3 ms·
How about asking to backup your data (which they ask anyway) and asking that the disk be wiped. There are no problems then. Handing over your password means th
by QuantumRoar 11y ago
How about asking to backup your data (which they ask anyway) and asking that the disk be wiped. There are no problems then.
Handing over your password means that there is practically no barrier for a technician to obtain all your data, all your private keys, etc. It only takes one guy with malicious intend to make your life miserable. Often, people also store their work related keys on their computers. So how about opening your company up for someone else?
The issue is that not all people are careful with that. And the code of conduct of Apple to just trust any technician 100% is completely wrong. Setting up a secure infrastructure means, you should assume that parts of it are already compromised. In that case, assume the technician is trying to obtain as much private data as possible, how can they still keep their customers safe?
- CHY872 11y agoIf you do work related stuff on your computer, your work should be taking care of the computer. This is why most people get assigned a computer by their places of employment, and are not expected to use their own. The place of work has their own tech team who deal with these types of issues. It's a really bad idea to do work stuff on a home computer because it makes your device much more vulnerable to being snooped on and controlled (for example, your place of employment may gain the ability to remotely wipe your device), and generally if you are in such a pickle then you should just not give them your password. Again, it could be a software issue. If I complain that my WiFi isn't working, and you take it in to have a look, and your diagnostics say that WiFi works, then without the password you can't do anything at all. If my problem is that Safari runs really slowly and you can't log in, you're not going to be able to fix that. If your only fix is then to reinstall the operating system and hope for the best, then you've done a terrible job. In any case, the tech has physical access to your computer, and in the presence of that you should not assume any security from your disk encryption. FDE is good for one loss of control; after that you should assume compromise.
- Dylan16807 11y ago>it could be a software issue They can still do some tests. It's not like wiping the hard drive helps solve software issues. >FDE is good for one loss of control; after that you should assume compromise. If the threat model is a malicious actor, yes. If the threat model is accidental plaintext password leaking, there is a huge difference between the scenarios. I could construct a similar argument against password hashing on servers...
- gambiter 11y ago>If the threat model is accidental plaintext password leaking, there is a huge difference between the scenarios. That's just fear mongering. Why would you not change your password before taking it in? You should be changing it regularly anyway, and you shouldn't be using that password in more than one place. The idea of it leaking from a technician's database is irrelevant because you would change it as soon as you get the machine back.
- berberous 11y ago99.999% people in this world would much rather take the risk of an Apple tech having their password, then go through the trouble of wiping their drive and reinstalling. Perfect is the enemy of good. Apple has made it easy for people to encrypt their drive with FileVault, which is a huge step forward for privacy and security. As a result, I am okay with a single Apple tech having my password, which I assume gets purged once the computer is returned to me. If you are that worried or tech savvy, just wipe it before you go in. You seriously expect them to ask every single customer to wipe their drive?