Top
Best
New

Posted by minimalthinker 13 hours ago

My smart sleep mask broadcasts users' brainwaves to an open MQTT broker(aimilios.bearblog.dev)
346 points | 174 commentspage 4
roywiggins 12 hours ago|
cyberpunk
mystraline 12 hours ago||
> For obvious reasons, I am not naming the product/company here, but have reached out to inform them about the issue.

Coward. The only way to challenge this garbage is "Name and Shame". Light a fire under their asses. That fire can encourage them to do right, and as a warning to all other companies.

My guess is this is Luuna https://www.kickstarter.com/projects/flowtimebraintag/luuna

a4isms 12 hours ago||
Doesn't disclosing this to the world at the same time as you disclose it to the company immediately send hundreds of black hats to their terminals to see how much chaos they can create before the company implements a fix?

Perhaps the author is not a coward, but is giving the company time to respond and commit to a fix for the benefit of other owners who could suffer harm.

rkagerer 11 hours ago|||
but is giving the company time to respond and commit to a fix for the benefit of other owners who could suffer harm.

If that's the case then they should have deferred this whole blog post.

mystraline 12 hours ago|||
It took me 30 seconds with ChatGPT by saying:

Identify the kickstarter product talked around in this blog post: (link)

To think some blackhat hasn't already did that is frankly laughable. What I did was like the lowest of low-bars these days.

Barbing 12 hours ago|||
Put the product name in the title & maybe it sends thousands instead of hundreds of blackhats…

We often treat doxxing the same way, prohibiting posting of easily discovered information.

mystraline 12 hours ago||
So your plan is to let the blackhats in the know attack user devices, rather than send out a large warning to "Quit using immediately"?

If we applied this similar analogy to a e.coli infection of foods, your recommendation amounts to "If we say the company name, the company would be shamed and lose money and people might abuse the food".

People need to know this device is NOT SAFE on your network, paired to your phone, or anything. And that requires direct and public notification.

pphysch 11 hours ago|||
And ChatGPT hallucinated a misleading answer that you are confidently regurgitating.
croisillon 11 hours ago||
their original message said "my guess", not ChatGPT's, talk about responsible disclosure...
minimalthinker 11 hours ago|||
I did consider naming, but they were very responsive to the disclosure and I was not entirely familiar with potential legal implications of doing so. (For what it's worth, it is not Luuna)
stavros 11 hours ago||
Please name 50 other companies it's not.

It's good that they were responsive in the disclosure, but it's still a mark of sloppiness that this was done in the first place, and I'd like to know so I can avoid them.

itishappy 12 hours ago|||
I don't see estim mentioned on that website, but I do see a comparison chart with 4 other competitors with similar capabilities to the one you linked.

What makes you think this is the one?

mystraline 12 hours ago||
https://meta.wikimedia.org/wiki/Cunningham%27s_Law

I said a guess, not absolute.

everdrive 12 hours ago|||
Even if naming and shaming doesn't work, I sure want to know so I can always avoid them for myself and my family. Thanks for the call-out and the educated guess.
j45 11 hours ago|||
EEG devices can cost a lot to own personally as well.

The other side of owning equipment like this is it still could be useful for some for personal and private use.

minimalthinker 10 hours ago||
EEG is very useful for accurate sleep tracking.
hxbdg 12 hours ago||
Presumably they’ll be named and shamed after they’ve been given a chance to fix things.
kevincloudsec 9 hours ago||
[dead]
roysting 9 hours ago|
> nobody budgets time for security architecture on v1

It’s quite literally why the internet is so insecure, because at many points all along the way, “hey, should we design and architect for security?” is/was met with “no, we have people to impress and careers to advance with parlor tricks to secure more funding; besides, security is hard and we don’t actually know what we are doing, so tow the line or you’ll be removed.”

intellirim 12 hours ago||
[dead]
ai-x 11 hours ago||
There should be two separate lines of products. One in which privacy is priority and adheres to government regulations (around privacy) and probably costs 2x and one with zero government intervention (around privacy) which costs less and time-to-market is faster.

I don't want a few irrationally paranoid people bottlenecking progress and access to the latest technology and innovation.

I'm happy to broadcast my brainwaves on an open YouTube channel for the ZERO people who are interested in it.

drnick1 9 hours ago|||
> I don't want a few irrationally paranoid people bottlenecking progress and access to the latest technology and innovation.

Paranoid? Is there not enough evidence posted almost daily on HN that tech companies are constantly spying on their users through computers, Internet-of-Shit devices, phones, cars and even washing machines? You might not care about the brainwave data specifically, but there is bound to be information on your devices that you expect remains private.

Things have become so bad that I now refuse to use computers that don't run a DIY Linux distro like Arch that allows users to decide what goes into their system. My phone runs GrapheneOS because Google and Apple can't be trusted. I self host email and other "cloud" services for the same reason.

tgv 10 hours ago||||
Explain how sending EEG recordings is progress. And why faster access to the latest tech is always good, for everyone.
selkin 11 hours ago|||
otoh: the non regulated should cost more.

It’s kinda like “qualified investors” - you want to make sure people who are wiling to do something extremely stupid can afford it and acknowledge their stupidity.

We don’t need regulation to protect those that can afford to buy protection: we need it for those who can’t.

plagiarist 11 hours ago||
It is a governance failure.

It is also technically a user failure to have purchased a connected device in the first place. Does the device require a closed-source proprietary app? Closed-source non-replaceable OS? Do not buy it.

brabel 10 hours ago|||
Very few options available, if any, if you actually do that. The IoT market is unfortunately small and dominated by vendors that don’t want at all an open ecosystem. That would hinder their ability to force you to pay for a subscription which is where all the money is.
jmb99 10 hours ago|||
Yes, that’s right, don’t buy any new car, any phone, any television. Hell don’t buy any x86 laptop or desktop computer, since you can’t disable out replace Intel ME/etc.
throw876987696 11 hours ago|
Without a brand name, how can we verify this is real?
ohyoutravel 11 hours ago|
Without any skin in the game with your username, why should we take anything you say seriously?
edgarvaldes 10 hours ago||
Interesting position in a thread about the dangers of exposing yourself to the internet.