Live data from Hacker News

Vacuum bricked after user blocks data collection – user mods it to run anyway

tomshardware.com

41–50 of 174 posts

Re: Vacuum bricked after user blocks data collection – user mods it to run anyway

#41
A good time to point out https://github.com/Hypfer/Valetudo.

I haven't tried it personally because my particular model of vacuum has some complicated and potentially destructive procedure to get the required access, but there's quite a few models where it can be installed easily.

Re: Vacuum bricked after user blocks data collection – user mods it to run anyway

#42

Earlier quoted context omitted.

>>>>> I expect the moment unsolicited data collection becomes a liability manufacturers will drop it like a hot potato. Possession of the data needs to be illegal. Here's how it could work. It's similar to how copyrights for music are enforced. A person whose data are found in someone's files or server can sue for "statutory" damages, which are levied on a per-offense basis.

What are the odds individuals learn their data has been found. What kind of damages could be awarded that would make hiring a lawyer and giving them 50% of winnings a worth while effort? I could also easily see individual cases combining to become class action reducing the winnings even further. In other words, I find this a silly suggestion as it's just never going to work in the real world.

I seem to find out my data has been leaked in a breach every other month. I don't even care if I actually get the money for it, let it go to the class action lawyers. Life is good so long as the companies pay more than they make by holding the data.

Re: Vacuum bricked after user blocks data collection – user mods it to run anyway

#43
post #12

Earlier quoted context omitted.

This is a cool article, and neat he got it working in the end. One thing that is odd - if he blocked it calling home, it doesn't make sense that the kill code was issued remotely. It makes more sense that there is a line of code internally that kills the machine when it can't call home (which would be far less malicious).

> It makes more sense that there is a line of code internally that kills the machine when it can't call home (which would be far less malicious). Would it be? Whether the line of code is on the server or the device, what's the difference?

[deleted]

Re: Vacuum bricked after user blocks data collection – user mods it to run anyway

#44
post #12

Earlier quoted context omitted.

This is a cool article, and neat he got it working in the end. One thing that is odd - if he blocked it calling home, it doesn't make sense that the kill code was issued remotely. It makes more sense that there is a line of code internally that kills the machine when it can't call home (which would be far less malicious).

> It makes more sense that there is a line of code internally that kills the machine when it can't call home (which would be far less malicious). Would it be? Whether the line of code is on the server or the device, what's the difference?

If you bring me your silverware from the kitchen, or I go into your house to take it, what's the difference?

(CFAA charges)

Re: Vacuum bricked after user blocks data collection – user mods it to run anyway

#45
post #29

Probably a felony under the DMCA. I'm reminded of when AWS us-east-1 went down and all the beds made by EightSleep (business model: Juicero for beds) became disabled. EightSleep put all the significant control for their beds in the cloud, doubtless because they couldn't or didn't know how to hire embedded engineers, and the only devs they could find were node.js flunkies who only knew how to do cloud. Looks like the…

"Never attribute to incompetence that which can be attributed to malice" or something.

Clearly automatic beds have some degree of embedded software. The decision to put the controls in the cloud was certainly a conscious one.

Re: Vacuum bricked after user blocks data collection – user mods it to run anyway

#46
post #29

Probably a felony under the DMCA. I'm reminded of when AWS us-east-1 went down and all the beds made by EightSleep (business model: Juicero for beds) became disabled. EightSleep put all the significant control for their beds in the cloud, doubtless because they couldn't or didn't know how to hire embedded engineers, and the only devs they could find were node.js flunkies who only knew how to do cloud. Looks like the…

And what the company did is a felony under CFAA.

Re: Vacuum bricked after user blocks data collection – user mods it to run anyway

#47
post #23

Earlier quoted context omitted.

Depending on where he lives this might be illegal. Yes, we live in a cyberpunk dystopia where the manufacturer can break what you bought and then send you to jail for repairing it. You can read more about it here: https://consumerrights.wiki/w/Digital_Millennium_Copyright_A... This shit is absolutely dystopian. The law must not just be reversed, manufacturers need to be taken to court for shoddy software. Insecure da…

There's an exemption from Section 1201 for "Computer programs that control devices designed primarily for use by consumers for diagnosis, maintenance, or repair of the device or system".

That's news to me. Do you have a source for that I can look at? Not being snarky. I would legitimately like to read more about this.

Re: Vacuum bricked after user blocks data collection – user mods it to run anyway

#48
post #12

Earlier quoted context omitted.

This is a cool article, and neat he got it working in the end. One thing that is odd - if he blocked it calling home, it doesn't make sense that the kill code was issued remotely. It makes more sense that there is a line of code internally that kills the machine when it can't call home (which would be far less malicious).

> It makes more sense that there is a line of code internally that kills the machine when it can't call home (which would be far less malicious). Would it be? Whether the line of code is on the server or the device, what's the difference?

He implied they were remoting in after he blocked network traffic. It could easilyl be a standard exception handling approache when it can't call home and fetch latest settings etc. It might not be malicious - not defending the architecture, just think that there is an assumption of intent here.

Re: Vacuum bricked after user blocks data collection – user mods it to run anyway

#49
post #46
post #29

Probably a felony under the DMCA. I'm reminded of when AWS us-east-1 went down and all the beds made by EightSleep (business model: Juicero for beds) became disabled. EightSleep put all the significant control for their beds in the cloud, doubtless because they couldn't or didn't know how to hire embedded engineers, and the only devs they could find were node.js flunkies who only knew how to do cloud. Looks like the…

And what the company did is a felony under CFAA.

Yes, I was thinking he needs an attorney to file suit against them for intentionally damaging his property, and then charge them for the 'repair' which would be the months he probably spent fixing it at a top grade engineering salary.

Re: Vacuum bricked after user blocks data collection – user mods it to run anyway

#50
post #23

Earlier quoted context omitted.

Depending on where he lives this might be illegal. Yes, we live in a cyberpunk dystopia where the manufacturer can break what you bought and then send you to jail for repairing it. You can read more about it here: https://consumerrights.wiki/w/Digital_Millennium_Copyright_A... This shit is absolutely dystopian. The law must not just be reversed, manufacturers need to be taken to court for shoddy software. Insecure da…

>>>>> I expect the moment unsolicited data collection becomes a liability manufacturers will drop it like a hot potato. Possession of the data needs to be illegal. Here's how it could work. It's similar to how copyrights for music are enforced. A person whose data are found in someone's files or server can sue for "statutory" damages, which are levied on a per-offense basis.

>Here's how it could work. It's similar to how copyrights for music are enforced. A person whose data are found in someone's files or server can sue for "statutory" damages, which are levied on a per-offense basis.

That's not how copyright lawsuits work though. For the typical person torrenting, it's because they were caught in the act of torrenting (eg. they had a torrent client in the swarm connecting from an ip that was assigned to them). Otherwise it's a DMCA takedown and companies don't even bother suing. Nobody is getting their hard drives searched for illegal music and getting sued as a result.

Post reply on HN