Why is this allowed? There’s no way to consent to a coffee machine.

If you buy a Keurig machine you've already signalled you're a sucker. (sorry)

This is the most Gilfoyle-coded comment of the day

I'll take that as a compliment!

Laughs in Moccamaster.

Tongue-in-cheek, but my Moccamaster which I bought second-hand is still doing great after 15 years. Two deep cleaning sessions in all that time and just running it with vinegar a couple of times a year seems to be all it needs.

The device is dead simple. No advanced electronics. Nothing complex that can break. Just a coffee maker fine-tuned to near perfection.

The only flaw it has is the handle for the pot. I've resorted to replacing the plastic handle with a fancy walnut one I made myself. I needed that because we tilt the pot sideways to fill the reservoir with water (because of the placement on the kitchen counter and the cabinets above), and that plastic handle is not designed for sideways stresses.

You shouldn’t fill the reservoir with the coffee pot, unless you’re really washing the pot super clean after each use. Better get a proper jug for filling the reservoir, so you’re not putting coffee residue and oils back into the clean-water system.

perfect person to sell to advertisers.

Like the people who reply to nigerian emails have already been pre-qualified by 1) ignoring the misspellings and 2) replying.

Presumably during setup and connection to the AP it has a ToS. Doubtful they just unboxed, plugged in, and it connected to the right AP and went.

> Doubtful they just unboxed, plugged in, and it connected to the right AP and went

Why not? iirc some of the smart TVs have been shown to find open wifi networks on their own and upload data. (I'm not sure about that though. But it's plausible and undoubtedly will be implemented some day).

I've read this argument dozens of times on HN and on HN only - I'd love to see an example of that actually provably happening anywhere in the real world.

I would love to as well. It sounds like something that's plausible but potentially a minefield of liability for the manufacturer.

I could also see some kind of partnership with ISPs to use their "public" WiFi hotspots[1]. This seems more likely since it's (probably) harder to honeypot but requires making regional deals.

[1] https://www.highspeedinternet.com/resources/is-your-router-a...

The use WiFi networks as a form of GPS, much like smartphones on first stage of geolocation

Maybe they bought it used?

ToS can't trump the actual law.

It is one thing to make a law, it is another to enforce a law.

The actual law is typically so weak and spineless that the ToS doesn't need to trump it. Particularly when it comes to data security or privacy.

Ok, but it can collect consent

LOL

Legislators are cheap to purchase

It's not allowed in the EU. Not without consent.

[flagged]

It's implied consent when you give it access to your WiFi.

Why you would give a coffee maker access to your WiFi is the real question,

So in other words, they were asking for it?

Well, yeah sorta since the only reason appliances connect to the internet is to steal data. I mean, if you buy a connected x that normally would not be connected, it’s 99 percent there to do nefarious stuff for its real owners. It’s like having a pet lion. Sure, it’s horribly irresponsible that someone sold you a pet lion, but. Uuuh you bought at pet lion. What did you think it was going to do?

Besides, did you see how he was dressed?

This is funny.

How do you feel about thermostats? Are some things worth it? I've had a "smart" one for the past five years, part of a new furnace install, that I've stubbornly refused to connect to my wifi. Of course this means if we forget to turn the heat down while no one's home, there's nothing to be done about it.

There are ways to control a device remotely without letting the device spy on you and call home - Zigbee, Matter, Esphome..

How does this analogy go when people buy a house kitten and it turns out they have been sold a lion cub? Most people simply do not have the tech literacy to understand that what they a are buying is actually a lion, they thought they were buying a coffeemaker with some cool features. It's difficult to blame the victim when they would need to spend hours trying to understand why the thing mapping out their local network is something that they should even care about

In that context the person is a fool who shouldn’t be in charge of another life, because they’re incapable of basic prudence.

I don’t actually think that applies to coffee makers spying on people though. People shouldn’t be expected to understand how computer networks or ad tech spying works in the same way that literally any child or idiot should know the difference between a lion cub and a house cat.

In the analogy, there is no such thing as a house kitten. They are all cute and cuddly lion cubs. Society needs to develop a deep awareness of this, in spite of the ocean of fraudulent advertising to the contrary. (individual-liberty-protecting regulation like the GDPR would be nice too, alas)

You have latched on to an important idea here.

Since most appliances now contain a general-purpose computer, it would be unfair to say that a device is incapable of hacking or hosting malware, because any device with the given sensors and radios and capabilities can be essentially reprogrammed at any time.

So, if we're looking at smart TVs with cameras and microphones and Wi-Fi and Bluetooth and all the connectors, or if we're simply looking at a an ordinary network device, they all fall under the umbrella of general purpose computer, and there is no way to trust their maker, or some equally capable programmer, not to turn them malevolent in some future update.

I don't view this as an issue of terms of service or of software or of your manufacturer. I view this as an existential and fundamental problem with dropping general purpose computers into your home and behind your DMZ.

Consumer operating systems like Windows and Apple have all kinds of countermeasures against this malicious use. But without the proper introspection and without the proper safeguards, a device that looks special purpose but is in fact general purpose is far more dangerous.

Getting technical - the way I see it, the problem arises from a combination of three things - sensors/access, Internet access, and source of software/authority.

Sensors/access is unavoidable, otherwise the device doesn't actually do anything useful. The point is it sets the scope for what the device is able to affect. When people say "set up a separate IoT VLAN" (that still has Internet access) this is basically what they're addressing - how a device can access other devices they may care about more.

Internet access is the catalyst that's created this whole dumpster fire - I don't care about the proprietary software on my keyboard/mouse/UPS/monitor/GPU/etc to nearly the same extent. I've got some TP-Link plugs that I control local network only. They don't get Internet access, so no updates, telemetry backhaul, etc.

The authority to update/configure/change that software is the crux. With proprietary software, there are no cuddly kittens period. Here we've got a case of a "legitimate" company choosing to be a bona fide attacker to increase their bottom line! The harm was exacerbated by a bug causing it to run amok, but even without the bug they are deliberately violating trust.

But even libre software can fall to security holes as well. Meaning you want to centralize the attack surface as much as possible, for administration's sake of keeping updated. "Internet" of things is basically the direct opposite of this - postulating many illegible fine-grained links between devices on different networks. Whereas really need more like the Home Assistant model, where peripheral devices may communicate over the network, but it's only ever over the local network. Think how ethernet is set up when used in industrial control networks (or at least how it should be set up, hehe).

Instead of a deep awareness, wouldn't it be easier to simply ban selling lions?

I think the two go hand in hand, unfortunately.