$17 smartwatch sends something to random Chinese IP address
theregister.co.uk
theregister.co.uk
In this case there just aren't any English speakers to show up in the press and spit sophistry about how a stopwatch app needs to exfiltrate your entire contacts book for business reasons and "you clicked OK so fuck you."
Dunno why you're so downvoted. Is the HN audience too thick to see your point, or was it using language too close to IRL politics?
Interestingly enough, the author himself uses the word "random" to describe the address, but then implies it is indeed unique: "it didn't resolve to anything".
I believe he really meant "unknown" there, but he is a professional researcher, so what do I know? I guess we will have to wait for the paper he mentioned he was writing on the subject.
http://www.thefreedictionary.com/random
> 3. informal (of a person) unknown: some random guy waiting for a bus.
It's not great journalism, but this is the register.
But it's needlessly confusing to use "random" to describe something that's represented numerically unless it's mathematically random. "Arbitrary" or "unknown" is better.
Replace "camera" with "watch":
“The details about how P2P feature works which will be helpful for you understand why the camera need communicate with P2P servers,” Qu explained. “Our company deploy many servers in some regions of global world.” Qu further explained:
1. When the camera is powered on and connected to the internet, the camera will log in our main P2P server with fastest response and get the IP address of other server with low load and log in it. Then the camera will not connect the main P2P server.
2. When log in the camera via P2P with Foscam App, the app will also log in our main P2P server with fastest response and get the IP address of the server the camera connect to.
3. The App will ask the server create an independent tunnel between the app and the camera. The data and video will transfers directly between them and will not pass through the server. If the server fail to create the tunnel, the data and video will be forwarded by the server and all of them are encrypted.
4. Finally the camera will keep hearbeat connection with our P2P server in order to check the connection status with the servers so that the app can visit the camera directly via the server. Only when the camera power off/on or change another network, it will replicate the steps above.”
Nothing inherently malicious about this, unless the vendor is irresponsible with user data, or collects data it should not be collecting in the first place.
[1] http://krebsonsecurity.com/2016/02/this-is-why-people-fear-t...
Sounds legit. Does that not raise any red flags?
Even if it requests a bunch of permissions, I believe that it needs access to your call logs, SMS etc. as its core functionality since it is, after all, a smart watch that wants to display to you your notifications and allow you to react on them.
I would be much more open then if I just stumbled on the app on Google Play that requires the exact same permissions.
Resellers here (Bosnia & Herzegovina) are selling it for a slightly higher price (~19.5 USD, which I would accept because it does not require me waiting for the thing to be delivered across the world).
I'm in the same situation as you, never had a smart-thing in my life (unless you count Raspberry Pi and Google Cardboard, which I personally don't). I have never realized the appeal of a smart watch until a colleague of mine just clicked on its iWatch once, said something like "remind me that I have a meeting tonight at 8 PM with XX at YY", and had the event created for him on his iPhone. Seems way more convenient than actually getting my phone out of my pocket, unlocking it, finding the app, and inputing the event details.