It started to stop kids vaping [pot] in school bathrooms. Then they stuck it in poor people's homes. | DEF CON Snitch Puck Talk, October 2025
from brbposting@sh.itjust.works to privacy@lemmy.ml on 19 Oct 09:52
https://sh.itjust.works/post/48192512

A lotta vapes are reportedly chock full of lead, so kids probably shouldn’t be puffing clouds in the bathroom stall, but was there any reason to design the most exploitable version of a product to alert school administrators about it?
The manufacturer was happy to expand to Section 8 (USA, subsidized) housing in spite of script kiddies, rogue employees, or legit employees working under new guidelines being able to root into the Motorola Halo 3C and use its fully-functioning microphones to invade privacy.
The frog is boiling slowly: pay more for your car insurance when your insurer buys your driving data today; risk your home insurance when you don’t install this “fire prevention” spyware tomorrow.

DEF CON 33 - Unmasking the Snitch Puck: IoT surveillance tech in the school bathroom - Reynaldo, nyx: YouTube
83,126 views, Oct 10, 2025

#privacy

threaded - newest

INHALE_VEGETABLES@aussie.zone on 19 Oct 10:40 next collapse

Yeah cool that frog started getting hot 15 years ago whats the plan haha

brbposting@sh.itjust.works on 19 Oct 10:46 next collapse

Donate to EFF

<img alt="" src="https://sh.itjust.works/pictrs/image/ee120a4b-d352-4c26-9c8f-b460b2d29340.jpeg">

alt-text:

what can the hackers do?
• buy weird coptech on eBay then tell people about it
• ask your school board if they’re using these things
• campaign for strong privacy legislation
• give money to the EFF
• stay aware and informed
• keep your friends and communities safe

supporters.eff.org/donate

INHALE_VEGETABLES@aussie.zone on 19 Oct 11:12 collapse

I feel like the privacy issues goes back waaaaay further than any of this and that attempts to stop it then were fruitless.

I hate to be pessimistic but I was butt hurt about rights to privacy online and in public (security cameras) long ago. Nobody cares about them now and soon nobody will care that I’m caught ripping bongs in a school. Lol.

I’m old and tired.

frongt@lemmy.zip on 20 Oct 00:48 collapse

No, more people definitely do care now. Not as much add they should in the ways that they should, but they do. Keep proving the information, over time people will learn.

Meanwhile, keep pushing your government reps for more immediate change.

INHALE_VEGETABLES@aussie.zone on 21 Oct 12:08 collapse

That’s what we said back then bro

anomnom@sh.itjust.works on 19 Oct 15:15 collapse

You mean24 years ago when they signed the fucking Patriot act?

Also go watch and act on Benn Jordan’s license plate reader video. It might be the best thing you can do for keeping your insurance rate low for now.

LemmyKnowsBest@lemmy.world on 21 Oct 00:01 next collapse

Ah the pleasant names they give these things: The Patriot Act, The Big Beautiful Bill, No Child Left Behind, giving citizens the illusion these will improve the country and improve everyone’s lives but it couldn’t be more opposite.

floquant@lemmy.dbzer0.com on 21 Oct 00:21 collapse

Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act doesn’t hit the same, especially after knowing what they would pass for “terrorism”

INHALE_VEGETABLES@aussie.zone on 21 Oct 12:08 collapse

Yea

AmbiguousProps@lemmy.today on 19 Oct 12:48 next collapse

A terrifying/infuriating/interesting watch.

dan1101@lemmy.world on 19 Oct 16:18 next collapse

*chock full

irmadlad@lemmy.world on 19 Oct 17:41 collapse

c. 1400, chokkeful “crammed full;” the first element is possibly from choke “cheek” (see cheek (n.)). Or it may be from Old French choquier “collide, crash, hit” (13c., Modern French choquer), which is probably from Germanic (compare Middle Dutch schokken, and see shock (n.1)).

<----- etymology freak

brbposting@sh.itjust.works on 19 Oct 18:55 collapse

Chalk-free edit, thanks @dan1101@lemmy.world

Probably < choke v. + full adj. (with an underlying sense ‘full to the point of choking’), in later use (especially in α forms) probably reinforced by association with chock n.^1^ and chock v.^1^

<img alt="OED, Oxford English Dictionary, Meaning & Use of chock-full" src="https://sh.itjust.works/pictrs/image/3f99dd31-f7ae-4f04-9dae-f42963cfe0d1.png">

Charottez chokkefull charegyde with golde, yadadamean?

irmadlad@lemmy.world on 19 Oct 19:11 collapse

Awesome! Etymology is a fascination of mine, where language derives itself from and how words and phrases have changed and even been bastardized to mean something else. One of my favorites being ‘Pull yourself up by your bootstraps’.

brbposting@sh.itjust.works on 19 Oct 22:23 collapse

lol it’s impossible to do that huh

<img alt="Screenshot of above bootstraps Wiktionary" src="https://sh.itjust.works/pictrs/image/3a083a09-df28-4fdd-8a15-dcc2f5835864.png">

The Moar I Know 💫

irmadlad@lemmy.world on 19 Oct 22:30 collapse

The phrase also derives from a mid 1800 child’s physics book that had review questions at the end of each chapter to check if you understood the information. One of the questions was ‘Can a man pull himself up by his bootstraps?’, which is of course impossible because he is being acted upon by forces greater than himself…namely gravity.

Indeed, the more you know.

fubarx@lemmy.world on 19 Oct 16:38 next collapse

The minute the Pi4 compute module showed up, the jig was up.

For the secure boot scheme to be really secure, you have to generate a unique key for each device. Most vendors don’t bother because it means each firmware update has to be signed and encrypted for each unique device. This also means you have to have the infrastructure for device attestation. You can’t just stick an update file on a public S3 bucket or FTP site like the good old days.

Some end up reusing the same product key, so if it’s compromised, all devices in that family can be hacked. But even that’s too much for some vendors.

Instead, they just wing it, and go back to the bad old habits (no encryption, or symmetric keys embedded in firmware) that get them featured in DefCon presentations.

thepompe@ttrpg.network on 20 Oct 09:37 next collapse

Insurance is a scam and our rulers rejoiced when they made it mandatory for cars.

[deleted] on 21 Oct 10:38 collapse

.

smh@slrpnk.net on 21 Oct 00:23 collapse

Students smoking where they shouldn’t is a PITA to me, a librarian, because it can set off some fire alarms.

I do not appreciate needing to help a less mobile coworker down the stairs to evacuate the building. I don’t like spending in the rain while we wait for the fire department to declare the “all clear”.

We don’t use spy pucks to tattle on students, though: we know what alarm was triggered and we know who checked out that study room. Or we know who came out of the single seat bathroom.

Edit: and generally students have been contrite when they return the study room key after the building was evacuated. Very “I didn’t do it but I’ll let my friends who were studying with me know…” and we’ve not had repeat offenders. Tbh, they’re [young] adults so as long as no one is hurt and I don’t hear about it I’m cool with it.