Why printers add secret tracking dots (2020)
bbc.com
bbc.com
- Required me to install an app
- Required me to enable gps on my device (and allow app to access)
- Printer phoned home after / during setup (as did the app)
They really don’t need the dots any more when they know the gps coordinates and have the ability to send anything they want to and from the device.
I personally spoofed the gps, ran a vpn and blocked the device from phoning home (after setup). Had me saying “what the f**!?” a couple of times.
Solved
We're well into that era, but neither the technological protections nor the legal ones have kept up.
Tech laws are still barely on the level of requiring manufacturers of network devices not to use the same default password every time and manufacturers of kitchen appliances to accept some basic "right to repair" provisions. These are steps in the right direction of course but they are small steps at the start of a marathon.
I think a lot of political leaders fail to appreciate the danger here. This has somehow remained true even as tech crime is rocketing. We are seeing more and more headlines about how some aspect of critical infrastructure has been brought down due to some form of technological attack, businesses have lost money due to data losses, people have had their identities stolen after data breaches, etc.
Meanwhile, the tech firms best placed to defend ordinary people and businesses against these kinds of attack are often the ones carrying out the attacks. The fox is guarding the hen house.
Just yesterday, there was a news story in the UK[1] about some home car charging stations being vulnerable to simple attacks. These devices get connected to both home networks and electricity grids. The specific models in question were government-approved too.
I think typical open-by-default networking is fundamentally broken today. It's like software for non-experts that doesn't have the option to install security updates automatically, or a browser or mobile OS that doesn't sandbox web pages or apps individually. Professionals use many tools to lock down organisational networks, audit and manage connected devices, and deal with modern challenges like bring-your-own-device, and they still get hit from time to time. Meanwhile home users are basically expected to install a new Trojan every time they buy a new device. This is not going to end well.
The Brother printer I have attempts to hit some static IP in Japan for firmware updates, unencrypted http. So while on some OSes, you can use it without installing a drive, on MacOS, your desktop will automatically download the vendor's software indirectly from Apple. That is why installing printers is a separate permission as it updates system level components.
The only immediate solution I see to this is to have a protocol level firewall say running on an RPi that firewalls the printer off and intermediates all communication between the devices on the local network and the printer.
It seems that on some Xiaomi models, VLAN can't be configured but its firmware is based on OpenWRT, so it can be enabled by hidden API. So maybe SoC itself supports it but manufacturer disable/don't enable it.
I would really like to know if there's a good printer manufacturer that makes simple, high quality printers that just work, don't require all these needless hoops, and respect the customer. Sounds like there should be a market for that, and yet somehow all printer manufacturers seem to suck.
A lot of wifi problems are due to bad/flaky access point hardware. Notably, a lot of the internet recommended "good" consumer wifi gear actually sucks from a reliability point of view. It took me months to get my home setup reliable enough to take it for granted.
There should be a labelling standard for this where the manufacturer must disclose if any registration is required to operate the device to its full potential, if any app or special software is needed other than a system driver, if any phone-home data is being sent, and what data is actually sent, when and why.
"Buyer beware" but most of the time you have no idea what the experience will be like. It's usually not disclosed on the box, reviews rarely mention it and I'd like to have a sure way of being informed before I make my purchase.
It's a similar thing with software, software and apps that require registration for no other reason than add you to their marketing list, but it's particularly egregious with physical items.
Not everything is measured in dollars, and getting back the dollars spent as a result of deceitful advertising does not undo the damage caused by the deceit.
In some cases, it does. In medical trials, you need "informed consent", and not just regular consent. It doesn't matter what papers are signed, if a patient isn't informed what the trial is testing, what known side effects there are, and what alternatives there are, it doesn't count.
More relevant to this issue, GDPR also uses the concept of informed consent. Under GDPR, tracking is legal only if consent is informed and freely given. The example printer fails both these conditions. It is not informed consent, because the tracking is not prominently disclosed to the user, and merely mentioning it in the fine print is insufficiently prominent. It is not freely-given consent, because a service being conditional on acceptance of tracking means that there is coercion to accept the tracking.
My viewpoint on the ethics tends to follow somewhat close to the GDPR's requirements. Even if somebody clicked through a 50-page EULA, that does not give informed permission to track somebody, and so it is still spying.
At the end of the day it's a team of psychologists, computer scientists, and super computers against one human. It's not a fair fight. There are plenty of dark patterns to make you not internalize the tracking. So while you're technically right, no one expects to see this happen in practice because your model isn't accounting for this.
Of course it won't help when you are shopping and looking around in a store for some reason.
For printers, I also recommend pricing out five years of supplies. I bought a printer that cost 5x as much as one with similar specs, but ends up costing less in supplies.
So, yeah, it is good advice if the outcome is important to you and you dont know a better way to protect yourself from accidentally buying something like that. Unless you know a better way and are holding out on everyone?
"This device certified not to compromise your privacy" could be a good selling point for a printer, especially if half of the printers have it and half don't.
"Keep your secrets safe with Printer X".
Or would the state come down hard on any such manufacturer?
There's still Trusting Trust, but that's rather harder to pull off.
our biggest client just wants a offline ios printer driver for bouncing previews to Acrobat via the share option. ios so far off our path.. this client would talk about any OSS driver deal for commercial rates in fact they definitely don't want any unique driver to profile... we're totally lost to find resources we can understand or resources at all. for a business to thrive with critical necessities hobbled I think there's always a central crime like how drugs and spectacles frames prices shown constant price for 30 plus years.. something artificial is happening with pressure applied.
It's hard to really buy with your wallet when you don't even know you have a reason to be cautious. Similarly, it's been suggested that boycotts and "vote with your wallet" are woefully ineffectual nowadays.
It's not that consumers don't care, it's that most don't have a choice or aren't even aware of such a need
Remember what happened to the Quest CEO when he refused to allow his company to spy for NSA?
https://www.washingtonpost.com/news/the-switch/wp/2013/09/30...
Just one major telecommunications company refused to participate in a legally dubious NSA surveillance program in 2001. A few years later, its CEO was indicted by federal prosecutors. He was convicted, served four and a half years of his sentence and was released this month.Print heads are a more of a challenge, but you can buy manufacturer originals and build a printer around them.
The firmware is a big problem, but there's a lot of research in the public domain that could be repurposed.
After all of that, you need compatible ink. You'd be reliant on third party ink clones and cartridge systems.
It wouldn't necessarily be harder than a 3D printer project, but it's not trivial, and it would be hard to make it work financially.
Given a choice between an official printer that costs $35 to buy and $60 for replacement inks, and an OpenPrinter that costs $60 to buy and $35 for inks, most people will buy the former.
There is no way to force the business models to keep printing on a full cartridge that has met its page limit(per reviews on Amazon), and the salesman at a store told me brothers have replaceable parts in them now besides the toner carts that they force you to replace.
This is why I love Brother printers: I've never had to touch their software. Ever. Been buying their printers for over a decade. You pipe postscript to them on port 9100, they print it. Done. Their software could be 100% refined APT-malware, and I'm totally okay with that.
They often are not any more, at least on the software side.
Also, of course, if you need to produce really great colors (think 6-color inkjets), or really large printouts (say 3' wide), your choice is narrower.
It doesn't necessarily mean that the app accessed your GPS location.
Depending on your device, actual access might be shown, I recently installed an Epson printer and while the app needed location permission, it did not access might coordinates, it only scanned for wifi networks.
One day, the camera permission will probably have the same problem. The time of day and position of the sun can give a coarse location, and perhaps future algorithms will be able to search Google Street View to find your exact location.
So actually intelligence organizations already do this. If they have a mundane picture of an adversary they will try to pinpoint where the picture was taken. Of course there's more clues that they have because they know things about the target, but I guess I'm saying it's not unreasonable to believe such a thing could exist today.
This is why a wifi scan requires location permission.
One big question I have: "is it legal to sell a printer that requires the use of someone else's toner?". If so, then the concern about sourcing toner after the whitebox company fails can be addressed in the design stage.
What I really want to know is why there is no BYOPK whitebox TPM product. That should be easy to make and could dominate the market.
https://news.ycombinator.com/item?id=14501894
https://news.ycombinator.com/item?id=21330718
https://news.ycombinator.com/item?id=17392977
https://news.ycombinator.com/item?id=14509249
Why printers add secret tracking dots (2020) - https://news.ycombinator.com/item?id=26526035 - March 2021 (3 comments)
DEDA – Tracking Dots Extraction, Decoding and Anonymisation Toolkit - https://news.ycombinator.com/item?id=17392977 - June 2018 (7 comments)
Why printers add secret tracking dots - https://news.ycombinator.com/item?id=14505444 - June 2017 (100 comments)
Printer Tracking Dots Back in the News - https://news.ycombinator.com/item?id=14504833 - June 2017 (1 comment)
List of Printers Which Do or Do Not Display Tracking Dots - https://news.ycombinator.com/item?id=14501894 - June 2017 (210 comments)
Secret Dots from Printer Outed NSA Leaker - https://news.ycombinator.com/item?id=14494818 - June 2017 (211 comments)
Printer dots raise privacy concerns - https://news.ycombinator.com/item?id=245963 - July 2008 (13 comments)
I currently have a color laser which also works fine and is cheap but is just far too big (Oki MC625)
It's been a few years now and while I don't print enormous amounts, I regularly do need to print out forms or documents. I still haven't used up the original ink cartridge it came with.
There's also a Linux driver provided by the company for this model.
[0]: https://www.usa.canon.com/internet/portal/us/home/products/d...
Are Linux drivers still a thing? Both our current and previous printers could be used without setting up any drivers through AirPrint. The new printer also scans without any drivers through AirPrint. I'd assume that Linux can also print driverless through AirPrint?
But then once they realise they are being fooled thats a datapoint in itself.
And who knows, maybe tools like that print microcode inside the microcode. If it does I hope it’s not the full text of gpl licence.
https://www.ownedcore.com/forums/world-of-warcraft/world-of-...
With current games I go in with the assumption that I'm in a public place, and act accordingly. But back then I really counted on my Personal Computer being personal, so this feels like a breach of trust.
How many government provision contracts has Hewlett-Packard closed?
That's probably enough incentive for most to do it once known or suggested
Things like this are revealed all the time, half the public doesn't care and the other half already know we are living in a surveilance dystopia and are not surprised about it.
>The U.S. Government Agency conducted an internal audit to determine who accessed the intelligence reporting since its publication. The U.S. Government Agency determined that six individuals printed this reporting. WINNER was one of these six individuals. A further audit of the six individuals' desk computers revealed that WINNER had e-mail contact with the News Outlet. The audit did not reveal that any of the other individuals had e-mail contact with the News Outlet.
>On June 3, 2017, your affiant spoke to WINNER at her home in Augusta, Georgia. During that conversation, WINNER admitted intentionally identifying and printing the classified intelligence reporting at issue [...] WINNER further admitted removing the classified intelligence reporting from her office space, retaining it, and mailing it [...] WINNER further acknowledged that she was aware of the contents of the intelligence reporting and that she knew the contents of the reporting could be used to the injury of the United States and to the advantage of a foreign nation.
https://www.justice.gov/opa/press-release/file/971331/downlo...
In other words, it's still officially a government secret, even though everyone knows about it.
Prosecuting someone for a crime based on yellow-dot evidence could force the government to testify under oath about the yellow dots and what they mean... which could force them to answer some uncomfortable questions about how the dots got there... maybe officially admit ownership of the program... and I imagine that could open a whole legal can of worms they'd rather avoid.
The Intercept knows all of this, which is why I suspect that for whatever reasons they had, they intentionally threw her to the wolves. The Intercept is not run by dummies.
Not that I necessarily think doing this is a good thing, for the record.
I assume the note needs to have the euro constellation, if its not there the copier/printer would work normally.
Only problem i’ve had with this setup is during the configuration of IoT where mobile device must be on same subnet as IoT devices, that is all.
If we want them to be uniquely identifiable, then we don’t need to hide the identifier. If we don’t want them to be uniquely identifiable, then hiding the identifiable ID becomes a violation of the voters privacy.
Or you can register as an independent if you prefer. The rules vary by state, but the worst that happens is you can't participate in the primaries (but can absolutely vote in the final election). Who you, as an individual, voted for is still not traceable back to you.
In other words, it's your right, thanks to the secret ballot, to vote completely differently from the party you registered under or even differently from how everyone in your life perceives you, and nobody will ever know.
There are people who changed their mind years ago about what party they support and have been voting that way ever since, but just haven't gotten around to (or don't care enough to) update the party they listed on their voter registration.
Also IANAL but I feel like there must be some law about deception of this kind. Selling a product that does something you don't expect it to, were never told about, and would not reasonably even observe feels somehow like fraud.
More generally, for ballots you don't need to hide this, you could just have a number on them.
Ballots typically do have unique IDs usually on some part that is removed by the voter. The problem is that isn't linked to anything because we don't want it linked to anything. This form of auditing isn't compatible with ballot secrecy. US elections do undergo rigorous process audits but the electorial process presents challenges to results audits.
1. That each paper ballot was only counted once by the tabulating machine.
2. No extra ballots were returned with an id that was not generated.
3. Easily spot copied ballots.
You could probably audit more things. If for example the id corresponded to a county, and so on.
If the government mails me a ballot with ID #1234 on it at my home address, then they have a way of knowing that Ballot #1234 belongs to me in particular when they're tabulating the votes, which means they can find out exactly how I voted. Now we don't have a secret ballot anymore, and the secret ballot is a fundamental part of our democratic voting system; a secret ballot prevents the government from rewarding people or doling out punishment based on how they voted. It's a safeguard against authoritarianism.
(I think some US states put identifying info on the outer envelope or sleeve that the ballot is returned in, but there's a strict system to keep the envelope-opening step separate from the ballot-tabulation step, so people's votes cannot be personally linked to them as long as the system is followed. And these days there are usually cameras watching to make sure it is followed, and the footage is public.)
If you do get rid of the secret ballot then there's not much of a reason to hide the ballot ID via yellow dots. Just put "Ballot #1234" all over it and/or print a unique barcode. But regardless of whether the ballot ID is displayed or hidden, if you happen to get a dictatorial maniac into power (whatever you personally envision that person to look like) then you would be one step closer to letting that leader use personally-identifiable voting records to punish the people who voted the way he (probably a he) didn't like and/or give the people who voted the way he did like rewards or unfair advantages.
If you want to audit mailed out ballots, use two envelopes instead. The outer one will carry a unique id, the inner one will be completely anonymous and contain the actual ballot. All the auditing can be done on the outer, unopened envelopes. Then they are stripped off, all the inner envelopes are thrown on a heap and only then opened and counted.
Of course, even then, the paper ballots contain traces of the voter's DNA, so the truly paranoid will not be happy either.
The completed ballot goes into an opaque sleeve devoid of identifying information, which then goes inside of an envelope. The envelope has an extra "flap" where you put your information and signature, and then it seals onto the envelope.
When processed, the flaps have perforations that can be physically separated from the rest of the envelope and validated and retained for audit purposes, and later on the collection of sealed envelopes can be opened and the ballots counted without having any attached personal information.
> popularity contest driven by peer pressure
No, it's so people can't sell their votes, or be told by their parents/employer/local gangs that if they don't verify they voted correctly, they will be hurt. It's not cancel culture or popularity contests or whatever. Voting is definitely supposed to be a popularity contest based on peer pressure.
The process should be well known since all it takes to find out is go sit in an election committee.
But this article seems to imply that the yellow dots also occur on black-and-white printers. How is that possible?
Then the jury must select the "not guilty" verdict since "has_yellow_dots" evaluated to false.
-HN Legal Reasoning
On that page you can see that on the caption of the same image the printer is identified as an "HP Color Laserjet 3700". The BBC journalist or whoever wrote the captions simply wasn't very precise and probably didn't mean to imply that the yellow dots are produced by black-and-white printers.
Your printer uses 10-100x the ink these dots require just by powering it on when it has to do a flush. These make effectively zero impact.
Source: I am an inkjet print engineer, but also just common sense.
I had no idea my printer used any ink at all during startup.