{"id":9336,"date":"2022-02-19T15:59:07","date_gmt":"2022-02-19T23:59:07","guid":{"rendered":"https:\/\/www.lee.org\/blog\/?p=9336"},"modified":"2022-02-19T15:59:07","modified_gmt":"2022-02-19T23:59:07","slug":"sunbeam-electric-blanket-app-steals-data","status":"publish","type":"post","link":"https:\/\/www.lee.org\/blog\/2022\/02\/19\/sunbeam-electric-blanket-app-steals-data\/","title":{"rendered":"Sunbeam Electric Blanket App Steals Data"},"content":{"rendered":"<p>Here is the letter I wrote to Sunbeam today<\/p>\n<p>Data Privacy Enquiry<br \/>\nAttn: Data Protection Director<br \/>\n6655 Peachtree Dunwoody Road<br \/>\nAtlanta, Georgia 30328<br \/>\n2-19-22<\/p>\n<p>Lee Sonko<br \/>\n[address redacted]<\/p>\n<p>Dear Data Protection Director,<\/p>\n<p>Holy Moley! I did not expect my new Sunbeam electric blanket to be stealing my data!<\/p>\n<p>I bought your <a href=\"https:\/\/smile.amazon.com\/gp\/product\/B08X15F59C\">Sunbeam LoftTec Wi-Fi Connected Heated Blanket<\/a> and installed the <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.sunbeambedding.app\">required Sunbeam app<\/a>. Every time I start the app on my Android phone to control my electric blanket, I see a message from Android saying &#8220;Sunbeam pasted from your clipboard.&#8221; Why is your electric blanket app scraping my clipboard? An electric blanket does not need to know what is in my phone\u2019s clipboard!<\/p>\n<p>Please tell me you will fix this insane privacy and security hole!<\/p>\n<p>I looked through the Privacy Policy of the app and you made no argument for capturing my clipboard. In fact, the Privacy Policy reads:<\/p>\n<blockquote><p>5. SENSITIVE PERSONAL DATA<br \/>\nUnless specifically requested, we ask that you not send us, and you not disclose, on or through the Sites or otherwise to us, Sensitive Personal Data (e.g., religion, ethnicity, political opinions, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions) unless specifically requested by us or required by law.<\/p><\/blockquote>\n<p>So you don\u2019t want my sensitive personal data, and I don\u2019t want to give it to you, but you make it impossible when you\u2019re grabbing snippets of my clipboard!<\/p>\n<p>I\u2019ve already returned the electric blanket. I would love to buy a version that doesn\u2019t violate your own Privacy Policy. It could be the best electric blanket on the market but as it stands, it literally can\u2019t be trusted.<\/p>\n<p><a href=\"https:\/\/www.lee.org\/blog\/wp-content\/uploads\/2022\/01\/Sunbeam-clipboard-scraping.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-9304\" src=\"https:\/\/www.lee.org\/blog\/wp-content\/uploads\/2022\/01\/Sunbeam-clipboard-scraping-150x300.png\" alt=\"\" width=\"150\" height=\"300\" srcset=\"https:\/\/www.lee.org\/blog\/wp-content\/uploads\/2022\/01\/Sunbeam-clipboard-scraping-150x300.png 150w, https:\/\/www.lee.org\/blog\/wp-content\/uploads\/2022\/01\/Sunbeam-clipboard-scraping-300x600.png 300w, https:\/\/www.lee.org\/blog\/wp-content\/uploads\/2022\/01\/Sunbeam-clipboard-scraping-60x120.png 60w, https:\/\/www.lee.org\/blog\/wp-content\/uploads\/2022\/01\/Sunbeam-clipboard-scraping-768x1536.png 768w, https:\/\/www.lee.org\/blog\/wp-content\/uploads\/2022\/01\/Sunbeam-clipboard-scraping-1024x2048.png 1024w, https:\/\/www.lee.org\/blog\/wp-content\/uploads\/2022\/01\/Sunbeam-clipboard-scraping-25x50.png 25w, https:\/\/www.lee.org\/blog\/wp-content\/uploads\/2022\/01\/Sunbeam-clipboard-scraping.png 1080w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>What is \u201cclipboard scraping\u201d? It\u2019s when an app grabs the contents of your clipboard. Sometimes it is a convenience feature so a user doesn\u2019t have to copy-and-paste data themselves. But if the app obviously doesn\u2019t need the data, the only reasons are nefarious ones. An electric blanket does not need to know what is in anyone\u2019s phone\u2019s clipboard! Tik-Tok stopped the practice promptly after it was exposed in 2020. I hope you do the same.<\/p>\n<p>Most sincerely,<br \/>\nLee Sonko<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here is the letter I wrote to Sunbeam today Data Privacy Enquiry Attn: Data Protection Director 6655 Peachtree Dunwoody Road Atlanta, Georgia 30328 2-19-22 Lee Sonko [address redacted] Dear Data Protection Director, Holy Moley! I did not expect my new Sunbeam electric blanket to be stealing my data! I bought your Sunbeam LoftTec Wi-Fi Connected [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-9336","post","type-post","status-publish","format-standard","hentry","category-general"],"_links":{"self":[{"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/posts\/9336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/comments?post=9336"}],"version-history":[{"count":2,"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/posts\/9336\/revisions"}],"predecessor-version":[{"id":9338,"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/posts\/9336\/revisions\/9338"}],"wp:attachment":[{"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/media?parent=9336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/categories?post=9336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/tags?post=9336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}