run Apple's hardware tests. This is literally the most insane thing that ever happened to me...
- etchalon 11y agoThat's not even a little insane. They needed access to something, and asked you for it to complete their work. It would have been insane if the guy had just hit a button, and your data was decrypted. As it stood, you were always in complete control of your data.
- QuantumRoar 11y agoI added a little bit to my comment above. They are asking people for administrator passwords and put them into forms in their computer system. Rule number one of computing is that you shouldn't ever tell anybody your passwords. Asking for it is ridiculous. Considering how casual they acted, I can only assume that quite a lot of people actually told them. That makes me really worried.
- CHY872 11y agoIf you have a software problem, how are they supposed to check that they fixed it without being able to boot the computer?
- Dylan16807 11y agoWhy do they need the password to boot? Especially why do they need to write it down?
- CHY872 11y agoIf you have full disk encryption enabled, the system won't boot if you don't give it the password. They write it down because you can't expect a tech to remember 16 digits of alphanumeric password for each client, as it looks bad when they have to phone up the client asking what their password is when they forget it. Writing down passwords is bad because other people can find them. If they're kept safe, there's no issue.
- QuantumRoar 11y agoHow about asking to backup your data (which they ask anyway) and asking that the disk be wiped. There are no problems then. Handing over your password means that there is practically no barrier for a technician to obtain all your data, all your private keys, etc. It only takes one guy with malicious intend to make your life miserable. Often, people also store their work related keys on their computers. So how about opening your company up for someone else? The issue is that not all people are careful with that. And the code of conduct of Apple to just trust any technician 100% is completely wrong. Setting up a secure infrastructure means, you should assume that parts of it are already compromised. In that case, assume the technician is trying to obtain as much private data as possible, how can they still keep their customers safe?
- CHY872 11y agoIf you do work related stuff on your computer, your work should be taking care of the computer. This is why most people get assigned a computer by their places of employment, and are not expected to use their own. The place of work has their own tech team who deal with these types of issues. It's a really bad idea to do work stuff on a home computer because it makes your device much more vulnerable to being snooped on and controlled (for example, your place of employment may gain the ability to remotely wipe your device), and generally if you are in such a pickle then you should just not give them your password. Again, it could be a software issue. If I complain that my WiFi isn't working, and you take it in to have a look, and your diagnostics say that WiFi works, then without the password you can't do anything at all. If my problem is that Safari runs really slowly and you can't log in, you're not going to be able to fix that. If your only fix is then to reinstall the operating system and hope for the best, then you've done a terrible job. In any case, the tech has physical access to your computer, and in the presence of that you should not assume any security from your disk encryption. FDE is good for one loss of control; after that you should assume compromise.
- 2muchcoffeeman 11y agoWas this done through an Apple Store? The Apple Store staff have asked me for my password too. I've always asked if a Guest account was enough and it's never been a problem. I've always found the "Geniuses" to be fairly helpful and they always explain what they were going to do to my gear.
- QuantumRoar 11y agoIt works with a Guest account, if you don't encrypt your hard drive. If you use FileVault, they specifically need your administrator password. So what are they actually doing there?
- rainforest 11y agoI don't think you can boot the machine to login as Guest without a password if you have FileVault enabled.
- QuantumRoar 11y agoI think you can still boot from the network. If that's correct, then this whole thing gets ever more mysterious for me.
- ajro 11y agoBut they did not use any backdoor. Etchalon is right - if they had to access file system how should they do that if it was encrypted? And you were in control of the situation - next time change the password to temporary one before handing it over. And if you are really paranoid decrypt and encrypt the drive afterwards to have new encryption keys ;-) EDIT: spelling.
- lewisl9029 11y agoThat rule #1 doesn't quite apply in this situation. That you should never need to give out passwords is mostly a safeguard for social engineering and phishing scams for accounts stored on a server over the internet. Only a malicious third party would ever ask for these types of account passwords, because those with legitimate needs to access it (you and the service operator) already have it (hopefully just the hash in the case of the latter). The password you're referring to here is an encryption key for a local hard drive that nobody else has access to. If they do in fact need access to the encrypted OS partitions stored on your hard drive in order to diagnose your problem, then they have no choice but to ask you for your encryption key. That's cryptography working as intended.
- QuantumRoar 11y agoI disagree. Not even someone who's there to help you should know your passwords. Consider that many people use the same password for a lot of accounts. On top of that, they already have your email address. By asking their customers for their passwords, they don't just ask them to hand over all the data on their computers, but they also make them vulnerable with regards to their internet accounts. If I have a hardware problem with my display, I don't want them to read my hard drive. Apparently they still try to do so, which I think is a severe violation of privacy. I'd have completely understood if they'd asked me to wipe my hard drive because of some data crawling Apple hardware test with an uplink to HQ. So they do have a choice "Can you make a backup and wipe your hard drive?" But asking me for my encryption password means they fail to understand why people encrypt and they don't care for the integrity of your computing.
- gambiter 11y agoApple techs have access to external drives with multiple versions of OSX installed. If they need to boot your device to test the hardware itself, they will use one of these. If those tests indicate no hardware issue, their only next step is to check out your OS. That would require administrator access to your machine if you're using whole drive encryption. I mean, I get what you're saying... they should have verified those things up front before asking for access, but I'm pretty sure they work on the concept of getting you the fastest service they can, balanced with the amount of customers they need to help simultaneously. My guess is that the admin password is a default question because they know they _generally_ will need it, so it's best get it up front rather than waiting hours or days for the customer to get back to them. Personally, when I had to take my Macbook in, I just zero'd out the sensitive data, changed my admin pw to something temporary, and let them have it. I know this will be a TOTAL surprise, but the multibillion dollar corporation didn't use this as a chance to hack my life. What a novel thought.
- iribe 11y agoYes, this speech is more marketing than anything. At the end of the day, just like with google, apple is sending your data to the cloud. Location data, they even have their own street view now...
- CHY872 11y agoAt an Apple Store, I've been asked this a few times. Then, I just say "I'd prefer not to" and have no problem.
- QuantumRoar 11y agoWell, I was arguing with them for 10 Minutes. They tried to get my administrator password (because I use FileVault) and I refused. They wouldn't even look at the display issue (not software or data related) without the password. In the end I just wiped the hard drive. They should've asked for that immediately.
- sbuk 11y ago>"In the end I just wiped the hard drive. They should've asked for that immediately." They should have. That said, I'm confident that the significant majority react extremely negatively towards that request, so they have learned to ask for passwords first. Best practice? Definately not.
- kranner 11y agoMy out-of-warranty MBP needed a new battery because the original battery had started to swell up. I called my local Apple Authorized Service Provider (the only one within 250km) what the procedure was if I wanted to purchase a new battery. They said I would need to drop off the computer with them; they would order a new battery and I could have it back in a week or so. I said I couldn’t do without the computer and I couldn’t let them access the hard drive (not encrypted) as I have proprietary data on it. They said I could make the full payment and bring it in when the replacement battery arrives, leave it with them and collect it in a few hours. They insisted they could not replace it with me present and the minimum time I would need to leave it was 3 hours. This is easily enough time to clone the hard disk, which I did point out, politely, but they said this was the most they could do for me. I ended up buying a third-party battery and changing it myself. It took less than 10 minutes. If it doesn’t last long, I’ll just have to buy a new Mac. So yes, apparently there are no standards in place for data security as far as authorized service centres are concerned.
- Margh 11y agoCould have cloned the drive yourself and given them a nice clean factory new OSX install to snoop on.
- asd 11y agoYep. This is what I've done in the past for our machines. 1) Time Machine it 2) Clean install 3) Drop off computer to be fixed 4) Pick up computer 5) Restore from Time Machine I've never had a problem.
- jkestner 11y agoIf Cook is serious, the message will have to trickle down to the people who make these processes to be sensitive to privacy needs. It takes some commitment.
- unprepare 11y agoThis is akin to giving your car to a mechanic to repair but refusing to give him the keys in case he might make a copy.