Popular Sex Toy Caught Sending Intimate Data To Manufacturer (fusion.net)
In a world where thermostats, and smart locks can be hacked, and companies covertly record information, why should sex toys remain unaffected. Fusion is reporting that the We-Vibe 4 Plus, a popular vibrator sends a range of intimate data to its manufacturer. The sex toy uses a smartphone app, which lets a use control the vibration among other things. From the report: When the device is in use, the We-Vibe 4 Plus uses its internet connectivity to regularly send information back to its manufacturer, Standard Innovations Corporation. It sends the device's temperature every minute, and lets the manufacturer know each time a user changes the device's vibration level. The company could easily figure out some seriously intimate personal information like when you get off, how long it takes, and with what combinations of vibes. This was revealed on Friday at hacker conference Defcon in Las Vegas by two security researchers, who wish to be called only by their handles @gOldfisk and @rancidbacon. The two examined the app's code and the information being sent by the device over Bluetooth. In a statement sent by email, Standard Innovation Corporation's president Frank Ferrari confirmed that the company collects this information. [...]
" seriously intimate personal information like when you get off, how long it take"
Most Slashdotters already have information like this collected by their ISP ;-)
If you post as Anonymous Coward, don't expect a reply.
Is nothing sacred anymore? Are we really nothing more than market research tools and products to be sold to the highest bidder anymore? Look, if you give me something for free, I don't think it's necessarily unreasonable to ask for something in return (provided you disclose that you're collecting that data). But if I'm paying for it, then please just stop. I'm the customer, not the product.
"Tell me doctor, with all of your defenses, are there any provisions for an attack by killer bees?"
Do they have the smartphone-enabled model that lets you control the vibration functionality from a *remote* smartphone, so you can further bridge the phone sex gap?
I'm asking for a friend.
It's hard to type properly with only one hand
If you can get over the fact it's about sex, it's actually a pretty good collection of metrics to collect when you're looking to get the best performance out of your product.
They'll take that data and use it to improve future products to better get you off /with science/
Also could provide pretty good data for legit scientific study - It can be hard to get funding to study taboo subjects.
Of course, this all needs to be clearly stated in a privacy policy and data should be anonymized.. That's the real fuck-up here.
Sex toy makers are dicks.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
...this security issue will affect very few /.ers...
On the upside, it could be used to create a custom profile on what REALLY gets the person off. I imagine a vibrator that "learns" would be a welcome asset to a lot of women out there.
The real problem with your philosophy is that so much of that information is secretly personably identifiable.
It is like the extra data a browser gives - things like versions, addons, etc. There is enough variability that you can determine the exact person.
It may not be good enough in a court of law, but it is good enough for a private investigator.
excitingthingstodo.blogspot.com
Does it send the phone's device ID? I didn't see it in the summary.
The article also doesn't even mention the topic of personally identifiable information. That fact alone speaks volumes about the question, given that TFA quotes a rather lengthy statement from the company president, who didn't once take the opportunity to say that the device doesn't collect personally identifiable data.
So I'm genuinely not seeing what's inherently wrong with wanting to understand how products are used and could improve, especially in the burgeoning sexual-health industry.
Please note that "wanting to understand how products are used and could improve" is neither the ethical nor the logical equivalent of collecting private, intimate, real-time data without anywhere informing the purchaser that this is happening. Also, even if the data collected isn't personally identifiable now, it could become so later, and there are plenty of precedents for this.
Another note: when the president of the company says "our policy does disclose that we may collect data", that refers to their website policy; it IS NOT disclosed when the app is downloaded, according to TFA.
Do you see now "what's inherently wrong" with this picture?
'The Economy' is a giant Ponzi scheme whose most pitiable suckers are the youngest among us and the yet-unborn.
Non-personally identifying data rarely is non-personally identifying. Also, they failed to mention it in their privacy policy, which means they probably broke the law in many EU countries where it is mandatory when data is collected this way.
It's okay if they ask and have an opt-in button, but just doing it on the sly is underhanded and wrong.
const int one = 65536; (Silvermoon, Texture.cs)
SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
Great - now I have to worry about man-in-the-middle attacks in the bedroom too?
If Slashdot were chemistry it would look like this:Cadaverine
give the editors a break. they had to type this summary with only 1 hand!
--
"It is now safe to switch off your computer."