Rendered at 03:41:07 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
altairprime 10 hours ago [-]
In the Twitter thread linked, the person confirms two things:
1. It saturated the local network with 1TB of metadata sniffing scans, not the network uplink to the outside world.
2. It does so because, as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.
Grombobulous 2 hours ago [-]
I don’t dispute the purpose of the data collection, but I can’t believe this quantity of data collection is intentional.
There’s no way Keurig is has the intention of paying the kind of costs required to collect a terabyte of data every two weeks for millions of people who own their coffee makers.
There must be some kind of bug here. I imagine if you unplugged it and plugged it in again the data usage would settle down.
mindslight 48 minutes ago [-]
Probes create much more traffic locally than it takes to backhaul a summary of their results.
sgillen 16 minutes ago [-]
1TB still smells like a bug
whycome 9 hours ago [-]
Why is this allowed? There’s no way to consent to a coffee machine.
nicbou 60 minutes ago [-]
It's not allowed in the EU. Not without consent.
Neywiny 8 hours ago [-]
Presumably during setup and connection to the AP it has a ToS. Doubtful they just unboxed, plugged in, and it connected to the right AP and went.
Citizen_Lame 5 hours ago [-]
ToS can't trump the actual law.
preg_match 2 hours ago [-]
The actual law is typically so weak and spineless that the ToS doesn't need to trump it. Particularly when it comes to data security or privacy.
black6 3 hours ago [-]
It's implied consent when you give it access to your WiFi.
Why you would give a coffee maker access to your WiFi is the real question,
pfannkuchen 3 hours ago [-]
So in other words, they were asking for it?
K0balt 1 hours ago [-]
Well, yeah sorta since the only reason appliances connect to the internet is to steal data. I mean, if you buy a connected x that normally would not be connected, it’s 99 percent there to do nefarious stuff for its real owners. It’s like having a pet lion. Sure, it’s horribly irresponsible that someone sold you a pet lion, but. Uuuh you bought at pet lion. What did you think it was going to do?
Besides, did you see how he was dressed?
AnimalMuppet 7 hours ago [-]
To me, this is begging for a class-action lawsuit.
Yeah, sure, the terms of service probably say that they can do that. That's still in "unconscionable" territory. And courts do not like unconscionable contracts. If it's unconscionable, it's invalid (if I understand the law correctly).
Is this why everybody wants to make appliances with wireless?
altairprime 6 hours ago [-]
Yes, this is why everybody wants to make vehicles and refrigerators and thermostats and ereaders with cellular and/or wireless: subscription revenue from bulk data purchasers of what their scans reveal. IIRC Amazon was an industry leader in this space by showing book authors what page you stopped reading on, and then bulk assessing that data at scale to estimate which sentence or word; of course, Google’s Android remains the most successful at-scale deployment of data collection for advertisers worldwide. See also, for recent context, the top comment (and others) of the LG Smart TV problem (30 days ago, 1012 comments) https://news.ycombinator.com/item?id=49592375
kotaKat 5 hours ago [-]
Funny thing, that. Go into an electronics store now and pay attention to the TV boxes and the printer boxes. The amount of crazy fine print on both of them now is absurd. The printer boxes all now have lots of fine print about the various ink protection and DRM schemes and subscription services, the TV boxes have everything ranging from binding arbitration on the box (LG) to "(brand) accounts are REQUIRED to use this TV" (Visio).
Customers are gonna get lost in the sauce and skip right past all of that and toss the packaging.
rasz 4 hours ago [-]
> as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.
its LGs glass in LG household, and now Keurigs kitchen
lazide 9 hours ago [-]
#1 - why?
#2 - oh, because fucking yikes.
ck2 10 hours ago [-]
it took me a month to notice my Midea A/C was absolutely hammering my router
I didn't even know it had wifi capability but it was trying to connect
I use mac whitelist so it wasn't even getting in but that didn't stop it from trying every seond
Fortunately it was just a usb dongle so yanked it out
altairprime 8 hours ago [-]
Most Midea units can be swapped for an ESPhome USB dongle if you ever wish to have remote control on your own terms — note various countries’ shop links, and the various wiki and other outlines for DIY etc: https://smlight.tech/product/slwf-01
HankB99 6 hours ago [-]
Ooo. I have a Midea dehumidifier. When it powers up it displays the WiFi symbol. I wonder if it is hammering away at my access point. Might it be better to bring it on line and then just block all traffic?
And I wonder how I would even tell if it was trying to associate with my WiFi.
ars 10 hours ago [-]
I have two of them, and I just checked and both are quiet. Mine don't connect to WiFi unless you go through an entire process first with an android phone and Matter.
It's great having them on WiFi - you can turn on the AC before getting home to pre-cool, without having to leave it on all day.
sillyfluke 8 hours ago [-]
Boy: So, how it get this bad grandpa?
Man: Well, before you couldn't turn on the AC before you got home
ars 7 hours ago [-]
Realistically people would just leave their AC on. So this saves energy, rather than changing comfort.
Cpoll 6 hours ago [-]
Realistically ACs have timers, so you're really only optimizing for days where you go off-schedule.
sillyfluke 5 hours ago [-]
I have a friend who diy'ed a button on single webpage that he presses on his phone while at work in order to open the gate to the building that he lives so delivery people can get in. I also think Bret Victor diy'ed the AC as mentioned while he was a student quarter century or more ago[0]
I know this sounds like the famous "just do it this way in linux instead" criticism of Dropbox back in the day. But I do think we reached "life parodies fiction" with these smart devices where it makes sense to give diy another go. And with AI, there's less excuses this time around I would imagine.
But I would literally rather buy a cheap phone, a cheap SIM, hotspot it and connect it to a charger and have the AC connect to that and isolate it that way instead of letting it touch the network.
You can (and should) just segregate your network to have separate paths for IoT/"smart devices" and normal personal/family devices. Makes it all worry free and transparently observable.
I have my IoT on a separate VLAN and I can observe communications for any given device at any given time.. this seems like a much saner solution than outright not buying any IoT devices, though that is also a respectable decision!
tamimio 8 hours ago [-]
Reminds me when couple years ago I plugged the TV to the internet (so my relatives kids can watch YT) and I forgot to unplug it for almost a week after, only to find the router dns resolved (and blocked) a million queries, all from that one TV!
bombcar 3 hours ago [-]
I love when it keeps checking some random DNS address, because who knows, with a TTL of 64000 it may just have changed in the last seven milliseconds!
altairprime 8 hours ago [-]
The traffic generated here is network scans, not external traffic, and so blocking DNS wouldn’t have helped.
ButlerianJihad 7 hours ago [-]
A year or two ago, I was using NextDNS in ad-blocking and logging mode, which very helpfully exposed malware sitting on my very router, which had been completely undetectable, except for the veritable flood of bizarre DNS queries it was routinely sending to the self-configured DNS servers.
Now that I have a new router and I've re-enabled NextDNS, I've ironically discovered that the chief abuser of DNS right now is the router's own legit security software, which is absolutely hammering on the same query, several times a second.
Of course, since I am currently on NextDNS free tier, this matters a lot, because they cut you off after about 300,000 queries in a month. So any hammering abuse will make me lose my privileges much earlier than I would otherwise. So, to stop the abuse, should I shut off my legit security software? It is absolutely rubbish at identifying malware on the device itself...
matteoraso 6 hours ago [-]
I honestly hate the IoT so much. Why should a coffee machine of all things use data? Just make the coffee.
rendall 7 hours ago [-]
The GDPR consent form on this blog did not have a “Reject all” button. It required me to manually reject 16 instances of “legitimate interest,” then scroll through 1,746 vendors to make sure they were all set to reject.
Seems worth mentioning in a post about excessive and intrusive collection of user data. The moral outrage rings hollow when opting out of tracking is so deliberately onerous.
wafflemaker 7 hours ago [-]
And also illegal. It's illegal not to have one button. Companies didn't do it because they suddenly stopped being scum.
1. It saturated the local network with 1TB of metadata sniffing scans, not the network uplink to the outside world.
2. It does so because, as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.
There’s no way Keurig is has the intention of paying the kind of costs required to collect a terabyte of data every two weeks for millions of people who own their coffee makers.
There must be some kind of bug here. I imagine if you unplugged it and plugged it in again the data usage would settle down.
Why you would give a coffee maker access to your WiFi is the real question,
Besides, did you see how he was dressed?
Yeah, sure, the terms of service probably say that they can do that. That's still in "unconscionable" territory. And courts do not like unconscionable contracts. If it's unconscionable, it's invalid (if I understand the law correctly).
Is this why everybody wants to make appliances with wireless?
Customers are gonna get lost in the sauce and skip right past all of that and toss the packaging.
its LGs glass in LG household, and now Keurigs kitchen
I didn't even know it had wifi capability but it was trying to connect
I use mac whitelist so it wasn't even getting in but that didn't stop it from trying every seond
Fortunately it was just a usb dongle so yanked it out
And I wonder how I would even tell if it was trying to associate with my WiFi.
It's great having them on WiFi - you can turn on the AC before getting home to pre-cool, without having to leave it on all day.
Man: Well, before you couldn't turn on the AC before you got home
I know this sounds like the famous "just do it this way in linux instead" criticism of Dropbox back in the day. But I do think we reached "life parodies fiction" with these smart devices where it makes sense to give diy another go. And with AI, there's less excuses this time around I would imagine.
But I would literally rather buy a cheap phone, a cheap SIM, hotspot it and connect it to a charger and have the AC connect to that and isolate it that way instead of letting it touch the network.
[0] https://worrydream.com/Electronics/
I have my IoT on a separate VLAN and I can observe communications for any given device at any given time.. this seems like a much saner solution than outright not buying any IoT devices, though that is also a respectable decision!
Now that I have a new router and I've re-enabled NextDNS, I've ironically discovered that the chief abuser of DNS right now is the router's own legit security software, which is absolutely hammering on the same query, several times a second.
Of course, since I am currently on NextDNS free tier, this matters a lot, because they cut you off after about 300,000 queries in a month. So any hammering abuse will make me lose my privileges much earlier than I would otherwise. So, to stop the abuse, should I shut off my legit security software? It is absolutely rubbish at identifying malware on the device itself...
Seems worth mentioning in a post about excessive and intrusive collection of user data. The moral outrage rings hollow when opting out of tracking is so deliberately onerous.