Poop-peeping toilet attachment has a different definition of 'end-to-end' encryption
- Reference: 1764785071
- News link: https://www.theregister.co.uk/2025/12/03/pooppeeping_dekoda_toilet_attachment_encryption/
- Source link:
The [1]Dekoda , [2]released in October by people seemingly unaware of [3]this 11-year-old yet incredibly prescient Adult Swim spoof infomercial, attaches to existing dumb toilets. It includes a camera that thankfully only gazes downward at your leavings instead of elsewhere, and claims to be able to analyze waste for gut health, hydration, and the presence of blood.
Given the sensitive nature of what Dekoda is analyzing, Kohler [4]says it designed Dekoda and the accompanying Kohler Health app "with privacy-first features" including so-called end-to-end encryption (E2EE). But according to freelance journalist, software engineer, privacy expert, and former Federal Trade Commission technology advisor Simon Fondrie-Teitler, Kohler is misusing the term "E2EE".
[5]
Writing in the premiere [6]post of his /var/log/simon blog, Fondrie-Teitler dug into Dekoda's use of the term E2EE and its treatment of user data. E2EE is commonly understood to be encryption of communications data between a sender and recipient, with even the company providing the service unable to decrypt the shared data.
[7]
[8]
No such features exist in the Kohler Health app, Fondrie-Teitler noted.
"While one 'end' would be the user, it's not clear what the other end would be," Fondrie-Teitler explained in the Tuesday post before noting that his communications with Kohler made clear that the other end was the company itself.
[9]
According to the blog post and our review of Kohler's privacy [10]policy , user data is encrypted "at rest, when it's stored on your mobile phone, toilet attachment, and on our systems," as well as in transit. That said, Kohler has access to user data, meaning its version of E2EE "is simply HTTPS encryption between the app and the server, something that has been basic security practice for two decades now, plus encryption at rest," Fondrie-Teitler explained.
For that matter, it appears the company is using said data for more than just serving poo-related health data through its mobile apps.
[11]No way? Big Tech's 'lucrative surveillance' of everyone is terrible for privacy, freedom
[12]If you like to play along with the illusion of privacy, smart devices are a dumb idea
[13]Bossware booms as bots determine whether you're doing a good job
[14]Look for the label: White House rolls out 'Cyber Trust Mark' for smart devices
Per Kohler's privacy policy, Dekoda customers give the company permission to use anonymized health data "to train our AI models and for other machine learning purposes and we may disclose de-identified data to third parties."
Users have the right to decline to share personal data with Kohler, per the policy, but opting out means some services may not be provided.
In other words, Kohler really wants that data if you want to know what's up with your toilet deposits.
[15]
We reached out to Fondrie-Teitler to see what he had to say about Kohler anonymizing the data and what he thought about the company's use of such P(ee)II, and he told us that in an ideal world, none of that doo-doo data would leave its point of collection.
"Ideally this type of data would remain on the user's device for analysis, and client-side encryption would be used for backups or synchronizing historical data to new devices," Fondrie-Teitler told us in a chat on Bluesky. He's not sure that's possible, given he's not sure how Kohler's systems work, but at the least, he hopes they stop saying the system is end-to-end encrypted, giving users a false sense of security.
"I'm hoping they update the language on the website to more clearly articulate the scope of their privacy protections," Fondrie-Teitler told us.
Kohler didn't respond to questions for this story. ®
Get our [16]Tech Resources
[1] https://www.kohlerhealth.com/dekoda/
[2] https://www.prnewswire.com/news-releases/kohler-co-launches-kohler-health-ushering-in-a-new-era-of-health-and-wellness-in-the-home-302584350.html
[3] https://www.youtube.com/watch?v=DJklHwoYgBQ
[4] https://www.kohlerhealth.com/support/privacy/how-kohler-health-keeps-my-data-private/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aTDBBygTh0tCvRuoCOGb3AAAAEg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[6] https://varlogsimon.leaflet.pub/3m6zrw6k2bs2p?interactionDrawer=quotes
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aTDBBygTh0tCvRuoCOGb3AAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aTDBBygTh0tCvRuoCOGb3AAAAEg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aTDBBygTh0tCvRuoCOGb3AAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.kohlerhealth.com/privacy-policy/
[11] https://www.theregister.com/2024/09/19/social_media_data_harvesting_handling_ftc/
[12] https://www.theregister.com/2023/09/07/smart_devices_privacy/
[13] https://www.theregister.com/2025/11/23/bossware_monitor_remote_employees/
[14] https://www.theregister.com/2025/01/09/white_house_smart_device_security_label/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aTDBBygTh0tCvRuoCOGb3AAAAEg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://whitepapers.theregister.com/
GIGO
PIPO ;)
Aaargh thank you for reminding me of Eurotrash with Jean-Paul Gaultier, Antoine de Caunes… and “Pipi and Popo”.
“‘Allo my eeenglish chums…”
Down the pan...
I assume that the Kohler LLM is being trained to create potty humour, thus another example of the great strides that AI (Asinine Intelligence) has been making recently.
They'll get my shit for free when they pry it from my cold, dead hands
Yeah, local processing should be a must for this kind of app, especially since their LLM is based on "1.2M Data Points Collected during the development of Dekoda", which means it can't be terribly huge (at most a few 100 thousand weights, maybe a megabyte), so no real need to share "fecal and urine images" (from privacy policy), or willfully "opt-out of [their] processing of your personal information" (which should be opt-in instead), a simple in-package CPU should right be able to do the doo indeed, without a monthly subscription.
Then again, sensor fusion may be more appropriate to this job than "spectroscopy" alone. Olfactive sensors could help diagnose the degree to which something may have inadvertently crawled up the user's buttocks, and died, prior to any given session, and FFT analysis of audio could help not-only determine whether that crawler is in effect still alive, and screaming, but also classify session characteristics into health-defining torpedo, naval mine, cannonball, and jet-stream categories (among others) ...
The possibilities seem endless!
(that Adult Swim Smart Pipe was truly prescient. Hopefully Dekoda can also, in time, update my waste profile on all my social media accounts simultaneously ... ;)
I'm disappointed by the Comentards' lack of shit jokes!
Look, it is quite simple. For the right-pondians among us it is quite late in the evening.
We are all pooped!
Commenturds, shirley?
Just flushing our buffers.
Real security, or just going through the motions?
A reliable source tells me…
A reliable source tells me that the directors’ reaction to hearing the Register were making inquiries was “oh sh*t”….
(Full disclosure — this was absolutely a joke and I have no friends who ever be interested in building systems to look at literal cr@p all day…)
Misunderstanding
There's a misunderstanding here. 'E2EE' obviously stands for 'excrement to extended exposure'.
Anyway, I would be glad to share some personal 'data' with Kohler...
Next Kohler innovation: "B2B"... Butt-to-butt.
Smart Pipe Inc. is a Registered Sex Offender
[1]Smart Pipe Inc. is a Registered Sex Offender
[1] https://www.youtube.com/watch?v=DJklHwoYgBQ
Finally! A problem for worthy of AI!