Live data from Hacker News

Vendors must start adding physical on/off switches to devices that can spy on us

larrysanger.org

31–40 of 200 posts

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#31
post #27

To suggest an alternative, all devices capable of internet communication must allow their traffic to be decrypted by their owner (how that password gets set is up to the individual device). This would allow owners who care to set up a man in the middle and confirm that all outgoing (and maybe even incoming) traffic to the device is what they expect. Any outgoing message that is not decryptable or not expected would b…

What you’re describing is possible and is done currently in corporate environments by forcing devices to accept a self signed cert that allows companies to spy on their employees traffic.

Haven’t seen anything for the home market yet, and I’m not sure how you’d get a consumer IOT device to accept your cert.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#33
post #16

Earlier quoted context omitted.

What's the brand damage from the resultant public shaming of e.g. Google Nest Guard' 'hidden' microphone?

That's different. While still very bad, one is omission, and one is full-on deceit.

How meaningful is brand damage when a company has a quasi monopoly in multiple markets?

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#34
post #23
post #21

Earlier quoted context omitted.

Where’s it been shown that Amazon Echos spy on you?

The purpose of a knife is to cut. You simply trust the wielder of it, perhaps more than you should.

This entire branch of the discussion is being buried in downvotes, but that is actually a very good analogy. Except in the case of Alexa, it's like you are holding the onion and someone else is slicing it. With a very sharp knife.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#35
post #27

To suggest an alternative, all devices capable of internet communication must allow their traffic to be decrypted by their owner (how that password gets set is up to the individual device). This would allow owners who care to set up a man in the middle and confirm that all outgoing (and maybe even incoming) traffic to the device is what they expect. Any outgoing message that is not decryptable or not expected would b…

What you’re describing is possible and is done currently in corporate environments by forcing devices to accept a self signed cert that allows companies to spy on their employees traffic. Haven’t seen anything for the home market yet, and I’m not sure how you’d get a consumer IOT device to accept your cert.

Stick all your IoT stuff in a private VLAN and use a MITM proxy to decrypt / recrypt everything. I have yet to find a consumer device of any sort that lets you easily swap out SSL certs. Even the devices where it’s possible to set up LetsEncrypt will usually get overwritten by firmware updates.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#36
post #27

To suggest an alternative, all devices capable of internet communication must allow their traffic to be decrypted by their owner (how that password gets set is up to the individual device). This would allow owners who care to set up a man in the middle and confirm that all outgoing (and maybe even incoming) traffic to the device is what they expect. Any outgoing message that is not decryptable or not expected would b…

What you’re describing is possible and is done currently in corporate environments by forcing devices to accept a self signed cert that allows companies to spy on their employees traffic. Haven’t seen anything for the home market yet, and I’m not sure how you’d get a consumer IOT device to accept your cert.

Doesn't work for apps which check for more than the certificate validity, for instance public key or the signer as well.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#37
post #23
post #21

Earlier quoted context omitted.

Where’s it been shown that Amazon Echos spy on you?

The purpose of a knife is to cut. You simply trust the wielder of it, perhaps more than you should.

Analogously, the purpose of an Echo is to listen.

A sheath is an off-switch for a blade.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#38
A vendor who doesn't like it could just make it very inconvenient to use the on/off switch, for example by making it take a very long time until the device becomes available after it has been turned off using a switch. Thus users would be strongly discouraged to use the switch.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#39
post #28

This sounds similar to the "do not track" setting in browsers ... which was respected by almost no websites. Why would it work this time? (Physical switch or not)

"Do not track" is kind of fundamentally misguided because it's physically impossible to verify and amounts to just another bit of tracking information.

Physical switches are physical and auditable and if the switch is audited to work, it works.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#40
The 1st-generation Echo has a hardware microphone cut-off, but I've never seen confirmation that the Dot (or any later variants of Echo) continue to have a hardware cut-off.

I'd hazard a guess that once the public seemed relatively unconcerned about Echo snooping on them, the hardware cut-off would have been removed for cost reductions (alongside the twist-to-adjust volume control).

Post reply on HN