(Some) Computer Technicians Are Creepy
secretGeek .:dot Nuts about dot Net:.
home .: about .: sign up .: sitemap .: secretGeek RSS

(Some) Computer Technicians Are Creepy

he right clicks task bar and selects properties

Well, this leaves me feeling somewhat sick in the stomach.

I was planning to put out some other blog entries just now, but i've felt dizzy and nauseous for the last few hours. Here's the story:

Last week I took my computer in to the shop to get it fixed. (I refuse to deal with hardware. I don't even change staples in a stapler. I have the midas touch and can even blow up passive circuits when they're disconnected plus i'm wearing a static wrist strap.)

I got the computer back a few days later and everything was fine.

he goes to advanced menu and clicks on clear list

On a crazy paranoid whim, I decided to look back through my TimeSnapper history to see if the technicians had used my computer in any unexpected ways.

I've been meaning to check this all week. I even woke in the night once, thinking: I really ought to check what TimeSnapper says happened on my computer when it was in the shop.

Well I finally got around to checking, just now. And what I found has left me unwell. It's nothing too major, but here goes.

A technician started up the computer and spent a short while looking through the 'my pictures' folder. First they looked at some photos of my baby daughter. Then they perused through some other family photos. Finally, they cleared the 'recent documents' list, checked that it was clear, and shut down the computer. (Sequence shown at right.)

The bit where they deleted the recent documents list happened extremely quickly. Watching it play out i am certain that they've done this activity many times before on many other people's machines.

he check that recent documents are indeed clear

I'm not too worried. They were pretty quick about it, only had the most cursory glance really. All sorts of other things were possible. My paranoid delusions included them installing a keylogger, searching for banking information. Lots of other possibilities. So it's not bad as such. I'll probably continue to use them for my computer needs (hey they're the best in town). But I'll probably create a guest account with minimum permissions, next time. And I still wonder what other things dirty technicians are getting away with on other machines entrusted to their care.

Okay that's off my chest now. And onto yours ;-)

 





'honest<T>' on Fri, 29 Feb 2008 11:55:38 GMT, sez:

If you give your computer to a technician and don't have a password on it then you get what you deserve.

You got away lightly!



'jtboofle' on Fri, 29 Feb 2008 12:18:33 GMT, sez:

Unfortunately, this is really common.

See: http://consumerist.com/consumer/investigations/video-consumerist-catches-geek-squad-stealing-porn-from-customers-computer-271963.php



'Chad' on Fri, 29 Feb 2008 12:53:11 GMT, sez:

That's really disappointing. However creating a limited user account won't work for techs - they may need admin access on your machine to do their job.

I believe that creating password protected accounts will limit access to other password protected accounts personal folders though, so you should at least do that.

My friend actually got "burned" by this when he reinstalled (not formatted) his machine without backing anything up. His admin account no longer had access to his old user directory!

If your pictures are stored outside of your user account folder, they won't be protected with this.

We put a lot of trust in our service people - Janitors, Car repair tech, Garbage collectors (need I say TSA reps?) all have access to vast amounts of personal information. Hopefully most of them are behaving in a professional manner, but you may want to "encourage" this particular tech by talking to his/her manager about the issue.



'aaron' on Fri, 29 Feb 2008 13:26:42 GMT, sez:

Weeellll...I'd disagree with mr. honest<t>.

1.) if you have physical possession of the machine, a p/w is largely irrelevant
2.) often a tech needs the admin password to do whatever it is s/he needs to do.

And if it really comes to it, there are numerous linux live (bootable) CD's that'll mount an NTFS filesystem and allow untraceable browsing and/or resetting of any of the account passwords.

Per jtboofle, I'd wager that's what your wayward tech was indeed looking for.

The only way, off hand, I can think of providing some small modicum of protection would be to use ntfs encryption on those folders you'd like private. (mydocs, etc) It's tied to the nt user, so the tech logging in as a separate user (admin or not) wouldn't be able to browse 'em.

Come to think of it, Vista does this (or something like it)...

Anywho...if that's defeated (let's say, by the aforementioned pw reset) you'll know...because your account password will be different.

All that said, this doesn't sound like a particularly tech savvy tech...if he didn't notice timesnapper running in the background. =^)))))

I have to relate a story: (I'm almost done, really!)

I've trumpeted the goodness of timesnapper far and wide in the IT department where I work. Great for filling out timecards and figuring out "just what _was_ I doing last monday?!!" A few have installed it, including this manager friend-of-mine.

Now this manager friend has a nasty habit of walking away and leaving his computer unlocked. Bad, bad, bad.

I decided to "clippy" him. ( http://www.rjlsoftware.com/software/entertainment/clippy/ ) Stuck the .exe on a network share for one of my servers, and when I next found his PC unlocked, walked up <start>=><run>=>\\aaronserver\share, copied the file over and launched it.

The next morning he called me into his office and wondered aloud what could have happened to his system. Thought some odd spyware might have infected it.

Then he looked at me and grinned an evil grin. "So I decided to look back over my timesnapper history and see what could have happened..."

Oh s##t.

I'd been caught red-handed. (so to speak) He saw the file copy, the server name, etc.

We both laughed.

And now he always locks his system. =^)

-aaron



'Colin' on Fri, 29 Feb 2008 22:26:25 GMT, sez:

If you really don't want people like this to have access to your data in this way remove it before they get it if you can or put it in a truecrypt file/drive (and hope they can freeze the memory chips)
Admin accounts can easily be reset in XP (I personally would not know about Vista) so I think various accounts will not help much



'Phillip' on Tue, 04 Mar 2008 12:47:29 GMT, sez:

Actually, as a computer technician, I can see where this could be used legitimately. I've had cases where people will ask for things to be done, whether software installed or removed or hardware upgrades, and find out that it's affected several unrelated things in strange ways. After enough times having things brought back to me because something was "different", I got used to just checking everything to make sure that documents would open correctly, pictures would open, and websites would load, just to name a few. It takes me all of ten minutes to go through and test everything, versus up to half an hour or more if the client has a complaint. And when you're talking on-site service, it can eat a couple or more hours out of your day that you can't charge for. Better to test it all, and then you can say honestly "I checked it for functionality, everything seems fine." I even tell people what I did if they seem at all interested. Most people want to pay and go on, though.

However, there are some technicians I've known that will look to see if you've got anything 'interesting' in your "My Pictures" folder, and I've no doubt some will look for banking information. What you have to take into consideration is whether the guy that's working on your system has a vested interest in making it work, or is it just some high school kid making some side money? That does tend to figure high in the reason for looking there.

Go with your gut. If you think they're not trustworthy, don't give them your computer. If you think they are, then give it to them. But always keep backups of the important stuff.



'lb' on Tue, 04 Mar 2008 19:57:52 GMT, sez:

@Phillip

Yeh, what you describe is a 'smoke test' where you make sure that a few basic things work. And this was no smoke test.

Trusting your 'gut' is not as good as using careful measurement. In this case I have figures to show that my gut instinct was wrong.



'mrwilhite' on Mon, 29 Sep 2008 23:36:33 GMT, sez:

Thinks if you are that concerned about what they are looking at on your computer, that it shouldnt be there! Forget time snapper! Store all sensitive information on an external hard drive or a password protected partition. Security is the responsibility of the owner/user. Find a tech which HAS a security clearance and or is bonded. Locks etc are only to keep the honest man honest, the same holds true for passwords and computer security. Time Snapper will not stop a good tech and wouldnt even slow me down if I were looking to access a computer. A guest account? I would laugh and recommend a shop down the street! Do you wear a tin foil hat to keep aliens from reading your mind? As the Time Snapper Icon below says "Know Thyself"



'John Smith' on Mon, 05 Jan 2009 15:47:30 GMT, sez:

I am a pc technician and in alot of cases it is neccassary to view the customers documents folder to assertain the next proceddure for backup, this is because usually custmers dont have a backup copy of there work and personal files and I do not do anything to a computer until the customers documents are backed up. I always explain this to the customer




name


website (optional)


enter the word:
 

comment (HTML not allowed)


All viewpoints welcome. But the right to delete any post for any reason is reserved. Don't make me do it. Aim for constructiveness. Comments may be republished, emailed to your loved ones or printed and used as toilet paper. Also, I get particularly nasty on comment spam. It's not worth even trying to post comment spam here -- your html is escaped, and your links are given a rel='nofollow'. By attempting to post a comment, you understand that if the comment is considered spam, at my absolute discretion, your IP address may be used as the target of a prolonged distributed denial of service attack. Your electricity might suddenly stop working. Your car tyres will go mysteriously flat. You will suffer permanent hairloss. Your dreams will be filled with terrifying monsters. And in any case I reserve the right to record and publish your IP address.

 

TimeSnapper is a life analysis system that stores and plays-back your computer use. It makes timesheet recording a breeze, helps you recover lost work and shows you how to sharpen your act.

 

NimbleText - FREE text manipulation and data extraction

NimbleText is a Powerful FREE Tool

Use it for:

  • extracting data from text
  • manipulating text
  • generating code

It makes you look awesome. Use it right now! Go on! Hurry! Don't walk, run!

 

Articles

Mind-boggling Demo of New Gaming Genre, aka Folder-Based Hangman, aka Fun with Recursion Mind-boggling Demo of New Gaming Genre, aka Folder-Based Hangman, aka Fun with Recursion
Got CSV in your javascript? Use agnes. Got CSV in your javascript? Use agnes.
I went to write down a book name and founded an internet empire instead. I went to write down a book name and founded an internet empire instead.
NimbleText: Origins NimbleText: Origins
The Windows 8 Mullet The Windows 8 Mullet
Cosby: spontaneous striped background generator Cosby: spontaneous striped background generator
Slides from WDCNZ: Live Coding Asp.net MVC3 Slides from WDCNZ: Live Coding Asp.net MVC3
MVC 3, MVC 3, "Third Times a Charm" references
Custom Errors in ASP.Net MVC: It couldn't be simpler, right? Custom Errors in ASP.Net MVC: It couldn't be simpler, right?
Anatomy of a Domain Hijacking, part 2: The Website Who Came In From The Cold Anatomy of a Domain Hijacking, part 2: The Website Who Came In From The Cold
Anatomy of a Domain Hijacking, part 1 Anatomy of a Domain Hijacking, part 1
secretGeek.net domain has been stolen. The site may go down. secretGeek.net domain has been stolen. The site may go down.
Boring article: 'untrusted domain' issue with SQL Server. Boring article: 'untrusted domain' issue with SQL Server.
Coding While You Commute Coding While You Commute
Test Driven Dentistry Is A Good Thing Test Driven Dentistry Is A Good Thing
The 'less crashy' release of NimbleText The 'less crashy' release of NimbleText
Rethinking Toolbars in Visual Studio (or any IDE) Rethinking Toolbars in Visual Studio (or any IDE)
Where shall we have lunch? Where shall we have lunch?
Setting up email for your microIsv Setting up email for your microIsv
The NO Visual Studio movement: Compiling .net projects in Notepad++ The NO Visual Studio movement: Compiling .net projects in Notepad++
ZeroOne: the editor for programmers who think in binary ZeroOne: the editor for programmers who think in binary
Mercurial workflow for personal projects (with a .net bias) Mercurial workflow for personal projects (with a .net bias)
I see you're using vim. Let me fix that for you. I see you're using vim. Let me fix that for you.
The worst recruitment spam I've ever read The worst recruitment spam I've ever read
A thank you I forgot to say A thank you I forgot to say
My new product, NimbleText, is live My new product, NimbleText, is live
Grabbing the free songs of Jonathan Coulton (with Powershell) Grabbing the free songs of Jonathan Coulton (with Powershell)
Using NimbleSet to compare lists Using NimbleSet to compare lists
Wanted: Wiki Lists (dot org) Wanted: Wiki Lists (dot org)
DOS on Dope: The last MVC web framework you'll ever need DOS on Dope: The last MVC web framework you'll ever need
JSON Query Languages: 5 special purpose editors JSON Query Languages: 5 special purpose editors
What then, is b? What then, is b?
SQLike: A simple editor SQLike: A simple editor
Yet Another BizPlan Generator. Yet Another BizPlan Generator.
HOT GUIDS: A hot or not site for guids HOT GUIDS: A hot or not site for guids
How does life get better? One tiny hack at a time. How does life get better? One tiny hack at a time.
24 things to do, and 100 things *not* to do (yet) for building a MicroISV 24 things to do, and 100 things *not* to do (yet) for building a MicroISV
Venture capital won't kill Jeff Atwood, it will only make him Jeffer. Venture capital won't kill Jeff Atwood, it will only make him Jeffer.
A handy workflow image for newbie mercurial users A handy workflow image for newbie mercurial users
Fractal Feedback, a diversion into recreational programming Fractal Feedback, a diversion into recreational programming
Hump-Jumping: How the Education of Computer Science can be Saved, err, maybe. Hump-Jumping: How the Education of Computer Science can be Saved, err, maybe.
Suggested User Experience Improvements for DiffMerge Suggested User Experience Improvements for DiffMerge
SQL Style Extensions for C# SQL Style Extensions for C#
The Movie Hollywood (And My Wife) Doesn't Want You To See: Weekend at Jacko's The Movie Hollywood (And My Wife) Doesn't Want You To See: Weekend at Jacko's
Sysi: the ultimate administrators toolkit Sysi: the ultimate administrators toolkit

Archives .: secretGeek :: Complete Archives
TimeSnapper -- Automated Screenshot Journal TimeSnapper.com    
Version 3.3: true productivity boost

Next Action NextAction
Managing the top of your mind

NimbleText -- World's Simplest Code GeneratorNimbleText -- World's Simplest Code Generator, Text Manipulator, Data Extractor

25 steps for building a Micro-ISV 25 steps for building a Micro-ISV
3 minute guides -- babysteps in new technologies: powershell, JSON, watir, F# 3 Minute Guide Series
Universal Troubleshooting checklist Universal Troubleshooting Checklist
Top 10 SecretGeek articles Top 10 SecretGeek articles
ShinyPower (help with Powershell) ShinyPower
Now at CodePlex

Realtime CSS Editor, in a browser RealTime Online CSS Editor
Gradient Maker -- a tool for making background images that blend from one colour to another. Forget photoshop, this is the bomb. Gradient Maker


[powered by Google] 


How to be depressed How to be depressed
You are not inadequate.



Recommended Reading


the little schemer


The Best Software Writing I
The Business Of Software (Eric Sink)

Recommended blogs

Jeff Atwood
Joseph Cooney
Phil Haack
Scott Hanselman
Julia Lerman
Rhys Parry
Joel Pobar
Thomas White
OJ Reeves
Eric Sink

Aggregated Links

proggit
dzone
hacker news
dot net kicks

Human Link Machines

interesting finds
a continuous learner's weblog
arjan's world
weekly link post

LinkedIn profile
LogEnvy - event logs made sexy
Computer, Unlocked. A rapid computer customization resource
PC Smart Buys - Computer Hardware in Australia
 
home .: about .: sign up .: sitemap .: secretGeek RSS .: © Leon Bambrick 2006 .: privacy

home .: about .: sign up .: sitemap .: RSS .: © Leon Bambrick 2006 .: privacy