Commercial repair shops caught snooping on customer data by canny Canadian research crew
- Reference: 1668501010
- News link: https://www.theregister.co.uk/2022/11/15/repair_technicians_data/
- Source link:
In a four-part research study distributed via ArXiv, " [1]No Privacy in the Electronics Repair Industry ," University of Guelph researchers Jason Ceci, Jonah Stegman, and Hassan Khan describe how they tested the privacy policies and practices of electronics repair shops.
The inquiry consisted of a field survey of 18 repair service providers in North America – three national, three regional, and five local service providers, as well as two national smartphone repair service providers and five device manufacturers.
[2]
Representatives of these firms – unidentified in the study as a consequence of the Canadian university's ethical review requirements – were questioned to determine whether they have privacy policies, and how they treat customer data.
[3]
[4]
Then, repair personnel were asked to perform battery replacement for Asus UX330U laptops running Microsoft Windows 10 – a fix that should not require login credentials or operating system access. Yet, all but one of the firms asked for login credentials.
"None of the service providers posted any notice informing customers about their privacy policies," the paper says. "Similarly, until the devices were handed over, no researcher was informed about a privacy policy, their rights as a customer, or how to protect their data."
[5]
And once the laptops were provided, only the three national and three regional service providers offered a terms and conditions document to be signed. Worse still, these contracts disclaimed liability for any data loss.
I wonder why?
Having assessed the privacy policies of these repair shops, the researchers tested the technicians' actual privacy practices by giving them rigged Windows laptops with dummy data to secretly log how repair staff used the devices.
The results were not encouraging: Six of sixteen technicians snooped on customers' data, and in two of 16 tests copied customer data to external devices. Among these six snoopers, one technician did so in a way to avoid generating evidence, while three others took steps to conceal their activities – the device logs show offending technicians attempted to hide their tracks by deleting items in the "Quick Access" or "Recently Accessed Files" on Microsoft Windows.
In a phone interview, Jason Ceci – a security researcher and co-author of the paper – told The Register that the privacy violations referred to in the paper were mostly snooping through customers' photos.
"Some of them were just going through someone's browsing history," said Ceci. "And then in two of the cases, they were actually copying the data off the device. In one of those two cases, I believe, they were going through financial data."
[6]
Ceci said the repair shops evaluated were not identified in the study and that they were also not informed of the researchers' findings. "If we told them that we were going to be looking at the logs, and what they did after, we were worried about possible backlash to the researchers who were [dropping the rigged devices off and providing personal information]," he explained.
The other portions of the study involved an online survey and interviews with consumers to better understand how they interacted with repair services. The data obtained suggests that about a third of broken devices do not get repaired due to the privacy concerns of their owners.
[7]Russia-based Pushwoosh tricks US Army and others into running its code – for a while
[8]Google slapped with $391.5m settlement in privacy lawsuit
[9]Apple sued for collecting user data despite opt-outs
[10]World Cup apps pose a data security and privacy nightmare
Ceci and his co-authors argue there's a dire need to assess privacy policies and practices in the repair industry, which generates $19 billion annually. They cite reports about past privacy violations – like claims that Best Buy's Geek Squad technicians [11]served as informants for the FBI , as well as reports that [12]Apple and [13]Geek Squad technicians have been accused of stealing nude pictures found on devices brought in for repair.
Ceci said regulators should look at the repair industry and consider clarifying privacy rules for device repairs. He also reiterated a point made in the research paper about device makers taking a more proactive approach to standardize diagnostic interfaces and permissions. He pointed to Samsung's recently introduced " [14]Repair Mode " – a way to protect on-device data during repairs – as an example of the sort of privacy protection device makers ought to consider. ®
Get our [15]Tech Resources
[1] https://arxiv.org/abs/2211.05824
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y3NxQhrUpcS38PBdQd8L@QAAABU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y3NxQhrUpcS38PBdQd8L@QAAABU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y3NxQhrUpcS38PBdQd8L@QAAABU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y3NxQhrUpcS38PBdQd8L@QAAABU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y3NxQhrUpcS38PBdQd8L@QAAABU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/11/15/russia_pushwoosh_us_army/
[8] https://www.theregister.com/2022/11/15/google_391m_privacy_settlement/
[9] https://www.theregister.com/2022/11/14/apple_data_collection_lawsuit/
[10] https://www.theregister.com/2022/11/11/world_cup_security/
[11] https://www.eff.org/deeplinks/2018/03/geek-squads-relationship-fbi-cozier-we-thought
[12] https://www.ibtimes.co.uk/woman-catches-apple-technician-stealing-her-nude-photos-during-phone-repair-1671893
[13] https://www.huffpost.com/entry/geek-squad-nude_n_3749201
[14] https://www.xda-developers.com/samsung-repair-mode-coming-for-galaxy-s21/
[15] https://whitepapers.theregister.com/
Re: And anyone is surprised?
Not surprised at all.
For all of my personal (and family) gear I'm the first port of call for repair, and (touch wood) so far I have never had to hand any hardware over to a shop for repair. And if I ever did then any personal data would be removed beforehand.
SWMBO went on a holiday to Las Vegas a few years ago, and she was provided with a dumb phone for the trip. And any documents that had to go with her were placed on a microSD card that was placed into a hollowed out pound coin. And this was just because I don't like the TSA policies they have over there.
Re: And anyone is surprised?
I know haters got to hate .... but sometimes I wish they'd actually let you know what it is they're hating.
I've reread what I put and can see nothing offensive. Only that my 'nobody gets my personal data' policy is extended to gum'nts that tell you in advance that they're gonna grab what they want if you visit their precious shores.
---------> Cos you always want to avoid his gaze!
Re: And anyone is surprised?
> sometimes I wish they'd actually let you know what it is they're hating
Agreed. Just taking a guess, but the hollowed out quid was probably a bit over the top and more likely to cause trouble to a third party (namely your wife) than not.
Re: And anyone is surprised?
Things will go badly if the customs people find a hollowed out coin with microSD. You might just want to set up a (password protected) website in your home country with the documents to download once SWMBO gets to the coffee shop after customs.
Then again, maybe SWMBO getting the rubber glove treatment is part of your fun.
Re: And anyone is surprised?
But that is fine if you know what you are doing and have a spare HDD. To get a HDD out of many laptops requires taking it apart, and not only does that mean having the screwdrivers (small or security), but also tools to get into the case without damaging.
People on here are probably OK doing that, but I know many people who would not know what to do or even want to do it (for damaging my case).
Also a lot of people would need to look at the internet for the fixit sites or youtube videos and the laptop maybe their only way onto the internet and if it is busted, they have no way to get that info.
Bring back the days where HDD's were easily removed, RAM upgrades was via a 2 screw slot at the bottom and batteries were not embedded within the guts of the machine
Snooping
Tricky one, of course it's morally wrong to snoop, but we did catch a few criminals back when I worked in a PC shop.
Chucklefucks like this
give the entire field a bad name, especially since most are looking for sexy pics and usually can't help sharing them around. Not just the idiot 20-yos, there were plenty in their 30s and 40s who got their kicks that way, like there aren't a billion sexy pics just a google away.
Full disclosure: When I've told people they can't store their iTunes library on their network folder, back in the heady pre-Spotify days, I've been known to first snag an album or two.
Hmm
This is a tough one. Snooping isnt good but then Hunter Biden and various others wouldnt have been caught 'behaving badly' without looking.
I was at a domestic job yesterday where her hotmail account was compromised and the lady had difficulty changing the password as she used it all over other places. We went though various accounts changing them, and despite me having typed in the passwords initially and she wrote them down, when she did it, I still turned my head. Just habit. She thought it was hilarious.
And anyone is surprised?
There have been so many stories over the years of repair personel rummaging through the hard drives of devices in for repair.
It would never even cross my mind to supply a device for repair without a virgin hard disc/os in. Though I'd be likely to request repair only for a hardware part - a socket or module perhaps - that I couldn't easily obtain elsewhere.