20 ms·
Has anyone worked on fighting back this kind of telemetry/spyware of essential consumer appliances? I'm thinking something similar to what https://adnauseam.io
by thn-gap 4y ago
Has anyone worked on fighting back this kind of telemetry/spyware of essential consumer appliances?
I'm thinking something similar to what https://adnauseam.io/ https://adnauseam.io/ does, but but amplified:
1. Someone reverse engineer what does the device send to which address.
2. Block the particular device to access internet (and make it easy for others too).
3. Constantly send bogus data to the manufacturer so the personal data they get overall loses value or is unusable. Make it easy for a lot of people to do it as well, or even just rent a bot farm.
There's too many legit and good services that end up being turned down due to abuse and DDos, and they don't even bring anything good to the attackers. Why not using these techniques for something actually good to consumers privacy?
- encrux 4y agoWhy would you want to go out of your way to send bogus data to the manufacturer? I'm all for being able to choose whether or not to disclose that data, but then we'll also have to accept different choices than ours. There's no point in sabotaging others.
- krageon 4y ago> Why would you want to go out of your way to send bogus data to the manufacturer? Because getting a ton of garbage will positively stimulate them to stop trusting this data. That helps everyone.
- widjit 4y agoThough more likely no one will notice/care and they will just sell the bad data regardless
- Nextgrid 4y agoIf someone's buying the data they will care sooner or later. After all, if they wanted bogus data, they can generate it themselves instead of buying it.
- barbazoo 4y agoPlease someone tell me what anyone would do with data obtained from a fridge.
- deleted 4y ago[deleted]
- TedDoesntTalk 4y agoCustomer is out of cheese. Supermarket texts and emails you asking if you want cheese delivery (bundled with other items).
- barbazoo 4y agoUnless there's cameras everywhere in the fridge (plus advanced object recognition that knows that that bundled up pack of goat cheese inside a ziplock bag is in fact goat cheese) or people are scanning items as they take them out I don't see how that would work and both things seem kinda unlikely so it's weird they'd start with the easiest part which is hook up the thing to the internet.
- Nextgrid 4y agoUsage patterns? Fridge being opened means someone is home. That data point is meaningless in isolation, but can be valuable if you want to use it to confirm/deny other data points - let's say another data broker is trying to get an accurate ad targeting profile but only has breadcrumbs here and there such as IP addresses, user-agents that by themselves don't mean much, but they can use other data points (such as fridge activity data) to link your otherwise-anonymous IP-based profile if they see that the only times this IP lights up is when the fridge was also used recently. Whether that's currently done is up for debate - maybe there are other lower-hanging fruits that are easier to do, but if you've exhausted all your other options and still want even more accurate profiles, I don't see why you wouldn't do it.
- vorpalhex 4y agoI went through a serious attempt to remove all of my resumes on the web. Paid a firm, whole nine yards. Several data brokers still have very, very old copies.. and they still sell them.. and recruiters still buy them.. and still contact me.. and still get met with an email politely telling them off. But that years old shitty linkedin dataset still gets sold to thousands of people for thousands of dollars a year and nobody bats an eye. The recruiters are too stupid to spot the bad data and the brokers too lazy to care.
- princekolt 4y agoNo one will hand you your rights for free on a silver plate. Protesting and fighting back is the only way any progress is made in society.
- car_analogy 4y ago> There's no point in sabotaging others. We're already being sabotaged, by manufacturers - what else would you call this sometimes hidden, non-disablable connectivity/"telemetry", and the disappearance of dumb options? The only question is if we let them get away with it scot-free.
- AnIdiotOnTheNet 4y agoAdvertisements for products invade our lives, unbidden, nearly every second of every day. Turnabout, as they say, is fair play.
- itsboring 4y agoI agree with the other responses here, but they missed one reason: because it’s funny.
- PaulKeeble 4y agoTwo ways. 1) Set up a pihole or ad guard or similar and block the requests the device makes. You can probably find someones list or it may already be in the default one. 2) Put all the IOT's devices into a virtual wifi lan that doesn't by default doesn't allow internet access. Then only add in the few places you want them to be able to get to. In general putting IOT devices on a network separate from your real computers is a good idea for isolation anyway since they are likely to have poor security.
- L_riel 4y agoAssuming the device doesn't have its own modem and internet connection integrated.
- bornfreddy 4y agoYup. That's my worry - I can block them now, but what do I do when all these devices have their own "WhisperNet"?
- rjsw 4y agoGet your own femtocell.
- myself248 4y agoSo like Sidewalk...
- BizarroLand 4y agoFor that to happen, the value of the data it extracts would have to be greater than the cost of installing and paying for a cellular modem and the data fees over its lifetime. I think most of us aren't worth it, as it would take away from the upfront profit of the machine to add features people aren't told about just to get a few years of "Subject opened left door. Temp 39 degrees. Subject used ice maker." or whatever.
- ridgered4 4y ago
- somenameforme 4y agoIn my ever-cynical view, I imagine in most cases manufacturers don't, themselves, especially care about the data from their devices. I see various other motivations: 1) Price increases. It's "smart". Pay us more. 2) Planned obsolescence. You have numerous new points of failure in your product + make repairing vastly more difficult. 3) Monetize collected data by selling it to interested parties. The data quality, or lack thereof, is a secondary concern.
- s3p 4y ago> Monetize collected data by selling it to interested parties. then they do care about the data, just not the quality of that data. But the fact they are collecting data is definitely of importance or they would not be collecting and selling it.
- mirntyfirty 4y agoI’d just want to know who on earth would want such data and what insights could be gained from it. It can be challenging to build models with tons of really good data.
- IshKebab 4y agoI've worked in a big consumer electronics company and 2. is just a conspiracy theory. Nobody wants their products to be unreliable or difficult to repair. They want them to be cheap to manufacture and unlikely to fail during the warranty period. Everything else stems from that. Your other two points are broadly correct though. Also data collection is helpful for seeing how customers use products, which genuinely does influence development.
- alpaca128 4y ago> Nobody wants their products to be unreliable or difficult to repair. Hard to believe when a printer manufacturer moves a commonly failing part from cartridges to the printer itself, then makes it impossible to repair that specific part without taking apart the whole thing and buying a replacement part for 160 bucks. > Also data collection is helpful for seeing how customers use products, which genuinely does influence development. I'll start calling it helpful once it actually improves product quality and usability.
- sdoering 4y agoI remember there was something similar once for web analytics. The extension would obfuscate stuff by changing values, esp. e-commerce values like price and quantity so that the data becomes quite tainted. Just can't remember what it was called.
- Sephr 4y agoThe comment you're that replying to has the answer to your question. It's https://adnauseam.io/ https://adnauseam.io/
- sdoering 4y agoI understood adnauseam as clicking ads, not fuzzing web analytics data on the site I am currently on. Should read their site in more detail probably.
- lcnPylGDnU4H9OF 4y agoI'd guess that the one you were remembering (also mentioned on AdNauseam's site; this functionality of AdNauseam is new to me too) is TrackMeNot.
- Mumps 4y agofor 3. I wonder if you can go a step further and pummel them with extra data. like insane amounts of (bogus) data. At some point even plain s3 storage costs will become problematic for them.
- lupire 4y ago0. Buy a "dumb" device that works better.
- ss108 4y agoIt seems that less and less such devices are being produced.
- closewith 4y agoI’m trying to do this now, but dumb high-quality appliances are hard to come by and much more expensive. I don’t think there’s any dumb TVs at the state of the art.
- bonzini 4y agoDumb TVs are sold as digital signage. They are the state of the art for durability/reliability but they typically have a screen from the "previous" generation, so for example they might not have HDR.
- user3939382 4y agoSome kind of legislative protection would be nice too. eg any mechanism that collects or transmits telemetry must be able to operate totally separate from any other feature of the device and have a hardware kill switch.
- eternityforest 4y agoI would hate to see smart stuff taken off the market. A DDoS could cause the company to drop support faster(Like they already always do), and hurt the people who can no longer use the features on their expensive device. Besides, if DDoSing got popular with average consumers it would never stop, and they'd go after everything that has any privacy risk(AirTag/Tile comes to mind), no matter how critical it is to some people's lives. Admittedly a bit of a slippery slope argument, but less so in an age where there is a significant minority that would love to undo all tech from the last 70 years. Instead we could be fighting for laws requiring that that all smart devices use an open and app-capable OS, or that all features exposed via proprietary connection to their server also be exposed via local API.
- LargoLasskhyfv 4y agoWhat did the people do, to whose lifes AirTags have become critical, before they were available?
- eternityforest 4y agoWe spent several hours a week dealing with, worrying about, and developing mitigation strategies for losing out keys, quite possibly even shortening our lives with stress. If you aren't one of those people that can just walk by something and passively remember it's location, IoT is great. Tile doesn't completely replace constant vigilance and planning, and carefully thinking about every step, but it does help.
- kurisufag 4y ago>1. Someone reverse engineer what does the device send to which address. 2. Block the particular device to access internet (and make it easy for others too). 3. Constantly send bogus data to the manufacturer so the personal data they get overall loses value or is unusable. Make it easy for a lot of people to do it as well, or even just rent a bot farm. requests probably need to be send with valid serials, in which you can't effectively anonymously flood the telemetry by yourself. given that there is absolutely no way even a small percentage of Samsung fridge (why even buy one?) users will care about this, all it does is reveal the participant's identities and motivations.