I regularly build little Raspberry Pi gadgets and hand them to friends or family. The tempting workflow is to clone a configured SD card and pass it over, but that image may still contain my SSH access, Wi-Fi credentials, API tokens, calibration history, application data, or persistent diagnostic logs. Raspberry Pi Imager makes setup convenient, including Wi-Fi and SSH configuration; it does not, as far as I can tell, turn that handoff into a privacy wipe.
Should a proper offline “change of owner” process become standard maker practice, basically a factory reset for homebrew hardware? I’d want it to remove or regenerate secrets, create the recipient’s account, and produce a readable local report verified after a clean boot—not rely on a vendor cloud. What would count as convincing proof, especially on flash storage? Disagree, share your handoff checklist, or describe a safer approach.