Three recent papers uncover the extent of tracking on TVs
twitter.com
twitter.com
I'm not saying I'm perfect, like I said I have a phone and a router, and I understand at a point I can't hide certain things, i.e. my ISP can see what I'm pulling on the net and I find it's not worth the hit to convenience to try to scrub or obfuscate that info, but man, one guy I know has an Alexa in every room in his house! Another has IoT'd his place upside down with various Chinese equipment that is collecting who-knows-what data and sending it who-knows-where, and it's not that I have a problem with it, but they don't even think of the privacy implications when they buy these things.
I try to live my life as if I'd become president one day and the CIA/FBI/NSA would use everything in their power to find something heinous they could use to destroy my life, and also so that I don't have to worry about my future children having their entire life uploaded from birth to death because of mistakes I made in the technology I buy. It keeps me humble and skeptical of new hardware and I truly measure the impact it has on the privacy of myself and those around me, but I wonder sometimes if it has no affect because they could always build a profile based on how I've intereacted around others' technology
It was very very freaky to say the least. I've beefed up all my security credentials and deleted a lot of my social media accounts as well. Most of what I do online now is pseudonymous.
Lots of people say stuff like "I have nothing to hide" but trust me, you definitely do. You don't want people to know your first and last name, your address, where you work, your phone number. There are criminals out there that will try to rip you off any second they get and try to pull all sorts of tricks to get access to your money. The level of effort I saw in these attempts was significant and I could see how lots of people could get tricked by it. I would say that all of the attempts from the calls to the e-mails were custom written specifically based on the information they knew about me.
In hindsight, this is all my fault. I was too trusting of big tech companies putting my information out there for all to see and now I am paying the price for it.
No amount of security best practices on your part can save you from these sorts of attacks.
Eg, scammers are now scrapping haveibeenpwned.com, then matching it with all the other publicly available information. I imagine non-geeks easily believing the extortion emails I now routinely receive.
I guarantee you that if brand X would have explicitly stated what they were doing the outcry would have ended it all rather quickly.
They have nothing to fear or lose. So that one guy gets his promotion while everyone's privacy is sold for pennies.
I recently lost a domestic argument over Google Home Minis in my kid's rooms... we just sound like conspiracy theorists, even in this post-Snowden era. The response is a shrug of the shoulders more often than not. Honestly it's just going to be played out. The masses will need to get screwed badly before we collectively wake up.
I'm opting to simply prepare myself for the fallout, like rampant identity theft, loss of privacy, lack of objective / critical news coverage, etc. As an example, the SASS service I built and run does absolutely zero user tracking / analytics, anticipating that some day this will be appreciated.
You could use a VPN if you wish to avoid that.
Generally, I agree with you and wrote about my thoughts:
https://austingwalters.com/the-last-free-generation/
My concern is really that we wont have any kind of freedom in the years to come. There's pretty much nothing you can do. Only thing we can kind of do is provide some privacy, sometimes...
As far as the forces go, the first and biggest force should probably be the legal one, companies generally can't lie or mislead while advertising or entering contracts. If a VPN company advertises that they don't keep logs and it's discovered that they keep logs it's a pretty good case for a claim against the company to get out of the contract at the very least. This all depends on specific countries, VPN companies involved, what claims those companies are making, etc. It should be noted that an employee doesn't need to leak anything for this to be the case, if the VPN company is involved in a public court case then it can be inferred whether they actually keep logs, this has been the case with at least one company.
The second force tends to work in favour of the VPN company and is the market forces involved, generally you might only have a handful of ISPs to choose from if you even have a choice as you could be stuck with a single cable company for instance. This isn't the case for VPN companies as you have literally thousands to choose from and they can be located anywhere in the world, and while this might not be a big deal if you're from a first world country with good network infrastructure and regulatory environment already it'll be a bigger deal for people living outside of these countries.
The third is somewhat related to the second, there's obviously a use case for privacy focused VPN companies whose value added product is simply to provide a good service and there's more than enough people that will want to make a business out of it. This is obviously the case for ISPs too where their value added product may be technically competent staff and ensuring that they'll uphold your privacy and won't engage in censorship, etc, but again access to these ISPs may be limited.
Also, you're still trusting Amazon to play by the rules, which is unlikely if state actors are involved as the comment (which spawned this discussion) insinuated
I had to tunnel dns through openvpn to make dnssec reliable.
On a wifi router, there's loads of leakage; mdns, ntp, things devices do to check for captive portal, weather apps, etc etc.
You can mitm https, but breaks hsts sites, unless you hack your browser
Although I pay for ProtonMail, this year I started using gmail again for almost everything - I found email search and automatic calendar integration compelling, especially for travel arrangements and keeping organized while traveling.
I am starting to regret the switch back to gmail because I am slipping on privacy for the sake of convenience.
EDIT: as a self labeled liberal, I find Kevin Williams very conservative politics somewhat disagreeable, but I still find his new book “ The Smallest Minority: Independent Thinking in the Age of Mob Politics” well worth reading and has slightly changed my viewpoint on the importance of personal liberty.
In the larger context it's easy to forget that good compromises are available, it doesn't have to be all surveillance or nothing at all.
It's a smart move. It's more likely to happen during a regime change, shift in popular opinion, etc where a group is labelled unpopular, not to be tolerated, and/or dangerous. That has happened many times in my life. Then, the Patriot Act passed letting them black-bag people for torture flights or hold them indefinitely due to what they claim to find via secret surveillance whose methods aren't peer reviewable ("classified").
(And you're not getting any of the benefits those technologies could have; worst of both worlds).
You'll get away with using a internal combustion engine. You'll be fine.
But you are harming me and everybody else.
Forbo's answers points it out.
> Chances are I probably won't invite you.
Can't you come up with a better argument?
My take on this is that I can't miss what I never had. Knowing myself, once I get used to some convenient tech it's hard to go back. I got my first smartphone only two years ago and even then consciously restricted my usage by basically just using it like my old phone plus email and a browser. No WhatsApp, no cloud services, no voice assistant.
And every now and then when visiting a friend or colleague I'm amazed to see what's actually possible with modern tech if you fully embrace it. So I just fiddle around a bit out of curiosity and that's it.
It's stupid anyway.
Will DNS over HTTPS help mitigate this?
And I honestly think that I'm taking the lazy approach because I'm not overly concerned about being targeted, just caught in dragnets. Anybody practiced and willing to put in a few hours of work could own me. I could own me, so I know it's true. People who aren't technical with software, hardware, and web architecture just have no chance.
Also, you can easily intercept traffic over wifi. You can even do that while switching off GSM.
You can investigate cell traffic with an SDR.
https://en.wikipedia.org/wiki/Video_Privacy_Protection_Act
Even the amendment in 2012 seems to make it only legal to add a function "share" functoin for a user to post what they watched on a service. It does not seem to make it possible to just share all viewing info. It also does not make it possible to just add it to a EULA or TOS.
So the TV company would probably argue that it's not a violation if they don't know your real identity. Even though they share the data with an analytics company that does.
But the only way to really answer the question is to litigate.
Typically circuit splits end up in the Supreme Court sooner or later. So if it does come up it'll be some pretty expensive litigation.
Watching TV is a social activity - gathering at a friend's place to watch a new episode, or relaxing with family.
The future implied by these developments is that TV-based tracking will take the home audience into account, and the screen becomes -- in some sense at least -- a camera as well as a display.
Instead of being shown subtly inadequacy-leveraging ads on your own device, now they're going to be interwoven into you and your family's home in such a way as to influence thoughts and opinions.
Gradually adtech will - as it has already - erode the ability to have peaceful, genuine social human interaction while enjoying an artist's intended work uninterrupted.
I'd like to think that alternatives to advertising finance are on the horizon, because the ad business seems to further income inequality. Adtech employees deny and avoid their guilt by enjoying the profits they make, while their audience (who are increasingly also their acquaintances, as peer-based referrals and influence marketing heat up) are pressed to spend and consume, often unnecessarily.
I'd wager the trend towards ads and quantified influence is going to continue until it necessitates radical change.
NB: In reality the capability likely already exists to target ads based on who you're currently with, so this is really just an opportunity for the advertising industry to socialize and normalize these practices.
At the end of the day, there are a lot of limits on how successful any ad campaign can be. How much budget your target has, how elastic it is, how much demand is inherent to the product type.
Even with perfect 24/7 targeted advertising, Toyota's maximum possible upside is selling me one Camry every two years. Once they reach that point, any further marketing spend is wasted.
There's also the problem of advertising being imperfect. We'll always have faulty data, and importantly an trustless adversarial relationship with the consumer, which will limit the ability to improve ad effectiveness. (Imagine the opportunity to say in one central place "I have bought a widget, everyone I researched with can discontinue the widget post-visit campaign as there's no further chance of victory"-- advertisers wouldn't go for it and consumers wouldn't believe it). I also suspect tighter and tighter targeting increases the risk of catastrophic ad failure-- where it undermines the brand's reputation or creates public backlash. The Uncanny Valley can be one hostile place for brands.
Do expensive, high-tech ads outperform cheap spray-and-pray techniques like TV spots and dumb banners? Probably. But I suspect the price-performance curve is approaching an asymptote pretty quickly. Billions are spent to chase increasingly small gains in actual sales over older, less creepy techniques. Someone's going to do the numbers and start asking questions.
With perfect information about how well an advertising campaign works, you can convince the rest of the org to spend up to 100% of the profit margin of a sale on enough marginal advertising to drive one additional sale.
In other words, the end state is measuring ad performance well enough that spending on ad buys wind up cannibalizing all the corporate surplus generated from them.
Not necessarily. Growing their brand and making it more trustworthy has intangible benefits, but they do exist. The idea is to make you feel better about their company.
Ads maybe but phones are personal as much as your contacts list and metadata leaks.
> I'd like to think that alternatives to advertising finance are on the horizon,
It will never happened because alternatives wont scale.
My current practical requirements: Lately, I mostly watch movies and series from borrowed Blu-ray and DVD discs (which turned out to be a better catalog, IMHO, than Netflix's streaming catalog at the time I switched). I also want to occasionally play PS4 online multiplayer games on the same display.
I didn't want the PS4 to be phoning home when I played the discs, so I found a model of Blu-ray player that does DVD 1080p upscaling, but which still doesn't have WiFi. I did a final firmware update of the (EOL'd) Blu-ray player over the Internet, and then have a policy that the player will never be plugged into the Internet again. (Again, this is mostly an on-principle exercise, and, so far, it's proven practical for me. I've encountered only one Blu-ray implementation bug, which is known lockups of a very small number of titles in 24p mode of some players, and which never got a firmware update anyway.)
(Before the Blu-ray player appliance, I tried using Kodi for playing DVDs, first with a laptop, and then a RasPi 3 setup, but that worked poorly.)
I paired the airgapped Blu-ray player with a nice older Sony 1080p TV with decent integrated speakers, and which had no WiFi, and was not new enough to be fully "smart TV" obnoxious. It has a nice picture, and works well with the Blu-ray player's remote over HDMI. To get this one, I had to do some research, and then do daily searches on CraigsList for a while.
The two main drawbacks to the older, less-smart TV are that it's not 4K, and that it's power-hungry. (20W off, 90W to display no-signal screen, peaks to 140W+ even in a dim room.) For saving the 20W when off, I'll probably move the TV to a secondary position on a smart power switch, but I've hesitated, because I don't know whether the TV was designed for frequent abrupt power cuts, and, if I wear it out prematurely, finding a similar replacement model on the used market looks increasingly difficult.
When I eventually upgrade to 4K or whatever is next, I suspect I'll probably end up getting a non-TV commercial display without Internet, and a separate audio amp and speakers.
Maybe I'll also be forced to give up on borrowed discs, and switch more to streaming, which I suspect will be locked-down with anti-user hardware and software, and (unless regulation really steps up) fraught with excessive corporate surveillance and other misbehavior (and possible attendant vulnerabilities, due to the complexity and methods).
There are some open source media player things I'd like to build, if I can ever spare the time again, but those might be precluded by the available (legal) consumer-hostile media methods at the time.
[0] https://www.lg.com/us/monitors/lg-43UD79-B-4k-uhd-led-monito...
In theory, HDMI-CEC might make it possible to control everything with any device's remote. My TVs are too old for that to work properly though. The receiver should come with a universal remote, which may work for you. I'm happier with the logitech harmony non-touchscreen remotes; model 665 has a nice shape, and the screen is useful for picking activities amd using functions that are hard to map. The configuration software is torturous, however. If you're using an IR remote like the harmony 665, you'll want to group components for easier aiming.
I have a 6+ year old dumb panel that has S/PDIF and RCA "audio out" connectors.
I run HDMI from a Pi to my TV, then S/PDIF to a receiver for full surround sound. Volume control is either done through the TV remote or Kodi, the receiver stays on 24/7. With CEC, the TV remote can also control Kodi.
My setup is a stereo receiver plugged into the display's stereo out. A Linux desktop, RPI4 (for Kodi), and a PS2 (via a component->HDMI converter) all plug into the display, so all audio is device->display-> receiver, except for the PS2 which is optical S/PDIF. All HDMI devices end up on the same channel on the receiver.
I keep the volume on the receiver at a pretty neutral level, so I don't often use the receiver remote, instead using volume control on the display remote. Of course, when I want to play CDs/cassettes/records I can't use the display remote...
If anybody has any recommendations for a good universal remote, I'd love to hear them! Nothing I've found works well with my receiver (HK 3490). Of course, I also don't want the remote to have WiFi or Bluetooth.
Next time around I'm planning on going the monitor/commercial display route too.
It's like buying chips and candy, few care about "nutritional value", and most care about a twist of taste.
* "We" figuratively; I don't have a TV for last 20 years, and so do likely a number of readers. Not a large enough number of consumers, though.
For now the TV owners (if you can even call it ownership) can work around by not connecting them to the internet (and using an Apple TV or some open source system for streaming), but individual streaming providers on that will still track you, so it’s a small win. And if enough people did that, manufacturers would just stick a cellular modem in to bypass the WiFi network.
I don’t see a solution to this short of comprehensive privacy legislation.
People have been litigating this for a while, and the best Google and Apple have come up with is prompting you for permission to access your camera.
That was a form of collective bargaining, and that was the result, I just don't necessarily believe that a congressperson's staff is going to do a better job than the monopolist platform holder.
T&Cs really just seem like a way to ensure that the company can get away with every abuse of the consumer that's arguably legal. In some cases, e.g. credit bureaus, there isn't really a way to opt out of signing their T&Cs without also opting out of modern society.
Without a government that's actually interested in protecting consumers, it's a moot point.
If anyone's curious, here's more detail.
Opting out of credit bureaus is actually not possible. One can opt out of pre-screened offers of credit (https://optoutprescreen.com/, https://simpleoptout.com/#lexis-nexis), can lock your credit to prevent credit checks, and can opt out of some of data sharing, but financial institutions have safe harbor to release information to credit reporting agencies under the Fair Credit Reporting Act (https://www.law.cornell.edu/uscode/text/15/1681).
The Gramm-Leach-Bliley Act requires financial institutions to let customers opt out of disclosing "nonpublic personal information to a nonaffiliated third party" (https://www.law.cornell.edu/cfr/text/16/313.7). That constraint would be fairly reasonable, except that there's giant additional carve-outs (https://www.law.cornell.edu/cfr/text/16/313.14, https://www.law.cornell.edu/cfr/text/16/313.15). The biggest things that no one can opt out of are "(3) To provide information to insurance rate advisory organizations, guaranty funds or agencies, agencies that are rating you, persons that are assessing your compliance with industry standards, and your attorneys, accountants, and auditors;" and "(i) To a consumer reporting agency in accordance with the Fair Credit Reporting Act (15 U.S.C. 1681et seq.)."
This is true even if one has never requested, been extended, or will ever request credit. As you noted, the only way to "opt out" would be to only receive or pay cash for everything and forgo modern society.
The root cause is FCRA's overly broad scope. Instead of allowing credit applicants/recipients and credit providers to establish an equilibrium that works for both parties ("Want credit? Okay, opt in to credit reporting from your other vendors and then we'll review your application"), FCRA forcibly opts everyone in.
You've probably seen this form before: https://www.ftc.gov/system/files/documents/rules/privacy-con.... Those FCRA carve-outs are why "Can you limit this sharing?" always says "No" for the top few rows.
How so? AFAIK Apple and Google did not negotiate those solutions with organisations that represents users (such as industry ombudsmen, consumer rights orgs etc), that scenario would qualify as collective bargaining IMO
Yes, that's what GDPR is all about, you need informed consent (not just yes/no) and also the collection of data needs to be related of what you are trying to achieve (that's almost never the case with tracking).
In the office I’ve taken to calling connected TVs a security concern, but I didn’t realise how right I was. The conference room TVs there are currently connected (before my time) but I’ll be disconnecting them next week.
I can't help but wonder if it's intentional. It did get me to connect the damn thing, despite my severe misgivings.
Has anyone else noticed the same thing?
Would not be surprising to see Comcast/TW/Charter/$ISP would strike a deal with TV vendors to provide a wifi network on the ISP-provided routers just for the TVs or other 'smart' devices [2]
Start watching out for cellular connectivity in TVs as yet-another-phone-home-vector too [3]
[1] https://www.reddit.com/r/security/comments/bpjky4/worried_ab...
[2] https://www.xfinity.com/support/articles/about-xfinity-wifi-...
[3] https://venturebeat.com/2019/05/01/huawei-reportedly-plans-f...
I didn't buy them for that functionality, but was hoping that someone would figure out how to root them - AFAIK though that still hasn't happened.
https://www.theverge.com/2019/1/7/18172397/airplay-2-homekit...
Meat of it starts @15:58
My intention is to keep my TV offline right from the start, but maybe I'm screwing myself out of useful (display) firmware updates?
But yeah I'm with you that's it's excessive and needs regulation.
> [...] you should have a general picture of what goes inside it: CPU, Memory, GPU, Northbridge, Southbrige, Cellular radios, Other radios [...]
> [...] Such is the case with the Snapdragon S4 from Qualcomm, which has an embedded LTE modem on board responsible for 4G LTE connectivity [...]
Good luck!
> Here’s a doozy: Roku has a “Limit Ad Tracking” option. Turning it on increased the number of tracking servers contacted It did prevent Roku’s AD ID from being leaked, but a whole bunch of other unique IDs are available. Even Pi-hole wasn’t that effective at limiting tracking.
At some point, I'll probably get a larger one.
And for sound, a 100W per channel amp driving a pair of ancient JBL L96s.
Drives me insane buying a device and for it to get slathered with ads six months later.
I wonder if you could DIY a set-- buy the panel and a controller dumb controller board and bolt it together yourself? I know someone did that back when the "import an off-brand 27" LCD monitor for 1/3 the price of the Apple equivalent" was a trend.
built an HTPC that's connected via HDMI that i can use for youtube, netflix, plex/kodi, NAS, etc.
basically a dumb display.
i should actually intercept the traffic to double check.
The solution? connect the TV to internet (in a rural area), wait overnight so it can download the Terms and Conditions without any indication that this is what it is trying to do, sign the T&C and then it works...
How does it know what I'm watching? Is it analyzing the feed like Shazam to music?
Recently an old friend crashed on my couch for a week, bringing such a device. He couldn't download any new books from the library while staying. On the last day of his stay we didn't have anything better to do so we researched that problem. After some googling we actually found a long thread in some forum where people had all kinds of problems with a recent firmware update which didn't actually seem to be the problem here, but then there was some guy in this thread casually mentioning that he solved it by disabling his pi-hole. And yes, indeed, that immediately fixed the problem in our case too.
Let that stink in: You pay for your e-reader. You pay a monthly subscription. And then they dare to require you to send your data to googleanalytics.com, a foreign company, and don't even show a meaningful error message if that doesn't work (too embarrassed?)
Does anyone have any recommendations?
Seems like a good policy now.
You also get to demand access to your data and can instruct them to delete it (and they must or run afoul of the law).