Nest to join forces with Google’s hardware team
nest.com
nest.com
However, recently I moved into sysadmin-type work, partly doing work for state governments. Cybersecurity is really bad everywhere, and it’s scary, and it’s frustrating how abstract and very theoretical all the risk is as it makes hard (justifiably) to take seriously.
Anyway, Google’s reputation with security is (fingers crossed) nothing short of “almost bulletproof”, and I’d love to see more IoT devices from them. With the recent rollout of Nest Security System, we’ve actually been advising lots of small businesses to combine this system, along with Nest cameras + fire alarms as a solution to actual physical security and fulfilling compliance alarms. Since Nest also does cellular backup in case of internet outage, we just hook everything up to an APC and the whole system can run for 10+ hours without power or internet.
Also also, Android security sucks. Not Google’s fault, but thank god they moved to making their own phones. Maybe that will encourage better behaviors from other manufacturers.
The GCP "best practices" sections in the docs* have been top tier in my experience and you can learn a lot, even if you're using AWS or Azure.
* my one complaint is that searching for the docs almost always ends you up on marketing pages, which you then have to find the docs link on.
Also, Google's "reputation with security" needs some serious nuance: They are very good at preventing types of exploits they care about, but they are a literal joke when it comes to security that interfaces with submitted content and user choice. Consider that the Chrome Web Store is a literal cesspool of malware, and that a lot of websites blatantly try to force you to install extensions through the Chrome Web Store which steal your browsing data. Since extensions are permitted to request such a huge security hole, Google doesn't consider it their problem that extensions do it maliciously.
Because Google doesn't consider something they gave permission to do malicious things to be an exploit or vulnerability, Google can simultaneously claim that Chrome is the most secure browser, and it be literally the easiest browser to get malware with.
I can definitely agree with you that state level government security has a long way to go and is a pretty scary place. But Google can't fix it, because the biggest problem in government security is still humans, a security layer that Google has repeatedly demonstrated no understanding of.
My positive perception mainly comes from this super paranoid dude, Michael Bazzell: https://inteltechniques.com/experience.html. He both hates Google for their data collection and also respects it for their security practices.
Ugh I also hate to hear they’re doing the “we’re secure but who knows about our 3rd parties” practice. State IT does this as well. As long as you sign some contract with them that promises them you do NSA-style security, they’ll buy anything from you. Of course what 5-man IT shop wouldn’t sign a $20,000,000 IT contract when worst case, they get a bad audit and have to spend 50k really quickly to get up to SOC II?
You can literally find a list of State IT contractors for most govs, and just go through them finding all the fly-by-night shops. That being said, the big vendors aren’t that much better either...
tl;dr: everyone sucks and be afraid and use mfa
The thing people need to remember is that the CIA Director's AOL email account got hacked. In 2015. We are so far as a society from where we should be.
It would seem you still don't understand how Android is built. Google cannot update the phones made by other OEM's. OEM's download the Android source code, add their modifications and create their own forked version of Android. This is like asking Debian to update Redhat's Linux distribution. Blaming Google for the OEM's inability to update their own phones is disingenuous, but it does support your prime directive of disparaging Google every opportunity you get.
>especially when you consider it took Google five months to patch KRACK in the Pixel 2, when third party ROM authors did it in two days.
Those patches were provided by Google incidentally. Additionally, Google patched KRACK in Dec, 2017 on the Pixel phones. So where exactly did you get this 5 months?
>Also, Google's "reputation with security" needs some serious nuance: They are very good at preventing types of exploits they care about, but they are a literal joke when it comes to security that interfaces with submitted content and user choice. Consider that the Chrome Web Store is a literal cesspool of malware, and that a lot of websites blatantly try to force you to install extensions through the Chrome Web Store which steal your browsing data. Since extensions are permitted to request such a huge security hole, Google doesn't consider it their problem that extensions do it maliciously.
Could you point me to the malware on the Chrome Web Store? Since you claim it's a "literal cesspool of malware" it shouldn't be that difficult for you to point to those extensions. I look forward to those links.
https://arstechnica.com/information-technology/2018/01/malic...
>Proving once again that Google Chrome extensions are the Achilles heel of what's arguably the Internet's most secure browser, a researcher has documented a malicious add-on that tricks users into installing it and then, he said, is nearly impossible for most to manually uninstall. It was available for download on Google servers until Wednesday, 19 days after it was privately reported to Google security officials, a researcher said.
Another one: https://arstechnica.com/information-technology/2018/01/50000...
>Researchers have uncovered four malicious extensions with more than 500,000 combined downloads from the Google Chrome Web Store, a finding that highlights a key weakness in what's widely considered to be the Internet's most secure browser. Google has since removed the extensions.
July, vendors notified (incl. Google): https://www.nbcnews.com/tech/tech-news/krack-attack-security...
October, my Windows Mobile phone was patched: https://www.bleepingcomputer.com/news/security/microsoft-qui...
October, vulnerability goes public: http://www.businessinsider.com/krack-attack-wi-fi-vulnerabil...
October, Lineage patched: https://twitter.com/LineageAndroid/status/920143977256382464
December, Google patches their own phones: https://arstechnica.com/gadgets/2017/11/pixel-wont-get-krack...
They just don't care about updates, otherwise they would remove certification access to any OEM not providing updates.
Even with Treble they are letting the OEMs do the updates, if they ever take place.
And to add to injury, devices that are upgraded to 8.0 instead of being released with it, don't require Treble compliance.
So, our lovely OEMs are mostly shipping Android 7.0 devices in 2018 to avoid Treble.
It is 100% Google's fault.
I think they care, but they can't do something about it. Because OEM's dislike updates. Updates does not sell new phones.
Google on the other hand actually has it easier if all their devices are up to date. They do not need to maintain old code/branches whatever.
It's still Google's fault that they never had something in place to enforce it. They basically wanted to have anybody on board of the OHA, so they needed to make tradeoffs in their contracts.
The Nest Protect Smoke & CO sensor does not qualify as a 24 hour monitored fire protection device. This is due to the requirement from Nest that the user must first verify that the Nest protect fire alarm signal is or could be real before the monitoring service will receive the fire alarm signal and dispatch the fire department
--
This was a deal breaker for me using the nest eco system for home security -and- fire protection. Other systems don't suffer from this. It's too bad as I like the tech but it's not bulletproof yet.
100% Google's fault when they don't do contracts enforcement with OEMs.
No upgrades, no access to Play store and other related Google services, easy they just don't want to do it, plain and simple.
Instead of buying Nest's entire line to outfit the house I'm building, I'm avoiding them completely even though I think their products are at the top of their class.
Nest isn't unique anymore... neither are their cameras... and they are late to the party with the doorbell. Do I think they are great products? Absolutely!! But they aren't in a position of leverage, the market is becoming commoditized, and forcing consumers to use only your app is a poor strategy. Especially considering it wasn't until a few weeks ago did Nest's app support iPhone X's new format, MONTHs after it was available to the public.
https://www.theregister.co.uk/2016/05/11/google_open_sources...
I think most home automation purists would provide a contrarian argument that points to z-wave or zigbee. :)
How do you force companies to play nice without regulation?
Edit: What about Zigbee? Google Home? WeMo? And new to me, Bluetooth Mesh.
Almost all the mentioned standards are based on IEEE 802.15.4.
The difference between 6LoWPAN and and the rest of the mentioned "standards": 6LoWPAN is IPv6 "adapted"/compatible. Thread is based/extends on 6LoWPAN, and adds several missing features or replaces some parts, because similar to conventional Internet devices, you need something more than IPv6 to get things going.
Thread was developed at Nest. The Thread Group was announced July 2014, far into HomeKit's R&D cycle. There wasn't much, or obvious, commercial support for for years. (Although to be fair, HomeKit has taken forever to get traction, too.)
I believe that at the time Apple was also concerned about the quality and security considerations of a Thread-like system. I can't prove or cite this, but having worked with Apple engineers who worked on MFi (ironically, I worked with them at Nest, not Apple), I'm skeptical of the narrative that it was devised as a revenue source. My sense from the culture of Apple when I was there (90s) and everything I see coming out of there more recently is that Apple tries to maintain standards of peripheral quality, security, and compatibility and that have been difficult to find in the Android ecosystem, say, although this has been detrimental in the case of HomeKit adoption and they've finally backed off.
All members had input in the specification, and subsequent specs.
Edit: also, homekit uses either IP (usually WiFi) or Bluetooth LE. It's very different than thread.
[1] - https://www.threadgroup.org/ThreadSpec [2] - https://github.com/openthread/openthread
And as a sibling comment mentions, HomeKit is not as open as what Google and Nest already use. The onus is on Apple.
This is in contrast to hardware support, which has tended to contract (floppy drives, CD drives, Ethernet cables, USB jacks, iPhone headphone jack).
It also makes sense to many of us who have done platform development and/or supported public APIs.
I'd want more evidence before concluding that HomePod's initial limitations are an M.O rather than an MVP.
It isn't an accident that they've failed to extend voice support to third parties after ten years. If they did plan to add it any time soon, they would have easily been able to get that to market before HomePod. They decided they'd rather continue trying to shove users into their subpar Music service, instead of supporting what users actually want and use.
Conclusion: Don't Buy unless the only audio service you ever use is Apple Music.
> Apple's modus operandi is to, for example, enforce Apple Music as the only native HomePod music service.
(emphasis mine). I think you mean "natively support". You can send anything you like via their proprietary airplay service (like chromecast). "Enforce" is appropriate for, say, their requirement that iOS apps come only via their app store.
Historically Apple, like others, play nice with standards when they are the underdog (the NeXT, and thus MacOS X.<small-integer>) was all about open standards like JPG, though they also paid the danegeld for things like the RTF and GIF licenses. The iPod not only supported mp3 but they openly encouraged ripping CDs. Hell, Steve Jobs paid us actual money to make gcc & objective-C++ gret on the NeXT (though he had a really good team already in place as well). Then as they gained more power they cared about openness less.
Google was similar; they have a better committment to open source than Apple does but also try to use their market muscle to do things like their own mobile page format.
In case I sound like an apologist, I also prefer open interoperability. But I am realistic about looking at the landscape.
Using homebridge with the smartthings plugin is more responsive than smart things itself ironically enough.
For similar - see Android Auto / Apple Carplay, where Android can use any music/map service, but the Apple version is limited to theirs.
I have my issues with Google but they're like night and day when it comes to interoperability.
The thing Apple limits music-wise is Siri. You can't use voice control to tell Spotify what tracks to play.
"If you're interested in developing or manufacturing a HomeKit accessory that will be distributed or sold, your company must enroll in the MFi Program."
Then see the NDA you must sign just to apply to the MFi program: https://mfi.apple.com/MFiWeb/getOnLineNDA.action
Take some wild guesses what you must agree to in order to get accepted to MFi.
Now explaining to my mother that we want to install Google Cameras in my Apartment is a whole different deal.
So as a competitor (say a camera maker) you could feel somewhat OK partnering with Google Home integrations because there were legal protections that data, roadmaps, confidential info wouldn't be shared.
Now they're literally the same person, according to this. Ouch.
This just smells like politics.
did they? i thought nest was an alphabet subsidiary, and operated as an independent company to Google.
It didn't seem like there was any more separation than you'd expect of the Android and chromecast groups, for example.
For instance, let's say I integrate a thermostat/camera/x device with Google Home/Assisstant. Based on # of users who connect devices and use the integration I could get some idea of user base/popularity/sales rate.
"On paper" there is separation between the two companies, and the agreement between Google and Thermostat Company A might say "data is not shared with any other entity within Alphabet".
Now that agreement is potentially null, since they might be the same thing now.
Or even things like "we're going to release a new product and want to integrate it with Google Home in advance, etc, etc".
Will Google HW products become branded under Nest? Will Nest remain specific to the home? Will the Nest brand be dropped entirely? Will things remain "separate-but-together?"
Will Nest Weave [1] become the default IoT offering from Google, superseding Android Things? Will Nest Weave run on GCP?
I'm guessing there is quite a bit of turf-warfare going on to determine the answers to those questions.
[1] - https://nest.com/weave/
It's probably just my Stockholm syndrome of being 100% invested in Apple's ecosystem, but I'm kind of less interested in how open something is (because open often means "slow, takes forever to get anyone to agree"). I'm more concerned about companies actually having an attention span of more than a couple of years.
Is Mozilla's thing going to last for 10 years? Is HomeKit? HomeKit has a better chance. But look at things like Google Weave. What even happened with that?
All that said, HomeKit, even though it seems superior to everything else from a security standpoint, has been moving at a glacial pace. Hopefully this software authentication stuff will make a difference.
The only ecosystems that seem to be sort of thriving are closed, but extensible ones (Alexa, Google Home) and their originators seem incentivized to keep them going.
It will be interesting to see how it plays out, but I think Amazon has a big advantage in that it has sold a massive number of Echo and Echo Dots and is fairly open in all respects except the actual voice data captured.
Apple, Google, and Amazon are developing competing ecosystems and Apple has been making/keeping theirs as closed as possible. Amazon has remained relatively open and Google has been somewhere between the two.
I get the feeling that Google would love to be a completely closed system and they seem to be moving in that direction.
Will they become better tested, or will it work the other way?
Of course, the likely thing is that Google will not go out of their way to make it possible to make Nest plugins for Alexa, Cortana, etc.
Thank god. Nest cameras' object detection leave a lot to be desired as of present. Like accuracy.
I was going to say that Nest products could use some Google software engineering polish—which they could—but then remembered the state of Music and many Play apps on iOS.
>Nest's brand, known for the internet-connected thermostat it created in 2011, isn't going anywhere, Osterloh and Fawaz say.
https://www.cnet.com/news/google-and-nest-reunite-in-push-to...
I love this silo problem.
Failure to detect smoke: "Consumer Product Safety Commission: Nest Labs Recalls to Repair Nest Protect Smoke + CO Alarms Due to Failure to Sound Alert" [1]
False alarms.[2]
[1] https://www.cpsc.gov/Recalls/2014/nest-labs-recalls-to-repai...
Incorrect. If you examine the announcement you linked, the issue was a failure to alarm when smoke was detected (below UL's must-alarm threshold, above which the Protect ALWAYS alarmed) due to false detection of a hand-wave as part of the "Wave to Hush" feature. This feature was remotely disabled on all Protects via a software update.
> False alarms.
Not for a long time. The second-gen Protect, which has been out for years, includes much-improved smoke sensors and algorithms. This is reflected in its unusually-high 4.6 star Amazon rating [0].
> Those are Nest's worst product.
How did you reach this conclusion? In addition to its outstanding score on Amazon, the second-gen Protect is frequently recommended by professional reviewers [1][2][3].
Anecdotally, I have 3 first-gen Protects in my home (in addition to 2 second-gens) and have never had any false alarms (except when I forget to run the fan while cooking bacon, and fill the entire house with smoke...).
[0] https://www.amazon.com/Nest-Protect-Carbon-Monoxide-Generati... [1] https://www.popsci.com/nest-protect-smoke-co-detector-review [2] https://www.cnet.com/products/nest-protect-second-generation... [3] https://www.engadget.com/2015/09/16/nest-protect-review-2015... [4] https://www.digitaltrends.com/home/nest-protect-smoke-alarm-...
We'll i bought one for the kitchen to try out. At some point my wife burned dinner and the alarm went off and notified my phone. It was that notification that made me realize, ah ha, i get it. This $100 purchase is giving me piece of mind. This thing is smart, and its protecting me. Not only that, i bet google put way more engineering into this then some cheap one.
Now that i have kids, i have piece of mind that nest protect is protecting my kids while they sleep. Might sound silly to some, but thats how i feel.
Are you still unable to see the point?
Imagine you live in a big family and people come and go all day long and no one remembers to turn the thermostat down when they’re the last person to leave.
Are you still unable to see the point?
(Sometimes it seems like “I don’t see the point” is code for “I can’t imagine a lifestyle different than my own”)
If I leave the house for a few hours on the weekend, there isn't a big enough energy savings for turning it off. My range of comfortable temperatures is large enough that feeling cold while sitting on the couch and needing to turn the thermostat up a few degrees higher than normal doesn't sound plausible. Like wearing a wristwatch, this just seems like more trouble than it's worth.
It is not uncommon.
I think many of the cost savings from auto-away would only be realized for the lazy/inattentive and particularly for those with air conditioning, which is far more expensive to run than heat.
Also, it's really nice to turn on the heat before arriving home when it's been off all weekend, or at the cabin for a weekend skiing. The difference between walking into a 38 degree house and a 50 degree house is pretty large.
- Turn it off from bed when I forget to do it before going to sleep. My system is too loud for us to have it one while we sleep.
- Peace of mind that I didn't leave it on while outside the house. It just detects when our phones have left. Whatever savings that makes, too.
- Similarly, it starts when it detects our phones are about to enter the house, so when we get in the heater is already on to welcome us.
- No need to walk all the way to it, all freezing, first thing in the morning. If I need to wake up before it turns on automatically, I just tell it to turn on from bed.
1) "It pays for itself"
2) It looks fancy and expensive
Offer people a fancy expensive-looking thing for "free", and they'll take it. It's marketing genius, really.
Btw, a nest is about $200, a furnace is $2-5k.
All these problems are made much simpler with a wired thermostat and battery backup. I wish it was easier, but in this case "smart" doesn't really buy you much energy or UX savings over a simple programmable wired device.
Not to mention the security implications of having an appliance on your network.
Yeah, but the Nest is already connected.
The reason you need a fallback local control is because, in many environments, heating/cooling control failing is a dangerous condition.
If nothing else, I think it creates a sense of security in that they'll be able to still use it if they lose their controller or their phone dies.
You can cut a huge chunk of the cost out of the Nest if you drop the LCD, touchscreen glass, and fancy stainless steel housing.
It could be a simple plastic box with the CPU, radio, sensor and control relays inside, and then a hidden mechanical thermostat knob/control to use as a floor + emergency override if the internet cuts out or the phone goes away.
As for having a thermostat, there needs to be something that actually has a thermometer in the house.