Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’m completely lost. I’m not talking about safe, I’m talking about how routing everything though a server gives a lot more control to the manufacturer and they’re loathe to give that up.
 help



I’m pointing out that has literally nothing to do with LAN or Wifi. It’s a problem with having literally any (unfiltered) network access at all. Though even filtered, you’re susceptible to bypass attacks.

Notably, a device can even route all command and control through a cloud service, including sending copies/hashes of all accessed content AND also serve just local (as in physically connected) media/content, if it has a network connection.

This has been an issue since BluRAY at least, where players have the capability to check physical media licensing and deny/brick BluRAY media based on network updates of the keys, and could run Java apps which had network access. So at least 20 years? It is a big reason why there was resistance to BluRAY vs DVD, as DVD was a relatively dumb player.

The only way to prevent that is to firewall off or physically disconnect any network access. Which is getting harder to do with cheap LTE modems.

In this example, for instance, I bet these LG TV’s will happily send all this info even if no one is using any network or app based media streaming at all.


And if everything goes through the manufacturer’s servers then you have to give it internet access for it to work at all. If it works over then LAN then you at least have the option to block it without disabling the functionality.

Again with the ‘works over the LAN’. What do you think that actually means, because I keep explaining that doesn’t mean what you seem to think it does, and then you keep repeating it in a context which doesn’t make any sense.

It means that my device at e.g. 192.168.123.45 can be controlled by my phone or computer at 192.168.123.46 on the same LAN without any of the traffic going over the internet. And since none of the traffic goes over the internet, the device can be completely blocked from internet access without disabling the ability to control it.

I'm not really sure what the disconnect is here. This seems like the obvious meaning of "works over the LAN" and it means, by definition, that you can control the device without letting it access the manufacturer's servers.


You’re saying ‘works behind a firewall’, or ‘works without an internet connection’. Maybe ‘works on a fully isolated LAN or VLAN’?

A LAN (or WiFi) typically has routability to the Internet (though doesn’t have to, of course!) which is why what you are saying is confusing. It has for at least 20 years, and is especially true in residential, but also true even in commercial.

Those some IP addresses could also be NAT’d, and often are.

Most modern products have also spent significant R&D figuring out how to bypass NAT and firewalls and even hide from packet inspection (tunneling DNS and command and control over HTTPS, for one example).

Very few people are able to handle or setup actual air gapped LANs now (or isolated VLANs), but anything besides that is risky in these scenarios.


I was replying to “Manufacturers just need to realize that LANs exist and allow their devices to be used with the Internet turned off.” If it took you this long to figure out what I was talking about, I don’t think it’s really a problem with my description.

So weird, it’s like you refuse to read my comment and keep replying with the part of your comment which ISN’T that part, and then act like I’m the problem when I point out you aren’t making any sense.

Are you real?


Your comments consist of two parts. 1) telling me that I’m wrong because you insist on not understanding what I’m saying 2) a bunch of irrelevant stuff based on not understanding. So yeah, I’m replying to part 1 and ignoring part 2.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: