Live data from Hacker News

Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

varlogsimon.leaflet.pub

41–50 of 227 posts

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#41
post #4

So basically their marketing-department is abusing a security term in order to sound good, as opposed to a software flaw. They're claiming "end to end" encryption, which usually implies the service is unable to spy on individual users that are communicating to one-another over an individualized channel. However in this case there are no other users, and their server is one of the "ends" doing the communicating, which…

> However in this case there are no other users, and their server is one of the "ends" doing the communicating, which is... perhaps not a literal contradiction in terms, but certainly breaking the spirit of the phrase.

Am I understanding correctly that the other end of this is a rear end?

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#42
post #4

So basically their marketing-department is abusing a security term in order to sound good, as opposed to a software flaw. They're claiming "end to end" encryption, which usually implies the service is unable to spy on individual users that are communicating to one-another over an individualized channel. However in this case there are no other users, and their server is one of the "ends" doing the communicating, which…

This is exactly what E2EE means. I used to work at a bank, and our data was E2EE, and we had to certify that it was E2EE - from the person paying, through the networks, through the DNS and Load balancers, until it got to the servers. Only at the servers could it be unencrypted and a (authoried) human could look at it.

Of course, only authorized users could see the data, but that was a different compliance line item.

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#43
post #34

Earlier quoted context omitted.

You could have a classifier running on-device that sends summary data (rather than raw images) back to Kohler.

Yeah, it’s kinda like such a reasonable thing too Doing on device compute is probably expensive and would prohibit such a product based on the economics but ITS A GENITAL CAM

Well, this waste analyzing piece of e-waste costs $600, so you could probably cram a lot of inference horsepower in there if you wanted to.

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#44

Holy crap. I remember a sign in our dorm bathroom that read, “toilet cam is for research purposes only”. It was a joke, but always got a nice reaction from new people in the building. But they actually sell this?! And want to charge me for it!? Holy crap!

They want to charge you $600 for it, plus a $7/mo subscription.

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#47
post #4

So basically their marketing-department is abusing a security term in order to sound good, as opposed to a software flaw. They're claiming "end to end" encryption, which usually implies the service is unable to spy on individual users that are communicating to one-another over an individualized channel. However in this case there are no other users, and their server is one of the "ends" doing the communicating, which…

This is exactly what E2EE means. I used to work at a bank, and our data was E2EE, and we had to certify that it was E2EE - from the person paying, through the networks, through the DNS and Load balancers, until it got to the servers. Only at the servers could it be unencrypted and a (authoried) human could look at it. Of course, only authorized users could see the data, but that was a different compliance line item.

Nah. You have no reasonable expectation that the bank itself can’t access your financial records. Anyone reading Kohler’s lies would have every expectation that the Internet of Poopcam screenshots are theirs and theirs alone.

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#49
Imagine the collective brainpower that could be used to help solve the world's ills, and instead decided, no, what we need is a camera pointed at your asshole which we feed into an AI-powered SaaS we can then sell to you for a subscription. This industry is finished.

Re: Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

#50
post #36

Earlier quoted context omitted.

Creating a new term for the less secure definition doesn't work, as they'll just continue to call it E2EE encrypted.

I think part of the problem is that prior to WhatsApp's E2EE implementation in like 2014, TLS was very often called "End to End Encryption" as the ends were Client and Server/Service Provider. It got redefined and now the new usage is way more popular than the old one. I can't blame most people for calling TLS "E2EE", even some folks in industry, but it's not great for a company to advertise that you offer X if the m…

The two endpoints of the communication with Kohler's app are the client and the server. In WhatsApp's E2EE implementation the endpoints are two client devices. Both are valid meanings of E2EE. You're defining that "end to end" means the server cannot access it but that's simply not what it means.
Post reply on HN