cross-posted from: https://infosec.pub/post/50218987

Karcher DAB radios are broadcasting an SSID for open Wi-Fi access. It doubles as an Internet radio, but AFAICT from the manual it’s only expected to act as a client.

So WTF is going on?

It seems like a really bad idea for consumers to connect this radio to their LANs to use to play Internet radio and podcasts when there is an always available Wi-Fi AP that enables anyone in proxity to connect to the radio. What’s the point? There is no way to disable the SSID broadcasting and it remains on even when the radio is “off” (but plugged in).

The manual shows that there is a remote control. Is the remote using wi-fi? I don’t have the remote so I have no way of verifying. In any case, this design seems like a recipe for disaster. Karcher should perhaps just stick to making pressure washers.

Google and Apple use Wi-Fi SSIDs for navigation. I boycott both companies. As such, I prefer not to have any wi-fi APs. And when I decide to run an AP, I ensure the SSID ends in _optout_nomap to opt-out of giving uncompensated help to the nav systems of Apple and Google.

Does this violate the GDPR? I cannot change the SSID, so it’s like I am being forced to share with the general public the fact that there is a Karcher radio in my home. That does not respect data minimisation.

  • one_old_coder@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    16 days ago

    All data the relates to you is your personal data

    How does a single number relates to you? Is it linked to your purchase? If not, it’s not GDPR. You’re severely mistaken. Or you gave your first and last name when you bought the device, but I’m pretty sure it did not happen. You bought a piece-of-shit “smart device” and it’s sad, but it’s irrelevant to the GDPR. Random data linked to no one does not fit.

    Last but not the very least, are you European?

    • daveyOsborn@infosec.pubOP
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      edit-2
      15 days ago

      How does a single number relates to you? Is it linked to your purchase? If not, it’s not GDPR. You’re severely mistaken. Or you gave your first and last name when you bought the device, but I’m pretty sure it did not happen.

      A purchase is orthoganol to the GDPR. Even if I dug the Karcher out of a dumpster, the MAC address can still be linked to me by aggregating other data. A purchase transaction is irrelevant.

      You bought a piece-of-shit “smart device” and it’s sad, but it’s irrelevant to the GDPR.

      “Smart devices” are most certainly not irrelevant to the GDPR. The Article 29 Working Party devoted a 30-page guideline (opinion 02/2013 tagged WP202) entirely to the relevancy of smart devices to the EU privacy law just prior to the GDPR, which is now viewed through the lens of the GDPR.