hm, and you don't see a problem with sending a device with unencrypted personal data not knowing what they will do with it? e.g. there is my google account wich can be used to activate other devices - including email, password manager and google pay... and amazon, and kobo, and...
what do they do with the devices they get - looking at the reddit posts they send you a new one - so sombody now has a device with your data. i don't think it's a big problem to read out the memory or reactivate the device...
|