by gorjusborg on 1/18/2022, 8:25:52 PM
by treesknees on 1/18/2022, 8:40:57 PM
The method to get into "God Mode" is the same, except now it prompts you for a code. Someone has figured out how to calculate it and actually created a website to generate codes for you.
Apparently the algorithm is very simple according to Reddit https://old.reddit.com/r/nordictrack/comments/ozkp8v/privile...
>long responseCode = new Random((long) Integer.parseInt(iFitCode)).nextInt(999999);
It's not a perfect workaround, as it resets on the next boot, but I've seen that people are installing apps such as Taskbar which float overtop the iFit app and start on boot, allowing you to still launch your apps like Netflix etc even without God Mode enabled.
It's only a matter of time before Nordic decides to block this method as well. We should also be looking into how to block updates to these devices.
by jabroni_salad on 1/18/2022, 8:32:41 PM
Jeeze, I will stick with my modular solution: an ipad on a music stand. This is compatible not only with any commodity treadmill, but also bike trainers, ellipticals, and making vroomvroom noises on the motorcycle when it's too icy to actually ride. I could also swap out the ipad for a laptop, non-ipad tablet, or a collection of cute succulents should I desire it.
snark aside, I'm a bicycle guy and I really like that we have an ecosystem of bluetooth trainers and apps that all work pretty well with each other. Simulating hilly courses is actually really useful and has made me a better rider, so it's not like I'm advocating being a total luddite. While I prefer to ride outdoors in the sun, my area in Iowa is extremely flat and the only difficulty comes from the wind, and I find the new toys are a lot more fun than a dumb trainer with a sufferfest DVD. I don't really know much about the treadmill scene but I hope you guys have access to similar stuff.
by beloch on 1/19/2022, 12:19:46 AM
"NordicTrack says it supports right-to-repair rules. However, because of its equipment’s moving parts, the spokesperson says, it believes that restricting access to its operating system is important for safety. "
The real reason they don't want people using other apps or watching third party videos is because anyone doing that is not spending money on iFit. Or, at least, not as much as they could be. NordicTrack likely discounted these treadmills to squeeze out competitors with the intention of making their money back by locking customers into iFit.
If a few users hack their treadmills, that's not going to hurt NordicTrack's bottom line. If most users are doing it because it's as easy as tapping the screen 10 times, then there's a problem. So, NordicTrack has made it harder to gain admin access. Not impossible. Just harder. More people will go back to spending money on iFit, the determined few will roll up their sleeves, and the business model will be restored.
The problem is that this business model is a bait and switch. When people pay for a treadmill they don't expect to be locked into further monthly payments to unlock its features. It's inherently dishonest, and the victim, aside from users, is the competitor who produces an honest product that's paid for entirely up front and is, hence, more expensive and less competitive.
by mcherm on 1/18/2022, 9:00:34 PM
My solution to this problem would be legislation that allows customers, if they wish to, to return devices for a full refund if the company that manufactures the device makes a change that removes functionality that the customer valued. This doesn't prevent the company from making the change, it simply makes sure that they incur a cost for doing so, and it makes whole any customer affected by the change.
by MaxBarraclough on 1/18/2022, 8:34:18 PM
Not the first time a company has pushed an update that removes important features.
To my knowledge the first high-profile instance of this was when Sony updated the PS3 to remove Linux support, which resulted in a successful class-action in the US. [0]
by bmcniel on 1/18/2022, 8:12:41 PM
Classically the feature was taken away to make you safer :)
> The block on privilege mode was automatically installed because we believe it enhances security and safety while using fitness equipment that has multiple moving parts,
by cwal37 on 1/18/2022, 9:01:01 PM
This is related to why I bought a concept2 erg recently. Hurt my achilles and needed to switch to a low impact exercise, which I prefer to be able to do at home rather than going somewhere else (so swimming is out).
Looked at Peloton, but it's about twice as much as an erg up front, has running costs each month, and what seemed to be many more points of failure (which includes the electronics). The Concept2[0] is a tank that should last me a very long time. Space is an issue (I had to shove my dining table to the side), but the workout is amazing and I have a lot of faith in the machine to last. Plus it has a pretty straightforward bluetooth connection if I want to get data out and multiple USB and ethernet ports on the very simple monitor it came with.
[0] https://www.roguefitness.com/black-concept-2-rowerg-rower-pm...
by anyfoo on 1/18/2022, 10:31:17 PM
Following Wirecutter's suggestion, I got a ProForm 505 treadmill. Like Wirecutter said, it's cheap, a bit janky, but does the job adequately for a "non-pro" like me.
When unpacking it and setting it up, there were multiple notices everywhere: On the packaging, as a separate note in the packaging, in the manual, on the treadmill itself. Those notes all said that the treadmill is "locked" and you need "online activation" to unlock it.
I was getting very nervous, since I thought I bought something that does not need online activation.
However I think it was also Wirecutter that mentioned that you can just press the iFit button for longer than 15 seconds--or was it 30 seconds?--and it's "unlocked". I did that once and it worked ever since, never needed to do anything online, or connect it via Bluetooth, WiFi or anything else.
by erwincoumans on 1/18/2022, 8:48:21 PM
Suitable story, hacking walled gardens on HN.
Reminds me of the Rigol DS1054Z 50 MHz oscilloscope, that you can trivially 'hack' into the more expensive DS1074Z 75 MHz or DS11074Z 100 MHz scope. Rigol hasn't disabled this hack, even though they can easily do it. They likely loose money if they do so, since customers move to other scopes.
Also, some Tesla updates make the experience worse instead of better (V11 update is terrible, inconsistent UI and much more menu diving). I should have disabled auto-updates, and read the forums before doing the update next time.
by friendlydog on 1/18/2022, 9:40:12 PM
We need an Electronic bill of rights.
1. You must allow full root privileges for Electronic devices to the owners
2. You may not circumvent owners rights through leasing or other means.
3. You may not create barriers to device owners using their devices how they see fit.
by dhimes on 1/18/2022, 8:12:04 PM
If Nordic is being honest that the issue is safety- preventing users from diddling with their software and accidentally making it unsafe, then they can simply install a browser so the users can view what they wish online.
by cwkoss on 1/18/2022, 11:17:26 PM
It should be illegal to remove features from a hardware product with a software 'update' without offering all pre-existing customers to return the hardware if they affirm the removed (or newly pay-gated) feature was a factor in making their purchase.
Customers currently have zero recourse, because they are paying for the hardware, but the software allows the hardware functionality to be changed or removed at whim without any financial risk to the company. Credit card chargebacks may work sometimes, but only if the purchase was recent: 'smart' hardware vendors often ruin their products more than 90 days after purchase.
by charles_f on 1/18/2022, 10:28:08 PM
> NordicTrack says it supports right-to-repair rules.
I don't get why companies think this kind of blanket statements are useful, when they're immediately made null by their actions.
> However, because of its equipment’s moving parts, the spokesperson says, it believes that restricting access to its operating system is important for safety.
This is such obvious BS, when the real kicker is that after you already shelled $4k, they really really want you to rack out that sweet sweet monthly subscription money and don't want any competitors on a screen that, it turns out, they can control.
Greedy manufacturers wanting to get into that monthly recurring revenue model.
by remram on 1/18/2022, 9:25:32 PM
"God Mode" make it seem like such an unreasonable request. How about "Owner Mode"?
by ijidak on 1/19/2022, 1:24:18 AM
On October 28, I bought the NordicTrac T-Series for $650.
After installation, it had a lock screen asking me to subscribe to start using the treadmill!
Can you imagine?
I paid for the treadmill, and you're telling me I can't even walk on it without paying you again?
So what did my $650 pay for?!?
If I can't use a device's most basic function without paying an additional subscription, then can Amazon label the button "Buy Now"?
What exactly did I "Buy" if it's a paperweight without an additional subscription?
Nowhere did the product page say that having a subscription is a pre-req to use this device: https://www.amazon.com/gp/aw/d/B0193V3DJ6
Thankfully, the company Amazon hired to setup the treadmill found the trick to bypass that screen.
But now, after hearing about this update, I'm afraid they will lock my treadmill again.
I just use my treadmill to walk on it.
I don't need any apps.
Left to their own devices, these companies will find a way to charge us to breathe.
So happy I'm not looking to any human governments to fix this nonsense.
by gnabgib on 1/18/2022, 8:18:12 PM
This is a couple of months old now, posted a few times.. not much discussion:
[0] 8pts/1 comment
[1] 15pts/1 comment
[2] 5pts/0 comments
[0]: https://news.ycombinator.com/item?id=29288525
[1]: https://news.ycombinator.com/item?id=29292826
[2]: https://news.ycombinator.com/item?id=29296501by gennarro on 1/18/2022, 9:07:50 PM
Exactly why I only buy dumb devices ex: https://non-smart.com type stuff
by 300bps on 1/18/2022, 8:10:00 PM
by alkonaut on 1/18/2022, 10:35:54 PM
That it was advertised anywhere in documentation as possible is what makes it a hostile move by the manufacturer.
Had this been just some kind of open secret “hack” then buyers really should expect this.
Remember: when you buy a gadget with a screen and associated “services” like video subscriptions you aren’t just buying a lump of tech. Your price is set after careful weighing of how much customers will consume the subscription services. If the add on service is provided by a third party it’s even worse: your products’ ability to deliver something other than their service is probably a breach of contract.
My guess: the treadmill makers didn’t mind people watching Netflix on their gadget. Their partners on content though has given them deals on the premise that everyone who didn’t buy a subscription should have a feeling that they wasted $4k on an empty screen. So when they hear a number of users are watching Netflix, they get angry. Treadmill makers must block the god mode.
The sad thing here is obviously that the idea of making a good open product without strings attached or subscriptions seems like an impossibility these days.
by musikele on 1/19/2022, 8:32:52 AM
When I read these articles, where people buy 4000$ treadmills only to watch netflix using an unsupported feature, I wonder why they don't buy a 1000$ treadmill without any display, a 50$ tablet stand, and an iPad or Android tablet (that they probably already have). You'd get exactly what you want, for a cheaper price..
by m463 on 1/19/2022, 2:50:08 AM
I bought a proform pro 2000 treadmill at costco.
On the box, it mentioned "one-year iFit membership included (then says wifi and registration required for ifit)"
I didn't want to use iFit, I just wanted to use the treadmill.
However -
You can't use the treadmill without connecting it to wifi, except for "manual mode". ZERO workouts. This involves dark patterns for setting up your treadmill and avoiding a wifi connection. then you can select manual mode - which can ONLY set the speed or incline manually.
Oh yeah, this treadmill has an embedded camera and microphone.
The description is a dark pattern, the UI is a dark pattern. pro-form has a horrible reputation from my direct experience.
so I use it in manual mode. I don't use the 10.1" touchscreen except to start it moving.
I suggest folks who want a treadmill just go to somewhere like Dick's and look at the treadmills and buy one after checking out the UI in person.
by mikestew on 1/18/2022, 9:11:06 PM
Not that NordicTrack cares about purchases from l'il ol' me in the larger scheme of things, this is precisely why we didn't buy a NordicTrack treadmill despite being tickled with our NordicTrack rowing machine: that screen is there for NordicTrack's benefit, not yours. Sure, I'm a software engineer as well as owning a soldering iron and knowing how to use it. But if I've got to unsolder/resolder wires or cut traces on my brand-new machine to get the functionality I thought I paid for, I bought the wrong machine. If I have to use a software hack that is one update away from not working anymore, I have purchased the wrong machine. I'll let others rant about not being able to use the hardware that one paid for, I'm just not going to pay for the HW in the first place. (And, honestly, how many of us on HN need another screen around the house?)
It's disappointing, too, because we're quite satisfied with our NT rowing machine, which was purchased right before the "big screen" models, and we would otherwise recommend it. But now you can't buy the one with the cheap LCD display like we have and just bring your own screen, you have to get proprietary screen models now. So I don't recommend their rowing machines anymore, either.
After much research, we bought a treadmill from Horizon fitness[0]. We've been nothing but happy with it, which is their top-of-the-line 7.8. It has BT for music to play over the built-in speakers, and it works fine with Zwift and even the iFit subscription that NordicTrack pushes (it just won't auto-control the treadmill speed/incline, which is a-okay by me). BT streams your data to Zwift, et. al., including speed/incline/HR. It has a built-in stand for your tablet, though anyone on HN ought to be able to rig some cheap 27" 4k monitor in there somehow (we use a wall-mount for the rowing machine that swivels for general purpose use). The spouse and I have used it with Zwift, iFit, and Apple Fitness+, though Zwift is the only one that cares about data from the BT stream. As running goes I used to be fast, but now I'm just old and still faster than most, and it does everything I need for dark, rainy PNW days. I use it for tempo and intervals on occasion as well, and the one-button presets for interval/recovery are nice so when I'm gasping for breath I just need to be able to push the recovery button.
Anyway, no association whatsoever with Horizon, just a very satisfied customer.
by glitcher on 1/19/2022, 2:40:37 PM
Wow, sounds like a huge missed opportunity! If so many people were willing to pay a premium price for a device primarily because of how easy it was to customize, then perhaps it should be marketed that way in the first place.
Hardware vendor lock-in subscriptions may seem to the corporate world like a big win on paper, but how many customers are they losing who are willing to pay for a very premium product that they get full control over? (looking at you peloton)
by pm24601 on 1/19/2022, 4:14:00 AM
This is why I don't buy specialty hardware devices anymore. I jumped off the smart device treadmill with the fitbit.
The only thing in my house that gets access to the internet are my computers and phone. Nothing else. If I turn it on and it complains about no internet - it gets returned as defective.
I have a car charger (Juice Box) that have a smart app to control it. Nope not for me. Last thing I want is a hacked device fucking with my car's charging.
by _fat_santa on 1/18/2022, 8:16:33 PM
I really hate how we are moving more and more towards "managed experiences" in products. Used to, you would buy a product and use it how you see fit. But these days it seems that's not what the company wants you to do. You buy the product and enjoy a "managed" experience from the company.
We see it everywhere with printers, coffee makers, phones, laptops, treadmills and even cars now. Everyone knows why this is being done, simply making money on a $99 coffeemaker is not good enough anymore, we have to make that $99 plus we have to make money in perpetuity because the customer now has to subscribe to our "managed experience".
Now I understand this on some level with cheaper stuff like printers, that printer doesn't cost $20, it costs that because the company assumes you will buy the pods from them. But with a treadmill that goes for thousands it's a completely different ball game.
Were going to get to the point where one day you will hop in your car and start driving into the countryside. At a certain point your car will just shut off because "Ford has decided that this route in unsafe for your vehicle, for the best experience, please drive back to the city, on your way back, consider enabling cup holders for an improved coffee drinking experience".
The glimmer of hope on the horizon are companies like Framework and Pinephone. These companies realize that consumers are not happy with this shit and market themselves as the antithesis of these practices. I really hope these types of companies take off in the future.
by DrJaws on 1/19/2022, 10:30:40 AM
A construction worker moving to cloud security and in a single sabbatical year already scrutinizing by himself the firmware and closed OS of a treadmill.
makes me happy. Hope a lot of people can leave behind those low paid high effort jobs thanks to this 2 shitty years
by keyle on 1/18/2022, 9:26:55 PM
I'm utterly disappointed I didn't see any footage of DOOM running on it. If those hackers didn't spend so much time trying to be healthy, they could focus their time on an actual worthy task! /s
by coopreme on 1/19/2022, 1:00:54 AM
Does anyone know the domains they use to connect/update? I’ve got one of these (different brand) but still unlocked by the 10 taps method. I’ve still never connected mine to WiFi but I like to dim the screen. I could setup DNS blocks and then connect to WiFi to verify it works for a more long term solution for folks (well, that intersection of those that run a pinhole and on a treadmill).
I didn’t connect it to WiFi (even after unlocking) primarily because I worry about it being another data collection tool (WiFi, bt) and it has a camera/mic on it.
by rchaud on 1/18/2022, 9:22:53 PM
"God Mode"? What they describe is just how to access developer options on an Android device, isn't it?
It doesn't provide root access or anything, just the ability to sideload apps and a few other things.
by mdavis6890 on 1/19/2022, 6:18:05 PM
A good reason why I don't like to buy smart devices.
That said, I think that if we want right-to-repair/tinker I think we also have to make reasonable concessions as well. E.g. No liability for the manufacturer due to running older or non OEM versions of software/firmware. No expectation of ongoing support or updates on those older branches. Of course liability should still exist for issues that were not caused by this alternate software even if you're running it.
by logicalmonster on 1/18/2022, 11:04:15 PM
Is there any theory as to what NordicTrack hopes to gain out of preventing customers from using the screen as they see fit? NordicTrack already has the customers' money, so why would they really care?
Are they trying to do some kind of advertising on the screen? Are just going through run of the mill security updates and there's bad communication between the customers and NordicTrack not understanding each other because of a layer of dumb bureaucracy between marketing/developers?
by iandanforth on 1/19/2022, 2:10:30 AM
This is obviously wrong and should be blocked via laws, but just in case you're here and haven't heard of pi-hole (https://pi-hole.net/) taking internet-of-shit devices and blocking all the ways they try to access the net is kinda fun.
by chris_wot on 1/18/2022, 10:02:13 PM
Honestly, it is getting to the point where your best bet is to buy a cheaper device with minimal features, then mount a screen onto it and hook it up to a Linux box to play what you want.
Cheaper and actually gives you what you want. Might force the vendor to allow for more customization, given a lot of people stop buying their premium range.
by habeebtc on 1/18/2022, 9:33:22 PM
The alternative here is to buy a waterproof tablet, and a decent mount to attach it to your treadmill.
https://amazon.com/Arkon-TAB086-12-Tablet-Galaxy-Retail/dp/B...
by sandworm101 on 1/18/2022, 9:49:23 PM
>> and finding workarounds that allow them to bypass the update and watch whatever they want while they work out.
Like buying a TV and mounting it on the wall in front of the treadmill? Do these people not have access to 2x4s? Why does your TV screen need to be integrated into your exercise equipment?
by CrendKing on 1/19/2022, 1:28:34 AM
The "right-to-repair" sentiment is totally understandable, as the article says. However, on the other hand, imagine some user modified the underlying Android, which caused the treadmill to run unstoppably, which end up injuring him. He then sues the company for millions of dollars. If I were the owner of the company, I would rather losing some customers than sleeping on a ticking bomb. Their move is also understandable.
I think an ideal solution could be the manufacturer officially supports accessing the "privilege mode" with some sort of "release of liability". Customer must agree to this the first time they access, forfeiting warranty and ability to sue. Much like when people decide to unlock phone bootloader and root.
And to make all manufacturers willing to provide privilege mode to their products, I think either 1) the court makes clear statement of supporting this legally, or 2) having a supreme court precedence established for this, is required, otherwise some manufacturers would still fear the potential legal risk.
by Zak on 1/19/2022, 12:26:54 AM
If you don't have root on a software-controlled device, it isn't really yours. Unfortunately, I think we've lost a lot of ground in that fight when it comes to consumer devices.
To the HN community at large: how do we start clawing it back?
by OneLeggedCat on 1/19/2022, 12:02:09 AM
> “The block on privilege mode was automatically installed because we believe it enhances security and safety while using fitness equipment that has multiple moving parts,” says a spokesperson for NordicTrack
lol what a straight up fucking lie.
by thomas on 1/22/2022, 3:49:30 PM
Totally dystopian. We need more dumb devices like https://non-smart.com
by luckystarr on 1/19/2022, 8:05:20 AM
This isn't "hacking". This is "using". As long as the current vocabulary is used, it will be advantageous for "hardware hostage takers".
by dschuetz on 1/18/2022, 9:04:11 PM
Remember Sony removing OtherOS/Linux from the PS3? Yeah? No? That's the reason I don't buy Sony hardware anymore.
See, the issue is decades old. But somehow people keep forgetting.
by kelvin0 on 1/18/2022, 9:43:36 PM
I like my devices cheap, dumb and offline. Nothing else.
by sharperguy on 1/19/2022, 12:44:25 PM
Every time I read an article like this I just imagine Richard Stallman's face as he smugly says "treacherous computing".
by DevKoala on 1/18/2022, 8:54:41 PM
This hacks is impressive, but very pointless. A regular treadmill plus an iPad is a much better combo and it goes for $1k less total.
by maurits on 1/18/2022, 9:20:12 PM
The short and completely correct reason as to why my e-reader has never, and will never ever, be connected to wifi.
by donatj on 1/19/2022, 4:14:23 AM
Is the difference between a $500 treadmill and a $4,000 really just an Android tablet? A fool and money.
by phasersout on 1/19/2022, 7:09:18 AM
It seems these customers would be happier with any ole treadmill and a simple TV mounted to it.
by davidw on 1/19/2022, 1:22:07 AM
I can hear RMS singing "Join us now and share the software".
by hrdwdmrbl on 1/19/2022, 10:15:34 AM
I wish it was even possible on my Peloton tread.
by davidgrenier on 1/19/2022, 12:35:55 PM
I have setup firefox to drop all cookies when closing and whitelisted a few websites I still need to bear cookies.
Upon using the above link, I ended up on a paywall. I hit F12 and check the creation date of all the cookies and confirm they had all been created the 19th (today, and incidentally had just woken up and turned on the computer). I refresh the website, still paywall.
I delete all cookies manually for that page, hit refresh and can read the whole article. I don't understand how this is possible.
by mdoms on 1/18/2022, 11:39:42 PM
Wait until runners hear about "outside".
by CountDrewku on 1/18/2022, 8:35:34 PM
I don't understand this obsession with electronic exercise devices. The peloton, that stupid thing that mounts to the wall, treadmills etc.
Outside is so much better than all of those. I will 100% run in single digit temperatures with snow on the ground before I touch a treadmill. If I have to be inside it's weight lifting.
by axiosgunnar on 1/18/2022, 8:31:31 PM
Just put a screen on a stand infront of your treadmill?
by waffle_maniac on 1/18/2022, 8:09:33 PM
I have an ebook reader mount I attach to the rafters. If I want to watch TV I set my laptop on some storage containers far back from the treadmill and put in my airpods. In both cases I'm looking straight ahead.
Looking down at the NordicTrack screen doesn't seem ergonomic or comfortable. I don't get this article.
Edit: From 2 points to 0. And probably going to go negative LOL.
This type of 'update' is one reason I tend to stay away from so-called 'smart' devices.
If part of the product I've paid for is software, and the company can update it without customer consent at any time, then I can't rely on the product's features. Period.
I experienced this myself on the PS4 version of Terraria. I bought a hard-copy of the game. I mastered the controls, and loved them. Terraria was updated one day, and the controls were all changed, completely. Total rip-off. I liked the game I bought, but it was replaced without my consent.
My feeling is that this behavior should be illegal for purchased products.