Live data from Hacker News

Vendors must start adding physical on/off switches to devices that can spy on us

larrysanger.org

51–60 of 200 posts

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#51
post #22

It's too bad there's not a company with enough funding and incentive to make equivalents that don't need to phone home. Ones that are competitive in price, functionality, etc. The recent HN post about Mozilla's IOT offering was encouraging: https://news.ycombinator.com/item?id=19695595

While that would be ideal, I don't personally mind the phoning home if it only happens after the wake word and if the cloud service greatly improves the response capabilities it might otherwise have. Yes, the word can be heard by mistake, but that's just the risk trade-off I make. I think a physical off switch would be good. At the moment I just unplug my Alexa if I'm particularly concerned it might hear something se…

What about having a home router which had a visual alert to all outbound traffic from connected devices to their locations.

Super freaking simple to implement.

And if it were a page that you could just toggle the ability of the stream flow by clicking on it... to create the FW rule instantaneously and stop that flow.

You pull up a dashboard and see all your threads. If you see a thread from [phone]-->[Facebook] and you can just disable that stream. (Where [Facebook] is a list item of all the known FB addresses etc)

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#52
post #27

To suggest an alternative, all devices capable of internet communication must allow their traffic to be decrypted by their owner (how that password gets set is up to the individual device). This would allow owners who care to set up a man in the middle and confirm that all outgoing (and maybe even incoming) traffic to the device is what they expect. Any outgoing message that is not decryptable or not expected would b…

What you’re describing is possible and is done currently in corporate environments by forcing devices to accept a self signed cert that allows companies to spy on their employees traffic. Haven’t seen anything for the home market yet, and I’m not sure how you’d get a consumer IOT device to accept your cert.

I recommend setting up a pfSense box with squid proxy and a self-signed root ca. It can decrypt essentially everything; works great.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#53
post #33

Earlier quoted context omitted.

That's different. While still very bad, one is omission, and one is full-on deceit.

How meaningful is brand damage when a company has a quasi monopoly in multiple markets?

Nest Guard is a monopoly? Or were you referring to something else? I also think a lot of this is completely non-essential (e.g. Nest Guard). I do not have any such "smart devices" at home, and encourage others to do the same. They provide, in my opinion, very little benefit for a great sacrifice. And all that aside, they're just too dang expensive. I don't see the point of spending $600 on a machine-learning toaster.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#54

Earlier quoted context omitted.

I like the way the lens works on the new Lenovo Thinkpad camera. It slides sideways, thereby blocking the camera. That's how I like to see it done

It would be awesome if the physical sliding of the lens lid was also the physical circuit of the mic. So if closed, the Mic could not EVER function as it would have been physically disconnected.

It's a good idea, but I think a separate switch might be better. I might want to talk on a non-video normal call (most of what I do) or record something but not use the camera, and would want to keep it shut. I think many other people might use the microphone separately from the camera as well.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#55

Meh. Houses still have windows, and people still have binoculars, but we seem to get by fine with blinds. Tape over your webcam, unplug Alexa, or turn off your phone if you want more privacy. More importantly, there is a social norm that you don't look through people's windows with binoculars. Of course police, spies, or creeps might do it, but that's incredibly rare. Unfortunately, the social norm (and business mode…

then give them something quite indigestible and toxic to stare at rather than a blank nothing.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#56
post #4

Note that a physical switch can be overridden just as easy as a soft switch, the vendor can just put a soft switch in parallel with it and you would never know it. The hard switch could turn off the display, speaker etc. while the processor and radio can stay on.

the printer/scanner/copier at my workplace needs about 30 seconds when you press the physical switch to actually switch off, it's more of a command than an actual switch

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#57
post #50

Janie Crane: “An off switch?” Metrocop: “She'll get years for that. Off switches are illegal!” —Max Headroom, season 1, episode 6, “The Blanks” https://www.maxheadroom.com/index.php?title=Episode_ABC.1.6:...

a real life blank reg here. I live in an RV operate a MESHNET and do everthing i can to foster a common persons free decentralized infrastructure. As mentioned elsewhere ive been taping cameras and stabbing microphones for years now.

Thank you for your service.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#58
post #4

Note that a physical switch can be overridden just as easy as a soft switch, the vendor can just put a soft switch in parallel with it and you would never know it. The hard switch could turn off the display, speaker etc. while the processor and radio can stay on.

I thought lying about such functionality to consumers would be illegal. I feel that if you sell me a device with the explicit promise that “off means off”, then bypassing that would be.. false advertising?

Is that true? Assuming they’d market it that way, originally?

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#59
post #35

Earlier quoted context omitted.

What you’re describing is possible and is done currently in corporate environments by forcing devices to accept a self signed cert that allows companies to spy on their employees traffic. Haven’t seen anything for the home market yet, and I’m not sure how you’d get a consumer IOT device to accept your cert.

Stick all your IoT stuff in a private VLAN and use a MITM proxy to decrypt / recrypt everything. I have yet to find a consumer device of any sort that lets you easily swap out SSL certs. Even the devices where it’s possible to set up LetsEncrypt will usually get overwritten by firmware updates.

Right, but how do you decrypt the vendor's encryption? That's why I think you'd need to be able to provide a second key, because if vendors give out their decrypt key they may as well send it all in plaintext.
Post reply on HN