1. It saturated the local network with 1TB of metadata sniffing scans, not the network uplink to the outside world.
2. It does so because, as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.
1. It saturated the local network with 1TB of metadata sniffing scans, not the network uplink to the outside world.
2. It does so because, as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.
WTF!! When did we land in the middle of a Black Mirror episode?
I'm half convinced the first run of the LHC split the timeline and we've landed in the evil one.
With just a little bit of interaction with the modern internet, the profiles created are stunningly accurate. Age, gender, political ideology, favorite food, relationship status, how many kids you have.
All this stuff gets slowly collected, aggregated and shared amongst data brokers.
People would care so much more if they knew just how invasive advertising actually is. All to try and convince you to drink one more coke or grab one more cheeseburger.
World only survives, in realities where this particular creature in containment is alive. I’ll see if I can dig it up.
https://en.wikipedia.org/wiki/Quantum_suicide_and_immortalit...
People can work around patents, or pay for licensing them etc, if they really want to do something.
At least a decade ago! The first TVs with Automatic Content Recognition shipped in 2013[0]. There was also a brief panic in 2024 about air fryers spying on people[1].
And of course practically every website you visit is doing a full session recording with mouse movements and key presses captured.
[0] https://en.wikipedia.org/wiki/Automatic_content_recognition
[1] https://www.theguardian.com/technology/2024/nov/05/air-fryer...
I worked at a major media buyer agency “big 5” in advanced analytics; we were a team of 5-10 data scientists. We got a firehose on behalf of our client, a major movie studio, of search of their titles by zip code from “G”.
On top of that we had clean roomed audience data from “F” of viewers of the ads/trailers who also viewed ads on their set top boxes. Basically any internet connected device you get is probably doing whatever it can to sniff mac addresses of your network at the least.
From a previous comment of mine:
> … my Insignia TV (best buy store brand) with fire tv built in is basically unusable. Echoing a previous comment I made too, about “smart tvs” and the “streaming sticks”: Hey, have you ever thought of why even the $149 Black Friday loss-leader no-name-brand TVs all have Amazon Fire, Roku, or are now "Smart" in some way? Certainly isn't because they need to incentivise you to connect it to the internet so it acts as a Nielsen-esq measurement device of all media you view on the screen via digital fingerprints that exist in all commercial media and advertisements. [1][2]
Doesn't Google basically make this kind of data public? I know I've seen maps by state of what people are searching for, this is barely different.
Point being, it seems absurd to compare this to snooping on people's private networks by third parties
April 29, 2016. It explains so much.
There’s no way Keurig is has the intention of paying the kind of costs required to collect a terabyte of data every two weeks for millions of people who own their coffee makers.
There must be some kind of bug here. I imagine if you unplugged it and plugged it in again the data usage would settle down.
Now I'm left wondering what this traffic actually is - assuming probe (arp/icmp) packet size of 64 byte, that's 17kpps. I don't think an ESP32 class Internet-of-Trash chip can even do that. Even bulk transfers rather than small probes would be pushing it.
Perhaps this thing found some fellow-traveler device streaming video on a port it happened to connected to?
... the linked xit says it "broadcast 1TB of data". So maybe some protocol with a much larger packet than icmp, spammed in a hard loop without any delay?
But still must be a bug.
What kind of processor does this thing have ?
Still seems buggy.
Manager: We might miss something. Since scanning doesn't cost us anything, better do it a thousand times a second!
Real world example: þe Windows registry DWORD time periods seems to invite 10^-3s granularity for totally inappropriate timescales. Perhaps its considered a "best practice" by the dick heads that decide to do these things, who knows? Why bother considering how a sysadmin might actually want to use the knobs and dials and what is an appropriate value for a parameter.
I could probably find a better example but this is recent: Smoothwall has an agent (IDEX) that you install on a Windows domain controller and one of its functions can be to harvest DHCP data and pass it onto the firewall so that it can track sessions. The upload period is a registry DWORD value.
I fixed a "problem" by stopping IDEX trying to upload data a thousand times per second. I will also point out that switching on this functionality and the periodicity setting is only applied by editing the registry - there is no GUI for this. The dReal world example -ocs are clear that you should initially set 1000 as the period.
For me that sort of thing comes under the heading of "you are holding it wrong", potential victim shaming and rubbish engineering.
The traffic volume just sounds like a bug to me.
Closed source software/hardware is a data exfiltration device first, and the thing they're sold for secondarily.
TVs, Blurays, set top boxes, MS Windows.. All of them are the same.
Selling devices to consumers is a solved problem. The problem we're currently trying optimise solutions for is selling consumers to the advertising companies.
With this particular company, everything else they do is malicious so I won't ever give them the benefit of the doubt.
I tried to use a reusable pod in one of their machines the other day and when I shut it the handle broke off leaving me rather confused. Turns out in the closing head of the machine they stuck in 4 big metal spikes to destroy anything put in there. There is absolutely no reason to do this, none, other than being dicks. Had to get out the epoxy and repair the handle of a friends machine.
So yea, screw them.
The frequency etc. leading to 1TB is probably ignorance, but that doesn't matter as it is consequence of malicious scanning either way.
I understand why a TV would keep track of what I’m watching so they can sell the data. I think it should be illegal. It’s horrible. My TV isn’t connected. But the reason they would do it fits in my brain. I can see how they got there.
How a coffee machine got to running network probes… nothing. It seems like some sort of Internet of Things DEFCON presentation topic made up by putting random words together.
So to think that on top of that they were purposefully causing so much traffic on the local network is just a few steps too far for me to think that part was intentional.
This may be working exactly as designed, as it costs them effectively nothing to constantly scan.
It might not seem to be anything (people will assume private network traffic is free) but there is a cost - it's capacity that could be used for other purposes, eg. home alarms.
Here that means no lawyers, no discovery, $100 to file in plain language, and a company employee (not a company lawyer, or a contractor, or a temp employee) must attend or they default.
$15k damages.
Reasons it could happen? Imagine grandpa has a tech come out 4 times, because his network is super slow. EG, this thing pounding his wifi for its scans.
Grandpa gets reimbursed for the four techs who came out, that's it.
Grandpa gets his money back. The company? Well, it has to spend money talking to a lawyer, because even though a lawyer can't attend small-claims court, they still consult.
They also have to send an employee to small-claims court, just have to deal with it. In the end it costs the company thousands of dollars maybe even over ten grand. It costs you a hundred bucks and you get your money back. That sort of asymmetry is beautiful, and if everybody availed themselves in small claims court, it would be far better than any class action lawsuit.
Grandpa is definitely not getting $15k in damages, and Keurig can deal with this with their in house lawyer that they're already paying a salary for. They're definitely not shelling out big bucks here. It'd be cheaper for them to let the default judgement happen than to actually show up.
Right now companies are somewhat limited in how much use they can get out their horde of private and personal information, but AI is changing that rapidly. As long as you don't mind a huge rate of error (and companies don't because it all becomes "good enough" at a large enough scale) it's basically perfect for the task of digging through endless amounts of information and spewing out bullet points.
Not in my house. What is even the point of connecting a coffee machine or a washing machine to the internet? I think my washing machine advertised that I could download new washing cycle programs in the app. Who on earth cares?
None of these are worth the spying that these companies do though.
Looks like nmap OS detection can use ~90kb per host per attempt.
Coffee machine scans network? Nope.
Coffee machine reports things about your network? Nope.
TV does ACR? Nope.
TV reports things it incidentally learns about your listening habits? Nope.
TV transmits any microphone data or things derived from mic data that aren't explicit user commands? Nope.
Companies who collect this data even though it's illegal want to sell it or use it for marketing or transfer it to anyone else? Nope.
Company A provides an SDK to company B that does this kind of thing and company B sells the product? A is liable, civilly and criminally, and B is also civilly liable to the extent that they should have and did not exercise due diligence to prevent it.
Company A, company B, and/or the end user have some contract shifting liability? Nope. The parties that the law said are liable are liable, cannot use the contract to avoid liability, cannot use the contract to recover money they have paid as a result of this liability, and cannot enforce arbitration provisions.
Anyone tries to use a contract that is considered illegal under this law? That party becomes responsible for their opposition's legal fees even if they are ultimately found not liable for some other reason.
Police wants to buy this data? Sure, they're welcome to buy what's legally available, except that they, like everyone else, will have a hard time getting the data because it's illegal for anyone to acquire it or sell it.
It's high time to get this done. We've got this and the recent evidence of LG doing all kinds of worse crap and it really should be possible to get some legislators on board.
I understand your feeling of despair. Of course I do. But you don't have to make other people despair. History has shown us where we end up when enough people despair.
If marketers cannot pay Google, Meta, etc to show their ads to people whom pervasive surveillance indicates are the appropriate targets, then they will pay companies (probably still Google and Meta and very likely still American companies) to show ads to people selected by other means. Everyone’s retirement account will be just fine.
For that matter, consider who some of the biggest offenders are right now. LG and Samsung are Korean. Sony is Japanese. (But Vizio is American and seems to be owned by Walmart.) Maybe reducing surveillance capitalism will make it harder for some of these foreign companies to extract money from the US.
There’s also the national security aspect. Right now, we expect foreign corporations to extensively spy on us. Sure, a law would not necessarily stop foreign powers from spying on us, but at least if we banned the general practice, then foreign powers who do spy on us might get noticed.
With all the hacks going on, I can't imagine why any company would even want to collect anything if they have a business model that works without it. I would think selling coffee makers and coffee pods would easily be a business model that works without data harvesting. Companies made whole businesses out of selling coffee makers alone for decades.
https://help.earnapp.com/hc/en-us/articles/38191916327441--W...
I think Bright Data is similar but I didn’t find their authoritative numbers. It doesn’t help that my ad blocker blocks their entire domain.
This shit needs to be banned, now!
That still doesn't make any sense. If they want to collaborate to build an advertising profile, your public IP is all you need. Otherwise if they're not collaborating, what's the plan, find 0days in random IOT devices and hack them? I might be concerned about random chinese IOT devices doing that, but not devices from western companies.
Data brokers are buying from multiple sources because maybe a home has a keurig but not an LG tv. Or an LG tv and not a keurig.
The plan for the likes of Keurig is "These data brokers will give us free money for data from our coffee machines? Where can we sign up!". It doesn't even matter if the money translates to $0.01 per unit sold. That's probably the most disgusting part.
Right, but OP's premise is that putting everything on the same LAN is somehow even better for the manufacturers/data brokers/ad networks/whatever, which doesn't make any sense. The only thing that actually matters is a device with internet connection.
Client isolation would help, but it also breaks some devices.
Are there decent daemons that allow me to allowlist which broadcast traffic to permit?
Ideally it'd be compatible with IPv6-only clients on my LAN.
I've heard that they put it in IoT devices, free Android apps that people use on their TVs, free phone apps, games, prob lots more.. The companies advertise it like its super safe only legit normal people borrow the internet from these people but then in fine print it'll say its not our responsibility etc.
What I have been wondering is - since they don't seem to care or check what people are using the "residential ip's" for, what happens when someone does a bunch of illegal stuff on some random person's home IP and ends up raided by cops?
I feel like the world is going in these directions.. the excuse is always "well, they clicked Yes on the Terms of Service! They agreed to it!"
Legislators are cheap to purchase
Why not? iirc some of the smart TVs have been shown to find open wifi networks on their own and upload data. (I'm not sure about that though. But it's plausible and undoubtedly will be implemented some day).
I could also see some kind of partnership with ISPs to use their "public" WiFi hotspots[1]. This seems more likely since it's (probably) harder to honeypot but requires making regional deals.
[1] https://www.highspeedinternet.com/resources/is-your-router-a...
Why you would give a coffee maker access to your WiFi is the real question,
Besides, did you see how he was dressed?
Since most appliances now contain a general-purpose computer, it would be unfair to say that a device is incapable of hacking or hosting malware, because any device with the given sensors and radios and capabilities can be essentially reprogrammed at any time.
So, if we're looking at smart TVs with cameras and microphones and Wi-Fi and Bluetooth and all the connectors, or if we're simply looking at a an ordinary network device, they all fall under the umbrella of general purpose computer, and there is no way to trust their maker, or some equally capable programmer, not to turn them malevolent in some future update.
I don't view this as an issue of terms of service or of software or of your manufacturer. I view this as an existential and fundamental problem with dropping general purpose computers into your home and behind your DMZ.
Consumer operating systems like Windows and Apple have all kinds of countermeasures against this malicious use. But without the proper introspection and without the proper safeguards, a device that looks special purpose but is in fact general purpose is far more dangerous.
Sensors/access is unavoidable, otherwise the device doesn't actually do anything useful. The point is it sets the scope for what the device is able to affect. When people say "set up a separate IoT VLAN" (that still has Internet access) this is basically what they're addressing - how a device can access other devices they may care about more.
Internet access is the catalyst that's created this whole dumpster fire - I don't care about the proprietary software on my keyboard/mouse/UPS/monitor/GPU/etc to nearly the same extent. I've got some TP-Link plugs that I control local network only. They don't get Internet access, so no updates, telemetry backhaul, etc.
The authority to update/configure/change that software is the crux. With proprietary software, there are no cuddly kittens period. Here we've got a case of a "legitimate" company choosing to be a bona fide attacker to increase their bottom line! The harm was exacerbated by a bug causing it to run amok, but even without the bug they are deliberately violating trust.
But even libre software can fall to security holes as well. Meaning you want to centralize the attack surface as much as possible, for administration's sake of keeping updated. "Internet" of things is basically the direct opposite of this - postulating many illegible fine-grained links between devices on different networks. Whereas really need more like the Home Assistant model, where peripheral devices may communicate over the network, but it's only ever over the local network. Think how ethernet is set up when used in industrial control networks (or at least how it should be set up, hehe).
I don’t actually think that applies to coffee makers spying on people though. People shouldn’t be expected to understand how computer networks or ad tech spying works in the same way that literally any child or idiot should know the difference between a lion cub and a house cat.
How do you feel about thermostats? Are some things worth it? I've had a "smart" one for the past five years, part of a new furnace install, that I've stubbornly refused to connect to my wifi. Of course this means if we forget to turn the heat down while no one's home, there's nothing to be done about it.
The device is dead simple. No advanced electronics. Nothing complex that can break. Just a coffee maker fine-tuned to near perfection.
The only flaw it has is the handle for the pot. I've resorted to replacing the plastic handle with a fancy walnut one I made myself. I needed that because we tilt the pot sideways to fill the reservoir with water (because of the placement on the kitchen counter and the cabinets above), and that plastic handle is not designed for sideways stresses.
Like the people who reply to nigerian emails have already been pre-qualified by 1) ignoring the misspellings and 2) replying.
Makes me think of DraftKings. You take your average 20 something sports fan - drinking beer, watching the game. And, on the other end of that smartphone display exist some of the most complex algorithms ever designed by teams of mathematics / statistics PhDs and it's deliberately built around targeting... this one guy from Florida who is pretty sure his team will be up by 7 at halftime.
Maybe it's more of a morbid joke, but it makes me laugh to think about.
It's an accurate explanation.
so if you know that a user is having an affair, you might want to serve divorce lawyer ads (I'd imagine those are very expensive) or something.
this kind of data though is just like a cog in the machine, but it can e.g. give enough info to know how many people likely are in that household, and so on. useful when combined with other signals
It can also correlate it with geolocation data. Google, for eg, sniffs all broadcasted SSIDs with their StreetView cars. If you can pick up on a SSID (or any of the MAC addresses of the other devices), you can buy the data set that includes it which further pinpoints demographics given the neighborhood AMI.
You can also build behavioral profiles patterns based on things like, for eg, if a baby monitor model is present or a robot vacuum, if certain devices only connect at certain times, etc.
I think the general rule for adtech is that profile guesstimates just need to be around 70%+ fidelity to determine if a sale can be made.
Lastly, you can also just sell the data on the gray market. The more datapoints, the higher the price. Most consumer product companies do that since we have little-to-no data privacy laws and the people who seem the most aware of it also are generally very apathetic and disinterested in advocating for them.
For example, your aged mother's phone will get pinged within X meters of an urgent-care facility, or she'll do some web-search about "hip pain", and then all the adult children start getting ads about elderly-parent-care.
Or perhaps the pervy-panopticon decides some phone-on-wifi events look like adultery, and both suppposed spouses start getting ads for divorce lawyers, private investigators, or track-covering products. (Bonus if certain specialized "adult" toys are detected on Wifi or Bluetooth...)
it's probably even more dystopian now with phone apps vacuuming up every last dreg.
Scale it up - make that millions of homes. Now there is godlike strategic value. Esp when "borrowed" by 3 letter agencies.
If you have even very crude data from somewhere else for the targeting, improvements in attribution tech are actually the more important factor. The adtech company mostly doesn't even care who you are, just whether the ad turned into a purchase or not, and that's where a lot of the invasive tracking comes from. They'd be perfectly happy with a quickly changing "identity" if they knew it was reliable and stable between ad and purchase.
Because the article is also full of 238 advertisers.
Yeah, sure, the terms of service probably say that they can do that. That's still in "unconscionable" territory. And courts do not like unconscionable contracts. If it's unconscionable, it's invalid (if I understand the law correctly).
Is this why everybody wants to make appliances with wireless?
Customers are gonna get lost in the sauce and skip right past all of that and toss the packaging.
Which raises in my mind the obvious defense, which is that if you try to put four or five of these devices on your network they'll be too busy interfering with each other for them to actually spy on anything.
Let the wiretaps wiretap the wiretaps. Keeps 'em busy, makes 'em feel like they're doing something important.
> What is my purpose?
You wiretap the wiretaps wiretapping our wiretaps.
> Oh my god.But why do they need to collect 1 TB? Sounds like a lot of redundant/doublicated entries then for a small network?
its LGs glass in LG household, and now Keurigs kitchen
The people that said LG isn’t the only company doing invasive data harvesting is sadly correct.
How did we as a society let it get to this point?