Top
Best
New

Posted by ck2 1 day ago

Man discovers his parents' coffee machine used 1TB of data in 10 days(www.dexerto.com)
234 points | 130 commentspage 2
ButlerianJihad 1 day ago|
A year or two ago, I was using NextDNS in ad-blocking and logging mode, which very helpfully exposed malware sitting on my very router, which had been completely undetectable, except for the veritable flood of bizarre DNS queries it was routinely sending to the self-configured DNS servers.

Now that I have a new router and I've re-enabled NextDNS, I've ironically discovered that the chief abuser of DNS right now is the router's own legit security software, which is absolutely hammering on the same query, several times a second.

Of course, since I am currently on NextDNS free tier, this matters a lot, because they cut you off after about 300,000 queries in a month. So any hammering abuse will make me lose my privileges much earlier than I would otherwise. So, to stop the abuse, should I shut off my legit security software? It is absolutely rubbish at identifying malware on the device itself...

ck2 1 day ago||
it took me a month to notice my Midea A/C was absolutely hammering my router

I didn't even know it had wifi capability but it was trying to connect

I use mac whitelist so it wasn't even getting in but that didn't stop it from trying every seond

Fortunately it was just a usb dongle so yanked it out

altairprime 1 day ago||
Most Midea units can be swapped for an ESPhome USB dongle if you ever wish to have remote control on your own terms — note various countries’ shop links, and the various wiki and other outlines for DIY etc: https://smlight.tech/product/slwf-01
HankB99 1 day ago|||
Ooo. I have a Midea dehumidifier. When it powers up it displays the WiFi symbol. I wonder if it is hammering away at my access point. Might it be better to bring it on line and then just block all traffic?

And I wonder how I would even tell if it was trying to associate with my WiFi.

pseudohadamard 8 hours ago||
I have a Midea dehumidifier too. It moves around 200kB/hour which seems to be cloud polling about once a minute, so no big deal traffic-wise.
jedbrooke 57 minutes ago||
it’s checking to see if they discovered a new type of water

https://xkcd.com/3109/

ars 1 day ago||
I have two of them, and I just checked and both are quiet. Mine don't connect to WiFi unless you go through an entire process first with an android phone and Matter.

It's great having them on WiFi - you can turn on the AC before getting home to pre-cool, without having to leave it on all day.

sillyfluke 1 day ago||
Boy: So, how it get this bad grandpa?

Man: Well, before you couldn't turn on the AC before you got home

ars 1 day ago||
Realistically people would just leave their AC on. So this saves energy, rather than changing comfort.
seb1204 2 hours ago|||
Really? And then complain about the energy cost? People are nutz. Like it's so unbearable to come home, open windows to get peak hot air out, then turn on AC and get cool. Energy is too cheap it seems. Also even very old AC remotes show there is usually the option to set up times etc.
Cpoll 1 day ago||||
Realistically ACs have timers, so you're really only optimizing for days where you go off-schedule.
sillyfluke 23 hours ago|||
I have a friend who diy'ed a button on single webpage that he presses on his phone while at work in order to open the gate to the building that he lives so delivery people can get in. I also think Bret Victor diy'ed the AC as mentioned while he was a student quarter century or more ago[0]

I know this sounds like the famous "just do it this way in linux instead" criticism of Dropbox back in the day. But I do think we reached "life parodies fiction" with these smart devices where it makes sense to give diy another go. And with AI, there's less excuses this time around I would imagine.

But I would literally rather buy a cheap phone, a cheap SIM, hotspot it and connect it to a charger and have the AC connect to that and isolate it that way instead of letting it touch the network.

[0] https://worrydream.com/Electronics/

ttytty 23 hours ago||
You can (and should) just segregate your network to have separate paths for IoT/"smart devices" and normal personal/family devices. Makes it all worry free and transparently observable.

I have my IoT on a separate VLAN and I can observe communications for any given device at any given time.. this seems like a much saner solution than outright not buying any IoT devices, though that is also a respectable decision!

tamimio 1 day ago||
Reminds me when couple years ago I plugged the TV to the internet (so my relatives kids can watch YT) and I forgot to unplug it for almost a week after, only to find the router dns resolved (and blocked) a million queries, all from that one TV!
bombcar 21 hours ago||
I love when it keeps checking some random DNS address, because who knows, with a TTL of 64000 it may just have changed in the last seven milliseconds!
altairprime 1 day ago||
The traffic generated here is network scans, not external traffic, and so blocking DNS wouldn’t have helped.
realaaa 1 hour ago||
ahahahah that's gold !

IoT network yep, needed yesterday

matteoraso 1 day ago||
I honestly hate the IoT so much. Why should a coffee machine of all things use data? Just make the coffee.
anigbrowl 2 hours ago|
I love IoT. It's the greedy corporations I hate. Everyone who implements this kinda abusive stuff, from the CEO down to the people building and installing the firmware, are scum.
skupig 38 minutes ago|||
Technology could be so much more useful and fun if we just fully banned the collection and sale of personal data. We've been dreaming of smart homes for, like, 80 years, but advertising ruined it just like it ruins everything. Imagine how cool it would be to able to connect devices to the internet for purely functional purposes without them spying on you!
autoexec 1 hour ago||||
This is all technology. Everything is being infested with spying and tracking.
Levitating 1 hour ago||
No, just pick your technology better. My LineageOS phone and framework laptop do nothing of the sort.
autoexec 19 minutes ago||
LineageOS helps, like installing an adblocker helps, but there's no hope for cell phones. Your wireless provider is still tracking you and nobody knows what the blackbox wireless chipsets are doing, including your OS. Framework is a pretty good laptop (it's a candidate for my next even) if you can afford the premium. My next TV and car will be my biggest worry.
goatlover 2 hours ago||||
What is the need for a coffeemaker on the internet?
scrlk 1 hour ago||
A coffee maker was the subject of the world's first webcam: https://en.wikipedia.org/wiki/Trojan_Room_coffee_pot :^)
linker3000 37 minutes ago||
Yeah, but the people running the Webcam probably didn't make notes about the watch / rings / shirt / dress / shoes worn by the people using the coffee maker, nor take down whether they were wearing glasses and if they added milk - and sell this information to the local jewelers, clothes shop, shoe shop, opticians and dairy.

Probably.

robotnikman 2 hours ago|||
The shareholders as well.
bitwize 2 hours ago||
As another sign of the enshittified world we live in, the thing probably wasn't even RFC 2324 compliant.

https://datatracker.ietf.org/doc/html/rfc2324

Bruh should have set his PiHole to return HTTP 418 in response to any outbound request this thing made.

ButlerianJihad 18 hours ago||
Last year I had a big dispute with my ISP that was refusing to support or provide proper WiFi on their router, even while they touted a trademarked brand-name to do it. I ended up turning their router into Bridge Mode and purchasing a real router that could do WiFi. I did this extremely reluctantly, because every other personally-owned router had contracted malware.

After installing the new router (Netgear) my HP LaserJet began printing error pages. Like, I had done nothing to send anything to it, but a blank error page or three would pop out of it at very random times.

It took awhile to narrow down and diagnose this. But it turned out that the Netgear system had a very... proactive network malware detection system. It was red-team scanning my LAN for "vulnerabilities" or exploits or the presence of malware (I think just known vulns). It was a known side-effect of these scans, where it would tickle an RTSP TCP port of some kind and the HP printer would respond with its error printout.

I was so livid that the router was scanning the LAN, basically unbidden and completely undocumented. Even worse, they were not sharing the logs or results of that scan with the consumer. No, they were being sent back to the Netgear mothership, and their cybersecurity vendor overlords. So the scans were not designed to benefit me; they were simply designed to spy on everyone from a privileged vantage point. Now I ask you, why is a piece of kit that is supposed to be "yours" compiling secrets about your network, hiding them from you, and turning them over to, I guess a big database for hackers to leak in due time? This is not a question of "well, devices hooked up to a network should not be vulnerable" if the devices were contained in a private network, and 100% inaccessible from outside, and only attackers inside my perimeter could do these exploits in the first place.

Thankfully I found a way to disable this. Their "security" shitware is still spamming DNS and I may be forced to disable that as well. Meanwhile, routers 100% cannot self-introspect or self-diagnose and find their own malware. I've said it once; I'll say it again: consumer routers are the Achilles Heel to your network. They are ideal points of compromise for any actor to gain a foothold and pivot, or simply gain persistence undetected. Your ISP doesn't care, and your vendors don't care. Perhaps you should.

freecodeio 1 hour ago||
If my printer printed random shit I would just get paranoid and wipe every piece of tech clean. But good on you for discovering why though.
AngryData 14 hours ago||
Wow that seems bonkers to me. Basically scanning and cataloging known vulnerabilities on the sly, and when anyone notices they pretend it is for your benefit somehow.

It would be like finding out ring cameras are taking pictures of your keys and calculating the pin set to producing duplicates and sending that pin set data off somewhere and when caught them being like "Uh, we are uhhh... doing it to make sure your key isn't too worn down or to detect if someone made a crude hand filed key. Yeah that's it!"

rendall 1 day ago||
The GDPR consent form on this blog did not have a “Reject all” button. It required me to manually reject 16 instances of “legitimate interest,” then scroll through 1,746 vendors to make sure they were all set to reject.

Seems worth mentioning in a post about excessive and intrusive collection of user data. The moral outrage rings hollow when opting out of tracking is so deliberately onerous.

wafflemaker 1 day ago|
And also illegal. It's illegal not to have one button. Companies didn't do it because they suddenly stopped being scum.
Gauchy101 1 hour ago||
[flagged]
3seashells 1 hour ago|
[dead]