News: 1604322909

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google's home security package flies the Nest, Chocolate Factory pledges software support – for now

(2020/11/02)


In brief Bad news for those who have bought into the Nest Secure home surveillance system – Google has surprised many by halting further deployments.

The Secure package consists of motion sensors for doors and windows that communicate with the Hub, a modern-day version of the traditional home alarm keypad but with NFC Tag key fobs and smartphone alerts. The Register thought it was a [1]pretty good system , but it's now deader than corduroy flares with satin lining, although it is still being supported.

"We sold out of Nest Secure and won't be making the full system available for sale any longer," the Chocolate Factory [2]said on a support page.

"We are committed to bringing our users the same feature and software support they've always had with Nest Secure, including existing cross-product integrations within the Nest ecosystem. We will also continue to deliver critical security updates and software fixes."

The key question there is for how long? Google is notorious for not supporting Chromebooks and smartphones longer than three years. If you've spent hundreds of dollars rigging your house up with the kit, some certainty would be nice.

No more Nest Secure starter kits are being sold but Google [3]promised "more Nest Detect sensors available for sale in mid-December" if you want the Betamax of home security systems.

Google's immigration lawyers hacked

The US firm of Fragomen, Del Rey, Bernsen & Loewy getting hacked might seem like a run-of-the-mill security breach, but it has raised red flags because the legal biz happens to do Google's immigration work.

The Chocolate Factory is a firm believer in hiring the best talent from around the world and so it was somewhat unfortunate for the outfit to confirm

[4]PDF

that its servers had been illegally accessed by an unknown "third party" and the I-9 employment eligibility verification forms of Google staff past and present compromised.

The I-9 form is packed full of all the lovely information identity thieves love. However, the legal eagles didn't give any more details on the type of data lost or the number of records accessed.

SonarQube hack may be much worse than first thought

The FBI has admitted that it and other US government agencies lost source code thanks to poorly secured SonarQube use.

In August, potentially damaging source was leaked online after users of the code-checking platform were found to have left data exposed. The leaker, Swiss computer consultant Tillie Kottmann, [5]told The Reg that it came from platforms that either didn't have the built-in authentication mechanisms turned on or were otherwise misconfigured.

A leaked [6]TLP: WHITE briefing , an FBI service to national corporate security teams, warned that Intel wasn't the [7]only organization to get hit in the code leak. SonarQube customers beware – code fixing can bear unpleasant gifts.

Russian Fancy Bear hackers going after think tanks – report

The [8]Fancy Bear hacking crew, six of whom were indicted earlier this month on hacking charges, have been accused of probing political organizations in the run-up to the US elections on November 3.

Reuters [9]reports Microsoft has warned the US government that the ursine undercover security undoers have been active at the Center for American Progress, the Council on Foreign Relations, and the Washington-based Carnegie Endowment for International Peace.

This may be why Redmond is [10]so keen for the Netlogon patch to be installed so quickly. It's one of the [11]top flaws the NSA is warning about, so get busy. ®

Get our [12]Tech Resources



[1] https://www.theregister.com/2018/04/21/time_to_ditch_the_front_door_nest_yale_lock/

[2] https://support.google.com/googlenest/answer/10191961

[3] https://support.google.com/googlenest/thread/79491075?hl=en

[4] https://oag.ca.gov/system/files/FDBL%20-%20California%20Notice.pdf

[5] https://www.theregister.com/2020/08/04/sonarsource_defends_sonarqube_after_leaks/

[6] https://beta.documentcloud.org/documents/20399900-fbi_flash_sonarqube_access_bc

[7] https://www.theregister.com/2020/08/06/intel_nda_source_code_leak/

[8] https://www.theregister.com/2020/10/19/russians_charged_olympics/

[9] https://mobile.reuters.com/article/amp/idUSKBN27F1CP?__twitter_impression=true

[10] https://msrc-blog.microsoft.com/2020/10/29/attacks-exploiting-netlogon-vulnerability-cve-2020-1472/

[11] https://www.theregister.com/2020/10/20/nsa_china_hacking/

[12] https://whitepapers.theregister.com/

Surely by now...

Anonymous Coward

People know not to rely on Google products for anything of major importance?

They are way too keen on shutting down products that have lots of users (be it hardware or software).

Anon because of this:

A place I worked, even though Google (paid for) mapping APIs likely to stay up and running, took decision to use different paid for mapping APIs, just because Google cannot be trusted for long term support and didn't want anything really important reliant on them when rug could be pulled at any time.

I'm sure plenty of other businesses take a similar worst case scenario with Google - a significant, hidden, revenue loss based on their past history.

0laf

"Smart products" = "short term" products.

Joe Public doesnt understadn when they buy "Smart" they are buying to the commercial world of 3yr depreciation cycles.

People might not be so keen if they know they are having to rebuy their kit every 3yr.

"I tolja so"

Anonymous Coward

A friend dropped megabucks on Nest Secure.

I showed him all the stuff Google has abandoned, including G+, Revolv, and others. I also talked about bouncing your private stuff through other people's servers. Nope. Ignored me.

So I'll be doing the "I told you so" dance.

Add it to the list

fidodogbreath

Courtesy of [1] Ars Technica .

[1] https://arstechnica.com/series/google-kills-product/

Superstition, idolatry, and hypocrisy have ample wages, but truth goes
a-begging.
-- Martin Luther