22 comments

  • altairprime 1 day ago
    In the Twitter thread linked, the person confirms two things:

    1. It saturated the local network with 1TB of metadata sniffing scans, not the network uplink to the outside world.

    2. It does so because, as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.

    • khriss 21 minutes ago
      > as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.

      WTF!! When did we land in the middle of a Black Mirror episode?

      I'm half convinced the first run of the LHC split the timeline and we've landed in the evil one.

      • etatoby 2 minutes ago
        Do you remember how a series of crazy coincidences and freak accidents kept preventing the LHC from being turned on? What if the LHC was causing world-ending or life-ending events, and we simply kept surviving only in thinner and thinner slices of amplitude (timelines) where those freak accidents happened, but where also more improbable world conditions took place?
      • VariousPrograms 9 minutes ago
        No one cares. There’s little serious pushback to privacy invasions by big tech. Flock cameras have been a rare exception. Half the people “have nothing to hide” and half aren’t willing to give up the convenience that the popular app or gadget gives them.
      • aintnoprophet 17 minutes ago
        Unauthorized Bread
    • dovin 1 hour ago
      That's obviously bad and I hate it, but how much value even is there is the data that a spyware coffee machine could collect about your home? What advertisers would buy such data and what would they advertise to me? What is the marginal value of that data?
      • paimapi 52 minutes ago
        You can also map a home out depending on signal strength. That gives you approximate size of home which gives you approximate income.

        It can also correlate it with geolocation data. Google, for eg, sniffs all broadcasted SSIDs with their StreetView cars. If you can pick up on a SSID (or any of the MAC addresses of the other devices), you can buy the data set that includes it which further pinpoints demographics given the neighborhood AMI.

        You can also build behavioral profiles patterns based on things like, for eg, if a baby monitor model is present or a robot vacuum, if certain devices only connect at certain times, etc.

        I think the general rule for adtech is that profile guesstimates just need to be around 70%+ fidelity to determine if a sale can be made.

        Lastly, you can also just sell the data on the gray market. The more datapoints, the higher the price. Most consumer product companies do that since we have little-to-no data privacy laws and the people who seem the most aware of it also are generally very apathetic and disinterested in advocating for them.

        • dovin 30 minutes ago
          Yeah, it definitely makes sense to me if what adtech is often doing is just backing out from specific data to a general profile like income, location, etc, so that that level of targeting can work.
        • tomrod 8 minutes ago
          Its just sick.
      • danielheath 1 hour ago
        Knowing what TV you own, what phone models are used in your house, and what other devices you own tells advertisers about your spending patterns and income.
        • swerve3815 1 hour ago
          I wonder if you can identify the age of devices based just on network scans? Like if an advertiser can tell I've got a washing machine model that was last sold 7 years ago, it's time to spam me with washing machine ads.
          • bityard 20 minutes ago
            Quite probably. nmap does (or certainly used to) have options to report the OS of a given machine had based on various quirks of the packets it got back from them. It was disturbingly accurate at times. You put that together with banner messages from running services, MAC addresses, responses to broadcast packets, deliberate probing, and the number of devices you _can't_ remotely identify on a network without actually logging into them is probably very small.
        • tomrod 9 minutes ago
          My income is low. Ignore me, advertisers, you have no power here.
        • ambicapter 1 hour ago
          And can be used to cross-correlate with other datasets to further narrow down who you are and how you can be targetted.
          • NichoPaolucci 17 minutes ago
            I love that a poor, stupid man like me is being targeted by teams of the smartest data analytics professionals on the planet.

            Makes me think of DraftKings. You take your average 20 something sports fan - drinking beer, watching the game. And, on the other end of that smartphone display exist some of the most complex algorithms ever designed by teams of mathematics / statistics PhDs and it's deliberately built around targeting... this one guy from Florida who is pretty sure his team will be up by 7 at halftime.

            Maybe it's more of a morbid joke, but it makes me laugh to think about.

            • BLKNSLVR 2 minutes ago
              The way you explain it really captures how predatory the behavior is.

              It's an accurate explanation.

      • lenkite 39 minutes ago
        > but how much value even is there is the data that a spyware coffee machine could collect about your home? What is the marginal value of that data?

        Scale it up - make that millions of homes. Now there is godlike strategic value. Esp when "borrowed" by 3 letter agencies.

        • dovin 21 minutes ago
          Yeah, that seems like the kind of dataset they would like to keep in their back pockets
      • Quinner 58 minutes ago
        If it scans the network and sees a smart dishwasher, smart washer/drier, and smart lights, but no smart fridge, I imagine its worth something to a company like Samsung to start targeting that customer with ads for a smart fridge.
      • srcreigh 33 minutes ago
        It’s not so hard to get root shell on some routers via the admin panel, which usually has the same password as the wifi network or a default password. From there the device can capture dns logs.
        • jacquesm 24 minutes ago
          That would be a crime, wouldn't it?
      • eckelhesten 1 hour ago
        All data is valuable. Even something as simple as the MAC address to your iPhones WiFi or Bluetooth chip is worth something to dataprofilers.
        • dovin 28 minutes ago
          This does seem to be true in the age of throwing all data in to training the next iteration of the God Machine, but also, some data is a lot more valuable than other data and I want to know what the incentives are of people who are collecting data in our homes and what the actual data / derived data that they're after.
    • Grombobulous 20 hours ago
      I don’t dispute the purpose of the data collection, but I can’t believe this quantity of data collection is intentional.

      There’s no way Keurig is has the intention of paying the kind of costs required to collect a terabyte of data every two weeks for millions of people who own their coffee makers.

      There must be some kind of bug here. I imagine if you unplugged it and plugged it in again the data usage would settle down.

      • didgetmaster 1 hour ago
        As article says, the coffee machine didn't 'collect' or phone home a TB of data. It just saturated the local network looking for data to collect. This doesn't cost Keurig or any other IoT device company a single cent. It might have been a bug, or maybe not. Without some bad press, like this post; they have no incentive to change anything
        • MBCook 1 hour ago
          Yeah but that can’t even be useful can it? What’s that going to find that only using 500 MB of probes wouldn’t have found?

          Still seems buggy.

          • didgetmaster 1 hour ago
            Engineer: How often should our software scan the local network looking for new devices? Once a day? Once an hour?

            Manager: We might miss something. Since scanning doesn't cost us anything, better do it a thousand times a second!

            • gerdesj 40 minutes ago
              Oh let's be charitable! A parameter measured in ms is mistakenly thought be measured in s. Hilarity ensues.

              Real world example: þe Windows registry DWORD time periods seems to invite 10^-3s granularity for totally inappropriate timescales. Perhaps its considered a "best practice" by the dick heads that decide to do these things, who knows? Why bother considering how a sysadmin might actually want to use the knobs and dials and what is an appropriate value for a parameter.

              I could probably find a better example but this is recent: Smoothwall has an agent (IDEX) that you install on a Windows domain controller and one of its functions can be to harvest DHCP data and pass it onto the firewall so that it can track sessions. The upload period is a registry DWORD value.

              I fixed a "problem" by stopping IDEX trying to upload data a thousand times per second. I will also point out that switching on this functionality and the periodicity setting is only applied by editing the registry - there is no GUI for this. The dReal world example -ocs are clear that you should initially set 1000 as the period.

              For me that sort of thing comes under the heading of "you are holding it wrong", potential victim shaming and rubbish engineering.

          • Refreeze5224 1 hour ago
            I don't understand giving the benefit of the doubt to a company that is actively spying on its customers, which in some jurisdictions would be illegal.
            • MBCook 44 minutes ago
              I’m not defending the spying.

              The traffic volume just sounds like a bug to me.

        • blackoil 1 hour ago
          Than What is the meaning of "used"?
          • awesome_dude 49 minutes ago
            I mean, it wasn't clear to me without the explanation (I too thought it used 1TB of public internet data), but it's clear now that it is accurate (it literally used 1 TB of private network data)

            It might not seem to be anything (people will assume private network traffic is free) but there is a cost - it's capacity that could be used for other purposes, eg. home alarms.

        • b112 54 minutes ago
          They could be sued in small claims court.

          Here that means no lawyers, no discovery, $100 to file in plain language, and a company employee (not a company lawyer, or a contractor, or a temp employee) must attend or they default.

          $15k damages.

          Reasons it could happen? Imagine grandpa has a tech come out 4 times, because his network is super slow. EG, this thing pounding his wifi for its scans.

      • jimt1234 1 hour ago
        One thing that confuses me is, well, at this point in the data collection game, is there still value in this 'local' data? I mean, everyone is doing it, collecting the same data - hasn't that decreased the value? Obviously not, but I still wonder.
        • josephg 17 minutes ago
          > everyone is doing it

          Not in my house. What is even the point of connecting a coffee machine or a washing machine to the internet? I think my washing machine advertised that I could download new washing cycle programs in the app. Who on earth cares?

        • autoexec 1 hour ago
          If there's one thing you can be absolutely certain of it's that every scrap of the data they collect is either making companies money hand over fist or they strongly believe that it will soon. No company is going to bother collecting, storing, (hopefully securing), backing up, and analyzing all this data without a reason, and to them money and power are the only reasons that matter.

          Right now companies are somewhat limited in how much use they can get out their horde of private and personal information, but AI is changing that rapidly. As long as you don't mind a huge rate of error (and companies don't because it all becomes "good enough" at a large enough scale) it's basically perfect for the task of digging through endless amounts of information and spewing out bullet points.

      • mindslight 19 hours ago
        Probes create much more traffic locally than it takes to backhaul a summary of their results.
        • sgillen 18 hours ago
          1TB still smells like a bug
          • nomel 55 minutes ago
            My naive assumption would be it's looking for events in time, like sign of occupancy. For example, when your phone leaves the wifi network.

            But still must be a bug.

          • mindslight 6 hours ago
            I was thinking that repeated small probes add up quicker than you'd expect. But this is ~1.1MB/sec, which still seems a few orders of magnitude off.

            Now I'm left wondering what this traffic actually is - assuming probe (arp/icmp) packet size of 64 byte, that's 17kpps. I don't think an ESP32 class Internet-of-Trash chip can even do that. Even bulk transfers rather than small probes would be pushing it.

            Perhaps this thing found some fellow-traveler device streaming video on a port it happened to connected to?

            ... the linked xit says it "broadcast 1TB of data". So maybe some protocol with a much larger packet than icmp, spammed in a hard loop without any delay?

    • whycome 1 day ago
      Why is this allowed? There’s no way to consent to a coffee machine.
      • triceratops 1 hour ago
        If you buy a Keurig machine you've already signalled you're a sucker. (sorry)
        • m463 6 minutes ago
          perfect person to sell to advertisers.

          Like the people who reply to nigerian emails have already been pre-qualified by 1) ignoring the misspellings and 2) replying.

        • spandrew 1 hour ago
          This is the most Gilfoyle-coded comment of the day
        • zikduruqe 1 hour ago
          Laughs in Moccamaster.
          • Freak_NL 1 hour ago
            Tongue-in-cheek, but my Moccamaster which I bought second-hand is still doing great after 15 years. Two deep cleaning sessions in all that time and just running it with vinegar a couple of times a year seems to be all it needs.

            The device is dead simple. No advanced electronics. Nothing complex that can break. Just a coffee maker fine-tuned to near perfection.

            The only flaw it has is the handle for the pot. I've resorted to replacing the plastic handle with a fancy walnut one I made myself. I needed that because we tilt the pot sideways to fill the reservoir with water (because of the placement on the kitchen counter and the cabinets above), and that plastic handle is not designed for sideways stresses.

            • thinkingQueen 1 hour ago
              You shouldn’t fill the reservoir with the coffee pot, unless you’re really washing the pot super clean after each use. Better get a proper jug for filling the reservoir, so you’re not putting coffee residue and oils back into the clean-water system.
      • Neywiny 1 day ago
        Presumably during setup and connection to the AP it has a ToS. Doubtful they just unboxed, plugged in, and it connected to the right AP and went.
        • egorfine 10 hours ago
          > Doubtful they just unboxed, plugged in, and it connected to the right AP and went

          Why not? iirc some of the smart TVs have been shown to find open wifi networks on their own and upload data. (I'm not sure about that though. But it's plausible and undoubtedly will be implemented some day).

          • sroussey 1 hour ago
            The use WiFi networks as a form of GPS, much like smartphones on first stage of geolocation
          • gambiting 1 hour ago
            I've read this argument dozens of times on HN and on HN only - I'd love to see an example of that actually provably happening anywhere in the real world.
            • AlexandrB 54 minutes ago
              I would love to as well. It sounds like something that's plausible but potentially a minefield of liability for the manufacturer.

              I could also see some kind of partnership with ISPs to use their "public" WiFi hotspots[1]. This seems more likely since it's (probably) harder to honeypot but requires making regional deals.

              [1] https://www.highspeedinternet.com/resources/is-your-router-a...

        • criddell 2 hours ago
          Maybe they bought it used?
        • Citizen_Lame 23 hours ago
          ToS can't trump the actual law.
          • pjmorris 1 hour ago
            It is one thing to make a law, it is another to enforce a law.
          • preg_match 20 hours ago
            The actual law is typically so weak and spineless that the ToS doesn't need to trump it. Particularly when it comes to data security or privacy.
          • anigbrowl 2 hours ago
            LOL

            Legislators are cheap to purchase

          • advisedwang 18 hours ago
            Ok, but it can collect consent
      • nicbou 19 hours ago
        It's not allowed in the EU. Not without consent.
      • black6 22 hours ago
        It's implied consent when you give it access to your WiFi.

        Why you would give a coffee maker access to your WiFi is the real question,

        • pfannkuchen 21 hours ago
          So in other words, they were asking for it?
          • K0balt 19 hours ago
            Well, yeah sorta since the only reason appliances connect to the internet is to steal data. I mean, if you buy a connected x that normally would not be connected, it’s 99 percent there to do nefarious stuff for its real owners. It’s like having a pet lion. Sure, it’s horribly irresponsible that someone sold you a pet lion, but. Uuuh you bought at pet lion. What did you think it was going to do?

            Besides, did you see how he was dressed?

            • noduerme 1 hour ago
              This is funny.

              How do you feel about thermostats? Are some things worth it? I've had a "smart" one for the past five years, part of a new furnace install, that I've stubbornly refused to connect to my wifi. Of course this means if we forget to turn the heat down while no one's home, there's nothing to be done about it.

            • thatguy0900 8 hours ago
              How does this analogy go when people buy a house kitten and it turns out they have been sold a lion cub? Most people simply do not have the tech literacy to understand that what they a are buying is actually a lion, they thought they were buying a coffeemaker with some cool features. It's difficult to blame the victim when they would need to spend hours trying to understand why the thing mapping out their local network is something that they should even care about
              • EA-3167 1 hour ago
                In that context the person is a fool who shouldn’t be in charge of another life, because they’re incapable of basic prudence.

                I don’t actually think that applies to coffee makers spying on people though. People shouldn’t be expected to understand how computer networks or ad tech spying works in the same way that literally any child or idiot should know the difference between a lion cub and a house cat.

              • mindslight 7 hours ago
                In the analogy, there is no such thing as a house kitten. They are all cute and cuddly lion cubs. Society needs to develop a deep awareness of this, in spite of the ocean of fraudulent advertising to the contrary. (individual-liberty-protecting regulation like the GDPR would be nice too, alas)
                • ButlerianJihad 55 minutes ago
                  You have latched on to an important idea here.

                  Since most appliances now contain a general-purpose computer, it would be unfair to say that a device is incapable of hacking or hosting malware, because any device with the given sensors and radios and capabilities can be essentially reprogrammed at any time.

                  So, if we're looking at smart TVs with cameras and microphones and Wi-Fi and Bluetooth and all the connectors, or if we're simply looking at a an ordinary network device, they all fall under the umbrella of general purpose computer, and there is no way to trust their maker, or some equally capable programmer, not to turn them malevolent in some future update.

                  I don't view this as an issue of terms of service or of software or of your manufacturer. I view this as an existential and fundamental problem with dropping general purpose computers into your home and behind your DMZ.

                  Consumer operating systems like Windows and Apple have all kinds of countermeasures against this malicious use. But without the proper introspection and without the proper safeguards, a device that looks special purpose but is in fact general purpose is far more dangerous.

                  • mindslight 30 minutes ago
                    Getting technical - the way I see it, the problem arises from a combination of three things - sensors/access, Internet access, and source of software/authority.

                    Sensors/access is unavoidable, otherwise the device doesn't actually do anything useful. The point is it sets the scope for what the device is able to affect. When people say "set up a separate IoT VLAN" (that still has Internet access) this is basically what they're addressing - how a device can access other devices they may care about more.

                    Internet access is the catalyst that's created this whole dumpster fire - I don't care about the proprietary software on my keyboard/mouse/UPS/monitor/GPU/etc to nearly the same extent. I've got some TP-Link plugs that I control local network only. They don't get Internet access, so no updates, telemetry backhaul, etc.

                    The authority to update/configure/change that software is the crux. With proprietary software, there are no cuddly kittens period. Here we've got a case of a "legitimate" company choosing to be a bona fide attacker to increase their bottom line! The harm was exacerbated by a bug causing it to run amok, but even without the bug they are deliberately violating trust.

                    But even libre software can fall to security holes as well. Meaning you want to centralize the attack surface as much as possible, for administration's sake of keeping updated. "Internet" of things is basically the direct opposite of this - postulating many illegible fine-grained links between devices on different networks. Whereas really need more like the Home Assistant model, where peripheral devices may communicate over the network, but it's only ever over the local network. Think how ethernet is set up when used in industrial control networks (or at least how it should be set up, hehe).

                • fwip 4 hours ago
                  Instead of a deep awareness, wouldn't it be easier to simply ban selling lions?
                  • mindslight 4 hours ago
                    I think the two go hand in hand, unfortunately.
    • AnimalMuppet 1 day ago
      To me, this is begging for a class-action lawsuit.

      Yeah, sure, the terms of service probably say that they can do that. That's still in "unconscionable" territory. And courts do not like unconscionable contracts. If it's unconscionable, it's invalid (if I understand the law correctly).

      Is this why everybody wants to make appliances with wireless?

      • criddell 2 hours ago
        You would have to show the judge how you have been harmed and the judge will want to know what the damages are.
      • altairprime 1 day ago
        Yes, this is why everybody wants to make vehicles and refrigerators and thermostats and ereaders with cellular and/or wireless: subscription revenue from bulk data purchasers of what their scans reveal. IIRC Amazon was an industry leader in this space by showing book authors what page you stopped reading on, and then bulk assessing that data at scale to estimate which sentence or word; of course, Google’s Android remains the most successful at-scale deployment of data collection for advertisers worldwide. See also, for recent context, the top comment (and others) of the LG Smart TV problem (30 days ago, 1012 comments) https://news.ycombinator.com/item?id=49592375
      • kotaKat 23 hours ago
        Funny thing, that. Go into an electronics store now and pay attention to the TV boxes and the printer boxes. The amount of crazy fine print on both of them now is absurd. The printer boxes all now have lots of fine print about the various ink protection and DRM schemes and subscription services, the TV boxes have everything ranging from binding arbitration on the box (LG) to "(brand) accounts are REQUIRED to use this TV" (Visio).

        Customers are gonna get lost in the sauce and skip right past all of that and toss the packaging.

        • seb1204 1 hour ago
          Enshittyfication of everything
      • jerf 1 hour ago
        "Is this why everybody wants to make appliances with wireless?"

        Which raises in my mind the obvious defense, which is that if you try to put four or five of these devices on your network they'll be too busy interfering with each other for them to actually spy on anything.

        Let the wiretaps wiretap the wiretaps. Keeps 'em busy, makes 'em feel like they're doing something important.

            > What is my purpose?
        
            You wiretap the wiretaps wiretapping our wiretaps.
        
            > Oh my god.
    • KellyCriterion 12 hours ago
      Reg 2:

      But why do they need to collect 1 TB? Sounds like a lot of redundant/doublicated entries then for a small network?

    • rasz 22 hours ago
      > as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.

      its LGs glass in LG household, and now Keurigs kitchen

    • lazide 1 day ago
      #1 - why? #2 - oh, because fucking yikes.
  • jakub_g 10 minutes ago
    The real question is: could someone explain me why anyone would want a smart coffee maker?

    What kind of functions it has that can't be replaced by:

    - walking a few meters and pushing a physical button

    - waiting a whopping minute for coffee to brew, instead of triggering it remotely

    • smallnix 7 minutes ago
      Maybe they want to save their extraction & profile curves per recipe in the cloud or something. Or for less advanced devices, simply notifications to change the filter I guess.
    • simlevesque 7 minutes ago
      The problem is that when I want to make coffee, I'm my most stupid self I'll be all day.
  • sam-cop-vimes 1 hour ago
    This website values your privacy. Only shares data with 1747 partners.
  • altern8 1 hour ago
    Can someone explain to me what kind of data it collects, and what value could that data have to advertisers or anyone else?
    • rwz 15 minutes ago
      It collects the data about your home appliances and personal devices. This data can tell a lot about your income level and spending habits. This is extremely useful for advertisers for obvious reasons.
      • altern8 11 minutes ago
        I see, like how many cell phones are in the household and what brand
        • rwz 7 minutes ago
          Right, or laptops. Or TVs. Or other IOT devices like coffee makers, dishwashers, washers, garage openers, smart locks, vacuums etc.
  • matthewmcg 1 hour ago
    Wow, maybe this is the push I need to finally set up an isolated "IOT" VLAN at my home.
  • ttytty 23 hours ago
    It's so important to have a dedicated VLAN (or 2.4g SSID) for IoT devices and block access to your regular VLAN/SSID or enforce some more granular rules on what devices can communicate with each other.

    Most non-ancient routers/gateways support this. There are way too many IoT devices running code that's _worse_ than what older LLMs produce.

    • Levitating 1 hour ago
      This is good advice but a simpler solution is to just not buy these things? Coffee machines don't need internet. Your thermostat doesn't either.
      • stronglikedan 54 minutes ago
        > Coffee machines don't need internet. Your thermostat doesn't either. reply

        Yours may not, but that's just your personal preference. A lot of folks enjoy these products. An argument could be made that no one needs a coffee machine or thermostat to begin with.

        • askvictor 39 minutes ago
          I can definitely see the case for an internet connected thermostat. A coffee machine, much less so.
    • randerson 58 minutes ago
      It's not enough to simply have a IoT VLAN that you put all your IoT devices on. Because those devices can see one another. In this case, if the coffee machine can see what type of smart fridge and smart toaster you're using, they can sell that data.

      I default to adding IoT devices to a 2.4g "Guest" network where they can't see each other. Exceptions are IoT devices that need to see their friends to do what I bought them for, or devices I want to integrate with HomeAssistant. In those cases I create a separate IoT device per IoT brand. Excessive but necessary.

    • pjmorris 1 hour ago
      My Bialetti Moka pot doesn't attempt to acquire an IP address.
      • ErroneousBosh 33 minutes ago
        I'm in Rome right now.

        There's a Bialetti shop on the road between the flat I'm staying in, and the Metro station.

        If I'm not careful this is going to seriously damage my wealth.

        • jjgreen 19 minutes ago
          They're not expensive and last a lifetime, get one.
    • mindslight 5 hours ago
      Of course by VLAN, I presume you mean one that doesn't have access to the Internet.

      FWIW preventing the harm that happened here would seem to require a second set of APs (radios) on a different channel.

    • pseudohadamard 8 hours ago
      I have a firewall that tells me how much data each device is uploading and downloading. One particular device pulled down 6GB a week and uploaded 1.5GB doing absolutely nothing. I mean literally nothing, I use the local API to communicate with it. Blocking the one domain it was doing this to dropped traffic to essentially zero with no loss in functionality.
  • j45 8 minutes ago
    A great reason to limit “Smarthome” devices to a dedicated guest or iot wifi network.
  • PinkaDunka 1 hour ago
    This website generated 1tb of bandwidth while serving me 1kb of text
  • landgenoot 17 hours ago
    Never assume malicious intent when incompetence.

    I have multiple devices that queries their update server every 15 seconds, which all shows up as the top 10 queried domain in my network.

    • Telaneo 1 hour ago
      It's in Kerig's interest to be evil in this case. There's money to be made in malice. There's good reason to assume this isn't incompetence.
      • rwz 13 minutes ago
        I'm sure they could've collected the same data they're collecting with 0.1% of the traffic. This particular case seems to be greed AND incompetence.
      • foobarian 29 minutes ago
        It could be incompetent malice.
    • kps 1 hour ago
      Sufficiently advanced incompetence is indistinguishable from malice.
    • GuB-42 1 hour ago
      There is no way it is not incompetence.

      Considering the computing power of these kinds of devices, it is most likely stuck inside an infinite loop sending garbage at full speed, there is not enough power to process that much volume in any maliciously useful way.

    • mjburgess 1 hour ago
  • jttnr 1 hour ago
    Maybe the coffee machine is subsidized by a residential botnet?
  • lifeisstillgood 2 hours ago
    Holy moly - 1,747 “partners” to share my data with. I mean, how can you even find 1747 data brokers? Where do you get that list. What does the JavaScript look like - I mean … this is getting ridiculous.

    But at least the EU did me a solid. I really wanted to read that but I think 2000 data scumbags is not worth the effort.

    All I need know is to realise bottlecaps must be recycled and federalism is good. Repeat in the mirror each morning

  • jason_s 16 hours ago
    `C0FFEEEEEEEEEEEEEEEEEEEEE...`
    • a96 9 hours ago
      418 I'm a teapot
  • ButlerianJihad 1 day ago
    A year or two ago, I was using NextDNS in ad-blocking and logging mode, which very helpfully exposed malware sitting on my very router, which had been completely undetectable, except for the veritable flood of bizarre DNS queries it was routinely sending to the self-configured DNS servers.

    Now that I have a new router and I've re-enabled NextDNS, I've ironically discovered that the chief abuser of DNS right now is the router's own legit security software, which is absolutely hammering on the same query, several times a second.

    Of course, since I am currently on NextDNS free tier, this matters a lot, because they cut you off after about 300,000 queries in a month. So any hammering abuse will make me lose my privileges much earlier than I would otherwise. So, to stop the abuse, should I shut off my legit security software? It is absolutely rubbish at identifying malware on the device itself...

  • ck2 1 day ago
    it took me a month to notice my Midea A/C was absolutely hammering my router

    I didn't even know it had wifi capability but it was trying to connect

    I use mac whitelist so it wasn't even getting in but that didn't stop it from trying every seond

    Fortunately it was just a usb dongle so yanked it out

    • altairprime 1 day ago
      Most Midea units can be swapped for an ESPhome USB dongle if you ever wish to have remote control on your own terms — note various countries’ shop links, and the various wiki and other outlines for DIY etc: https://smlight.tech/product/slwf-01
    • HankB99 1 day ago
      Ooo. I have a Midea dehumidifier. When it powers up it displays the WiFi symbol. I wonder if it is hammering away at my access point. Might it be better to bring it on line and then just block all traffic?

      And I wonder how I would even tell if it was trying to associate with my WiFi.

      • pseudohadamard 8 hours ago
        I have a Midea dehumidifier too. It moves around 200kB/hour which seems to be cloud polling about once a minute, so no big deal traffic-wise.
    • ars 1 day ago
      I have two of them, and I just checked and both are quiet. Mine don't connect to WiFi unless you go through an entire process first with an android phone and Matter.

      It's great having them on WiFi - you can turn on the AC before getting home to pre-cool, without having to leave it on all day.

      • sillyfluke 1 day ago
        Boy: So, how it get this bad grandpa?

        Man: Well, before you couldn't turn on the AC before you got home

        • ars 1 day ago
          Realistically people would just leave their AC on. So this saves energy, rather than changing comfort.
          • seb1204 1 hour ago
            Really? And then complain about the energy cost? People are nutz. Like it's so unbearable to come home, open windows to get peak hot air out, then turn on AC and get cool. Energy is too cheap it seems. Also even very old AC remotes show there is usually the option to set up times etc.
          • Cpoll 1 day ago
            Realistically ACs have timers, so you're really only optimizing for days where you go off-schedule.
          • sillyfluke 23 hours ago
            I have a friend who diy'ed a button on single webpage that he presses on his phone while at work in order to open the gate to the building that he lives so delivery people can get in. I also think Bret Victor diy'ed the AC as mentioned while he was a student quarter century or more ago[0]

            I know this sounds like the famous "just do it this way in linux instead" criticism of Dropbox back in the day. But I do think we reached "life parodies fiction" with these smart devices where it makes sense to give diy another go. And with AI, there's less excuses this time around I would imagine.

            But I would literally rather buy a cheap phone, a cheap SIM, hotspot it and connect it to a charger and have the AC connect to that and isolate it that way instead of letting it touch the network.

            [0] https://worrydream.com/Electronics/

            • ttytty 22 hours ago
              You can (and should) just segregate your network to have separate paths for IoT/"smart devices" and normal personal/family devices. Makes it all worry free and transparently observable.

              I have my IoT on a separate VLAN and I can observe communications for any given device at any given time.. this seems like a much saner solution than outright not buying any IoT devices, though that is also a respectable decision!

  • tamimio 1 day ago
    Reminds me when couple years ago I plugged the TV to the internet (so my relatives kids can watch YT) and I forgot to unplug it for almost a week after, only to find the router dns resolved (and blocked) a million queries, all from that one TV!
    • bombcar 21 hours ago
      I love when it keeps checking some random DNS address, because who knows, with a TTL of 64000 it may just have changed in the last seven milliseconds!
    • altairprime 1 day ago
      The traffic generated here is network scans, not external traffic, and so blocking DNS wouldn’t have helped.
  • matteoraso 1 day ago
    I honestly hate the IoT so much. Why should a coffee machine of all things use data? Just make the coffee.
    • anigbrowl 2 hours ago
      I love IoT. It's the greedy corporations I hate. Everyone who implements this kinda abusive stuff, from the CEO down to the people building and installing the firmware, are scum.
      • skupig 9 minutes ago
        Technology could be so much more useful and fun if we just fully banned the collection and sale of personal data. We've been dreaming of smart homes for, like, 80 years, but advertising ruined it just like it ruins everything. Imagine how cool it would be to able to connect devices to the internet for purely functional purposes without them spying on you!
      • autoexec 1 hour ago
        This is all technology. Everything is being infested with spying and tracking.
        • Levitating 1 hour ago
          No, just pick your technology better. My LineageOS phone and framework laptop do nothing of the sort.
      • robotnikman 1 hour ago
        The shareholders as well.
      • goatlover 1 hour ago
        What is the need for a coffeemaker on the internet?
        • scrlk 1 hour ago
          A coffee maker was the subject of the world's first webcam: https://en.wikipedia.org/wiki/Trojan_Room_coffee_pot :^)
          • linker3000 9 minutes ago
            Yeah, but the people running the Webcam probably didn't make notes about the watch / rings / shirt / dress / shoes worn by the people using the coffee maker, nor take down whether they were wearing glasses and if they added milk - and sell this information to the local jewelers, clothes shop, shoe shop, opticians and dairy.

            Probably.

  • realaaa 50 minutes ago
    ahahahah that's gold !

    IoT network yep, needed yesterday

  • bitwize 2 hours ago
    As another sign of the enshittified world we live in, the thing probably wasn't even RFC 2324 compliant.

    https://datatracker.ietf.org/doc/html/rfc2324

    Bruh should have set his PiHole to return HTTP 418 in response to any outbound request this thing made.

  • ButlerianJihad 18 hours ago
    Last year I had a big dispute with my ISP that was refusing to support or provide proper WiFi on their router, even while they touted a trademarked brand-name to do it. I ended up turning their router into Bridge Mode and purchasing a real router that could do WiFi. I did this extremely reluctantly, because every other personally-owned router had contracted malware.

    After installing the new router (Netgear) my HP LaserJet began printing error pages. Like, I had done nothing to send anything to it, but a blank error page or three would pop out of it at very random times.

    It took awhile to narrow down and diagnose this. But it turned out that the Netgear system had a very... proactive network malware detection system. It was red-team scanning my LAN for "vulnerabilities" or exploits or the presence of malware (I think just known vulns). It was a known side-effect of these scans, where it would tickle an RTSP TCP port of some kind and the HP printer would respond with its error printout.

    I was so livid that the router was scanning the LAN, basically unbidden and completely undocumented. Even worse, they were not sharing the logs or results of that scan with the consumer. No, they were being sent back to the Netgear mothership, and their cybersecurity vendor overlords. So the scans were not designed to benefit me; they were simply designed to spy on everyone from a privileged vantage point. Now I ask you, why is a piece of kit that is supposed to be "yours" compiling secrets about your network, hiding them from you, and turning them over to, I guess a big database for hackers to leak in due time? This is not a question of "well, devices hooked up to a network should not be vulnerable" if the devices were contained in a private network, and 100% inaccessible from outside, and only attackers inside my perimeter could do these exploits in the first place.

    Thankfully I found a way to disable this. Their "security" shitware is still spamming DNS and I may be forced to disable that as well. Meanwhile, routers 100% cannot self-introspect or self-diagnose and find their own malware. I've said it once; I'll say it again: consumer routers are the Achilles Heel to your network. They are ideal points of compromise for any actor to gain a foothold and pivot, or simply gain persistence undetected. Your ISP doesn't care, and your vendors don't care. Perhaps you should.

    • freecodeio 39 minutes ago
      If my printer printed random shit I would just get paranoid and wipe every piece of tech clean. But good on you for discovering why though.
    • AngryData 14 hours ago
      Wow that seems bonkers to me. Basically scanning and cataloging known vulnerabilities on the sly, and when anyone notices they pretend it is for your benefit somehow.

      It would be like finding out ring cameras are taking pictures of your keys and calculating the pin set to producing duplicates and sending that pin set data off somewhere and when caught them being like "Uh, we are uhhh... doing it to make sure your key isn't too worn down or to detect if someone made a crude hand filed key. Yeah that's it!"

  • rendall 1 day ago
    The GDPR consent form on this blog did not have a “Reject all” button. It required me to manually reject 16 instances of “legitimate interest,” then scroll through 1,746 vendors to make sure they were all set to reject.

    Seems worth mentioning in a post about excessive and intrusive collection of user data. The moral outrage rings hollow when opting out of tracking is so deliberately onerous.

    • wafflemaker 1 day ago
      And also illegal. It's illegal not to have one button. Companies didn't do it because they suddenly stopped being scum.
  • Gauchy101 51 minutes ago
    [flagged]
  • 3seashells 41 minutes ago
    [dead]