Man discovers his parents' coffee machine used 1TB of data in 10 days
ck2
87 points
37 comments
October 07, 2026
Related Discussions
Found 5 related stories in 196.1ms across 8,795 title embeddings via pgvector HNSW
- A 12TB Steam “teraleak” spills more than a decade of lost PC gaming history WithinReason · 371 pts · August 31, 2026 · 54% similar
- Devastated father says his 9-year-old son spent $118,000 on YouTube ads vanburen · 58 pts · September 16, 2026 · 48% similar
- 16-year-old found Microsoft bug, got admin access to 17.3T-row databases johnshades · 26 pts · September 30, 2026 · 47% similar
- Another way to leak traffic on Android has been discovered mhitza · 33 pts · September 11, 2026 · 46% similar
- LG accused of 'egregious invasion of privacy' over TV data collection beardyw · 12 pts · September 09, 2026 · 46% similar
Discussion Highlights (9 comments)
ck2
it took me a month to notice my Midea A/C was absolutely hammering my router I didn't even know it had wifi capability but it was trying to connect I use mac whitelist so it wasn't even getting in but that didn't stop it from trying every seond Fortunately it was just a usb dongle so yanked it out
altairprime
In the Twitter thread linked, the person confirms two things: 1. It saturated the local network with 1TB of metadata sniffing scans, not the network uplink to the outside world. 2. It does so because, as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.
tamimio
Reminds me when couple years ago I plugged the TV to the internet (so my relatives kids can watch YT) and I forgot to unplug it for almost a week after, only to find the router dns resolved (and blocked) a million queries, all from that one TV!
rendall
The GDPR consent form on this blog did not have a “Reject all” button. It required me to manually reject 16 instances of “legitimate interest,” then scroll through 1,746 vendors to make sure they were all set to reject. Seems worth mentioning in a post about excessive and intrusive collection of user data. The moral outrage rings hollow when opting out of tracking is so deliberately onerous.
ButlerianJihad
A year or two ago, I was using NextDNS in ad-blocking and logging mode, which very helpfully exposed malware sitting on my very router, which had been completely undetectable, except for the veritable flood of bizarre DNS queries it was routinely sending to the self-configured DNS servers. Now that I have a new router and I've re-enabled NextDNS, I've ironically discovered that the chief abuser of DNS right now is the router's own legit security software, which is absolutely hammering on the same query, several times a second. Of course, since I am currently on NextDNS free tier, this matters a lot, because they cut you off after about 300,000 queries in a month. So any hammering abuse will make me lose my privileges much earlier than I would otherwise. So, to stop the abuse, should I shut off my legit security software? It is absolutely rubbish at identifying malware on the device itself...
matteoraso
I honestly hate the IoT so much. Why should a coffee machine of all things use data? Just make the coffee.
ButlerianJihad
Last year I had a big dispute with my ISP that was refusing to support or provide proper WiFi on their router, even while they touted a trademarked brand-name to do it. I ended up turning their router into Bridge Mode and purchasing a real router that could do WiFi. I did this extremely reluctantly, because every other personally-owned router had contracted malware. After installing the new router (Netgear) my HP LaserJet began printing error pages. Like, I had done nothing to send anything to it, but a blank error page or three would pop out of it at very random times. It took awhile to narrow down and diagnose this. But it turned out that the Netgear system had a very... proactive network malware detection system. It was red-team scanning my LAN for "vulnerabilities" or exploits or the presence of malware (I think just known vulns). It was a known side-effect of these scans, where it would tickle an RTSP TCP port of some kind and the HP printer would respond with its error printout. I was so livid that the router was scanning the LAN, basically unbidden and completely undocumented. Even worse, they were not sharing the logs or results of that scan with the consumer. No, they were being sent back to the Netgear mothership, and their cybersecurity vendor overlords. So the scans were not designed to benefit me; they were simply designed to spy on everyone from a privileged vantage point. Now I ask you, why is a piece of kit that is supposed to be "yours" compiling secrets about your network, hiding them from you, and turning them over to, I guess a big database for hackers to leak in due time? This is not a question of "well, devices hooked up to a network should not be vulnerable" if the devices were contained in a private network, and 100% inaccessible from outside, and only attackers inside my perimeter could do these exploits in the first place. Thankfully I found a way to disable this. Their "security" shitware is still spamming DNS and I may be forced to disable that as well. Meanwhile, routers 100% cannot self-introspect or self-diagnose and find their own malware. I've said it once; I'll say it again: consumer routers are the Achilles Heel to your network. They are ideal points of compromise for any actor to gain a foothold and pivot, or simply gain persistence undetected. Your ISP doesn't care, and your vendors don't care. Perhaps you should.
landgenoot
Never assume malicious intent when incompetence. I have multiple devices that queries their update server every 15 seconds, which all shows up as the top 10 queried domain in my network.
jason_s
`C0FFEEEEEEEEEEEEEEEEEEEEE...`