HN user

rhd

48 karma
Posts1
Comments16
View on HN

Here's an example in Michigan's law:

The Shopping Reform and Modernization Act, or Scanner Law, requires that most items on store shelves be clearly displayed with the price; by signage, electronic reader, price sticker, or any other method that clearly and reasonably conveys the price to a consumer in the store at the place where the item is located. If an automatic checkout system (scanner) charges you more than the displayed price of an item, and:

the transaction has been completed, and you have a receipt indicating the item purchased and the price charged for it; Then:

You must notify the seller that you were overcharged, within 30 days of the transaction, either in person or in writing. Within two days of receiving your notice, the seller may choose to refund you the difference between the amount charged and the price displayed plus a "bonus" of ten times the difference, with a minimum of $1.00 and a maximum of $5.00. If the seller does not pay you both the refund and the bonus, you may bring a lawsuit to recover your actual damages or $250.00, whichever is greater, plus reasonable attorney fees up to $300.00. You may instead file a complaint in a small claims court without an attorney.

https://www.michigan.gov/ag/consumer-protection/consumer-ale...

There could be privacy concerns where Apple isn't the party using the data, but has allowed a third party access unintentionally.

I don't know if this would be possible given the limited information currently available, but an example may be:

User attempts to browse anonymously through the use of A VPN, obscuring their residential IP. Website, or third party analytics on a website generate unique links and embed them in QR codes hidden on the page. A twist on tracking pixels. Browser requests, and caches image containing QR code on disk. Later, after user has disconnected from VPN their OS indexes images on the filesystem (for search purposes, or whatever, parses the QR code and requests the url contained. Malicious site/analytics firm now has additional data point (residential IP, not obscured by VPN) to correlate against.

There's also the remote potential that the QR code parsing/request functionality could have vulnerabilities. The behavior known doesn't indicate that, but it might result in exploitation with less human interaction if they are found.

I went down a similar journey over the last couple years (CO2, VOC, PM1.0/2.5/10 sensors). In my apartment I sit around zero for particulate with windows closed. I jump up significantly with windows open unfortunately (for my allergies) in the midwest.

I do wish my AC/Heat had more air exchange, similar to your space my CO2 levels rise dramatically after an hour or two of occupation with windows closed.

And SOC/CSIRT folks. A staggering amount of incidents involve an external wordpress install used as free real estate by threat actors in some way (e.g. phishing kit, malware infra).