Karcher DAB radios are broadcasting an SSID for open Wi-Fi access. It doubles as an Internet radio, but AFAICT from the manual it’s only expected to act as a client.
So WTF is going on?
It seems like a really bad idea for consumers to connect this radio to their LANs to use to play Internet radio and podcasts when there is an always available Wi-Fi AP that enables anyone in proxity to connect to the radio. What’s the point? There is no way to disable the SSID broadcasting and it remains on even when the radio is “off” (but plugged in).
The manual shows that there is a remote control. Is the remote using wi-fi? I don’t have the remote so I have no way of verifying. In any case, this design seems like a recipe for disaster. Karcher should perhaps just stick to making pressure washers.
Google and Apple use Wi-Fi SSIDs for navigation. I boycott both companies. As such, I prefer not to have any wi-fi APs. And when I decide to run an AP, I ensure the SSID ends in _optout_nomap to opt-out of giving uncompensated help to the nav systems of Apple and Google.
Does this violate the GDPR? I cannot change the SSID, so it’s like I am being forced to share with the general public the fact that there is a Karcher radio in my home. That does not respect data minimisation.
4 Comments
amelore@slrpnk.net · 2 pts · 20d
LG HVAC doesn't stop broadcasting it's own network after configuring, but every other device I've seen do this did. So try connecting it to a wifi. It is technically a data leak, but no, I don't think you owning a Karcher radio would be considered PII under GDPR.
daveyOsborn@infosec.pub · 1 pts · 20d
I appreciate the tip. Luckily I happen to have a spare router that has no uplink. So IIUC, setting up an ephemeral network on the router with no WAN then configuring the Karcher to connect to it might result in the Karcher detecting that it has been configured and then stop squaking, all without the Karcher ever being able to phone home. I will have to test this theory.
Suppose Google and Apple know that Bob lives at 123 main st., Paris. Bob plugs in a Karcher and a google and apple spy (read: anyone with an iphone or Android) walk past the house. The SSID and MAC address is captured and sent to Google and Apple. Google and Apple infer that the MAC address belongs to Bob. Then Bob moves to 456 Broad st., Amsterdam. Bob does not give Google or Apple his new address. But within a day a Google spy and Apple spy happen to walk past his new location. The SSID and MAC is sent to the motherships, who then instantly work out Bob’s new address. Even though Bob himself quit feeding Google and Apple, they effectively track Bob’s new home location using the unique MAC address that follows him for as long as he has the radio.
How is that GDPR compliant? The MAC address becomes a unique identifier, like a social security number to an American. It seems quite far from data minimisation. What is Karcher’s legal basis for broadcasting a unique number from the address of the data subject?
ChaoticNeutralCzech@feddit.org · 2 pts · 19d
No remote control uses Wi-Fi, that's a very high-power, high-bandwidth standard. Even RF ones often prefer the simple 433 MHz band over Bluetooth.
Connect it to your Wi-Fi, that should occupy the Wi-Fi radio (in this case, radio means transciever+antenna system), it's very unlikely to have two. You can fully firewall it at the router if you only use non-Internet functions.
daveyOsborn@infosec.pub · 1 pts · 19d
Ah, good point. It could not be both a client and server at the same time with just one wi-fi radio. And they wouldn’t blow money on two radios just so one of them could have a relatively useless task.