logoalt Hacker News

Man discovers his parents' coffee machine used 1TB of data in 10 days

262 points • by ck2 • yesterday at 4:56 PM • 161 comments • view on HN

Comments

BLKNSLVR • today at 10:21 PM

So, separate VLANs, wifi isolation and complete internet blocking for all devices such as this, and only purchase devices that can be controlled via Home Assistant.

What hope do normies have?

➕ show 3 replies
altairprime • yesterday at 5:45 PM

In the Twitter thread linked, the person confirms two things:

1. It saturated the local network with 1TB of metadata sniffing scans, not the network uplink to the outside world.

2. It does so because, as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.

➕ show 2 replies
nelsonfigueroa • today at 10:29 PM

can't even make a coffee at home without being tracked

sam-cop-vimes • today at 8:51 PM

This website values your privacy. Only shares data with 1747 partners.

jakub_g • today at 10:04 PM

The real question is: could someone explain me why anyone would want a smart coffee maker?

What kind of functions it has that can't be replaced by:

- walking a few meters and pushing a physical button

- waiting a whopping minute for coffee to brew, instead of triggering it remotely

➕ show 2 replies
altern8 • today at 9:00 PM

Can someone explain to me what kind of data it collects, and what value could that data have to advertisers or anyone else?

➕ show 1 reply
matthewmcg • today at 9:03 PM

Wow, maybe this is the push I need to finally set up an isolated "IOT" VLAN at my home.

➕ show 1 reply
ttytty • yesterday at 10:15 PM

It's so important to have a dedicated VLAN (or 2.4g SSID) for IoT devices and block access to your regular VLAN/SSID or enforce some more granular rules on what devices can communicate with each other.

Most non-ancient routers/gateways support this. There are way too many IoT devices running code that's _worse_ than what older LLMs produce.

➕ show 5 replies
landgenoot • today at 4:35 AM

Never assume malicious intent when incompetence.

I have multiple devices that queries their update server every 15 seconds, which all shows up as the top 10 queried domain in my network.

➕ show 4 replies
PinkaDunka • today at 8:50 PM

This website generated 1tb of bandwidth while serving me 1kb of text

j45 • today at 10:06 PM

A great reason to limit “Smarthome” devices to a dedicated guest or iot wifi network.

jttnr • today at 8:34 PM

Maybe the coffee machine is subsidized by a residential botnet?

lifeisstillgood • today at 8:03 PM

Holy moly - 1,747 “partners” to share my data with. I mean, how can you even find 1747 data brokers? Where do you get that list. What does the JavaScript look like - I mean … this is getting ridiculous.

But at least the EU did me a solid. I really wanted to read that but I think 2000 data scumbags is not worth the effort.

All I need know is to realise bottlecaps must be recycled and federalism is good. Repeat in the mirror each morning

jason_s • today at 5:23 AM

`C0FFEEEEEEEEEEEEEEEEEEEEE...`

➕ show 1 reply
ButlerianJihad • yesterday at 8:58 PM

A year or two ago, I was using NextDNS in ad-blocking and logging mode, which very helpfully exposed malware sitting on my very router, which had been completely undetectable, except for the veritable flood of bizarre DNS queries it was routinely sending to the self-configured DNS servers.

Now that I have a new router and I've re-enabled NextDNS, I've ironically discovered that the chief abuser of DNS right now is the router's own legit security software, which is absolutely hammering on the same query, several times a second.

Of course, since I am currently on NextDNS free tier, this matters a lot, because they cut you off after about 300,000 queries in a month. So any hammering abuse will make me lose my privileges much earlier than I would otherwise. So, to stop the abuse, should I shut off my legit security software? It is absolutely rubbish at identifying malware on the device itself...

ck2 • yesterday at 5:45 PM

it took me a month to notice my Midea A/C was absolutely hammering my router

I didn't even know it had wifi capability but it was trying to connect

I use mac whitelist so it wasn't even getting in but that didn't stop it from trying every seond

Fortunately it was just a usb dongle so yanked it out

➕ show 2 replies
tamimio • yesterday at 7:18 PM

Reminds me when couple years ago I plugged the TV to the internet (so my relatives kids can watch YT) and I forgot to unplug it for almost a week after, only to find the router dns resolved (and blocked) a million queries, all from that one TV!

➕ show 1 reply
matteoraso • yesterday at 9:19 PM

I honestly hate the IoT so much. Why should a coffee machine of all things use data? Just make the coffee.

➕ show 1 reply
realaaa • today at 9:23 PM

ahahahah that's gold !

IoT network yep, needed yesterday

ButlerianJihad • today at 3:50 AM

Last year I had a big dispute with my ISP that was refusing to support or provide proper WiFi on their router, even while they touted a trademarked brand-name to do it. I ended up turning their router into Bridge Mode and purchasing a real router that could do WiFi. I did this extremely reluctantly, because every other personally-owned router had contracted malware.

After installing the new router (Netgear) my HP LaserJet began printing error pages. Like, I had done nothing to send anything to it, but a blank error page or three would pop out of it at very random times.

It took awhile to narrow down and diagnose this. But it turned out that the Netgear system had a very... proactive network malware detection system. It was red-team scanning my LAN for "vulnerabilities" or exploits or the presence of malware (I think just known vulns). It was a known side-effect of these scans, where it would tickle an RTSP TCP port of some kind and the HP printer would respond with its error printout.

I was so livid that the router was scanning the LAN, basically unbidden and completely undocumented. Even worse, they were not sharing the logs or results of that scan with the consumer. No, they were being sent back to the Netgear mothership, and their cybersecurity vendor overlords. So the scans were not designed to benefit me; they were simply designed to spy on everyone from a privileged vantage point. Now I ask you, why is a piece of kit that is supposed to be "yours" compiling secrets about your network, hiding them from you, and turning them over to, I guess a big database for hackers to leak in due time? This is not a question of "well, devices hooked up to a network should not be vulnerable" if the devices were contained in a private network, and 100% inaccessible from outside, and only attackers inside my perimeter could do these exploits in the first place.

Thankfully I found a way to disable this. Their "security" shitware is still spamming DNS and I may be forced to disable that as well. Meanwhile, routers 100% cannot self-introspect or self-diagnose and find their own malware. I've said it once; I'll say it again: consumer routers are the Achilles Heel to your network. They are ideal points of compromise for any actor to gain a foothold and pivot, or simply gain persistence undetected. Your ISP doesn't care, and your vendors don't care. Perhaps you should.

➕ show 2 replies
bitwize • today at 8:08 PM

As another sign of the enshittified world we live in, the thing probably wasn't even RFC 2324 compliant.

https://datatracker.ietf.org/doc/html/rfc2324

Bruh should have set his PiHole to return HTTP 418 in response to any outbound request this thing made.

rendall • yesterday at 8:20 PM

The GDPR consent form on this blog did not have a “Reject all” button. It required me to manually reject 16 instances of “legitimate interest,” then scroll through 1,746 vendors to make sure they were all set to reject.

Seems worth mentioning in a post about excessive and intrusive collection of user data. The moral outrage rings hollow when opting out of tracking is so deliberately onerous.

➕ show 1 reply
Gauchy101 • today at 9:22 PM

[flagged]

3seashells • today at 9:33 PM

[dead]