科勒公司可以访问来自“端到端加密”马桶摄像头中的图片。
Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera

原始链接: https://varlogsimon.leaflet.pub/3m6zrw6k2bs2p?interactionDrawer=quotes

科勒最近推出的售价600美元以上的“Dekota”智能马桶承诺通过数据收集提供肠道健康信息,但其隐私声明正受到质疑。科勒大力宣传用户数据采用“端到端加密”,导致许多人认为只有用户才能访问数据。然而,该公司承认他们*可以*解密收集的数据——这意味着它并非真正的端到端加密。 相反,科勒使用标准的HTTPS加密进行数据传输和“静态”加密,以及内部安全措施。至关重要的是,科勒保留了访问数据的权限,并打算将其用于超越个人用户利益的目的,包括训练人工智能模型。 虽然科勒表示用于人工智能训练的数据是“去标识化”的,但其隐私政策允许更广泛的数据使用以及与第三方共享用于商业目的。营销宣传与实际情况之间的这种差异引发了对用户隐私以及这款新型设备数据收集范围的担忧。

一份最新报告详细说明了科勒公司能够访问其“智能马桶”内摄像头拍摄的图像——尽管该公司声称使用了端到端加密。Hacker News上的讨论强调了对收集的数据的隐私担忧,特别是其可能被用于人工智能训练和健康分析。 尽管该公司辩称访问数据对于处理健康结果是必要的,但评论员指出,核心问题不是数据*如何*被访问,而是数据*是否*被收集并与个人关联。建议优先考虑完全匿名化,以减轻风险,即使发生数据泄露。一位评论员将这款马桶戏称为“智能管道”,它展示了一种令人担忧的趋势,即日常物品越来越依赖数据驱动。
相关文章

原文

In October Kohler launched Dekota, a $600-plus-monthly-subscription device that attaches to the rim of your toilet and collects images and data from inside, promising to track and provide insights on gut health, hydration, and more. To allay the obvious privacy concerns, the company emphasizes the sensors are only pointed down, into the bowl, and assures potential buyers that the data collected by the device and app are protected with "end-to-end encryption”.

Kohler Health’s homepage, the page for the Kohler Health App, and a support page all use the term “end-to-end encryption” to describe the protection the app provides for data. Many media outlets included the claim in their articles covering the launch of the product.

However, responses from the company make it clear that—contrary to common understanding of the term—Kohler is able to access data collected by the device and associated application. Additionally, the company states that the data collected by the device and app may be used to train AI models.

What is End-to-End Encryption?

"End-to-end encryption", or E2EE, is a method of securing data that ensures only the sender and their chosen recipient are able to view it. Correctly implemented, it prevents other parties, including the developer of the application, from accessing the protected data. E2EE is best known for its use in messaging applications like WhatsApp, iMessage, and Signal, where it allows users to communicate securely and privately without worrying about their messages being seen by prying eyes at the app developers, internet service providers, and even governments.

E2EE also provides an additional layer of protection if the servers of the application developer are compromised by an attacker. Any data stored on those servers will be meaningless to the attacker, which can significantly reduce the impact of a breach. For a more detailed look at E2EE, see A Deep Dive on End-to-End Encryption from the Electronic Frontier Foundation.

What is Kohler Doing?

The initial issue with Kohler using the term “end-to-end encryption” is that it’s not obvious how it could apply to their product. The term is generally used for applications that allow some kind of communication between users, and Kohler Health doesn’t have any user-to-user sharing features. So while one “end” would be the user, it’s not clear what the other end would be.

I thought Kohler might actually have implemented a related data protection method known as “client-side encryption”, used by services like Apple’s iCloud and the password manager 1Password. This technique allows an application to back up a user’s data to the developers servers, or synchronize data between multiple devices owned by a user, without allowing anyone but the user to access the data.

But emails exchanged with Kohler’s privacy contact clarified that the other “end” that can decrypt the data is Kohler themselves: “User data is encrypted at rest, when it’s stored on the user's mobile phone, toilet attachment, and on our systems.  Data in transit is also encrypted end-to-end, as it travels between the user's devices and our systems, where it is decrypted and processed to provide our service.”

They additionally told me “We have designed our systems and processes to protect identifiable images from access by Kohler Health employees through a combination of data encryption, technical safeguards, and governance controls.”

What Kohler is referring to as E2EE here is simply HTTPS encryption between the app and the server, something that has been basic security practice for two decades now, plus encryption at rest.

How is Kohler Using the Data?

If Kohler can access the data stored on its servers, what are they doing with it? While I don’t have a precise answer, there are indications they’re using it for purposes beyond simply providing a service to the user. This may include training AI models. 

In response to my question about their use of E2EE, Kohler told me “our algorithms are trained on de-identified data only.” When signing up for an account on the app, the user is prompted to allow Kolher to use the data to "research, develop, and improve its products and technology, and to de-identify [the user’s] data for lawful purposes.”

And the privacy policy states data may be used “To create aggregated, de-identified and/or anonymized data, which we may use and share with third parties for our lawful business purposes, including to analyze and improve the Kohler Health Platform and our other products and services, to promote our business, and to train our AI and machine learning models.”

联系我们 contact @ memedata.com