HACKER Q&A
📣 hedora

APC adding monthly fees / remotely defeaturing existing UPS's?


I got an email this morning saying that APC has "changed" their cloud offering to add a premium tier, and that my current cloud service will lose features such as email notifications and firmware updates when the warranty expires (unless I pay a subscription fee).

Is this new? I don't remember agreeing to pay for firmware updates when I set it up. They recently had to patch a remotely exploitable security flaw, so it seems foolhardy to continue to use remote monitoring moving forward. (Will put entire email in thread).


  👤 hedora Accepted Answer ✓
The email:

New Subscription Plans for EcoStruxure Ready Smart-UPS Web Portal.

-----

Hello,

Thank you for being a valued APC Smart-UPS web portal customer. Out-of-box remote UPS monitoring via the SmartConnect Ethernet port is included with the purchase of every new Smart-UPS device tied to warranty. On the Standard plan, you have the following great benefits while you are under warranty:

1. Remote UPS status monitoring

2. Configurable power event notifications

3. Remote UPS self-test and audible alarm diagnostics

4. One-click remote UPS firmware upgrade

== What's changing?

APC is introducing optional cloud service plans for customers who require more advanced features or for Smart-UPS that are no longer under warranty.

== New Advanced plan

The Advanced plan introduces remote UPS outlet group power cycling for devices in locations that are hard to reach or have no IT staff on site. Remote outlet group reboot can be enabled for any Smart-UPS by purchasing the Advanced plan.

== What does this mean for you?

Once your UPS warranty expires, your Smart-UPS will move to a Basic plan. You can continue to log into the web portal and view your UPS status but will no longer receive email notifications, remote UPS firmware updates or access to remote diagnostics. To restore your current features, you can purchase the Standard plan or purchase the Advanced plan if you also require remote outlet group reboot.

== Next steps

Log into the Smart-UPS web portal today to learn more about these options and optimise your Smart-UPS cloud monitoring benefits


👤 neilv
This is another reason for me not to connect a UPS to data.

I started using data-connectable UPSes at home a couple decades ago. When I got my first such UPS, I happened to be in an IRC community of systems people who were frequently targeted by script kiddies. Usually they would just knock people or servers off the net, but sometimes they'd hack in, and we got a little practice at countermeasures. With this awareness in mind, I decided that having a UPS-triggered smooth server shutdown, in event of rare extended power outage, wasn't worth even the tiny risk of someone messing with the UPS remotely, and accidentally causing a fire.

I currently have two rackmount Cyberpower UPSes at home, still not data-connected. And it turns out, in the last couple decades, I've never needed the data connection.

Incidentally, this IoT move by APC sounds off-putting. I've long favored APC, and only switched to Cyberpower at home for the short-depth form factors. APC now has a neat and pricey Lithium battery short-depth line, but if Cyberpower can beat APC on customer goodwill (including IoT nonsense), they'll cement me and presumably others as loyal customers.


👤 dmitrygr
And people ask me why I want ability to disable all automatic firmware updates (so i can vet them against people's comments when they roll out to others) and prefer to buy non-internet-connected things.

👤 obenn
Are you sure this removes the ability to perform ANY software update? As far as I can interpret from this email this just seems to remove the ability to perform the update remotely.

👤 0des
Subscription things are something I wish would have died in the media wars of cable TV.

Also, on a more tangential note, allow me to gripe briefly: Blue Apron, and other with this model, consider how much garbage you are creating for the minimal value of your schemes.


👤 1-6
That’s why going to an open-source BMC is important.

👤 Tijdreiziger
Where are you located? If you're in the EU, this might be illegal: https://www.howtogeek.com/342735/if-you-live-in-the-eu-you-p...

👤 cute_boi
This is why I always avoid closed source things :). I don't want my device to stop working due to updates. Also, its impossible that someone will keep running cloud for my device forever.

👤 m-p-3
I suggest that if you have a server attached to it, to monitor it through a dashboard like Grafana. You can also set up monitoring alerts from there too.