Google Is Collecting Troves of Data From Downgraded Nest Thermostats
(Monday November 17, 2025 @10:30PM (BeauHD)
from the would-you-look-at-that dept.)
- Reference: 0180111709
- News link: https://tech.slashdot.org/story/25/11/17/225229/google-is-collecting-troves-of-data-from-downgraded-nest-thermostats
- Source link:
Even after disabling remote control and [1]officially ending support for early Nest Learning Thermostats, Google is [2]still receiving detailed sensor and activity data from these devices , including temperature changes, motion, and ambient light. The Verge reports:
> After digging into the backend, security researcher Cody Kociemba found that the first- and second-generation Nest Learning Thermostats are still sending Google information about manual temperature changes, whether a person is present in the room, if sunlight is hitting the device, and more. Kociemba made the discovery while participating in a bounty program [3]created by FULU , a right-to-repair advocacy organization cofounded by electronics repair technician and YouTuber Louis Rossmann.
>
> FULU [4]challenged developers to come up with a solution to restore smart functionality to Nest devices no longer supported by Google, and that's exactly what Kociemba did with his open-source No Longer Evil project. But after cloning Google's API to create this custom software, he started receiving a [5]trove of logs from customer devices , which he turned off. "On these devices, while they [Google] turned off access to remotely control them, they did leave in the ability for the devices to upload logs. And the logs are pretty extensive," Kociemba tells The Verge. [...] "I was under the impression that the Google connection would be severed along with the remote functionality, however that connection is not severed, and instead is a one-way street," Kociemba says.
[1] https://tech.slashdot.org/story/25/04/25/2052237/google-is-killing-software-support-for-early-nest-thermostats
[2] https://www.theverge.com/news/820600/google-nest-learning-thermostat-downgraded-data-collection
[3] https://bounties.fulu.org/
[4] https://www.youtube.com/watch?v=LsI6P2lxcHM
[5] https://pastebin.com/fkQDkSwu
> After digging into the backend, security researcher Cody Kociemba found that the first- and second-generation Nest Learning Thermostats are still sending Google information about manual temperature changes, whether a person is present in the room, if sunlight is hitting the device, and more. Kociemba made the discovery while participating in a bounty program [3]created by FULU , a right-to-repair advocacy organization cofounded by electronics repair technician and YouTuber Louis Rossmann.
>
> FULU [4]challenged developers to come up with a solution to restore smart functionality to Nest devices no longer supported by Google, and that's exactly what Kociemba did with his open-source No Longer Evil project. But after cloning Google's API to create this custom software, he started receiving a [5]trove of logs from customer devices , which he turned off. "On these devices, while they [Google] turned off access to remotely control them, they did leave in the ability for the devices to upload logs. And the logs are pretty extensive," Kociemba tells The Verge. [...] "I was under the impression that the Google connection would be severed along with the remote functionality, however that connection is not severed, and instead is a one-way street," Kociemba says.
[1] https://tech.slashdot.org/story/25/04/25/2052237/google-is-killing-software-support-for-early-nest-thermostats
[2] https://www.theverge.com/news/820600/google-nest-learning-thermostat-downgraded-data-collection
[3] https://bounties.fulu.org/
[4] https://www.youtube.com/watch?v=LsI6P2lxcHM
[5] https://pastebin.com/fkQDkSwu
Google (Score:2)
by Sebby ( 238625 )
Privacy Rapists only second to Meta[stasize].
Re: (Score:2)
by srmalloy ( 263556 )
"Don't Be Evil... unless we can do it covertly."
Re: (Score:3)
by haruchai ( 17472 )
> "Don't Be Evil... unless we can do it covertly."
they changed in in 2015 to "Do The Right Thing" but didn't specify for whom
Apparently they were also collecting data (Score:3)
During incognito browser mode. So that's fun. As usual we found out as part of a lawsuit and settlement.