| |
| ▲ | MBCook a day ago | parent | next [-] | | Yeah but that can’t even be useful can it? What’s that going to find that only using 500 MB of probes wouldn’t have found? Still seems buggy. | | |
| ▲ | didgetmaster a day ago | parent | next [-] | | Engineer: How often should our software scan the local network looking for new devices? Once a day? Once an hour? Manager: We might miss something. Since scanning doesn't cost us anything, better do it a thousand times a second! | | |
| ▲ | gerdesj a day ago | parent | next [-] | | Oh let's be charitable! A parameter measured in ms is mistakenly thought be measured in s. Hilarity ensues. Real world example: þe Windows registry DWORD time periods seems to invite 10^-3s granularity for totally inappropriate timescales. Perhaps its considered a "best practice" by the dick heads that decide to do these things, who knows? Why bother considering how a sysadmin might actually want to use the knobs and dials and what is an appropriate value for a parameter. I could probably find a better example but this is recent: Smoothwall has an agent (IDEX) that you install on a Windows domain controller and one of its functions can be to harvest DHCP data and pass it onto the firewall so that it can track sessions. The upload period is a registry DWORD value. I fixed a "problem" by stopping IDEX trying to upload data a thousand times per second. I will also point out that switching on this functionality and the periodicity setting is only applied by editing the registry - there is no GUI for this. The dReal world example -ocs are clear that you should initially set 1000 as the period. For me that sort of thing comes under the heading of "you are holding it wrong", potential victim shaming and rubbish engineering. | | |
| ▲ | MBCook a day ago | parent | next [-] | | This is what I suspect. A retry every X milliseconds actually being used against a variable nanoseconds, a broken loop condition that ends up always retrying, something like that. | |
| ▲ | frogulis a day ago | parent | prev [-] | | Not really relevant, but I have to ask: why did you only use letter þ once in your comment? | | |
| ▲ | eloisius 19 hours ago | parent | next [-] | | Not making an accusation, but it reminds me of a chat transcript oddity I saw while using opencode back in August. It replace a syllable of a word with a punctuation mark that has the same pronunciation or HTML entity. It was something like "...the &litude of that waveform..." but I can't remember exactly, nor which model I was using. I just noticed it and thought, that's weird. A few days later I read about text watermarking and figured it may be that. | | |
| ▲ | Scoundreller 18 hours ago | parent [-] | | ChatGPT sometimes spit out some characters from very foreign character sets. Maybe only an issue on the free side? | | |
| ▲ | lxgr 14 hours ago | parent [-] | | Happens on paid too. Every once in a while, one of my conversation names will have random Chinese characters in them. I guess distillation goes both ways. |
|
| |
| ▲ | nom a day ago | parent | prev | next [-] | | I wondered about that too, i think they use a compose key and accidentally pressed it | |
| ▲ | 7 hours ago | parent | prev | next [-] | | [deleted] | |
| ▲ | cobbzilla 21 hours ago | parent | prev [-] | | a thorny question to be sure | | |
|
| |
| ▲ | lxgr 14 hours ago | parent | prev | next [-] | | > Since scanning doesn't cost us anything, better do it a thousand times a second! This works only up to a point. Now it is costing them something. | |
| ▲ | raffael_de 12 hours ago | parent | prev [-] | | "you mean one tick is a microsecond?" |
| |
| ▲ | al_borland a day ago | parent | prev | next [-] | | I was talking to the guy who used to run our ITSM system at work. He said a team was trying to query the system 10x per second to check for updates, which was causing performance issues. Assuming it was a bug, he went to the team to have them tone it down. He was shocked when they fought with him over it. It was working as designed and they didn't want to check less frequently, despite there being no logical reason to do this. This may be working exactly as designed, as it costs them effectively nothing to constantly scan. | | |
| ▲ | alexfoo 16 hours ago | parent [-] | | > It was working as designed and they didn't want to check less frequently, despite there being no logical reason to do this. We had a similar thing, the other team wouldn't back down. We ended up implementing a kind of rate limiting internally. If the previous request (from that IP) was more than 4.5 seconds ago we let the check request through as normal. If the previous request (from that IP) was more recent than that we just returned a cached "there is no update" payload that had a TTL of 60 seconds. We told them this and left it up to them, they soon changed their polling frequency. | | |
| ▲ | zettabomb 10 hours ago | parent [-] | | I'm surprised you were that nice about it. If it was that ridiculous I'd be reaching for fail2ban. |
|
| |
| ▲ | pixl97 a day ago | parent | prev | next [-] | | It's impossible to tell the difference between being malicious and being ignorant. With this particular company, everything else they do is malicious so I won't ever give them the benefit of the doubt. I tried to use a reusable pod in one of their machines the other day and when I shut it the handle broke off leaving me rather confused. Turns out in the closing head of the machine they stuck in 4 big metal spikes to destroy anything put in there. There is absolutely no reason to do this, none, other than being dicks. Had to get out the epoxy and repair the handle of a friends machine. So yea, screw them. | | |
| ▲ | johannes1234321 a day ago | parent | next [-] | | The scanning is malicious. The frequency etc. leading to 1TB is probably ignorance, but that doesn't matter as it is consequence of malicious scanning either way. | | |
| ▲ | MBCook a day ago | parent | next [-] | | Exactly. The whole thing is weird and creepy and wrong. I understand why a TV would keep track of what I’m watching so they can sell the data. I think it should be illegal. It’s horrible. My TV isn’t connected. But the reason they would do it fits in my brain. I can see how they got there. How a coffee machine got to running network probes… nothing. It seems like some sort of Internet of Things DEFCON presentation topic made up by putting random words together. So to think that on top of that they were purposefully causing so much traffic on the local network is just a few steps too far for me to think that part was intentional. | | |
| ▲ | johannes1234321 8 hours ago | parent | next [-] | | The reason is that probably the coffee machine vendor doesn't know what is going on. They probably got that module from.some third party, like "hey, you want to cheapen your smart coffee machine? - take out network stack!" and then they don't have to hire developers doing all the work to implement a network configuration system and all that stuff, but have a simple API for the App telling you coffee is ready | |
| ▲ | mcv 11 hours ago | parent | prev | next [-] | | I think the reason to use a coffee machine is because it's an innocent device that doesn't require any data whatsoever, so nobody would ever suspect it of something so nefarious. They're explicitly taking advantage of their customers' trust, and deserve to go bankrupt. | |
| ▲ | fragmede a day ago | parent | prev [-] | | The reason is the same though. Probe the shit out of your network and gather data so they can sell it. |
| |
| ▲ | mrweasel 17 hours ago | parent | prev [-] | | The funny part is that the manufactures shitty QA made this a much bigger thing that it could have been. Had the machine done a scan once every week, which is more than enough for their purpose, diffed the result locally and pushed the few kB of data to the internet, then no one would have noticed anything. Yes, it's malicious and completely unnecessary, but incompetence has potentially made it a PR problem. |
| |
| ▲ | 21 hours ago | parent | prev | next [-] | | [deleted] | |
| ▲ | mahboi a day ago | parent | prev [-] | | It's malicious either way. Question is whether 1TB was intended operation. I don't think it was. |
| |
| ▲ | Refreeze5224 a day ago | parent | prev [-] | | I don't understand giving the benefit of the doubt to a company that is actively spying on its customers, which in some jurisdictions would be illegal. | | |
| ▲ | MBCook a day ago | parent [-] | | I’m not defending the spying. The traffic volume just sounds like a bug to me. | | |
| ▲ | BLKNSLVR a day ago | parent | next [-] | | A software bug in a coffee machine sounds like a problem of management not understanding the product market they're in. | | |
| ▲ | nekusar a day ago | parent [-] | | No, Management completely understands. Closed source software/hardware is a data exfiltration device first, and the thing they're sold for secondarily. TVs, Blurays, set top boxes, MS Windows.. All of them are the same. | | |
| ▲ | BLKNSLVR a day ago | parent [-] | | All these companies make their money as 'feeders' to the advertising industry, they just sell a different device to consumers in order to achieve it. Selling devices to consumers is a solved problem. The problem we're currently trying optimise solutions for is selling consumers to the advertising companies. |
|
| |
| ▲ | sixothree a day ago | parent | prev | next [-] | | Maybe they literally just don't care about how much traffic they put on your network. Maybe the thought is "1 tb of traffic internally is very low utilization of the network over the course of a month". | | |
| ▲ | mahboi a day ago | parent [-] | | Whatever they're trying to accomplish with these scans would probably be impeded in some way by this much volume. Like it'd compete with the link it's using to phone home or overload whatever on-device processing it does with that data. The man in the article who discovered this called it a bug, I agree with him. | | |
| ▲ | sixothree a day ago | parent [-] | | "With enough incompetence, the only interpretation is malice." - SixOThree | | |
| ▲ | mahboi 8 hours ago | parent [-] | | I'm not saying there's no malice, it's just that maliciously spamming the network would get in the way of the malicious spying they actually want to do. |
|
|
| |
| ▲ | lovich 19 hours ago | parent | prev [-] | | When the cost of the action to you is 0, why not do it as fast and as frequently as possible until you get your intended benefit. Even the act of engineering rate limiting costs you more than just having this run wild over your customers networks because the vast majority of people buying these machines do not have the inclination or skills to detect this activity. |
|
|
| |
| ▲ | mcv 11 hours ago | parent | prev | next [-] | | Let's saturate every review site with reports of their spying. This definitely deserves to be public knowledge. | |
| ▲ | nkrisc a day ago | parent | prev | next [-] | | It uses energy paid for by the homeowner. | | |
| ▲ | didgetmaster a day ago | parent [-] | | Has anyone done the math to determine how much electricity it takes to send 1 TB of data around your local network? | | |
| |
| ▲ | b112 a day ago | parent | prev | next [-] | | They could be sued in small claims court. Here that means no lawyers, no discovery, $100 to file in plain language, and a company employee (not a company lawyer, or a contractor, or a temp employee) must attend or they default. $15k damages. Reasons it could happen? Imagine grandpa has a tech come out 4 times, because his network is super slow. EG, this thing pounding his wifi for its scans. | | |
| ▲ | zdragnar a day ago | parent [-] | | Small claims court in the US typically requires actual damages, and doesn't add punitive damages. Grandpa gets reimbursed for the four techs who came out, that's it. | | |
| ▲ | b112 a day ago | parent [-] | | Of course, that's the whole point. Grandpa gets his money back. The company? Well, it has to spend money talking to a lawyer, because even though a lawyer can't attend small-claims court, they still consult. They also have to send an employee to small-claims court, just have to deal with it. In the end it costs the company thousands of dollars maybe even over ten grand. It costs you a hundred bucks and you get your money back. That sort of asymmetry is beautiful, and if everybody availed themselves in small claims court, it would be far better than any class action lawsuit. | | |
| ▲ | zdragnar a day ago | parent [-] | | > $15k damages. Grandpa is definitely not getting $15k in damages, and Keurig can deal with this with their in house lawyer that they're already paying a salary for. They're definitely not shelling out big bucks here. It'd be cheaper for them to let the default judgement happen than to actually show up. | | |
| ▲ | 3-cheese-sundae 19 hours ago | parent | next [-] | | Like everything else in today’s world: scale makes all the difference. Let everyone file that claim for a single geek squad visit. | |
| ▲ | b112 18 hours ago | parent | prev [-] | | In which case, your grandpa gets his money back, plus filing costs, plus serving costs, and if it's a default judgement, no one to argue against the gas costs, and time costs you tack on. Please show me how this is suboptimal? Especially with LLMs to write the demand letter, and walk you through the process. And 'using their in house lawyer' still has time cost, as does dealing with the routing and pondering the service letter. And accounting paying up. There is no aspect of your 'worst case' where it's bad. It's still all pluses. And if as I suggest, lots and lots of people do it, then they end up with a loss on that product. If each case is $1000, or even $500 payout, how much profit does that take? Profit on 100 units? 50? If a product is horrifically bad, and everyone runs to small claims court, that's disaster for a company. | | |
| ▲ | zdragnar 11 hours ago | parent [-] | | I'm not saying any of this is bad at all. I'm saying you can't expect the $15k damages you mentioned in your post that I first replied to. It won't cost Keurig anywhere near that even with fees and such. That's why I quoted it specifically in both of my comments. > If each case is $1000, or even $500 payout How many people are going to spend $500 on service techs coming out to their house? So far we've got a report from one guy who figured it out with no damages at all, and therefore no case for a small claims court. Since it was found to be defective 10 days after first use, it's probably still eligible to be returned for a refund, so even the cost of the machine isn't eligible. > If a product is horrifically bad, and everyone runs to small claims court, that's disaster for a company This much I can agree with for sure. While it is definitely bad, I don't think flooding small claims courts is going to be a viable strategy in this particular case. | | |
| ▲ | b112 5 hours ago | parent [-] | | I get it now. Looking back at my post, I left out something important. 15K is the maximum damage allowed in small claims court where I live. For whatever reason I didn't finish that sentence, and just said 15k. Sorry about that. Where I am, you can get back the cost for sending a registered letter by courier to have it served, signature required. Also for the demand letter. You can get money back for filing, the $100 for example. Lots of little incidentals. To me, it's when the damages are smallest, that small claims court is the biggest benefit. Losing $30, suddenly becomes a bill of $200, after it goes through small claims court. But anyhow, I'm just happy if you like small claims court to some degree. I just think we should all use it more. |
|
|
|
|
|
| |
| ▲ | blackoil a day ago | parent | prev [-] | | Than What is the meaning of "used"? | | |
| ▲ | weaksauce a day ago | parent | next [-] | | local area network traffic was sent out and received by the device to the tune of 1TB of traffic. not internet data but local area network data which is not ideal for a coffee machine either way you slice it. if it were some kind of local bonjour or whatever the open standard is called service that was just alerting the network of their name it would be understandable but the coffee maker is streaming the equivalent of about 17 high def movies every day to the local network. | |
| ▲ | awesome_dude a day ago | parent | prev [-] | | I mean, it wasn't clear to me without the explanation (I too thought it used 1TB of public internet data), but it's clear now that it is accurate (it literally used 1 TB of private network data) It might not seem to be anything (people will assume private network traffic is free) but there is a cost - it's capacity that could be used for other purposes, eg. home alarms. |
|
|
| |
| ▲ | josephg a day ago | parent | next [-] | | > everyone is doing it Not in my house. What is even the point of connecting a coffee machine or a washing machine to the internet? I think my washing machine advertised that I could download new washing cycle programs in the app. Who on earth cares? | | |
| ▲ | Aerroon a day ago | parent [-] | | I could see its use - you could remotely activate them. Or activate them on a timer that isn't constrained by the functions of the coffee machine. None of these are worth the spying that these companies do though. | | |
| ▲ | prmoustache 7 hours ago | parent | next [-] | | > I could see its use - you could remotely activate them What is the point of activating a washing machine remotely if you aren't there to put your laundry inside? What is the point of activating your coffee machine remotely if you are not here to drink it? Even when you have to fill water in the machine and grind coffee beans, and wait for the machine to preheat the water.it takes less than 3 minutes to prepare an espresso. | |
| ▲ | alexfoo 16 hours ago | parent | prev [-] | | Of course you can set up firewalls and VLANs to have the best of both worlds. You can remotely interact with an IoT device like this to set them off or check the status, but the device itself can't see anything else on the local network. I have all of my IoT devices on separate Wifi network(s) and VLANs and almost all of them are isolated so they can't talk to each other, plus I occasionally look at how much data they are sending/receiving from the Internet (some is expected obviously, and it differs by device). Doing this requires a considerable amount of admin work and IT knowledge though. It also requires something a step above most consumer grade or supplier provided networking equipment. I've never spotted anything egregious like the coffee maker in the OP but if I did I'd be making sure other people knew about it and the device itself is either firewalled off properly or replaced by a brand that isn't a security risk. | | |
| ▲ | simoncion 12 hours ago | parent [-] | | > Doing this requires a considerable amount of admin work... As someone who has done this, it's a one-time cost (as long as you're not the sort who simply can't stop tinkering with it and ends up totally rebuilding it like once a quarter (don't ask me how I know)) and -if you have even just a shaky understanding of how to do it- it's not _that_ large of a cost. > ...and IT knowledge though. I definitely agree that doing this requires quite a bit of IT knowledge... but it's all stuff that's pretty easily learnable for anyone who's interested in technical stuff and/or technically-inclined. For folks who are looking to do this on their home LAN, I have some hardware manufacturer recommendations: All of this VLAN work will be entirely pointless if your switches can't be programmed to enforce the separation, so one will need "managed" switches of some kind. I'd recommend anyone who wants to try to do this to have a look at Mikrotik switches... they are inexpensive and definitely more than good enough for a fancy home LAN. Mikrotik also sells routers and WiFi APs. I can't comment on the quality, as I have slapped together my own router PC and use OpenWRT Ones for my APs... but I've found their switches to be more than good enough for my fancy home LAN. Perhaps their routers and AP are equally good? Mikrotik publishes pretty comprehensive documentation here [0]. If you want to dick around with the Mikrotik management CLI for RouterOS -which is their name for their fancy management software- you can install the x86 version of RouterOS in a VM by booting a VM from one of the x86 install images at [1]. They also have a much simpler management software that you can run on all of their switches called "SwOS" -documented here [2]- but that doesn't have any x86 installation media so you can't play with it on your PC. [0] <https://manual.mikrotik.com/docs/introduction> [1] <https://mikrotik.com/download?architecture=x86> [2] <https://manual.mikrotik.com/docs/bridging-and-switching/swos...> |
|
|
| |
| ▲ | autoexec a day ago | parent | prev [-] | | If there's one thing you can be absolutely certain of it's that every scrap of the data they collect is either making companies money hand over fist or they strongly believe that it will soon. No company is going to bother collecting, storing, (hopefully securing), backing up, and analyzing all this data without a reason, and to them money and power are the only reasons that matter. Right now companies are somewhat limited in how much use they can get out their horde of private and personal information, but AI is changing that rapidly. As long as you don't mind a huge rate of error (and companies don't because it all becomes "good enough" at a large enough scale) it's basically perfect for the task of digging through endless amounts of information and spewing out bullet points. | | |
| ▲ | burpingtree a day ago | parent | next [-] | | Ha. I feel like you have never worked for a large company if you think they are making rational decision at all. They may “believe” this will make them money, but there is no guarantee that this isn’t just costing them money hand over fist. | | | |
| ▲ | 0cf8612b2e1e a day ago | parent | prev [-] | | It was revealed that Honda sold data on customers for less than a dollar a piece. It’s not big money at all, but they cannot stop themselves. | | |
| ▲ | autoexec 9 hours ago | parent [-] | | Honda had enough customers that they still made millions selling that data. One company only gave them $25,920 for a bunch of it, but why should that matter when it was data they would have collected anyway, can still use themselves, and they're still able to sell it over and over and over again. It doesn't really cost Honda anything to do it so it's basically all profit for them. It tells us how little Honda values our privacy, not the value of that data to Honda. |
|
|
|