Do you remember how a series of crazy coincidences and freak accidents kept preventing the LHC from being turned on? What if the LHC was causing world-ending or life-ending events, and we simply kept surviving only in thinner and thinner slices of amplitude (timelines) where those freak accidents happened, but where also more improbable world conditions took place?
No one cares. There’s little serious pushback to privacy invasions by big tech. Flock cameras have been a rare exception. Half the people “have nothing to hide” and half aren’t willing to give up the convenience that the popular app or gadget gives them.
That's obviously bad and I hate it, but how much value even is there is the data that a spyware coffee machine could collect about your home? What advertisers would buy such data and what would they advertise to me? What is the marginal value of that data?
You can also map a home out depending on signal strength. That gives you approximate size of home which gives you approximate income.
It can also correlate it with geolocation data. Google, for eg, sniffs all broadcasted SSIDs with their StreetView cars. If you can pick up on a SSID (or any of the MAC addresses of the other devices), you can buy the data set that includes it which further pinpoints demographics given the neighborhood AMI.
You can also build behavioral profiles patterns based on things like, for eg, if a baby monitor model is present or a robot vacuum, if certain devices only connect at certain times, etc.
I think the general rule for adtech is that profile guesstimates just need to be around 70%+ fidelity to determine if a sale can be made.
Lastly, you can also just sell the data on the gray market. The more datapoints, the higher the price. Most consumer product companies do that since we have little-to-no data privacy laws and the people who seem the most aware of it also are generally very apathetic and disinterested in advocating for them.
Knowing what TV you own, what phone models are used in your house, and what other devices you own tells advertisers about your spending patterns and income.
If it scans the network and sees a smart dishwasher, smart washer/drier, and smart lights, but no smart fridge, I imagine its worth something to a company like Samsung to start targeting that customer with ads for a smart fridge.
It’s not so hard to get root shell on some routers via the admin panel, which usually has the same password as the wifi network or a default password. From there the device can capture dns logs.
I don’t dispute the purpose of the data collection, but I can’t believe this quantity of data collection is intentional.
There’s no way Keurig is has the intention of paying the kind of costs required to collect a terabyte of data every two weeks for millions of people who own their coffee makers.
There must be some kind of bug here. I imagine if you unplugged it and plugged it in again the data usage would settle down.
As article says, the coffee machine didn't 'collect' or phone home a TB of data. It just saturated the local network looking for data to collect. This doesn't cost Keurig or any other IoT device company a single cent. It might have been a bug, or maybe not. Without some bad press, like this post; they have no incentive to change anything
One thing that confuses me is, well, at this point in the data collection game, is there still value in this 'local' data? I mean, everyone is doing it, collecting the same data - hasn't that decreased the value? Obviously not, but I still wonder.
To me, this is begging for a class-action lawsuit.
Yeah, sure, the terms of service probably say that they can do that. That's still in "unconscionable" territory. And courts do not like unconscionable contracts. If it's unconscionable, it's invalid (if I understand the law correctly).
Is this why everybody wants to make appliances with wireless?
Yes, this is why everybody wants to make vehicles and refrigerators and thermostats and ereaders with cellular and/or wireless: subscription revenue from bulk data purchasers of what their scans reveal. IIRC Amazon was an industry leader in this space by showing book authors what page you stopped reading on, and then bulk assessing that data at scale to estimate which sentence or word; of course, Google’s Android remains the most successful at-scale deployment of data collection for advertisers worldwide. See also, for recent context, the top comment (and others) of the LG Smart TV problem (30 days ago, 1012 comments) https://news.ycombinator.com/item?id=49592375
Funny thing, that. Go into an electronics store now and pay attention to the TV boxes and the printer boxes. The amount of crazy fine print on both of them now is absurd. The printer boxes all now have lots of fine print about the various ink protection and DRM schemes and subscription services, the TV boxes have everything ranging from binding arbitration on the box (LG) to "(brand) accounts are REQUIRED to use this TV" (Visio).
Customers are gonna get lost in the sauce and skip right past all of that and toss the packaging.
"Is this why everybody wants to make appliances with wireless?"
Which raises in my mind the obvious defense, which is that if you try to put four or five of these devices on your network they'll be too busy interfering with each other for them to actually spy on anything.
Let the wiretaps wiretap the wiretaps. Keeps 'em busy, makes 'em feel like they're doing something important.
> What is my purpose?
You wiretap the wiretaps wiretapping our wiretaps.
> Oh my god.
Maybe they want to save their extraction & profile curves per recipe in the cloud or something. Or for less advanced devices, simply notifications to change the filter I guess.
It collects the data about your home appliances and personal devices. This data can tell a lot about your income level and spending habits. This is extremely useful for advertisers for obvious reasons.
It's so important to have a dedicated VLAN (or 2.4g SSID) for IoT devices and block access to your regular VLAN/SSID or enforce some more granular rules on what devices can communicate with each other.
Most non-ancient routers/gateways support this. There are way too many IoT devices running code that's _worse_ than what older LLMs produce.
I agree on the coffee machine. On the thermostat, not so much. We keep pretty irregular hours so being able to control the thermostat remotely, so the house isn’t being heated unnecessarily but is warm on our return, is useful.
> Coffee machines don't need internet. Your thermostat doesn't either.
reply
Yours may not, but that's just your personal preference. A lot of folks enjoy these products. An argument could be made that no one needs a coffee machine or thermostat to begin with.
It's not enough to simply have a IoT VLAN that you put all your IoT devices on. Because those devices can see one another. In this case, if the coffee machine can see what type of smart fridge and smart toaster you're using, they can sell that data.
I default to adding IoT devices to a 2.4g "Guest" network where they can't see each other. Exceptions are IoT devices that need to see their friends to do what I bought them for, or devices I want to integrate with HomeAssistant. In those cases I create a separate IoT device per IoT brand. Excessive but necessary.
I have a firewall that tells me how much data each device is uploading and downloading. One particular device pulled down 6GB a week and uploaded 1.5GB doing absolutely nothing. I mean literally nothing, I use the local API to communicate with it. Blocking the one domain it was doing this to dropped traffic to essentially zero with no loss in functionality.
Considering the computing power of these kinds of devices, it is most likely stuck inside an infinite loop sending garbage at full speed, there is not enough power to process that much volume in any maliciously useful way.
Holy moly - 1,747 “partners” to share my data with. I mean, how can you even find 1747 data brokers? Where do you get that list. What does the JavaScript look like - I mean … this is getting ridiculous.
But at least the EU did me a solid. I really wanted to read that but I think 2000 data scumbags is not worth the effort.
All I need know is to realise bottlecaps must be recycled and federalism is good. Repeat in the mirror each morning
A year or two ago, I was using NextDNS in ad-blocking and logging mode, which very helpfully exposed malware sitting on my very router, which had been completely undetectable, except for the veritable flood of bizarre DNS queries it was routinely sending to the self-configured DNS servers.
Now that I have a new router and I've re-enabled NextDNS, I've ironically discovered that the chief abuser of DNS right now is the router's own legit security software, which is absolutely hammering on the same query, several times a second.
Of course, since I am currently on NextDNS free tier, this matters a lot, because they cut you off after about 300,000 queries in a month. So any hammering abuse will make me lose my privileges much earlier than I would otherwise. So, to stop the abuse, should I shut off my legit security software? It is absolutely rubbish at identifying malware on the device itself...
Most Midea units can be swapped for an ESPhome USB dongle if you ever wish to have remote control on your own terms — note various countries’ shop links, and the various wiki and other outlines for DIY etc: https://smlight.tech/product/slwf-01
Ooo. I have a Midea dehumidifier. When it powers up it displays the WiFi symbol. I wonder if it is hammering away at my access point. Might it be better to bring it on line and then just block all traffic?
And I wonder how I would even tell if it was trying to associate with my WiFi.
I have two of them, and I just checked and both are quiet. Mine don't connect to WiFi unless you go through an entire process first with an android phone and Matter.
It's great having them on WiFi - you can turn on the AC before getting home to pre-cool, without having to leave it on all day.
Reminds me when couple years ago I plugged the TV to the internet (so my relatives kids can watch YT) and I forgot to unplug it for almost a week after, only to find the router dns resolved (and blocked) a million queries, all from that one TV!
I love IoT. It's the greedy corporations I hate. Everyone who implements this kinda abusive stuff, from the CEO down to the people building and installing the firmware, are scum.
Technology could be so much more useful and fun if we just fully banned the collection and sale of personal data. We've been dreaming of smart homes for, like, 80 years, but advertising ruined it just like it ruins everything. Imagine how cool it would be to able to connect devices to the internet for purely functional purposes without them spying on you!
Last year I had a big dispute with my ISP that was refusing to support or provide proper WiFi on their router, even while they touted a trademarked brand-name to do it. I ended up turning their router into Bridge Mode and purchasing a real router that could do WiFi. I did this extremely reluctantly, because every other personally-owned router had contracted malware.
After installing the new router (Netgear) my HP LaserJet began printing error pages. Like, I had done nothing to send anything to it, but a blank error page or three would pop out of it at very random times.
It took awhile to narrow down and diagnose this. But it turned out that the Netgear system had a very... proactive network malware detection system. It was red-team scanning my LAN for "vulnerabilities" or exploits or the presence of malware (I think just known vulns). It was a known side-effect of these scans, where it would tickle an RTSP TCP port of some kind and the HP printer would respond with its error printout.
I was so livid that the router was scanning the LAN, basically unbidden and completely undocumented. Even worse, they were not sharing the logs or results of that scan with the consumer. No, they were being sent back to the Netgear mothership, and their cybersecurity vendor overlords. So the scans were not designed to benefit me; they were simply designed to spy on everyone from a privileged vantage point. Now I ask you, why is a piece of kit that is supposed to be "yours" compiling secrets about your network, hiding them from you, and turning them over to, I guess a big database for hackers to leak in due time? This is not a question of "well, devices hooked up to a network should not be vulnerable" if the devices were contained in a private network, and 100% inaccessible from outside, and only attackers inside my perimeter could do these exploits in the first place.
Thankfully I found a way to disable this. Their "security" shitware is still spamming DNS and I may be forced to disable that as well. Meanwhile, routers 100% cannot self-introspect or self-diagnose and find their own malware. I've said it once; I'll say it again: consumer routers are the Achilles Heel to your network. They are ideal points of compromise for any actor to gain a foothold and pivot, or simply gain persistence undetected. Your ISP doesn't care, and your vendors don't care. Perhaps you should.
Wow that seems bonkers to me. Basically scanning and cataloging known vulnerabilities on the sly, and when anyone notices they pretend it is for your benefit somehow.
It would be like finding out ring cameras are taking pictures of your keys and calculating the pin set to producing duplicates and sending that pin set data off somewhere and when caught them being like "Uh, we are uhhh... doing it to make sure your key isn't too worn down or to detect if someone made a crude hand filed key. Yeah that's it!"
The GDPR consent form on this blog did not have a “Reject all” button. It required me to manually reject 16 instances of “legitimate interest,” then scroll through 1,746 vendors to make sure they were all set to reject.
Seems worth mentioning in a post about excessive and intrusive collection of user data. The moral outrage rings hollow when opting out of tracking is so deliberately onerous.
In the Twitter thread linked, the person confirms two things:
1. It saturated the local network with 1TB of metadata sniffing scans, not the network uplink to the outside world.
2. It does so because, as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.
> as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.
WTF!! When did we land in the middle of a Black Mirror episode?
I'm half convinced the first run of the LHC split the timeline and we've landed in the evil one.
There is a singular patent owned by Sony that stands between you and being required to physically acknowledge ads on your TV: https://patents.google.com/patent/US8246454B2/en
Do you remember how a series of crazy coincidences and freak accidents kept preventing the LHC from being turned on? What if the LHC was causing world-ending or life-ending events, and we simply kept surviving only in thinner and thinner slices of amplitude (timelines) where those freak accidents happened, but where also more improbable world conditions took place?
No one cares. There’s little serious pushback to privacy invasions by big tech. Flock cameras have been a rare exception. Half the people “have nothing to hide” and half aren’t willing to give up the convenience that the popular app or gadget gives them.
Unauthorized Bread
That's obviously bad and I hate it, but how much value even is there is the data that a spyware coffee machine could collect about your home? What advertisers would buy such data and what would they advertise to me? What is the marginal value of that data?
You can also map a home out depending on signal strength. That gives you approximate size of home which gives you approximate income.
It can also correlate it with geolocation data. Google, for eg, sniffs all broadcasted SSIDs with their StreetView cars. If you can pick up on a SSID (or any of the MAC addresses of the other devices), you can buy the data set that includes it which further pinpoints demographics given the neighborhood AMI.
You can also build behavioral profiles patterns based on things like, for eg, if a baby monitor model is present or a robot vacuum, if certain devices only connect at certain times, etc.
I think the general rule for adtech is that profile guesstimates just need to be around 70%+ fidelity to determine if a sale can be made.
Lastly, you can also just sell the data on the gray market. The more datapoints, the higher the price. Most consumer product companies do that since we have little-to-no data privacy laws and the people who seem the most aware of it also are generally very apathetic and disinterested in advocating for them.
2 replies →
Knowing what TV you own, what phone models are used in your house, and what other devices you own tells advertisers about your spending patterns and income.
6 replies →
> but how much value even is there is the data that a spyware coffee machine could collect about your home? What is the marginal value of that data?
Scale it up - make that millions of homes. Now there is godlike strategic value. Esp when "borrowed" by 3 letter agencies.
1 reply →
If it scans the network and sees a smart dishwasher, smart washer/drier, and smart lights, but no smart fridge, I imagine its worth something to a company like Samsung to start targeting that customer with ads for a smart fridge.
It’s not so hard to get root shell on some routers via the admin panel, which usually has the same password as the wifi network or a default password. From there the device can capture dns logs.
1 reply →
All data is valuable. Even something as simple as the MAC address to your iPhones WiFi or Bluetooth chip is worth something to dataprofilers.
1 reply →
I don’t dispute the purpose of the data collection, but I can’t believe this quantity of data collection is intentional.
There’s no way Keurig is has the intention of paying the kind of costs required to collect a terabyte of data every two weeks for millions of people who own their coffee makers.
There must be some kind of bug here. I imagine if you unplugged it and plugged it in again the data usage would settle down.
As article says, the coffee machine didn't 'collect' or phone home a TB of data. It just saturated the local network looking for data to collect. This doesn't cost Keurig or any other IoT device company a single cent. It might have been a bug, or maybe not. Without some bad press, like this post; they have no incentive to change anything
9 replies →
One thing that confuses me is, well, at this point in the data collection game, is there still value in this 'local' data? I mean, everyone is doing it, collecting the same data - hasn't that decreased the value? Obviously not, but I still wonder.
2 replies →
Probes create much more traffic locally than it takes to backhaul a summary of their results.
3 replies →
Why is this allowed? There’s no way to consent to a coffee machine.
If you buy a Keurig machine you've already signalled you're a sucker. (sorry)
6 replies →
Presumably during setup and connection to the AP it has a ToS. Doubtful they just unboxed, plugged in, and it connected to the right AP and went.
10 replies →
It's not allowed in the EU. Not without consent.
1 reply →
It's implied consent when you give it access to your WiFi.
Why you would give a coffee maker access to your WiFi is the real question,
10 replies →
To me, this is begging for a class-action lawsuit.
Yeah, sure, the terms of service probably say that they can do that. That's still in "unconscionable" territory. And courts do not like unconscionable contracts. If it's unconscionable, it's invalid (if I understand the law correctly).
Is this why everybody wants to make appliances with wireless?
You would have to show the judge how you have been harmed and the judge will want to know what the damages are.
Yes, this is why everybody wants to make vehicles and refrigerators and thermostats and ereaders with cellular and/or wireless: subscription revenue from bulk data purchasers of what their scans reveal. IIRC Amazon was an industry leader in this space by showing book authors what page you stopped reading on, and then bulk assessing that data at scale to estimate which sentence or word; of course, Google’s Android remains the most successful at-scale deployment of data collection for advertisers worldwide. See also, for recent context, the top comment (and others) of the LG Smart TV problem (30 days ago, 1012 comments) https://news.ycombinator.com/item?id=49592375
Funny thing, that. Go into an electronics store now and pay attention to the TV boxes and the printer boxes. The amount of crazy fine print on both of them now is absurd. The printer boxes all now have lots of fine print about the various ink protection and DRM schemes and subscription services, the TV boxes have everything ranging from binding arbitration on the box (LG) to "(brand) accounts are REQUIRED to use this TV" (Visio).
Customers are gonna get lost in the sauce and skip right past all of that and toss the packaging.
1 reply →
"Is this why everybody wants to make appliances with wireless?"
Which raises in my mind the obvious defense, which is that if you try to put four or five of these devices on your network they'll be too busy interfering with each other for them to actually spy on anything.
Let the wiretaps wiretap the wiretaps. Keeps 'em busy, makes 'em feel like they're doing something important.
Reg 2:
But why do they need to collect 1 TB? Sounds like a lot of redundant/doublicated entries then for a small network?
> as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.
its LGs glass in LG household, and now Keurigs kitchen
#1 - why? #2 - oh, because fucking yikes.
The real question is: could someone explain me why anyone would want a smart coffee maker?
What kind of functions it has that can't be replaced by:
- walking a few meters and pushing a physical button
- waiting a whopping minute for coffee to brew, instead of triggering it remotely
Maybe they want to save their extraction & profile curves per recipe in the cloud or something. Or for less advanced devices, simply notifications to change the filter I guess.
The problem is that when I want to make coffee, I'm my most stupid self I'll be all day.
This website values your privacy. Only shares data with 1747 partners.
Can someone explain to me what kind of data it collects, and what value could that data have to advertisers or anyone else?
It collects the data about your home appliances and personal devices. This data can tell a lot about your income level and spending habits. This is extremely useful for advertisers for obvious reasons.
I see, like how many cell phones are in the household and what brand
1 reply →
Wow, maybe this is the push I need to finally set up an isolated "IOT" VLAN at my home.
It's so important to have a dedicated VLAN (or 2.4g SSID) for IoT devices and block access to your regular VLAN/SSID or enforce some more granular rules on what devices can communicate with each other.
Most non-ancient routers/gateways support this. There are way too many IoT devices running code that's _worse_ than what older LLMs produce.
This is good advice but a simpler solution is to just not buy these things? Coffee machines don't need internet. Your thermostat doesn't either.
I agree on the coffee machine. On the thermostat, not so much. We keep pretty irregular hours so being able to control the thermostat remotely, so the house isn’t being heated unnecessarily but is warm on our return, is useful.
> Coffee machines don't need internet. Your thermostat doesn't either. reply
Yours may not, but that's just your personal preference. A lot of folks enjoy these products. An argument could be made that no one needs a coffee machine or thermostat to begin with.
2 replies →
My Bialetti Moka pot doesn't attempt to acquire an IP address.
I'm in Rome right now.
There's a Bialetti shop on the road between the flat I'm staying in, and the Metro station.
If I'm not careful this is going to seriously damage my wealth.
1 reply →
It's not enough to simply have a IoT VLAN that you put all your IoT devices on. Because those devices can see one another. In this case, if the coffee machine can see what type of smart fridge and smart toaster you're using, they can sell that data.
I default to adding IoT devices to a 2.4g "Guest" network where they can't see each other. Exceptions are IoT devices that need to see their friends to do what I bought them for, or devices I want to integrate with HomeAssistant. In those cases I create a separate IoT device per IoT brand. Excessive but necessary.
Of course by VLAN, I presume you mean one that doesn't have access to the Internet.
FWIW preventing the harm that happened here would seem to require a second set of APs (radios) on a different channel.
I have a firewall that tells me how much data each device is uploading and downloading. One particular device pulled down 6GB a week and uploaded 1.5GB doing absolutely nothing. I mean literally nothing, I use the local API to communicate with it. Blocking the one domain it was doing this to dropped traffic to essentially zero with no loss in functionality.
This website generated 1tb of bandwidth while serving me 1kb of text
Never assume malicious intent when incompetence.
I have multiple devices that queries their update server every 15 seconds, which all shows up as the top 10 queried domain in my network.
It's in Kerig's interest to be evil in this case. There's money to be made in malice. There's good reason to assume this isn't incompetence.
I'm sure they could've collected the same data they're collecting with 0.1% of the traffic. This particular case seems to be greed AND incompetence.
It could be incompetent malice.
Sufficiently advanced incompetence is indistinguishable from malice.
There is no way it is not incompetence.
Considering the computing power of these kinds of devices, it is most likely stuck inside an infinite loop sending garbage at full speed, there is not enough power to process that much volume in any maliciously useful way.
https://en.wikipedia.org/wiki/Plausible_deniability
A great reason to limit “Smarthome” devices to a dedicated guest or iot wifi network.
Maybe the coffee machine is subsidized by a residential botnet?
Holy moly - 1,747 “partners” to share my data with. I mean, how can you even find 1747 data brokers? Where do you get that list. What does the JavaScript look like - I mean … this is getting ridiculous.
But at least the EU did me a solid. I really wanted to read that but I think 2000 data scumbags is not worth the effort.
All I need know is to realise bottlecaps must be recycled and federalism is good. Repeat in the mirror each morning
`C0FFEEEEEEEEEEEEEEEEEEEEE...`
418 I'm a teapot
A year or two ago, I was using NextDNS in ad-blocking and logging mode, which very helpfully exposed malware sitting on my very router, which had been completely undetectable, except for the veritable flood of bizarre DNS queries it was routinely sending to the self-configured DNS servers.
Now that I have a new router and I've re-enabled NextDNS, I've ironically discovered that the chief abuser of DNS right now is the router's own legit security software, which is absolutely hammering on the same query, several times a second.
Of course, since I am currently on NextDNS free tier, this matters a lot, because they cut you off after about 300,000 queries in a month. So any hammering abuse will make me lose my privileges much earlier than I would otherwise. So, to stop the abuse, should I shut off my legit security software? It is absolutely rubbish at identifying malware on the device itself...
it took me a month to notice my Midea A/C was absolutely hammering my router
I didn't even know it had wifi capability but it was trying to connect
I use mac whitelist so it wasn't even getting in but that didn't stop it from trying every seond
Fortunately it was just a usb dongle so yanked it out
Most Midea units can be swapped for an ESPhome USB dongle if you ever wish to have remote control on your own terms — note various countries’ shop links, and the various wiki and other outlines for DIY etc: https://smlight.tech/product/slwf-01
Ooo. I have a Midea dehumidifier. When it powers up it displays the WiFi symbol. I wonder if it is hammering away at my access point. Might it be better to bring it on line and then just block all traffic?
And I wonder how I would even tell if it was trying to associate with my WiFi.
I have a Midea dehumidifier too. It moves around 200kB/hour which seems to be cloud polling about once a minute, so no big deal traffic-wise.
1 reply →
I have two of them, and I just checked and both are quiet. Mine don't connect to WiFi unless you go through an entire process first with an android phone and Matter.
It's great having them on WiFi - you can turn on the AC before getting home to pre-cool, without having to leave it on all day.
Boy: So, how it get this bad grandpa?
Man: Well, before you couldn't turn on the AC before you got home
5 replies →
Reminds me when couple years ago I plugged the TV to the internet (so my relatives kids can watch YT) and I forgot to unplug it for almost a week after, only to find the router dns resolved (and blocked) a million queries, all from that one TV!
I love when it keeps checking some random DNS address, because who knows, with a TTL of 64000 it may just have changed in the last seven milliseconds!
The traffic generated here is network scans, not external traffic, and so blocking DNS wouldn’t have helped.
I honestly hate the IoT so much. Why should a coffee machine of all things use data? Just make the coffee.
I love IoT. It's the greedy corporations I hate. Everyone who implements this kinda abusive stuff, from the CEO down to the people building and installing the firmware, are scum.
Technology could be so much more useful and fun if we just fully banned the collection and sale of personal data. We've been dreaming of smart homes for, like, 80 years, but advertising ruined it just like it ruins everything. Imagine how cool it would be to able to connect devices to the internet for purely functional purposes without them spying on you!
This is all technology. Everything is being infested with spying and tracking.
1 reply →
The shareholders as well.
What is the need for a coffeemaker on the internet?
2 replies →
ahahahah that's gold !
IoT network yep, needed yesterday
Last year I had a big dispute with my ISP that was refusing to support or provide proper WiFi on their router, even while they touted a trademarked brand-name to do it. I ended up turning their router into Bridge Mode and purchasing a real router that could do WiFi. I did this extremely reluctantly, because every other personally-owned router had contracted malware.
After installing the new router (Netgear) my HP LaserJet began printing error pages. Like, I had done nothing to send anything to it, but a blank error page or three would pop out of it at very random times.
It took awhile to narrow down and diagnose this. But it turned out that the Netgear system had a very... proactive network malware detection system. It was red-team scanning my LAN for "vulnerabilities" or exploits or the presence of malware (I think just known vulns). It was a known side-effect of these scans, where it would tickle an RTSP TCP port of some kind and the HP printer would respond with its error printout.
I was so livid that the router was scanning the LAN, basically unbidden and completely undocumented. Even worse, they were not sharing the logs or results of that scan with the consumer. No, they were being sent back to the Netgear mothership, and their cybersecurity vendor overlords. So the scans were not designed to benefit me; they were simply designed to spy on everyone from a privileged vantage point. Now I ask you, why is a piece of kit that is supposed to be "yours" compiling secrets about your network, hiding them from you, and turning them over to, I guess a big database for hackers to leak in due time? This is not a question of "well, devices hooked up to a network should not be vulnerable" if the devices were contained in a private network, and 100% inaccessible from outside, and only attackers inside my perimeter could do these exploits in the first place.
Thankfully I found a way to disable this. Their "security" shitware is still spamming DNS and I may be forced to disable that as well. Meanwhile, routers 100% cannot self-introspect or self-diagnose and find their own malware. I've said it once; I'll say it again: consumer routers are the Achilles Heel to your network. They are ideal points of compromise for any actor to gain a foothold and pivot, or simply gain persistence undetected. Your ISP doesn't care, and your vendors don't care. Perhaps you should.
If my printer printed random shit I would just get paranoid and wipe every piece of tech clean. But good on you for discovering why though.
Wow that seems bonkers to me. Basically scanning and cataloging known vulnerabilities on the sly, and when anyone notices they pretend it is for your benefit somehow.
It would be like finding out ring cameras are taking pictures of your keys and calculating the pin set to producing duplicates and sending that pin set data off somewhere and when caught them being like "Uh, we are uhhh... doing it to make sure your key isn't too worn down or to detect if someone made a crude hand filed key. Yeah that's it!"
As another sign of the enshittified world we live in, the thing probably wasn't even RFC 2324 compliant.
https://datatracker.ietf.org/doc/html/rfc2324
Bruh should have set his PiHole to return HTTP 418 in response to any outbound request this thing made.
The GDPR consent form on this blog did not have a “Reject all” button. It required me to manually reject 16 instances of “legitimate interest,” then scroll through 1,746 vendors to make sure they were all set to reject.
Seems worth mentioning in a post about excessive and intrusive collection of user data. The moral outrage rings hollow when opting out of tracking is so deliberately onerous.
And also illegal. It's illegal not to have one button. Companies didn't do it because they suddenly stopped being scum.
[flagged]
[dead]