News: 1623084309

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Apple settles with student after authorized repair workers leaked her naked pics to her Facebook page

(2021/06/07)


Apple has paid a multimillion-dollar settlement to an unnamed Oregon college student after one of its outsourced repair facilities posted explicit pictures and videos of her to her Facebook page.

According to [1]legal documents obtained by The Telegraph , the incident occurred in 2016 at a Pegatron-owned repair centre in Sacramento, California. The student had mailed in her device to have an unspecified fault fixed.

While it was at the facility, two technicians published a series of photographs showing the complainant unclothed to her Facebook account, as well as a "sex video." The complaint said the post was made in a way that impersonated the victim, and was only removed after friends informed her of its existence.

[2]

The two men responsible were fired after an investigation. It is not known if the culprits faced criminal charges.

[3]

[4]

Much of the details of the case, as well as the exact size of the settlement, were sealed. Lawyers for the plaintiff sought a $5m payout. The settlement included non-disclosure provisions that prevented the student from revealing details about the case, or the exact size of the compensation.

Counsel for the victim threatened to sue for infliction of emotional distress, as well as invasion of privacy. The filings show they warned Apple that any lawsuit would result in inevitable negative publicity for the company.

[5]

Pegatron settled with the victim separately, per the filings.

In its fight against the right to repair, Apple has argued that allowing independent third-party businesses to service its computers and smartphones would present an unacceptable risk to user privacy and security.

[6]This scumbag stole and traded victims' nude pics and vids after guessing their passwords, security answers

[7]Ex from Hell gets six years for online stalking, revenge pics campaign against two women

[8]It is with a heavy heart we must inform you, once again, folks are accidentally spilling thousands of sensitive pics, records onto the internet

[9]iCloud hacker perv cops nearly 3 years in jail for stealing and sharing people's private, intimate pics

[10]British voyeur escapes US extradition over 770 cases of webcam malware

This incident, which occurred at the facilities of an authorised contractor, has undercut that argument somewhat.

It follows [11]a similar incident in November 2019, where a Genius Bar employee texted himself an explicit image taken from an iPhone he was repairing. After the victim complained, the employee was fired.

In [12]a 13-minute video , prolific right-to-repair activist Louis Rossmann accused Apple of hypocrisy due to its framing of independent repair as inherently unsafe.

[13]

"When it comes to right-to-repair, a lot of the arguments are that if [we] get access to a charging chip, so that when the charging chip inside your laptop dies and he can fix it without charging you $1,500, then he's going to breach your privacy. He's going to go through your data, hack you," he said.

"When we need to get out to people is that when you go to the dealer, they may use different parts and have different repair procedures, but at the end of the day, they're no better at filtering out creeps than us."

The Register has asked Apple to comment. In a statement to The Telegraph , the iGiant said: "We take the privacy and security of our customers' data extremely seriously and have a number of protocols in place to ensure data is protected throughout the repair process. When we learned of this egregious violation of our policies at one of our vendors in 2016, we took immediate action and have since continued to strengthen our vendor protocols." ®

Get our [14]Tech Resources



[1] https://www.telegraph.co.uk/business/2021/06/06/apple-pays-millions-woman-explicit-photos-posted-online/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YL6XPPc20Agw9Ve16UQFQAAAAJU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YL6XPPc20Agw9Ve16UQFQAAAAJU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YL6XPPc20Agw9Ve16UQFQAAAAJU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YL6XPPc20Agw9Ve16UQFQAAAAJU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/02/11/hacker_suny_pictures/

[7] https://www.theregister.com/2019/11/08/six_years_cyberstalking_sentence/

[8] https://www.theregister.com/2020/02/17/roundup_feb14_2020/

[9] https://www.theregister.com/2020/02/03/icloud_hacker_sentenced/

[10] https://www.theregister.com/2020/12/11/christopher_taylor_webcam_perv_extradition_case/

[11] https://www.washingtonpost.com/technology/2019/11/12/an-apple-store-employee-helped-customerby-texting-himself-private-photo-her-phone/

[12] https://www.youtube.com/watch?v=xt3YSD36ZNc

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YL6XPPc20Agw9Ve16UQFQAAAAJU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/

In before . . .

Throatwarbler Mangrove

. . . the Apple fanbois and other assorted neckbeards start up with the victim-blaming. To get out ahead of your criticisms, we don't know the nature of the required repair, so it may not have been possible for the student to remove the intimate material, and, in any case, the fact that she did not in no way implies that it was appropriate for repair shop staff to a) go rooting around on her hard drive and b) post the material to Facebook. Furthermore, the fact that she has a Facebook account in no way makes her a lesser person deserving of scorn, ridicule, or public humiliation, no matter what the commentard community may think.

Does that cover all the bases?

Re: In before . . .

yetanotheraoc

Comparing your "In before ..." post #1 with "How to tell if you're stupid." post #2 immediately after, I would say you covered it.

Re: In before . . .

MrBanana

Someone stole their Edit Post button.

Re: In before . . .

45RPM

I can’t thumbs up this enough. Victim blaming is never acceptable, no matter what the circumstances are.

Re: In before . . .

Ian Johnston

"Victim" is not a boolean variable. Some victims aren't to blame, sure, but some are partly or wholly to blame for what happens to them. Easy example: the courts decided that George Zimmerman was entitled to defend himself with lethal force against Trayvon Martin. Do you think that he, as a victim, was entirely blameless?

Re: In before . . .

MrDamage

Unless you run a "secure" for-profit carpark, or are police. In which case it seems to be perfectly acceptable to blame the victim if their car gets broken into and contents stolen.

Cunts.

Re: In before . . .

macjules

To have logged in as the user, rummaged through her personal photos and then posted them onto Facebook is a crime, without any doubt. If that had been her bank account they logged into, because she left her banking details in a Note, would there have been any excuses then?

Re: In before . . .

cb7

Yep. Covers all bases, except there ain't no pussy pics out there worth $5m

Re: In before . . .

gnasher729

What makes you think anyone would start blaming the victim?

Oh my god, I read some more posts and there they come…

Nude pictures sent to your boyfriend/girlfriend and they get shared: Cut his balls off. Blame yourself for the shared pics. He can blame himself for his loss.

Nude pictures on a phone without passcode get stolen: Blame yourself. If you find the perp see above and he can blame himself.

Nude pictures on a phone that you hand to Apple for repair: Blame the idiots who copied them, collect money from Apple. If you’re Apple, find the perps and see above.

How to tell if you're stupid.

TeeCee

If you take nude pics of yourself, you're probably stupid (and vain).

If you keep nude pics of yourself on your phone / computer / tablet / whatever, you are definitely stupid.

And if you leave them on there when you send it in for repair, congratulations, you just made yourself the poster child for stupid.

As always I am disappointed to see the legal system reward stupidity, it just brings the idiocracy closer.

Re: How to tell if you're stupid.

MrBanana

Try substituting 'nude pics of yourself' with 'pictures of my mother dying alone in a hospital bed'. The total disregard for personal privacy is the issue here, not the actual data involved.

Re: How to tell if you're stupid.

cornetman

> Try substituting 'nude pics of yourself' with 'pictures of my mother dying alone in a hospital bed'. The total disregard for personal privacy is the issue here, not the actual data involved.

Not only that, perhaps substitute images or any information that you hold in a professional capacity that you have a responsibility to keep private.

On Louis's YouTube, there is a dumb as f*ck commentator who calls himself "Spenser" trolling for Apple making the same arguments as to the alleged stupidity of the phone's owner. Trivial damage to a phone could easily make it non-functional, a failed battery or charging socket, a cracked screen that makes the display unreadable so that the data couldn't be removed before shipping. And the data is supposed to be encrypted.

As stated by others, this is a huge breach of privacy expectation by an Apple contractor and they should be slapped down mercilessly.

Re: How to tell if you're stupid.

redpawn

You send your computer to professionals. You should be able to expect them to be as discrete as a therapist. There are plenty of opportunities to look at porn already on the internet so no reason to commit a crime to post more just to damage and embarrass your customers.

Re: How to tell if you're stupid.

Blank Reg

Yes the repair people are 100% liable here. They should know better and must be held accountable.

On the other hand I've told my kids to never take a photo that you wouldn't want to show your grandmother. Either by accident or by malice there is a good chance such photos will one day end up where you don't want them to. And once that happens good luck purging them from the internet.

Re: How to tell if you're stupid.

Martin

Read what the article said.

...two technicians published a series of photographs showing the complainant unclothed to her Facebook account, as well as a "sex video". The complaint said the post was made in a way that impersonated the victim , and was only removed after friends informed her of its existence.

Which makes me wonder if this was actually someone who deepfaked her? We may never know, as they've settled with a non-disclosure agreement.

But in any case, saying that leaving nude photos on a phone means it's your fault they got spread around the internet is the same argument that wearing a short skirt means it's your fault you got raped.

Downvote duly administered.

....continued to strengthen our vendor protocols

Woodnag

Don't worry, it's won't happen again becuase Apple said they will "continued to strengthen our vendor protocols" which means have signs saying don't do it with bigger letters.

Re: ....continued to strengthen our vendor protocols

Brewster's Angle Grinder

Or they could put some more small letters in the contract. Letters like, "You will be liable for our damages if you violate these protocols."

Re: How to tell if you're stupid.

Anonymous Coward

I wonder if TeeCee realises just how incel he sounds?

Re: How to tell if you're stupid.

NotBob

If you take nude pics of yourself, you're probably stupid (and vain)

If you keep nude pics of yourself on your phone / computer / tablet / whatever, you are definitely stupid.

And if you leave them on there when you send it in for repair, congratulations, you just made yourself the poster child for stupid.

As always I am disappointed to see the legal system reward stupidity, it just brings the idiocracy closer..

How to tell if you're stupid, indeed. If you unironically hold these views, it's probably safe to assume you are.

Re: How to tell if you're stupid.

Phil O'Sophical

poster child for stupid.

Stupid or not, there's still no excuse for someone who happens to find those photos then sharing them. That's what Apple has paid up for. If the repair tech had simply admired the images and fixed the phone there wouldn't have been a problem.

Re: How to tell if you're stupid.

Throatwarbler Mangrove

I think a good way to tell if someone is stupid is that they receive a person's electronic device for repair and then violate the person's privacy in a very public way which leads directly back to the repair shop. If the techs had just rubbed one out to the pictures, it would be creepy and disgusting, but no one would ever know. Posting the pictures publicly when only a very short list of people would have access to those pictures is the very distilled essence of stupidity.

Re: How to tell if you're stupid.

tfewster

There have been cases of technicians finding illegal materials, e.g. child porn, and reporting it - as you would expect IF they found something.

Though it was not clear if the illegal materials were found accidentally, or if the technicians routinely went looking (for themselves, or a fishing operation for law enforcement).

Cameras and/or managers overlooking the repair benches might deter snooping. That might seem intrusive and degrading to professionals - but I'd rather have proof I did no wrong than the unverifiable suspicion that I'd erred

Re: How to tell if you're stupid.

Rol

I have pictures of my bum on my phone, 'cos I much prefer to diagnose my ailments for myself, before troubling my overworked doctor.

I also have pics of me fully clothed, because I find looking in the mirror just doesn't seem to work the same. I'm not vain, just conscious of the fact my career prospects are not improved if I stroll into work looking like a wanker from a 70's porn film. I'm sure many people do exactly the same, as it's far easier to see the whole picture on a screen than in a reflection, or maybe wanking to all those 70's porn films did send me blind...hahaha

I also repair my own phones. Admittedly some fixes involve a big hammer and a recycling bin, but seeing as I have never paid more than a tenner for a phone, it's not a big loss.

If you can go to Germany and watch them building your car, or an old time watch repairer fix your Rolex in front of you, then why can't you sit and chat with the genius as they fix your iphone and thus dispel any worries that you might get it back a little stickier than you sent it?

Re: How to tell if you're stupid.

PRR

> If you take nude pics of yourself

Twice this month I have taken "nude" pictures on my phone. FOR A DOCTOR. In this COVID world, and backed-up medical services, especially way back in the woods, it is making sense to send pictures rather than schedule and attend a follow-up.

Friend had a suspicious growth cut off her back. The picture is her naked scabbed back, not so erotic.

Dog had major urinary trouble. The only vet who would do it is 200 miles away. Normally we would go back 2 weeks later for follow-up. We opted for a very gross close-up photograph of the dog's poor crotch.

Wondering if this adds enough to the topic to pass moderation.

Demand 100% control : accept 100% liability

Howard Sway

It was an Apple authorised repair outfit. And I'm guessing that Apple authorisation doesn't come cheap or easy. So if any person in any of Apple's control freak supply or repair chain screws up in any way, then Apple should be liable.

And what applies to nudie pics applies just as much to any work or other private data on somebody's machine. It should not be touched by the repair people.

Re: Demand 100% control : accept 100% liability

iron

> I'm guessing that Apple authorisation doesn't come cheap or easy

You'd be surprised.

An official Apple repair centre in the UK used to be a customer of mine, I did maintenance on their thermal transfer printers whenever a field service colleague was on holiday but I'm really a developer. One time when Apple introduced a new PSU for a laptop I was asked by a manager at said repair centre if I knew how to repair it. They couldn't even get the thing open because the special tools hadn't arrived from Apple yet.

I couldn't do anything with it either but my point is I was a random, unqualified third party who has never owned an Apple product and they asked for my help. They would regularly call us out to fix faults that turned out to be print head needs cleaned despite their own staff of on-site engineers.

I wouldn't trust that company to rewire a 13 amp plug let alone fix a smartphone or laptop.

Details

yetanotheraoc

"In its fight against the right to repair, Apple has argued that allowing independent third-party businesses to service its computers and smartphones would present an unacceptable risk to user privacy and security. (p/) This incident, which occurred at the facilities of an authorised contractor, has undercut that argument somewhat."

I'm not sure it does undermine Apple's argument. Doesn't that depend on those pesky details? How much effort does Apple *actually* put into safe-guarding privacy at 3rd parties? Versus how much effort do / will / would independent shops put? And what would be the rate of incidents at various levels of effort? Apple's vendors have notably failed, but that doesn't tell us much about effort or rate.

Re: Details

MrBanana

"Apple's vendors have notably failed, but that doesn't tell us much about effort or rate."

Apple's effort - slap a non-disclosure on the whole thing. The rate of incidents should be zero. anything else is unacceptable.

Re: Details

yetanotheraoc

Zero defects with _people_ involved. Wow.

Re: Details

MrBanana

It is what Apple has decreed in the second decade of the new freedom- the just repairers are not mortals. Hail the the anointed, only they shall be sanctioned to fix the iThingy. Let the Apple, righteous repairers release the daemons from the holy device. Sacred are the repair manuals - let them never be seen in plain sight.

Re: Details

yetanotheraoc

I'm actually amused by the number of downvotes I am getting for a rational post. Change the names of the defendants from Apple and vendor to *you* and your helper and I think the details might suddenly start to matter.

The poor customer was wronged, no doubt. The lawyers did their thing which did not make it all better but then nothing could.

My point stands. Apple and vendor failed, but would an independent repair shop do better? Maybe yes, maybe no, it all comes down to details.

Re: Details

MrDamage

So Apple has shown they do nothing about your security and privacy in respect to third party repairs. The most that will happen, if the 3rd party misbehaves often enough, is they will lose their Apple certification.

What does losing your Apple certification mean? You no longer have to send Macs older than 5 years to the landfill, as you are now allowed to repair them how you see fit.

Will an independent repair shop do better? Let's face it, they can't do any fucking worse.

Re: Details

gnasher729

You missed about five million important points in your analysis.

Re: Details

doublelayer

"You missed about five million important points in your analysis."

As useful as that comment was in enlightening the person who wrote the original comment and those of us reading it, perhaps you'd care to list some of the important points? You obviously know what they are. Due to comment size limits, perhaps you can split it into five posts of a million reasons each. I assure you we wouldn't mind.

Re: Details

doublelayer

Let me clear up the problem.

"My point stands. Apple and vendor failed, but would an independent repair shop do better? Maybe yes, maybe no, it all comes down to details."

The answer is no. An independent repair shop would not necessarily be better. Some could do the same. However, that is not an excuse for Apple to ban them on privacy grounds when Apple-certified people are doing just as badly. That is the argument. Not that independent repair is always better, but that the excuse provided by Apple for not allowing it is completely incorrect as proven by this example.

Re: Details

gnasher729

Since the repair was done by someone authorised by Apple, the victim received a nice amount of money. Anyone else she could have sued of course but the perp wouldn’t have been able to pay a tenth of what Apple paid.

Re: Details

Joe W

So it is better to have $(personal_data) being stolen by Apple than by others, because you get more money out from a lawsuit?

How?

Bertieboy

If you pass a switched off Apple device to a repairer (of any description) how does the repairer get access to your private data without the unlock code? I'm assuming they require the owner to supply it which in itself should be a very large flag as in most cases (new battery, screen etc. ) just switching on should be sufficient to validate the repair. Sorry if the question seems to be a silly one but I am genuinely interested whether these repairers routinely seek the unlock code.

Re: How?

Filippo

I guess it depends on the nature of the fault. Ability to switch on may not be sufficient to validate the repair.

Re: How?

Brewster's Angle Grinder

Aha, so the way to crack open a perp's phone is to, um, crack it open and then intercept it when they post it to the idiot bar.

Re: How?

yetanotheraoc

"just switching on should be sufficient to validate the repair"

Sounds useful, maybe someone could invent some kind of power-on self-test to validate the hardware. Yes, I know you know that. The problem is the average end user who turns in their machine to the Apple proxy doesn't know about it.

As for your real question, I bet the repairers seek the lock code *every time*.

Here at work some years back I took the new cyber-security training which explained to *never* give our password to *anyone*. The next time I called in a ticket for a software problem, the level two help-desk technician asked for my password! What to do? It's not my data, it's not my software, I called them, so F*** it, I gave it to him. Also as soon as the call ended I changed it. It's better now, they don't ask any more, which means if they ask again this time I will say no.

One of my Thunderbolt ports has failed and at some point I will take it in for repairs. At which time I can add one more data point to the how often question. If they ask for my password, they are getting a flat No. If they tell me they need it to test, I will tell them I'll test it when I pick it up. And if they don't agree, I'll keep using just the one port.

Re: How?

gnasher729

Some small problems that I had, I had to enter the unlock code myself.

Re: How?

John Brown (no body)

"I'm assuming they require the owner to supply it which in itself should be a very large flag as in most cases (new battery, screen etc. ) just switching on should be sufficient to validate the repair. Sorry if the question seems to be a silly one but I am genuinely interested whether these repairers routinely seek the unlock code."

One of the strings to the bow of the company I work for is being an Apple dealer/authorised repair centre. Yes, the users access codes are required. Replacing a broken screen and simply confirming it works by turning it on is no substitute for doing a full diag of the system to make sure nothing else broke at the same time. If they refuse (some do) the warranty repair will be completed if possible and returned "as is" if only limited further diags are possible. The vast majority of what we deal with is corporate though, so in most cases a device, Apple or otherwise is either returned with a clean OS image or the customers specified OS image. All firmware is updated by default where applicable and all the hardware is checked so it goes back "as new" (in terms of functionality, case scratches ain't our problem), no unreported faults left unfound and unfixed unless, as above, the customer refuses required access codes or passwords.

And no, the guys in the workshop don't really have time to go rooting around in customers data. Diagnose, fix, test, onto the next one. Anyone caught doing anything untoward with customer data would be marched out of the door. Some of our customers are the type you occasionally see in the press as having left unsecured data on trains, so that's the sort of data that would be on some of the kit we fix. That sort of contract customer is too lucrative to risk.

Apple's new repair policy

steelpillow

Apparently we are about to be told that third-party repair outfits are a great idea after all.

Not because they provide any greater or lesser security/privacy/integrity etc, but because you can't sue Apple for approving them.

(OK I made it up, but be honest, how long are we going to have to wait?)

Re: Apple's new repair policy

yetanotheraoc

"you can't sue Apple for approving them"

If that were true, Apple would have been using them long ago. Anything to make the lawsuits go away.... But it wouldn't work. Lawyerly logic always finds some blame for the deepest pockets in the neighborhood of the crime. Driving your Mercedes Benz down the street near the accident? You should have stopped! See you in court.

Apple are no saints. They get sued all the time, every day, multiple times per day. Some of which they brought on themselves by doing wrong, and some of which they brought on themselves by having deep pockets. Either way, their lawyers are very busy.

Lorribot

There is a simple fix to this, make it easy to remove the storage chips like you would an SD card, it woudl help if all your personal data was only stored on that card not sprayed around by apps all over the place, but a well written OS should be able to manage that (stop laughing), then if you have to send it off you just remove your personal data and just send the kit in for repair with your personal data and porno movies never leaving your possession.

Or you can encrypt you local drive on a MacOS device but who does that.

doublelayer

"Or you can encrypt you local drive on a MacOS device but who does that."

A lot of people, because it's now in the setup questions and opt out. And it's enabled on IOS as long as the device has a passcode, which the vast majority does. All of which doesn't help you if the repair people ask for the codes, which they do.

I have no problem with the award

DS999

Apple is ultimately responsible, so they deserved to be sued. But there's no way Apple's contract with Pegatron doesn't make them liable for misconduct on the part of their employees, so Apple will be sending them the bill for the settlement and their lawyers.

If that invoice doesn't give Pegatron incentive to police their employees better, I don't know what would!

Isn't it nice that people who prefer Los Angeles to San Francisco live there?
-- Herb Caen