Jailbreaking your connected Coffee Machine: The Idiocy of Things

By Jason Perlow | September 21, 2017

Source: http://www.zdnet.com/article/jailbreaking-your-coffee-machine-the-idiocy-of-things

How many more of these IoT devices that use DRM technology to validate the use of proprietary refills do we have to endure?

The Internet of Things (IoT) is awesome. I love my smart devices when they make my life easier.

That's supposed to be the point of connected devices, which is to add sensor capability, remote operation, and data gathering that benefits the end-user.

Yes, that data is valuable to the device manufacturer, too, which runs cloud services in order to make that product work. And it's a huge liability should that data make it out into the wild. But that's the cost of IoT.

I have a lot of connected devices in my home. Thermostats, lighting, fans, electrical switches, garage door openers, and even my swimming pool/spa heater and pump. And, of course, my smart speakers, such as my Amazon Echo devices and Sonos devices.

Pretty much all these things -- with the exception of the Amazon Echo, which uses AWS for virtually everything -- can act as regular dumb devices that can be operated manually in the event they lose connectivity.

But, increasingly, I am starting to see smart devices that not only rely on connectivity for basic functionality but use networking and sensors in order to prevent end-users from actually getting the most out of their devices.

Specifically, I am talking about smart appliances that depend on refillable supplies. In information technology, the most notable offender is Hewlett-Packard small/home office printers, which not only use proprietary ink and toner cartridges that are specific to each model but employ validation technology to determine that the refills are in fact genuine OEM parts, and it will disable third-party cartridges if detected.

Why does HP do this? Well, the consumable supplies business for printers is huge. The company essentially sells the printers at extremely low margins in order to make up for it in consumables -- that's why the devices are so cheap and the refills cost almost as much as the printer itself.

Sometimes it is actually cheaper to buy a new printer with an included ink cartridge than to buy a refill. Hewlett-Packard is probably the worst offender in this group, but it isn't the only one. Consumer devices are also getting in on the act.

The most notable example is Keurig, which is one of the most popular pod-based coffee machines on the market. Keurig's parent company is Green Mountain, which is a coffee distributor and producer. It also developed the K-Cup standard that the Keurig machines use.

Now, it's bad enough that the K-Cup has to be licensed in order for third-parties to legally produce them. Newer-generation Keurig machines actually scan and validate the supplies using digital rights management (DRM) before brewing. If the machine detects an unauthorized K-cup, no brew for you. But resourceful end-users have figured out how to bypass that DRM with a simple hack using a previously used K-cup and a small amount of tape. There is also another hack that opens up additional brewing choices with the use of a small magnet.

Great. I love having to jailbreak my coffee machine at 7am every morning.

Another company that uses proprietary coffee pods is Nespresso. But instead of using technology to block third-party pod makers, it has traditionally done it through the supply chain; you can only buy pods directly from Nespresso on its coffee club web site, retail shops, or via authorized resellers like Amazon.

Interestingly, I am OK with this approach. But I am not OK when technology prevents users from using products -- like that is used in the company's new VertuoLine pods and brewers

Now, the Keurig brewer isn't exactly an IoT device, because it has no connectivity. But that's clearly the next step. Recently, Juicero, which went through initial Kickstarter seed funding, attempted to bring a $400 internet-connected juice machine to market. It used proprietary juice bags that you had to buy from Juicero.

The company ended up closing shop 18 months after it was founded when it was determined that you didn't actually need the machine to get the juice out of the bags.

You would think companies would learn from the Juicero experience. But apparently not.