1. It saturated the local network with 1TB of metadata sniffing scans, not the network uplink to the outside world.
2. It does so because, as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.
Seems worth mentioning in a post about excessive and intrusive collection of user data. The moral outrage rings hollow when opting out of tracking is so deliberately onerous.
Now that I have a new router and I've re-enabled NextDNS, I've ironically discovered that the chief abuser of DNS right now is the router's own legit security software, which is absolutely hammering on the same query, several times a second.
Of course, since I am currently on NextDNS free tier, this matters a lot, because they cut you off after about 300,000 queries in a month. So any hammering abuse will make me lose my privileges much earlier than I would otherwise. So, to stop the abuse, should I shut off my legit security software? It is absolutely rubbish at identifying malware on the device itself...
Most non-ancient routers/gateways support this. There are way too many IoT devices running code that's _worse_ than what older LLMs produce.
FWIW preventing the harm that happened here would seem to require a second set of APs (radios) on a different channel.
After installing the new router (Netgear) my HP LaserJet began printing error pages. Like, I had done nothing to send anything to it, but a blank error page or three would pop out of it at very random times.
It took awhile to narrow down and diagnose this. But it turned out that the Netgear system had a very... proactive network malware detection system. It was red-team scanning my LAN for "vulnerabilities" or exploits or the presence of malware (I think just known vulns). It was a known side-effect of these scans, where it would tickle an RTSP TCP port of some kind and the HP printer would respond with its error printout.
I was so livid that the router was scanning the LAN, basically unbidden and completely undocumented. Even worse, they were not sharing the logs or results of that scan with the consumer. No, they were being sent back to the Netgear mothership, and their cybersecurity vendor overlords. So the scans were not designed to benefit me; they were simply designed to spy on everyone from a privileged vantage point. Now I ask you, why is a piece of kit that is supposed to be "yours" compiling secrets about your network, hiding them from you, and turning them over to, I guess a big database for hackers to leak in due time? This is not a question of "well, devices hooked up to a network should not be vulnerable" if the devices were contained in a private network, and 100% inaccessible from outside, and only attackers inside my perimeter could do these exploits in the first place.
Thankfully I found a way to disable this. Their "security" shitware is still spamming DNS and I may be forced to disable that as well. Meanwhile, routers 100% cannot self-introspect or self-diagnose and find their own malware. I've said it once; I'll say it again: consumer routers are the Achilles Heel to your network. They are ideal points of compromise for any actor to gain a foothold and pivot, or simply gain persistence undetected. Your ISP doesn't care, and your vendors don't care. Perhaps you should.
It would be like finding out ring cameras are taking pictures of your keys and calculating the pin set to producing duplicates and sending that pin set data off somewhere and when caught them being like "Uh, we are uhhh... doing it to make sure your key isn't too worn down or to detect if someone made a crude hand filed key. Yeah that's it!"
I have multiple devices that queries their update server every 15 seconds, which all shows up as the top 10 queried domain in my network.
Considering the computing power of these kinds of devices, it is most likely stuck inside an infinite loop sending garbage at full speed, there is not enough power to process that much volume in any maliciously useful way.
But at least the EU did me a solid. I really wanted to read that but I think 2000 data scumbags is not worth the effort.
All I need know is to realise bottlecaps must be recycled and federalism is good. Repeat in the mirror each morning
https://datatracker.ietf.org/doc/html/rfc2324
Bruh should have set his PiHole to return HTTP 418 in response to any outbound request this thing made.
Legislators are cheap to purchase
Why not? iirc some of the smart TVs have been shown to find open wifi networks on their own and upload data. (I'm not sure about that though. But it's plausible and undoubtedly will be implemented some day).
Why you would give a coffee maker access to your WiFi is the real question,
Besides, did you see how he was dressed?
Yeah, sure, the terms of service probably say that they can do that. That's still in "unconscionable" territory. And courts do not like unconscionable contracts. If it's unconscionable, it's invalid (if I understand the law correctly).
Is this why everybody wants to make appliances with wireless?
Customers are gonna get lost in the sauce and skip right past all of that and toss the packaging.
its LGs glass in LG household, and now Keurigs kitchen
There’s no way Keurig is has the intention of paying the kind of costs required to collect a terabyte of data every two weeks for millions of people who own their coffee makers.
There must be some kind of bug here. I imagine if you unplugged it and plugged it in again the data usage would settle down.
Now I'm left wondering what this traffic actually is - assuming probe (arp/icmp) packet size of 64 byte, that's 17kpps. I don't think an ESP32 class Internet-of-Trash chip can even do that. Even bulk transfers rather than small probes would be pushing it.
Perhaps this thing found some fellow-traveler device streaming video on a port it happened to connected to?
... the linked xit says it "broadcast 1TB of data". So maybe some protocol with a much larger packet than icmp, spammed in a hard loop without any delay?
Still seems buggy.
But why do they need to collect 1 TB? Sounds like a lot of redundant/doublicated entries then for a small network?
ck2•1d ago
I didn't even know it had wifi capability but it was trying to connect
I use mac whitelist so it wasn't even getting in but that didn't stop it from trying every seond
Fortunately it was just a usb dongle so yanked it out
ars•1d ago
It's great having them on WiFi - you can turn on the AC before getting home to pre-cool, without having to leave it on all day.
sillyfluke•1d ago
Man: Well, before you couldn't turn on the AC before you got home
ars•1d ago
Cpoll•23h ago
sillyfluke•21h ago
I know this sounds like the famous "just do it this way in linux instead" criticism of Dropbox back in the day. But I do think we reached "life parodies fiction" with these smart devices where it makes sense to give diy another go. And with AI, there's less excuses this time around I would imagine.
But I would literally rather buy a cheap phone, a cheap SIM, hotspot it and connect it to a charger and have the AC connect to that and isolate it that way instead of letting it touch the network.
[0] https://worrydream.com/Electronics/
ttytty•21h ago
I have my IoT on a separate VLAN and I can observe communications for any given device at any given time.. this seems like a much saner solution than outright not buying any IoT devices, though that is also a respectable decision!
altairprime•1d ago
HankB99•22h ago
And I wonder how I would even tell if it was trying to associate with my WiFi.
pseudohadamard•6h ago