Man discovers his parents' coffee machine used 1TB of data in 10 days
dexerto.com
[34 comments hidden]
Tech enthusiast:"My entire house is smart! Everything is connected to the cloud, automated, and I can control every appliance from my phone!"
Tech worker / Software engineer:"The only piece of technology in my house is a printer from 2004, and I keep a loaded gun next to it in case it makes a noise I don't recognize."
I hope its just a retry loop and not actually data.
[4 comments hidden]
[16 comments hidden]
> Tech worker / Software engineer:"The only piece of technology in my house is a printer from 2004, and I keep a loaded gun next to it in case it makes a noise I don't recognize."
You forgot an additional well-known punchline (source: https://old.reddit.com/r/NonPoliticalTwitter/comments/1e8do2...):
> I wouldn't keep the gun next to the printer; it may be able to use it against you
[hidden]
[4 comments hidden]
[hidden]
[hidden]
Reddit seems hell bent on making me not use Reddit.
[9 comments hidden]
[4 comments hidden]
[7 comments hidden]
My wife asked me why I was carrying a gun in the kitchen
I said "Rogue AI"
My wife laughed
I laughed
The toaster laughed
I shot the toaster[2 comments hidden]
I have been a software developer for 30 years, and I am always wanting to automate and ‘smartify’ everything in my house.
It is true that I want to self host everything, too, and use open source as much as I can, but I am not avoiding technology.
I got into computers because I love technology, and want to play with as much of it as I can.
[hidden]
Once upon a time someone wanted to automate a printer. Why? It kept jamming paper. That's how the free software movement was born.
As far as "smart devices" go, we haven't really escaped that hell. This coffee machine is an example of it. Thankfully, open source firmware and DIY have an incredible amount of worldwide momentum, but we are still far away from devices and software serving their user first. DIY is a niche by definition, everybody around you aka normies still have to suffer from technology. Even when don't recognize it: https://danluu.com/bug-blind/
[hidden]
Now that you have said that I am hoping (just a little bit) it is actual data and we learn what it is. What is life like for a toaster.
[hidden]
But ... I kinda feel the sentiment, I routinely joke (and feels like less of a joke every year) that when I retire in a few years, I'm removing every last computer from my life.
[hidden]
So, yeahh, the 1 TB of data is bad, but that seems more like a bug. The bigger issue is that people are buying "IoT" products without even realizing it. They're looking for a simple, decent coffee maker, and what they get is a coffee maker bundled with an even shittier app that can be insecure, become outdated, be full of bugs, turn into a paid service, or eventually stop working and prevent you from using a product you legally bought. And who knows what other issues it'll introduce along the way.
I fucking hate how apps and connectivity have become the default for practically everything you buy, even when there's absolutely no clear need for them. They usually offer very little additional convenience while introducing all the issues mentioned above. More things to break, more security and privacy risks, more dependencies on services you don't control, and potentially a perfectly functional product turned into e-waste because some company decided to stop supporting its shitty app.
To me, the trade-off is almost never worth it. If I was naive I would think for other people the trade-off is just OK for them but actually they're not aware they're doing this trade-off at all.
[6 comments hidden]
Here's an example from my unifi dash right now, my laptop has done 24tb of data? lol email and web browsing
[hidden]
[7 comments hidden]
[6 comments hidden]
But I sincerely hope things like muse will force public and unethical programmers to change.
[5 comments hidden]
[2 comments hidden]
This is just me musing. I don’t actually know what Muse’s music is like.
[hidden]
[3 comments hidden]
[hidden]
[6 comments hidden]
[7 comments hidden]
[hidden]
[hidden]
[hidden]
Yes, they can trivially build systems to filter this out, but your favorite coding agent can probably make it more stochastic / clever ;)
In my experience, this has basically 'neutered' personalised advertising for me (I get all kinds of ads, in all kinds of languages, when using my Google account or network w/o an adblocker); so it definitely has an effect.
[18 comments hidden]
What hope do normies have?
[8 comments hidden]
[2 comments hidden]
[2 comments hidden]
Sometimes I like the idea of preheating oven on my way home but then I get home and forget about it.
[hidden]
[2 comments hidden]
My LG washer/dryer tell me when loads are done and when someone lets wet clothes sit in the washer. This is priceless. But yeah they are probably profiling my house.
[7 comments hidden]
None, without people like us in their families who are able and willing to help.
We as computer people need to internalize and accept the idea that helping our immediate and even extended family with technology is now part of defending human freedom. And we need to form ourselves into the best helpers we can be by learning how to teach and communicate well.
[5 comments hidden]
I am able and willing to help my parents get off of a lot of the spyware bullshit they have throughout their house, but they don't want to hear it. They liked the connected stuff and I think that they think I'm a little weird when I push back about why we can't trust corporations like Google or Microsoft to do everything.
[hidden]
"Nomad," the guy from the article, was already administering his parents' home LAN.
How do you get there? "Mom and Dad, we're going to set up your home network so that it's blended with my home network. To all the machines in your house and mine, it'll look like they're on the same network together. That'll make it easier for me to help you with any tech problems you're having, on your computer or on any smart device. The connection between our houses will be encrypted and secure" You're installing a router/firewall for them and adding to your WireGuard overlay network, but you're not using any of those words to tell them what's going on.
What to do next? "How was watching TV last night from {$TIMESTAMP_A} to {$TIMESTAMP_B}? Yeah, my network sentinel detected that your TV was sending your viewing habits out to somewhere on the Internet and warned me and blocked it. I can't tell what you were watching, but {$TV_BRAND} sure can." You're monitoring their LAN via the router/firewall you've set up, but you are again not using technical language.
Wherever spying is invisible and frictionless, make it loud and incessant. And continue to provide value to the family on the shared overlay network. Photo and home video backups, media server (it's like Netflix!), mutual offsite buddy backups, password management, a local Minecraft server for the kids and the cousins.
Cultivate a family network garden that is good enough to consider leaving the leviathans behind and build walls around it that are high enough to commit to leaving the leviathans behind for what is now a garden inside a family network castle.
[hidden]
Recommending they turn off ACR and other spyware on their TV is based on recent reporting is good and backed up by said reporting. Probably even recommending against too-good-to-be-true connected doorbells even.
Meanwhile, telling them not to use a first-party Google, Amazon, or Apple smart home speakers is a bit questionable when there's been pretty good audits over the years that show they really do only do wake word detection. You'll just sound like a crazy person if you can't point to some reporting on a device doing bad.
[hidden]
Folks be crazy.
[hidden]
I don't need voice-activated lights for the basement for when I head down there with my arms full of laundry, or with a bunch of food to put into the freezer, or whatever shit I'm carrying. I don't need them to turn themselves back off after a time, either.
I mean: I could use any of a wide array of motion sensors, but they'll turn the lights on even when I'm just working in the kitchen near the basement stairs. (Or maybe I could use a beam curtain! Yeah! Now they only respond when a beam breaks, instead of when I'm working in the kitchen near the basement stairs!)
Or I could just put the shit down and flip the switch.
Or: Plan ahead, and flip the switch in advance. And then just flip it back off when I'm done down there.
On a long-enough timeline, someone will find a way to make a point of explaining that any combination of a lack of planning and a lack of effort is completely and utterly inexcusable. That every action should should be planned, and that every manual effort has value.
But I chose this path anyway, and I like it this way. I invited the spies into my home very deliberately. The basement light automations work great, by the way, and the default non-voice UI is the same, plain, old-school light switch that the house came with.
(I also chose to carry an always-on pocket supercomputer with me wherever I go even though I have no way to observe what that thing is really doing at any given time.)
[32 comments hidden]
What kind of functions it has that can't be replaced by:
- walking a few meters and pushing a physical button
- waiting a whopping minute for coffee to brew, instead of triggering it remotely
[2 comments hidden]
[2 comments hidden]
[2 comments hidden]
[23 comments hidden]
- have a short window to get to the train in the morning - want coffee on the train - don't particularly like drip machine coffee - want the water boiling when I wake up so that I can make coffee and get out of the house as quickly as possible - am more morally opposed to waking up five minutes earlier (pushing my wake time into the 4 o'clock hour) than I am to having a smart device.
I couldn't find a kettle that runs on a timer, and just taping the switch in the "on" position and hooking it up to a plug timer felt unsafe, so getting a stupid wifi kettle and using their stupid app to set it to auto-start was the best option. It's on its own network, though.
[5 comments hidden]
I do feel that over-automation is a thing
[4 comments hidden]
I use a Hario Switch to make coffee. It takes 3:30 to brew, so I pour the water and then brush my teeth and prep while waiting. Async coffee! I’m out the door as soon as the coffee is in the mug and get to the train station about 2 minutes before the train arrives.
[6 comments hidden]
[5 comments hidden]
This is possibly not an issue with a regular drip coffee machine. It’s definitely an issue with a kettle or, say, air fryer.
[6 comments hidden]
Just say it: you bought a smart kettle due to your completely adjustable preferences.
[3 comments hidden]
Thus-constrained, this person states that they're able to get 5 more minutes of sleep every night and still make coffee before taking the train to work. That's ~25 minutes per week, or ~1.8 hours per month.
They didn't have to choose to go to bed earlier in order to gain this time and still make coffee in the morning. They were going to make coffee with a kettle anyway and were constrained by a the necessity of maintainining ownership of a kettle with which to do that.
So they simply selected a kettle that can be safely automated so as to be ready at the right time every morning instead of one that cannot be. In exchange, they gain around 20 hours per year, for every year that this kettle lasts for. (What would you do for nearly an entire extra day, per year?)
Sure: It's adjustable, just as many constraints are.
Maybe there's even a coffee shop around the corner that they could work at instead, and they could just walk there and brew themselves a cup of coffee using the hot tap on the espresso machine before they start their shift -- and skip the train.
But maybe that wouldn't fit into the constraint of being able to support the dwelling that they prefer to live in.
So maybe they could soften that constraint as well, and live a little lower. (Maybe they can soften enough constraints that they can just live under a bridge somewhere, with no permanent dwelling, no job, and no coffee. Perhaps, if we look hard enough, we might find that even the constraint of living a life -- at all -- is also adjustable.)
[2 comments hidden]
They can shift their daily schedule e.g. 30 minutes earlier and peacefully drink their coffee at home. They also should eat something at home or on their way, because hurrying in a cold morning with an empty stomach is not good. Source: personal experience. I did that for months as a student until I passed out one day in class.
If they don't like waiting for the train in the cold, they probably can find a warm place near the station, and wait there a little.
[hidden]
[hidden]
[4 comments hidden]
[hidden]
In other words, these product decisions aren't really made on the rationale that internet connected coffee makers make sense from the standpoint of a consumer who simply wants coffee made...
It's more: "let's make smart coffee makers so that we can sell to 2 markets:
1) a coffee maker to consumers who want coffee made
2) consumers data/eyeballs to advertisers who want their info/eyes
... and make more profits for ourselves".[hidden]
[23 comments hidden]
Most non-ancient routers/gateways support this. There are way too many IoT devices running code that's _worse_ than what older LLMs produce.
[hidden]
[hidden]
FWIW preventing the harm that happened here would seem to require a second set of APs (radios) on a different channel.
[9 comments hidden]
[3 comments hidden]
Yours may not, but that's just your personal preference. A lot of folks enjoy these products. An argument could be made that no one needs a coffee machine or thermostat to begin with.
[2 comments hidden]
[hidden]
[5 comments hidden]
[hidden]
[2 comments hidden]
It's smart and supports only Z-Wave, not WiFi. So something like a machine running Home Assistant must sit between it and the Internet. And then its up to you to decide how you want to do remote access, but WireGuard overlay networks (e.g. Netbird, Tailscale) basically solve that problem at home-user scale.
[hidden]
Reject all the WiFi-connected stuff, unless it's very user-centered and worst case you can upload your own firmware (e.g. a bunch of Shelly devices).
[6 comments hidden]
[5 comments hidden]
There's a Bialetti shop on the road between the flat I'm staying in, and the Metro station.
If I'm not careful this is going to seriously damage my wealth.
[4 comments hidden]
[5 comments hidden]
I default to adding IoT devices to a 2.4g "Guest" network where they can't see each other. Exceptions are IoT devices that need to see their friends to do what I bought them for, or devices I want to integrate with HomeAssistant. In those cases I create a separate IoT device per IoT brand. Excessive but necessary.
[4 comments hidden]
That requires a lot of SSIDs though and AFAIK it reduces airtime for each SSID on the same router (which may be bad if you also use 2.4GHz for your regular devices).
So far two separate VLAN + SSID (IoT-Good and IoT-Bad) with client isolation on IoT-Bad has worked pretty well for me. In some cases mDNS advertisements have to travel at least from the IoT VLAN to the VLAN HA is on for the devices to be discovered.
[3 comments hidden]
There's ways to reduce the expense like changing DTIM interval (for less-frequent broadcasts) and increasing base data rate. Few folks in 2026 have anything at home that requires the 1Mbps base rate of 1999's 802.11b anyway, and slower DTIM can have other advantages, so these tend to work well at increasing available airtime for more SSIDs.
There's an additional trick that can also be used, though: Wifi client isolation. This lets the IoT widgets share an SSID and VLAN with which to talk to the HA machine and/or their cloud-based mothership(s) or whatever, but without being able to see eachother on the SSID.
It still needs set up right lest stuff walk right by it, but it's an available feature.
A smart coffee machine may need to talk to some kind of controlling endpoint (whether local or afar) in order to do whatever it does. It does not need to be able to enjoin in a conversation with my light bulb in order to get there. But that doesn't mean that they can't share an SSID. :)
[2 comments hidden]
Indeed, this is what I do on our home network. I have two IoT SSIDs. One with devices I generally trust, where mDNS proxying is enabled and another that is excluded. I've found that the worst devices are generally not locally controllable anyway and always want to go through the cloud, even when you control them through HA or your phone.
[hidden]
Now that I have a new router and I've re-enabled NextDNS, I've ironically discovered that the chief abuser of DNS right now is the router's own legit security software, which is absolutely hammering on the same query, several times a second.
Of course, since I am currently on NextDNS free tier, this matters a lot, because they cut you off after about 300,000 queries in a month. So any hammering abuse will make me lose my privileges much earlier than I would otherwise. So, to stop the abuse, should I shut off my legit security software? It is absolutely rubbish at identifying malware on the device itself...
[hidden]
> I'm tempted to scan it's packets with Wireshark and other tools, but honestly, I'd rather keep it offline.
The X replies are equally empty. This is the top reply when I opened it:
> I haven't read the comments, but if this isn't a bug, I'm going to guess it has access to the wifi map. For those who don't know, your router can effectively create a 3D live scan of your home, where you are, and even figure out what you're saying without microphones.
In case you were wondering, no, your home router cannot create a live map of your home and hear your conversations.
Even the traffic numbers are suspect, as the UniFi dashboard is known to occasionally miscount things.
If you know anything about networking, you know that it doesn't take 1TB of data to scan a network, even if you're doing it once a minute.
It's crazy that there's so much confident discussion from people who are certain it was harvesting data, when the self-described "IT professional" who posted this wasn't even curious enough to capture a few packets.
[3 comments hidden]
I find the idea that you'd connect things like these to the Internet absolutely insane. I do think we're past the point where being able to ensure you don't leak data isn't compatible with functioning in the modern world, but trying to limit the things that have Internet access to systems where you have control just seems sensible.
[2 comments hidden]
I'm ammused people call these "smart speakers".
Use their real name: Smart Microphones.
Alexa = Amazons microphone.
[hidden]
Yes they are constantly listening, but this is just for the watch word (as a cue to start listening/sending) but they lack the on-device ability to convert anything else to text on their own. All they can do on their own is listen out for the watch word.
Certain smart TVs on the other hand, are known to constantly stream audio back to their HQ as they don't have on-board watchword detection.
[12 comments hidden]
[11 comments hidden]
[10 comments hidden]
[9 comments hidden]
[hidden]
Here's an example of the sorta-end-game: Currently they can know how many kind of "devices" are in your household and using probabilistic statistics give a decent n value of how many "devices" are in a certain zip code. Using that, your advertising can become more efficient by only buying ads in zip codes that contain certain "devices".
I say Zip code because that's what I've worked on in the past at the most granular level for Marketing Mix Modeling or MMM. You can easily venn diagram your first party data with 3rd party brokers, and you can cleanroom the whole thing to get a decent venn-diagram of the overlap.
[7 comments hidden]
[5 comments hidden]
[4 comments hidden]
[3 comments hidden]
You need a router that allows you to configure strong policies, such as client isolation, what data can flow between VLANs, etc.
More broadly you cannot solve every with technology. The most effective route would be to simply outlaw such analytics without informed consent. This is basically what the GDPR does, but it takes a while before enough companies get fined before the industry understands. That said, the last few years, products sold in the EU are starting to get toggles to request analytics that are _off_ by default, etc.
[2 comments hidden]
[hidden]
If the device does anything with network, other devices can likely sniff a lot of information about it with high degree of accuracy based on how they react to certain network probes.
and my point was that you can prevent this by using e.g. WiFi client isolation and isolating VLANs (while still using the 'smart' features of said device).
I am not sure how your comment is a reaction to what I said?
[hidden]
The problem is that most ISP (modem+)routers are bottom of the barrel devices that do not allow users to configure such features. Even worse, some ISPs also scan the user's network and sell data to analytics companies [1]. This is a very good reason to always use your own router. If you want something with an Apple-like experience (mostly), Unifi gear is quite good. If you want something open source, then a router with something like OpenWrt or OPNsense + an access point with OpenWrt will do the job.
[1] https://tweakers.net/nieuws/245620/odido-router-stuurde-anal...
[3 comments hidden]
[13 comments hidden]
I didn't even know it had wifi capability but it was trying to connect
I use mac whitelist so it wasn't even getting in but that didn't stop it from trying every seond
Fortunately it was just a usb dongle so yanked it out
[7 comments hidden]
It's great having them on WiFi - you can turn on the AC before getting home to pre-cool, without having to leave it on all day.
[6 comments hidden]
Man: Well, before you couldn't turn on the AC before you got home
[5 comments hidden]
[hidden]
[2 comments hidden]
I know this sounds like the famous "just do it this way in linux instead" criticism of Dropbox back in the day. But I do think we reached "life parodies fiction" with these smart devices where it makes sense to give diy another go. And with AI, there's less excuses this time around I would imagine.
But I would literally rather buy a cheap phone, a cheap SIM, hotspot it and connect it to a charger and have the AC connect to that and isolate it that way instead of letting it touch the network.
[hidden]
I have my IoT on a separate VLAN and I can observe communications for any given device at any given time.. this seems like a much saner solution than outright not buying any IoT devices, though that is also a respectable decision!
[hidden]
[4 comments hidden]
And I wonder how I would even tell if it was trying to associate with my WiFi.
[3 comments hidden]
[2 comments hidden]
[hidden]
[6 comments hidden]
I bet a real coffee machine is even cheaper if you consider the cost of beans vs capsules.
[3 comments hidden]
[hidden]
I seen a heavy duty (office) top notch and top brand coffee maker breaking down in every two weeks before the IoT frenzy and killing people's privacy by collecting all their data covertly. The mechanics may be good, may be bad, and for a grinder+brewer unit connected to the water pipes so you don't have to fill it up, except beans, can also be 'improved' (if not for the benefit of the user, but for the benefit of the manufacturer, making it cheaper to produce but selling at the same premium price people got used to before the PE bought it from the founders). It can have sensitive parts without software.
Now, when marketing and technology-fandom dominates over common sense it is even more difficult telling beforehand if a particular make of a particular brand will be a good buy or a disaster. More goes into the second category as time goes by.
To me, a french-press and buying ground coffee from a reliable brand (I am not a coffee evangelist, I only drink it, not worshipping it), or alternatively a moka pot are the reliable choice.
[hidden]
Keurig is really convenient and cheap.
A Keurig machine, regardless of model, doesn't take much space. You can almost certainly put it somewhere in the kitchen or an office and just leave it there. By contrast, a machine that can grind beans is much larger, and you need to carefully plan for its presence.
The machine is obviously cheap -- most models are under $100, and only "high end" models with questionable features but not necessarily better taste are over that number. The pods are cheap -- you can easily get them for less than $0.5/pod, sometimes $0.4/pod. By comparison, Nespresso capsules are generally around $0.8-1/capsule. Note that I didn't say it's cheap per "unit coffee" -- there is usually less than 10g coffee in each pod (and that varies) and can be really weak for the amount of water used. This is why people suggest that if you have to use Keurig, use the least amount of water allowed.
Of course Keurig coffee doesn't taste the best. But most people aren't aware (even though they are likely able to tell the difference), and at the end of the day, the machine gets the job done. What makes them popular is cost and convenience. Like so many other products on the market.
[4 comments hidden]
- switch between my network and the cable router
- one port on the switch is set to "mirror mode"
- hooked up that port to a dedicated ethernet port on one of my boxes
Why do this?
Because if I run a tcpdump on that interface I see ALL of the traffic passing through the switch which includes all outbound and inbound traffic from my devices.
One interesting thing I've already discovered:
My oven sends random unencrypted keepalive messages over regular HTTP (not HTTPS) to an EC2 server.
I'm very curious to see if that changes over time.
[2 comments hidden]
[hidden]
One ISP here was recently caught scanning the local network on their modem/router-combo and uploading all the MAC addresses to... an analytics company.
If you have any chance to replace the ISP-provided router (in some countries ISPs are required to offer this option), do so. You can also replace it by something that has a traffic flow monitor, proper firewall (e.g. to block outgoing connections to trackers), etc.
[2 comments hidden]
[2 comments hidden]
[2 comments hidden]
[hidden]
"Performs chainsaw work"
I'm satisfied with my manliest man profile. Amazon nailed it.[hidden]
[hidden]
[hidden]
I was hoping this post would say what happened and what kinds of packets it was sending.
[3 comments hidden]
[4 comments hidden]
[3 comments hidden]
But at least the EU did me a solid. I really wanted to read that but I think 2000 data scumbags is not worth the effort.
All I need know is to realise bottlecaps must be recycled and federalism is good. Repeat in the mirror each morning
[hidden]
[10 comments hidden]
I have multiple devices that queries their update server every 15 seconds, which all shows up as the top 10 queried domain in my network.
[hidden]
Considering the computing power of these kinds of devices, it is most likely stuck inside an infinite loop sending garbage at full speed, there is not enough power to process that much volume in any maliciously useful way.
[3 comments hidden]
[6 comments hidden]
After installing the new router (Netgear) my HP LaserJet began printing error pages. Like, I had done nothing to send anything to it, but a blank error page or three would pop out of it at very random times.
It took awhile to narrow down and diagnose this. But it turned out that the Netgear system had a very... proactive network malware detection system. It was red-team scanning my LAN for "vulnerabilities" or exploits or the presence of malware (I think just known vulns). It was a known side-effect of these scans, where it would tickle an RTSP TCP port of some kind and the HP printer would respond with its error printout.
I was so livid that the router was scanning the LAN, basically unbidden and completely undocumented. Even worse, they were not sharing the logs or results of that scan with the consumer. No, they were being sent back to the Netgear mothership, and their cybersecurity vendor overlords. So the scans were not designed to benefit me; they were simply designed to spy on everyone from a privileged vantage point. Now I ask you, why is a piece of kit that is supposed to be "yours" compiling secrets about your network, hiding them from you, and turning them over to, I guess a big database for hackers to leak in due time? This is not a question of "well, devices hooked up to a network should not be vulnerable" if the devices were contained in a private network, and 100% inaccessible from outside, and only attackers inside my perimeter could do these exploits in the first place.
Thankfully I found a way to disable this. Their "security" shitware is still spamming DNS and I may be forced to disable that as well. Meanwhile, routers 100% cannot self-introspect or self-diagnose and find their own malware. I've said it once; I'll say it again: consumer routers are the Achilles Heel to your network. They are ideal points of compromise for any actor to gain a foothold and pivot, or simply gain persistence undetected. Your ISP doesn't care, and your vendors don't care. Perhaps you should.
[hidden]
It would be like finding out ring cameras are taking pictures of your keys and calculating the pin set to producing duplicates and sending that pin set data off somewhere and when caught them being like "Uh, we are uhhh... doing it to make sure your key isn't too worn down or to detect if someone made a crude hand filed key. Yeah that's it!"
[hidden]
[3 comments hidden]
[2 comments hidden]
[hidden]
[hidden]
[hidden]
[hidden]
[4 comments hidden]
[hidden]
[hidden]
[hidden]
[hidden]
[hidden]
[2 comments hidden]
[2 comments hidden]
Seems worth mentioning in a post about excessive and intrusive collection of user data. The moral outrage rings hollow when opting out of tracking is so deliberately onerous.
[hidden]
[hidden]
[2 comments hidden]
[hidden]
Some more consumer-oriented router/APs like Fritz!Box support a guest network that uses WiFi client isolation and internally uses a VLAN that is separate from the main network (though due to being non-pro end-user focus, you cannot set up your own VLANs or additional SSIDs).
[3 comments hidden]
At my local home depot where I shop, there is like 1 of each type of appliance that has any type of smarts, and each one is always the most expensive. All the rest, and more reasonable, are dumb. No apps, no wifi, etc. I'm not usually a guy who cheaps out on stuff, but I also know when I'm overpaying, and would never pay $2,000 for a fridge just because it has a giant screen (and now shows ads apparently...ahem...samsung)
I have 3 Keurig coffee makers, and they are dumb as a brick.
If you buy something that can connect to wifi/the internet, please understand that you are never actually buying it. You are actually only renting it. Either you pay the price via lack of privacy, or you pay the price via subscription...and the company at the other end of the deal controls which bargain you get...you have no input.
Keurig could brick all their smart coffee makers tomorrow and demand users cough up $30/mo, and users would then have to decide on whether they should toss their coffee makers or pay up.
I'm not saying it's right. Governments aren't doing enough in this area, especially the US, but also Europe. However, that is the name of the game.
Buy something dumb and enjoy not having to worry about this nonsense at all.
[hidden]
[hidden]
The vast majority of consumers don't understand that purchasing hardware with cloud integration essentially means they're renting their own products. I don't think it's a very logical conclusion to make either, unless you spend some time thinking about it. Therefore I don't think it's fair at all to say that they deserve this. Lawmakers need to push back on this, but that I think we agree on.
[hidden]
[hidden]
[hidden]
[hidden]
[hidden]
[hidden]
https://www.theguardian.com/technology/2016/oct/12/english-m...
[hidden]
- A coffee machine should not be broadcasting anything. - Stop drinking coffee and go outside and enjoy the great outdoors.
[hidden]
It's easier than ever today with LLMs to find bugs in the firmware and get complete trace of what's they are sending and shame these companies.
The next phase for the technically inclined is to patch these appliances and remove the collection, also possible today
[hidden]
[11 comments hidden]
[10 comments hidden]
[4 comments hidden]
[2 comments hidden]
[hidden]
Probably.
[3 comments hidden]
[2 comments hidden]
[hidden]
[hidden]
[hidden]
It’s not like it was an actually good coffee machine that has an app to select espresso profiles like a Wendougee Data S or something.
[hidden]
[hidden]
[hidden]
[hidden]
[2 comments hidden]
Right now I don’t care, I just never plug anything into my network
I don’t want to have to mod all my shit just to remove data collection stuff this way
Cars already do this and it’s a bitch to disable, can’t imagine having to do it every time I buy a blender, coffee maker, knife sharpener, tv, light bulb, speakers etc etc
[hidden]
[hidden]
[hidden]
[2 comments hidden]
[hidden]
[hidden]
There is no good goddamn reason for a coffeemaker to talk to the Internet.
I have a VERY VERY nice coffee machine. The model was somewhat controversial b/c it DOES have integrated circuits in it, but only for the PID and the auto on/off. It has no wifi, bluetooth, Ethernet, NFC, or any other such tomfoolery because literally NONE of that would be useful.
[hidden]
IoT network yep, needed yesterday
[hidden]
[hidden]
https://datatracker.ietf.org/doc/html/rfc2324
Bruh should have set his PiHole to return HTTP 418 in response to any outbound request this thing made.
[hidden]
My grandmother made the best coffee I’ve ever tasted. Every time she made me a cup, she transferred an entire library from the studio to the living room.
Whenever I saw her coming in from the garden, pushing the wheelbarrow, I’d get excited: “The coffee is coming!”
altairprime[282 comments hidden]
1. It saturated the local network with 1TB of metadata sniffing scans, not the network uplink to the outside world.
2. It does so because, as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.
lazide[hidden]
whycome[35 comments hidden]
Neywiny[11 comments hidden]
Citizen_Lame[5 comments hidden]
preg_match[hidden]
advisedwang[hidden]
anigbrowl[hidden]
Legislators are cheap to purchase
pjmorris[hidden]
egorfine[4 comments hidden]
Why not? iirc some of the smart TVs have been shown to find open wifi networks on their own and upload data. (I'm not sure about that though. But it's plausible and undoubtedly will be implemented some day).
sroussey[hidden]
gambiting[2 comments hidden]
AlexandrB[hidden]
I could also see some kind of partnership with ISPs to use their "public" WiFi hotspots[1]. This seems more likely since it's (probably) harder to honeypot but requires making regional deals.
[1] https://www.highspeedinternet.com/resources/is-your-router-a...
criddell[hidden]
black6[12 comments hidden]
Why you would give a coffee maker access to your WiFi is the real question,
pfannkuchen[11 comments hidden]
K0balt[10 comments hidden]
Besides, did you see how he was dressed?
thatguy0900[7 comments hidden]
mindslight[5 comments hidden]
fwip[2 comments hidden]
mindslight[hidden]
ButlerianJihad[2 comments hidden]
Since most appliances now contain a general-purpose computer, it would be unfair to say that a device is incapable of hacking or hosting malware, because any device with the given sensors and radios and capabilities can be essentially reprogrammed at any time.
So, if we're looking at smart TVs with cameras and microphones and Wi-Fi and Bluetooth and all the connectors, or if we're simply looking at a an ordinary network device, they all fall under the umbrella of general purpose computer, and there is no way to trust their maker, or some equally capable programmer, not to turn them malevolent in some future update.
I don't view this as an issue of terms of service or of software or of your manufacturer. I view this as an existential and fundamental problem with dropping general purpose computers into your home and behind your DMZ.
Consumer operating systems like Windows and Apple have all kinds of countermeasures against this malicious use. But without the proper introspection and without the proper safeguards, a device that looks special purpose but is in fact general purpose is far more dangerous.
mindslight[hidden]
Sensors/access is unavoidable, otherwise the device doesn't actually do anything useful. The point is it sets the scope for what the device is able to affect. When people say "set up a separate IoT VLAN" (that still has Internet access) this is basically what they're addressing - how a device can access other devices they may care about more.
Internet access is the catalyst that's created this whole dumpster fire - I don't care about the proprietary software on my keyboard/mouse/UPS/monitor/GPU/etc to nearly the same extent. I've got some TP-Link plugs that I control local network only. They don't get Internet access, so no updates, telemetry backhaul, etc.
The authority to update/configure/change that software is the crux. With proprietary software, there are no cuddly kittens period. Here we've got a case of a "legitimate" company choosing to be a bona fide attacker to increase their bottom line! The harm was exacerbated by a bug causing it to run amok, but even without the bug they are deliberately violating trust.
But even libre software can fall to security holes as well. Meaning you want to centralize the attack surface as much as possible, for administration's sake of keeping updated. "Internet" of things is basically the direct opposite of this - postulating many illegible fine-grained links between devices on different networks. Whereas really need more like the Home Assistant model, where peripheral devices may communicate over the network, but it's only ever over the local network. Think how ethernet is set up when used in industrial control networks (or at least how it should be set up, hehe).
EA-3167[hidden]
I don’t actually think that applies to coffee makers spying on people though. People shouldn’t be expected to understand how computer networks or ad tech spying works in the same way that literally any child or idiot should know the difference between a lion cub and a house cat.
noduerme[2 comments hidden]
How do you feel about thermostats? Are some things worth it? I've had a "smart" one for the past five years, part of a new furnace install, that I've stubbornly refused to connect to my wifi. Of course this means if we forget to turn the heat down while no one's home, there's nothing to be done about it.
05[hidden]
nicbou[2 comments hidden]
hobo123[hidden]
That, plus nobody in their right mind would buy American (vs French, Italian, German, Dutch...) when it comes to coffee. (yes, Starbucks is a thing here, but I'd argue people who are into _coffee_ don't go there, people go there for other reasons.)
triceratops[8 comments hidden]
zikduruqe[4 comments hidden]
Freak_NL[3 comments hidden]
The device is dead simple. No advanced electronics. Nothing complex that can break. Just a coffee maker fine-tuned to near perfection.
The only flaw it has is the handle for the pot. I've resorted to replacing the plastic handle with a fancy walnut one I made myself. I needed that because we tilt the pot sideways to fill the reservoir with water (because of the placement on the kitchen counter and the cabinets above), and that plastic handle is not designed for sideways stresses.
thinkingQueen[hidden]
lkjdsklf[hidden]
spandrew[2 comments hidden]
triceratops[hidden]
m463[hidden]
Like the people who reply to nigerian emails have already been pre-qualified by 1) ignoring the misspellings and 2) replying.
ncr100[hidden]
Limiting the quantity of data which is transmitted, received or sent, an appliance that a person purchases.
AnimalMuppet[6 comments hidden]
Yeah, sure, the terms of service probably say that they can do that. That's still in "unconscionable" territory. And courts do not like unconscionable contracts. If it's unconscionable, it's invalid (if I understand the law correctly).
Is this why everybody wants to make appliances with wireless?
altairprime[hidden]
kotaKat[2 comments hidden]
Customers are gonna get lost in the sauce and skip right past all of that and toss the packaging.
seb1204[hidden]
criddell[hidden]
jerf[hidden]
Which raises in my mind the obvious defense, which is that if you try to put four or five of these devices on your network they'll be too busy interfering with each other for them to actually spy on anything.
Let the wiretaps wiretap the wiretaps. Keeps 'em busy, makes 'em feel like they're doing something important.
rasz[hidden]
its LGs glass in LG household, and now Keurigs kitchen
Grombobulous[70 comments hidden]
There’s no way Keurig is has the intention of paying the kind of costs required to collect a terabyte of data every two weeks for millions of people who own their coffee makers.
There must be some kind of bug here. I imagine if you unplugged it and plugged it in again the data usage would settle down.
mindslight[5 comments hidden]
sgillen[4 comments hidden]
mindslight[hidden]
Now I'm left wondering what this traffic actually is - assuming probe (arp/icmp) packet size of 64 byte, that's 17kpps. I don't think an ESP32 class Internet-of-Trash chip can even do that. Even bulk transfers rather than small probes would be pushing it.
Perhaps this thing found some fellow-traveler device streaming video on a port it happened to connected to?
... the linked xit says it "broadcast 1TB of data". So maybe some protocol with a much larger packet than icmp, spammed in a hard loop without any delay?
nomel[hidden]
But still must be a bug.
Melatonic[hidden]
What kind of processor does this thing have ?
didgetmaster[50 comments hidden]
MBCook[34 comments hidden]
Still seems buggy.
didgetmaster[12 comments hidden]
Manager: We might miss something. Since scanning doesn't cost us anything, better do it a thousand times a second!
gerdesj[9 comments hidden]
Real world example: þe Windows registry DWORD time periods seems to invite 10^-3s granularity for totally inappropriate timescales. Perhaps its considered a "best practice" by the dick heads that decide to do these things, who knows? Why bother considering how a sysadmin might actually want to use the knobs and dials and what is an appropriate value for a parameter.
I could probably find a better example but this is recent: Smoothwall has an agent (IDEX) that you install on a Windows domain controller and one of its functions can be to harvest DHCP data and pass it onto the firewall so that it can track sessions. The upload period is a registry DWORD value.
I fixed a "problem" by stopping IDEX trying to upload data a thousand times per second. I will also point out that switching on this functionality and the periodicity setting is only applied by editing the registry - there is no GUI for this. The dReal world example -ocs are clear that you should initially set 1000 as the period.
For me that sort of thing comes under the heading of "you are holding it wrong", potential victim shaming and rubbish engineering.
frogulis[7 comments hidden]
nom[hidden]
cobbzilla[2 comments hidden]
FabHK[hidden]
eloisius[3 comments hidden]
Scoundreller[2 comments hidden]
lxgr[hidden]
MBCook[hidden]
lxgr[hidden]
This works only up to a point. Now it is costing them something.
raffael_de[hidden]
Refreeze5224[10 comments hidden]
MBCook[9 comments hidden]
The traffic volume just sounds like a bug to me.
BLKNSLVR[3 comments hidden]
nekusar[2 comments hidden]
Closed source software/hardware is a data exfiltration device first, and the thing they're sold for secondarily.
TVs, Blurays, set top boxes, MS Windows.. All of them are the same.
BLKNSLVR[hidden]
Selling devices to consumers is a solved problem. The problem we're currently trying optimise solutions for is selling consumers to the advertising companies.
sixothree[4 comments hidden]
mahboi[3 comments hidden]
sixothree[2 comments hidden]
mahboi[hidden]
lovich[hidden]
Even the act of engineering rate limiting costs you more than just having this run wild over your customers networks because the vast majority of people buying these machines do not have the inclination or skills to detect this activity.
pixl97[8 comments hidden]
With this particular company, everything else they do is malicious so I won't ever give them the benefit of the doubt.
I tried to use a reusable pod in one of their machines the other day and when I shut it the handle broke off leaving me rather confused. Turns out in the closing head of the machine they stuck in 4 big metal spikes to destroy anything put in there. There is absolutely no reason to do this, none, other than being dicks. Had to get out the epoxy and repair the handle of a friends machine.
So yea, screw them.
mahboi[hidden]
johannes1234321[6 comments hidden]
The frequency etc. leading to 1TB is probably ignorance, but that doesn't matter as it is consequence of malicious scanning either way.
MBCook[4 comments hidden]
I understand why a TV would keep track of what I’m watching so they can sell the data. I think it should be illegal. It’s horrible. My TV isn’t connected. But the reason they would do it fits in my brain. I can see how they got there.
How a coffee machine got to running network probes… nothing. It seems like some sort of Internet of Things DEFCON presentation topic made up by putting random words together.
So to think that on top of that they were purposefully causing so much traffic on the local network is just a few steps too far for me to think that part was intentional.
fragmede[hidden]
mcv[hidden]
They're explicitly taking advantage of their customers' trust, and deserve to go bankrupt.
johannes1234321[hidden]
mrweasel[hidden]
Yes, it's malicious and completely unnecessary, but incompetence has potentially made it a PR problem.
al_borland[3 comments hidden]
This may be working exactly as designed, as it costs them effectively nothing to constantly scan.
alexfoo[2 comments hidden]
We had a similar thing, the other team wouldn't back down.
We ended up implementing a kind of rate limiting internally.
If the previous request (from that IP) was more than 4.5 seconds ago we let the check request through as normal.
If the previous request (from that IP) was more recent than that we just returned a cached "there is no update" payload that had a TTL of 60 seconds.
We told them this and left it up to them, they soon changed their polling frequency.
zettabomb[hidden]
blackoil[3 comments hidden]
awesome_dude[hidden]
It might not seem to be anything (people will assume private network traffic is free) but there is a cost - it's capacity that could be used for other purposes, eg. home alarms.
weaksauce[hidden]
b112[8 comments hidden]
Here that means no lawyers, no discovery, $100 to file in plain language, and a company employee (not a company lawyer, or a contractor, or a temp employee) must attend or they default.
$15k damages.
Reasons it could happen? Imagine grandpa has a tech come out 4 times, because his network is super slow. EG, this thing pounding his wifi for its scans.
zdragnar[7 comments hidden]
Grandpa gets reimbursed for the four techs who came out, that's it.
b112[6 comments hidden]
Grandpa gets his money back. The company? Well, it has to spend money talking to a lawyer, because even though a lawyer can't attend small-claims court, they still consult.
They also have to send an employee to small-claims court, just have to deal with it. In the end it costs the company thousands of dollars maybe even over ten grand. It costs you a hundred bucks and you get your money back. That sort of asymmetry is beautiful, and if everybody availed themselves in small claims court, it would be far better than any class action lawsuit.
zdragnar[5 comments hidden]
Grandpa is definitely not getting $15k in damages, and Keurig can deal with this with their in house lawyer that they're already paying a salary for. They're definitely not shelling out big bucks here. It'd be cheaper for them to let the default judgement happen than to actually show up.
3-cheese-sundae[hidden]
Let everyone file that claim for a single geek squad visit.
b112[3 comments hidden]
Please show me how this is suboptimal? Especially with LLMs to write the demand letter, and walk you through the process.
And 'using their in house lawyer' still has time cost, as does dealing with the routing and pondering the service letter. And accounting paying up. There is no aspect of your 'worst case' where it's bad. It's still all pluses. And if as I suggest, lots and lots of people do it, then they end up with a loss on that product.
If each case is $1000, or even $500 payout, how much profit does that take? Profit on 100 units? 50? If a product is horrifically bad, and everyone runs to small claims court, that's disaster for a company.
zdragnar[2 comments hidden]
> If each case is $1000, or even $500 payout
How many people are going to spend $500 on service techs coming out to their house? So far we've got a report from one guy who figured it out with no damages at all, and therefore no case for a small claims court. Since it was found to be defective 10 days after first use, it's probably still eligible to be returned for a refund, so even the cost of the machine isn't eligible.
> If a product is horrifically bad, and everyone runs to small claims court, that's disaster for a company
This much I can agree with for sure. While it is definitely bad, I don't think flooding small claims courts is going to be a viable strategy in this particular case.
b112[hidden]
For whatever reason I didn't finish that sentence, and just said 15k. Sorry about that.
Where I am, you can get back the cost for sending a registered letter by courier to have it served, signature required. Also for the demand letter. You can get money back for filing, the $100 for example. Lots of little incidentals.
To me, it's when the damages are smallest, that small claims court is the biggest benefit. Losing $30, suddenly becomes a bill of $200, after it goes through small claims court.
But anyhow, I'm just happy if you like small claims court to some degree. I just think we should all use it more.
nkrisc[3 comments hidden]
didgetmaster[2 comments hidden]
nkrisc[hidden]
mcv[hidden]
jimt1234[11 comments hidden]
autoexec[5 comments hidden]
Right now companies are somewhat limited in how much use they can get out their horde of private and personal information, but AI is changing that rapidly. As long as you don't mind a huge rate of error (and companies don't because it all becomes "good enough" at a large enough scale) it's basically perfect for the task of digging through endless amounts of information and spewing out bullet points.
burpingtree[2 comments hidden]
3-cheese-sundae[hidden]
0cf8612b2e1e[2 comments hidden]
autoexec[hidden]
josephg[5 comments hidden]
Not in my house. What is even the point of connecting a coffee machine or a washing machine to the internet? I think my washing machine advertised that I could download new washing cycle programs in the app. Who on earth cares?
Aerroon[4 comments hidden]
None of these are worth the spying that these companies do though.
alexfoo[2 comments hidden]
I have all of my IoT devices on separate Wifi network(s) and VLANs and almost all of them are isolated so they can't talk to each other, plus I occasionally look at how much data they are sending/receiving from the Internet (some is expected obviously, and it differs by device).
Doing this requires a considerable amount of admin work and IT knowledge though. It also requires something a step above most consumer grade or supplier provided networking equipment.
I've never spotted anything egregious like the coffee maker in the OP but if I did I'd be making sure other people knew about it and the device itself is either firewalled off properly or replaced by a brand that isn't a security risk.
simoncion[hidden]
As someone who has done this, it's a one-time cost (as long as you're not the sort who simply can't stop tinkering with it and ends up totally rebuilding it like once a quarter (don't ask me how I know)) and -if you have even just a shaky understanding of how to do it- it's not _that_ large of a cost.
> ...and IT knowledge though.
I definitely agree that doing this requires quite a bit of IT knowledge... but it's all stuff that's pretty easily learnable for anyone who's interested in technical stuff and/or technically-inclined.
For folks who are looking to do this on their home LAN, I have some hardware manufacturer recommendations:
All of this VLAN work will be entirely pointless if your switches can't be programmed to enforce the separation, so one will need "managed" switches of some kind. I'd recommend anyone who wants to try to do this to have a look at Mikrotik switches... they are inexpensive and definitely more than good enough for a fancy home LAN.
Mikrotik also sells routers and WiFi APs. I can't comment on the quality, as I have slapped together my own router PC and use OpenWRT Ones for my APs... but I've found their switches to be more than good enough for my fancy home LAN. Perhaps their routers and AP are equally good?
Mikrotik publishes pretty comprehensive documentation here [0]. If you want to dick around with the Mikrotik management CLI for RouterOS -which is their name for their fancy management software- you can install the x86 version of RouterOS in a VM by booting a VM from one of the x86 install images at [1]. They also have a much simpler management software that you can run on all of their switches called "SwOS" -documented here [2]- but that doesn't have any x86 installation media so you can't play with it on your PC.
[0] <https://manual.mikrotik.com/docs/introduction>
[1] <https://mikrotik.com/download?architecture=x86>
[2] <https://manual.mikrotik.com/docs/bridging-and-switching/swos...>
prmoustache[hidden]
What is the point of activating a washing machine remotely if you aren't there to put your laundry inside? What is the point of activating your coffee machine remotely if you are not here to drink it? Even when you have to fill water in the machine and grind coffee beans, and wait for the machine to preheat the water.it takes less than 3 minutes to prepare an espresso.
protocolture[hidden]
Looks like nmap OS detection can use ~90kb per host per attempt.
fmbb[hidden]
jiscariot[hidden]
KellyCriterion[hidden]
But why do they need to collect 1 TB? Sounds like a lot of redundant/doublicated entries then for a small network?
dovin[33 comments hidden]
danielheath[11 comments hidden]
swerve3815[6 comments hidden]
bityard[hidden]
hansvm[hidden]
jz391[hidden]
dolmen[2 comments hidden]
wiml[hidden]
ambicapter[3 comments hidden]
NichoPaolucci[2 comments hidden]
Makes me think of DraftKings. You take your average 20 something sports fan - drinking beer, watching the game. And, on the other end of that smartphone display exist some of the most complex algorithms ever designed by teams of mathematics / statistics PhDs and it's deliberately built around targeting... this one guy from Florida who is pretty sure his team will be up by 7 at halftime.
Maybe it's more of a morbid joke, but it makes me laugh to think about.
BLKNSLVR[hidden]
It's an accurate explanation.
tomrod[hidden]
eckelhesten[3 comments hidden]
dovin[2 comments hidden]
r_lee[hidden]
so if you know that a user is having an affair, you might want to serve divorce lawyer ads (I'd imagine those are very expensive) or something.
this kind of data though is just like a cog in the machine, but it can e.g. give enough info to know how many people likely are in that household, and so on. useful when combined with other signals
Quinner[hidden]
paimapi[7 comments hidden]
It can also correlate it with geolocation data. Google, for eg, sniffs all broadcasted SSIDs with their StreetView cars. If you can pick up on a SSID (or any of the MAC addresses of the other devices), you can buy the data set that includes it which further pinpoints demographics given the neighborhood AMI.
You can also build behavioral profiles patterns based on things like, for eg, if a baby monitor model is present or a robot vacuum, if certain devices only connect at certain times, etc.
I think the general rule for adtech is that profile guesstimates just need to be around 70%+ fidelity to determine if a sale can be made.
Lastly, you can also just sell the data on the gray market. The more datapoints, the higher the price. Most consumer product companies do that since we have little-to-no data privacy laws and the people who seem the most aware of it also are generally very apathetic and disinterested in advocating for them.
dovin[hidden]
tomrod[hidden]
Terr_[4 comments hidden]
For example, your aged mother's phone will get pinged within X meters of an urgent-care facility, or she'll do some web-search about "hip pain", and then all the adult children start getting ads about elderly-parent-care.
Or perhaps the pervy-panopticon decides some phone-on-wifi events look like adultery, and both suppposed spouses start getting ads for divorce lawyers, private investigators, or track-covering products. (Bonus if certain specialized "adult" toys are detected on Wifi or Bluetooth...)
paimapi[3 comments hidden]
it's probably even more dystopian now with phone apps vacuuming up every last dreg.
crummy[2 comments hidden]
paimapi[hidden]
lenkite[2 comments hidden]
Scale it up - make that millions of homes. Now there is godlike strategic value. Esp when "borrowed" by 3 letter agencies.
dovin[hidden]
srcreigh[4 comments hidden]
jacquesm[3 comments hidden]
reaperducer[hidden]
ted_dunning[hidden]
hansvm[hidden]
If you have even very crude data from somewhere else for the targeting, improvements in attribution tech are actually the more important factor. The adtech company mostly doesn't even care who you are, just whether the ad turned into a purchase or not, and that's where a lot of the invasive tracking comes from. They'd be perfectly happy with a quickly changing "identity" if they knew it was reliable and stable between ad and purchase.
adamrezich[2 comments hidden]
scun[hidden]
ncr100[hidden]
I don't know if it has a microphone, to be clear. Just answering your question
khriss[86 comments hidden]
WTF!! When did we land in the middle of a Black Mirror episode?
I'm half convinced the first run of the LHC split the timeline and we've landed in the evil one.
aintnoprophet[hidden]
VariousPrograms[23 comments hidden]
newswasboring[15 comments hidden]
cogman10[13 comments hidden]
With just a little bit of interaction with the modern internet, the profiles created are stunningly accurate. Age, gender, political ideology, favorite food, relationship status, how many kids you have.
All this stuff gets slowly collected, aggregated and shared amongst data brokers.
People would care so much more if they knew just how invasive advertising actually is. All to try and convince you to drink one more coke or grab one more cheeseburger.
bushbaba[5 comments hidden]
newswasboring[4 comments hidden]
bushbaba[2 comments hidden]
newswasboring[hidden]
ligne[hidden]
pmichaud[3 comments hidden]
lovich[hidden]
scruple[hidden]
lwhi[hidden]
Maybe I should be port scanning it to make sure?
newswasboring[3 comments hidden]
projektfu[2 comments hidden]
newswasboring[hidden]
pennomi[hidden]
n0dose[3 comments hidden]
DANmode[hidden]
red-iron-pine[hidden]
330M people in the country, you can run that entirely though a remote FBI office.
and the people using the data are gonna be the local cops; FBI ain't flying out to chase a couple of basic-ass assault charges or thefts.
email snooping, hand full of highway cameras at known bottlenecks, border crossings -- these are abstractions to most people. the flock cameras in their neighborhood are not, and cannot be absractions.
rockskon[hidden]
If people didn't care then why do so many companies have to coerce/deceive users into using their product?
Convenience my ass - the alternative to "convenience" is not participating in modern society, which isn't a decision at all.
GJim[hidden]
Ahem
https://www.gov.uk/data-protection
aleph_minus_one[2 comments hidden]
This depends on the country:
- In Germany, many people are very suspicious about such privacy invasions.
- In Singapore, on the other hand, people seem to very accepting of public surveillance if it serves public safety.
- In China, of course, public surveillance is also huge (at least in the big cities). I don't know how Chinese citizens think about that.
goalieca[hidden]
And thanks to surveillance, you never will.
etatoby[20 comments hidden]
FridgeSeal[5 comments hidden]
World only survives, in realities where this particular creature in containment is alive. I’ll see if I can dig it up.
andersonpico[4 comments hidden]
iririririr[hidden]
> Reactive Action: None taken; event fully consistent with long-term probability models.
heh. love scp humor.
TeMPOraL[hidden]
But thanks for an hour-long break from work nevertheless.
SCP Wiki should itself be classified an Euclid-level threat (TV Tropes is obviously Keter class).
martey[hidden]
swader999[hidden]
Melatonic[4 comments hidden]
drybjed[2 comments hidden]
AspireOne[hidden]
rootsudo[hidden]
devmor[4 comments hidden]
https://en.wikipedia.org/wiki/Quantum_suicide_and_immortalit...
kelipso[3 comments hidden]
https://reactormag.com/divided-by-infinity/
lwhi[hidden]
devmor[hidden]
emmelaich[hidden]
rustcleaner[4 comments hidden]
gblargg[2 comments hidden]
cheschire[hidden]
mr_mitm[hidden]
oooyay[4 comments hidden]
OneDeuxTriSeiGo[hidden]
eru[hidden]
People can work around patents, or pay for licensing them etc, if they really want to do something.
red-iron-pine[hidden]
fcarraldo[14 comments hidden]
At least a decade ago! The first TVs with Automatic Content Recognition shipped in 2013[0]. There was also a brief panic in 2024 about air fryers spying on people[1].
And of course practically every website you visit is doing a full session recording with mouse movements and key presses captured.
[0] https://en.wikipedia.org/wiki/Automatic_content_recognition
[1] https://www.theguardian.com/technology/2024/nov/05/air-fryer...
godelski[2 comments hidden]
[0] https://m.youtube.com/watch?v=tL8_caB35Pg
lifestyleguru[hidden]
wcfields[3 comments hidden]
I worked at a major media buyer agency “big 5” in advanced analytics; we were a team of 5-10 data scientists. We got a firehose on behalf of our client, a major movie studio, of search of their titles by zip code from “G”.
On top of that we had clean roomed audience data from “F” of viewers of the ads/trailers who also viewed ads on their set top boxes. Basically any internet connected device you get is probably doing whatever it can to sniff mac addresses of your network at the least.
From a previous comment of mine:
> … my Insignia TV (best buy store brand) with fire tv built in is basically unusable. Echoing a previous comment I made too, about “smart tvs” and the “streaming sticks”: Hey, have you ever thought of why even the $149 Black Friday loss-leader no-name-brand TVs all have Amazon Fire, Roku, or are now "Smart" in some way? Certainly isn't because they need to incentivise you to connect it to the internet so it acts as a Nielsen-esq measurement device of all media you view on the screen via digital fingerprints that exist in all commercial media and advertisements. [1][2]
[1] https://www.ispot.tv/
[2] https://www.samba.tv/
creato[hidden]
Doesn't Google basically make this kind of data public? I know I've seen maps by state of what people are searching for, this is barely different.
Point being, it seems absurd to compare this to snooping on people's private networks by third parties
Zak[hidden]
And yes, it's for the reasons those of us who have been in the tech field for a while would guess: it's "smart". It comes preloaded with apps for several streaming services, from which it surely gets a cut. It probably displays ads if allowed to connect to the internet. No doubt it reports what you watch.
chaostheory[2 comments hidden]
conductr[hidden]
consp[hidden]
dahart[3 comments hidden]
Well yeah at the very least, that’s Google Analytics and/or similar alternatives.
Most individual websites outside of Google/Facebook/Amazon don’t get any data other than what you do on their website, so it doesn’t seem quite as creepy to me as a device on your home network port scanning and sniffing other traffic.
Google and Facebook can and do ‘spy’ a lot, of course, but otherwise the browser does protect you from most trivial spying by random sites. Not that that’s reason to feel any safer; the few people actually spying on what you do everywhere on the web are the ones with the most resources. This is all going to get way weirder with AI logs, I’m guessing.
convict[2 comments hidden]
matltc[hidden]
mdp2021[2 comments hidden]
And the first store clerks at the time that shout that "all people have agreed on that, period, complaints are non appropriate because society decided".
A small step for senseless humanity, a giant leap for the beast with big promises (that we are still seeing in development).
PeterStuer[hidden]
dofm[hidden]
April 29, 2016. It explains so much.
dboreham[hidden]
rebolek[2 comments hidden]
podocarp[hidden]
akssri[hidden]
3RTB297[hidden]
Lovey example: https://frescocooks.com/platform/marketing-and-engagement
Air Fryers selling data: https://abc7news.com/post/certain-air-fryers-app-connected-a...
Student in NZ protesting it: https://www.consumer.org.nz/consumer-rights-and-campaigns/da...
Hope your TV isn't connected to the internet: https://www.cnet.com/tech/home-entertainment/tv-spying-yes-h...
sharperguy[hidden]
harrouet[2 comments hidden]
The first thing that Meta did after Brexit was moving its UK's user data to the US.
GJim[hidden]
The FUD (never laughter) came from the scummy US ad-tech industry; the people whos very salleries depend on invading our privacy.
You will find many of them posting (and downvoting GDPR posts) here on HN to spread their FUD.
baxtr[hidden]
samsari[hidden]
Sadly the real answer is much less dramatic: we did this entirely to ourselves, voluntarily, purely out of lazily taking the path of least resistance offered us by companies that don't have our best interests in mind.
ywvcbk[hidden]
blitzar[hidden]
lifeisloving[hidden]
conjectures[hidden]
I'd convergence was about 10 years back. Whenever the David Cameron pig story broke.
wartywhoa23[hidden]
The majority of people just chose to turn their blind eye towards those developments and dismiss the warnings as conspiracy theories.
coldtea[hidden]
"Smart" devices have been pulling this shit for years. If you're surprised by this you weren't paying attention!
FrustratedMonky[2 comments hidden]
red-iron-pine[hidden]
mikrl[hidden]
wesammikhail[hidden]
marginalia_nu[hidden]
The EFF, Doctorow, et. al. were warning us that this was going to happen, over and over again for a really long time. Then they were saying it was beginning to happen for a really long time. Well guess what, the thing they were saying was going to happen happened!
rose-knuckle17[hidden]
We really need laws protecting consumers from "data collection for advertising". It should be a default no with a requirement for explicit opt-in /and with no legal way for companies to charge less for the advertising model/. In fact, customers who agree to the advertising model should be able to get profit sharing revenue.
jimrandomh[2 comments hidden]
radio879[hidden]
I've heard that they put it in IoT devices, free Android apps that people use on their TVs, free phone apps, games, prob lots more.. The companies advertise it like its super safe only legit normal people borrow the internet from these people but then in fine print it'll say its not our responsibility etc.
What I have been wondering is - since they don't seem to care or check what people are using the "residential ip's" for, what happens when someone does a bunch of illegal stuff on some random person's home IP and ends up raided by cops?
I feel like the world is going in these directions.. the excuse is always "well, they clicked Yes on the Terms of Service! They agreed to it!"
mahboi[hidden]
ultrahax[12 comments hidden]
SlightlyLeftPad[2 comments hidden]
gspr[hidden]
This shit needs to be banned, now!
kevin_nisbet[hidden]
thedougd[8 comments hidden]
gruez[4 comments hidden]
That still doesn't make any sense. If they want to collaborate to build an advertising profile, your public IP is all you need. Otherwise if they're not collaborating, what's the plan, find 0days in random IOT devices and hack them? I might be concerned about random chinese IOT devices doing that, but not devices from western companies.
cogman10[3 comments hidden]
Data brokers are buying from multiple sources because maybe a home has a keurig but not an LG tv. Or an LG tv and not a keurig.
The plan for the likes of Keurig is "These data brokers will give us free money for data from our coffee machines? Where can we sign up!". It doesn't even matter if the money translates to $0.01 per unit sold. That's probably the most disgusting part.
gruez[2 comments hidden]
Right, but OP's premise is that putting everything on the same LAN is somehow even better for the manufacturers/data brokers/ad networks/whatever, which doesn't make any sense. The only thing that actually matters is a device with internet connection.
thedougd[hidden]
clivedup[2 comments hidden]
Client isolation would help, but it also breaks some devices.
Are there decent daemons that allow me to allowlist which broadcast traffic to permit?
Ideally it'd be compatible with IPv6-only clients on my LAN.
thedougd[hidden]
I feel like we could build a custom reflector/firewall that would make selective isolation possible.
gblargg[hidden]
WheatMillington[3 comments hidden]
dolmen[2 comments hidden]
account42[hidden]
Waterluvian[hidden]
dolmen[2 comments hidden]
Because the article is also full of 238 advertisers.
zahlman[hidden]
amluto[11 comments hidden]
Coffee machine scans network? Nope.
Coffee machine reports things about your network? Nope.
TV does ACR? Nope.
TV reports things it incidentally learns about your listening habits? Nope.
TV transmits any microphone data or things derived from mic data that aren't explicit user commands? Nope.
Companies who collect this data even though it's illegal want to sell it or use it for marketing or transfer it to anyone else? Nope.
Company A provides an SDK to company B that does this kind of thing and company B sells the product? A is liable, civilly and criminally, and B is also civilly liable to the extent that they should have and did not exercise due diligence to prevent it.
Company A, company B, and/or the end user have some contract shifting liability? Nope. The parties that the law said are liable are liable, cannot use the contract to avoid liability, cannot use the contract to recover money they have paid as a result of this liability, and cannot enforce arbitration provisions.
Anyone tries to use a contract that is considered illegal under this law? That party becomes responsible for their opposition's legal fees even if they are ultimately found not liable for some other reason.
Police wants to buy this data? Sure, they're welcome to buy what's legally available, except that they, like everyone else, will have a hard time getting the data because it's illegal for anyone to acquire it or sell it.
It's high time to get this done. We've got this and the recent evidence of LG doing all kinds of worse crap and it really should be possible to get some legislators on board.
komali2[6 comments hidden]
gspr[4 comments hidden]
I understand your feeling of despair. Of course I do. But you don't have to make other people despair. History has shown us where we end up when enough people despair.
dboreham[hidden]
komali2[2 comments hidden]
For certain definitions of corrupt, with almost no exceptions, all politicians in neoliberal democracy are corrupt, because they serve the needs of Capital rather than people.
There's some interesting things happening with DSA in the USA but it feels like plugging a thumb in a dam.
I'm hardly killing democracy. More like poking a rotten corpse with a stick.
I don't despair, btw, I don't rely on the continuation of liberal democracy for my happiness. I'm waaaaaaay left of that.
gspr[hidden]
amluto[hidden]
If marketers cannot pay Google, Meta, etc to show their ads to people whom pervasive surveillance indicates are the appropriate targets, then they will pay companies (probably still Google and Meta and very likely still American companies) to show ads to people selected by other means. Everyone’s retirement account will be just fine.
For that matter, consider who some of the biggest offenders are right now. LG and Samsung are Korean. Sony is Japanese. (But Vizio is American and seems to be owned by Walmart.) Maybe reducing surveillance capitalism will make it harder for some of these foreign companies to extract money from the US.
There’s also the national security aspect. Right now, we expect foreign corporations to extensively spy on us. Sure, a law would not necessarily stop foreign powers from spying on us, but at least if we banned the general practice, then foreign powers who do spy on us might get noticed.
al_borland[2 comments hidden]
With all the hacks going on, I can't imagine why any company would even want to collect anything if they have a business model that works without it. I would think selling coffee makers and coffee pods would easily be a business model that works without data harvesting. Companies made whole businesses out of selling coffee makers alone for decades.
amluto[hidden]
https://help.earnapp.com/hc/en-us/articles/38191916327441--W...
I think Bright Data is similar but I didn’t find their authoritative numbers. It doesn’t help that my ad blocker blocks their entire domain.
kittomic[hidden]
voidUpdate[hidden]
xyst[hidden]
The people that said LG isn’t the only company doing invasive data harvesting is sadly correct.
How did we as a society let it get to this point?
zahlman[2 comments hidden]
dboreham[hidden]
gblargg[2 comments hidden]
smt88[hidden]
MarceliusK[hidden]
hn_throwaway_99[2 comments hidden]
This is either outright false or at least highly misleading. Keurig says they may sell information about your coffee brewing habits to third parties (i.e. your usage of the coffee machine itself), but nowhere does "Keurig note" that they collect other data about your household through network scans and sell that to advertisers.
I'm not even sure which tweet you were referring to that implied that. In any case, there are tons of responses here that are interpreting your quote as saying Keurig admitted they do network scans to acquire info about your household to sell to third parties, and that (the idea that Keurig says they do this) is flat out false.
isolli[hidden]
h1fra[hidden]
bodge5000[hidden]
Off topic, but an odd and dubious upside to AI is that it provides an actually valid reason for this mass data collection. Before AI, as you note it was for advertisers, but what are they actually doing with it?
The promise was that with all this data, advertising would be perfected. I seem to remember fears back in the day that it could end up being a form of mind control, with this perfect understanding of you an advertiser could sell you anything, and you'd willingly consume adverts as entertainment they'd be so perfectly tailored to you. Not something any of us would want I'm sure, but that was the promise for advertisers. The opposite ended up happening. Nobody wants to use the internet without an ad-blocker, when you're forced to use Youtube or something without an ad-blocker you're counting down the seconds until you can skip it, and the rest of the time you don't even notice they're there, let alone any kind of mind control. Of course you do get thinly veiled advertisements as entertainment, but none of them use mass data collection, they're really not much different to how tv shows used to get made to sell toys in the 80s.
The reason I bring this up is for the question; what is this mass data collection for? We (really) don't want it, advertisers are either unwilling or unable to use it and it costs a tonne of money and effort. The obvious, and disappointing, reason is that we all need to pretend it works or the internet as we know it collapses, for better or worse. That plus AI being the new excuse I suppose.
ubermonkey[hidden]
Good lord.
DebtDeflation[3 comments hidden]
sumtechguy[2 comments hidden]
It is a question many devs miss. what happens when I put this in the wild and I now have hundreds of them.
In this case it is probably scanning aggressively. Just incase you plugged in a new devices in the past 100ms. Then some sort of filter with data compression (hopefully) and then sending its exfiltrated data back home. Honestly, not a cool thing to do and makes your customers NOT trust you. I had an old LG TV that was doing this 15 years ago where it would send every button press back to LG. I unplugged it. It agressivly scan its empty socket.
DebtDeflation[hidden]
svachalek[hidden]
Aurornis[hidden]
Where is this shown? I see it repeated all through the HN comments but I don't see it in the X thread.
The person who discovered this says he didn't even open Wireshark and capture a few packets, which would have immediately revealed something about the situation.