cross-posted from: https://infosec.pub/post/50218987

Karcher DAB radios are broadcasting an SSID for open Wi-Fi access. It doubles as an Internet radio, but AFAICT from the manual it’s only expected to act as a client.

So WTF is going on?

It seems like a really bad idea for consumers to connect this radio to their LANs to use to play Internet radio and podcasts when there is an always available Wi-Fi AP that enables anyone in proxity to connect to the radio. What’s the point? There is no way to disable the SSID broadcasting and it remains on even when the radio is “off” (but plugged in).

The manual shows that there is a remote control. Is the remote using wi-fi? I don’t have the remote so I have no way of verifying. In any case, this design seems like a recipe for disaster. Karcher should perhaps just stick to making pressure washers.

Google and Apple use Wi-Fi SSIDs for navigation. I boycott both companies. As such, I prefer not to have any wi-fi APs. And when I decide to run an AP, I ensure the SSID ends in _optout_nomap to opt-out of giving uncompensated help to the nav systems of Apple and Google.

Does this violate the GDPR? I cannot change the SSID, so it’s like I am being forced to share with the general public the fact that there is a Karcher radio in my home. That does not respect data minimisation.

  • one_old_coder@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    2
    ·
    edit-2
    16 days ago

    Is the SSID linked to your identity? Then it’s not GDPR. Also you mistook that brand with Kärcher.

    Anyway, get a refund and stop complaining.

    • daveyOsborn@infosec.pubOP
      link
      fedilink
      arrow-up
      3
      arrow-down
      2
      ·
      edit-2
      16 days ago

      Is the SSID linked to your identity? Then it’s not GDPR.

      Nonsense. “Personal data” is not just your identity. All data the relates to you is your personal data. That includes your home address. When your home address becomes aggregated with a unique MAC address, that MAC address also becomes personal data that relates to you.

      And because the SSID does not include the string _optout_nomap, Google and Apple can use the SSID and MAC to track you and to keep tabs on where you relocate to so long as the Karcher radio moves with you.

      Anyway, get a refund and stop complaining.

      What EU country do you live in that you can get a refund on this basis (which according to you does not violate law)? Why do you think it would it be sensible to solve the problem for one person with respect to a manufactured product with likely tens or hundreds of thousands of consumers who are subject to the same abuse?

      • one_old_coder@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        16 days ago

        All data the relates to you is your personal data

        How does a single number relates to you? Is it linked to your purchase? If not, it’s not GDPR. You’re severely mistaken. Or you gave your first and last name when you bought the device, but I’m pretty sure it did not happen. You bought a piece-of-shit “smart device” and it’s sad, but it’s irrelevant to the GDPR. Random data linked to no one does not fit.

        Last but not the very least, are you European?

        • daveyOsborn@infosec.pubOP
          link
          fedilink
          arrow-up
          1
          arrow-down
          1
          ·
          edit-2
          16 days ago

          How does a single number relates to you? Is it linked to your purchase? If not, it’s not GDPR. You’re severely mistaken. Or you gave your first and last name when you bought the device, but I’m pretty sure it did not happen.

          A purchase is orthoganol to the GDPR. Even if I dug the Karcher out of a dumpster, the MAC address can still be linked to me by aggregating other data. A purchase transaction is irrelevant.

          You bought a piece-of-shit “smart device” and it’s sad, but it’s irrelevant to the GDPR.

          “Smart devices” are most certainly not irrelevant to the GDPR. The Article 29 Working Party devoted a 30-page guideline (opinion 02/2013 tagged WP202) entirely to the relevancy of smart devices to the EU privacy law just prior to the GDPR, which is now viewed through the lens of the GDPR.