Live data from Hacker News

More awful IoT stuff

mjg59.dreamwidth.org

201–210 of 245 posts

Re: More awful IoT stuff

#201
post #74

Earlier quoted context omitted.

Lost its power? This is just copyright apathy. Nothing new, especially in China. Look at it from the manufacturer's point of view. They know how expensive this would be to take to China and prosecute and they know they're a tiny fish. It's simply a reasoned gamble that saying no is the fastest, most efficient way to get this dealt with. Much easier than auditing the code, having the developer separate out sensitive d…

This makes me wonder how imports are handled. If I can buy a third party power supply from a US based order system (amazon), and this ps is dangerous (eg. those knock off Apple power supplies). How is this legal, presumably the device hasn't passed safety regulations here. So, there must be some way to stop this product from entering the country. Why isn't that mechanism happening? Same applies for this device. If a…

There are mechanisms for policing (certainly in the UK) this but:

- Containers are MASSIVE. Seriously. You can fit hundreds and hundreds and hundreds of thousands of plug-sized widgets in a container.

- Millions of containers leave China every day.

- People lie about certification, provenance, component specs. Even if you do test one, the next 999,999 are probably all using shitty capacitors.

- There are many ports that don't all share data.

The only stuff that gets refused are where you have repeat offenders coming into the same port with the same dangerous stuff.

And yes, MPAA and other trademark bandits with all the cash can pay to police this stuff. It isn't fair... But I'm not sure the world would have the appetite for absorbing the costs in import tax. A testing container of plugs would push the price up way beyond $30 a unit and that's testing 1/1000.

Demanding certified manufacturing might be an option but that's expensive for China so they'll resist (or do a job equally shitty as the plugs they'd be supposed to police).

Re: More awful IoT stuff

#202

Earlier quoted context omitted.

Lost its power? This is just copyright apathy. Nothing new, especially in China. Look at it from the manufacturer's point of view. They know how expensive this would be to take to China and prosecute and they know they're a tiny fish. It's simply a reasoned gamble that saying no is the fastest, most efficient way to get this dealt with. Much easier than auditing the code, having the developer separate out sensitive d…

I'm also curious how many manufacturers (especially of questionable-quality products like this) simply don't bother to read and understand the licenses of the OSS they're using. I suspect it's a lot.

Pretend that you knew you could get away with not paying tax or keeping records. You might get an email from the IRS but in this imaginary world, they only prosecute the biggest cheats.

I'm sure you're a fine person who would keep paying but do you think everybody would because it's the right thing?

That's all that's happening here.

Re: More awful IoT stuff

#203
post #198

Earlier quoted context omitted.

IMO: this is actually a good default setting. Home-router designers should assume that things are hostile by default. Of course, it should be dead-simple to turn this off as well.

I pretty vehemently disagree. We should be very reluctant to systematically break good things to protect badly written junk. Let badly written junk burn. Then people will learn it's junk and stop using it or the developers and vendors will be forced to fix it.

Isn't it more like having a median barrier?

It's unnecessary if everyone drives competently, but it also successfully prevents people crashing through no fault of their own.

It also breaks or complicates use cases like "changing which direction you're going on the highway".

Re: More awful IoT stuff

#204
post #175

Earlier quoted context omitted.

We've been using the term "endpoint hostile" to describe how networks are typically deployed, especially with IPv4. "Endpoint hostile" networks are designed with a single use case in mind: accessing remote servers, usually via HTTP/HTTPS. Other use cases are prohibited or broken. Here are some of the characteristics that would label a network as endpoint hostile: - "Device isolation," which prohibits local LAN device…

This is exactly why the use of a remote server exists in so many IoT devices. Widely deployed home APs, even in USA, come with device isolation on by default or even not disableable.

I'm surprised that device isolation is common on home APs. Wouldn't that break some fairly mainstream things like Chromecast?

Re: More awful IoT stuff

#205

Earlier quoted context omitted.

What do you think of this. I'm producing it: https://www.facebook.com/kokonautweathersensors/ It's not using my network, but it's hackable enough that you can use it on your own network if you know how to flash it yourself.

Is it open source? that looks pretty rad. Are they available to purchase? Any plans for other devices?

What would you use this device for?

I haven't released the code for it yet, but there are plenty of tutorials online. It's using NodeMCU and a DHT11. If there's more interest in hacking the device, I can provide some blogposts or tutorial videos.

There are 5 available and 15-25 more are on the way. Please contact me if you're interested. I'm planning on selling it for around $35 and for the first few batches at $30 (as an early adopter discount). Email: antoniuschan99@gmail.com

For personal uses, I have a waterproof temperature sensor coming in, and plan to use that for my aquarium, so maybe I will produce that version. Also I am tinkering with electrical outlets that can be remotely triggered. So you can set the weather alarm to trigger appliances.

Re: More awful IoT stuff

#206

I just blogged about this yesterday. In short: > The line in the sand for me is: network vs cloud-based systems. I want things to be network connected, but I want it for my own network only. I want to be able to control my coffee pot, but only from home. If I choose to expose this over the internet, great! It's up to me to make sure it's secure. I don't want anyone making that decision for me. I also want it to be up…

So totally this. I refused to buy a Nest for exactly this reason. In the words of the Cluetrain manifesto: 'We are not seats or eyeballs or end users or consumers. We are human beings - and our reach exceeds your grasp. Deal with it.'

I'm not here to be monetized by being glued to the hip to your infrastructure that may go away for any number of reasons (technical or non) and make my property suddenly stop working.

Re: More awful IoT stuff

#207

Earlier quoted context omitted.

It's absurd that an IoT device contacts a server hundreds of miles away when I'm inside my house turning on my lights via wifi.

Apparently this is kind of a hard thing to handle. I battle with this and PS4 Remote Play -- about 80% of the time, RP will give up looking on my local network and go out to the internet to find my PS4... which is right here on the same network. If I cancel it and retry a few times it always ends up seeing it but man what a pain.

Same with the way Xbox One Streaming works. At least Sony has set up some kind of NAT traversal to allow proper remote play.

Re: More awful IoT stuff

#208

The principal reason devices need to be connected is so that business can hold your devices ransom and charge you money to use them. Turn on lights with a phone? No need for Internet. Open doors with a fingerprint? No need for Internet. An auto-adjusting energy-saving thermostat? No need for Internet. A fridge that knows the milk is low? No need for Internet. Charge people money to use their toaster? You need the Int…

I would say the principal reason they need to be connected is because consumers expect it. But yes, some unscrupulous businesses will take advantage of that. People need to vote with their money and not buy from companies that do this.

Re: More awful IoT stuff

#209
post #130

Earlier quoted context omitted.

I'd love a list like that as well, but sadly I don't think one exists and I don't think there's any money in doing it. Nobody wants to hear about good IoT devices, they want to make fun of bad ones and feel superior, that's what sells clicks. Maybe i'm just being cynical...

I think you nailed it: hackers don't want to write blog posts saying "damn, this thing was pretty well made". Perhaps an open-source effort to document & track what work has been done, even if it's just pulling firmware images and taking a look around. Maybe some kind of gamification to motivate researchers to pull things apart and report what they see.

I'll write one when I find something worthy of it. I've got stupidly high standards though.

I've bought everything from wireless hard drives to $250 Wifi routers to $20 ethernet/3G bridges and the quality of the firmware is pretty garbage on all of them.

I see brand new devices on kernel 2.4 and 2.6 with no upgrade plans in sight, and hacked up kernel trees that have no chance of building except on the developers' Red Hat 9 (!) workstations.

http://www.devttys0.com/blog/ is another good place to follow. I guess it's more fun to write a negative article, not to mention it gets a lot more views.

Re: More awful IoT stuff

#210
post #198

Earlier quoted context omitted.

IMO: this is actually a good default setting. Home-router designers should assume that things are hostile by default. Of course, it should be dead-simple to turn this off as well.

I pretty vehemently disagree. We should be very reluctant to systematically break good things to protect badly written junk. Let badly written junk burn. Then people will learn it's junk and stop using it or the developers and vendors will be forced to fix it.

So you're in favor of Grandparents getting cryptowall from someone else connected to their WEP-encrypted wifi because screw them for using Windows XP and a cheap router? Off-switches for things like this are cool, because people who need them will find them, and people who don't won't.

This is remarkably similar to defeatable traction-control; people who care enough to figure out what that button does will push it and have fun. People who don't won't and they'll be safe.

Post reply on HN