Rendered at 14:50:56 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
SoftTalker 18 hours ago [-]
> Despite repeated warnings from the FBI and security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands
I scanned the comments and I didn't see anyone suggesting that these companies should share any responsibility for selling these harmful products. Why is it that they seem to get a pass? Would we feel the same about giant retailers selling tainted food, or unsafe children's toys?
al_borland 18 hours ago [-]
One of the main value propositions for retailers in a world of endless cheap garbage being sold online, is to vet products so customers can trust that what their buying is from a legitimate company and not junk or stuff like these streaming sticks.
This is the problem with being an “everything store”. “Everything” includes a lot of things most consumers would like to be protected from, and assume they are due to the long history of retailers standing behind the products they sell. That history seems to have come to an end. They only stand behind it enough to offer a refund if there is a problem, not to ensure it’s good before selling it.
omilu 16 hours ago [-]
Costco vets their products very well, if I see something at costco and its something I need I just buy it. No need to research and I've never been burned. They only sell good quality stuff.
Rickasaurus 13 minutes ago [-]
I have to disagree, costco often has custom worse versions of better products, we recently had a costco air conditioner fail just to find out it wasn't built quite as robustly as the $50 more expensive midea sold elsewhere with an almost identical model number. Similarly had my costco GE washing machine fail last year right out of warranty. There's a real quality problem going on with costco right now.
riddlemethat 3 hours ago [-]
We bought a Bosch dishwasher from Costco in January. It was defective and wouldn’t start after 10 days. Costco replaced it. The replacement came with a big gash on the front off the truck so we refused it and Costco sent a third replacement. Again, it was the same model and again it wouldn’t start after another 30 days. Costco took it back. No cost to us for any of these delivery or install attempts.
We bought a different model from Costco and it’s been rock solid. I expect I will never buy a major appliance from any other retailer as long as Costco continues to care like they do today.
fn-mote 2 hours ago [-]
> I will never buy a major appliance from any other retailer
Weird. You experienced failures of the manufacturer (failure to start) and the warehouse (huge scratch), and are still singing someone’s praises.
It sounds to me like the brand’s quality assurance is low and the retailer also isn’t taking care of their stock.
If I had to take three days off work to accept these deliveries, doubtless I would have a very different conclusion from yours.
rpdillon 33 minutes ago [-]
Yep, I'm pretty much a lifetime member of Costco if this sort of prioritization doesn't change. A recent article put it well "Costco is the anti-Amazon".
I say this as a happy customer of both, though. I don't seem to have the problems others do with horrible products from Amazon, but I suspect my purchasing habits might be different as well.
_RPM 2 hours ago [-]
> I will never buy a major appliance from any other retailer
That's called stinking thinking.
femto 15 hours ago [-]
Check their tomato paste. It turns out that nearly every tomato paste in Australia comes from Xinjiang in China, including those marked as Australian or Italian. Simplot (Leggos), the big US company, was the worst offender, so it's possible that tomato paste in Costco's US stores has been produced in Xinjiang using slave labour, irrespective of what the label says.
According to this none of the samples tested from US retailers contained Chinese tomatoes. https://www.bbc.com/news/articles/crezlw4y152o It seems like the US ban on Xinjiang is working
femto 14 hours ago [-]
Thanks for that informative link. I looked to see if there was any data beyond the ABC article and didn't find it. Some of the truthful brands listed in the BBC article are available where I live. Kudos to the US that their labels match their contents.
stubish 13 hours ago [-]
The ABC just broke their story a few days ago. There will continue to be fallout over the next few months or years (much like their last one, where they found that many sunscreens did not meet their SPF ratings, a hot topic in the skin cancer capital of the world)
(edit: whoops, Choice did the SPF rating investigation. ABC just did a lot of reporting on it)
biztos 12 hours ago [-]
While it could of course be produced in Xinjiang without using "slave labor," the US government banned those tomatoes in 2021 because of that risk:
If Costco were circumventing the ban it'd be a pretty big deal. I couldn't google up any indications that they are, so on balance I'd say it's "possible" in the same way my winning the lottery is possible. Can't rule it out, but reasonable people should probably bet against it.
TIL: Xinjiang tomatoes are something like 15% of the global market!
seanmcdirmid 12 hours ago [-]
> TIL: Xinjiang tomatoes are something like 15% of the global market!
China consumes 37% of the world’s tomatoes. 80% of China’s processed tomatoes are from xinjiang. Fresh tomatoes are generally grown locally, but that is true around the world.
LordAtlas 9 hours ago [-]
China _produces_ 37% of the world's tomatoes, not consumes.
seanmcdirmid 9 hours ago [-]
[dead]
Nursie 13 hours ago [-]
> It turns out that nearly every tomato paste in Australia comes from Xinjiang in China
I think that might be a bit of a strong assertion, from your article there -
"It analysed 221 processed tomato products from 39 brands, including paste, passata and diced tomato.
Twenty-two per cent of the products failed country-of-origin testing, while a further 6 per cent were flagged for further testing."
So while 28 percent is scandalous, and those companies need to face consequences, the other 72 percent seem to be genuine.
femto 11 hours ago [-]
A big chunk of that 72% are legitimately labeled "Made in China" or niche brands. The brands that failed, plus the products that are actually labeled "Made in China", dominate Australia's four supermarkets with the majority of the market share. I've just done my weekly shop, so trawled their web sites looking for alternatives.
Summarising the Australian situation, taking the 4corners results into account, the following non-Chinese tomato pastes are available:
Coles (29% market share): 1 x 140g premium product in a tube (expensive with reduced market share) out of about 20 products.
Woolworths (38% market share): 1 x 140g premium product (Mutti) in a tube (expensive with reduced market share) out of about 20 products.
Aldi (10% market share): None out of about 4 products
IGA (7% market share): 5 of 16 products, being the same premium brands that Coles and Woolworths sell.
Maybe qualify my comment with "by market share and availability". The effect is that if you stand in front of an Australian supermarket shelf, every product, bar one or two in the corner, come from China. China is a proxy for Xianjing, in that sources say 80%-90% of tomato paste from China comes from Xinjiang.
> Woolworths (38% market share): 1 x 140g premium product (Mutti) in a tube (expensive with reduced market share) out of about 20 products.
Eh ...
"Well-known tomato brands that passed country-of-origin testing include Mutti, SPC, Woolworths, Providore D'Italia and Annalisa. Diced tomato cans and passata from Leggo's and Coles also passed."
So here are 4 tomato pastes in woolworths that would seem to pass the test of not being from China and not being liars, just from a quick search (and I have seen all these in my local) -
I usually buy Mutti stuff because it's low-ish salt, and that claims to come from Italy and wasn't implicated in the report here. And while I understand those are at the 'premium' end, it's not like it's one product on the end of the shelf either.
It's true that "Leggo" occupies a lot of the shelf space and a lot of the cheaper 'own brand' stuff is labelled as coming from China. And coles appears to be in a weirder/worse spot that woollies, with only Providore being Italian and two brands of turkish tomato paste, which is interesting.
It's sad that I can't find an Australian tomato paste that isn't a liar.
So I'm still not fully on board with "nearly every", OTOH thanks for the further information. I shall continue to try to avoid these products!
p-e-w 14 hours ago [-]
The above thread was about quality issues, not ethical issues such as “slave labor” (a term somehow reserved for certain countries, even though most countries use unfree prison labor, including the US and much of the EU).
iamnothere 13 hours ago [-]
Our vocational training program, your prison labor, their slave labor.
femto 14 hours ago [-]
It's about trust.
perpetuallunch 13 hours ago [-]
Difficult to distinguish between actual slave labour and China-is-bad propaganda.
Harm to the end user: none^
Benefits to the end user: more affordable tomato paste
Government action to prevent slave labour products entering Australia: none^
^close enough.
stubish 12 hours ago [-]
It is perfectly legal to sell Chinese tomatoes in Australia (which is not necessarily a good thing, re: forced labour in Italy and China). The fraud is mislabeling them as Australian or similar, denying consumers from making their own ethical choice. Which is your harm to the end user and generally enforced by the ACCC.
kkotak 10 hours ago [-]
If you're going to start talking about mislabelling products, you're going doing a rabbit hole of hundreds if not thousands of products sold in reputable stores. Look up how FDA labels for Organic, Grass fed, Pasture raised, etc. are used through out the industry in the US and the world. You should also look up the requirements for "Made in X" labels for consumer products. Playing with word and people's emotions on what those labels mean when making a purchase decision is as old as commerce itself. Don't for a moment think of the US or a Western country being rightious about this.
perpetuallunch 7 hours ago [-]
The information this is based on is reporting from the Australian ABC TV program Four Corners.
The ABC is a know, as in they don't even try to pretend propriety, propaganda outlet of the Australia Albanese federal Government.
I'm not saying this is definitely propaganda, but there's a non-zero chance it is.
The Albanese government has been very open about attacking industry.
martimarkov 13 hours ago [-]
Negatives to end user: unknown pesticides or banned pesticides.
No propaganda - lack of validation, evidence and trust
perpetuallunch 7 hours ago [-]
What does slavery, real slavery or anti-China propaganda fake slavery, have to do with the with the presence or absence of pesticides, banned or otherwise?
neves 9 hours ago [-]
Chinese workers earn more than workers from latin America. At least their government isn't slave for billionaires
40four 9 hours ago [-]
I don’t disagree, Costco has a reputation for selling well vetted products, but that’s not a good comparison. I trust Costco (even their online only sales), but in no way do I trust the other merchants listed.
We’re specifically taking about merchants that have a super shady online presence. They will basically sell you anything and everything and don’t care if it harms you.
The ones mentioned (Amazon, Best Buy, New Egg), it’s going to be hard to argue they vet (or care about vetting) the digital products they sell. You might as well throw Walmart into group too, their online offerings have gotten super sketchy if you really do into it.
Uvix 3 hours ago [-]
Target as well. It was one thing when it was just Amazon acting as a sketchy third party storefront, but now everybody’s doing it.
red-iron-pine 2 hours ago [-]
arguably it's part of their main value proposition: bulk, but not terrible, and generally decent.
fixed fee membership also means a very stable revenue stream and they can take the time to do this, while other places like newegg are herding 3rd parties to get cuts of ever cheaper 3rd party crap
altruios 16 hours ago [-]
Costco isn't perfect, and things slip through still.
For example: this is a minor annoyance, but comes readily to mind.
The problem is labeling conventions leading to inaccurate assumptions of what's even IN that "protein powder"...
you would think the protein, being the largest in print, is the primary ingredient but no. A serving is 51grams, and the protein makes up 21grams of that serving: less than half, that's not a 'protein powder' if the primary ingredient isn't protein.
It should be labeled "SUPERFOODS with protein" not the other way around.
There have been other things similar in scope less readily recalled. It may seem minor to some... but labeling accuracy and transparency is something we had to fight for collectively.
tejohnso 14 hours ago [-]
A 51 g serving might contain 40 g of the protein blend, making it a protein powder as the primary ingredient is protein blend.
However, this is plant-based protein, not pure way isolate. A plant-based protein powder from mung beans for example isn't going to be 100% protein. Chickpea powder contains roughly 20% protein.
So I don't know if that helps at all, but it doesn't seem as bad as you and you might be suggesting.
al_borland 15 hours ago [-]
Ingredients are listed in order from greatest to least amount. Protein is listed first. It seems it’s the creamer that throws off the ratio you’re looking at, which I’m assuming is there for consistency/taste.
tiltowait 13 hours ago [-]
The first ingredient is a plurality, not a majority.
bell-cot 15 hours ago [-]
Compared to the big e-commerce retailers, Costco's total number of sku's isn't even a rounding error.
And most of Costco's sku's are food, clothing, housewares, bulk consumables, and such - vastly easier to test and vet than computer & internet-connected electronics.
ChoGGi 31 minutes ago [-]
Sounds like you're agreeing that Costco is well curated?
jon-wood 2 hours ago [-]
Amazon even have big "people commonly return this product" warning on some product pages. Anywhere halfway sensible would maybe reconsider stocking a product worthy of that but because they've set themselves up as a middleman without any of the risk they can just churn junk out of their warehouses.
Aerroon 16 hours ago [-]
You go to an online store to buy a hard drive. It's listed as "in stock" and you buy it and pay for it. A week later you get an email from the store that the specific hard drive is now available at a third party warehouse and they can order it from there, but the price is about 10% higher.
The above actually happened to me. That's what online retailers were like before Amazon's reach properly extended here. That's also the main value proposition for these retailers for me.
Also, online retailers are far more likely to accept returns compared to regular stores. If you get a bad product from a regular store you're often just screwed.
swatcoder 15 hours ago [-]
The late-Amazon process for this is to just send you whatever's marked as the hard drive in their warehouse, which may be that actual product, a counterfeit, or a brick in the hard drive's package.
Later, when you want to try the return, a black box algorithm asseses your transactional value to Amazon and decides whether your concerns are worth attending and to what degree.
Maybe that really is better than whatever you were used to in your own market, but it's a profound regression on the traditional retail experience for most of us here.
ephemeral67 17 hours ago [-]
interesting bit of information: most EV mower companies now do not provide replacement parts - if a mower dies within warranty, a 'certified' warranty repair shop does basic troubleshooting, and if it's beyond a piece of cheap plastic, the mfr just ships a new mower to the 'repair shop'. Once out of warranty, you're on your own.
bdamm 16 hours ago [-]
My electric mower has lasted longer than the gasoline mower before it, which literally had plastic valves inside the carbeurtator.
bluGill 13 hours ago [-]
There is a big difference in quality levels. If you want a good mower pay the price for a commercial mower, people who use them 8 hours a day need something that lasts.
30 years ago a friend of mine did the mold for a lawn mower. They put an engine on it and it ran for 120 hours before the deck failed. It took 7 more tries until the deck failed after 80 hours. Commercial mowers are expected to run over 1000 hours.
bigiain 7 hours ago [-]
I remember asking a chippie (carpenter tradesman) a while back why he was using Ozito brand power tools (the cheapest Chinese brand from the local tool barn). He said "The good gear like Milwaukee and Makita last years. The cheap Chinese junk lasts maybe six months. Whatever I buy it gets stolen about every 3 months. I'd rather have a spare $40 drill waiting at home when my van gets broken into, than have to go buy another $600 Milwaukee one that I'd otherwise rather be using."
zdragnar 16 hours ago [-]
Counter anecdote, I've had gas mowers survive decades and EV electrical equipment (in this case, a chainsaw and a battery pack for a mower) both die within 14 months of purchase.
Slash65 16 hours ago [-]
This is my experience as well. String trimmer battery went out (still in warranty and replaced) but my gas string trimmer I use at a bigger property came home with me and worked great. She’s only 15 years old, the battery was 6 months. I love my battery blower and string trimmer, but the gas ones are going strong but typically stay at the ranch property due to it being a bigger property to maintain. I would also need 3-4 battery’s out there to keep up with maintaining it, the gas is a whole lot cheaper than a grands worth of battery’s.
taneq 15 hours ago [-]
Counter counter anecdote, I was just tidying up the yard with my 18V whipper snipper and contemplating the fact that I bought it in 2012 and it hasn’t skipped a beat.
HDBaseT 14 hours ago [-]
I have a mower that my dad gave to me, which his dad gave to him.
It is in rough shape, but it still cuts grass perfectly fine.
I have a wippersnipper from before I was born which runs perfectly today. It was left out laying sideways in the rain for about a month. Quick clean and a new plug and it was going again.
I'm sure the electric devices can run a long time, but when they fail, they tend to be not repairable.
markdown 14 hours ago [-]
Makita, amirite?
taneq 13 hours ago [-]
Ryobi, but I have plenty of Makita gear too. :)
lazylester 15 hours ago [-]
almost all 2-stroke engines have had plastic flapper valves and a plastic fuel pump for as long as I can remember.
MostlyStable 16 hours ago [-]
These are the kinds of products I now just straight up refuse to buy.
taneq 15 hours ago [-]
I think that’s “most mass produced item manufacturers”. It’s just cheaper to ship a new one than waste time trying to troubleshoot.
drnick1 16 hours ago [-]
Thank you for reminding us that electric mowers are garbage.
classichasclass 14 hours ago [-]
My wife derides my Home Despot special plug-in mower as a Tonka toy, but it's basically just a motor, a blade and a bag, and I don't have a lot of lawn to mow.
timc3 8 hours ago [-]
My Makita one is excellent.
nullhole 16 hours ago [-]
I mean, not all of them?
Mine's a fancy-pants Stihl battery mower, but it works quite well and has been doing so without problem since I bought it ~4 years ago. The other battery stuff from the same brand (trimmer, chainsaw, kombi-tool) have the same story.
bluGill 13 hours ago [-]
Stihl is a commercial product (mostly). They design for people using them as a full time job. You pay the price for quality.
zrobotics 9 minutes ago [-]
No, they definitely have homeowner grade tools available.
For instance, the MS182 [0] is a $270, 2.2cu in saw with a 16" bar listed "For homeowners and light duty work".
Meanwhile, the MS201 [1] is $1100 for a 2.1cu in saw with a 16" bar listed as "The lightest professional gas chainsaw from STIHL
Perfect for delimbing work in forestry".
Service interval on the 201 will be much longer, and it's expected to last longer but is priced accordingly. I ended up having to buy one of their homeowner grade saws 10 years ago when I was up in the mountains and my saw died, that was all that was available locally. I'm certainly not a professional, but at the time my primary heat source was wood and I had always used the stihl pro-grade saws. However, that cheap stihl was an absolute piece of junk, it was half wore out after cutting 2 cords of firewood that first time. Terrible ergonomics and poor power to boot, even after reserving the saw for light-duty work it only lasted 2 years and was miserable to start and run the entire time.
At least they explicitly say that they are for light duty though, a less honest company would market everything as pro-grade. But don't just buy the name, while they make good quality products they also sell cheap crap under the same name. It also isn't that clear in a retail store besides the price which ones are the homeowner grade saws.
Yeah, mine are the AP ('professional') class ones.
What matters is the amortized cost per year, I think - more expensive up front but cheaper in the long run.
newAccount2025 16 hours ago [-]
Why? Mine is great. And light. And QUIET.
bigstrat2003 15 hours ago [-]
They really aren't particularly quiet imo. Yes, there's no motor, but it turns out that the whirring sound of blades rotating and cutting grass is quite loud even without a motor. I would say mine is perhaps 3/4 as loud as a gas mower, which isn't a very impressive reduction in noise.
maxerickson 14 hours ago [-]
With logarithmic perception, it's about a 50% reduction in sound energy.
My battery mower is quiet enough that I don't feel terribly rude mowing at twilight.
astura 15 hours ago [-]
I love mine.
Gigachad 16 hours ago [-]
Everything is garbage now. It’s the end state of unrestrained capitalism.
11 hours ago [-]
exe34 16 hours ago [-]
Surely not, the invisible hand of the market should crawl up their arse and make them do the right thing any day now.
actionfromafar 16 hours ago [-]
The invisible hand crawled up the arses of Congress and seems to enjoy it there.
zombot 10 hours ago [-]
Crooks will be crooks, but that the lawmakers let them get away with it is something that should change.
deaton 2 hours ago [-]
Online it still seems like for the most part if you buy from something a bit more specialty (e.g. McMaster, Digikey, etc) you still get really good vetting and high quality stuff, but amazon is more than happy to be filled with absolute garbage.
boondongle 18 hours ago [-]
Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold. They certainly don't advertise to the big box retailer that buys them "and it uses the customer's internet connection for fraud."
Hell, there's a section of comments that would probably going "hey, RELAX guy" because it's not US companies doing this. For any American companies that do this though, sure - block/suspend/prosecute.
malfist 18 hours ago [-]
If I open my own line of home improvement stores and do no oversight on what I sell and wind up selling really dangerous lawnmowers, I'm partly responsible.
Or if I open up a gas station and allow any company without oversight to sell "supplements" through my shelves and cops arrest me for selling heroin, I don't get a free pass.
Why should amazon or Walmart get a free pass just because they sell more items?
awakeasleep 17 hours ago [-]
One problem I see with your analogy is that the dangerous lawnmower can cause an easily quantifiable harm.
You have to be able to show damages you incurred and assign a dollar value to them to sue people.
That doesn’t work at all for a something that sells your bandwidth to a proxy service. People wouldn’t even be aware that it was happening they weren’t told.
SoftTalker 17 hours ago [-]
What about when the police show up because some highly illegal content was traced to your IP address? Will they believe that you were the unwitting victim of a rogue proxy server running on your streaming stick? Would you have even been aware of that possibility?
ndsipa_pomu 7 hours ago [-]
That shows the problem or trying to link an IP address to an individual.
xorcist 16 hours ago [-]
There's also always the flip side: When the police shows up because of your illegal acitivities, you have a rogue proxy server running. All bought in good faith of course.
Not legal advice.
(It would surprise me greatly if we as a society let these gadgets be sold openly from here on.)
inigyou 5 hours ago [-]
Believe it or not, that is what happens when the police show up to the house of a primary school teacher. They will think they have the wrong address. Even US police.
The cybercrime raids happen when they run into someone who looks like a hacker and has a lot of computers.
II2II 14 hours ago [-]
> If I open my own line of home improvement stores and do no oversight on what I sell and wind up selling really dangerous lawnmowers, I'm partly responsible.
While there would be oversight, it is highly unlikely that a person opening a home improvement store would perform any meaningful safety testing. They simply would not be qualified. The oversight would lay in selling certified products, pulling recalled products off the shelf, and (perhaps) removing products if there is a reason to suspect safety issues.
Now consider streaming sticks. There are safety standards for the physical device but, to my knowledge, there are no such standards for the software itself. Heck, there aren't even standards for the engineers who work on the software. One can make highly prejudiced decisions based upon the country of origin. Perhaps there are even good reasons to avoid products from certain countries. Yet the lack of standards also means that products from trustworthy sources can be suspect, since all it takes is a management decision to change things.
inigyou 5 hours ago [-]
But these products aren't dangerous. And proxying internet traffic isn't illegal. Fake ad clicks may be illegal but that falls on whoever is providing that service, which isn't the proxy or the resident. On what basis would you ban them?
wsintra2022 17 hours ago [-]
Except the devices are not dangerous. Its the software installed on the device. Consumers have a choice. Pay for the trusted Apple TV or Amazon firestick, or go the wild west and see what's on offer.
CrazyMusicians 17 hours ago [-]
with the devices mentioned in the article, there is no consent requested, and the malicious apps are installed either before the box is sold or after as a requirement for getting the streaming services to work.
inigyou 5 hours ago [-]
You call them malicious apps but what is the evidence they are more malicious than the things they fight against?
jon-wood 2 hours ago [-]
Really? You'd be ok with me putting a proxy server on your home network then, which anyone with a few bucks can use to attach your IP address and subscriber details to anything they choose to request from the internet? How about a Tor exit node?
Its incredibly obvious to anyone applying any thought at all to this that its a malicious to sell a product that labels itself as a TV streaming stick which is in fact a paid for relay server with the money made from providing the internet connection to a random third party unrelated to the person who bought the thing without ever telling the customer.
inigyou 2 hours ago [-]
Yeah I actually do several of those to earn a few bucks.
jon-wood 2 hours ago [-]
The typical consumer has no idea what they're buying, and they shouldn't have to because the retailer selling the product should have done some basic due diligence before stocking the thing. People aren't going to some clearly shady Chinese website and buying a device labelled "cheap TV streaming stick, will sublease your internet connection to criminals", they're putting "FireTV" into amazon.com and somehow being presented with these things alongside the Amazon FireTV they expect to find, or maybe "streaming stick" which really shouldn't be surfacing clearly malicious products.
inigyou 2 hours ago [-]
If the average consumer did get a disclaimer it would sublease their internet connection to a few criminals and a lot of people who aren't criminals, would they care?
crote 17 hours ago [-]
> Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold.
You already answered it: block it from being sold.
1) Make Amazon responsible for the products they are selling. 2) Introduce a law banning malware tv sticks 3) Sue Amazon for a percentage of their yearly revenue when caught violating it 4) Amazon will finally start caring and do some kind of review on the crap they sell.
themaninthedark 7 minutes ago [-]
I think a law that makes a marketplace responsible for items being sold if the qty of items is above a threshold would be a great idea.
You don't want to penalize someone selling their Xbox or lawnmower on Ebay but you want to stop what is going on here. A place like Etsy where people are selling their crafts is an interesting edge case but I think they should probably be a little regulated.
pixl97 17 hours ago [-]
And if the first time you get it online it just updates itself to malware?
That's the biggest problem with any device that updates.
Yea, this will work for the moment and the seller will be covered in the sense that "well, it wasn't infected when we sold it".
deaton 1 hours ago [-]
The law is not software. It would be very easy to argue that a streaming stick that automatically downloads malware is no different from one that came with malware.
pixl97 56 minutes ago [-]
And that's where the retailer is no longer in the loop, which is what this thread was about.
StilesCrisis 16 hours ago [-]
If it's malware, maybe existing laws apply already. I think the bigger problem is enforcement. In China, it's easy to close up shop if anything goes wrong and then just start over. Any liability dies with the brand name.
AngryData 17 hours ago [-]
But it is a retailer's responsibility to know what they are selling. If it was added after they started selling it and hidden in secret, sure a retailer might have an excuse. But it isn't really hidden, most often its put in their marketing materials as a benefit and have been knowingly doing it for many years now.
US retailers can be told they can't sell it here. If you buy it outside of that, well that is buyer beware, but 99% of people aren't buying things from Alibaba or ordering from some random foreign store, they are buying them off US Amazon, Walmart, big box retailers, etc. You don't have to ban things consumer level to deal with 99% of it, you just gotta tell big corporations no and stop dismissing any ideas that put responsibility or liability on big business.
crote 17 hours ago [-]
The problem is that Amazon, Walmart & friends have said the "we are a platform, not a retailer" magic incantation, which means that through the power of friendship and unicorns they are now suddenly no longer responsible for the stuff they sell.
And the "retailer" on record is of course not a real company. They'll just pay some third-party to file a bunch of paperwork in Delaware, pay the $110 fee, and let it go bust if anyone tries to investigate it or make it liable.
pixl97 17 hours ago [-]
>If it was added after they started selling it
While it's great we're getting the manufactures to just stop sending out straight malware and it should be stopped the next most obvious means of attack is just having the device update and add superaids to it's new functionality.
So, no, it won't stop 99% of it at all.
And honestly this isn't that much different from what US companies are already great at by providing updates that take away features we bought with the device.
And not just updating really doesn't save you, instead of being part of a factory botnet, you're just open to become part of some other botnet.
skybrian 16 hours ago [-]
The FCC tests electronics for radio interference. Perhaps they could test electronics for Internet behavior like this too?
Some manufacturers will try to cheat on the tests, but we have AI security checking now, so maybe that would make it harder to cheat?
iamnothere 13 hours ago [-]
That sounds like a fast track to government control of what operating systems are allowed. These aren’t just electronics, they are low power computers that happen to have an OS and software preinstalled.
(I’d be open to a rule that devices must allow users to wipe the devices and install their own OS.)
skybrian 9 hours ago [-]
On the other hand, I suppose if the OS on a TV stick ran in a hardware-enforced sandbox that restricted network access to certain necessary domains, it couldn't be used for scraping websites and ad fraud? It's not being sold as a general-purpose computer so maybe it shouldn't be one.
lesostep 7 hours ago [-]
Simple. Buy one, put it on a test stand, and look at connection log.
Buying in bulk for a resell without testing even one product is kinda insane.
ChuckMcM 15 hours ago [-]
In the US at least there is a lot (and by that I mean like maybe more than half) of civil case law around seller liability for defective or 'dual use' products. In the 70's some cities tried to sue hardware stores for selling spray paint that taggers were using, in several jurisdictions you can find authorities trying to sue vendors of lock picking and/or safe opening tools, etc. My non-lawyer reading of all that is that if it is reasonable to assume that the vendor didn't know, at the time of sale, what the customer was going to do with it, they aren't liable.
Once a vendor has been notified that these units are doing these sorts of things they will stop selling them. Its sadly very prescriptive in that if Newegg gets a notice that "WatchFunTV" streaming sticks are doing this, they will remove that brand but if the same hardware shows up from the same vendor as "SuperTVStreamer" or some such, that product won't be banned until someone does the test and then notifies the sellers. It's cat and mouse all the time.
Now the people who could do something about it, the ad networks like Google, do not do anything because ad revenue is ad revenue, people buying the ads cannot prove that the click was false so hey who can say it was? Which is why ad fraud is a perennial favorite of crooks. The people being ripped off don't have any way to prove it without a lot of support from the ad network traffic data which is "proprietary". Really stupid ad fraud gets shut down, but put a bit of care into it so that the Ad network and claim ignorance? You can do that all day. Just don't get greedy and try to pull in more than say 30 or 50 thousand dollars a month. Remember, the IAB said in 2025 alone Ad Revenue was $300B[1] so 2% of that is only $6B and any network with 2% or less of undetected fraud is considered a "high quality" ad network.
So yeah, ad fraud is the gift that keeps on giving.
This is why I hate the "marketplace" of these stores. In many cases these products never hit their inventory at all, they are functioning like a search engine and payments processor.
eddythompson80 11 hours ago [-]
That’s generally in their definition. “Amazon Marketplace” came out in 2000 allowing 3rd party sellers on their platform. However, until maybe the mid 2010s, they favored product sold by Amazon over 3rd party in their results and recommendations. I remember numerous forum and Reddit posts from the late 2000s about “How Amazon scams 3rd party sellers” by only wanting them there to give the illusion that they have everything but once some category starts selling, they will vendor it too and steal your customers.
At some point in the second half of the 2010s Amazon figured out they can’t compete with a million foreign randomly-generated companies on price, and their users didn’t seem to mind too much. They figured their users cared about delivery times, ease of returns, ease of dealing with Amazon instead of dozens of online sellers, etc and they leaned heavily into that. They will handle fulfillment and take their cut and let people buy whatever garbage they want. They still screw sellers too btw. Ask any one who is trying to sell something on Amazon and they will fill your ear with how much leverage amazon has over them. You can check r/FulfillmentByAmazon/ Or r/AmazonSellers for stories.
eightysixfour 18 hours ago [-]
Probably because we have little to no way to punish those companies. We can't even stop DJI from shipping their drones under other brands to get around the ban.
dessimus 17 hours ago [-]
Our government chooses to not punish those companies. Unfortunately, the lawmakers have decided that the donations to their PACs are more important than actually doing something about it.
ryandrake 18 hours ago [-]
I would very much be in favor of grocery stores sharing responsibility (and regulatory penalties) for selling tainted food! It's kind of mind boggling that this is controversial. "Buyer beware" is not an acceptable basis for society to function.
SoftTalker 18 hours ago [-]
I can't think of a case where a supermarket, upon becoming aware of a problem with a food product, didn't immediately pull it from the shelves, post a notice to customers, and offer a full refund to anyone who had purchased it.
StilesCrisis 16 hours ago [-]
This is unfortunately exactly how society operates in China. It is basically on the buyer to confirm that they're getting something acceptable. Once they've paid, it is what it is.
fragmede 5 hours ago [-]
Not exactly. In 2008 there was a huge scandal where melamine was in baby's milk, so it isn't always what it is.
Yes, if your malfeasance is large enough to be on the front page of the New York Times, you'll be sentenced to life in prison or even death. But killing babies is a bit more heinous than fraudulent ad clicks!
(Also of note: WHY melamine in the baby formula? Because they knew the buyer would check the nitrogen content, because it's a caveat emptor culture.)
16 hours ago [-]
lotsofpulp 18 hours ago [-]
Probably because most people don’t equate the damages from causing bodily harm to whatever these ad clicking networks do.
Voters don’t like seeing themselves or their kids get hurt, but they do like lower cost live sports.
tclancy 14 hours ago [-]
This is one of those things where I, as a suburban white kid, am so happy I discovered Public Enemy and similar bands as a kid.
"Money talks. And bullshit brothers walk a marathon."
sneak 15 hours ago [-]
Tainted food and unsafe children’s toys kill people.
Sketchy devices on your wi-fi don’t really harm anyone. They’re a minor inconvenience at best, mostly to large corporations that like to discern residential connections from business/corporate ones.
inigyou 5 hours ago [-]
I don't know why this is such an unpopular opinion on HN.
red-iron-pine 50 minutes ago [-]
you don't get why a news aggregator for tech bros have problems with crappy devices hacking them?
inigyou 37 minutes ago [-]
What is being hacked? The ad industry? I didn't know the average HNbreader had such deep compassion for the ad industry.
bashtoni 16 hours ago [-]
Yes, fascinating that this is apparently all the fault of Chinese companies, and not the American companies distributing and retailing these products.
simojo 19 hours ago [-]
We purchased a Chinese-made projector from Amazon, which was surprisingly inexpensive (~40 USD). Upon connecting it to the internet, it placed a constantly running feed of ads on the corner of the screen, even while movies were playing. There was no way to disable it either. Even though it's not a stick, it's a similar principle.
xyx0826 18 hours ago [-]
I remember reading an analysis on one of those projectors; the author found a residential proxy running on their device. I would recommend keeping these things off the internet.
mrloopex 14 hours ago [-]
Yes that’s what the article is about.
simojo 17 hours ago [-]
I'd be very interested to see it if you still have access to it.
dhruvrrp 17 hours ago [-]
Dunno if this is the same issue, but someone found malware in their projector. I'm not sure about the accuracy since the report is blatantly AI generated: https://github.com/jrm360seclab/aodin-vo1d-malware
throwa356262 9 hours ago [-]
If the hardware is good and cheap, it should be a fun project to replace the OS with a custom Android build that is clean of adware.
Do you have a link to the projector?
__turbobrew__ 9 hours ago [-]
You forgot to drink a verification can
tollgategit 6 hours ago [-]
> Upon connecting it to the internet,
I dare not ask why you would do such a thing, instead, I will simply ask if you now think the reason was good, and I will hint at you that if the reason was "convenience", then you should answer "No".
breppp 4 hours ago [-]
You assume a lot of things, sometimes you have to connect it to the internet for it to work (such as robovacuums)
GJim 28 minutes ago [-]
Why in the name of all that is holy would you need to connect a projector or vacuum cleaner to the internet in order for it to work?
Seriously, why do you think this is normal or acceptable?
This is bullshit needs to stop (and the scummy AdTech industry has a lot to answer for).
15 hours ago [-]
ubermonkey 2 hours ago [-]
I'm still trying to figure out why you didn't see that coming.
Pxtl 19 hours ago [-]
I mean, did you have to connect it to the internet though? Did it not just have a dp/hdmi port?
mikestew 19 hours ago [-]
Upon connecting it to the internet…
I hesitate to blame the victim here, but why on earth would you do that? “$40 Chinese-made” didn’t give you pause?
bigmattystyles 18 hours ago [-]
To be fair, everything is Chinese made. I would be even the Apple TV and NVIDIA Shield are made in China and if a state actor is determined to get a malicious payload in....
miladyincontrol 18 hours ago [-]
To play devil's advocate, when someone says "Chinese made" they're usually well aware of your point, and are more using it as a common way to describe product mills spitting out countless devices with dubious quality or configuration.
Of course theres good products made in China, and plenty of entirely Chinese brands killing it doing their thing.
8note 15 hours ago [-]
its pretty straight racism though.
its US software companies that are the worst of the worst in terms of adware and malware being shipped under monopoly control
wvh 4 hours ago [-]
It's not racism at all to be weary of (any) political system, its overreach and the incentives of the people living in it, be it China or America or Russia.
The word racism is vastly overused these days.
parineum 32 minutes ago [-]
> its pretty straight racism though.
It's not. Firstly, because countries aren't races. Second, because it's just a leftover from a time where that was a good heuristic.
SecretDreams 12 hours ago [-]
There's enough evil malware provider blame to go around.
Eisenstein 14 hours ago [-]
Its based on the most common heuristic people have developed in regards to the phenomenon. What do you think about 'alphabet soup company' instead, referring to the tendency for names to be a mix of random letters? Otherwise, you can try and create a better term for 'unaccountable third parties using US platforms to dodge liability for their product made out of the cheapest components and software possible' and see if that catches on.
Yes it is also the US companies that are a problem but these are two separate problems and need different terms.
handle584 18 minutes ago [-]
[dead]
r_lee 18 hours ago [-]
Made in China and random Chinese brands are two very different things
ChrisRR 7 hours ago [-]
Often they're exactly the same things
r_lee 45 minutes ago [-]
if you think the Apple TV or Nvidia shield example applies to this then I don't know what to say
inigyou 5 hours ago [-]
Often the USA brand is just buying the random Chinese design from the same factory that brands it in random letters, and tripling the price.
fc417fc802 18 hours ago [-]
This isn't about state actors though. There's a world of difference between a name brand (possibly even a Chinese one) versus what I would term "chineseum". It's nothing to do with China per se and everything to do with purchasing from the extreme low end of the market. It just so happens that the vast majority of that segment is manufactured in China at present.
speerer 18 hours ago [-]
I think normally when people say Chinese made in this way, what they're really communicating is that there's no (meaningful) brand. All they know about it is that it is from China.
worik 18 hours ago [-]
> To be fair, everything is Chinese made
Yes. Chinese manufacturing is quite a phenomenon, useful and everywhere
But to be completely fair, a $40 video projector has a warning label. The price
ponector 17 hours ago [-]
My Samsung phone is made in Vietnam.
SiempreViernes 18 hours ago [-]
This is an age where even teacups demand internet connectivity to fetch firmware updates
Ballas 9 hours ago [-]
And then what happens if someone accidentally pushes the saucer firmware to the cup update?
I mean I get why my cups need frequent java updates, but still.
tollgategit 6 hours ago [-]
And yet, it is now still just as stupid to do it as it was before we arrived here.
handle584 14 minutes ago [-]
[dead]
qmr 15 hours ago [-]
...firewall it then?
dboreham 18 hours ago [-]
Capitalism!
wil421 12 hours ago [-]
Chinese!
Epa095 9 hours ago [-]
Chinese capitalism!
red-iron-pine 7 minutes ago [-]
Communism with Chinese Characteristics
jojobas 15 hours ago [-]
At least in capitalism you have the choice to look for a malware-free alternative. 100% USSR, had it survived to the IoT era, would penalize you for not having a state-mandated surveillance device on at all times.
DoctorOetker 12 hours ago [-]
I agree fully with your assessment of USSR but basically any nation state with the power does such things.
Show me a COTS smartphone where the end-user can burn the OTP fuses for his personal public key, so they can have it boot their own custom signed firmware, and control exactly what runs in TrustZone's SW Secure World?
red-iron-pine 6 minutes ago [-]
show me anyone outside of HN or XDA devs that would ever want to do that
jojobas 9 hours ago [-]
You can flash yourself GrapheneOS with your own keys for the bootloader. Then again "I can't make sure all manufacturers aren't in collusion" when FBI sues Apple and others (and fails) over suspects' phone access is quite different from "every device sold in the country must have government malware", as it is in China.
inigyou 5 hours ago [-]
I can't find a device in the USA that doesn't come with government malware. Is this another instance of the USA accusing China of everything the USA is doing (like with the credit scores)?
breppp 4 hours ago [-]
You'd have to be a bit more specific of which government malware you found in Android/iOS devices, cause that would be interesting
inigyou 4 hours ago [-]
Android comes with something called Google Play Services, and iOS has a thing called iCloud. You may have heard of them.
azan_ 17 hours ago [-]
Absolutely, there's no scam outside capitalism!
jkahrs595 17 hours ago [-]
Outside of capitalism is outer space, so your snarky comment is actually true.
usef- 16 hours ago [-]
I think he meant the other kind of "outside", not physically. Plenty of bad stories.
azan_ 15 hours ago [-]
Of course, every socialist country is actually capitalism and that's why it fails.
inigyou 5 hours ago [-]
Which country is socialist?
ColdStream 15 hours ago [-]
Get the sarcasm, but of course there is scam outside of capitalism. Its just that the capitalistic model almost turns it from an inconvenient bug into a mainline feature.
Not saying there is an absolute perfect alternative, anyone who says that is usually shoveling smoke, but there are flaws with this economic model to be addressed.
azan_ 15 hours ago [-]
Not true at all. I'm from Poland which was occupied by communist for a long time, and I can guarantee you - the amount of scam we had under that rule was orders of magnitude larger than what we have now.
ColdStream 15 hours ago [-]
Yeah I did forget about that. When you flatten the pay structure across the board, it makes bribes and scams so much more desirable. But also, communist structure in practices is sort of the total opposite of capitalism at a distance.
It was said that Karl Marx was completely right about Capitalism and completely wrong about Communism. And that is fairly accurate, both have big flaws.
Most times, the opposite of one bad idea is another bad idea.
azan_ 15 hours ago [-]
I think it's really far fetched to say capitalism is bad idea. It's great system, it has some problems, but the upside is so big and alternatives are so bad that it's really unfair to call it bad system.
pbhjpbhj 2 hours ago [-]
Yh, the end of civilisation is a good thing after all, so enabling greedy fuckers to accelerate all life on Earth ever more rapidly towards destruction has to be good ...
ndsipa_pomu 7 hours ago [-]
I think that encouraging corporations to destroy our environment (e.g. climate change) as fast as possible to maximise profits is a very good reason to call it a bad system. Yes, some goods and services become much more efficient, but now we're all going to have to pay the price for it.
inigyou 5 hours ago [-]
Like the current never-ending heat wave. It's predicted to go on for months btw and the ocean is 4 Kelvins warmer than it should be.
mortenjorck 21 hours ago [-]
In this case it’s actual malice, that the streaming stick is set up for residential proxy and ad fraud straight from the factory. But incompetence can lead to the same place if it’s a poorly engineered, un-maintained device with an old version of Android that will never be patched and is always one no-click exploit away from being commandeered into residential proxy and ad fraud.
FinnKuhn 21 hours ago [-]
Those TV streaming boxes really are (from a cybersecurity perspective) probably one of the worst things you can buy. Here is the "Darknet Diaries" Episode on them: https://darknetdiaries.com/episode/172/
Thank you for sharing this. The superbox investigations have been incredibly interesting to follow.
acdha 18 hours ago [-]
I was trying to figure out why we saw so many fraudulent applications from Vietnam for a service which is restricted to the United States, especially because they were all getting rejected - it seemed like even the laziest spammer would lose interest in something they couldn’t monetize.
A guy in Vietnam mentioned that one of the largest ISPs there used these really dodgy Chinese modems which were so notoriously insecure that it was apparently common knowledge that you should replace them if performance was slow because that was a sign that yours was being used by a botnet. Apparently the cost of access to one of those nodes was so low that the spammers don’t even really monitor their bots.
frollogaston 19 hours ago [-]
Since these are poorly engineered, wonder how easy it'd be to reverse-engineer one and just get the free streaming on a non-scam device.
kiririn 18 hours ago [-]
See CoreELEC/LibreELEC/etc - totally replaces the (potentially dodgy) Android OS on these kind of streaming boxes with a stripped down Linux+Kodi setup
qmr 15 hours ago [-]
I thought those were for x86? They run on ARM TV boxes / sticks now?
tesnorindian 8 hours ago [-]
LibreElec also supports ARM builds than can run on SBC like Raspberry Pi. While CoreElec is exclusively for Amlogic ARM processors.
wildzzz 14 hours ago [-]
Best case, you can grab the credentials off the Kodi box and use them on a clean install.
Worst case, everything is packaged up in a single app so it's all or nothing. Although you could just wipe the box and find another pirate TV provider.
dpoloncsak 18 hours ago [-]
If it's something like a Firestick (or the knock-off featured in the article), you're really just connecting to Content Provider servers to handle auth and content streaming, right? They're just OSes designed to run Netflix and Hulu. Would be hard to spoof I think
mikepurvis 18 hours ago [-]
Indeed. Owning the streaming box lets you loose on whatever network it's on, but it doesn't actually get you inside the content gardens; those are separately managed by teams of people much more motivated to protect their IP.
inigyou 5 hours ago [-]
What is the malice in those things?
alex_duf 21 hours ago [-]
I wonder to what degree malice can be engineered to look like incompetence?
consumers are however happy to buy a cheaper stick with an overall public bad
inigyou 5 hours ago [-]
I don't even think it's a public bad. I think attacking internet gatekeepers like Cloudflare is objectively a public good. So is attacking legal spam companies.
pavel_lishin 21 hours ago [-]
> generic TV boxes that promise unlimited content streaming for a one-time fee
I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.
havaloc 21 hours ago [-]
I have an elderly client who sends me links of stuff to buy all the time. One day it's one of these streaming sticks, the next day it's half-price stamps, and I tell her every time, please don't buy this stuff. And yet she does anyway, as if I was almost being mean and saying no just to say no.
So yes, I do want to blame the purchasers of these things, sometimes. To prove her point that her stamps were legitimate, she mailed me a card using one of her half priced (but likely fake) stamps and it made it through!
Terr_ 20 hours ago [-]
Perhaps they grew up in a time/environment where "if it was that bad they wouldn't be allowed to advertise it", and they're still using that old calibration?
mhurron 19 hours ago [-]
My falther-in-law was less that and more, if I can get away with it, it's actually legal. Many know their fake, and do it because they can get away with it.
That was his justification for a satellite descrambler, they're sending me the signals, obviously I'm allowed to.
brewdad 18 hours ago [-]
There's an old Carlin joke about "If a cop didn't see it, I didn't do it."
mmooss 18 hours ago [-]
I can imagine many on HN having excited discussions about their satellite descramblers.
> do it because they can get away with it.
Lots of people on HN download and upload copyrighted materials. Is it really different?
bityard 17 hours ago [-]
Fine, you've nerd-sniped me.
I tinkered with Dish Network descrambling 20 years ago. Not because I wanted to just watch a bunch of free TV (I hardly watched any TV anyway, we mostly watched DVDs from the video store and Netflix). More because it felt like an interesting rabbit hole. And it was pretty interesting!
I picked a good (newer!) satellite dish and LNB from the trash and had a friend help with the installation and alignment because that was his previous job. Normal people use some kind of tool to find the satellites' geosynchronous orbital station in the sky, but he did it often enough that he could simply look up into the sky and point at them.
There were a handful of grey-market satellite receivers you could buy that were technically capable of descrambling a commercial signal. Of course, they did not advertise themselves as such. They were marketed as FTA (free-to-air) DVB-S receivers. These were not illegal as they were fairly popular in regions of the world that actually _had_ a fair amount of FTA (unscrambled) satellite channels. The only satellites visible from North America, however, tended to carry religious, shopping, or Mexican/Central American programming. Oh, and NASA TV.
The receiver I bought had DVR functionality if you hooked up a USB drive to it. I think I still have some recorded shows on it. It would have been a great way to harvest and release pirated TV shows to the Internet, if you didn't mind editing out all of the ads and whatever.
DVB-S was basically a raw MPEG-2 TS stream that could be optionally encrypted. To use these grey-market receivers as descramblers, you install some custom firmware containing the descrambling modifications and keys. I'm failing to remember the technical details, but the encryption they used was not very good. Dish Network would rotate the keys occasionally, and when they did, you had to update them on your receiver. I can't remember now if the keys were part of the firmware, but I remember it being a pain in the ass.
The firmware/keys part of this had a very "colorful" community. You had to sign up to a very specific and somewhat exclusive web bulletin board in order to download the firmware/keys. I don't remember how I gained an account, but I remember it being non-trivial. IIRC, it was like one guy maintaining the firmware/keys and sometimes it took weeks for him to adapt to whatever thing DN did to thwart piracy. The board was moderated by a complete power-tripping asshat who enjoyed banning people for fun and then gloating about it. (I was not banned, that I recall.) I think they started requiring "donations" in order to view certain threads (like firmware releases) after a while. But I could be misremembering that. I just remember the community was very toxic.
After a few months of this setup, DN figured out how to rotate their keys too often for the casual pirate to keep up. I disconnected mine around that time and moved onto other things. Partly because the experiment ran its course and partly because migrating to real-time key updates would have meant buying a newer receiver. For a while, I flirted with the idea of getting a DVB-T PCI receiver card and working on breaking the encryption myself, but it was quite a bit above my skill level at the time and there did not seem to be anyone else working on it out in the open, since the DMCA was still pretty new then.
wildzzz 14 hours ago [-]
Your experience describes lots of the kinds of communities you can use to access pirated media. You either pay for the legit service, pay for pirate streaming services, pay with your privacy with the free, dodgy pirate streaming services, or pay with your sanity in dealing with nutjobs.
Scoundreller 11 hours ago [-]
I recall the “free to air” receivers being pretty easy to configure. My main pita was getting a cheap ftdi usb->serial adapter because that’s how old the underlying tech was. Still easier than jtagging an official receiver.
I migrated into it from the earlier days involving iso7816 card programming and mitm cards so I guess I didn’t have trouble finding which sites to get the fta files. I have good memories of those places being quite welcoming if you did your reading but sometimes ephemeral. Plenty of freeware (but sometimes delayed access). But part of the “payment model” was sevurity vendors trying to destroy their competitors or sell more countermeasures and card swaps to their satellite tv broadcast clients (!!!).
A card swap (and some prosecutions on the nudge nudge “free to air receiver” importers) put an end to most of it unless you went to internet-key-sharing systems where I guess the shared keys come from a handful of slave receivers somewhere. Given the 2-way nature of those key “subscriptions” and network connections required, I could (moreso) understand the paranoia of the operators.
Broadband penetration ultimately killed sat cracking, Netflix et al too. Oh, and what people usually call “iptv”.
kotaKat 4 hours ago [-]
Yep. Gone are the days of running out for a "119 IKS" or hunting for Bev and Charlie, now everyone just grabs some pooched RTSP feeds and calls it a day.
Feels fitting recently to discover the Dish Network "Pirate TV" recordings. I should run my own in-home IPTV station and use the Pirate TV bug as the logo...
You're watching Dish Network's Pirate TV channel!... ... if you're watching me, you're a SATELLITE PIRATE!
15 hours ago [-]
al_borland 18 hours ago [-]
They aren’t downloading that content from a company with a $2.5T market cap. They presumably aren’t making a living by selling that copyrighted material via a retail that claims to run a legitimate business.
I think that makes a big difference.
Imagine if Amazon Video, Audible, and Kindle will all just pirate stores, where uploaders of the pirated content made money on the downloads, people paid for those downloads, and Amazon took a cut of everything. How long would that go on before they were in court and that was shutdown?
iamben 19 hours ago [-]
I think that's a default for a lot of the older (and some of the younger!) generation, same goes for news and media. They grew up in a time where there was a practical barrier to publishing and (largely) laws behind you doing it.
So they trust literally everything they read. I still don't think my folks can fathom you can spin up a very real looking newspaper website with fake articles in about 10 minutes.
mmooss 18 hours ago [-]
I find younger people are more likely to trust whatever they read - social media rumors, LLM output, Reddit threads - and older people looking for credible sources.
CM30 15 hours ago [-]
Honestly, my experience is that it's less age specific and more like 80-90% of the general public. A lot of people just can't recognise the difference between a credible source and a dubious/fake one, and will just share any old random page or social media post they come across online. Heck, the number of people I know that see things like ChatGPT as some magic encyclopedia/sage that knows everything is depressingly high...
brewdad 18 hours ago [-]
When my kid was young I set up a basic web server and taught him how to make a VERY basic web page. I let him write whatever nonsense he wanted to and then we made it live.
It was both a gateway into learning how the web works but also that literally anyone can post anything to the internet and it doesn't make it true. I like to think he's more savvy than many of his peers but we all have our blind spots.
doctorspazz 16 hours ago [-]
was the url for the website you set up for him www.creedthoughts.gov.www\creedthoughts
rrr_oh_man 17 hours ago [-]
> time/environment where "if it was that bad they wouldn't be allowed to advertise it"
I doubt there ever was a time/environment. Snake oil has been around consistently for a very long time.
Pxtl 19 hours ago [-]
Of course, what they're missing is that laws are for poor people.
Amazon will be notified they sold something illegal and will take it down and ban the seller who will immediately launch a new store under a new name.
The purchaser, on the other hand, will be fully liable for whatever horrible thing they bought.
19 hours ago [-]
_carbyau_ 15 hours ago [-]
What is the world view (aka context) of this little old lady?
Watch the news and see CEO's with golden handshakes after the company is nailed for something. Wall street failures. Companies getting government bailouts. The current US president. It is all about getting away with what you can.
The news - being the news - doesn't show process as per normal. People doing the right thing most of the time.
In this context, fake stamps for the "little person" doesn't even rate a mention. Who the hell is going to raise a moral panic about an old lady with fake stamps...
And so the "little people" will keep buying fake whatevers as long as it stretches their dollar further.
rrr_oh_man 17 hours ago [-]
What is your line of work, if I may ask?
floam 19 hours ago [-]
Half priced stamps work though, and nobody is going to prosecute grandma for counterfeiting postage stamps.
zeafoamrun 18 hours ago [-]
Yes they do. USPIS does not f around
Pxtl 18 hours ago [-]
Oddly they don't ever seem to prosecute the sites that profit from selling them. Funny, that.
Terr_ 18 hours ago [-]
It doesn't seem too weird to me: Selling someone fake stamps is a general act of fraud, between buyer and seller, and would be pursued by state/federal attorneys general.
The USPS becomes directly involved only later, when someone tries to defraud them by using a fake stamp.
kube-system 18 hours ago [-]
Makes sense to me, the only place I've ever seen them personally advertised are overseas websites.
mmooss 17 hours ago [-]
> half-price stamps
Who is selling half-price stamps?
#1 How big is your potential market? It's people still mailing things from home, who haven't figured out how to do postage on their computer.
#2 Of the population in #1, it's those who find real stamps so expensive that it's worth bothering with discounts.
#3 Of the population in #2, it's those who would want to buy something fraudulant (or not know better) and who would want to risk using it.
#4 Considering the size of the #3 population, how many stamps do they use in a month?
#5 What is your margin on a half-price stamp? You have to pay for advertising, printing (we're talking a profit margin under $1), packaging, and your own time, but at least shipping is free!
wildzzz 14 hours ago [-]
Its the grandmas still sending you a $5 check in the mail for your birthday
mmooss 13 hours ago [-]
How can those few people - and again narrowed down to the population mailing letters AND needing stamps AND seeking discounts AND willing or ignorant enough to do/risk fraud - with that little revenue per item, make a half-price stamp operation worthwhile?
Scroll_Swe 19 hours ago [-]
Then again I used to torrent everything under the sun and it actually rocks to have every tv show, movie, game ever released for free forever.
So is it greed? Yes, but I did it too so now that its more accessible I cannot really blame people.
al_borland 18 hours ago [-]
Why should anyone assume a product being sold by (or at least on) Amazon, the latest retailer in the country, is an illegal device?
It’s not like they’re buying these things out of a car trunk in a dark alley. These retailers need to be held liable for selling these things. If they sell this stuff, why not illicit drugs?
If they are unable to maintain control of 3rd party sellers, then they should end the 3rd party seller program. It has done nothing but damage Amazon’s reputation, and it just keeps getting worse.
nvme0n1p1 21 hours ago [-]
OTOH - TV, radio, and YouTube are all unlimited and free. Why not streaming?
There are lots of people alive who grew up during the days of broadcast TV and radio. I get why they might not understand the difference.
weberer 19 hours ago [-]
There are a ton of legitimately free IPTV streams. You can watch them through most media players like VLC without having to download anything shady.
Ok but have fun explaining that to the average person. Buying a dongle is easier than installing software or typing URLs into their TV ("my TV doesn't even have a keyboard").
To most people IPTV is a bunch of gibberish letters, indistinguishable from the gibberish brands on Amazon. Someone's grandma from Colorado doesn't deserve to get scammed because she didn't research the acronyms.
kube-system 18 hours ago [-]
That is chock-full of pirated content.
crote 17 hours ago [-]
Most of it seems to be first-party streams of content which is also available as unencrypted over-the-air broadcasts.
It is paid for via ads or subsidies, so there's no reason to block access to the stream, so they just don't bother, and make life easier for anyone building streaming devices wanting to integrate their channel.
Someone accessing the stream directly is not the originally intended use case, but it isn't any different from someone accessing it via their smart tv.
nuxi 19 hours ago [-]
Two things:
- How are these "legitimately free"? For example AMC is a commercial TV channel and as far as I know, they don't offer free streaming. Same goes for MGM, FilmBox etc.
- Strictly speaking this isn't IPTV, it's just web streams. IPTV is usually delivered via multicast (MPEG-TS/RTP/RTSP streams, over UDP mostly).
18 hours ago [-]
bluedino 19 hours ago [-]
Most people who buy these want to watch free movies, sports streams, etc that aren't on OTA or free services
Scoundreller 11 hours ago [-]
Or straight up unavailable on paid services. There’s often no way to legitimately subscribe to programming from $HomeCountry, especially if you’re not in a big Diaspora country.
Tangurena2 17 hours ago [-]
The streaming services have fractured and taken so many movies off their service so much that it is too hard for most people to figure out where that show/movie can be found.
From a link above to the story on darknetdiaries:
> For Pokemon, there is a website that tells you how to watch this. You start off on Netflix, then swap over to the Pokemon streaming service, which is the only place that has Season 2, then swap over to Prime Video for Seasons 3 through 5, swap to Freevee, then Hoopla. Season 13 is only on Amazon, though. Then swap to Tubi, then Hulu, then Roku channel, and then finally back to the Pokemon streaming, and then Netflix. Easy.
That's 8 different streaming services to view one series.
tomaskafka 16 hours ago [-]
And yet they can all be comfortably watched at a single place, with high quality and no ads.
pibaker 18 hours ago [-]
> it does seem like a Too Good To Be True situation
It's difficult to judge the price of media products. We have legal music streaming services that charges you an album's worth of money a month and lets you listen to millions of songs. You can pick up old AAA games for less than ten bucks. I'd say when people say that price tag, they don't think they get scammed into being a part of a botnet. They think the device manufacturer cut a good deal with the media rights holders.
joshmn 17 hours ago [-]
I had a streaming piracy site that I went to federal prison for. I can chime in on these people.
It's worth separating the two populations:
My users had money and had considered legal subscriptions. They paid me because the legal product was worse—in my case, sports blackouts, a bunch of different apps, etc. They knew what they were buying into and they had weighed the risk. I can tell you right now some of my former users have bought into this market.
Then there's the unwitting: a person buying one of these devices at a too-good-to-be-true price is treating it as a hardware purchase from Amazon, where the actual monetization isn't inferable from the listing. Calling it too good to be true assumes the buyer can see what shit they're standing in. They can't. There's no visible market here. It's just a product page with reviews.
To add to this: the proxy exit is exactly why these cost so little. Demand for residential IPs is booming (check some of the proxy subreddits to see what I mean).
The ironic part is that there's a chance the person who bought one of these boxes to watch pirated sports was the exit node I was using to acquire the feeds in the first place.
paultopia 19 hours ago [-]
Yeah, isn’t this a classic kind of scam the would-be scammer situation? If you think there’s some way to buy one cheap device and somehow get around subscribing to streaming services[1], then of course you’re going to be in a market with fraudsters…
[1] Can someone explain what the theory of the product is here? It sounds like they’re marketing these things as ways for the customer to commit fraud, for example by connecting to someone else’s login. How else would the customer expect to be able to get free Netflix or whatever?
chihuahua 16 hours ago [-]
It may be the case that these devices are front-ends for pirated content that's hosted in various places. They're not streaming it from Netflix servers. It's content similar to that offered by Netflix and other streaming services, pirated by someone else, and hosted by someone else for streaming by anyone who can figure out how to find it.
fred_is_fred 21 hours ago [-]
If you offered most people free streaming for a $37 USB stick but directly told them it would be faking ad clicks when the TV is off, would any of them really care?
1970-01-01 21 hours ago [-]
No, and that's is the root of the problem. The buyer is happy and so is the seller. They don't care to understand what they're allowing and everyone is allowing it to happen.
inigyou 5 hours ago [-]
And why should they care? There is literally no reason they should care, it does not affect them in any way, if it causes ad companies to ban their IP address that's actually good for them personally, and most people outside of the ad business would agree that hurting ad companies is good.
bayarearefugee 19 hours ago [-]
I wouldn't use a device like this for a lot of reasons, but the fact that what they are doing might be taking advantage of the incredibly predatory digital advertising system is neutral to positive for me, if I'm being fully honest.
If they were using the system to rip off random people, I'd be 100% against it, if they are fucking Google and the giant corps that advertise with them, ehh.. not my problem and can't be assed to care. Google is not a positive force in the world. Hasn't been for many years.
mschild 18 hours ago [-]
Wouldn't this ultimately make money FOR Google and only cost money to the company that placed the ad?
Sure, Google's paying but they get their money regardless.
crote 15 hours ago [-]
It reduces the value of their ads.
Let's say you are an ad buyer. Previously 1M clicks resulted in 1000 sales, now 2M clicks result in the same 1000 sales. If you previously paid $1000 for 1M clicks, you paid $1/sale. If they are now asking you to pay the same $1000 / M clicks you'd be paying $2/sale, so Google would have to drop to $500 / M clicks to offer the same value to advertisers.
But the same applies to ad sellers as well. Google would have to slash payouts to websites displaying ads by the same 50% / click or they'd be cutting into their margins. A competing ad platform without fraudulent clicks would be able to slide into this space, offering both a better value to ad buyers and a better payout to ad sellers, so they'd be taking market share from Google without having to do anything themselves.
Of course that assumes a market in which the value of ad clicks, views, and placements is clear to everyone and switching between ad platforms is trivial, which is not even remotely the case.
wildzzz 14 hours ago [-]
Sure but for the ad network, it means they can brag to new clients about how many clicks they can get them. If the ad clicker isn't buying, that's the client's problem, you already did your job by getting them to click. Maybe the client needs a more direct campaign (which costs more) or needs to change their website/prices, people are walking into the store but they just aren't buying.
Its either the ad network running these click botnets or contracting someone to do it. If it was just impressions getting boosted, that just looks shady, those are barely worth anything.
chowells 18 hours ago [-]
It might damage Google's reputation with advertisers in the long term. I'm not convinced Google would even care about it, given their other behavior.
inigyou 5 hours ago [-]
Proctor & Gamble did an experiment: they cancelled all of their online advertising and watched their sales numbers. Sales didn't change. That sort of thing is downstream of this sort of thing. Online advertising is a money black hole, a sacrifice to the gods. It doesn't really do anything.
pessimizer 16 hours ago [-]
> They don't care to understand what they're allowing
If you told normal people that they could get free content with a TV streaming stick that would also constantly fake clicks on AI generated websites to screw advertisers over, they would think of it as a bonus. Also it would make them trust the stick more (fallaciously), because they would know how the people who sold it were getting paid.
GolfPopper 21 hours ago [-]
They're just meeting the standards American society has set.
Scroll_Swe 19 hours ago [-]
[flagged]
dang 18 hours ago [-]
Could you please stop posting unsubstantive comments and flamebait, and also please stop using HN primarily for political/ideological battle?
These things are not what HN is for, and destroy what it is for, so we ban accounts that do them repeatedly.
Maybe they wouldn't care about the ads but the residential proxy is another story. I'm sure lots of problematic stuff goes through that and you take the risk of being associated with it.
inigyou 5 hours ago [-]
Not really. Has anyone ever got in trouble for this?
iugtmkbdfil834 21 hours ago [-]
Uhh, I have an extended family member, who not only uses it, but now also tries to get other people to get into it. Since I was familiar with this practice ( and the issues it makes worse ), I noted those to him in an attempt to both politely decline and, hopefully, spare him, and society, some future problems. Without going into any identifying details, he didn't take it well ( and I don't think I got on my high horse ).
Anyway, I think some level of blame is warranted.
chihuahua 16 hours ago [-]
According to the Darknet Diaries podcast episode "Superbox", some of these devices are sold via multi-level marketing schemes, which would explain why there are random individuals selling these, collecting a commission for each device sold. Which is why the person you mentioned is unhappy when someone points out the problems with these devices.
IncreasePosts 21 hours ago [-]
Maybe, but if they're a not-very-tech savvy older person buying this, they probably remember shows being free from over the air antennas and may think it is something like that.
ghostly_s 20 hours ago [-]
> they probably remember shows being free from over the air antennas
you are aware broadcast TV never ended?
myself248 14 hours ago [-]
An awful, awful, awful lot of consumers think their old antennas don't work now that everything's gone digital. And they've simply never tried.
IncreasePosts 20 hours ago [-]
Yes, in fact I have an antenna and a HDHomeRun nestled in my attic to record over the air shows that I occasionally consume.
But, I think it's far more common for people to have a TV service today, perhaps since comcast and their ilk push hard the TV/phone/internet bundle, and gone are the years when everyone would fiddle with the antennas on the back of their TV to get the right reception.
bdangubic 20 hours ago [-]
I watch TV over an antenna, shows are free still
varispeed 19 hours ago [-]
I used to know someone doing this. They said they know it is too good to be true, but they hate corporations and it's their little way to stick one in.
rng-concern 19 hours ago [-]
I know a few people who buy these, and they kind of know what they're doing. They just try and not think about it too hard.
It reminds me of the saying: "It Is Difficult to Get a Man to Understand Something When His Salary Depends Upon His Not Understanding It".
If these people thought about it for a few minutes, they would understand, but they choose not to, as ignoring it is too advantageous.
I admit I was tempted, as the price of all streaming services goes up, and services become more and more fragmented. During the same period where I have not had a raise.
acdha 18 hours ago [-]
In the 90s, there was a cottage industry selling CDs of bootleg software at swap meets and flea markets. A guy my dad knew was almost condescending to anyone who paid for software despite having been hit by viruses multiple times because it was so much cheaper. Even having to deal with a client(!) who naively called the vendor support only to be informed that they hadn’t actually purchased a license wasn’t enough to get him to resist that savings.
inigyou 5 hours ago [-]
On what grounds would they choose not to?
rng-concern 3 hours ago [-]
I won't argue the ethics of piracy. That was not my point, but if you want to I suppose I could.
My point was, their ethics WOULD have prevented them from doing the thing. But they chose not to think about it too hard. Perhaps subconsciously. I'm not above doing this sort of thing either. We all do it for various things.
I've added code that is bad for the user (overbearing telemetry for instance) because my salary depended on it. At the time I tried not to think about it too much, as it would cause cognitive dissonance.
croes 21 hours ago [-]
It sounds like scam
flerchin 21 hours ago [-]
Well now I want one
Cider9986 21 hours ago [-]
Stremio+TorBox are the two words. ($3/month)
ghostly_s 20 hours ago [-]
That's not what these things are. They come preloaded with apps that stream pirate broadcast streams and on-demand servers operated out of China.
Cider9986 17 hours ago [-]
Absolutely correct. My comment intention was if you want to make one yourself and get the experience of all shows +movies.
ghostly_s 13 hours ago [-]
Did OP say "I want something vaguely similar that requires a greater investment of my time and money"? Did you in any way indicate that's what you were proposing?
19 hours ago [-]
Cider9986 21 hours ago [-]
It could be possible, I haven't done the math though.
Stremio +Torbox is $3/month and they can probably share 10+ households on one TorBox account so it could work out. The seller could just stop paying the TorBox subscription at whatever point and they have an incentive to do so.
stevetron 23 minutes ago [-]
Birds Nest soup with Chinese tomatoes?
Or Cinese noodles with Chinese tomatoes?
It sounds likw 2 domestic markets that China should use to rid themseves of their over-abundance of tomatoes.
glitchc 21 hours ago [-]
Defrauding ad networks doesn't seem like a bad thing, although using my internet connection as a proxy is obviously terrible. It wouldn't surprise me to learn that my connection is being sold as a VPN service by the vendor.
alistairSH 21 hours ago [-]
It'll be a marginal effect, but fake clicks impacts the ad buyer, which then impacts their financials and pricing.
The only winner here is the scammers running the fake affiliate sites on which these sticks are "clicking". Or, am I missing some facet of this enterprise?
snickerbockers 9 minutes ago [-]
If all they did was shove banner ads for boner-pills in my face like they used to 25 years ago I wouldn't mind and I might even turn off adblock. The problem is that modern advertisements on the internet are spyware at best and a malware vector at worst.
It's arguably fraudulent to even refer to it as "advertising" at this point, clearly that's just a cover to give them an excuse to sell data to silicon valley corporations that are unironically named after fictional devices used by sci-fi/fantasy villains to manipulate people.
frollogaston 19 hours ago [-]
What this misses is the person buying the TV stick doesn't care about the impact on the ad market. The bigger problem is residential proxying, because their IP will end up getting used for something bad.
inigyou 5 hours ago [-]
And what does that cause? More captchas?
snickerbockers 7 minutes ago [-]
Probably, but in the worst-case scenario you could unwittingly become an accessory to a felony if the proxy is used to access CSAM. Especially if the proxy ends up caching files.
hnav 16 hours ago [-]
most residential proxying these days is used by the purveyors of AI
ssl-3 20 hours ago [-]
Another winner is the person who gets to watch cheap digital TV, without putting together a usable antenna and limiting their reception to the broadcast channels that are nearby.
I mean: They just pay the money, plug the thing in, push some buttons, and: TV happens. Right?
cryzinger 19 hours ago [-]
You really don't want fraudulent clicks ("invalid traffic", per industry lingo) coming from your home network, because any publishers (apps and websites, per normal-people lingo) who use tools designed to block invalid traffic might start flagging legitimate traffic from your network.
frollogaston 19 hours ago [-]
Can confirm. I used to use Ad Nauseam (Firefox extension that clicks all ads), eventually stopped when I was getting captcha'd left and right.
Also, visitors on my wifi started getting strange ads. Yes I threw off the algo, but I'm a guy with wife, I'd rather get car ads than like divorce lawyers + gay dating sites.
snickerbockers 19 hours ago [-]
Theres the question of whether or not the fraudulent advertisement clicking is using enough traffic to inconvenience or impose fees upon the user but otherwise I agree with you and am tempted to buy one just to fuck with advertisers.
Backdoors and spying are also a problem in theory except at this point you can't even trust "legitimate" companies on that front so it's a moot point.
acdha 18 hours ago [-]
> otherwise I agree with you and am tempted to buy one just to fuck with advertisers.
How that actually works in practice is that your favorite sites make less money and your IP gets a bad reputation so you CAPTCHAs or outright blocked. There’s no “sticking it to the man” here, just contributing to the frictional grind making the internet worse for ordinary people.
snickerbockers 5 hours ago [-]
You are drastically over-estimating how much fondness I have had for the web ever since social media companies and search providers colluded to drive everybody into their walled-off fiefdoms.
inigyou 5 hours ago [-]
My IP changes more than once a day. If Google captchas my whole ISP, good for them, hopefully it drives people away from Google.
DennisP 14 hours ago [-]
They make less money, but they also notice lower conversion rates on ads, which might make them rethink their strategy.
(IP reputation keeps me from doing it though.)
19 hours ago [-]
kube-system 18 hours ago [-]
Fraud is also bad, even if you aren't fond of those being defrauded.
blackjack_ 18 hours ago [-]
Fraud that destroys market trust in a market that mostly deals in surveillance and selling intrusive data that was collected mostly unknowingly from the subject seems great to everyone who has any amount of integrity.
pixl97 17 hours ago [-]
So distilling an AI model of one of the big SOTA models is a bad thing now?
tjpnz 11 hours ago [-]
What about all the fraud committed by the online ad industry?
ColdStream 15 hours ago [-]
They took the idea of the 'Ad-nauseam' add-on for Firefox and used it for their own gains I see.
why is running a proxy a bad thing? someone profiting off it could be bad maybe, but even that is good if it pays for my subscription.
but compare running tor nodes, and especially exit nodes. that surely would be a good thing, so at least if you think tor is good then running a proxy should be the same and it should be normalized.
doing it in secret without the user knowing is what's bad
From the outside, I don't see the problem. The sites I visit, including LWN, never seem slow or have downtime as a result of this increase in traffic. I hear complaints from people hosting small sites, but they never seem to include concrete examples of downtime or measurably bad user experience. Why does it matter if the server load is high if everything stays functioning? Going from 5-20% to 60-80% load hardly seems like a catastrophe to me when the remaining headroom was not going to be used for anything else. Having your data that's public-enough to be scraped/cited/parodied/ridiculed included in a training set also doesn't seem like a problem. Are they struggling to pay bandwidth usage bills? Is there some actually-necessary intervention required to keep things running smooth, as opposed to panicking and taking unnecessary preventative action?
glitchc 20 hours ago [-]
Indeed without my permission is implied. Without it, you have no idea what traffic is being routed and could be on the hook for something nasty like CSAM.
inigyou 5 hours ago [-]
Has that ever actually happened? Has anyone gone to court for downloading child porn that was actually through a residential proxy?
Dylan16807 18 hours ago [-]
Those are different issues. Permission doesn't mean you know what the content is, and lack of permission doesn't mean they're going to load anything weird or bad. Lack of permission implies worse ethics overall, but an operation focused on clicking ads will be loading relatively normal sites.
19 hours ago [-]
40four 18 hours ago [-]
Because your home IP address is going to be associated with criminal activity. So if that’s acceptable “payment” then I guess there’s no issue
inigyou 5 hours ago [-]
What concrete harm does this cause?
ta988 19 hours ago [-]
A familly member had one of those (he had to pay a yearly subscription in addition to the stick). Network would be unusable as soon as it was on for anyone else, and it also tried to scan things on the local network. It was indeed connecting to all kind of services all over the world (and saturating some tables in the router doing so which blocked other clients). Definitely evil, definitely on purpose.
deepfriedbits 18 hours ago [-]
Reading this, I caught myself wondering how we distill what's in this excellent write up into something the average consumer understands, including the dangers from buying and using devices like this.
Is it a graphic that's shared? Something else? I am sure we all know or have heard of people with these devices that promise free streaming.
Arainach 18 hours ago [-]
The bigger problem is convincing them to care. Botnets are abstract - where's the pain to them? Ad farms? That's "just hurting big corporations".
Remember, a significant portion of the population got angry (often violently so) when just asked to wear a mask to protect their neighbors. And the threat there was significantly easier to explain.
pibaker 18 hours ago [-]
Just tell the anti mask types the TV sticks come with CCP hacking software preinstalled.
inigyou 5 hours ago [-]
First you'd have to figure out what the dangers actually are. Most of what's cited in TFA and this comments section are only dangers to large evil companies, and why should anyone care about them?
10 hours ago [-]
ValdikSS 17 hours ago [-]
In the world of auto-updates of software and firmware, even the hardware which is now completely legal and crap-free, could convert itself to a proxy or ad network later any time.
And don't forget about counterfeit products (which look like original but different in firmware) and supply chain attack vectors, which are really, really common.
If you want to buy something as simple as a feature phone, going to a store with 10 of them will give you at least 1/10 chance to buy a phone with a trojan/backdoor.
ta988 18 hours ago [-]
I warned them about the risk of those things and showed them what I found, they continued buying the next generation (that person and his two >40yo kids). They NEEDED to watch those soccer games more than they cared about security...
SecretDreams 12 hours ago [-]
You can't. This is a legitimate thing the government needs to step in and deal with on behalf of their people via legislation because their people cannot be reasonably taught to protect themselves.
inigyou 5 hours ago [-]
Protect themselves from what?
inigyou 5 hours ago [-]
If it wasn't scanning your own network or using all of your bandwidth, would you still consider it evil?
scottydelta 17 hours ago [-]
After getting tired of ads on my PAID smart TV, 6 months ago I started building a casting device using raspberry pi for myself. A couple of months later one of my friends who is an AV technician ended up using it at the largest convention venue in Barcelona to play content on loop, here's a video of that: https://www.youtube.com/shorts/FF3I9EOs4AA.
Fast forward to last month, now I have started selling these in Barcelona, Spain where I am based out of and branched it into three use cases: digital signage, casting, and a portable computer for presentations at events. Here is the link with features: https://soljacast.com
emacdona 17 hours ago [-]
Clicked on the link, ready to buy one. “Contact sales”. Ew. No thanks.
scottydelta 17 hours ago [-]
We are literally new and only available in Barcelona at the moment which I mentioned in my comment as well. Not sure what's eww about that?
0manrho 16 hours ago [-]
I believe they're referring to the friction point of this company/website not publicly listing a price. That's a huge barrier/red flag to a lot of people. Myself included. Last thing I want to do is waste time bouncing emails back and forth between sales just to figure out if the price range is even remotely in my wheelhouse.
However, if your target is B2B (Business to Business) as opposed to B2C/D2C (Business to Client/Direct to Client) and you're selling the install plus enterprise support, then the sales thing makes way more sense, and is more expected/palatable for B2B type customers than your everyday consumers, so depends on who you're targeting.
scottydelta 14 hours ago [-]
We are working on figuring out payments, logistics, hardware compliance (different countries have different requirements), state-level tax handling, customs clearance, etc. for D2C.
Also right now we are focusing on B2B here in Spain like you guessed, and once we have the other things figured out, we will start shipping to the US and Europe. And after that we plan on rolling out to the rest of the countries.
emacdona 17 hours ago [-]
Sorry, knee jerk reaction any time I see “contact sales” instead of a price.
scottydelta 17 hours ago [-]
No worries. If you message me via the contact form or chat support on the website, I will try my best to provide you with one. The more feedback I can get, the better.
Thanks for liking my product enough to want to buy it right away :)
crote 15 hours ago [-]
Your device seems to be an off-the-shelf Raspberry Pi running custom software. Have you considered making the platform available in a BYOD form, either for fulltime use or for evaluation?
scottydelta 14 hours ago [-]
Yes, we're using an off-the-shelf Raspberry Pi for v1. We are working on figuring out a custom board for v2, because we can't scale with Raspberry Pi as a dependency, especially with RPi prices constantly rising due to the RAM shortage.
Also, we want to test our OS extensively before we release it to be used with a BYOD model. We are launching soon and after that we will try to offer BYOD model as well.
If you are interested in trying it out and helping me in evaluation, please reach out to me via email on my HN profile. Thank you
cryptoegorophy 15 hours ago [-]
Sales friction is how you lose sales. Make your website one click purchase product page. One button - apply pay, customer pays with preset shipping and then you handle everything from there.
scottydelta 14 hours ago [-]
Trust me, I really wish it were that easy. We're based out of Spain, so to sell in the US (or other countries) we either need to figure out assembly of the device there, or we need to solve cross-border payments, logistics, customs clearance, tax remittance to individual states, and hardware compliance. That said, we're working hard on all of it and plan to go D2C as soon as possible.
throwawsy7273 6 hours ago [-]
I haven't used them myself, but it seems that services such as paddle.com takes care of the payment and tax compliance. There are probably similar sevices for logistics as well.
scottydelta 5 hours ago [-]
The thing is majority platforms like paddle.com don't supoort hardware products. I was looking at fastspring as well but hit the same wall. I will still try reaching out to paddle.com support to see if they will allow it. Thank you for the suggestion.
crooked-v 13 hours ago [-]
The "eww" part is that normally, anytime you see "talk to us for a price", that means someone is charging an absurdly high amount for the good or service.
scottydelta 13 hours ago [-]
I see, the thing is we are very new and plan on launching soon. We are still trying to figure out our B2C/D2C pricing.
TiredOfLife 10 hours ago [-]
“contact sales” literally means expensive shitty product.
sajithdilshan 15 hours ago [-]
your product looks cool, but why do I need to contact sales to buy that device? can't you just open like a shopify shop and redirect end customers to that? Also showing the retail price on the page would be a plus one
scottydelta 14 hours ago [-]
Thank you for your kind words. I am pasting one of the comments I made on this thread regarding challenges with online sales at the moment:
> Trust me, I really wish it were that easy. We're based out of Spain, so to sell in the US (or other countries) we either need to figure out assembly of the device there, or we need to solve cross-border payments, logistics, customs clearance, tax remittance to individual states, and hardware compliance. That said, we're working hard on all of it and plan to go D2C as soon as possible.
For the pricing part, I am still trying to figure out the pricing for retail consumers. It was relatively easier to do for B2B but for retail, there are a lot of factors and moving parts such as import duties, taxes, shipping etc.
matheusmoreira 19 hours ago [-]
That reminds me, I need to configure VLANs in my router so that all my trusted computers are isolated from all the other garbage that makes it into the network.
__turbobrew__ 9 hours ago [-]
Doesn’t help when the garbage starts proxying illegal traffic through your home ISP.
inigyou 5 hours ago [-]
What happens then?
russdill 16 hours ago [-]
Seems like a motivation to switch to using a VPN for such untrusted devices that still require internet access.
ur-whale 17 hours ago [-]
Mmmh, I've always wondered ... as much as VLAN's are a very useful tools to - for example - route two separate LAN's traffic through a shared physical link ... are they any good when it come to security?
I mean, I don't believe VLAN's were designed with security as a goal, and I wonder how "strong" the virtual wall between two VLAN's actually is?
Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physical connection where packets from both VLANs happen to travel?
Just wondering.
inigyou 5 hours ago [-]
A VLAN is a virtual LAN. having two VLANs is like having two LANs but without as much duplicated wiring. It's quite well-supported and reliable.
You usually want to interconnect them at one central point, usually a router, and enforce a security policy there.
rcoder 17 hours ago [-]
Depends on your networking setup. A good switch will simply refuse to route packets between clients on different VLANs, and hide the existence of the tags that determine which VLAN a host is on.
A bad switch or router (which almost certainly includes a ton of crappy home APs and routers, compromised by the same actors who ship these devices) could let clients see VLAN tags and ignore them.
And an Ethernet “hub” does no filtering at all.
rcoder 17 hours ago [-]
Also: if you need a streaming box to see your AirPlay or UPnP devices for “casting” it necessarily has to be on the same VLAN as the devices it’s connecting to. Sonos speakers have this problem when subject to client isolation setups based on VLANs or switch-level packet filters.
And any kind of multicast (used for local service discovery and media streaming) has the same limitations.
xorcist 16 hours ago [-]
Network switches typically aren't known for their outstanding security record, but the vlan tags themselves are trivial and should be hard to mess up. Should someone hack your switch all bets are off, but as long as you don't have management accessible in-band you should be fine. Security problems are more likely to stem from bad configuration.
> Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physical connection where packets from both VLANs happen to travel?
That would be an exceptionally weird configuration. If a device "sits on VLAN1" that typically means that it's on an "untagged" port where only VLAN1 traffic is allowed. Ports that carry multiple VLANs are "tagged" ports and you normally wouldn't say they "sit" on any specific VLAN, precisely because that port carries tagged traffic for multiple VLANs. It's at best an irregular use of the terminology but likely a misunderstanding somewhere.
ahahs 17 hours ago [-]
this is a good question, i asked claude sonnet 5 and the answer is too big and complex for me to type out on mobile. but long story short, you absolutely need separate VLANs and Firewalls in conjuction to secure traffic between networks
matheusmoreira 17 hours ago [-]
Yeah, I've been using Claude to help me secure my home network. I applied to Anthropic's cyber program and got accepted despite being a hobbyist. I'm not very good at networks so I'm gonna try to make the most of it.
Really wish I could point Mythos at my router and just loop it until my router becomes literally unhackable.
TylerE 16 hours ago [-]
Making your router unhackable is trivial. Just pull the AC cord. You didn't specify that it had to be useable.
It's not just one device line; Have a look at the list maintained by the proxy tracking service Synthient, which tracks streaming boxes, digital picture frames and other IoT devices that have been known to bundle residential proxy software, among other malicious apps. They currently track almost 1,000 different makes and model numbers.
This is why Google/Meta is pushing for "age verification".
1. They want more as targeting data on you
2. They want to reduce bot clicks
It's an unholy alliance with governments who want to know who writes what online.
inigyou 4 hours ago [-]
I'll take residential proxies over mass surveillance any day. It seems surveillance will always expand unless countered.
PufPufPuf 18 hours ago [-]
My "streaming device" of choice, ThinkCentre Tiny with Linux, always feels validated with news like these. It fits behind a TV, you can get it second hand for around $40 and depending on model it can even act as a retro game console as well.
CrimsonCape 16 hours ago [-]
Is there a good TV UI OS that runs desktop youtube under the hood for ad blocking?
PufPufPuf 7 hours ago [-]
I use the VacuumTube app (https://flathub.org/en/apps/rocks.shy.VacuumTube), which has ad block, sponsor block, and some more advanced settings! You can use GNOME with scaled up UI or KDE Bigscreen (recently resurrected) for the DE.
jojobas 12 hours ago [-]
There is Kodi Youtube plugin that takes a developer token and is then ad-free.
yumraj 20 hours ago [-]
Any way to identify or block these proxy and ad click services in the router? Say a Ubiquiti or even pfsense?
I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.
Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?
My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.
thothless 12 hours ago [-]
roku is sniffing your farts. and reading your texts/emails.
Got myself a mi box with a custom launcher. Way better than any other Smart TV out there. Unless there's a smart tv that does not show ads right on the fing front page.
Anyway, the box is powerful enough to do several things. You can install a IP tv if you want. If you don't, you still have a pretty good media center (you can hook up an external hd on it)
aucisson_masque 10 hours ago [-]
The Xiaomi box also send lots of data to Xiaomi server but also ads/tracking network.
I switched to a Google box, this has no bloatware and this way I get tracked only by one company.
Scoundreller 11 hours ago [-]
Though I do then wonder about some of the iptv apps even the ones provided through paid subscriptions but that’s already on the dark side; but not as dark as these “buy once” 1000s of pirated channels devices
wao0uuno 9 hours ago [-]
If you have a Raspberry Pi 5 gathering dust somewhere and need a new streaming box then try LibreELEC. It decodes 4k content just fine. It has HDMI CEC. It can stream from local server or play directly from attached storage. There are no ads or tracking/profiling. It can play YouTube without ads but there is no support for Netflix, Apple TV or similar streaming services.
neves 9 hours ago [-]
I really don't mind anymore. My Roku stick is now owned by extreme right Fox Corporation. Chinese ad click network are petty villain compared.
m3047 21 hours ago [-]
Brazil. Last year I effectively blocked Brazil for a while. Ultimately I settled on three possibilities for the traffic I was seeing:
01: DDOS
10: Residential proxies
11: Somebody DDOSing residential proxies
drdexebtjl 21 hours ago [-]
I can’t prove it, but I live in Brazil and after getting a smart TV from LG, I started receiving challenges across all Google services, indicating they received bot traffic from my network. I only used apps from streaming services I actually paid for.
I suspect these TVs either come with residential proxies set up from the factory, or they have such poor security that they’re instantly hacked. Either way, TV manufacturers (including reputable ones like LG) are to blame.
mikestew 19 hours ago [-]
There have been articles lately about the residential proxies loaded in apps for LG TVs. My LG has never seen a network connection, so I’m fuzzy on details.
inigyou 5 hours ago [-]
LG has been in the news just this week for a whole lot of shady practices, which cast light on their other shady practices. Yes, residential proxying is one of them.
I don't think residential proxying is all that shady since groups like Cloudflare have made it a necessity. However, having it out-of-the-box on a name-brand device is extremely shady.
utopiah 20 hours ago [-]
I bet this is much broader than we all realized because just earlier today I was reading on https://gist.github.com/probonopd/3ad6b7777caea1503f00d5fe77... in order to tinker with a cheap (like really cheap) Android video projector : "Device: Magcubic HY300 Pro Android Projector (ui_Veng.projector) Issue: Device was being used as a residential proxy node without consent, causing thousands of suspicious DNS requests and bandwidth usage." linked in there just few months ago.
It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique.
An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.
LetsGetTechnicl 17 hours ago [-]
Oh wow that's the same projector I have. Would be really cool to install a custom build on it, but for now I just have an Apple TV connected to it.
utopiah 9 hours ago [-]
You can already adb connect in dev mode then install .apks, e.g. termux, Fennec and change some settings. It does seem rootable but I didn't try.
tomaskafka 16 hours ago [-]
At this point China probably has a botnet that can be turned on with a few deploys, and spans a majority of homes in US and RU (and thus is unblockable without disconnecting half of voters from the internet). Ready to attack the infrastructure.
bashtoni 16 hours ago [-]
I don't know where you get the idea this is a nation state attack.
The devices are used to sell proxy services and scam advertisers. This doesn't even need particularly large organised crime. It would certainly be easier than large scale illicit drug importation and retail, which is happening all the time.
Could China exploit these streaming sticks if it wanted to? Maybe, but no more than any other nation.
tossingafterxyz 15 hours ago [-]
Not necessarily correlated to this, but my perception is that china is generally ok with many types of crime as long as it’s not perpetrated on its citizens / aimed at foreigners (IP theft / counterfeit goods / cyber crime etc). However, I also think the state largely has a good sense of the actor or players and is perfectly capable of exerting force or coercing them to their cause at will.
AlexandrB 54 minutes ago [-]
This is only slightly more malicious than the software "Smart TVs" already ship with.
stronglikedan 20 hours ago [-]
> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
You had me at "But"! ::swoon::
hn_submit 19 hours ago [-]
I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.
Instead they're banning stuff willy nilly left and right without really solving the problem.
But there's good stuff coming out of China as well. I recently bought a cheap e-reader which has no WiFi or internet connection and it works stellar. And I bought some cheap Chinese sport cams which also lack internet and work great.
autoexec 18 hours ago [-]
> I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.
Personally, I think every other country should ban any product made by Google, Amazon, and Microsoft since they all spy on the users of their products too.
hn_submit 18 hours ago [-]
I've suggested legislation which would ban the sale of customer information to third-parties.
These companies could use the info they gather on customers for their own use but they cannot (re)sell it to anyone, not even the government. The reason being that the information eventually ends up abroad after which you lose all control over it.
RajT88 20 hours ago [-]
A pirate TV box from China presents a security threat?
This is my surprised face.
inigyou 5 hours ago [-]
No actual security threat was stated in TFA though. Only revenue threats.
theendisney 11 hours ago [-]
Long ago I ponder giving away free computers but an ethical formula is really hard. It seemed profit starts to scale exponentialy just beyond the line.
(Acepable would be something like 1TB worth of gamedemos)
Doohickey-d 17 hours ago [-]
Krebs' blog is nice, but quite often it's just re-reporting stuff from somewhere else:
“as part of a sprawling operation that seeks to defraud online merchants and advertising networks.”
Oh no! Not the advertising networks!
ColdStream 15 hours ago [-]
Alternatively, if you are going to do some questionable things, just buy loads of these things and create a hundred back doors on the network to increase the noise.
Sounds good in theory but in practice, computers are good at sorting this stuff out. Kind of why they are so popular.
dxxvi 15 hours ago [-]
Ah, got it. Those devices are like computer virus which don't need a computer to live on.They can make DDOS attacks if they want to. So, buying these devices at a cheap price is like renting out your IP address and your Internet connection.
BigTTYGothGF 15 hours ago [-]
> these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks.
Every cloud has a silver lining.
giantg2 21 hours ago [-]
So where can I get an actual privacy focused streaming box, even if the apps (Neflix etc) running on it are not?
ghostly_s 20 hours ago [-]
These are not "streaming boxes" in the sense you are talking about. Their appeal is that they come preloaded with chinese pirate streaming apps. Traditional streaming boxes - Apple TV, Fire stick, Roku - are not affected by this, though if you want privacy-focused Apple TV is the only remaining contender, and with Apple's continued descent into advertising vendor I'd guess that one is not long for this world, either.
giantg2 20 hours ago [-]
My understanding is that Roku bypasses DNS blocking with hardcoded tables so it can report back on various data they track on you.
autoexec 17 hours ago [-]
Roku collects an insane amount of data on users. Basically everything that they can get their hands on
> Roughly twice per second, a Roku TV captures video “snapshots” in 4K resolution. These snapshots are scanned through a database of content and ads, which allows the exposure to be matched to what is airing. For example, if a streamer is watching an NFL football game and sees an ad for a hard seltzer, Roku’s ACR will know that the ad has appeared on the TV being watched at that time. In this way, the content on screen is automatically recognized, as the technology’s name indicates. The data then is paired with user profile data to link the account watching with the content they’re watching. https://advertising.roku.com/learn/resources/acr-the-future-...
timbit42 20 hours ago [-]
Can you monitor its traffic and block by IP?
mikestew 19 hours ago [-]
I’m sure you could. At what point do you just rip out the thing that is trying so hard to work around your control of your network? An Apple TV doesn’t cost that much.
kube-system 18 hours ago [-]
The door is slowly closing on all of these blocking schemes by moving ad content to the same domains as the primary content.
This is already a common feature for analytics toolkits.
giantg2 19 hours ago [-]
I probably could, but haven't done so yet.
MattTheRealOne 21 hours ago [-]
Apple TV is currently the best balance of privacy and convenience. The only way to get more private is using a PC, but that limits the resolution for most streaming services to 720p or 1080p.
theshrike79 8 hours ago [-]
And longevity. It just keeps getting updated tvOS versions and every provider's apps keep working - unlike on random Android TVs that just fall out of support.
I'm on my second one and I've owned them since the first version. My current one is the first generation 4k that's ... seven years old? Still works like new.
PcChip 21 hours ago [-]
I assume apple TV doesn’t do malicious things like this, and we love the interface and it “just works” with HDR
noboostforyou 20 hours ago [-]
Besides setting up your own device, Apple TV would be the best bet from any of the large manufacturers.
cogman10 21 hours ago [-]
I'm increasingly being convinced the only way to do that is you do a media pc nuc. The problem, of course, is you probably won't have the netflix app. It's painful to setup such a box to stream from various services.
dwaltrip 8 minutes ago [-]
What about just using the Netflix desktop website? Or does that limit the resolution?
Tepix 20 hours ago [-]
What's wrong with Apple TV? It runs VLC if you want to stream something from your NAS.
giantg2 19 hours ago [-]
I tried to look at setting up an stripped down privacy-focused Android based box for Netflix, but ran into issues. Seems like you need to be spied on to run Netflix.
mbmbn 21 hours ago [-]
I tried going that route, but most apps for streaming are Android. And that was only one of the issues.
It was a rabbit hole and in the end I got back using my NVIDIA Shield. This is about 10 years now, but it’s actually still the best option.
drnick1 19 hours ago [-]
If you want actual privacy (rather than promises from Apple or Google), what you need is a mini-PC running Linux with the Plasma Bigscreen DE. You then use a Web browser rather than invasive "apps" for your streaming. For Youtube, there is VacuumTube (an improved Youtube Leanback client). The main limitation is capped resolution on some commercial streaming services. I believe Windows does not have that restriction, so a VM could presumably be used for streaming (I have not tried).
19 hours ago [-]
knowaveragejoe 18 hours ago [-]
The Onn TV devices from walmart seem fine, baseline google tracking not-withstanding... but no residential proxy or botnet participation without you knowing! You can just block them at the router and stream content locally.
Pxtl 19 hours ago [-]
kodi on an rpi5?
haunter 20 hours ago [-]
[dead]
estebarb 13 hours ago [-]
Oh wow, even scammers care about usability and their employees' well-being. What's the excuse for bad UX in internal company software?
a-dub 19 hours ago [-]
it's just like a phone. don't buy a crappy one with firmware of unknown provenance. make sure the one you do buy has an active and effective effort that you trust that ships timely security fixes.
perpetuallunch 13 hours ago [-]
> rent the user’s Internet connection out to strangers.
Harm to the user: none^
> spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks
Harm to the user: none^
Cost to the dodgy service provides: none
Government action to prevent continued dodgy services: none^
This is why internet securityg doomers have a hard time selling their story. Changing behaviour has an upfront, immediate, cost. Not changing it doesn't.
^close enough
charonn0 12 hours ago [-]
>> rent the user’s Internet connection out to strangers.
> Harm to the user: none^
Well, they are losing some of their bandwidth. They might not notice, but something which is rightfully theirs is being taken without consent.
perpetuallunch 7 hours ago [-]
If they don't notice, and they're on an unlimited data plan, or the usage is such that it doesn't result in exceeding their data cap, what argument is there that harm occurred?
Hasz 20 hours ago [-]
Hey that’s pretty smart! Fradulent, but very smart. I was honestly expecting botnet.
I expect many cameras of “dubious” origin are used for similar tasks, same with most “smart” devices with sufficient horsepower.
zeroq 16 hours ago [-]
tangent thought experiment
So you bought that top of the line security-as-a-product thingy you can stick in your rack and it will make sure that your network is impenetrable? You know, like those CISCO bricks everyone major company is buying.
So have you took an extra precautions to make sure that the firmware on the device is pristine? Do you know anyone who ever touched these devices who actually did?
Do you see the problem?
jojobas 11 hours ago [-]
Cisco bricks leave the factory as pristine as they can be. An intercept sort of attack is possible, but involve quite some effort and risk.
These sticks leave the factory with malware pre-flashed, the postman brings them to your door with zero risk for the beneficiary.
joeisnotjane 8 hours ago [-]
Ah, it's about "China, China.."
Preparing casus belli.. first, open weights LLM which are "not secure", now "TV sticks"..
Oh joes and janes, who will put finally some sense into you..
Ikatza 8 hours ago [-]
Ah, yes, the great TV sticks war of 2028. We'll tell the stories.
joeisnotjane 7 hours ago [-]
It is about gradually, but constantly, creating the image of an "evil adversary".. Venome drop after venome drop..
China is not doing that as far as I know. Neither Russia did it before the war, though you were claiming the contrary (I know, since I live in the west and could compare news from both sides, being a native Russian speaker).
mring33621 18 hours ago [-]
Using low code tools to build click fraud logic FTW!
16 hours ago [-]
rawgabbit 18 hours ago [-]
What happens when you stick this malware into your windows PC? The PC is now an accomplice to fraud?
crote 17 hours ago [-]
LG televisions and monitors spy on their users and install unwanted software. Half of all smart tvs are running "residential proxy" malware. Google is banning sideloading but happily hosting apps using the Bright SDK.
Sorry, but "your tv stick does ad fraud" is just about the most innocent thing I've seen in a while. Everyone in this market is doing the shadiest shit you can imagine. There are no good brands left, you just get to pick what logo your Malware Entertainment Device has.
inigyou 5 hours ago [-]
Is it even really malware if it's harming advertising networks and not you?
stuaxo 19 hours ago [-]
How hard is it to get something else on these ?
Looks like cheap small computer with a remote control.
kazinator 20 hours ago [-]
> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads ...
Compromised (or malicious from the factory) devices being recruited into bot farms for click fraud is ... a groundbreaking discovery in 2026?
> on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
To hell with AI-generated websites and advertising networks.
Say, where can I get the most effective malicious TV stick for click-frauding the fuck out of that shit? I will take fifteen! :)
snickerbockers 19 hours ago [-]
I'm imaging a largescale distributed project like folding@home except instead of doing scientific research everybody is working together to fuck with advertisers, tracking cookies, etc.
cryo32 21 hours ago [-]
A better solution is just leech the content and stick it on a generic USB flash stick.
harvey9 19 hours ago [-]
These are popular for illegal live sports streams.
cryo32 17 hours ago [-]
I just go down the pub.
munk-a 16 hours ago [-]
Read this:
Use a computer - you actually control the content that way.
codedokode 21 hours ago [-]
I do not see problems with fake ad clicks and have no sympathy for ad companies.
Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.
What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.
How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:
- the user must be able to re-flash firmware with their own code.
- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.
- any telemetry or data collection, or updates must be opt-in only and disabled by default.
- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.
Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.
Thrymr 21 hours ago [-]
> I do not see problems with fake ad clicks and have no sympathy for ad companies.
I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.
jrm4 20 hours ago [-]
Sure. And you'll quite literally never be able to get any meaningful reduction in this practice unless you attack it at the level of big, publically known companies; the warnings about these local dinky things I suppose are not harmful and help individuals a bit -- but I'm concerned they give the entirely false impression that the extremely similar stuff coming from the big boys is definitely a-ok.
Dylan16807 18 hours ago [-]
Reduction in what practice? Are there big companies doing ad fraud?
I want big companies to stop spying on me, which is a completely different issue.
Cider9986 20 hours ago [-]
>What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information.
Most Americans are at a greater threat of harm from their own government that a foreign one. What worries me is all the mass surveillance done by big tech which bypasses the 4th Amendment and gives the government Americans data without a warrant.
There's already a front door with the adtech for US alphabet boys. This could likely be collected by others as well. We saw this happened where foreign hackers exploited a backdoor designed for American authorities[1]. This is what experts are referring to when they say there's no backdoor only for me.
This could be compelling to politicians, though, and would certainly be a step in the right direction.
>- any telemetry or data collection, or updates must be opt-in only and disabled by default
This should be how it is for everything foreign made software or not. Would be very hard to get done with the big tech lobby in the US.
In some areas GPS is spoofed and the displayed location is wrong. If, for example, a "smart" car gets a task from its manufacturer to film some secret object, it would fail if it relied only on GPS and did not use cell towers and WiFi points for determining its location. So knowing their location determines whether the mission would fail or succeed. So foreign devices should not be allowed to collect such information.
bee_rider 20 hours ago [-]
I think that might have been semi-sarcastic. I mean, there are lots of reasons to do this sort of thing, some are bad, some are not so bad, most are not war.
BoppreH 21 hours ago [-]
> a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed
Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys.
Could it be used for missiles? Sure. Is it obviously the intention? No.
> If Location Services is on, your device will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers to Apple to augment Apple's crowd-sourced database of Wi-Fi hotspot and cell tower locations.
> When Location Accuracy is on, Google periodically collects information about the locations of wireless signals and sensors observed by your device to crowdsource location estimates. This helps everyone find locations better.
Not to mention truly crowd-sourced databases like wigle.net.
codedokode 20 hours ago [-]
They should ask the permission from device owner and local government before collecting the data.
aeturnum 20 hours ago [-]
They do ask the device owner - if you review the location services description on android[1] you will see they explicitly say they collect this information from your device. I strongly disagree that they need to get government permission for this - they are simply recording signals that reach the device, akin to making notes about what kinds of cars you see. This is not a thing a government should have control over people doing and not a thing that should be registered with the governement.
In the article you refer to, I see no mention of asking user's permission. However, I remember, when using an old version of Android, there indeed was a popup nagging me to allow sharing location data with Google every time I enabled GPS. Very annoying, makes you want to never enable GPS in the first place.
Regarding the government, the problem is that many people do not fully understand the mechanism of collecting the data. I remember the case when members of US military disclosed the location of secret objects through fitness tracker app. And they were probably smarter than average smartphone user. Obviously it would be better if enabling GPS required an approval from their commander.
aeturnum 16 hours ago [-]
I suppose they don't "ask you" in the same way that gmail never presents the user with a dialog explaining that gmail needs to store their emails in order to provide their email service. Instead they explain how the location service works and you can decide if you want to enable or disable it.
I'll agree that militaries would prefer their soldiers to not to dumb things - but I don't agree that it's 'obviously' best if people needed permission to enable GPS! If that's the case depends a lot on which soldier is enabling the GPS and their relation to me. In general I would say that government control of people recording and distributing their observations is associated with the most authoritarian governments and by claiming we should get government permission you appear to be aligning yourself with an authoritarian approach to data controls.
codedokode 20 hours ago [-]
Should Google ask permission from the device owner, and from the local government before collecting the data? I heard a certain foreign mobile app was banned in US for doing less than that.
Tangurena2 17 hours ago [-]
> What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information.
The Snowden leaks showed that the US was already doing this. I'm certain that everything purchased is already infected with something. Most likely bugs and bad security.
arjie 20 hours ago [-]
Oh this was a failed device that Mozilla offered. I had a couple back in the day. It was called Matchstick. Sick t shirts. Basically an OSS chromecast.
IncreasePosts 21 hours ago [-]
Fake ad clicks cost the advertiser money, not the ad company.
Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)
mcphage 21 hours ago [-]
> Fake ad clicks cost the advertiser money, not the ad company.
It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.
codedokode 20 hours ago [-]
Good products do not need much advertising. For example, when buying DRAM, I compare the specification and prices and do not look at the advertisement.
mcphage 21 hours ago [-]
> I do not see problems with fake ad clicks and have no sympathy for ad companies.
Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.
exe34 21 hours ago [-]
My pinenote runs the original spyware image - I don't have a problem with Winnie the Pooh reading along with me.
autoexec 18 hours ago [-]
> Yeah, it's like—a cheap streaming stick AND it poisons the advertising well?
Keep in mind that it's your IP and identity associated with those clicks and anything else criminals decide to do with your IP address. That means you're identity is being linked to things you may or not want to be known as being interested/involved in. The ads your TV stick clicks on can cause data brokers to include your name in lists of people who are heavily into drugs, have mental disorders, belong to certain religions or political parties, etc. All of that can come back to haunt you later.
Depending on what other activity your connection is used for as a proxy it can also get you in trouble with the police or with your ISP.
inigyou 5 hours ago [-]
So you're saying it's going to weaken the presumption that an IP can be easily tracked to an individual? Even better!
autoexec 18 minutes ago [-]
No, your IP will be easily tracked to you as an individual. You'll just suffer the consequences of whatever your streaming stick does with your IP. If your stick clicks a bunch of ads for fast food your heath insurance bill goes up because their algorithm thinks you're a higher risk. If your streaming stick clicks a bunch of ads for high end luxury goods, online stores start charging you more than they charge your neighbor for the same items because their algorithms think you have money to burn. Your streaming stick clicks a bunch of ads for addiction recovery services, you don't get a call back for the next job you apply to because the HR department paid a data broker to run a background check looking for "red flags".
What you do on the internet has very real impacts on your life offline and it's going to happen more and more over time. AI will make it easier for companies to leverage the massive amounts of data avilable to them about you. Surveillance pricing is spreading. Consumer reputation services are spreading. Law enforcement is buying up data from data brokers. Extremists are using data brokers to decide who to target with violence.
mcphage 3 hours ago [-]
Talk about the gift that keeps on giving…
soulofmischief 19 hours ago [-]
The problem is that when you need these powers most as a citizen is when your government is least likely to allow it.
19 hours ago [-]
inigyou 5 hours ago [-]
Krebs fails to make any case for why someone wanting to watch movies and TV should give a shit.
I get that these products are personally inconvenient to Brian Krebs and his work, and to companies that make money blocking people from accessing the internet, and to companies that make money spewing ads in people's faces. So? Why should anyone care about any of those? In fact I think some people would get one of these sticks just to inconvenience the latter two groups!
jms703 15 hours ago [-]
You buy garbage, you get garbage.
You can no longer depend on resellers or to protect you. They are unphased and unaffected by selling you this garbage. No one else has a financial incentive to protect you.
Sorry if this sounds victim blamey. Don't mean it to be. Just trying to convey that we're on our own.
gxs 20 hours ago [-]
No mention of Roku
I use one but only when traveling at hotels - it’s one of the only sticks that can connect to captive WiFi networks at hotels
I’ve got barely anything on it so privacy be damned - but at this point this is why I just buy apple products
I have two apple tv’s which probably do shady things too, but I’m willing to play the probabilities and assume it’s the least bad of my options short of tinkering with flashing hardware and all that stuff that used to be fun in my teens (emphasis on used to)
giraffe_lady 21 hours ago [-]
> allowing low-skilled operators to drag blocks of code together in their editor — without any need to understand what the underlying code blocks do or how they work.
We're called engineers brian.
byterivet 15 hours ago [-]
Good job.
shevy-java 15 hours ago [-]
> they secretly rent the user’s Internet connection out to strangers
So the mafia is back.
phendrenad2 18 hours ago [-]
On the other hand, these are great little devices to root and put Linux on.
cute_boi 20 hours ago [-]
The best solution to this problem is to block GeoIP traffic and monitor bandwidth consumption on a per-domain basis. If something is sending data during the night, it becomes much easier to identify suspicious activity.
Mistletoe 21 hours ago [-]
I recently got an Apple TV 4K and have been really enjoying the ad free experience. Worth every penny. Our smart tv had turned into a Christmas tree of ads.
wewtyflakes 19 hours ago [-]
There are plenty of ads on Apple TV; huge banners right at the top of the UI, and ads that launch before you get to see the content of a show with no way to automatically disable them (you have to manually click through or just wait it out). It is infuriating (to me).
ls612 18 hours ago [-]
Apple TV the app has ads for Apple TV shows. Apple TV the device doesn’t have ads built in.
wewtyflakes 15 hours ago [-]
The TV app is baked into the device and is automatically focused if you press up too many times on the remote (and thereby triggering the large banner ads).
ocd 20 hours ago [-]
As much as I hate Apple for what they've done to the average consumer in regards to computing, it would be just impossible and dishonest to say anything other than Apple is the outright winner in streaming devices. The experience is so smooth.
trouve_search 18 hours ago [-]
The nvidia shield is pretty damn good as well, even if old at this point.
ghostly_s 20 hours ago [-]
Considering their recent decision to give up on building Apple Maps into a serious contender and instead enshittify it with ads, I don't have much faith Apple TV will be far behind.
dhosek 20 hours ago [-]
One hopes that the new CEO will realize the turn towards ads is ruining the Apple brand and pull back on that front.
inigyou 5 hours ago [-]
Ha! No company has ever reversed enshittification.
shmuli9 16 hours ago [-]
This is amazing. Kudos to the team behind it
I mean, sucks for advertisers and is utterly deceitful… but genius!
j45 21 hours ago [-]
Generally, it's advisable to create a dedicated wifi network for all potentially hostile devices.
This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.
That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.
drnick1 19 hours ago [-]
> That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home
That is not enough. You need to air gap devices that have legitimately no business communicating with anyone or anything outside the house. TVs, thermostats, and other Internet-of-Crap gadgets do not need "firmware updates." Either they work out of the box, offline or within the LAN, or they get sent back for a refund wherever they came from.
j45 3 hours ago [-]
Agreed. That usually comes as a step after getting these items on a separate SSID.
spelk 19 hours ago [-]
I don't think this would make a big difference for the threat model described in the OP? They'd still be able to use your IP Address and potentially do nefarious things through your role as an unwitting proxy.
j45 19 hours ago [-]
Using one device as a proxy is a few steps away from trying to exploit and infiltrate the other devices on your machine as well. An unwitting proxy is already crossing the line to putting a fox in the henhouse.
Limiting what outbound access devices can/can't have is an important skill to learn.
burgreblast 18 hours ago [-]
Google clutches pearls and is shocked! Shocked! That anyone would violate its policies (while it pockets 30% of the fraudulent revenue). Shocked!
And they would have caught them but those crafty criminals spoofed the user-agent. So how _could_ they know?
Pxtl 19 hours ago [-]
> major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands that bundle unofficial versions of Google’s Android operating system and are frequently marketed (via online influencers) as a way to access a broad array of streaming services and live broadcasts without a subscription.
This is why I giggle when people talk about ending Section 230 in the USA (or various international counterparts thereof).
The largest companies on Earth are happily selling hacked piracy spyware botnet garbage. Not just hosting malicious posts for free like Section 230 protects, but selling illegal physical devices and taking a cut of the profit and excusing it with a pathetic whack-a-mole moderation system. It's already illegal and the law has already failed.
Sean Parker's mistake was that he wasn't rich enough.
Laws are for poor people.
buellerbueller 18 hours ago [-]
To those who are OK with these devices: when you engage in corruption, do you have any moral standing against your politicians when they engage in corruption?
Both you, and the corrupt politicians, are eating away at the trust that underpins society. Certainly, you can argue, your bite is just a tiny one; the politician is eating the whole apple.
At the end of the day, everyone suffers from the decline of trust and casual acceptance of fraud.
bronko_nagurski 22 hours ago [-]
[dead]
defmetrix 20 hours ago [-]
I didnt know anybody bought a streaming stick anymore
yunnpp 20 hours ago [-]
And which part of "ad fraud" is the fraud? As far as I can tell, ad networks and advertisers are the fraud and they are also part of the increasing surveillance state.
Didn't know Krebs was a mainstream news puppet.
brainwad 20 hours ago [-]
It's called fraud because the ad host colludes with (or directly controls) the botnet to get lots of clicks on ads hosted on their sites, making them money at the expense of advertisers.
If you just want to spam clicks on ads you don't financially be edit from, go for it.
AlotOfReading 21 hours ago [-]
Of all the evils normally associated with visual programming languages, enabling cybercrime isn't one I've previously considered. Now that I've seen it, I'm surprised it wasn't more common before LLMs appeared.
I scanned the comments and I didn't see anyone suggesting that these companies should share any responsibility for selling these harmful products. Why is it that they seem to get a pass? Would we feel the same about giant retailers selling tainted food, or unsafe children's toys?
This is the problem with being an “everything store”. “Everything” includes a lot of things most consumers would like to be protected from, and assume they are due to the long history of retailers standing behind the products they sell. That history seems to have come to an end. They only stand behind it enough to offer a refund if there is a problem, not to ensure it’s good before selling it.
We bought a different model from Costco and it’s been rock solid. I expect I will never buy a major appliance from any other retailer as long as Costco continues to care like they do today.
Weird. You experienced failures of the manufacturer (failure to start) and the warehouse (huge scratch), and are still singing someone’s praises.
It sounds to me like the brand’s quality assurance is low and the retailer also isn’t taking care of their stock.
If I had to take three days off work to accept these deliveries, doubtless I would have a very different conclusion from yours.
I say this as a happy customer of both, though. I don't seem to have the problems others do with horrible products from Amazon, but I suspect my purchasing habits might be different as well.
That's called stinking thinking.
https://www.abc.net.au/news/2026-07-27/australian-tomatoes-l...
(edit: whoops, Choice did the SPF rating investigation. ABC just did a lot of reporting on it)
https://www.cbp.gov/newsroom/national-media-release/cbp-issu...
If Costco were circumventing the ban it'd be a pretty big deal. I couldn't google up any indications that they are, so on balance I'd say it's "possible" in the same way my winning the lottery is possible. Can't rule it out, but reasonable people should probably bet against it.
TIL: Xinjiang tomatoes are something like 15% of the global market!
China consumes 37% of the world’s tomatoes. 80% of China’s processed tomatoes are from xinjiang. Fresh tomatoes are generally grown locally, but that is true around the world.
I think that might be a bit of a strong assertion, from your article there -
"It analysed 221 processed tomato products from 39 brands, including paste, passata and diced tomato.
Twenty-two per cent of the products failed country-of-origin testing, while a further 6 per cent were flagged for further testing."
So while 28 percent is scandalous, and those companies need to face consequences, the other 72 percent seem to be genuine.
Summarising the Australian situation, taking the 4corners results into account, the following non-Chinese tomato pastes are available:
Coles (29% market share): 1 x 140g premium product in a tube (expensive with reduced market share) out of about 20 products.
Woolworths (38% market share): 1 x 140g premium product (Mutti) in a tube (expensive with reduced market share) out of about 20 products.
Aldi (10% market share): None out of about 4 products
IGA (7% market share): 5 of 16 products, being the same premium brands that Coles and Woolworths sell.
Maybe qualify my comment with "by market share and availability". The effect is that if you stand in front of an Australian supermarket shelf, every product, bar one or two in the corner, come from China. China is a proxy for Xianjing, in that sources say 80%-90% of tomato paste from China comes from Xinjiang.
Hence the assertion I made.
Market share data: https://www.accc.gov.au/system/files/supermarkets-inquiry_1....
Xianjing percentages: https://tomatonews.com/countries/china/
Eh ...
"Well-known tomato brands that passed country-of-origin testing include Mutti, SPC, Woolworths, Providore D'Italia and Annalisa. Diced tomato cans and passata from Leggo's and Coles also passed."
So here are 4 tomato pastes in woolworths that would seem to pass the test of not being from China and not being liars, just from a quick search (and I have seen all these in my local) -
https://www.woolworths.com.au/shop/productdetails/290303/mut... https://www.woolworths.com.au/shop/productdetails/218066/mut... https://www.woolworths.com.au/shop/productdetails/901431/mac... https://www.woolworths.com.au/shop/productdetails/150875/pro...
I usually buy Mutti stuff because it's low-ish salt, and that claims to come from Italy and wasn't implicated in the report here. And while I understand those are at the 'premium' end, it's not like it's one product on the end of the shelf either.
It's true that "Leggo" occupies a lot of the shelf space and a lot of the cheaper 'own brand' stuff is labelled as coming from China. And coles appears to be in a weirder/worse spot that woollies, with only Providore being Italian and two brands of turkish tomato paste, which is interesting.
It's sad that I can't find an Australian tomato paste that isn't a liar.
So I'm still not fully on board with "nearly every", OTOH thanks for the further information. I shall continue to try to avoid these products!
Harm to the end user: none^
Benefits to the end user: more affordable tomato paste
Government action to prevent slave labour products entering Australia: none^
^close enough.
The ABC is a know, as in they don't even try to pretend propriety, propaganda outlet of the Australia Albanese federal Government.
I'm not saying this is definitely propaganda, but there's a non-zero chance it is.
The Albanese government has been very open about attacking industry.
No propaganda - lack of validation, evidence and trust
We’re specifically taking about merchants that have a super shady online presence. They will basically sell you anything and everything and don’t care if it harms you.
The ones mentioned (Amazon, Best Buy, New Egg), it’s going to be hard to argue they vet (or care about vetting) the digital products they sell. You might as well throw Walmart into group too, their online offerings have gotten super sketchy if you really do into it.
fixed fee membership also means a very stable revenue stream and they can take the time to do this, while other places like newegg are herding 3rd parties to get cuts of ever cheaper 3rd party crap
For example: this is a minor annoyance, but comes readily to mind.
https://www.costco.com/p/-/orgain-organic-protein-and-superf...
The problem is labeling conventions leading to inaccurate assumptions of what's even IN that "protein powder"...
you would think the protein, being the largest in print, is the primary ingredient but no. A serving is 51grams, and the protein makes up 21grams of that serving: less than half, that's not a 'protein powder' if the primary ingredient isn't protein.
It should be labeled "SUPERFOODS with protein" not the other way around.
There have been other things similar in scope less readily recalled. It may seem minor to some... but labeling accuracy and transparency is something we had to fight for collectively.
However, this is plant-based protein, not pure way isolate. A plant-based protein powder from mung beans for example isn't going to be 100% protein. Chickpea powder contains roughly 20% protein.
So I don't know if that helps at all, but it doesn't seem as bad as you and you might be suggesting.
And most of Costco's sku's are food, clothing, housewares, bulk consumables, and such - vastly easier to test and vet than computer & internet-connected electronics.
The above actually happened to me. That's what online retailers were like before Amazon's reach properly extended here. That's also the main value proposition for these retailers for me.
Also, online retailers are far more likely to accept returns compared to regular stores. If you get a bad product from a regular store you're often just screwed.
Later, when you want to try the return, a black box algorithm asseses your transactional value to Amazon and decides whether your concerns are worth attending and to what degree.
Maybe that really is better than whatever you were used to in your own market, but it's a profound regression on the traditional retail experience for most of us here.
30 years ago a friend of mine did the mold for a lawn mower. They put an engine on it and it ran for 120 hours before the deck failed. It took 7 more tries until the deck failed after 80 hours. Commercial mowers are expected to run over 1000 hours.
It is in rough shape, but it still cuts grass perfectly fine.
I have a wippersnipper from before I was born which runs perfectly today. It was left out laying sideways in the rain for about a month. Quick clean and a new plug and it was going again.
I'm sure the electric devices can run a long time, but when they fail, they tend to be not repairable.
Mine's a fancy-pants Stihl battery mower, but it works quite well and has been doing so without problem since I bought it ~4 years ago. The other battery stuff from the same brand (trimmer, chainsaw, kombi-tool) have the same story.
For instance, the MS182 [0] is a $270, 2.2cu in saw with a 16" bar listed "For homeowners and light duty work".
Meanwhile, the MS201 [1] is $1100 for a 2.1cu in saw with a 16" bar listed as "The lightest professional gas chainsaw from STIHL Perfect for delimbing work in forestry".
Service interval on the 201 will be much longer, and it's expected to last longer but is priced accordingly. I ended up having to buy one of their homeowner grade saws 10 years ago when I was up in the mountains and my saw died, that was all that was available locally. I'm certainly not a professional, but at the time my primary heat source was wood and I had always used the stihl pro-grade saws. However, that cheap stihl was an absolute piece of junk, it was half wore out after cutting 2 cords of firewood that first time. Terrible ergonomics and poor power to boot, even after reserving the saw for light-duty work it only lasted 2 years and was miserable to start and run the entire time.
At least they explicitly say that they are for light duty though, a less honest company would market everything as pro-grade. But don't just buy the name, while they make good quality products they also sell cheap crap under the same name. It also isn't that clear in a retail store besides the price which ones are the homeowner grade saws.
[0] https://www.stihlusa.com/en/p/chainsaws-ms-182-gasoline-chai... [1] https://www.stihlusa.com/en/p/chainsaws-ms-201-gasoline-chai...
What matters is the amortized cost per year, I think - more expensive up front but cheaper in the long run.
My battery mower is quiet enough that I don't feel terribly rude mowing at twilight.
Hell, there's a section of comments that would probably going "hey, RELAX guy" because it's not US companies doing this. For any American companies that do this though, sure - block/suspend/prosecute.
Or if I open up a gas station and allow any company without oversight to sell "supplements" through my shelves and cops arrest me for selling heroin, I don't get a free pass.
Why should amazon or Walmart get a free pass just because they sell more items?
You have to be able to show damages you incurred and assign a dollar value to them to sue people.
That doesn’t work at all for a something that sells your bandwidth to a proxy service. People wouldn’t even be aware that it was happening they weren’t told.
Not legal advice.
(It would surprise me greatly if we as a society let these gadgets be sold openly from here on.)
The cybercrime raids happen when they run into someone who looks like a hacker and has a lot of computers.
While there would be oversight, it is highly unlikely that a person opening a home improvement store would perform any meaningful safety testing. They simply would not be qualified. The oversight would lay in selling certified products, pulling recalled products off the shelf, and (perhaps) removing products if there is a reason to suspect safety issues.
Now consider streaming sticks. There are safety standards for the physical device but, to my knowledge, there are no such standards for the software itself. Heck, there aren't even standards for the engineers who work on the software. One can make highly prejudiced decisions based upon the country of origin. Perhaps there are even good reasons to avoid products from certain countries. Yet the lack of standards also means that products from trustworthy sources can be suspect, since all it takes is a management decision to change things.
Its incredibly obvious to anyone applying any thought at all to this that its a malicious to sell a product that labels itself as a TV streaming stick which is in fact a paid for relay server with the money made from providing the internet connection to a random third party unrelated to the person who bought the thing without ever telling the customer.
You already answered it: block it from being sold.
1) Make Amazon responsible for the products they are selling. 2) Introduce a law banning malware tv sticks 3) Sue Amazon for a percentage of their yearly revenue when caught violating it 4) Amazon will finally start caring and do some kind of review on the crap they sell.
You don't want to penalize someone selling their Xbox or lawnmower on Ebay but you want to stop what is going on here. A place like Etsy where people are selling their crafts is an interesting edge case but I think they should probably be a little regulated.
That's the biggest problem with any device that updates.
Yea, this will work for the moment and the seller will be covered in the sense that "well, it wasn't infected when we sold it".
US retailers can be told they can't sell it here. If you buy it outside of that, well that is buyer beware, but 99% of people aren't buying things from Alibaba or ordering from some random foreign store, they are buying them off US Amazon, Walmart, big box retailers, etc. You don't have to ban things consumer level to deal with 99% of it, you just gotta tell big corporations no and stop dismissing any ideas that put responsibility or liability on big business.
And the "retailer" on record is of course not a real company. They'll just pay some third-party to file a bunch of paperwork in Delaware, pay the $110 fee, and let it go bust if anyone tries to investigate it or make it liable.
While it's great we're getting the manufactures to just stop sending out straight malware and it should be stopped the next most obvious means of attack is just having the device update and add superaids to it's new functionality.
So, no, it won't stop 99% of it at all.
And honestly this isn't that much different from what US companies are already great at by providing updates that take away features we bought with the device.
And not just updating really doesn't save you, instead of being part of a factory botnet, you're just open to become part of some other botnet.
Some manufacturers will try to cheat on the tests, but we have AI security checking now, so maybe that would make it harder to cheat?
(I’d be open to a rule that devices must allow users to wipe the devices and install their own OS.)
Buying in bulk for a resell without testing even one product is kinda insane.
Once a vendor has been notified that these units are doing these sorts of things they will stop selling them. Its sadly very prescriptive in that if Newegg gets a notice that "WatchFunTV" streaming sticks are doing this, they will remove that brand but if the same hardware shows up from the same vendor as "SuperTVStreamer" or some such, that product won't be banned until someone does the test and then notifies the sellers. It's cat and mouse all the time.
Now the people who could do something about it, the ad networks like Google, do not do anything because ad revenue is ad revenue, people buying the ads cannot prove that the click was false so hey who can say it was? Which is why ad fraud is a perennial favorite of crooks. The people being ripped off don't have any way to prove it without a lot of support from the ad network traffic data which is "proprietary". Really stupid ad fraud gets shut down, but put a bit of care into it so that the Ad network and claim ignorance? You can do that all day. Just don't get greedy and try to pull in more than say 30 or 50 thousand dollars a month. Remember, the IAB said in 2025 alone Ad Revenue was $300B[1] so 2% of that is only $6B and any network with 2% or less of undetected fraud is considered a "high quality" ad network.
So yeah, ad fraud is the gift that keeps on giving.
[1] https://www.iab.com/insights/internet-advertising-revenue-re...
At some point in the second half of the 2010s Amazon figured out they can’t compete with a million foreign randomly-generated companies on price, and their users didn’t seem to mind too much. They figured their users cared about delivery times, ease of returns, ease of dealing with Amazon instead of dozens of online sellers, etc and they leaned heavily into that. They will handle fulfillment and take their cut and let people buy whatever garbage they want. They still screw sellers too btw. Ask any one who is trying to sell something on Amazon and they will fill your ear with how much leverage amazon has over them. You can check r/FulfillmentByAmazon/ Or r/AmazonSellers for stories.
https://en.wikipedia.org/wiki/2008_Chinese_milk_scandal
(Also of note: WHY melamine in the baby formula? Because they knew the buyer would check the nitrogen content, because it's a caveat emptor culture.)
Voters don’t like seeing themselves or their kids get hurt, but they do like lower cost live sports.
"Money talks. And bullshit brothers walk a marathon."
Sketchy devices on your wi-fi don’t really harm anyone. They’re a minor inconvenience at best, mostly to large corporations that like to discern residential connections from business/corporate ones.
Do you have a link to the projector?
I dare not ask why you would do such a thing, instead, I will simply ask if you now think the reason was good, and I will hint at you that if the reason was "convenience", then you should answer "No".
Seriously, why do you think this is normal or acceptable?
This is bullshit needs to stop (and the scummy AdTech industry has a lot to answer for).
I hesitate to blame the victim here, but why on earth would you do that? “$40 Chinese-made” didn’t give you pause?
Of course theres good products made in China, and plenty of entirely Chinese brands killing it doing their thing.
its US software companies that are the worst of the worst in terms of adware and malware being shipped under monopoly control
The word racism is vastly overused these days.
It's not. Firstly, because countries aren't races. Second, because it's just a leftover from a time where that was a good heuristic.
Yes it is also the US companies that are a problem but these are two separate problems and need different terms.
Yes. Chinese manufacturing is quite a phenomenon, useful and everywhere
But to be completely fair, a $40 video projector has a warning label. The price
https://hackaday.com/2022/03/18/welcome-to-the-future-where-...
Show me a COTS smartphone where the end-user can burn the OTP fuses for his personal public key, so they can have it boot their own custom signed firmware, and control exactly what runs in TrustZone's SW Secure World?
Not saying there is an absolute perfect alternative, anyone who says that is usually shoveling smoke, but there are flaws with this economic model to be addressed.
It was said that Karl Marx was completely right about Capitalism and completely wrong about Communism. And that is fairly accurate, both have big flaws.
Most times, the opposite of one bad idea is another bad idea.
https://hackertracker.app/defcon34/content/67257
A guy in Vietnam mentioned that one of the largest ISPs there used these really dodgy Chinese modems which were so notoriously insecure that it was apparently common knowledge that you should replace them if performance was slow because that was a sign that yours was being used by a botnet. Apparently the cost of access to one of those nodes was so low that the spammers don’t even really monitor their bots.
Worst case, everything is packaged up in a single app so it's all or nothing. Although you could just wipe the box and find another pirate TV provider.
I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.
So yes, I do want to blame the purchasers of these things, sometimes. To prove her point that her stamps were legitimate, she mailed me a card using one of her half priced (but likely fake) stamps and it made it through!
That was his justification for a satellite descrambler, they're sending me the signals, obviously I'm allowed to.
> do it because they can get away with it.
Lots of people on HN download and upload copyrighted materials. Is it really different?
I tinkered with Dish Network descrambling 20 years ago. Not because I wanted to just watch a bunch of free TV (I hardly watched any TV anyway, we mostly watched DVDs from the video store and Netflix). More because it felt like an interesting rabbit hole. And it was pretty interesting!
I picked a good (newer!) satellite dish and LNB from the trash and had a friend help with the installation and alignment because that was his previous job. Normal people use some kind of tool to find the satellites' geosynchronous orbital station in the sky, but he did it often enough that he could simply look up into the sky and point at them.
There were a handful of grey-market satellite receivers you could buy that were technically capable of descrambling a commercial signal. Of course, they did not advertise themselves as such. They were marketed as FTA (free-to-air) DVB-S receivers. These were not illegal as they were fairly popular in regions of the world that actually _had_ a fair amount of FTA (unscrambled) satellite channels. The only satellites visible from North America, however, tended to carry religious, shopping, or Mexican/Central American programming. Oh, and NASA TV.
The receiver I bought had DVR functionality if you hooked up a USB drive to it. I think I still have some recorded shows on it. It would have been a great way to harvest and release pirated TV shows to the Internet, if you didn't mind editing out all of the ads and whatever.
DVB-S was basically a raw MPEG-2 TS stream that could be optionally encrypted. To use these grey-market receivers as descramblers, you install some custom firmware containing the descrambling modifications and keys. I'm failing to remember the technical details, but the encryption they used was not very good. Dish Network would rotate the keys occasionally, and when they did, you had to update them on your receiver. I can't remember now if the keys were part of the firmware, but I remember it being a pain in the ass.
The firmware/keys part of this had a very "colorful" community. You had to sign up to a very specific and somewhat exclusive web bulletin board in order to download the firmware/keys. I don't remember how I gained an account, but I remember it being non-trivial. IIRC, it was like one guy maintaining the firmware/keys and sometimes it took weeks for him to adapt to whatever thing DN did to thwart piracy. The board was moderated by a complete power-tripping asshat who enjoyed banning people for fun and then gloating about it. (I was not banned, that I recall.) I think they started requiring "donations" in order to view certain threads (like firmware releases) after a while. But I could be misremembering that. I just remember the community was very toxic.
After a few months of this setup, DN figured out how to rotate their keys too often for the casual pirate to keep up. I disconnected mine around that time and moved onto other things. Partly because the experiment ran its course and partly because migrating to real-time key updates would have meant buying a newer receiver. For a while, I flirted with the idea of getting a DVB-T PCI receiver card and working on breaking the encryption myself, but it was quite a bit above my skill level at the time and there did not seem to be anyone else working on it out in the open, since the DMCA was still pretty new then.
I migrated into it from the earlier days involving iso7816 card programming and mitm cards so I guess I didn’t have trouble finding which sites to get the fta files. I have good memories of those places being quite welcoming if you did your reading but sometimes ephemeral. Plenty of freeware (but sometimes delayed access). But part of the “payment model” was sevurity vendors trying to destroy their competitors or sell more countermeasures and card swaps to their satellite tv broadcast clients (!!!).
A card swap (and some prosecutions on the nudge nudge “free to air receiver” importers) put an end to most of it unless you went to internet-key-sharing systems where I guess the shared keys come from a handful of slave receivers somewhere. Given the 2-way nature of those key “subscriptions” and network connections required, I could (moreso) understand the paranoia of the operators.
Broadband penetration ultimately killed sat cracking, Netflix et al too. Oh, and what people usually call “iptv”.
Feels fitting recently to discover the Dish Network "Pirate TV" recordings. I should run my own in-home IPTV station and use the Pirate TV bug as the logo...
https://www.youtube.com/watch?v=zVXSxJ357pw
You're watching Dish Network's Pirate TV channel!... ... if you're watching me, you're a SATELLITE PIRATE!
I think that makes a big difference.
Imagine if Amazon Video, Audible, and Kindle will all just pirate stores, where uploaders of the pirated content made money on the downloads, people paid for those downloads, and Amazon took a cut of everything. How long would that go on before they were in court and that was shutdown?
So they trust literally everything they read. I still don't think my folks can fathom you can spin up a very real looking newspaper website with fake articles in about 10 minutes.
It was both a gateway into learning how the web works but also that literally anyone can post anything to the internet and it doesn't make it true. I like to think he's more savvy than many of his peers but we all have our blind spots.
like cigarettes?
[1]: https://museum.dea.gov/museum-collection/collection-spotligh...
Amazon will be notified they sold something illegal and will take it down and ban the seller who will immediately launch a new store under a new name.
The purchaser, on the other hand, will be fully liable for whatever horrible thing they bought.
Watch the news and see CEO's with golden handshakes after the company is nailed for something. Wall street failures. Companies getting government bailouts. The current US president. It is all about getting away with what you can.
The news - being the news - doesn't show process as per normal. People doing the right thing most of the time.
In this context, fake stamps for the "little person" doesn't even rate a mention. Who the hell is going to raise a moral panic about an old lady with fake stamps...
And so the "little people" will keep buying fake whatevers as long as it stretches their dollar further.
The USPS becomes directly involved only later, when someone tries to defraud them by using a fake stamp.
Who is selling half-price stamps?
#1 How big is your potential market? It's people still mailing things from home, who haven't figured out how to do postage on their computer.
#2 Of the population in #1, it's those who find real stamps so expensive that it's worth bothering with discounts.
#3 Of the population in #2, it's those who would want to buy something fraudulant (or not know better) and who would want to risk using it.
#4 Considering the size of the #3 population, how many stamps do they use in a month?
#5 What is your margin on a half-price stamp? You have to pay for advertising, printing (we're talking a profit margin under $1), packaging, and your own time, but at least shipping is free!
So is it greed? Yes, but I did it too so now that its more accessible I cannot really blame people.
It’s not like they’re buying these things out of a car trunk in a dark alley. These retailers need to be held liable for selling these things. If they sell this stuff, why not illicit drugs?
If they are unable to maintain control of 3rd party sellers, then they should end the 3rd party seller program. It has done nothing but damage Amazon’s reputation, and it just keeps getting worse.
There are lots of people alive who grew up during the days of broadcast TV and radio. I get why they might not understand the difference.
https://github.com/iptv-org/iptv
To most people IPTV is a bunch of gibberish letters, indistinguishable from the gibberish brands on Amazon. Someone's grandma from Colorado doesn't deserve to get scammed because she didn't research the acronyms.
It is paid for via ads or subsidies, so there's no reason to block access to the stream, so they just don't bother, and make life easier for anyone building streaming devices wanting to integrate their channel.
Someone accessing the stream directly is not the originally intended use case, but it isn't any different from someone accessing it via their smart tv.
- How are these "legitimately free"? For example AMC is a commercial TV channel and as far as I know, they don't offer free streaming. Same goes for MGM, FilmBox etc.
- Strictly speaking this isn't IPTV, it's just web streams. IPTV is usually delivered via multicast (MPEG-TS/RTP/RTSP streams, over UDP mostly).
From a link above to the story on darknetdiaries:
> For Pokemon, there is a website that tells you how to watch this. You start off on Netflix, then swap over to the Pokemon streaming service, which is the only place that has Season 2, then swap over to Prime Video for Seasons 3 through 5, swap to Freevee, then Hoopla. Season 13 is only on Amazon, though. Then swap to Tubi, then Hulu, then Roku channel, and then finally back to the Pokemon streaming, and then Netflix. Easy.
That's 8 different streaming services to view one series.
It's difficult to judge the price of media products. We have legal music streaming services that charges you an album's worth of money a month and lets you listen to millions of songs. You can pick up old AAA games for less than ten bucks. I'd say when people say that price tag, they don't think they get scammed into being a part of a botnet. They think the device manufacturer cut a good deal with the media rights holders.
It's worth separating the two populations:
My users had money and had considered legal subscriptions. They paid me because the legal product was worse—in my case, sports blackouts, a bunch of different apps, etc. They knew what they were buying into and they had weighed the risk. I can tell you right now some of my former users have bought into this market.
Then there's the unwitting: a person buying one of these devices at a too-good-to-be-true price is treating it as a hardware purchase from Amazon, where the actual monetization isn't inferable from the listing. Calling it too good to be true assumes the buyer can see what shit they're standing in. They can't. There's no visible market here. It's just a product page with reviews.
To add to this: the proxy exit is exactly why these cost so little. Demand for residential IPs is booming (check some of the proxy subreddits to see what I mean).
The ironic part is that there's a chance the person who bought one of these boxes to watch pirated sports was the exit node I was using to acquire the feeds in the first place.
[1] Can someone explain what the theory of the product is here? It sounds like they’re marketing these things as ways for the customer to commit fraud, for example by connecting to someone else’s login. How else would the customer expect to be able to get free Netflix or whatever?
If they were using the system to rip off random people, I'd be 100% against it, if they are fucking Google and the giant corps that advertise with them, ehh.. not my problem and can't be assed to care. Google is not a positive force in the world. Hasn't been for many years.
Sure, Google's paying but they get their money regardless.
Let's say you are an ad buyer. Previously 1M clicks resulted in 1000 sales, now 2M clicks result in the same 1000 sales. If you previously paid $1000 for 1M clicks, you paid $1/sale. If they are now asking you to pay the same $1000 / M clicks you'd be paying $2/sale, so Google would have to drop to $500 / M clicks to offer the same value to advertisers.
But the same applies to ad sellers as well. Google would have to slash payouts to websites displaying ads by the same 50% / click or they'd be cutting into their margins. A competing ad platform without fraudulent clicks would be able to slide into this space, offering both a better value to ad buyers and a better payout to ad sellers, so they'd be taking market share from Google without having to do anything themselves.
Of course that assumes a market in which the value of ad clicks, views, and placements is clear to everyone and switching between ad platforms is trivial, which is not even remotely the case.
Its either the ad network running these click botnets or contracting someone to do it. If it was just impressions getting boosted, that just looks shady, those are barely worth anything.
If you told normal people that they could get free content with a TV streaming stick that would also constantly fake clicks on AI generated websites to screw advertisers over, they would think of it as a bonus. Also it would make them trust the stick more (fallaciously), because they would know how the people who sold it were getting paid.
These things are not what HN is for, and destroy what it is for, so we ban accounts that do them repeatedly.
If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here, we'd appreciate it.
Anyway, I think some level of blame is warranted.
you are aware broadcast TV never ended?
But, I think it's far more common for people to have a TV service today, perhaps since comcast and their ilk push hard the TV/phone/internet bundle, and gone are the years when everyone would fiddle with the antennas on the back of their TV to get the right reception.
It reminds me of the saying: "It Is Difficult to Get a Man to Understand Something When His Salary Depends Upon His Not Understanding It".
If these people thought about it for a few minutes, they would understand, but they choose not to, as ignoring it is too advantageous.
I admit I was tempted, as the price of all streaming services goes up, and services become more and more fragmented. During the same period where I have not had a raise.
My point was, their ethics WOULD have prevented them from doing the thing. But they chose not to think about it too hard. Perhaps subconsciously. I'm not above doing this sort of thing either. We all do it for various things.
I've added code that is bad for the user (overbearing telemetry for instance) because my salary depended on it. At the time I tried not to think about it too much, as it would cause cognitive dissonance.
Stremio +Torbox is $3/month and they can probably share 10+ households on one TorBox account so it could work out. The seller could just stop paying the TorBox subscription at whatever point and they have an incentive to do so.
Or Cinese noodles with Chinese tomatoes?
It sounds likw 2 domestic markets that China should use to rid themseves of their over-abundance of tomatoes.
The only winner here is the scammers running the fake affiliate sites on which these sticks are "clicking". Or, am I missing some facet of this enterprise?
It's arguably fraudulent to even refer to it as "advertising" at this point, clearly that's just a cover to give them an excuse to sell data to silicon valley corporations that are unironically named after fictional devices used by sci-fi/fantasy villains to manipulate people.
I mean: They just pay the money, plug the thing in, push some buttons, and: TV happens. Right?
Also, visitors on my wifi started getting strange ads. Yes I threw off the algo, but I'm a guy with wife, I'd rather get car ads than like divorce lawyers + gay dating sites.
Backdoors and spying are also a problem in theory except at this point you can't even trust "legitimate" companies on that front so it's a moot point.
How that actually works in practice is that your favorite sites make less money and your IP gets a bad reputation so you CAPTCHAs or outright blocked. There’s no “sticking it to the man” here, just contributing to the frictional grind making the internet worse for ordinary people.
(IP reputation keeps me from doing it though.)
but compare running tor nodes, and especially exit nodes. that surely would be a good thing, so at least if you think tor is good then running a proxy should be the same and it should be normalized.
doing it in secret without the user knowing is what's bad
Is it a graphic that's shared? Something else? I am sure we all know or have heard of people with these devices that promise free streaming.
Remember, a significant portion of the population got angry (often violently so) when just asked to wear a mask to protect their neighbors. And the threat there was significantly easier to explain.
And don't forget about counterfeit products (which look like original but different in firmware) and supply chain attack vectors, which are really, really common.
If you want to buy something as simple as a feature phone, going to a store with 10 of them will give you at least 1/10 chance to buy a phone with a trojan/backdoor.
Fast forward to last month, now I have started selling these in Barcelona, Spain where I am based out of and branched it into three use cases: digital signage, casting, and a portable computer for presentations at events. Here is the link with features: https://soljacast.com
However, if your target is B2B (Business to Business) as opposed to B2C/D2C (Business to Client/Direct to Client) and you're selling the install plus enterprise support, then the sales thing makes way more sense, and is more expected/palatable for B2B type customers than your everyday consumers, so depends on who you're targeting.
Also right now we are focusing on B2B here in Spain like you guessed, and once we have the other things figured out, we will start shipping to the US and Europe. And after that we plan on rolling out to the rest of the countries.
Thanks for liking my product enough to want to buy it right away :)
Also, we want to test our OS extensively before we release it to be used with a BYOD model. We are launching soon and after that we will try to offer BYOD model as well.
If you are interested in trying it out and helping me in evaluation, please reach out to me via email on my HN profile. Thank you
> Trust me, I really wish it were that easy. We're based out of Spain, so to sell in the US (or other countries) we either need to figure out assembly of the device there, or we need to solve cross-border payments, logistics, customs clearance, tax remittance to individual states, and hardware compliance. That said, we're working hard on all of it and plan to go D2C as soon as possible.
For the pricing part, I am still trying to figure out the pricing for retail consumers. It was relatively easier to do for B2B but for retail, there are a lot of factors and moving parts such as import duties, taxes, shipping etc.
I mean, I don't believe VLAN's were designed with security as a goal, and I wonder how "strong" the virtual wall between two VLAN's actually is?
Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physical connection where packets from both VLANs happen to travel?
Just wondering.
You usually want to interconnect them at one central point, usually a router, and enforce a security policy there.
A bad switch or router (which almost certainly includes a ton of crappy home APs and routers, compromised by the same actors who ship these devices) could let clients see VLAN tags and ignore them.
And an Ethernet “hub” does no filtering at all.
And any kind of multicast (used for local service discovery and media streaming) has the same limitations.
> Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physical connection where packets from both VLANs happen to travel?
That would be an exceptionally weird configuration. If a device "sits on VLAN1" that typically means that it's on an "untagged" port where only VLAN1 traffic is allowed. Ports that carry multiple VLANs are "tagged" ports and you normally wouldn't say they "sit" on any specific VLAN, precisely because that port carries tagged traffic for multiple VLANs. It's at best an irregular use of the terminology but likely a misunderstanding somewhere.
Really wish I could point Mythos at my router and just loop it until my router becomes literally unhackable.
https://github.com/synthient/public-research/blob/main/2026/...
1. They want more as targeting data on you
2. They want to reduce bot clicks
It's an unholy alliance with governments who want to know who writes what online.
I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.
Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?
My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.
https://docs.roku.com/published/userprivacypolicy
see: "olfactory", "content of"
or at least they're CYA while they're sniffing.
they definitely scan the entire local network.
Anyway, the box is powerful enough to do several things. You can install a IP tv if you want. If you don't, you still have a pretty good media center (you can hook up an external hd on it)
I switched to a Google box, this has no bloatware and this way I get tracked only by one company.
01: DDOS
10: Residential proxies
11: Somebody DDOSing residential proxies
I suspect these TVs either come with residential proxies set up from the factory, or they have such poor security that they’re instantly hacked. Either way, TV manufacturers (including reputable ones like LG) are to blame.
I don't think residential proxying is all that shady since groups like Cloudflare have made it a necessity. However, having it out-of-the-box on a name-brand device is extremely shady.
It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique.
An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.
The devices are used to sell proxy services and scam advertisers. This doesn't even need particularly large organised crime. It would certainly be easier than large scale illicit drug importation and retail, which is happening all the time.
Could China exploit these streaming sticks if it wanted to? Maybe, but no more than any other nation.
You had me at "But"! ::swoon::
Instead they're banning stuff willy nilly left and right without really solving the problem.
But there's good stuff coming out of China as well. I recently bought a cheap e-reader which has no WiFi or internet connection and it works stellar. And I bought some cheap Chinese sport cams which also lack internet and work great.
Personally, I think every other country should ban any product made by Google, Amazon, and Microsoft since they all spy on the users of their products too.
These companies could use the info they gather on customers for their own use but they cannot (re)sell it to anyone, not even the government. The reason being that the information eventually ends up abroad after which you lose all control over it.
This is my surprised face.
(Acepable would be something like 1TB worth of gamedemos)
Original with more details: https://www.bitsight.com/blog/fuyao-enterprise-building-ad-f...
Oh no! Not the advertising networks!
Sounds good in theory but in practice, computers are good at sorting this stuff out. Kind of why they are so popular.
Every cloud has a silver lining.
> Roughly twice per second, a Roku TV captures video “snapshots” in 4K resolution. These snapshots are scanned through a database of content and ads, which allows the exposure to be matched to what is airing. For example, if a streamer is watching an NFL football game and sees an ad for a hard seltzer, Roku’s ACR will know that the ad has appeared on the TV being watched at that time. In this way, the content on screen is automatically recognized, as the technology’s name indicates. The data then is paired with user profile data to link the account watching with the content they’re watching. https://advertising.roku.com/learn/resources/acr-the-future-...
This is already a common feature for analytics toolkits.
I'm on my second one and I've owned them since the first version. My current one is the first generation 4k that's ... seven years old? Still works like new.
It was a rabbit hole and in the end I got back using my NVIDIA Shield. This is about 10 years now, but it’s actually still the best option.
Harm to the user: none^
> spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks
Harm to the user: none^
Cost to the dodgy service provides: none
Government action to prevent continued dodgy services: none^
This is why internet securityg doomers have a hard time selling their story. Changing behaviour has an upfront, immediate, cost. Not changing it doesn't.
^close enough
> Harm to the user: none^
Well, they are losing some of their bandwidth. They might not notice, but something which is rightfully theirs is being taken without consent.
I expect many cameras of “dubious” origin are used for similar tasks, same with most “smart” devices with sufficient horsepower.
So you bought that top of the line security-as-a-product thingy you can stick in your rack and it will make sure that your network is impenetrable? You know, like those CISCO bricks everyone major company is buying.
So have you took an extra precautions to make sure that the firmware on the device is pristine? Do you know anyone who ever touched these devices who actually did?
Do you see the problem?
These sticks leave the factory with malware pre-flashed, the postman brings them to your door with zero risk for the beneficiary.
Preparing casus belli.. first, open weights LLM which are "not secure", now "TV sticks"..
Oh joes and janes, who will put finally some sense into you..
China is not doing that as far as I know. Neither Russia did it before the war, though you were claiming the contrary (I know, since I live in the west and could compare news from both sides, being a native Russian speaker).
Sorry, but "your tv stick does ad fraud" is just about the most innocent thing I've seen in a while. Everyone in this market is doing the shadiest shit you can imagine. There are no good brands left, you just get to pick what logo your Malware Entertainment Device has.
Looks like cheap small computer with a remote control.
Compromised (or malicious from the factory) devices being recruited into bot farms for click fraud is ... a groundbreaking discovery in 2026?
> on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
To hell with AI-generated websites and advertising networks.
Say, where can I get the most effective malicious TV stick for click-frauding the fuck out of that shit? I will take fifteen! :)
Use a computer - you actually control the content that way.
Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.
What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.
How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:
- the user must be able to re-flash firmware with their own code.
- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.
- any telemetry or data collection, or updates must be opt-in only and disabled by default.
- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.
Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.
I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.
I want big companies to stop spying on me, which is a completely different issue.
Most Americans are at a greater threat of harm from their own government that a foreign one. What worries me is all the mass surveillance done by big tech which bypasses the 4th Amendment and gives the government Americans data without a warrant.
There's already a front door with the adtech for US alphabet boys. This could likely be collected by others as well. We saw this happened where foreign hackers exploited a backdoor designed for American authorities[1]. This is what experts are referring to when they say there's no backdoor only for me.
This could be compelling to politicians, though, and would certainly be a step in the right direction.
>- any telemetry or data collection, or updates must be opt-in only and disabled by default
This should be how it is for everything foreign made software or not. Would be very hard to get done with the big tech lobby in the US.
[1] https://techcrunch.com/2024/10/07/the-30-year-old-internet-b...
Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?
> for every imported device having a CPU and Internet connectivity
Why limit this to imported devices?
> Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?
Cheap, slow-moving drones are the hot new missiles on the battlefield of today. This often talked-about model files at 115 mph (https://en.wikipedia.org/wiki/HESA_Shahed_136).
Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys.
Could it be used for missiles? Sure. Is it obviously the intention? No.
Apple: https://support.apple.com/en-us/102515
> If Location Services is on, your device will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers to Apple to augment Apple's crowd-sourced database of Wi-Fi hotspot and cell tower locations.
Google: https://support.google.com/android/answer/15157297?sjid=1648...
> When Location Accuracy is on, Google periodically collects information about the locations of wireless signals and sensors observed by your device to crowdsource location estimates. This helps everyone find locations better.
Mozilla used to run a very similar service: https://en.wikipedia.org/wiki/Mozilla_Location_Service
Not to mention truly crowd-sourced databases like wigle.net.
[1] https://support.google.com/android/answer/3467281?sjid=66634...
Regarding the government, the problem is that many people do not fully understand the mechanism of collecting the data. I remember the case when members of US military disclosed the location of secret objects through fitness tracker app. And they were probably smarter than average smartphone user. Obviously it would be better if enabling GPS required an approval from their commander.
I'll agree that militaries would prefer their soldiers to not to dumb things - but I don't agree that it's 'obviously' best if people needed permission to enable GPS! If that's the case depends a lot on which soldier is enabling the GPS and their relation to me. In general I would say that government control of people recording and distributing their observations is associated with the most authoritarian governments and by claiming we should get government permission you appear to be aligning yourself with an authoritarian approach to data controls.
The Snowden leaks showed that the US was already doing this. I'm certain that everything purchased is already infected with something. Most likely bugs and bad security.
Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)
It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.
Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.
Keep in mind that it's your IP and identity associated with those clicks and anything else criminals decide to do with your IP address. That means you're identity is being linked to things you may or not want to be known as being interested/involved in. The ads your TV stick clicks on can cause data brokers to include your name in lists of people who are heavily into drugs, have mental disorders, belong to certain religions or political parties, etc. All of that can come back to haunt you later.
Depending on what other activity your connection is used for as a proxy it can also get you in trouble with the police or with your ISP.
What you do on the internet has very real impacts on your life offline and it's going to happen more and more over time. AI will make it easier for companies to leverage the massive amounts of data avilable to them about you. Surveillance pricing is spreading. Consumer reputation services are spreading. Law enforcement is buying up data from data brokers. Extremists are using data brokers to decide who to target with violence.
I get that these products are personally inconvenient to Brian Krebs and his work, and to companies that make money blocking people from accessing the internet, and to companies that make money spewing ads in people's faces. So? Why should anyone care about any of those? In fact I think some people would get one of these sticks just to inconvenience the latter two groups!
I use one but only when traveling at hotels - it’s one of the only sticks that can connect to captive WiFi networks at hotels
I’ve got barely anything on it so privacy be damned - but at this point this is why I just buy apple products
I have two apple tv’s which probably do shady things too, but I’m willing to play the probabilities and assume it’s the least bad of my options short of tinkering with flashing hardware and all that stuff that used to be fun in my teens (emphasis on used to)
We're called engineers brian.
So the mafia is back.
This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.
That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.
That is not enough. You need to air gap devices that have legitimately no business communicating with anyone or anything outside the house. TVs, thermostats, and other Internet-of-Crap gadgets do not need "firmware updates." Either they work out of the box, offline or within the LAN, or they get sent back for a refund wherever they came from.
Limiting what outbound access devices can/can't have is an important skill to learn.
And they would have caught them but those crafty criminals spoofed the user-agent. So how _could_ they know?
This is why I giggle when people talk about ending Section 230 in the USA (or various international counterparts thereof).
The largest companies on Earth are happily selling hacked piracy spyware botnet garbage. Not just hosting malicious posts for free like Section 230 protects, but selling illegal physical devices and taking a cut of the profit and excusing it with a pathetic whack-a-mole moderation system. It's already illegal and the law has already failed.
Sean Parker's mistake was that he wasn't rich enough.
Laws are for poor people.
Both you, and the corrupt politicians, are eating away at the trust that underpins society. Certainly, you can argue, your bite is just a tiny one; the politician is eating the whole apple.
At the end of the day, everyone suffers from the decline of trust and casual acceptance of fraud.
Didn't know Krebs was a mainstream news puppet.
If you just want to spam clicks on ads you don't financially be edit from, go for it.