On TV.com: EMMANUELLE CHRIQUI Photos
BNET Business Network:
BNET
TechRepublic
ZDNet

August 18th, 2008

Security vs. convenience: Apple chooses poorly

Posted by Ryan Naraine @ 6:06 am

Categories: Apple, Contributors, Data theft, Open source, Passwords, Patch Watch, Pen testing, Punditocracy, Spam and Phishing, Spyware and Adware, Vulnerability research

Tags: Password, Apple Inc., Oliver, Security, Ryan Naraine

Guest post by Oliver Day

My PowerBook is in the third year of its life and has begun falling apart on a regular basis. I’ve had the laptop in for repair at least five times this year alone.

Every time I bring my laptop in Apple employees ask me the same question: “What is your administrator password?”

The first time I heard this question, I thought he was joking. Apple is not kidding.

Apple chooses poorly

They have offered every excuse imaginable for this practice but none have come close to convincing me to refuse to hand over my password. Sometimes the technicians would even try to intimidate me by saying that they might not be able to continue the repair if I refuse. One technician even tried to charge me an additional $100 for the installation of OS X for failing to divulge my password. The claim was that he had to perform additional work since I refused to cooperate.

This is official Apple policy and it needs to stop.

Consumers should never be asked for their passwords. It is a practice that defies logic to anyone that is trained in security. Given the state of the art in live OS distros, there is absolutely no reason that Apple should ever need access to consumers files for hardware repairs anyway. It isn’t as if technicians haven’t been caught pilfering files from users in the past.

When bringing Apple computers in for repairs, I strongly recommend that users do the following until this is resolved:

  1. Create a clone of the boot drive.
  2. Secure erase the contents of the drive.
  3. Install a fresh copy of the operating system.
  4. Re-image the drive once you receive your computer back.

This adds all kinds of time overhead to a process which already sets the consumer back.  All because Apple still believes this is a valid way to treat its customers.

(Image source: QiFei’s Flickr photostream — Creative Commons 2.0)

* Oliver Day is a security researcher at StopBadware.org, a project of the Berkman Center for Internet and Society at Harvard University.  He has over ten years experience in web and network security, working for companies including @stake, eEye, and Rapid7.  Oliver’s blog can be found here.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 126 Talkback(s)
They've never asked me for one...
I frequently drag my users' dead (or dying or squeaking or white-spotting) Macs to the Apple store for service, and i've -never- been asked for the admin password in the last four years.

'Tis a good thing, since i usually didn't know them.

--dick... (Read the rest)
Posted by: astro_z Posted on: 09/25/08 You are currently: a Guest | | Terms of Use
What if..  msalzberg | 08/18/08
You can't  Real World | 08/18/08
Absolutely not true!  Intellihence | 08/18/08
lol  rtk | 08/18/08
It wasn't even that!  GOTBO | 08/27/08
Slowly rock from side to side  Real World | 09/12/08
What if the technician ....  ShadeTree | 08/18/08
Booting from a clean disk...  msalzberg | 08/18/08
Are you sure about that...  Sleeper Service | 08/18/08
Yes, I'm sure.  msalzberg | 08/18/08
I think he was saying...  shadfurman | 08/20/08
Sure it does.  ShadeTree | 08/18/08
Deleted.  msalzberg | 08/18/08
Nice demonstration...  msalzberg | 08/18/08
Safety first  cquirke | 08/19/08
yep  shadfurman | 08/20/08
First Rule of Troubleshooting 101  kevin.denison@... | 08/18/08
LOL!  shadfurman | 08/20/08
What fantasy world are you living in?  bregalad | 08/18/08
great solution  Hogleg | 08/19/08
Depends on the Problem  mikefarinha | 08/18/08
But  Real World | 08/18/08
Safe Computing  mikefarinha | 08/18/08
I'd have to say  Real World | 08/18/08
Perhaps it depends on the point of view  mikefarinha | 08/18/08
Well, in your Real World...  msalzberg | 08/18/08
Follow the advice in the article(nt)  Real World | 08/18/08
I'll ask again.  msalzberg | 08/18/08
Fine  Real World | 08/18/08
It makes no sense to me...  msalzberg | 08/18/08
Not really  laura.b | 08/18/08
Even without the password  itguy08 | 08/18/08
I didn't say  laura.b | 08/18/08
Re: Not really  mikefarinha | 08/18/08
Not out of context  laura.b | 08/18/08
The answer needs strong data / code edge  cquirke | 08/19/08
More like...  euph0ria | 08/19/08
Based on history, OS X admin password isn't needed  NonZealot | 08/18/08
What holes?  itguy08 | 08/18/08
No you *CAN'T* remove Safari  rpmyers1 | 08/18/08
lol  isulzer | 08/18/08
Last time I recalled Ryan mentioning he uses a Mac.  Intellihence | 08/18/08
heh  isulzer | 08/18/08
Yes you can...  itguy08 | 08/18/08
Yeah, Safari is the only thing thing that uses WebKit  NonZealot | 08/18/08
Safari can be removed, and it does not get hidden like Internet Explorer.  Intellihence | 08/18/08
What does IE have to do with it?  NonZealot | 08/18/08
If you bothered to READ  itguy08 | 08/18/08
You'd better tell Apple that Safari isn't a part of OS X  NonZealot | 08/18/08
Oh please mister zealot,,,  Intellihence | 08/18/08
With physical access...  comp_indiana | 08/18/08
What does Windows have to do with this blog?  NonZealot | 08/18/08
With physical access to the computer it's game over anyway  Richard Flude | 08/25/08
RE: Security vs. convenience: Apple chooses poorly  flhu | 08/18/08
re: differences  Badgered | 08/18/08
RE: Security vs. convenience: Apple chooses poorly  itinko | 08/18/08
heh.  isulzer | 08/18/08
You are kidding, right?  itguy08 | 08/18/08
Personal data  djchandler | 08/18/08
RE: Security vs. convenience: Apple chooses poorly  muddybulldog | 08/18/08
Having done PC repair  itguy08 | 08/18/08
With 5 mins and an OSX DVD ...  dkawalec | 08/18/08
You can...  isulzer | 08/18/08
Shhh! That's a secret!  ZDnet User | 08/18/08
no...  isulzer | 08/18/08
paranoid  richvball44 | 08/19/08
RE: Having done PC repair  muddybulldog | 08/18/08
How about the REAL world?  bregalad | 08/18/08
RE: Security vs. convenience: Apple chooses poorly  pecosbill | 08/18/08
tbh  isulzer | 08/18/08
but...  pecosbill | 08/19/08
Oliver Day, you are truly clueless  Denexen | 08/18/08
re: Clueless  Badgered | 08/18/08
Hey stupid....  James T. Kirk | 08/18/08
ROFLMAO (nt)  No_Ax_to_Grind | 08/18/08
My Point Stands  Denexen | 08/18/08
Drivel  comp_indiana | 08/18/08
RE: Security vs. convenience: Apple chooses poorly  Chorizotarian | 08/18/08
Not sure how this is better...  rx7racer | 08/18/08
RE: Security vs. convenience: Apple chooses poorly  DannyO_0x98 | 08/18/08
RE: Security vs. convenience: Apple chooses poorly  npdavis@... | 08/18/08
News Flash... security "expert" misses the point!  techconc | 08/18/08
APPLE BASHING at its finest!!!  ronphlf@... | 08/18/08
Possibly the MOST stupid post on computing ever!  Win3.1 | 08/18/08
Trust  brunerd | 08/18/08
RE: Security vs. convenience: Apple chooses poorly  abuse.this2@... | 08/18/08
Said it before and will say it again. . .  psychosmurf | 08/18/08
Useless comment  rx7racer | 08/18/08
how?  richvball44 | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  james.scripko@... | 08/18/08
RE: Security vs. convenience: Apple chooses poorly  changeforge | 08/18/08
RE: Security vs. convenience: Apple chooses poorly  richvball44 | 08/19/08
Not Apple, but a dumb security model  cquirke | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  richvball44 | 08/19/08
RE: Security vs. convenience: GREAT FUN!!!  rickbarretttx | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  Jeffsters | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  joachim@... | 08/19/08
Security, Privacy & US gov't's corporatized DATA MINING & surveillance  BlueBerry Pick'n | 08/19/08
for crying out loud...  pgit | 08/19/08
I agree w/pgit  hadoz | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  FreeLaughs | 08/19/08
You can't be technology experts to say such stupid things!!!  rtalbert | 08/19/08
replace original drive at purchase  Jim Johnson | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  solson@... | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  solson@... | 08/19/08
RE: Security vs. convenience: Users stupity  rupaa62 | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  Eleutherios | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  mjolnar@... | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  euph0ria | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  mandehu@... | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  ceo@... | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  phatkat | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  hforman@... | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  apta | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  stephen.montano@... | 08/19/08
And Apple Users Make Fun of Microsoft Users?  melekali | 08/19/08
RE: Security vs. convenience: Apple chooses poorly  reuelb | 08/19/08
No Mac for me, just Linux and sometimes Windoz  se_lain@... | 08/20/08
Security?  mockingbirdfan | 08/21/08
This is a silly article  RealNonZealot | 08/25/08
I agree.  8wintermute8 | 08/26/08
typo?  mrbofus | 08/25/08
re: typo?  oliverday | 08/26/08
RE: Security vs. convenience: Apple chooses poorly *NOT*  8wintermute8 | 08/26/08
RE: Security vs. convenience: Apple chooses poorly  divemaster2@... | 09/09/08
They've never asked me for one...  astro_z | 09/25/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here