Ashton is actually convinced—on what does not appear to me compelling evidence—that the bad guys compromised his machine via a used iPhone beginning five years ago.
I made a house call to A’s rustic cottage in the wine country over the weekend in hopes of resolving his real or fancied security issues. I came away persuaded, if not certain, that his concerns are largely misplaced; he in turn was genially unconvinced by my assurances. I was, I think, able to demonstrate that at least some of the symptoms he believed to be evidence of hacking were no such thing, and stemmed from misconceptions about the Mac UI, and particularly about the way the “Dock” works, in one instance invoking on my own unconnected MBP a piece of visual feedback he’d considered damning evidence of outside interference.
There were other issues. His password recording hygiene (my own is not flawless) could be better. It took us a few attempts, where successful, to go places we needed to go. In other instances, we came a-cropper. His supposed iCloud password, revealed in Keychain Access, was a string of gibberish, and not the familiar characters he recalled. The string of gibberish, carefully entered (on the new machine, using my phone as a WiFi hot spot), was not recognized. Easy-peasy: enter the phone number associated with this account and Apple will help you reset the password via that device. Er, the phone was believed compromised, as mentioned above, and so the service was cancelled. Got a sort of Gordian knot thing going here.
Ashton believes that he is being hacked via AirDrop. Research suggests that AirDrop has an effective range of about ten meters, so unless the one neighbor within that distance is the author of his grief, this seems as implausible as his earlier Bluetooth model. He also asserted that the new iMac had also been infected, and that a dodgy icon for “GoToAssist”* (which I was able to remove from the old unit) had appeared in its dock. It was not there when we turned on the machine; nor could I find any evidence that the software had ever been in residence.
I append here a snippet from the Terminal app that, saith A, appeared unbidden on his screen the other day, although it appears to be a record from a month ago. It alarmed him deeply, and he takes it to mean that the baddies have been changing his passwords (I saw no evidence of this in Keychain Access). I’ve screenshotted and redacted it:
I see another house call in my future, because we’d left some issues unresolved, including the cabling configuration for his television/internet setup, by the time Lina, her errands in nearby Sonoma discharged, arrived to retrieve me. I’m particularly keen to determine which of the two “xfinity” wireless networks detectable from the premises is his: my money is on the unsecured one.
cordially,
*My understanding of this tech is, to put it mildly, imperfect, but if some external bad actor were actually fucking with A, GoToAssist, which some techie apparently installed on a consultation years ago, would seem a likelier channel than some of his other candidates.
I made a house call to A’s rustic cottage in the wine country over the weekend in hopes of resolving his real or fancied security issues. I came away persuaded, if not certain, that his concerns are largely misplaced; he in turn was genially unconvinced by my assurances. I was, I think, able to demonstrate that at least some of the symptoms he believed to be evidence of hacking were no such thing, and stemmed from misconceptions about the Mac UI, and particularly about the way the “Dock” works, in one instance invoking on my own unconnected MBP a piece of visual feedback he’d considered damning evidence of outside interference.
There were other issues. His password recording hygiene (my own is not flawless) could be better. It took us a few attempts, where successful, to go places we needed to go. In other instances, we came a-cropper. His supposed iCloud password, revealed in Keychain Access, was a string of gibberish, and not the familiar characters he recalled. The string of gibberish, carefully entered (on the new machine, using my phone as a WiFi hot spot), was not recognized. Easy-peasy: enter the phone number associated with this account and Apple will help you reset the password via that device. Er, the phone was believed compromised, as mentioned above, and so the service was cancelled. Got a sort of Gordian knot thing going here.
Ashton believes that he is being hacked via AirDrop. Research suggests that AirDrop has an effective range of about ten meters, so unless the one neighbor within that distance is the author of his grief, this seems as implausible as his earlier Bluetooth model. He also asserted that the new iMac had also been infected, and that a dodgy icon for “GoToAssist”* (which I was able to remove from the old unit) had appeared in its dock. It was not there when we turned on the machine; nor could I find any evidence that the software had ever been in residence.
I append here a snippet from the Terminal app that, saith A, appeared unbidden on his screen the other day, although it appears to be a record from a month ago. It alarmed him deeply, and he takes it to mean that the baddies have been changing his passwords (I saw no evidence of this in Keychain Access). I’ve screenshotted and redacted it:
I see another house call in my future, because we’d left some issues unresolved, including the cabling configuration for his television/internet setup, by the time Lina, her errands in nearby Sonoma discharged, arrived to retrieve me. I’m particularly keen to determine which of the two “xfinity” wireless networks detectable from the premises is his: my money is on the unsecured one.
cordially,
*My understanding of this tech is, to put it mildly, imperfect, but if some external bad actor were actually fucking with A, GoToAssist, which some techie apparently installed on a consultation years ago, would seem a likelier channel than some of his other candidates.