It doesn't make sense to tie the lifespan of a display to the lifespan of software support when the computing hardware is so ubiquitous outside of the TV anyway.
While the advertising / data sharing revenue is valuable to them, the vast majority of those are going into homes where they're going to be internet connected already. The cost of a modem + service fees for it wouldn't be worth it for most of them.
Amazon is starting to ship their Sidewalk protocol[1] which will be embedded into a bunch of their devices - but that seems to be mainly for low-power/remote devices to connect back to a Sidewalk access point, rather than to provide an alternative data-path for (say) customer metrics.
I do not agree with any of that, though.
Consider the beancounters at the manufacturer:
We are shipping a SmartTV, we expect our users to therefore have internet access, because the device is mostly non-working without it.
Why would we then include: a cellular radio AND make us pay for a cellular data service on an ongoing basis? Is the data from some small fraction of users who don't already have wifi valuable enough to pay off the hardware and service costs in every other TV? Seems unlikely.
Look at how much an ESP32 can do and what it costs.
At scale, the cost of the additional electronics is negligible, especially if it is being subsidized.
Nobody is making you pay for service. It will simply send back fingerprints of your screen image and usage data, and can probably load ads, as well.
You'll note though that getting a Kindle with 3G nowdays means paying for the more expensive models - Paperwhite or Oasis.
> Nobody is making you pay for service
I think you missed what I said. I was talking from the perspective of a manufacturer.
The cost of buying and integration the new hardware, and also an ongoing monthly sim cost for the benefit of getting analytics and ads from a tiny fraction of your userbase that does NOT already have their TV hooked up to wifi is significant, and I doubt it comes close to the added revenue you might get from that fraction of users.
That also assumes that those who don't have their Smart TV hooked up to wifi are going to be in cellular range.
I think what'll really happen is they'll become always online devices where if you're offline for more than X days they quit working and claim they need an update - please connect to the internet.
Some of the technologies are specifically intended to give "phone home" connectivity to low-power devices: https://en.wikipedia.org/wiki/Narrowband_IoT https://en.wikipedia.org/wiki/LTE-M
Bonus: This way, you don't have to worry about open wifi networks.
I live near a BK, my TV could dl some auto auth for the wifi and just upload my habits... if it wasn't specifically chosen to reduce that probability.
How is it possible that your TV could automatically log into your wifi?
Where I live I can see a few dozen networks active. At any one time at least a few are public.
Don't connect your TV to the internet, buy an Apple TV.
Giving google my viewing habits is bad, but giving Hisense + DodgyAdBroker.biz + CCP/PLA is even worse.
My understanding is that lots of them aggressively sniff and try to hop on any unsecured network that they can find.
Is that legal where you are, assuming your neighbour has not granted permission to do it?
AFAIK, violating the CFAA would involve actively circumventing a mechanism intended to restrict access.
This is a field that cries out "decent regulation". Terrible IoT security? Please see massive fines, Senators on TV claiming national security at risk, never allow that brand to be sold "on our soil" again.
I know there is no obvious technical framework that can be applied as " best practise", that IoT is a horrible wild west and governments choosing winners will lead down sub optimal paths but it's hard to see a real alternative fix.
>The European Telecommunications Standards Institute (ETSI) has released what it calls a globally applicable standard for cybersecurity in the Internet of Things (IoT). The new specification, TS 103645, seeks to establish a security baseline for internet-connected consumer products and provide a basis for future IoT certification schemes. https://futureiot.tech/europe-gets-first-global-consumer-iot...
Maybe if that works other places will follow.
This conversation happens on HN every week, and each time, commenters point out the numerous flaws in this plan:
Manufacturer requiring a firmware update or internet connection for the TV to work, quietly connecting to internet over HDMI, connecting automatically to neighbour's unsecured wifi, shipping with an internal cell modem, and many other methods that might be around the corner as privacy norms drift and certain technologies become cheaper.
I tend to go with US-based companies because they would legally be liable for damages, which would in theory mean they'd be less likely to knowingly ship malware and security disasters.
Either your devices and hub don't need to be exposed to the net (so why are you even using a router connected to the web?), or they do.
If they do, it's because that's how you control them, via the web. If that's the case, it doesn't matter what network your phone is on; command and control is done via the web.
Now, in terms of infecting each other, sure. But the point is to keep my data devices and such separate from my IoT devices. Yes, the whole IoT infrastructure may get infected and need a purge, but my goal is to keep infection of those from getting, say, my banking information. And yes, it assumes that the command and control app is reasonably secure, but that's a whole different issue (and one reason why I would rely on Amazon or Alexa as a hub, and not some random no name company).
I'm curious if you have suggestions for a hackable home automation/IoT hub that I can use without giving it access to the internet. I'm happy to DIY anything that doesn't deal with mains voltage.
[0]: https://www.home-assistant.io/ [1]: https://hubitat.com/
Homebridge: https://homebridge.io HOOBS: https://hoobs.org
it should be automated, you have controls in the house that trigger actions, ie a door opens, or a light switch is triggers.
If I have to use my phone to control it, I have failed at automation
I have a small arcade in my basement and the ability to control the lights from my phone would be way better than using the wall switch, mostly because of outlet placement and the fact the switch has to stay on.
My living room only has one switched outlet and it is the one closest to the switch. The lights across the room have to be manually controlled.
I've done some research into wifi controlled outlets and I have some very old radio controlled ones but I need more. Do you have any suggestions for hackable wifi plugs that do not connect to the internet? Maybe something that connects to a hub?
My dream would be something where I can make my own sensors and talk over wifi to outlets that are UL listed, without involving the internet. I'm happy to DIY anything that doesn't interact with mains voltage.
Zigbee/Zwave is controlled via Nortek USB interface connected to a rPI
Though I do have a couple of Shelly Devices, and some custom ESP8266 things
With Black Friday/Cyber Monday coming up I’m trying to compile a shopping list of good gear.
I am not sure under what legal basis you draw this conclusion given the EULA's and other laws explicitly shield them from said liability
you would have to prove intentional malicious intent not simply negligence
One of the big problems I have with more US Companies is they are a network of vendor Lock-in proprietary ecosystems that often do not work well together at all.
I prefer Open protocols, which sadly seem to be only adopted by non-US Companies.
Let's say the customer connects their own Wifi router to the ISP modem/router via Ethernet cable. There is no need for the ISP modem/router's Wifi AP. Does the ISP modem/router allow the customer to disable it?
what exactly do you mean? I tought piHole sits "between" the tv and your modem? I mean it probably can easily firewall those ips.
Edit: nvm PiHole is only a dns thingy.
So if say your TV calls out to backdoor.example.com - then PiHole can block it.
If instead it calls out to 1.2.3.4 (i.e no DNS lookup) - then PiHole won't block it for you, you'd have to instead set up controls on the firewall/router/etc to filter traffic.
Wanted: Firewall blocking all traffic directed at IP addresses not obtained from OS DNS resolver.
aka dynamic application level FQDN Egress Filtering. Mayor Cloud providers (aws, azure) and bigger firewalls (fortinet, cisco, paloalto) already offer ~half of what I want.
I want a little deamon that listens for DNS queries/replies and modifies firewall rules accordingly.
So, it could still bypass piHole and still resolve hostnames.
At the router level, I then forced all 8.8.8.8 traffic to be transformed into traffic to my pihole.
You can do the next step, but you need a router that supports it and the patience to handle it.
You shouldn’t need to do this.
So, if it is using HTTPS for DNS resolution, I don’t know how you would block that.
If you could install a self-signed cert onto the device, you could MitM the HTTPS traffic and see what it is doing.
By filtering traffic sent from that particular device based on a query to your DNS filter to approve or deny the destination address. (Some implementation work probably required.)
For example, iOS to Apple, mac to Apple, Win10 to MS, etc. These connections are much difficult to ban nowadays. What we could do might be limiting their upstream connection via physical firewall router with built-in good web-based GUI.
AT&T pushed an update that added an "Application Statistics" page to the router which keeps track of ports and sites visited and is basically hostile to privacy.
thing is - this is a rented router, so what can the customer do?
Also every time they push an update wifi turns itself back on. So I go in and disable it and then I get a giant warning email "AT&T wifi gateway settings updated".
Or someone to create a standard where the Panel is now working more like a Monitor and All electronics are into a separate box.
There's no winning with IoT.
There's no winning when a third party controls the lowest-level software of a thing on the internet. That includes your general purpose computers.
Unless you are the owner of the signing keys down to the bottom of the stack, your system can be remote-controlled.
By a stand-alone Roku for apps?
Apple TV is what you want if you don’t want to have your data/viewing habits sold to outside companies.
YouTube or Netflix or whatever can still do whatever they want with your 'viewing habits'.
The top device on my network being blocked from reaching it's mothership are my Roku devices. This is the top analytics from my NextDNS console for the past two weeks:
scribe.logs.roku.com 417,115
stats.gc.apple.com 24,752
ssl.google-analytics.com 16,178
track.sr.roku.com 7,534
Roku is easily on the top of my list on spying devices on my network. The Apple ones, while still worrying, are on a network with tons of Apple devices between phones, MacBooks, watches, iPads, etc whereas there are three Roku's making all that traffic.