Skip to main content

Google is collecting troves of data from downgraded Nest thermostats

The second-gen Nest Thermostat launched in 2012.

Google officially turned off remote control functionality for early Nest Learning Thermostats last month, but it hasn’t stopped collecting a stream of data from these downgraded devices. After digging into the backend, security researcher Cody Kociemba found that the first- and second-generation Nest Learning Thermostats are still sending Google information about manual temperature changes, whether a person is present in the room, if sunlight is hitting the device, and more.

Kociemba made the discovery while participating in a bounty program created by FULU, a right-to-repair advocacy organization cofounded by electronics repair technician and YouTuber Louis Rossmann. FULU challenged developers to come up with a solution to restore smart functionality to Nest devices no longer supported by Google, and that’s exactly what Kociemba did with his open-source No Longer Evil project.

But after cloning Google’s API to create this custom software, he started receiving a trove of logs from customer devices, which he turned off. “On these devices, while they [Google] turned off access to remotely control them, they did leave in the ability for the devices to upload logs. And the logs are pretty extensive,” Kociemba tells The Verge.

Along with preventing users from remotely controlling early Nest Learning Thermostats (in addition to the European version from 2014), Google turned off the ability for users to check the status of their devices from the Nest or Google Home app, while also blocking security and software updates. Google notes that the unsupported devices “will continue to report logs for issue diagnostics,” though the data the company is collecting no longer appears to be useful.

“Although these logs can contain technical details such as HVAC error states, Google can no longer use that information to assist the customers who still depend on these thermostats, since support has been fully discontinued, even in cases of device failure,” according to Kociemba.

Google is still getting all the information collected by Nest Learning Thermostats, including data measured by their sensors, such as temperature, humidity, ambient light, and motion. “I was under the impression that the Google connection would be severed along with the remote functionality, however that connection is not severed, and instead is a one-way street,” Kociemba says. The Verge reached out to Google with a request for comment but didn’t immediately hear back.

FULU awarded Kociemba and another winner, who goes by the name of Team Dinosaur, with the $14,772 bounty for bringing smart features back to the unsupported thermostats.



from The Verge https://ift.tt/5sSygBh

Comments

Popular posts from this blog

Pandora Stories lets artists add commentary to their own playlists

Pandora launched Stories today, a tool that lets artists and creators add voice commentary to their own playlists. The Stories feature merges podcasts with music playlists, and is meant for artists to add context to an album, or for podcasters to experiment with new storytelling formats. The feature is part of Pandora AMP, the streaming service’s free Artist Marketing Platform that helps creators promote their work. To kick off the launch, Pandora’s prepared some Stories by artists like John Legend and Daddy Yankee, who tell listeners their personal stories interspersed between their own songs. There’s also a Stories playlist called Love Songs That Aren’t Really Love Songs , which includes commentary on individual songs like a podcast... Continue reading… from The Verge - All Posts https://ift.tt/2Xz1oNc

Nomad’s 3-in-1 MagSafe Charger and the Sonos One are down to their best prices

Nomad’s minimalist Base One Max 3-in-1 is on sale for $95. | Image: Nomad Fancy phone chargers are nice, but they’re often too expensive to justify the cost. Nomad’s Base One Max 3-in-1 is one of those rare unicorns that delivers a lot of value for your money, however, thus making it worth the splurge. After all, the device can simultaneously charge a MagSafe-compatible phone, your Apple Watch, and a pair of AirPods (or another Qi-compatible device) — that’s something not even Nomad’s forthcoming Qi2 charger can do. What’s even better is that Nomad is currently selling the hefty, MagSafe-certified charger in both black and silver for its Black Friday price of $95 ($55 off). Designed with metal and glass, Nomad’s minimalist slab will look slick on any desk or bedside table. It’s also powerful, delivering up to... Continue reading… from The Verge - All Posts https://ift.tt/25YJfqR

Asus’ foldable laptop goes on sale for $3,499.99

The Asus Zenbook 17 Fold OLED, more or less fully unfolded.  | Photo by Monica Chin / The Verge Asus’ first foray into the world of folding-screen laptops, the Zenbook 17 Fold OLED, is now on sale for $3,499.99, the company has announced . Asus says the laptop is being sold in the US via B&H and Newegg though as of this writing only Newegg seems to have the laptop available for immediate shipping, with B&H listing it as “coming soon.” That aligns with the Q4 target date given to us when we reviewed the laptop in August . At $3,499.99, Zenbook 17 Fold OLED is eye-wateringly expensive, but my colleague Monica Chin points out that it’s the first such device that starts to deliver on the promise of this new form factor. You can either use the laptop with its 17.3-inch 2560 x 1920 screen fully unfolded and paired with a bluetooth keyboard... Continue reading… from The Verge - All Posts https://ift.tt/P4q7sej