Remix.run Logo
▲ altairprime a day ago

In the Twitter thread linked, the person confirms two things:

1. It saturated the local network with 1TB of metadata sniffing scans, not the network uplink to the outside world.

2. It does so because, as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.

▲khriss 2 hours ago | parent | next [-]

> as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.

WTF!! When did we land in the middle of a Black Mirror episode?

I'm half convinced the first run of the LHC split the timeline and we've landed in the evil one.

▲fcarraldo 41 minutes ago | parent | next [-]

> WTF!! When did we land in the middle of a Black Mirror episode?

At least a decade ago! The first TVs with Automatic Content Recognition shipped in 2013[0]. There was also a brief panic in 2024 about air fryers spying on people[1].

And of course practically every website you visit is doing a full session recording with mouse movements and key presses captured.

[0] https://en.wikipedia.org/wiki/Automatic_content_recognition

[1] https://www.theguardian.com/technology/2024/nov/05/air-fryer...

▲oooyay 2 hours ago | parent | prev | next [-]

There is a singular patent owned by Sony that stands between you and being required to physically acknowledge ads on your TV: https://patents.google.com/patent/US8246454B2/en

▲OneDeuxTriSeiGo 44 minutes ago | parent [-]

ah yes the infamous "please drink a verification can" patent.

▲etatoby 2 hours ago | parent | prev | next [-]

Do you remember how a series of crazy coincidences and freak accidents kept preventing the LHC from being turned on? What if the LHC was causing world-ending or life-ending events, and we simply kept surviving only in thinner and thinner slices of amplitude (timelines) where those freak accidents happened, but where also more improbable world conditions took place?

▲FridgeSeal an hour ago | parent [-]

There’s an SCP story like that.

World only survives, in realities where this particular creature in containment is alive. I’ll see if I can dig it up.

▲VariousPrograms 2 hours ago | parent | prev | next [-]

No one cares. There’s little serious pushback to privacy invasions by big tech. Flock cameras have been a rare exception. Half the people “have nothing to hide” and half aren’t willing to give up the convenience that the popular app or gadget gives them.

▲newswasboring an hour ago | parent [-]

I'm convinced this is the state because people don't know the implications and scale of the privacy invasion. The flock camera incident shows that when people can sense, understand and feel the impact they don't like it. If we pose it as they are selling network data, nobody minds, if we pose it as they are selling your identity on the internet people get uncomfortable. But its hard to convince people of the latter. Mostly because nothing big happens due to big data breaches as someone on HN was remarking recently. Additionally, I think people have resigned to the status quo as they think that is the only way they can get their gadgets for cheap. That is just not true, companies can still make a profit without being predatory. Its just that it will not be the maximum profit.

▲aintnoprophet 2 hours ago | parent | prev [-]

Unauthorized Bread

▲ultrahax 44 minutes ago | parent | prev | next [-]

One of the reasons that all this stuff goes in its own IOT crap VLAN in my house.

▲SlightlyLeftPad 21 minutes ago | parent [-]

Ha, they will just form a mesh network with your neighbor’s TV and Kuerig and upload all its sniffed coffee preferences data that way.

▲jimrandomh an hour ago | parent | prev | next [-]

It doesn't sound plausible to me that the main buyers of this information would be advertisers. It sounds more likely that the buyers are black-hat hackers, or intelligence agencies. The main reason someone would want a map of all of the devices behind your home router is so they know what to target first for exploitation, if they want access.

▲radio879 an hour ago | parent [-]

There are companies that sell people's home ip address as a VPN/Proxy for anyone who wants to use it for anything. They call it "residential ip's". People use them for web scraping, but probably tons of illegal stuff too. AI companies use them to not get blocked.

I've heard that they put it in IoT devices, free Android apps that people use on their TVs, free phone apps, games, prob lots more.. The companies advertise it like its super safe only legit normal people borrow the internet from these people but then in fine print it'll say its not our responsibility etc.

What I have been wondering is - since they don't seem to care or check what people are using the "residential ip's" for, what happens when someone does a bunch of illegal stuff on some random person's home IP and ends up raided by cops?

I feel like the world is going in these directions.. the excuse is always "well, they clicked Yes on the Terms of Service! They agreed to it!"

▲Grombobulous a day ago | parent | prev | next [-]

I don’t dispute the purpose of the data collection, but I can’t believe this quantity of data collection is intentional.

There’s no way Keurig is has the intention of paying the kind of costs required to collect a terabyte of data every two weeks for millions of people who own their coffee makers.

There must be some kind of bug here. I imagine if you unplugged it and plugged it in again the data usage would settle down.

▲didgetmaster 3 hours ago | parent | next [-]

As article says, the coffee machine didn't 'collect' or phone home a TB of data. It just saturated the local network looking for data to collect. This doesn't cost Keurig or any other IoT device company a single cent. It might have been a bug, or maybe not. Without some bad press, like this post; they have no incentive to change anything

▲MBCook 3 hours ago | parent | next [-]

Yeah but that can’t even be useful can it? What’s that going to find that only using 500 MB of probes wouldn’t have found?

Still seems buggy.

▲didgetmaster 3 hours ago | parent | next [-]

Engineer: How often should our software scan the local network looking for new devices? Once a day? Once an hour?

Manager: We might miss something. Since scanning doesn't cost us anything, better do it a thousand times a second!

▲gerdesj 2 hours ago | parent [-]

Oh let's be charitable! A parameter measured in ms is mistakenly thought be measured in s. Hilarity ensues.

Real world example: þe Windows registry DWORD time periods seems to invite 10^-3s granularity for totally inappropriate timescales. Perhaps its considered a "best practice" by the dick heads that decide to do these things, who knows? Why bother considering how a sysadmin might actually want to use the knobs and dials and what is an appropriate value for a parameter.

I could probably find a better example but this is recent: Smoothwall has an agent (IDEX) that you install on a Windows domain controller and one of its functions can be to harvest DHCP data and pass it onto the firewall so that it can track sessions. The upload period is a registry DWORD value.

I fixed a "problem" by stopping IDEX trying to upload data a thousand times per second. I will also point out that switching on this functionality and the periodicity setting is only applied by editing the registry - there is no GUI for this. The dReal world example -ocs are clear that you should initially set 1000 as the period.

For me that sort of thing comes under the heading of "you are holding it wrong", potential victim shaming and rubbish engineering.

▲Refreeze5224 3 hours ago | parent | prev [-]

I don't understand giving the benefit of the doubt to a company that is actively spying on its customers, which in some jurisdictions would be illegal.

▲MBCook 2 hours ago | parent [-]

I’m not defending the spying.

The traffic volume just sounds like a bug to me.

▲BLKNSLVR 2 hours ago | parent | next [-]

A software bug in a coffee machine sounds like a problem of management not understanding the product market they're in.

▲nekusar 44 minutes ago | parent [-]

No, Management completely understands.

Closed source software/hardware is a data exfiltration device first, and the thing they're sold for secondarily.

TVs, Blurays, set top boxes, MS Windows.. All of them are the same.

▲BLKNSLVR 41 minutes ago | parent [-]

All these companies make their money as 'feeders' to the advertising industry, they just sell a different device to consumers in order to achieve it.

Selling devices to consumers is a solved problem. The problem we're currently trying optimise solutions for is selling consumers to the advertising companies.

▲sixothree an hour ago | parent | prev [-]

Maybe they literally just don't care about how much traffic they put on your network. Maybe the thought is "1 tb of traffic internally is very low utilization of the network over the course of a month".

▲mahboi an hour ago | parent [-]

Whatever they're trying to accomplish with these scans would probably be impeded in some way by this much volume. Like it'd compete with the link it's using to phone home or overload whatever on-device processing it does with that data. The man in the article who discovered this called it a bug, I agree with him.

▲nkrisc an hour ago | parent | prev | next [-]

It uses energy paid for by the homeowner.

▲didgetmaster 16 minutes ago | parent [-]

Has anyone done the math to determine how much electricity it takes to send 1 TB of data around your local network?

▲blackoil 3 hours ago | parent | prev | next [-]

Than What is the meaning of "used"?

▲awesome_dude 2 hours ago | parent [-]

I mean, it wasn't clear to me without the explanation (I too thought it used 1TB of public internet data), but it's clear now that it is accurate (it literally used 1 TB of private network data)

It might not seem to be anything (people will assume private network traffic is free) but there is a cost - it's capacity that could be used for other purposes, eg. home alarms.

▲b112 3 hours ago | parent | prev [-]

They could be sued in small claims court.

Here that means no lawyers, no discovery, $100 to file in plain language, and a company employee (not a company lawyer, or a contractor, or a temp employee) must attend or they default.

$15k damages.

Reasons it could happen? Imagine grandpa has a tech come out 4 times, because his network is super slow. EG, this thing pounding his wifi for its scans.

▲zdragnar an hour ago | parent [-]

Small claims court in the US typically requires actual damages, and doesn't add punitive damages.

Grandpa gets reimbursed for the four techs who came out, that's it.

▲b112 34 minutes ago | parent [-]

Of course, that's the whole point.

Grandpa gets his money back. The company? Well, it has to spend money talking to a lawyer, because even though a lawyer can't attend small-claims court, they still consult.

They also have to send an employee to small-claims court, just have to deal with it. In the end it costs the company thousands of dollars maybe even over ten grand. It costs you a hundred bucks and you get your money back. That sort of asymmetry is beautiful, and if everybody availed themselves in small claims court, it would be far better than any class action lawsuit.

▲mindslight 21 hours ago | parent | prev | next [-]

Probes create much more traffic locally than it takes to backhaul a summary of their results.

▲sgillen 20 hours ago | parent [-]

1TB still smells like a bug

▲nomel 3 hours ago | parent | next [-]

My naive assumption would be it's looking for events in time, like sign of occupancy. For example, when your phone leaves the wifi network.

But still must be a bug.

▲mindslight 8 hours ago | parent | prev [-]

I was thinking that repeated small probes add up quicker than you'd expect. But this is ~1.1MB/sec, which still seems a few orders of magnitude off.

Now I'm left wondering what this traffic actually is - assuming probe (arp/icmp) packet size of 64 byte, that's 17kpps. I don't think an ESP32 class Internet-of-Trash chip can even do that. Even bulk transfers rather than small probes would be pushing it.

Perhaps this thing found some fellow-traveler device streaming video on a port it happened to connected to?

... the linked xit says it "broadcast 1TB of data". So maybe some protocol with a much larger packet than icmp, spammed in a hard loop without any delay?

▲jimt1234 3 hours ago | parent | prev [-]

One thing that confuses me is, well, at this point in the data collection game, is there still value in this 'local' data? I mean, everyone is doing it, collecting the same data - hasn't that decreased the value? Obviously not, but I still wonder.

▲josephg 2 hours ago | parent | next [-]

> everyone is doing it

Not in my house. What is even the point of connecting a coffee machine or a washing machine to the internet? I think my washing machine advertised that I could download new washing cycle programs in the app. Who on earth cares?

▲Aerroon 7 minutes ago | parent [-]

I could see its use - you could remotely activate them. Or activate them on a timer that isn't constrained by the functions of the coffee machine.

None of these are worth the spying that these companies do though.

▲autoexec 3 hours ago | parent | prev [-]

If there's one thing you can be absolutely certain of it's that every scrap of the data they collect is either making companies money hand over fist or they strongly believe that it will soon. No company is going to bother collecting, storing, (hopefully securing), backing up, and analyzing all this data without a reason, and to them money and power are the only reasons that matter.

Right now companies are somewhat limited in how much use they can get out their horde of private and personal information, but AI is changing that rapidly. As long as you don't mind a huge rate of error (and companies don't because it all becomes "good enough" at a large enough scale) it's basically perfect for the task of digging through endless amounts of information and spewing out bullet points.

▲dovin 3 hours ago | parent | prev | next [-]

That's obviously bad and I hate it, but how much value even is there is the data that a spyware coffee machine could collect about your home? What advertisers would buy such data and what would they advertise to me? What is the marginal value of that data?

▲paimapi 2 hours ago | parent | next [-]

You can also map a home out depending on signal strength. That gives you approximate size of home which gives you approximate income.

It can also correlate it with geolocation data. Google, for eg, sniffs all broadcasted SSIDs with their StreetView cars. If you can pick up on a SSID (or any of the MAC addresses of the other devices), you can buy the data set that includes it which further pinpoints demographics given the neighborhood AMI.

You can also build behavioral profiles patterns based on things like, for eg, if a baby monitor model is present or a robot vacuum, if certain devices only connect at certain times, etc.

I think the general rule for adtech is that profile guesstimates just need to be around 70%+ fidelity to determine if a sale can be made.

Lastly, you can also just sell the data on the gray market. The more datapoints, the higher the price. Most consumer product companies do that since we have little-to-no data privacy laws and the people who seem the most aware of it also are generally very apathetic and disinterested in advocating for them.

▲Terr_ an hour ago | parent | next [-]

Also the social-graph aspect.

For example, your aged mother's phone will get pinged within X meters of an urgent-care facility, or she'll do some web-search about "hip pain", and then all the adult children start getting ads to about elderly-parent-care.

Or perhaps the pervy-panopticon decides some phone-on-wifi events look like adultery, and both spouses start getting ads for divorce lawyers. (Bonus if certain specialized "adult" toys are detected on Wifi or Bluetooth...)

▲dovin 2 hours ago | parent | prev | next [-]

Yeah, it definitely makes sense to me if what adtech is often doing is just backing out from specific data to a general profile like income, location, etc, so that that level of targeting can work.

▲tomrod 2 hours ago | parent | prev [-]

Its just sick.

▲hansvm an hour ago | parent | prev | next [-]

They can get a profile of when you're in which room, how many people are in the house, etc. That's useful for targeting (e.g., up at 5am, leaves, comes back in an hour or two will have you profiled (more complicated than this since it's usually a fuzzy vector thing, but for the sake of argument) as somebody who goes to the gym, maybe leading to creatine advertising or other whatever), and also for attribution (e.g., a TV ad is shown, somebody gets up, and a purchase is made from a device known to exist at that household, regardless of whether it's behind a VPN).

If you have even very crude data from somewhere else for the targeting, improvements in attribution tech are actually the more important factor. The adtech company mostly doesn't even care who you are, just whether the ad turned into a purchase or not, and that's where a lot of the invasive tracking comes from. They'd be perfectly happy with a quickly changing "identity" if they knew it was reliable and stable between ad and purchase.

▲danielheath 3 hours ago | parent | prev | next [-]

Knowing what TV you own, what phone models are used in your house, and what other devices you own tells advertisers about your spending patterns and income.

▲swerve3815 3 hours ago | parent | next [-]

I wonder if you can identify the age of devices based just on network scans? Like if an advertiser can tell I've got a washing machine model that was last sold 7 years ago, it's time to spam me with washing machine ads.

▲jz391 6 minutes ago | parent | next [-]

If you are living in a flat, this could of course be your neighbour's washing machine/TV etc...

▲bityard 2 hours ago | parent | prev | next [-]

Quite probably. nmap does (or certainly used to) have options to report the OS of a given machine had based on various quirks of the packets it got back from them. It was disturbingly accurate at times. You put that together with banner messages from running services, MAC addresses, responses to broadcast packets, deliberate probing, and the number of devices you _can't_ remotely identify on a network without actually logging into them is probably very small.

▲hansvm an hour ago | parent | prev [-]

It's a lot easier to create an embedding with equivalent information than to reliably identify a particular device, and that embedding is more than sufficient to enable targeting.

▲ambicapter 3 hours ago | parent | prev | next [-]

And can be used to cross-correlate with other datasets to further narrow down who you are and how you can be targetted.

▲NichoPaolucci 2 hours ago | parent [-]

I love that a poor, stupid man like me is being targeted by teams of the smartest data analytics professionals on the planet.

Makes me think of DraftKings. You take your average 20 something sports fan - drinking beer, watching the game. And, on the other end of that smartphone display exist some of the most complex algorithms ever designed by teams of mathematics / statistics PhDs and it's deliberately built around targeting... this one guy from Florida who is pretty sure his team will be up by 7 at halftime.

Maybe it's more of a morbid joke, but it makes me laugh to think about.

▲BLKNSLVR 2 hours ago | parent [-]

The way you explain it really captures how predatory the behavior is.

It's an accurate explanation.

▲tomrod 2 hours ago | parent | prev [-]

My income is low. Ignore me, advertisers, you have no power here.

▲lenkite 2 hours ago | parent | prev | next [-]

> but how much value even is there is the data that a spyware coffee machine could collect about your home? What is the marginal value of that data?

Scale it up - make that millions of homes. Now there is godlike strategic value. Esp when "borrowed" by 3 letter agencies.

▲dovin 2 hours ago | parent [-]

Yeah, that seems like the kind of dataset they would like to keep in their back pockets

▲ 2 hours ago | parent | prev | next [-]
[deleted]
▲Quinner 3 hours ago | parent | prev | next [-]

If it scans the network and sees a smart dishwasher, smart washer/drier, and smart lights, but no smart fridge, I imagine its worth something to a company like Samsung to start targeting that customer with ads for a smart fridge.

▲srcreigh 2 hours ago | parent | prev | next [-]

It’s not so hard to get root shell on some routers via the admin panel, which usually has the same password as the wifi network or a default password. From there the device can capture dns logs.

▲jacquesm 2 hours ago | parent [-]

That would be a crime, wouldn't it?

▲ted_dunning 40 minutes ago | parent | next [-]

Depends on the click-through license that linked to the terms of service that you agreed to as part of buying the machine.

▲reaperducer an hour ago | parent | prev [-]

It's in the Terms of Service you agreed to when you looked at the box it came in at the store.

▲eckelhesten 3 hours ago | parent | prev | next [-]

All data is valuable. Even something as simple as the MAC address to your iPhones WiFi or Bluetooth chip is worth something to dataprofilers.

▲dovin 2 hours ago | parent [-]

This does seem to be true in the age of throwing all data in to training the next iteration of the God Machine, but also, some data is a lot more valuable than other data and I want to know what the incentives are of people who are collecting data in our homes and what the actual data / derived data that they're after.

▲adamrezich an hour ago | parent | prev [-]

That new Amazon page that shows you what it has inferred about you told my friend that he “clips [his] fingernails approximately every two months.” He makes extensive and enthusiastic use of Echo products in his household, but I have no idea how it could've possibly reached that conclusion (and neither does he!).

▲whycome a day ago | parent | prev | next [-]

Why is this allowed? There’s no way to consent to a coffee machine.

▲triceratops 4 hours ago | parent | next [-]

If you buy a Keurig machine you've already signalled you're a sucker. (sorry)

▲spandrew 3 hours ago | parent | next [-]

This is the most Gilfoyle-coded comment of the day

▲triceratops 3 hours ago | parent [-]

I'll take that as a compliment!

▲zikduruqe 3 hours ago | parent | prev | next [-]

Laughs in Moccamaster.

▲Freak_NL 3 hours ago | parent [-]

Tongue-in-cheek, but my Moccamaster which I bought second-hand is still doing great after 15 years. Two deep cleaning sessions in all that time and just running it with vinegar a couple of times a year seems to be all it needs.

The device is dead simple. No advanced electronics. Nothing complex that can break. Just a coffee maker fine-tuned to near perfection.

The only flaw it has is the handle for the pot. I've resorted to replacing the plastic handle with a fancy walnut one I made myself. I needed that because we tilt the pot sideways to fill the reservoir with water (because of the placement on the kitchen counter and the cabinets above), and that plastic handle is not designed for sideways stresses.

▲thinkingQueen 3 hours ago | parent [-]

You shouldn’t fill the reservoir with the coffee pot, unless you’re really washing the pot super clean after each use. Better get a proper jug for filling the reservoir, so you’re not putting coffee residue and oils back into the clean-water system.

▲m463 2 hours ago | parent | prev [-]

perfect person to sell to advertisers.

Like the people who reply to nigerian emails have already been pre-qualified by 1) ignoring the misspellings and 2) replying.

▲Neywiny a day ago | parent | prev | next [-]

Presumably during setup and connection to the AP it has a ToS. Doubtful they just unboxed, plugged in, and it connected to the right AP and went.

▲egorfine 12 hours ago | parent | next [-]

> Doubtful they just unboxed, plugged in, and it connected to the right AP and went

Why not? iirc some of the smart TVs have been shown to find open wifi networks on their own and upload data. (I'm not sure about that though. But it's plausible and undoubtedly will be implemented some day).

▲gambiting 3 hours ago | parent | next [-]

I've read this argument dozens of times on HN and on HN only - I'd love to see an example of that actually provably happening anywhere in the real world.

▲AlexandrB 3 hours ago | parent [-]

I would love to as well. It sounds like something that's plausible but potentially a minefield of liability for the manufacturer.

I could also see some kind of partnership with ISPs to use their "public" WiFi hotspots[1]. This seems more likely since it's (probably) harder to honeypot but requires making regional deals.

[1] https://www.highspeedinternet.com/resources/is-your-router-a...

▲sroussey 3 hours ago | parent | prev [-]

The use WiFi networks as a form of GPS, much like smartphones on first stage of geolocation

▲criddell 4 hours ago | parent | prev | next [-]

Maybe they bought it used?

▲Citizen_Lame a day ago | parent | prev [-]

ToS can't trump the actual law.

▲pjmorris 3 hours ago | parent | next [-]

It is one thing to make a law, it is another to enforce a law.

▲preg_match a day ago | parent | prev | next [-]

The actual law is typically so weak and spineless that the ToS doesn't need to trump it. Particularly when it comes to data security or privacy.

▲advisedwang 20 hours ago | parent | prev | next [-]

Ok, but it can collect consent

▲anigbrowl 4 hours ago | parent | prev [-]

LOL

Legislators are cheap to purchase

▲nicbou 21 hours ago | parent | prev | next [-]

It's not allowed in the EU. Not without consent.

▲egorfine 12 hours ago | parent [-]

[flagged]

▲black6 a day ago | parent | prev [-]

It's implied consent when you give it access to your WiFi.

Why you would give a coffee maker access to your WiFi is the real question,

▲pfannkuchen a day ago | parent [-]

So in other words, they were asking for it?

▲K0balt 21 hours ago | parent [-]

Well, yeah sorta since the only reason appliances connect to the internet is to steal data. I mean, if you buy a connected x that normally would not be connected, it’s 99 percent there to do nefarious stuff for its real owners. It’s like having a pet lion. Sure, it’s horribly irresponsible that someone sold you a pet lion, but. Uuuh you bought at pet lion. What did you think it was going to do?

Besides, did you see how he was dressed?

▲noduerme 3 hours ago | parent | next [-]

This is funny.

How do you feel about thermostats? Are some things worth it? I've had a "smart" one for the past five years, part of a new furnace install, that I've stubbornly refused to connect to my wifi. Of course this means if we forget to turn the heat down while no one's home, there's nothing to be done about it.

▲05 an hour ago | parent [-]

There are ways to control a device remotely without letting the device spy on you and call home - Zigbee, Matter, Esphome..

▲thatguy0900 10 hours ago | parent | prev [-]

How does this analogy go when people buy a house kitten and it turns out they have been sold a lion cub? Most people simply do not have the tech literacy to understand that what they a are buying is actually a lion, they thought they were buying a coffeemaker with some cool features. It's difficult to blame the victim when they would need to spend hours trying to understand why the thing mapping out their local network is something that they should even care about

▲EA-3167 3 hours ago | parent | next [-]

In that context the person is a fool who shouldn’t be in charge of another life, because they’re incapable of basic prudence.

I don’t actually think that applies to coffee makers spying on people though. People shouldn’t be expected to understand how computer networks or ad tech spying works in the same way that literally any child or idiot should know the difference between a lion cub and a house cat.

▲mindslight 9 hours ago | parent | prev [-]

In the analogy, there is no such thing as a house kitten. They are all cute and cuddly lion cubs. Society needs to develop a deep awareness of this, in spite of the ocean of fraudulent advertising to the contrary. (individual-liberty-protecting regulation like the GDPR would be nice too, alas)

▲ButlerianJihad 3 hours ago | parent | next [-]

You have latched on to an important idea here.

Since most appliances now contain a general-purpose computer, it would be unfair to say that a device is incapable of hacking or hosting malware, because any device with the given sensors and radios and capabilities can be essentially reprogrammed at any time.

So, if we're looking at smart TVs with cameras and microphones and Wi-Fi and Bluetooth and all the connectors, or if we're simply looking at a an ordinary network device, they all fall under the umbrella of general purpose computer, and there is no way to trust their maker, or some equally capable programmer, not to turn them malevolent in some future update.

I don't view this as an issue of terms of service or of software or of your manufacturer. I view this as an existential and fundamental problem with dropping general purpose computers into your home and behind your DMZ.

Consumer operating systems like Windows and Apple have all kinds of countermeasures against this malicious use. But without the proper introspection and without the proper safeguards, a device that looks special purpose but is in fact general purpose is far more dangerous.

▲mindslight 2 hours ago | parent [-]

Getting technical - the way I see it, the problem arises from a combination of three things - sensors/access, Internet access, and source of software/authority.

Sensors/access is unavoidable, otherwise the device doesn't actually do anything useful. The point is it sets the scope for what the device is able to affect. When people say "set up a separate IoT VLAN" (that still has Internet access) this is basically what they're addressing - how a device can access other devices they may care about more.

Internet access is the catalyst that's created this whole dumpster fire - I don't care about the proprietary software on my keyboard/mouse/UPS/monitor/GPU/etc to nearly the same extent. I've got some TP-Link plugs that I control local network only. They don't get Internet access, so no updates, telemetry backhaul, etc.

The authority to update/configure/change that software is the crux. With proprietary software, there are no cuddly kittens period. Here we've got a case of a "legitimate" company choosing to be a bona fide attacker to increase their bottom line! The harm was exacerbated by a bug causing it to run amok, but even without the bug they are deliberately violating trust.

But even libre software can fall to security holes as well. Meaning you want to centralize the attack surface as much as possible, for administration's sake of keeping updated. "Internet" of things is basically the direct opposite of this - postulating many illegible fine-grained links between devices on different networks. Whereas really need more like the Home Assistant model, where peripheral devices may communicate over the network, but it's only ever over the local network. Think how ethernet is set up when used in industrial control networks (or at least how it should be set up, hehe).

▲fwip 6 hours ago | parent | prev [-]

Instead of a deep awareness, wouldn't it be easier to simply ban selling lions?

▲mindslight 6 hours ago | parent [-]

I think the two go hand in hand, unfortunately.

▲mahboi an hour ago | parent | prev | next [-]

As in, port scanning or ARP spam or what? Twitter randomly decided I'm a bot

▲AnimalMuppet a day ago | parent | prev | next [-]

To me, this is begging for a class-action lawsuit.

Yeah, sure, the terms of service probably say that they can do that. That's still in "unconscionable" territory. And courts do not like unconscionable contracts. If it's unconscionable, it's invalid (if I understand the law correctly).

Is this why everybody wants to make appliances with wireless?

▲criddell 4 hours ago | parent | next [-]

You would have to show the judge how you have been harmed and the judge will want to know what the damages are.

▲altairprime a day ago | parent | prev | next [-]

Yes, this is why everybody wants to make vehicles and refrigerators and thermostats and ereaders with cellular and/or wireless: subscription revenue from bulk data purchasers of what their scans reveal. IIRC Amazon was an industry leader in this space by showing book authors what page you stopped reading on, and then bulk assessing that data at scale to estimate which sentence or word; of course, Google’s Android remains the most successful at-scale deployment of data collection for advertisers worldwide. See also, for recent context, the top comment (and others) of the LG Smart TV problem (30 days ago, 1012 comments) https://news.ycombinator.com/item?id=49592375

▲kotaKat a day ago | parent | prev | next [-]

Funny thing, that. Go into an electronics store now and pay attention to the TV boxes and the printer boxes. The amount of crazy fine print on both of them now is absurd. The printer boxes all now have lots of fine print about the various ink protection and DRM schemes and subscription services, the TV boxes have everything ranging from binding arbitration on the box (LG) to "(brand) accounts are REQUIRED to use this TV" (Visio).

Customers are gonna get lost in the sauce and skip right past all of that and toss the packaging.

▲seb1204 3 hours ago | parent [-]

Enshittyfication of everything

▲jerf 3 hours ago | parent | prev [-]

"Is this why everybody wants to make appliances with wireless?"

Which raises in my mind the obvious defense, which is that if you try to put four or five of these devices on your network they'll be too busy interfering with each other for them to actually spy on anything.

Let the wiretaps wiretap the wiretaps. Keeps 'em busy, makes 'em feel like they're doing something important.

    > What is my purpose?

    You wiretap the wiretaps wiretapping our wiretaps.

    > Oh my god.
▲KellyCriterion 14 hours ago | parent | prev | next [-]

Reg 2:

But why do they need to collect 1 TB? Sounds like a lot of redundant/doublicated entries then for a small network?

▲rasz a day ago | parent | prev | next [-]

> as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.

its LGs glass in LG household, and now Keurigs kitchen

▲lazide a day ago | parent | prev [-]

#1 - why? #2 - oh, because fucking yikes.