HP printers try to send data back to HP about your devices and what you print
robertheaton.com
robertheaton.com
> Programmers / Engineers: The most recent piece of technology I own is a printer from 2004 and I keep a loaded gun ready to shoot it if it ever makes an unexpected noise.
I recently got around to configuring the WiFi and it works. So call me a risk-taker!
Sooo true, my non tech friends make fun of me for how little automation/tech I have in my home.
Probably because we see how the sausage is made and how everyone prioritizes cost over security. It’s incredibly hard to make something secure once it’s connected to the internet.
Honestly I just want a few grams of explosives in my lock, wired so that they kill anybody attempting to pick the lock. Passive defenses are never enough.
The goal of all security methods is not to make breaching them impossible (since that can't be achieved), it's to make breaching them so expensive that it isn't worth what would be gained by doing so.
The point of mechanical locks is not absolute security, it’s to be more work to break than any alternative.
Crummy software updates (had to install an old version of some Intel tool to get my laptop to sleep in Windows 10) and the crapware they still bundle with Windows has made me take a step back from that position.
With this move I'm done with HP. I would have accepted a simple and clear explanation and toggle to send the same information, but this is just too shitty.
If anyone from HP is reading this, tell your supervisor that you've just lost another guy-that-everyone-goes-to-for-pc-advice. I hope you're happy.
This was very a different experience from the monochrome DeskJet 500 that was such a workhorse. And the 7470A plotter that dad used for over a decade.
I can attest that in Windows 10 I always have to delete and re-add the network printer whenever I want to print something because apparently being offline even once is enough of an upset to send the Windows printing system into paroxysms of fear, where it will tremble mightily, unable to re-try in less than 20 minutes. Don't get me started on how it's impossible to share a cellular connection over Ethernet because plugging Ethernet in turns the cell connection off to "save power" either. That little turd of a feature cost me a couple hours last week.
After this I would only get a printer which has IPP Everywhere or at least is supported by foomatic-db. hplip can get lost.
I can also get non Brother branded cartridges as they don't make a habit out of selling the printer so cheap that they have to then rape you on the price of the cartridges when it's time to refill.
The non-Brother branded cartridges work just as well as the official ones and I can go into any major office chain and buy them off the shelf.
Color laser printers are slow, but not expensive.
Beware, however, that if you live in a very humid climate, toner will clump easily. I suspect this is why inkjets are very common in Southeast Asia, whereas lasers are not as popular there.
Many printer manufacturers nowadays sell inkjet printers with laser-printer like operating costs, where ink is dirt-cheap, but the printer is correspondingly more expensive. Google for Epson EcoTank or Brother Inkvestment.
We need to come up with a better way to (automatically) hobble this nonsense, probably at the os level.
Note how often people say "insert law here". Compare that with how many times they actually propose the text of a law. Our most effective laws are exceptionally simple and short. It's not accidental that "modern" laws are intractably complex.
How about try it? Propose the law.
Government regulation of the net (aka speech) is a non-starter, so the people who think "insert rule" fixes something are forced to rebrand it to "net betterness". More than half of the general public is wise to these techniques.
What "pragmatic" law do you have in mind?
Personally, I'm less concerned about privacy of DNS queries than the loss of control and need to have another centralised third-party in the process.
As far as I'm concerned, Google are only interested in DoH so far as prohibiting DNS level adblocking within their walled gardens.
cloudflare DOH fortunately uses it own domain for dns, so you can block it at firewall level.
Google could be evil and make resolver "google.com", so you would have to block whole google.
I was talking to a few people, of creating a list of all public doh servers, so we could all use it on our firewalls to block them.
Mozilla I don't understand. The most likely explanation appears to be that they are still in a catch-up-to-Chrome mindset, which is a disservice to themselves and their community.
DNS queries should be encrypted. Centralization-by-default is not the answer and people should look more closely at the incentives in play by those pushing the DoH standard. I appreciate the efforts of e.g. OpenBSD to prevent this side-channel leakage of user data to private corporations: https://undeadly.org/cgi?action=article;sid=20190911113856
Ideally one could change to any range of DoH resolvers - right now there's 3 or so.
Mozilla also send tons of users data to Google, and, probably, gets money/better contracts/other benefits.
Proof: https://twitter.com/jonathansampson/status/11658588961766604...
All OS vendors benefit from this telemetry, so they all have it and support it. Microsoft collects lots of data, but don't be fooled, Apple also collects lots of telemetry.
I think what folks will start to realize is that RMS was right and only free software will be the only way to navigate this mess (since users are not denied access to the source code, which can be analyzed and the idiocy removed, like people do with ubuntu).
Tools are becoming available though. Projects like PiHole are making it easier to block many malicious trackers. There are even companies selling pre-built PiHole devices. Unless HP is hardcoding IP addresses, it's only a matter of adding the required domains to a tracker blocklist (if they're not already on there) and most of these problems go away nearly instantaneously.
I've noticed my PiHole helping a lot in regards to stuff like mobile apps (Google Analytics, Facebook Graph, etc.) and embedded devices like these are probably no exception.
I went through it with a magnifying glass to make sure it didn't select anything.
In addition, I set up the IP stuff manually on the printer to ensure there was no gateway... can't get out without a gateway.
At some point, though, I noticed that "something" [0] still managed to "get out".
After running some packet captures, it became clear what was going on. Although the device was using the network settings that I had manually configured, I had not specified a default gateway. The device decided it would use DHCP to discover the default gateway for the network and began automatically using it so it could get out to the Internet.
Since then, I've started specifying a default gateway for any devices that I don't want to get out. I give 'em an IP address that isn't in use on the network and, fortunately, I haven't ran into any other instances of crap like this happening.
[0]: I really wish I could remember what device this was but it's been a long time ago and I really have no idea, sorry.
They're dirt cheap and have been for the better part of a decade. If you're looking to upgrade, cost isn't a reason not to.
• http://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a_...
• https://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a...
My printer is in a VLAN which has no route out over the Internet. (The second link there uses VLANs).
It does not protect you from compromised, malicous (IoT) devices. Think about a network printer doing ARP spoofing and MiTM-attacking your VoIP phone or IP cam. E.g. googeling immediately turns up vulnerabilities like this [1] one. A properly configured VLAN setup can help to prevent or limit this threat.
[1] https://www.scmagazine.com/home/network-security/hp-officeje...
It is not in consumer products, period. Unless you are paying me for this information (in actual money, not discounts, not services) telemetry should be banned.
So it's helpful when it's someone else's problem?
It is not helpful when the absence of competition forces you to accept one devil or another and little power (or time) to understand how your information is being gathered and used.
So what do you propose then? Every website have a paywall and block poor people?
I suppose the big problem is that everyone gets into the data broker business when they get big enough these days. It fundamentally changes the expectations of your relationship with the company.
It's a lot like the Vizio/Samsung/etc Smart TV privacy fiasco. Back when you bought a $699 21" Zenith tube television, their business model was transparently "we make and sell televisions." The up-front cost was sufficient that they weren't too concerned with a trickle lifetime recurring revenue. There's no real place in that business model to focus on a data gathering side hustle, and you as a consumer had no reason to think they'd be interested that you kept the knob on UHF all night.
Similarly, if HP's business model is legitimately selling printers and printer accessories, there's very little information they need but are not getting from their existing "what retailers order for restock" and "direct sales and ink-as-a-service" channels. Even the obnoxious personalized 'you print lots of photos, buy our photo paper' ad doesn't require remote data submission; you could calculate it on the fly locally and pop up a banner, just like with 'you've printed 29 pages, time for a new cartridge!" I could see system and document info for crash log purposes, but even that's a one-time permission request you can make on demand.
I guess what's amazing is how much the tail has come to wag the dog-- they'd rather creep out people and run the risk people finding out losing the $100-plus-years-of-expensive-consumable sale in order to get that sweet sweet consumer-profile data worth a few dozen cents per-user in quantity.
Honestly, I want to replace my arthritic LaserJet 5 with something offering duplexing and more than four real-world pages per minute, but new printers seem to be doing everything they can to be a distasteful purchase instead of an exciting one.
If you aren't interested in sharing information without selling visitors data, your service isn't viable without charge, or nobody is willing to pay you, everybody is probably better off without what you're trying to offer.
Like all those “We value your opinion” customer feedback surveys. Yeah, you value it at $0.
If you have two feature-equal printers, but one doing data-collecting and $5 cheaper than the other, which one do you think will be sold out first?
I wish that manufacturers be forced to also show default/required data requirements on their products similar to how they already display minimum/recommended hardware requirements. This would at least increase consumer awareness of the issue, at best maybe abolish it entirely...
Force manufacturers to allow third party ink and to disclose data collection and you get a much different, better for the consumer, printer market.
Tackling on edge firewall, looking what goes through, and blocking it there is second step (but since a lot of it is going to various cloud providers and cloud flare) this is often not an option
Here's what I use. There's a free tool called Windows Ultimate Tweaker. It'll help with basic settings.
Next, Du Meter - shows network traffic right on taskbar. If I'm not actively using the internet and Du Meter shows 1MB/s, I get suspicious.
Finally BWMeter. I'll say it's little snitch for Windows. It'll alert you any time an application tries to access the internet. You can allow/forbid temporarily or permanently.
They are all light on resources. BWMeter's UI isn't great but it gets the job done.
https://www.obdev.at/products/littlesnitch/index.html
And Activity Monitor in the Dock (Icon set to Network Access)
There's also Little Snitch for network monitoring.
For the rest, haven't researched much.
Its on my plate to make a go at it, with some inspiration from pihole. But really it'd be about enabling myself to use some of this great data without sharing it with a third party.
For example, I'd wear my fitbit if it wasn't reporting in to their servers. But if I force my phone through a VPN, which routes through my transparent proxy, I could feed fitbit junk data while scraping the pieces I want to my own system.
We need apps that take control of these devices and their telemetry away from the third parties.
I know there is a Linux (python?) client that will sync (at least some models of fitbit) to their cloud service. But I've no idea if there is one that will dump the data locally. It's entirely possible that the cloud client is merely passing along an opaque blob.
I was responding to a comment that was talking about creating Free Software to communicate with the device, specifically the idea of proxying access to the corporate server and modifying the communication, rather than implementing the whole protocol from scratch.
I'd guess the Fitbit protocol is encrypted, from a desire to keep people from cheating their activity reports. If a company wants to spend the development time, there is basically nothing that can be done to prevent a device requiring Internet access on a dumb-pipe all-or-nothing basis.
I do both.
I run a firewall on my phone mostly to prevent applications from communicating out without my express permission. I also don't turn on my phone's radios without connecting to a VPN that I run at home, so that all of my phone's traffic gets routed through the defenses I've set up for my home network.
On top of that, I avoid using the web on mobile devices to the greatest degree possible.
On my Android, (sadly without root) I use NetGuard for similar purposes. I blanket disallow google for many apps. I allow carte blanch to my personal servers for apps that I use, but any telemetry of theirs is stonewalled.
In Firefox I use containers to separate FB/Twitter to their own hole, while I blacklist them in uMatrix for every other circumstance.
That said, things like doubleclick and crashlytics are fine to be black listed throughout a network.
My thoughts were more targeted toward a properly sandboxed os that gives users the chance to control on a port/ hostname level what is being connected to.
I have actually physically assaulted several HP products since then. Literally nothing but aggro.
Enterprise. Not so good. Arguing with Broadcom NICs and blade chassis switch problems for a decade and a half makes me happy about AWS.
Fortunately for me I have the skills to do so. Unfortunately the majority of users have to suffer the bloatware and weep for the lost CPU and RAM that garbage wastes.
Check our Samsung or Brother for printers that don't involve bullshit. Any Asus beats any HP laptop and HP "server" gear, jajaja
The HP Spectre line runs Linux out of the box with full device support. Asus is hit or miss.
Otherwise, yes, you're absolutely correct.
And guess most of HP ProBook line. Asus sucks here, plus zero chances to get any support.
The customer needs to download and run an installer, accept a license agreement and configure a bunch of options that have nothing to do with the primary function of the hardware, then they can configure the actual hardware. In the end the user will usually end up interacting with vendor specific (or even model specific) software to manage the printer or configure print jobs.
None of that is truly necessary. Microsoft can detect hardware and provide plenty of drivers under their operating system. The typical desktop Linux distribution can do the same. In both cases, the key are licensing agreements that allow for it. Those licensing agreements are much more flexible if the software isn't collecting analytics (either for telemetry or marketing).
I don’t think that “is it OK if we have your printer collect metadata about your devices and what you print, and then use it online advertising?” is a question that HP should even be asking. They already know the answer, and all they’re really doing is giving people who have already paid them several hundred dollars for a cheap but functional printer the opportunity to make a mistake.
...is so true, and HP are far from the only culprits here.
I imagine that a user’s data is exfiltrated back to HP by the printer itself, rather than any client-side software.
To me, that's a good reason (among others) to use a print server and plug the printer into it instead of a printer with its own networking; or if you must, keep it behind a firewall with no access to the Internet. Although I have no interest in owning one, I'd be curious to packet-sniff one of these.
That's an excellent idea. I wish I'd thought of it.
I have a couple of old Airport Expresses lying around with USB ports on them. I wonder if one of them could be pressed into service in this manner.
Raspberry pis also make decent print servers
(However, a print server is strictly better if only because you just can't know what such a printer is going to do on your network!)
I don't like it but I don't know how to disable it and don't have the time to look into it.
Arguably much worse than all this is the yellow dots tracking on some colour printers https://www.eff.org/deeplinks/2008/10/effs-yellow-dots-myste...
They know that almost nobody does, so they bank on it... it needs to be regulated.
We bought a Brother a few years ago, because it supported Google Cloud Print. The idea was that my son, who used a Chromebook, would be able to easily print. The problem came when the GCP worked only for a limited time, and then stopped working a few weeks after we got the printer. I was able to set it up to work via a Linux machine and the "cloudprint" daemon, but this was supposed to be _EASY_ and it wasn't.
Assuming this was just a problem with GCP, I recommended a Brother to an Apple-using friend who was trying to decide between an HP and a Brother. She uses airprint (I'm not a Mac/iPhone person, so I never tried it). And she has the same problems with the printer just not being found as an airprint device.
Works fine with everything I've connected to it. Very basic, black and white, but it's fast and I see no reason to get a new printer any time soon. Occasionally I wish it had a scanner, but I can get away with photos. Never felt the urge to get a colour printer which pushes the price up significantly.
It doesn't do airprint directly, but most of these things will plug into a router with a USB port for network printing.
I literally print about two pages per month, and it stopped being able to suck the paper up within the first three months. It can still print pages individually if you push the paper into it manually by sticking your hands into it.
It managed to print probably six pages before it stopped working properly.
Fail.
We used the current model with USB, but it has ethernet and wifi and I have not analyzed what it tries to do with an active network connection. If I hook that up, I would give it an internal ip with no outside connectivity and see what happens.
This is what I've ended up doing. We print maybe... 3-4 times a year? So I just walk down to a convenience store where they have a big multi copier/scanner/printer you can use for 10-20 cents a page. It also does photo printing so I don't have to choose between buying a laser or ink printer.
The only worry is you know the internal harddrives in those things are holding a copy of every thing that's gone through them, and god knows how they're going to be decommissioned...
I've printed thousands of pages and am on the same cartridge that came with the printer.
Amazing printer the way most HP devices were.
There is no USB, just LPT but there are USB->LPT adaptors
I don't know if it spied on me, though.
We don’t know how the data is being sent or stored nor whether it’s being anonymised sufficiently - if at all.
I would say this kind of data snooping is software malfeasance and could really pose a serious risk to individuals and organisations printing sensitive documents on HP printers.
iptables -t filter -I FORWARD -m mac --mac-source "${macaddr}" \! -d "192.168.0.0/16" -j REJECT
Replace 192.168.0.0/16 with your subnet. You may also want to manipulate chains besides FORWARD as necessary.But all the cloud-y firmware features of the new LaserJet looked so sketchy, I decided not to connect the printer's Ethernet to my LAN.
Instead, I set up a separate little print server, which connects to the printer's USB.
Of course there are still vulnerabilities, but at least now it's not as overtly sketchy.
But yeah, USB is good enough for printers.
So if I lose my configs, these devices will simply stop working. There is no way for them to accidentally connect to my real network (since they've never known the passphrase to those).
Wifi is actually kind of better than Ethernet for this use case, since even if you set up certain switch ports to be part of a different virtual interface, if you reset to the default config they'll have full Internet access again.
BTW, reportedly, there's already at least one brand-name TV in the wild that will automatically connect to any open WiFi it can find, for the purpose of phoning home. When I upgrade to 4K, I might have to get a commercial monitor instead, or do some Dremeling.
This is why you usually just blackhole the default VLAN 1, and configure all your trusted devices to be on an non-default VLAN. Then if your switch loses it's config, it defaults to nothing working rather than a free-for-all.
But if I did, I'd use an open-source driver in Linux.
> If corporations face unfair backlash for being open about their data policies, they'll just do it in secret.
Not in EU. (citation not needed, use google)
(edit: i do not agree its unfair)
They obscured as much as possible while still complying wit the law.
Turning it off is also not easy or straightforward as the article explained.
HP became one of the biggest in the printer market without their printers collecting so much metadata.
I agree with author, this reality where everything snoops on you pisses me off.
The intention of course is to enable discussion like this.
If they start collecting data in secret they will be punished for it.
That sounds suspiciously close to extortion. "If we tell customers what we're doing and they hate it, let's stop telling them" vs "if we tell customers what we're doing and they hate it, let's stop doing that stuff".
The thing that made me decide against HP products was the change on server firmware updates (bios, management controllers, etc) that basically requires an active warranty or service contract for updates. I'm just waiting to see a wormable iLO exploit that's easy to patch... As long as you're a paying HP customer.
That had to make somebody in Palo Alto flinch.
LVFS is seeing some success in consumer stuff. I hope it starts to catch on for server gear as well. Then we can start requiring firmware update via LVFS [1] as a hard requirement in RFP's and wave goodbye to these kinds of shenanigans.
[1] https://fwupd.org/ . This uses UEFI Capsule support to distribute and install the updates, similar to what apparently Windows is also doing these days.
I almost never visit my router's web interface, and when I do it's either to reboot it because it's acting funky, or check if it needs a firmware update. There's just nothing useful there. It's absolutely packed full of totally useless information.
And yet such a golden opportunity to provide actually helpful management functionality of all the devices on the network.
I'm not saying there aren't good products out there that do this, just sort of lamenting that routers differentiate on the colorful plastic molding instead of actually helping to manage, monitor, speed up, secure, and protect my devices, and when needed, protect me from my devices.
https://www.draytek.co.uk/products/business/vigor-2862#scree...
Obviously, I would prefer to go with lower-cost third-party ink cartridges. But the printer companies tend to be doing more and more to make that a pain. With my last printer, you could use a third-party cartridge, but only after you dissected the original, peeled off its chip, and glued the chip to the new cartridge. And even then, you'd deal with the perpetual warnings about low ink even though you know the new cartridge has plenty of ink.
So Instant Ink is something we've done begrudgingly, sort of like buying overpriced movie popcorn. And in order to work correctly, it needs to be able to track how many pages you've printed, and we get occasional alerts when it gets knocked off wifi and can't communicate with home base.
Ugh dollar shave club for printers or something?
I refuse to engage in thing-as-a-service. The only reason companies do this is because they know if they bleed a little bit out of you each month you're more likely to say "it's only a couple of dollars". It all adds up costing huge amounts in your monthly expenses.
They then also know there's a huge portion of customers paying for this who aren't using their '50 sheets', so wow, they've just built a model where customers pay for a thing they don't use and they don't have to provision for.
> Please stop supporting that. That business model really needs to die.
I would up vote you more than once if I could.
As someone who used to use an electric shaver since his teenage years I wholeheartedly agree. I do not grow a beard, hate them in fact and am always clean shaven.
I never ever once got a shave anywhere near as close as I did with a razor. After a while you can do it in the shower blind without a mirror just from feel.
Those rotary ones are notoriously bad, they will cause pulling. I found the foil based ones like the braun series 3 to be a lot better in that regard, closer shave too, still nothing like a razor though.
The blades on the 195s are parallel with the foil though, while the 190s are perpendicular, so I'm sure it's the same problem.
Pulling isn't really an issue unless my facial hair is extremely overdue for a shave. eg 4-5 days worth of hair.
When that happens, I just use my trimmer to take it back to near stubble, then use the above Philishave to finish things off.
I only cut myself very early on when I was new to it. That was about 5 years ago. I have now been using a razor exclusively for years now and cannot remember when I last cut myself.
I also use it for trimming other places too, haven't cut there either.
I got given one of these https://getrockwell.com/products/rockwell-6s-gift-set after I mentioned I wanted a stainless steel one and it was given to me as a gift.
Apparently it started from a kickstarter a few years ago https://www.kickstarter.com/projects/rockwellrazors/rockwell...
The person who gave it to me knew I am environmentally conscious. I remember reading that those cartridge razors are really bad for the environment as they are a mix of steel and plastic.
Now I can just use regular razor blades https://www.amazon.com/Feather-Razor-Blades-Hi-stainless-Dou... $22 for 100.
Feels good to not be locked into some proprietary mounting too, kind of the same feeling as using free software. hah.
I prefer it to my old Gillete one. More blades is not better, that is all marketing, and they just get clogged, ugh.
I don't see how being in a "club" that I have to pay any kind of "annual" fees would help me.
The idea is I have reduced my costs significantly and have everything I would want. Occasionally I buy a new tub of shaving cream when I run out. I am adult enough to go "that looks like a nice scent I will try that", and then decide if I want to buy more next time or buy something else.
I absolutely detest "monthly" or "weekly" payments of anything. The only exception I make is for utilities, or service contracts. If it's neither of those things why should I pay more than once? or pay for someone to trickle samples out in the post to me?
Seriously though, I have a safety razor, but I can't get a satisfactory shave out of something where the head doesn't pivot, so I use the local coops budget razors. They are pretty much the same as dollar shave clubs, but I don't have it here, and I rather not buy shit on subscription.
There are two things in the home that can be reused when I am dead: my model M and the safety razor.
You can get straight edge razors, a place I went to the other day was selling them. https://www.beardandblade.com.au/collections/straight-razors
They look really expensive, but I guess you'd only ever buy one once and then just sharpen with a strop https://en.wikipedia.org/wiki/Razor_strop
I think they would only be good for 'certain' places on your body though, ie your face.
As a side note, whether one uses it or not, it should be called what it is: thing-as-a-monthly-subscrition (often automatically renewing itself).
Maybe it is just me, but to me something "as a service" is still something I pay "per use" and not something I pay a monthly or yearly fee in exchange for a given limited amount of something that I may or may not use.
There is no minimum usage level, and the fact they might know that some airlines require I print a boarding pass every few months, or some government for needs to be printed, filled out and posted - that's really not so bad for free (+ data).
I'm OK with them receiving that data.
Is this some economy ultra light printer or something? I get several hundreds of pages from each syringe refill.
I’ve grown to hate the modern ink jet printers with a passion. I moved on to the consumer laser printers. I’m sure I’ll hate them too soon enough.
HOWEVER, I was recently looking at the bandwidth stats from my network switch, and was pretty shocked to see the printer has sent out several hundred megabytes of data back to HP over the past month. I knew it had to communicate with the mothership so they could charge me for my usage, but that should be a packet that says something like "User XYZ just printed 7 pages," which would reasonably be 5kb per job. I have no idea why hundreds of megs of data need to go out, and so I'm planning of on doing some DPI investigation the to set what on the world it feels like it needs to be sending.
Actually (of course IMHO) that should reasonably be (including the percentage of ink covered/black and a validation hash) below 150 bytes.
And surely I am (more than a bit) old-fashioned, but when you can use the Doom as a unit of measure, JFYI:
https://news.ycombinator.com/item?id=13211120
then it isn't reasonable anymore.
http://www.3000rpm.com/acatalog/Epson-Continuous-Ink-System-...
I have a CIS printer and dilute even further, usually a 5:1 ratio (it becomes slightly bluish beyond that point), but even as-is 100mL will print far more than 50 pages -- probably closer to 5000 if not more. At that point the cost of paper becomes more significant.
Edit: it looks like the other colours are the same price (when I last bought ink, which was a long time ago, CMY was slightly more expensive):
http://www.3000rpm.com/acatalog/Epson-HP-Canon-Brother-Conti...
It's actually the opposite, recently all the brands have been introducing "ink tank" style printers (e.g. Epson EcoTank, Canon MegaTank) where you just squirt ink into the printer from a bottle, no DRM involved.
As a side note, I'm always surprised by how bad printer software still is(even on device). I'd be more than happy to support a startup in this space. HP, Canon etc frustrate customers by their aggressive actions to sell ink eg software updates that made it almost impossible to refill ink
I’m just forever bummed about Palm, I adored my Pre.
AFAIK Facebook spies on all Oculus usage. Every app you run on it, how often, even apps not from their store. Even not VR apps.
There is a law that a video rental store can not share your rental history. Facebook is going beyond that. Sure they know what apps I bought from their app store but they also know every non Oculus app as well. They aren't sharing it, or maybe they are to "trusted 3rd parties", but to me that's like the video rental store somehow tracking all videos I watch even ones not rented from them.
Note that I don't know that Steam and Valve are any better but I absolutely hate the idea that everything I do on my PC (or phone) is tracked.
I have no idea if Apple or Microsoft knows I watch ?? hours of video a week or what the names of the files are. Even my TV I have no idea if it reports every network connection back to Sony or that my Apple TV doesn't report similar things to Apple.
I feel like I want that kind of collection made illegal as an invasion of privacy with very large fines for non-compliance and I don't feel like my only option should be run nothing but open source software and by open source hardware.
...sigh...
Why is that option not on the table? That is the thing to do.
Instant Ink has really been a positive for me so far, and while at first I was a bit uneasy about data gathering it seems similar (and probably less invasive for my use cases) to using a Google product for example.
Truly shocking, I cannot believe they have done this.
But it's Microsoft who started all this. I remember a few years ago the would politely ask if I want to "send a report" home about a some crash etc. Now they don't bother. You need to bend over backwards to change obscure settings and still can't be sure they don't phone home. Moreover, updates introduce new privacy violations, and people only find it after installing them, so privacy-conscious people have a tough choice.
No wonder other companies stopped caring about these things if MS can easily get away with it.
1. Load up the Pi with Cups, which has a web interface, and all the optional drivers and fonts it needs.
2. make sure ip_forward is off
3. set all your printers to use your Pi as their default network gateway
4. profit?
I mean if you're holding the majority of the computer-related industry when it comes to making the software, it would be a pity to not benefit from it.
That aside, I've been thinking about what is the minimum amount data needed to identify what's being printed. For example, if you knew tbe lenght of the first X words, how many words would be necessary to identify a source? If you added the awareness of periods, how many words?
Long to short, it seems to me, simple and basic meta data used wisely could be used as a fingerprint (or sorts) to identify what's being printed without actually needing to capture the actual content.
I've heard that in practice it does get you on a blacklist and they'll start ignoring what you send, so perhaps it does have some effect.
Reading about the tool makes me kinda wanna install it ... that should mess up the targeting profile quite a bit for my ip.
HP is collecting basic telemetry, analytics, and metadata, similar to... let me check... EVERYONE.
If you've ever worked in a large company, you'll know that you need that telemetry for debugging, first and foremost.
It's almost useless for analytic purposes. Let's be honest here. What advertiser cares about the number of pages you printed on Tuesday. Give me a break.
If you worked in a large company before telemetry was available, you know it's actually possible to make a product that works out of the box, rather ship something barely working and use users as unpaid QA testers.
Technology companies should be leading the way for privacy.
You'd think it'd be very bad for business for a company like HP to demonstrate that they don't care about their user's privacy.
But they all seem to do dodgy stuff like this, selling people's privacy for cents.
Possibly the requirement to download stuff is so they can geo-target?
As in buy or salvage the imaging and paper handling hardware, add your own CPU and software.
Or maybe root and reprogram an existing printer, like an OpenWRT for printers.
For HIPAA reasons we have a Kyocera at work that does this. After each job the display shows "Erasing hard disk data" or something like that as it scrubs the buffer.