• 14 Posts
  • 19 Comments
Joined 11 个月前
cake
Cake day: 2025年9月29日

help-circle


  • That’s no part of USB spec

    Do you mean the USB PD spec? It does not violate the USB spec which sets a default voltage of 5v. The adapter /might/ violate the USB PD spec if it were to claim to be PD compliant. But the shit-show we have is that USB-C does not imply USB PD. And so the market is full of USB-C things that are not USB PD. Often they do not claim to be USB PD as consumers are not wise enough to demand it. AFAICT, USB-C devices that do not mention USB PD would stand up in court.

    Note as well the adapter I mentioned is quite dumb – just hardwires pins for the situation that the appliance expects 5v without negotiation. Naive consumers could get burnt for sure whenever exceeding 5v.

    But it would be possible to implement a USB PD-compliant adaptor with the smarts to handshake, which would then refuse to complete the handshake in the event that the voltage supplied is not that requested. Of course it would be a bit strange to put that much sophistication into it which I suppose would drive the cost to that of a whole compliant PSU anyway (thus defeating the purpose). But notice the opposite has been done in a compliant manner, whereby the barrel adapter negotiates a USB voltage on behalf of a barrel device.

    as there’s no way to communcate requirements through the barrel.

    IIRC, it’s disputed whether the hanshake negotiation is needed for 5v. Some appliances expect to do a handshake /no matter what/, and some 5v appliances are designed to skip the negotiation entirely. If you are in the camp that says even 5v must have a handshake negotiation, then you would condemn the simple barrel to usb-c adapter (but perhaps not one that is only for a fixed input and the circuitry to do the negotiation).

    Hard to blame USB for when we side-step it’s design.

    The blame was not pin-pointed. I pointed out a shit show in the marketplace. There are bits of the standard you can blame (ambiguity and also having optional voltage steps), and you can also blame market actors. You can probably also blame regulators for not preventing the shit show that I described. And perhaps even blame consumers for not insisting that what they buy is tagged as USB PD complaint.


  • USB PD is also a shit show. You might want to read this:

    https://goughlui.com/2025/12/01/tested-usb-c-barrel-connector-adapters-5-5mm-od-2-1-2-5mm-id/

    Which shows those USB PD negotiations can get dicey. It chooses voltages thought to be close enough to what’s requested.

    I’ve run into a nasty problem where a USB-C appliance needed 9v. Says in the manual something like “only use Kenwood power supplies on this device”. I thought, fuck that, USB PD is a standard for a reason. I’m not going to blow money on a proprietary OEM Kenwood USB-C PSU. Then found that many power supplies actually skip 9v. The USB PD standard makes some voltage steps optional, and some mandatory. IIRC, 9v was one of the required ones, yet it was easy to find USB-C power supplies that skipped 9v but offered 12v (or 15v, I forget). And yet 12v or 15v was one of the voltage steps that’s optional. And IIRC, the Kenwood OEM PSU /only/ did 9v, which is also not USB PD compliant, so the Kenwood PSU could not be used on other things.

    So the USB PD strangely and arbitrarily makes some voltage steps optional, and manufacturers ignore the standard anyway.

    I have an adapter that goes from barrel to USB-C. Recipe for disaster. Even if a 9v PSU uses that adapter and a USB-C appliance wants 9v, it will fry shit because any non-5v appliance expects to negotiate the voltage. I don’t recall how it leads to frying (I think b/c it tries to start at the 5v default before negotiating for 9v but instead it just gets hit with 9v), but the fact that there are USB-C-barrel adapters that just hardwire without the needed logic is scary.


  • So in the context of copious dumb users plugging in anything that fits the socket, the data PIN may¹ have prevented a lot of damage while at the same time enabled HP to rack in lots of money on replacement OEM proprietary PSUs. Indeed I have seen on many occasians clueless plebs at the street market selling 2nd-hand appliances and quickly trying barrels from a pile of tangled PSUs until one fits, then trying to include that with the device they are selling without looking at voltage or anything. It’s common and I’m sure lots of gear gets fried because the general population is just not smart enough.

    I know how to match voltage, polarity, and current demands. And I got stung by the nannying to protect me from myself. Spent a lot of time disassembling a laptop, trying different RAM sticks, removing wifi cards and other components as I was baffled about what this fucking blicking LED means when it is not blinking in any way to convey an error code. Removed the CR2032 battery to reset the CMOS. Wondered if my slower than spec DDR3 RAM was causing this, so I went to the trouble of tracking down a RAM stick the precisely matched the specs. Still just got a steady non-stop blink, which the manual falsely states means it’s in sleep mode. So I was ready to conclude that the laptop was trapped in sleep mode and irreparably hosed. Perhaps I would have tossed a working laptop.

    Whether it is a good design to protect from incorrect PSUs (despite that the obscure barrel connector is probably only 19.5v systems anyway), most certainly it’s a crappy design to not inform users. To fail to assign an error code. Sure, it vaguely says in the manual something like “use only approved HP power adapters” – something /smart/ consumers do not take seriously because they know how to match PSUs to appliance and know that shit is always a branding hussle. The data pin should not be a secret that is concealed from both the user guide and the maintenance and service guide (which HP says is not for end users… yet they still withhold the info from service people).

    Perhaps good design as far as the PSU goes. But shitty to not document the situation and to not implement an error code.

    ¹ I stress /may have/ prevented damage because I have seen a lot of street market goods and only seen this obscure barrel tip on HP and Dell laptops, both of which are 19.5v.




  • AT&T is the worst of the worst. And I boycott them for countless reasons like snooping on their own customers voluntarily without a warrant. It’s really a hard-right corp. In any case, never tried them so I didn’t know they blocked egress 25.

    One trick that works if truth-in-advertising laws are in force: ask the sales people before subscribing if the block port 25. They always say “no, we block nothing” (in my experience). So you subscribe and sign the contract. Then when you see they actually block 25, you have a false advertising situation and also a contract violation (if either verbal contracts are enforcable or if you can get it in writing that nothing is blocked). So you complain. In my experience, they give a gratis upgrade to an enterprise level of service that generally has a static IP and no blocks – for the price of the residential plan you signed up for.


  • I can’t speak for @ShutUpWesley@piefed.zip, but I boycott both Google and Microsoft. This means 95+% of prospective people, corps, and gov agencies I would exchange email with are not getting email from me. They are also not getting an email address out of me.

    I have been done with email for nearly a decade now, mostly. So, to answer your question, I use fax and snail mail. Not joking. I feel liberated and don’t give a shit about postage or inconvenience. There is still that exceptional 5% or so who I will exchange email with, which does not have GAFAM in the loop.

    (edit) should add that I give friends and family an XMPP address (of my own, but often I also give them an XMPP acct for themselves). Google bounced from XMPP a decade or so ago and AFAIK Microsoft has no XMPP service. So it’s mostly snail mail and fax for govs and corps. XMPP for people.

    Any friends or family who resist XMPP are mostly stuffed. They can either proxy through a mutual friend or call me if they are local.









  • You’re likening the ability of apple/Google to see devices moving around in Ukraine to someone figuring out who you are because you have a DAB radio transmitting an SSID and a MAC address - that only people within a hundred or so metres can see.

    Of course. Apple does not distinguish a DAB radio from a smartphone from an access point. It just blindly collects all SSIDs and MACs. Why do you think a soldier in Ukraine would get not only different treatment, but in fact more compromising treatment? That’s absurdly unrealistic. It costs Apple money to pay engineers to write tailored code and filters that then get deployed to all iOS devices at the risk of the exceptional logic doing the wrong thing. Of course iOS devices indiscriminantly send all data just the same.

    The Ukraine soldier tracking was a scandalous embarrassment, so it stands to reason that adjustments have been made since then – and most likely by Ukraine not Apple. But if it were Apple, the change would obviously be to /not/ collect the compromising data of soldiers. A war fighter has a higher expectation for privacy than a DAB radio listener.

    It’s not Apple who tracked the Ukrainian soldiers. The exploit was demonstrated by an end user who was simply making use of available data from Apple. IOW, some avg. Joe tinkering in their basement could do it. And they could do it with LESS information to start with. The person who demonstrated the tracking was much further than 100 meters. They were not even in Ukraine IIRC. They did not know where the soldiers were to begin with (IIRC). Unlike a Karcher scenario, where an adversary could very well have the victim’s starting location. It’s trivial track the victim from there in this case.

    Again, I bring you back to the test laid out by the EDPB. For indirect identifiers like this to be considered personal data you have to consider the technical ability and the liklihood of someone converting that indirect identifier into something that actually identifies you as a natural person.

    Do stalker victims have to prove the likelihood that their threat agent will attack? It’s already clear to me that the GDPR is mostly a failure. If judges and GDPR practitioners were to require proof that excessive data would likely lead to misuse as a precondition to corrective action against art.5-1© infringements, it would be yet another failure of the GDPR. The whole point to Art.5-1© (data minimisation) is to improve privacy generally without anticipation of particular threats. That’s the whole point of it. What you suggest is a purpose-defeating abuse of interpretation and discretion.

    But in the real world, I don’t believe you do. You mention a stalker - a stalker isn’t going to find you by driving around using a WiFi scanner looking for a DAB radio.

    If I ever have a stalker, I hope they are as unmotivated and undevoted as you suggest. But I have to say you have a strangely optimistic or flippant view of the psychology of a stalker.


  • But a DAB radio? Like others have said,

    Others? You mean the person who thinks data is only collected by product registrations? Who thinks “smart” devices have no GDPR relevance? And who thinks MAC addresses are not unique and who also thinks a MAC address on a DAB radio can be changed by consumers apparently without breaking an anti-reverse engineering terms of use? Who also thinks Karcher would become GDPR compliant through a MAC changing mechanism if it were to exist. Who then tried to establish credibility by claiming to endorse the GDPR. Indeed… not a good source.

    unless you registered it under your name then its MAC is not linked to you.

    You cannot really know what Google and Apple do with their data collection as opaque as they are. But the data is there. They have enough to link people to MAC addresses on a large scale in an automated fashion. The data collection is proven by Douglas Leith’s research.

    At the same time, we need not rely on assumptions. I could unwittingly place my Karcher within view of my front window while my neighbors who know exactly who I am. I might also be the sole person in hundreds of meters who has a Karcher that emits a unique MAC address. Any arbitrary owner of a Karcher radio would not necessarily even be aware of the reckless emissions. My neighbor would realistically have a great degree of certainty that the MAC address relates to me as they can see the signal strength increase ast they approach my dwelling and decrease as they walk away from it.

    To make this more interesting, replace “neighbor” with “stalker” in the above paragraph. Then when I move to get away from the stalker, the DBs of Apple or Google could reveal¹ my new location. Or the stalker can war drive if they know I didn’t move far.

    ¹ Note that research showed that Ukranian troops were trackable using Apple’s map tool that all ordinary Apple consumers have access to.





  • You’re making lots of assumptions and leaps about Google.

    Amid Apple and Google’s opacity, you’re making lots of assumptions and leaps about Google that a Google spokesperson would praise you for. It’s unwise not to assume surveillance advertisers are collecting all profitable data possible.

    Like anyone else all they can do is map SSID to a general locality. They still dont know who you are based on that single piece of information.

    You’ve apparently not read Douglas Leith’s research. It’s the MAC address that is sent along with other telemetry data.

    The question is - is an SSID personal data.

    No. It isnt.

    We’re talking about MAC addresses that are linked to an individual natural person. Think of the SSID as the bait by which the uniquely identifying MAC address is discovered and collected.

    Is a MAC? Potentially but only to a very specific and small number of entities.

    Nonsense. A MAC address is unique and the box emitting it is owned by a particular person. In residential areas most such devices are owned by natural individuals.

    And then as I said for it to be personal data the link between that device and you has to be realistically and reasonably likely to occur.

    It’s automated. Apple collects the MAC addresses along with telemetry data. Apple also collects other data which can be aggregated. Data aggregation is profitable. It enables advertisers to know the most about their ad targets.

    I look forward to reading the result of your court case against Karcher in 3 years time.

    Woah, hold on. I never claimed the GDPR is actually enforced. The GDPR is widely disregarded. No, I do not have the confidence you seem to think I have in the GDPR being enforced. We can’t even get the most bluntly egregious indefensible GDPR violations enforced, much less any kind of nuanced scenario like this.

    The GDPR is just a prop… a façade to make the population comfortable with engaging with digital commerce (and for this purpose the GDPR works wonders on people). The discussion is whether there is a violation, not whether there would be justice. We can probably agree that Karcher will never face justice or be compelled to actually respect Art.5 and Art.32.


  • An SSID doesn’t do that. It might allow someone in the general vicinity the ability to identify which house the SSID originates from but that still doesnt reveal the identity of the person inside.

    Google and/or Apple already has that. They have maps. They know where people live.

    And to be clear, it’s not the SSID but rather the MAC address that’s unique enough to make this possible. Although the SSID alone could do it in aggregate with other local SSIDs.

    A natural person is “identified or identifiable” if they can be distinguished from others in a given context using means reasonably likely to be used and in a way that makes it possible to treat them differently.

    Google often knows who bought the Karcher radio. GAFAM is interested enough in who is buying what that they go as far as buying data from local shops in order to find out who buys what offline.

    Does the information relate to a natural person?

    Of course, when the radio is owned by a natural person.

    Is the natural person identifiable?

    They are identifiable to the entity who the SSID & MAC is shared with.

    Is it reasonably possible for someone to establish your identity and are they likely to bother trying.

    The machinery of surveillance advertisers like Google and Apple is designed to require no effort. They put effort into the infra, but from there the infra automatically identifies and grows profile data for further sales (read: privacy exploits).

    Karcher will be selling the fact that the device is WiFi enabled,

    Irrelevant. A wi-fi client does not need to broadcast an SSID.

    and they will argue that if a broadcast SSID does meet the criteria of personal data it is irrelevant

    They will want to avoid talking about MAC addresses for sure.

    because you willingly consented to it (or entered into a contract) by buying the product

    So you believe the legal basis is “consent” or “contract”? I don’t see how either apply. There is no contract to speak of. The purchase literature is on the box which does not mention SSID broadcasting.

    “Consent”-based legal basis requires being informed in the very least, according to the EDPB. And it cannot just be some fine print stashed somewhere. It requires explicit informed consent. They don’t have that. Consumers don’t even necessarily know this broadcast is occurring.

    and you can easily withdraw your consent by not using the product anymore.

    It must be unplugged. And the data subject must be informed in the first place. Which is the crux of the problem. It’s not art.5 (data minimisation) compliant, and data subjects are not being informed.