Live data from Hacker News

Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

varlogsimon.leaflet.pub

131–140 of 227 posts

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#131

Earlier quoted context omitted.

Can you expand on this a bit. It was my understanding that you're telling the bank to pay the vendor (from your money/credit). In that case, the bank certainly needs to know about the transaction... so it can make the payment. Are we talking about 2 different things here?

I suggest researching how ZCash uses zero-knowledge proofs to allow paying money from your balance to another person's balance without any middleman like a bank being able to decrypt your transaction, while still allowing everyone to verify that important invariants are maintained, such as not allowing you to spend more money than you have. This is what it takes to make a financial transaction E2EE. I'm not saying th…

Doesn't the anonymous-ness of crypto/zcash make it impossible for the bank to handle fraud (reversing of charges and such)?

My understanding is that banks, at least in the US, need to have fairly extensive knowledge relating to all transfers of money, both for fraud handling and for non-fraud (money laundering, etc). A transaction they can't know anything about other than "transfer X money to some recipient you can't know anything about" just doesn't seem realistic with the regulations involved.

Plus, even "transfer X money to some recipient you can't know anything about" is a message that you're sending _to_ the bank, that they have to be able to decode and read. And, presumably, you'd encrypt that message and expect the bank to decrypt it.

Honestly, I don't understand what argument is that you're not sending a message TO the bank, and they need to be able to read it in order to act on it, and they need to decrypt it to read it. The bank is the target of the message, they are one of the "ends" in E2EE.

I feel like I need an "Explain this like I'm 5", because clearly you believe differently than me... and I don't understand _how_ it can be otherwise.

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#132
post #60

Earlier quoted context omitted.

I’m pushing back on that one. I’ve been running websites since the ‘90s, and I’ve never heard E2EE used that way until very recently by vendors who, bluntly, want to lie about it.

It was pretty common to call client-side encryption/SSL "end to end encryption" among network engineers who were analyzing data flowing through their networks[0] as well as those who were implementing SSL/TLS into their applications[1]. The ends were the client and the server and the data was encrypted "end to end". The goal at that time was to prevent MITM snooping/attacks which were highly prevalent at the time. Pa…

At least in some circles, the real meaning of "end-to-end encryption" was being addressed. For example, in the field of credit card processing, here's an article from 2009 which talks about how people back then were misusing the term: https://web.archive.org/web/20090927092231/http://informatio...

Granted, it's a marketing piece trying to sell a product, but still.

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#133
post #125

Imagine the collective brainpower that could be used to help solve the world's ills, and instead decided, no, what we need is a camera pointed at your asshole which we feed into an AI-powered SaaS we can then sell to you for a subscription. This industry is finished.

It’s pretty impressive that that juicero thing wasn’t the most bizarre thing they could come up with.

I watched a teardown of it and the truly bizarre thing was that the build quality was actually amazing. Machined out of a huge block of aluminum, really big bearings, etc.

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#134

Earlier quoted context omitted.

This is an incredibly common misuse of the term e2ee. I think at this point we need a new word because you have a coin flip's chance of actually getting what you think when a company describes their product this way.

I have never seen "e2ee" abused this way personally.

There was a discussion here on hn about OpenAI and it's privacy. Same confusion about e2ee. Users thinking e2ee is possible when you chat with an ai agent.

https://news.ycombinator.com/item?id=45908891

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#136
post #94

Earlier quoted context omitted.

I have never seen "e2ee" abused this way personally.

Zoom also did this once

I believe they now have a proper e2ee mode which disables all the cloud powered features, no?

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#137

Imagine the collective brainpower that could be used to help solve the world's ills, and instead decided, no, what we need is a camera pointed at your asshole which we feed into an AI-powered SaaS we can then sell to you for a subscription. This industry is finished.

Who the hell buys this...

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#138
post #4

So basically their marketing-department is abusing a security term in order to sound good, as opposed to a software flaw. They're claiming "end to end" encryption, which usually implies the service is unable to spy on individual users that are communicating to one-another over an individualized channel. However in this case there are no other users, and their server is one of the "ends" doing the communicating, which…

> They're claiming "end to end" encryption, which usually implies the service is unable to spy on individual users that are communicating to one-another over an individualized channel.

It doesn't "imply", it outright states that. Their server isn't the end, it's the middle. They're not "breaking the spirit" or something, what they are doing is called lying.

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#139
post #125

Earlier quoted context omitted.

It’s pretty impressive that that juicero thing wasn’t the most bizarre thing they could come up with.

I watched a teardown of it and the truly bizarre thing was that the build quality was actually amazing. Machined out of a huge block of aluminum, really big bearings, etc.

That was part of why it failed though. The over-engineering made it very hard to recover costs
Post reply on HN