Update: We Will Replace Your Logitech Harmony Links
blog.logitech.com
blog.logitech.com
Likewise, if you are a consumer and buying a physical device that needs an upstream service, you dont really own, or really even need to own the device. What you really want is the value the device brings, without any of the headaches that go along with devices becoming obsolete.
Logitech is so used to selling hardware products that they didn't realize that they became a service provider as soon as their Harmony Link required connectivity. They should not be marketing or selling devices, despite their history of being a physical product vendor. If users had purchased a "Harmony Link" service agreement, and Logitech was responsible for keeping their users devices up to date and functioning with their service, then nobody would complain.
Cable companies figured this out a long time ago. When was the last time anyone had to care about cable modem or set top boxes being deprecated? The cable companies have always sold the service, and the hardware was either rentable, or, sometimes, provided by the consumer, but always with the understanding that the hardware wasnt why people bought cable.
I've avoided any of these connected home hardware specifically because the manufacturers try and push ownership to the consumers. As soon as its the service providers responsibility to ensure the devices are secure and work with their service, I'll sign right up.
[1] https://blog.bolt.io/keurig-accidentally-created-the-perfect...
And you can cut servers as people end up using devices less on their own.
My guess would be the company lawyers told them they were digging themselves into a very deep hole, and that replacing the Harmony Links would be the least damaging / expensive option.
> Q: Are you censoring the words “class action lawsuit” in your Logitech Forum?
> Our intention is to ensure our forums help our customers when they need support. This includes keeping the conversation productive by monitoring the language used and automatically blocking profanity or personal attacks. This is common practice. The words “class action lawsuit” were blocked as our Community Terms of Use do not allow solicitation, including legal solicitation. We have unblocked the terms and are reviewing our list of blocked terms.
Shutting down such discussion isn't going to shut down the discussion on the rest of the internet and is unlikely to help. Its a pretty easy conflict of interest to resolve because your ultimate interest is not looking like an asshole to your potential customers.
So was Logitech censoring? Yes. Was it a free speech issue? No.
My bigger question here is of "reasonable sale" and CFAA. How are these NOT violations of the CFAA? Cause I can think of no customer who bought the Phillips Hue sets who wanted the "feature" of 'nuke 3rd party bulbs'.
And yeah, it's only time when Phillips, Logitech, and the rest of IoT crap gets remote-nuked. Give me MQTT/CoAP/AMQP or you can keep your shit!
(And yeah, this topic, like my name, makes me CRANKY. My hardware is mine, and I expect that the vendor I buy stuff from doesn't vandalize or destroy functionality now or in the future. That's vandalism, computer hacking, and/or fraudulent transaction. Take your pick.)
UPDATE: I didn't mention what I'd like as a way forward. Sure, I'm OK with updates as long as they FIX problems, and potentially add features. My ideal setup is: supports basic MQTT/CoAP/AMQP with local server, along with their proprietary cloud control. If cloud control bails, you might lose add-on value but you can re-implement yourself. The devices don't end up dead, just temporarily reduced. You might have to buy a VPS, or poke a hole in your firewall and do the dyndns song and dance..
It's about time companies disclosed in their specifications whether or not a product functions without their permission.
How do we, let along the average consumer, actually know this?
(Needless phone-home stuff is another matter, all the risk with no value add)
Additionally, the thermostat supports demand-response features (where your utility shuts off the thermostat), and can even pre-warm or pre-cool before the demand-response event as needed. The sprinkler controller checks the weather and works out optimal scheduling. Both receive regular firmware updates, and feed telemetrics back to the company for further improvement of their firmware.
Technically all of this could be done independent of their own hosted service, such that everything would still run normally without it. But there's a lot of connected features, and integrating a centralized hosted service simply makes everything far easier to develop.
At which point keeping a centralized service out of the equation becomes a feature requiring money & manpower to develop- a feature most customers don't care about, at that. (And let's be honest, what company wants to spend their energy on a future where they are out of business?)
[1] "Nest's Hub Shutdown Proves You're Crazy to Buy Into the Internet of Things", Kint Finley, Wired, 15 Mar 16. https://www.wired.com/2016/04/nests-hub-shutdown-proves-your...
[2] "What Nest's Product Shutdown Says about the Internet of Things", Christina Warren, 4 Apr 2016 Mashable. http://mashable.com/2016/04/04/revolv-smart-home-shutdown/#0...
[3] "Nest's Meager Response To Revolv Users Falls Short", Aaron Pressman, Fortune , 6 Apr 2016. http://fortune.com/2016/04/06/nest-meager-response-google-re...
[4] "Here's How Google Is Handling a Big Controversy", By Lisa Eadicicco, 6 April 6 2016, Time. http://time.com/4283408/nest-google-shuts-down-revolv/
[5] Revolv is now closed. https://revolv.com
[1]: http://www.instructables.com/id/Amazon-Echo-Controlled-IR-Re...
It might be fair to presume the security certificates are needed to communicate with the Logitech cloud and not for the operation of the device itself, and this product might not be affected if there was no cloud.
Logitech should provide options to keep their existing devices running.
You wouldn't expect a keyboard or a mouse to stop working when software updates end.
Cloud only connected devices by Logitech have been exposed in this case to remain at the mercy of Logitech.
"Looking out for users security" could also have been carried out proactively to communicate the reasons and an exchange program.
Potential solutions:
- release something open source for users to to handle the back end once a device is eol
- update the harmony mobile app to directly update the Harmony Hub on your local network and not need the Logitech cloud.
- if the software and possibility exists, load a locally hosted offline first progressive web app if possible on the hub device itself. The harmony mobile app at last glance was a Microsoft Silverlight based app so the one codebase to multiple platform philosophy should not be new.
These type of solutions could allow updates to Logitech's cloud while it's available, and responsibly allow the devices to survive when Logitech moves forward.
I just don't want to be buying a Harmony Hub when in fact I'm renting it and could be turfed at any time. That's a bait and switch, however unintended and it is probably a fair question for a lot of our cloud connected devices to answer, not just Logitech.
The update framework is the second thing you figure out and don't cheap out on.
No in place updates, everything needs dual firmware support with the 0 stage bootloader in ROM.
UL listing should cover certificates, update, and boot resiliency.
Who on earth thought that was a good idea?
- Firmware is running SSL which doesn't support SHA-256, and a SHA-1 cert is expiring soon.
- Device (or other devices it communicates with) rely on cert pinning back to Symantec owned roots, and will somehow be affected by the Symantec distrust and Digicert acquisition.
They made a mistake and they've owned up to it and are doing the right thing.
Thank you, Logitech, for listening to your customers.
People should still be upset about this, even after Logitech's bean counters calculated that the negative PR cost would have been greater than the cost of doing the right thing in this instance.
Not that extreme, but come on... if you screw people over in a product space as janky and anti-consumer as the IoT, then replacements or refunds should be standard and not reluctantly extracted from you.
... will say some shit like, "I take care of my kids." You're supposed to, you dumb motherfucker! What kind of ignorant shit is that? "I ain't never been to jail!" What do you want, a cookie?! You're not supposed to go to jail, you low-expectation-having motherfucker!
A couple of days ago we had a power failure, the thing hadn't been rebooted in looong time. Since the reboot it hasn't been able to get passed an 'Authorizing...' screen.
Long story short, Sony discontinued some servers, the thing is a brick now.
I knew there were some cloud services been consumed but had no idea it wouldn't work at all without those services. It's a freaking alarm clock!!!!
Even if Sony would make this same move, and I would happily take the replacement, I would never buy another thing like this.
Dodge this bullet, what about the next one?
Yep. They'll keep shooting until enough buyers just give up and accept that tech is arbitrary and terrible in this way, too. The end state is negative-option billing protected by layers of automated phone "support" backed by a few people who barely speak your language.
tinfoilhat: Anyway, I for one deeply regret this - not least because I have some great Logitech devices that I depend on, and now I'm worried someone might decide to accidentaly brick them in a firmware upgrade, as they're no longer generating profit for Logitech. /tinfoilhat
That said, they badly mishandled this situation, and the fact that there was so much product confusion (people thought they had just bought a link, when they had bought a hub, and people who bought a link even when it was released 6 years ago have a reasonable expectation for it to keep working) and I am glad they have shifted their position.
For home automation, I would expect the appliance's lifecycle to be closer to the refrigerator and oven (20 years and still going; EDIT: this applies to audio as well, my previous A/V setup was mostly older than me while it worked, and I'm no audiophile), not to "get your ass on the HW upgrade treadmill and replace again with iWhatever2017 or suffer the consequences." There's the point, as you note: the expectation to keep working, as opposed to an endless pile of discarded gadgets.
People got mad, media found out about it. Now they suddenly can replace everyone's no problem.
Companies should be required to label whether a device depends on cloud service. Customers could buy a guarantee, like a service contract, that the service will keep running {for some amount of time, forever}.
If the company itself sells the guarantee, then it has to price the cost of breaking these contracts into decisions about whether to maintain the service. This doesn't protect the customer from a company going out of business, though. Maybe the provider is required to put the money in escrow; or maybe they're backed by re-insurer.
This allows customers to opt in or out, depending on their risk aversion and other factors. And it's more predictable, and maybe more efficient, than a class action lawsuit.
There's a model for this: consumers buy extended warranties and service contracts for some goods, especially appliances.
Currently I only have a M235 wireless mouse; it works well, but what about its drivers? Microsoft and Trust sell similar mice, and the choices for a replacement have just reduced.
Am I the only one who's thinking its a long deadline or does this have some sort of explanation?
I've long since switched to mechanical keyboards, but run a logitech mouse. What's everybody like for a non-logitech mouse when mine dies?
https://gizmodo.com/logitech-will-be-intentionally-bricking-...