<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: 8fingerlouie</title><link>https://news.ycombinator.com/user?id=8fingerlouie</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 10 Sep 2026 08:07:11 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=8fingerlouie" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by 8fingerlouie in "216M Spy TVs – The LG Smart TV Problem [video]"]]></title><description><![CDATA[
<p>Can you spot a device like this : <a href="https://www.intersign.dk/cdn/shop/products/868e2a0dce897d05afc0a7cafdf4c974.jpg" rel="nofollow">https://www.intersign.dk/cdn/shop/products/868e2a0dce897d05a...</a><p>The linked image shows a module meant for easy integration, but it could also simply be a part of the main board of the TV. They could "hide" the GSM antenna alongside the wifi antenna.</p>
]]></description><pubDate>Tue, 08 Sep 2026 06:40:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49606349</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49606349</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49606349</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "216M Spy TVs – The LG Smart TV Problem [video]"]]></title><description><![CDATA[
<p>Or simply increase the selling price by $20, would you even notice ?<p>And if they're not expecting to make $20 over 10 years selling your data, it hardly seems worth risking your reputation over.</p>
]]></description><pubDate>Tue, 08 Sep 2026 06:30:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=49606272</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49606272</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49606272</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "216M Spy TVs – The LG Smart TV Problem [video]"]]></title><description><![CDATA[
<p>Because they don't. It's too much guesswork, and honestly pretty complicated. From the user perspective the TV would appear to go offline every now and then, so also somewhat easily detected.<p>It's much easier to just throw a $10 5G modem in there, pay the $2/year subscription fee for service, and extract data that way. Assuming a 5-10 year relevant lifespan of the TV, they'd throw $20-$30 on top of the sales price for the modem and 10 years of service.<p>The 5G modem could run completely independent of the wifi network, be a completely different circuit, and you'd never know it was there.</p>
]]></description><pubDate>Mon, 07 Sep 2026 21:28:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=49603168</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49603168</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49603168</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "216M Spy TVs – The LG Smart TV Problem [video]"]]></title><description><![CDATA[
<p>Why go through all that trouble of spoofing MAC addresses or assuming it will always be able to connect to an open WiFi network.<p>5G connectivity is cheap. You can put a 5G modem in pretty much any device for $10 or less, and pay roughly $2/year in subscription fees. My local water utility with ~900 subscribers pays $2/year for 5G connectivity for water meters, and I have no doubt you can get it much cheaper at scale.<p>They don't even have to tell you about the 5G modem. It could exclusively be used for exfiltrating data about your viewing habits. It's virtually undetectable and more or less impossible to block. The TV could behave nice on the Wifi, you can block all the DNS servers you like, it would still be able to phone home.</p>
]]></description><pubDate>Mon, 07 Sep 2026 21:25:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=49603152</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49603152</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49603152</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "216M Spy TVs – The LG Smart TV Problem [video]"]]></title><description><![CDATA[
<p>They tried that in Denmark a decade ago (or more). Enabled a "public wifi" on all home routers to provide wifi coverage for that company's customers everywhere.<p>They gave every assurance that it would be secure, completely separate from the users own network, and the bandwidth consumed would be added on top of whatever the user had a contract for.<p>It took a couple of days after launch before somebody managed to gain access to someone's private network from the public network and they shut it down again and never opened it again.<p>Anyway, I may be spoiled from living in Denmark, but I'm using my own router, which is an option when ordering, so I'm fairly certain nobody is sharing additional wifi hotspots.<p>And it's not just me. The majority of people I know use some kind of 3rd party router with their ISP. Granted, some of them just use whatever the ISP sends them, but even then I haven't ever seen any additional wifi networks, and the ISP prints the router admin password on the box itself, so you can poke around if you like (though the ISP has a backdoor, which is also why 3rd party routers are a thing).</p>
]]></description><pubDate>Mon, 07 Sep 2026 21:20:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=49603103</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49603103</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49603103</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "LG smart TVs caught logging audio with screen off and snooping on local devices"]]></title><description><![CDATA[
<p>For now, setting up an IoT network is pretty much best practice, and I'd wager the average Hacker News reader both has the necessary equipment and skills to do it. That may not always be the case.<p>Assuming they install some 5G modem in the device, which is pretty much dirt cheap these days (our local water utility uses 5G for meter readings, and the cost per meter is something like $1/year), there's literally nothing short of a faraday cage you can do.<p>The can report on what you watch freely, and only consumer laws can stop them. However, without a wifi connection they can't snoop on your local network, and they probably can't connect the data to you, assuming you don't register the TV for those 3 months of added warranty or whatever they try to get you to register.<p>I tend to avoid devices that are built to snoop on you, so no Amazon Alexa, no Google Home, no Apple HomePod. Everything I have utilizes local control via Home Assistant, and most of it is actively blocked in the firewall from accessing the internet. It's not hard to implement, and doesn't require a master of IT, but it does remove a lot of the convenience, which I guess is the reason people don't do it.</p>
]]></description><pubDate>Mon, 07 Sep 2026 12:23:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=49597511</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49597511</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49597511</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "LG smart TVs caught logging audio with screen off and snooping on local devices"]]></title><description><![CDATA[
<p>And what exactly would they use that particular access path for ?<p>I could see a threat if the TV had access to the internet and could establish a TLS tunnel or similar from the mothership, and execute commands on my LAN (or IoT network as it stands), and report back. That could establish a command & control channel that could potentially orchestrate an attack on my infrastructure via the TV.<p>However, reporting that "network X exists and has these devices" over a different network complicates things a fair bit. In theory they could still use the TV as a command and control platform, but it would have to switch networks between my closed network and the open network in order to execute commands and report results. Not saying it's impossible, just very unlikely.<p>Besides, the TVs are not alone in being cut off from the internet. I have two IoT networks, one for trusted devices (AppleTVs, Sonos, and the likes), and one for untrusted devices like TVs. They run on different VLANs, and anything on the untrusted IoT network can pretty much only talk to itself (client isolation) and the gateway, and there's no internet and no open ports to any other VLAN.</p>
]]></description><pubDate>Mon, 07 Sep 2026 10:33:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=49596567</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49596567</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49596567</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "216M Spy TVs – The LG Smart TV Problem [video]"]]></title><description><![CDATA[
<p>I use Home Assistant to turn on/off the TV via automations, sensors, etc.<p>I could possibly do it via HDMI CEC, but I have a couple of Sony Bravia TVs that more often than not completely ignores that, so I prefer having control over assuming it happens.</p>
]]></description><pubDate>Mon, 07 Sep 2026 10:27:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=49596520</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49596520</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49596520</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "216M Spy TVs – The LG Smart TV Problem [video]"]]></title><description><![CDATA[
<p>But it's never connected to the internet, not even for software updates. If the TV isn't connected to the internet there's no reason to update it, assuming the TV works as expected.<p>It's a trade off I guess. I use Home Assistant to control TVs, so kinda need the access.</p>
]]></description><pubDate>Mon, 07 Sep 2026 10:25:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49596509</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49596509</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49596509</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "Ask HN: How do you manage skills files?"]]></title><description><![CDATA[
<p>I find them useful for deploying task specific agents, like reviewing Jira tickets, or otherwise ensuring compliance in open format submissions.<p>Otherwise I agree, and you don't even have to be that verbose with prompt engineering these days as LLMs have gotten increasingly good at figuring out what you want.</p>
]]></description><pubDate>Mon, 07 Sep 2026 09:32:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=49596105</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49596105</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49596105</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "216M Spy TVs – The LG Smart TV Problem [video]"]]></title><description><![CDATA[
<p>My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet.<p>DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.<p>All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.</p>
]]></description><pubDate>Mon, 07 Sep 2026 09:30:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=49596087</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49596087</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49596087</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "Creating Backup Storage Sucks"]]></title><description><![CDATA[
<p>I can't tell you what works for "you", but here's my setup, with the hope it inspires someone:<p>- Live data lives in the cloud. I could self host it, but it would always be inferior to the cloud offerings, and usually more expensive for my ~3TB data.<p>- I make local backups nightly<p>- I make remote backups nightly to another cloud.<p>- Once every week I make a local backup to a device that is offline 6/7 days a week (an old Synology NAS that powers on automatically, and powers off when it's been idle for 30 minutes).<p>- Every year I curate our photo library and burn a set of M-Disc Blu-Ray copies of all photos created or modified in the past 12 months. Two identical sets, one stored at home, the other stored at a remote location, each clearly labeled "Photo Backup <year>".<p>- Every year I also update a couple of external HDDs with the entire photo library, again identical copies, contents are verified yearly and updated, and stored again. Disks are also clearly labeled as "Photo backup".<p>As others have written, curate your data. In my case we have a 2.5TB photo library spanning a couple of decades, but that could easily have been 4TB without curation. I only backup documents in the nightly/weekly backups. (Personal) Documents usually only hold value for a short time, and after that it's mostly sentimental.<p>Anything media, or anything downloaded from the internet like books, music, etc, regardless of if I purchased it or pirated it, is not getting backed up. If it came from the internet, there's a good chance it can still be found on the internet.<p>I also (mostly) don't run RAID. RAID is for availability, and since all my important data lives in the cloud, and I will likely survive if one of my backups dies, there's little reason to run raid. The only exception is the share where PhotoSync backs up our photos, which is on a "small" RAID1 volume mainly because it acts as the source of all the other photo backups, so consistency and correctness is important.</p>
]]></description><pubDate>Thu, 03 Sep 2026 10:02:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49548049</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49548049</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49548049</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "It takes 5 cloud services to hear my doorbell"]]></title><description><![CDATA[
<p>I haven't tried it, but with newer ESP32's supporting Matter and Zigbee, you could potentially create a device with ESPHome that Alexa can "trigger" when the doorbell rings, which in turn can trigger HA, eliminating both the VPS and SmartThings in the process.</p>
]]></description><pubDate>Mon, 31 Aug 2026 13:28:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=49509550</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49509550</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49509550</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "My Homelab Got Hacked – A Postmortem"]]></title><description><![CDATA[
<p>Especially because this is a hobby for most homelabbers, I've never understood why people insist on opening it to the internet.<p>Visiting various subreddits, people massively underestimate the amount of time required to host something in a secure matter, and just because their little corner of the internet hasn't been hacked yet doesn't mean it's safe.<p>Self hosting stuff means you have a side gig as an unpaid system administrator. Sharing it with other people also means you have a SLA.<p>I self hosted for decades, but 5-6 years ago I simply put everything important in the cloud. The only things I host at home are media and my home assistant, and access to that is guarded by a VPN. I have a site to site tunnel between my home and summerhouse to allow media streaming there, and otherwise it's just regular road warrior tunnels. Using wireguard allows me to keep the VPN up 24/7 because it supports routing only specific subnets as well as auto disabling on predefined networks.<p>I also "host" backups at home. Everything stored in the cloud is backed up at home, as well as with another cloud provider.</p>
]]></description><pubDate>Thu, 13 Aug 2026 09:27:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=49283528</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49283528</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49283528</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "Zigbee vs. Matter over Thread:Understanding IoT Protocol Performance in Practice"]]></title><description><![CDATA[
<p>Initially it was just curiosity when thread/matter was new. Back then it was a horrible experience, but I was using primarily HomeKit as my home automation platform (which only supports thread) and didn't have that much complexity. I was also using a bunch of vendor specific apps to control each individual vendors ecosystem.<p>Fast forward some years and I had my share of vendor specific ecosystems be shut down, leaving me with a bunch of technically fine paperweights, which was when I started focusing on local first access. I didn't want to be locked in by yet another vendor, and I was still using HomeKit as my main platform (still not very advanced home automation), so thread/matter came naturally.<p>What really turned things around was when I purchased a Homey Pro in 2022/2023. I could integrate pretty much everything locally, and expose it to HomeKit to the "control surface" my family used, which is when I started using Zigbee more (only had Hue before that).<p>These days I'm running Home Assistant. The Homey Pro became too small, frequently running out of memory, and switching to Home Assistant opened a whole new set of doors with ESPHome and others, like gaining control of my Vaillant Heat pump thought an ESP32 [1], or reading the wmBus telegrams from my water meter.<p>My "main criteria" at the moment is not so much if it's thread, zigbee, or wifi, but heavily focused on local control. I'm only buying devices that have local access. I'm fine with devices offering an optional cloud plan, like my Tado X TRVs, but I must be able to access them locally from HA.<p>I still default to thread/matter where possible as to not have too many things going at once, and I have zero Z-Wave devices.<p>[1]: <a href="https://adapter.ebusd.eu/v5-c6/index.en.html" rel="nofollow">https://adapter.ebusd.eu/v5-c6/index.en.html</a></p>
]]></description><pubDate>Thu, 06 Aug 2026 08:31:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=49194055</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49194055</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49194055</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "Zigbee vs. Matter over Thread:Understanding IoT Protocol Performance in Practice"]]></title><description><![CDATA[
<p>I have 47 thread/matter devices, alongside some 10-15 matter over wifi devices, so not quite 50, but "close enough".<p>It's not as fast as Zigbee, not in day to day usage, and not in terms of reconnecting, which often takes 30 seconds (ie. after a power outage) where my Zigbee devices just seem to reconnect instantly. On day to day usage there's a slight delay when turning something on, but it's maybe 100ms or less.<p>I initially had quite a few problems, but after "standardizing" on a single thread network (I had 3 before for some reason), as well as adding some wired thread border routers, things have become much more stable.<p>My zigbee to thread is still a "work in progress", replacing devices as they fail (ie. lightbulbs), and I'm also still adding new Zigbee devices like the Aqara T1 Valve controller, but I prefer thread over zigbee today.<p>One thing I will note, people tend to underestimate the range of thread (and zigbee for that matter). Each mains powered device will function as a repeater just like zigbee, and I initially thought I might need a couple of smart plugs as repeaters, but despite having a somewhat large house (by european standards) as well as double brick walls dividing it, my thread devices have no problems "seeing" a thread border router in the opposite end of the house.</p>
]]></description><pubDate>Wed, 05 Aug 2026 11:09:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=49181152</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=49181152</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49181152</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "The EU is about to sell our most sensitive data to the US for visa-free travel"]]></title><description><![CDATA[
<p>Your DNA and fingerprints are literally everywhere you go, and they don't decay as soon as you leave. Hell, even passing close by a person can transfer your DNA to their clothes.<p>If the cops have a DNA Database, they "just" need to collect all DNA from a crime scene to compile a list of suspects, and by doing so, they're flipping the question of guilt around, you're no longer innocent until proven guilty, but guilty until proven innocent. You now have to prove you didn't "do it".</p>
]]></description><pubDate>Mon, 20 Jul 2026 23:26:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48986192</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=48986192</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48986192</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "The EU is about to sell our most sensitive data to the US for visa-free travel"]]></title><description><![CDATA[
<p>> In the US there have been notorious mistakes of using biometrics to falsely recognize an unknown criminal. Does this happen in the EU too?<p>This my major concern with biometrics and DNA databases. It makes the cops lazy. "Subjects fingerprints and DNA was found on the crime scene, so he's clearly the murderer". That flips the evidence around, suddenly "I" have to prove I'm innocent as opposed to the law proving I'm guilty.<p>If you can simply collect all DNA and fingerprints from a crime scene, look it up in a database and compile a list of suspects, it also eliminates the possibility that the real perpetrator didn't leave DNA or fingerprints.<p>Sure, DNA has its use, like "here's the murder weapon, and it has the suspects DNA and fingerprints on it". It's not a guarantee, but it's a closer match.<p>As for "does that happen in Europe as well", unfortunately yes. There have been cases where the police have found fingerprints and DNA and announced they had the suspect they were looking for, only for said person to be cleared weeks or months later.<p>As a general rule, DNA and fingerprints cannot be the sole evidence in EU courts. The law will need find more evidence before they can convict you. Also, no death penalty, and "lifetime" in the EU is usually around 10 years, so not a lot of people are found innocent after 30 years.</p>
]]></description><pubDate>Mon, 20 Jul 2026 23:22:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48986157</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=48986157</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48986157</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "The EU is about to sell our most sensitive data to the US for visa-free travel"]]></title><description><![CDATA[
<p>If you have a recent EU passport (like 6-8 years), biometrics like fingerprints are already in the chip, and you won't need to be fingerprinted upon arrival or departure, at least in theory, I wouldn't be surprised if some bureaucrat decided that the passport data can't be trusted and we'll fingerprint everybody anyway.</p>
]]></description><pubDate>Mon, 20 Jul 2026 23:17:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48986109</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=48986109</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48986109</guid></item><item><title><![CDATA[New comment by 8fingerlouie in "The EU is about to sell our most sensitive data to the US for visa-free travel"]]></title><description><![CDATA[
<p>Same here, went in 2019, got fingerprinted, and went again in 2021 and 2025, and they didn't even care about my ESTA, they just waved me through.<p>The TSA agent asked me the usual questions about where I was staying, how long I was staying, I replied, and despite having printed just about everything out, he just waved me through.<p>The closest I got was a "random inspection" in an airport, and the TSA agents asked for our passports and to go through our luggage, but as soon as we flashed our Danish passports they lost all interest and just waved us through.</p>
]]></description><pubDate>Mon, 20 Jul 2026 23:14:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48986085</link><dc:creator>8fingerlouie</dc:creator><comments>https://news.ycombinator.com/item?id=48986085</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48986085</guid></item></channel></rss>