{"id":32804,"date":"2021-06-11T20:21:31","date_gmt":"2021-06-12T00:21:31","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=32804"},"modified":"2021-06-11T20:21:31","modified_gmt":"2021-06-12T00:21:31","slug":"settlement-for-applecare-privacy-invasion","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2021\/06\/11\/settlement-for-applecare-privacy-invasion\/","title":{"rendered":"Settlement for AppleCare Privacy Invasion"},"content":{"rendered":"<p><a href=\"https:\/\/spencerdailey.com\/2018\/06\/27\/could-you-disable-your-admin-password-a-stressful-opsec-story-from-an-apple-store\/\">spencerdailey<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=27427748\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/spencerdailey.com\/2018\/06\/27\/could-you-disable-your-admin-password-a-stressful-opsec-story-from-an-apple-store\/\"><p>Back in 2018, I encountered what I&rsquo;d consider the cardinal sin of opsec by an Apple store employee. He asked me to <em>disable<\/em> my Mac&rsquo;s password before I turned it in for a multi-day off-site repair. The casual manner in which he asked me led me to assume this was not the first time he had pushed this question, and that it was a common practice at this store (Barton Creek Mall in south Austin, for those who care).<\/p>\n<p>Apple customers already place a great deal of trust in repair technicians who <em>have <\/em>the user&rsquo;s password, but disabling it for logging in means everyone who <em>handles<\/em> or has physical access to the device could trivially steal data from it or install malware on it. A Mac going offsite gets handled by several intermediaries, not just the technicians.<\/p>\n<\/blockquote>\n\n<p>The only safe option is to make several backups and then erase the device before getting it repaired.<\/p>\n\n<p><a href=\"https:\/\/9to5mac.com\/2021\/06\/07\/apple-pays-out-millions-in-compensation-to-student-after-iphone-repair-facility-shared-her-explicit-personal-images-online\/\">Benjamin Mayo<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=27422449\">Hacker News<\/a>, also: <a href=\"https:\/\/www.macrumors.com\/2021\/06\/07\/apple-settlement-customer-photos-posted-online\/\">MacRumors<\/a>):<\/p>\n<blockquote cite=\"https:\/\/9to5mac.com\/2021\/06\/07\/apple-pays-out-millions-in-compensation-to-student-after-iphone-repair-facility-shared-her-explicit-personal-images-online\/\"><p>Apple has settled a case with a 21-year-old student after she sent her iPhone to a repair facility in 2016 only to find that employees had uploaded personal explicit images and videos to her Facebook account from the phone during the repair process.<\/p>\n<p>The student had sent in her iPhone to Apple to get repaired. The invasion of privacy ultimately took place at a repair center in California, run by Pegatron, an Apple contractor. <em>The Telegraph <\/em><a href=\"https:\/\/www.telegraph.co.uk\/business\/2021\/06\/06\/apple-pays-millions-woman-explicit-photos-posted-online\/\">reports Apple paid out<\/a> millions in settlement compensation.<\/p><\/blockquote>\n\n<p>2016, meaning that this lawsuit was already well underway when Apple&rsquo;s lobbyist recently <a href=\"https:\/\/mjtsai.com\/blog\/2021\/03\/30\/more-apple-repair-providers-and-lobbying\/\">argued<\/a> against independent repair shops on the grounds that its own repair service offered better privacy.<\/p>\n\n<p><a href=\"https:\/\/www.ifixit.com\/News\/50700\/apple-insurance-and-stolen-photos-the-authorized-service-scandal\">Kevin Purdy<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.ifixit.com\/News\/50700\/apple-insurance-and-stolen-photos-the-authorized-service-scandal\"><p>This kind of arrangement isn&rsquo;t unusual. In fact, large companies almost always outsource repair and servicing to third parties. But it is also not something they readily acknowledge when they&rsquo;re arguing against right to repair laws. And for good reason. As it turns out: the incidence of misdeeds by employees at authorized service providers are actually pretty common &#x2013; and certainly no less common than independent repair shops. In 2019, for example, an Apple Genius Bar employee was caught <a href=\"https:\/\/www.washingtonpost.com\/technology\/2019\/11\/12\/an-apple-store-employee-helped-customerby-texting-himself-private-photo-her-phone\/\">texting intimate photos of a customer to himself <\/a>under the guise of helping her with a repair. The same thing happened in 2016 at an Apple Store in Brisbane, Australia.<\/p><p>Also, there is lots of evidence that, far from emphasizing quality of service, OEMs work to spend as little as possible on authorized repair. Note the 2019 ICE raid on a Texas-based Samsung authorized repair provider CVE Technology that <a href=\"https:\/\/www.vice.com\/en\/article\/xwbnpd\/ice-raid-on-samsung-repair-contractor-shows-big-techs-reliance-on-exploitative-labor\">discovered undocumented workers performing authorized repair on Samsung devices<\/a>.<\/p><p>In fact, when asked directly at the 2019 FTC <a href=\"https:\/\/www.ftc.gov\/news-events\/events-calendar\/nixing-fix-workshop-repair-restrictions\">Nix the Fix symposium<\/a> whether there was any data to support industry&rsquo;s contention that authorized repair is either higher quality or more secure than independent repair, Walter Alcorn of the Consumer Technology Association (CTA) admitted straight out that there was none.<\/p><\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/03\/30\/more-apple-repair-providers-and-lobbying\/\">More Apple Repair Providers and Lobbying<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2019\/11\/20\/where-to-get-apple-products-repaired\/\">Where to Get Apple Products Repaired<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>spencerdailey (via Hacker News): Back in 2018, I encountered what I&rsquo;d consider the cardinal sin of opsec by an Apple store employee. He asked me to disable my Mac&rsquo;s password before I turned it in for a multi-day off-site repair. The casual manner in which he asked me led me to assume this was not [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-06-12T00:21:34Z","apple_news_api_id":"9f8a21e7-a45f-45e0-956d-18e2c580e7c4","apple_news_api_modified_at":"2021-06-12T00:21:34Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/An4oh56RfReCVbRjixYDnxA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[38,416,25,41,209,30,1891,981,355],"class_list":["post-32804","post","type-post","status-publish","format-standard","hentry","category-technology","tag-apple","tag-applecare","tag-facebook","tag-lawsuit","tag-legal","tag-mac","tag-macos-11-0","tag-passwords","tag-privacy"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/32804","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=32804"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/32804\/revisions"}],"predecessor-version":[{"id":32805,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/32804\/revisions\/32805"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=32804"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=32804"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=32804"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}