Keurig 2.0 Genuine K-Cup Spoofing Vulnerability
An anonymous reader writes A security researcher has released a humorous vulnerability description for the Keurig 2.0 coffee maker, which includes DRM designed to only brew Keurig brand coffe pods (K-Cups): "Keurig 2.0 Coffee Maker contains a vulnerability in which the authenticity of coffee pods, known as K-Cups, uses weak verification methods, which are subject to a spoofing attack through re-use of a previously verified K-Cup." The vulnerability description even includes mitigating controls, such as keeping the Keurig in a locked cabinet when not in use.
Also at Hackaday.
too much free time.
Facts have a liberal bias.
Holy fuck! These pirated K-Cups are going to hurt the whole industry!
And they don't care if YOU the home user violate their profit, they care if somebody selling cups by the crate does it.
It's like a courtesy lock, it's only there to tell people you don't want them in, not to stop criminals.
K-Cups? Is this like inkjet printers? Can these genuises work out how i can spoof my lexmark pro?
I demand additional ineffective security procedures for my Nespresso machine. I'm completely ineffectively unprotected.
I should use this sig to advertise my book ISBN-13 : 978-1501515132.
I know someone who keeps a genuine k-cup lid around and just sets it on top of the off-brand cup every time he uses his machine.
Why in the hell would anybody buy a coffee maker that uses DRM to prevent using "non-genuine" coffee?
deserves to be DRM'd (now a verb!).
Oh, you thought this was a joke? Lawyers laugh last.
Do an(d doing what all parties it's election to the inventing excuses Gave the BSD at my freelance alike [to reap Is ingesting Creek, abysmal
I can only imagine how expensive that must be. The last pair of double-D's set me back a fortune before it was all said and done. Although, they were nice.
rm -Rf /home/kitchen/keurig
I fixed my Keurig problem. I now have $25 standard coffee pot in the kitchen.
This smacks of IBM and the PS/2. Long after they lost control of the market they created, they attempted to force their own propeitary expansion bus and other architecture on everyone. The end result is that the market took from them the few bits they liked and shoved them aside like yesterday's trash.
With so many alternatives out there, why on earth would anyone buy this idiotic machine that attempts to force you to use their cups yet fails miserably at doing do?
Keurig coffee, with all their DRM, just adds to our waste-plastic problem and costs about twice as much as coffee you grind at home. (http://goo.gl/NiVJ8D)
Get yourself a stainless steel cup, throw some coffee in there, and use the pilfered K-Cup tag to make it all work together.
Internet of Things.
Where all manner of previously easy to use appliances and household goods come with phone-home DRM for "added value".
We play the game with the bravery of being out of range
I now forgive you in perpetuity for Bennett Haselton and Dicevertisements...
Mostly from ignorance (It' not like the box will have "Uses electric verification to reject physically compatible coffees!" on the box in big friendly letters), but partly from being trained to expect physical incompatibility with products that use a "machine and consumable cartridges business model" like this (razors and blades, printers and ink, etc.)
So if they try a coffee and it doesn't work they assume it's a physical incompatibility and resume buying the branded ones that they know will work.
Sounds like the HP and IBM law suits over printer cartridge lock-in.
This is *exactly* the kind of thing that the DMCA was made to prevent! Tape is a circumvention device and should be banned! (Since there was recently an article here about how the DMCA is being abused, so I'm itching for them to issue a DMCA takedown against this article so I can add it to the list of reasons to repeal the DMCA).
1. Go to your favorite sore that carries coffee makers
2. Purchase a drip, french press or percolator, or whatever type I missed as per your wishes.
3. Buy some coffee at the same store. This may come as a shock to many people, but there is a large variety of typs of coffees out there. Different grinds, or grind your own - it is amazing I tell you, must be something new. Keurig is not the only company out there. I'm partial to a brand roasted in Philly, that I purchase from of all places, a diner in Rio Grande, New Jersey. But I digress.
Brew your own fucking coffee the way we used to do it when men were men, and the sheep knew to be respectful. Enjoy it on the patio, yelling at kids to get off the lawn.
The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
A malicious attacker could substitute toxic fake coffee or hot chocolate for the real thing.
A malicious attacker could also substitute a coffee or hot chocolate that is tainted with a chemical that creates slight etchings in the surface of the coffee cup or other cup used to hold the end product. For certain types of cups, the result will be a cup that will be more likely to harbor bacterial growth than one with a smooth surface. Assuming a successful attack, the risk of illness or fatality is low for a healthy adult but it might be significant for a person with a suppressed or compromised immune system.
Recommended mitigation:
Keep people who want to kill you away from your coffee maker.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
How
Fucking
Handy.
And so cool that the last people get their cup long after the first are done, or more likely if the guests have manners, the first will wait ahile their coffee gets cold.
In a world where people become lazier ever day, it's hard to imagine how such a waste of time would ever catch on.
Oh, I'm sorry, I didn't realize Keurig users don't have any friends. Carry on.
The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
The 2.0 can brew a cup or carafe of coffee depending on the pack inserted. They are just using rfid to differentiate. If they can not differentiate they don't brew.
In all seriousness, research the cost differences between traditional coffee makers and coffee vs the Keurig.
Tassimo
Nespresso
Get free satoshi (Bitcoin) and Dogecoins
in the Java run time environment
My God can beat up your God. Just kidding...don't take offense. I know there's no God.
Really just awesome. Hey can someone down mod me to negative bazillion?
It's horrifying, M$ should do something quick.
Please keep the discussion to coffee. I'm straight, as is most of the population, and I don't want to know what you do when you go to San Francisco
I'm an American. I love this country and the freedoms that we used to have.
For infringing DMCA, wire fraud, computer fraud and abuse, circumvention and dissemination of DRM, racketeering, leading to losses of [pinkie] One Billion Dollars [/pinkie] to Keurig.
Stand by for completely over-the-top reaction from the Establishment.
Prove anything by multiplying Huge Number times Tiny Number
We use something like these which are dirt cheap at just about any drug store:
http://topicspill.com/2013/01/03/official-cafe-cup-website-reusable-coffee-cup-you-can-fill-with-your-own-coffee/
We use K cups because we're lazy, but if we're go tot he trouble the refillable cup above drops in just like the real deal. It sounds like 2.0 (without the hack in TFA) would end that.
The way demonstrated in the video is a pretty ugly way to fix the problem, you have to constantly put your fake lid on top of the cup you make. Towards the back left side of the piece that lowers down there's some kind of small optical sensor that looks for the keurig border that's only on keurig cups -- if you peel the label off one you can cut out a small piece of just the border and tape it directly under the sensor -- you just have to make sure it's lined up the way it expects and you'll never have to futz with an extra lid again. Some quick scissor work and a piece of scotch tape and it's been going strong for probably around 2 months now.
Tassimos also use proprietary pods. Nespresso's patent has expired and there is competition, but most of it sucks (unlike the situation with Keurig)
Freedom Clip: Clips onto your Keurig over the DRM sensor hole so you don't have to mess with extra foil.
https://www.gourmet-coffee.com...
because the management of the place where I work decided to put one in
Those makers that force me to use Genuine Coffee (tm) have been a godsend! Before I started using K-cups, sometimes in my morning pre-caffeine foggy haze, I'd end up putting all kids of shit in my "standard" coffee maker. Pencil shavings, oatmeal, cheerios- I even packed an entire bag of pork rinds in there once! Some things were surprisingly good- I still make Fruit Loop coffee to this day- but others were absolutely horrible (pork rinds only sound good in theory). Ever since I switched to my Keurig, I have been saved from myself countless times. No more gagging on nutmeg, no more iron filings! So to answer your question, *I* am the one keeping Keurig in business! You can have my K-cups when you pry them from cold, dead hands!!!!!
I've had better coffee from a coffee percolator than from a K-Cup. It's simpler too, if you have one with a mesh screen you don't need filters and easily rinses out if you don't leave the coffee in it all day. Else you can scrub it out with a long handled brush when it starts smelling like old coffee. (for me the percolator coffee seems to do the best job at high altitude, start boiling at about 92C for me)
Since K-Cup's can't make espresso (not enough enough pressure), no need to compare it to a proper espresso machine. It's simply an elaborate drip coffee maker. A $30 Mr. Coffee from Costco will also make a fine drip coffee. You can use expensive unbleached compostable paper filters if you want, they're still a few percent of what each K-Cup costs.
My compost pile loves used coffee grounds.
“Common sense is not so common.” — Voltaire
I agree. Keurig is trying to sell Keurig 2.0 which has limited selection since you can't use "Keurig 1.0" pods in it. I'm guessing somebody will make a Keurig 1.0 compatible coffee brewer (if they haven't already). This will immediately have a large selection of pods that can be used in it, thanks to Keurig 1.0's success. A couple of years from now, talking about making quick cups of coffee might refer to SOME_OTHER_MAKER machines and not Keurig.
My sci-fi novel, Ghost Thief, is now available from Amazon.com.
Dear valued customer,
Our software is software is special, copyrighted stuff,
Just because the machine you bought contains it, does not mean you have a licence to use it for just anything.
To help you remember, we use DRM.
Just remember that circumvention of DRM to avoid a copyright issue is a federal offense.
Have a nice day.
Their marketing plan is a clever way to circumvent the need to make customers happy.
If you don't have any, you don't have to make them happy.
Clearly, that is their goal.
I wonder what the street price of a pre-2.0 machine is these days?
Yep. Pointy-haired-bosses make up the bulk of Keurig's market.
No... I'm pretty sure it would inject water.
Now the next revision will have a mandatory internet connection so they can blacklist used cups.
I am becoming gerund, destroyer of verbs.
I bet they'll still call them "K Cups" but like the modern "PC", the new generation will have no idea where the name comes from.
The coffee doesn't power the maker, your analogy is shit on a stick.
Does anyone else think these K-cups are extremely wasteful and possibility toxic? We had one these machines at my last work. Basically the machines pokes a hole and then pumps hot water thorough thin plastic. The garbage bin was full of these k cups which a normal coffee pot would just dispose of a paper filter and coffee grinds. I don't think they are recyclable due to the insides.... unless someone was to rip one open and take out the grinds. I hope these things get discontinued.
Keurig 2.0 machines brew K-Cup packs and larger K-Carafe packs. The new generation may not know what the K is but they will know what the Cup part is because you get one cup (200-250 mL) of beverage out of it.
The coffee doesn't power the maker, your analogy is shit on a stick.
I don't know, they might have something there... I'm pretty sure at 6 AM the coffee at least EMPOWERS the maker (me).
"File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
Shouldn't it be CRM? Where "C" stands for "Coffee"?
The coffee is entirely too weak and the cup is friggin' plastic. People complain about water bottles but not about this.
If the fork() commad has been run 1 or more times, you've got a full on rootkit there.
I mean, I understand the PHB/corporate group think that thinks this useful, but why, when I can get a perfectly good non-DRM official Keurig from amazon for less than I would pay for a Keurig 2.0? And no, it is not some discontinued model, it is the #1 best seller on Amazon.
"Be grateful for what you have. You may never know when you may lose it."
You're seriously a moron if you think Keurig has coffee worth pirating.
Hell, C-Cups are already enough for me!
The dangers of excessive individualism are nothing compared to the oppressiveness of excessive collectivism
Counterfeit pods to defeat DRM are all well and good, but I won't be impressed until someone makes one of these heaps of wasted technology make a real cup of coffee. And I won't be holding my breath.
I hope Keurig competitors are taking notice. Having to hack your way around their lame DRM in order to enjoy the coffee that you want is stupid. This is such an anti-consumer move on Keurig's part.