Live data from Hacker News

HomeKit

developer.apple.com

141–146 of 146 posts

Re: HomeKit

#141
post #67

Earlier quoted context omitted.

Or "I'm going to bed early, turn off all the lights". Or, "I'm having a party outdoors, turn on all the exterior lights." Or, "I'm done listening to music, turn off the audio." There are lots of use cases. But, all of this nifty tech does rely on tapping in to home infrastructure (switches and devices that understand the protocol), so it's a long haul. These devices are wired in and have 50-year design lives. The lif…

What is the best replacement for X10 stuff?

Z Wave and Zigbee are the two competing standards; swing by reddit.com/r/homeautomation for more info.

Re: HomeKit

#142
post #126

Earlier quoted context omitted.

And yet, they do deceive their users, just in subtle ways with plausible deniability (e.g. Facebook profile options related to privacy that are poorly named. Is it just a mistake, or a purposeful decision?)

Indeed. I feel a lot more deceived by the companies you named than by Apple or Microsoft. With them I know I am paying for a service or product and I clearly know where they take their profit. With Google and Facebook? Not so much. With them I feel used, induced to some behaviors because that way they can profit more and so on. I guess that's a lot more deceptive than selling high priced closed products that you can…

> that you can simply decide not to buy

There's the rub. The business of both Apple and Microsoft is lock-in. Unlike Google, their lifeblood is you buying their next device or next software release. So they are under constant temptation to take away your freedom to choose. Hence iMessage, hence Facetime, hence proprietary locked down exclusive App store, hence massive integration between OSX and iOS. Hence proprietary office formats, file systems that don't interoperate, etc etc. So sacrifice your information and privacy or sacrifice your freedom ...

If you want to be cynical enough nobody is clean, probably not who or whatever generates your income either.

Re: HomeKit

#143
post #119

Earlier quoted context omitted.

Security is incredibly important. If I give someone my WiFi password, I'd really rather they didn't have the ability to open/close my windows, turn off my heating, turn on my lights etc. Introducing such a system to the consumer domain would be the most socially irresponsible thing Apple could do. Now when your kid downloads dodgy porn and gets a virus, you don't just get a slower computer demanding your cash, your c…

Yes, security is important. What I asked was if the BACnet layer should have its own security, or if we should rely on the network security. (My router at home already gives me a 'guest' wifi with restricted access.) And no, by adding new stuff I don't mean a new standard. It's called an addendum. Which, I'm surprised I overlooked, some were made especially to address the security issues: http://www.bacnet.org/Addend…

All your points have contradicted my most important one.

We should never allow the situation in which someone who has been given access to the network (a guest, a child, ...) can be allowed to either control the BACnet components themselves, or install a trojan that can. By having no security built in, BACnet can be controlled by any device that has unrestricted access to the network - whether it be a compromised computer, a guest, etc. You can say that giving someone access to your wifi is some cardinal error, but people do it every day, and ignoring it would just give Apple a headache. In an enterprise this is manageable, in a home it is not - because Apple will have bad pr from people getting their central heating hacked, but will not be able to supervise the installation themselves. My phone is not particularly secure, no. But good sandboxing means that I can ignore the majority of network threats. If Apple programmed this in their computers as a system level program, then it would be at least as secure as (say) the keychain, which already contains enough to leave me in big trouble if it got leaked.

BACnet can use all of the network architecture around, but generally needs it to be supported in some way. For example, had BACnet used TCP - it would have been fairly trivial to get BACnet to use TLS as well, and then the security issue would have gone away.

I'm sure that all of the critical flaws with BACnet (and don't be confused, they are critical flaws) can be fixed with addendums to the standard. The problem is that then we have much BACnet compatible software that doesn't support BACnet as implemented by Apple. Again, were I Apple, I'd

- Refuse to use any BACnet device that didn't provide a minimum level of security, because it could lead to bad PR.

- Refuse to use any BACnet device that didn't operate on top of TCP at a minimum (because using TCP allows me to use (say) TLS).

- Refuse to use any BACnet device that wouldn't support both IPv4 and IPv6.

- Have to work with all the BACnet stakeholders.

- Have to make all of my software backwards compatible.

- Have to find some way of agreeing with all the stakeholders to market their Apple-compatible devices in such a way that Apple customers won't have to spend days poring over spec sheets to find out which BACnet devices are compatible with the Apple software.

BACnet is just a protocol, and a complex, bloated one - if it's flawed such that to fix it we must change it drastically, it's probably easier to just replace it. It's already clear that almost all of the devices on the market currently would not be compatible with whatever a reasonable Apple might do. Given that this might require many changes to the standard, why should they bother with all the politics when they can just do it themselves?

These flaws (believe it or not) actually negate the rest of the BACnet standard. It's a standard, yes, but it's an old one, and we can do better with the benefit of both hindsight and modern hardware. From a hardware point of view, it's probably better to use the standard - from a software or UX point of view, the standard adds nothing, but takes many things away.

As a pure point of history, BACnet became an ISO standard in 2003, work having started in 1987. TCP has been a standard since 1974, and a new standard was published in 1989. The problem for BACnet is obviously that every time a new physical transport is announced, BACnet as a standard has to add support - much effort on the part of anyone who wants to get things moving faster.

Addendums to a standard don't really hold much water, by the way. If you can just add something to a standard whenever the standard doesn't do what you want, then you lose the standardisation. Indeed, if you add anything to a standard, it ceases to be that standard (it becomes a new standard).

Re: HomeKit

#144

Earlier quoted context omitted.

How can the word "ethical" ever describe a company that gets all of its money from advertising, the business of deception and manipulation, and then deepens its pact with the Devil by trading all of our privacy for more profit and control, a company whose CEO says things like, "If you have something that you don't want anyone to know, maybe you shouldn't be doing it in the first place."? https://news.ycombinator.com/…

Eh! Don't all news corporations depend on advertising revenue? are all of them unethical?

Tell me honestly what you think of the quality and independence of news today? Why are Nielsen Ratings so important? Is news driven more by journalistic principles and pursuit of the truth, or by the profit motive?

If the truth is oxygen of democracy, then journalism is the lifeblood and distorting the truth for increased revenue is unethical.

Re: HomeKit

#145

don't mean to spam, but can the opensource world just do something better? clearly apple is going to use some super apple only thing...and always will I tried a while back, and it looks awfully similar to what apple is doing... I use it all the time, manages my lights, my server, my IR electronics, through the UI or on a schedule. Has macros, etc. doesn't have the fancy detection features although at the time those w…

Well "we" aren't waiting, lots of people set this kind of thing up themselves with a few Raspberry Pis and software like the one you linked. The reason people wait for commercial alternatives is obviously ease of installation, support, etc., but there are also some features the big guys can offer that open source just can't compete with. Voice recognition is one, what if you want to talk to your TV or set your alarm…

http://cmusphinx.sourceforge.net/

http://jasperproject.github.io/

agreed though on the nice packaging/ease of use. i'm hoping the hardware revolution can change that though.

Re: HomeKit

#146
post #143

Earlier quoted context omitted.

Yes, security is important. What I asked was if the BACnet layer should have its own security, or if we should rely on the network security. (My router at home already gives me a 'guest' wifi with restricted access.) And no, by adding new stuff I don't mean a new standard. It's called an addendum. Which, I'm surprised I overlooked, some were made especially to address the security issues: http://www.bacnet.org/Addend…

All your points have contradicted my most important one. We should never allow the situation in which someone who has been given access to the network (a guest, a child, ...) can be allowed to either control the BACnet components themselves, or install a trojan that can. By having no security built in, BACnet can be controlled by any device that has unrestricted access to the network - whether it be a compromised com…

Your criticism of addendums to standard is warranted, except the standards we use are continuously upgraded. This week's news? HTTP/1.1. How about IPv6? HTML5? CSS3? Every time something new needs to be added, we must ask ourselves if it's worth it to start from scratch.

About security, your opinion is that the private network should be considered insecure for HVAC control. IMO someone changing the setpoint of your air conditioned is the least of your worries if someone gets in your network. But you might be right, perhaps there's a need for yet another level of security. If that's the case, then we can evaluate if we can use what's in the standard, or if we need something brand new.

These flaws (believe it or not)(...)

You can keep your snarky comments, thank you very much. A year ago I was the only one on the BACnet mailing list saying BACnet should get its shit together or a giant like Google or Apple would come and eat its lunch. I know these are flaws. I also know there are ways to patch them. The question is whether it's worth starting from scratch. You know how many Apple's engineers asked info on the BACnet mailing list? Oh right, NONE.

This smells a lot like young software developers looking at a complex software thinking they can do better... only to realize later that heck, some of these complexities were there for a reason.

Some other times, it might be 'cleaner' to start anew, but the shear effort to shift an entire industry ins't worth it. Make no mistake, it's an entire industry, and a huge one!

--

Again, were I Apple, I'd

- Refuse to use any BACnet device that didn't provide a minimum level of security, because it could lead to bad PR.

- Refuse to use any BACnet device that didn't operate on top of TCP at a minimum (because using TCP allows me to use (say) TLS).

- Refuse to use any BACnet device that wouldn't support both IPv4 and IPv6.

- Have to work with all the BACnet stakeholders.

- Have to make all of my software backwards compatible.

- Have to find some way of agreeing with all the stakeholders to market their Apple-compatible devices in such a way that Apple customers won't have to spend days poring over spec sheets to find out which BACnet devices are compatible with the Apple software.

--

In other words, make your own walled garden where you can do what you want. That's pretty much the history of Apple, unfortunately. Sad days for those yearning for more open protocols.

BACnet is just a protocol, and a complex, bloated one - if it's flawed such that to fix it we must change it drastically, it's probably easier to just replace it.

MAYBE, but I've yet to see Apple (or anyone else) opening a discussion with the HVAC industry asking what's going on, what are the needs, etc.

What I do see, is a company on the brink of disregarding a standard in 3 of the biggest standard organizations, just 'because'.

Post reply on HN