Read this before you buy that TV streaming stick

Posted by speckx 4 days ago

Counter809Comment545OpenOriginal

Comments

Comment by simojo 3 days ago

We purchased a Chinese-made projector from Amazon, which was surprisingly inexpensive (~40 USD). Upon connecting it to the internet, it placed a constantly running feed of ads on the corner of the screen, even while movies were playing. There was no way to disable it either. Even though it's not a stick, it's a similar principle.

Comment by xyx0826 3 days ago

I remember reading an analysis on one of those projectors; the author found a residential proxy running on their device. I would recommend keeping these things off the internet.

Comment by mrloopex 3 days ago

Yes that’s what the article is about.

Comment by simojo 3 days ago

I'd be very interested to see it if you still have access to it.

Comment by dhruvrrp 3 days ago

Dunno if this is the same issue, but someone found malware in their projector. I'm not sure about the accuracy since the report is blatantly AI generated: https://github.com/jrm360seclab/aodin-vo1d-malware

Comment by throwa356262 3 days ago

If the hardware is good and cheap, it should be a fun project to replace the OS with a custom Android build that is clean of adware.

Do you have a link to the projector?

Comment by __turbobrew__ 3 days ago

You forgot to drink a verification can

Comment by Pxtl 3 days ago

I mean, did you have to connect it to the internet though? Did it not just have a dp/hdmi port?

Comment by 3 days ago

Comment by ubermonkey 3 days ago

I'm still trying to figure out why you didn't see that coming.

Comment by mikestew 3 days ago

Upon connecting it to the internet…

I hesitate to blame the victim here, but why on earth would you do that? “$40 Chinese-made” didn’t give you pause?

Comment by bigmattystyles 3 days ago

To be fair, everything is Chinese made. I would be even the Apple TV and NVIDIA Shield are made in China and if a state actor is determined to get a malicious payload in....

Comment by miladyincontrol 3 days ago

To play devil's advocate, when someone says "Chinese made" they're usually well aware of your point, and are more using it as a common way to describe product mills spitting out countless devices with dubious quality or configuration.

Of course theres good products made in China, and plenty of entirely Chinese brands killing it doing their thing.

Comment by 8note 3 days ago

its pretty straight racism though.

its US software companies that are the worst of the worst in terms of adware and malware being shipped under monopoly control

Comment by wvh 3 days ago

It's not racism at all to be weary of (any) political system, its overreach and the incentives of the people living in it, be it China or America or Russia.

The word racism is vastly overused these days.

Comment by parineum 3 days ago

> its pretty straight racism though.

It's not. Firstly, because countries aren't races. Second, because it's just a leftover from a time where that was a good heuristic.

Comment by Eisenstein 3 days ago

Its based on the most common heuristic people have developed in regards to the phenomenon. What do you think about 'alphabet soup company' instead, referring to the tendency for names to be a mix of random letters? Otherwise, you can try and create a better term for 'unaccountable third parties using US platforms to dodge liability for their product made out of the cheapest components and software possible' and see if that catches on.

Yes it is also the US companies that are a problem but these are two separate problems and need different terms.

Comment by SecretDreams 3 days ago

There's enough evil malware provider blame to go around.

Comment by handle584 3 days ago

[dead]

Comment by r_lee 3 days ago

Made in China and random Chinese brands are two very different things

Comment by ChrisRR 3 days ago

Often they're exactly the same things

Comment by inigyou 3 days ago

Often the USA brand is just buying the random Chinese design from the same factory that brands it in random letters, and tripling the price.

Comment by r_lee 3 days ago

if you think the Apple TV or Nvidia shield example applies to this then I don't know what to say

Comment by worik 3 days ago

> To be fair, everything is Chinese made

Yes. Chinese manufacturing is quite a phenomenon, useful and everywhere

But to be completely fair, a $40 video projector has a warning label. The price

Comment by fc417fc802 3 days ago

This isn't about state actors though. There's a world of difference between a name brand (possibly even a Chinese one) versus what I would term "chineseum". It's nothing to do with China per se and everything to do with purchasing from the extreme low end of the market. It just so happens that the vast majority of that segment is manufactured in China at present.

Comment by speerer 3 days ago

I think normally when people say Chinese made in this way, what they're really communicating is that there's no (meaningful) brand. All they know about it is that it is from China.

Comment by ponector 3 days ago

My Samsung phone is made in Vietnam.

Comment by SiempreViernes 3 days ago

This is an age where even teacups demand internet connectivity to fetch firmware updates

Comment by Ballas 3 days ago

And then what happens if someone accidentally pushes the saucer firmware to the cup update?

https://hackaday.com/2022/03/18/welcome-to-the-future-where-...

Comment by earleybird 2 days ago

You get a Saucerfull of Secrets :-)

Comment by histriosum 3 days ago

Finally, a legitimate use case for HTTP 418…

Comment by red-iron-pine 3 days ago

and they thought it was an April Fools joke, hah!

Comment by contravariant 3 days ago

I mean I get why my cups need frequent java updates, but still.

Comment by tollgategit 3 days ago

And yet, it is now still just as stupid to do it as it was before we arrived here.

Comment by handle584 3 days ago

[dead]

Comment by qmr 3 days ago

...firewall it then?

Comment by tollgategit 3 days ago

> Upon connecting it to the internet,

I dare not ask why you would do such a thing, instead, I will simply ask if you now think the reason was good, and I will hint at you that if the reason was "convenience", then you should answer "No".

Comment by dspillett 3 days ago

The streaming sticks the article is discussing basically need network access to function. They might support streaming from local media sources and file shares too, but that is also done over WiFi. Unless you have a properly firewall controlled home (very few people do, I'm pretty nerdy and most devices on my network can just NAT to the outside these days) then just giving it a WiFi connection gives it access to the wider network from your location.

You'll probably find the projectors are pretty much the same hardware and OS as the sticks except with the projection device added where the stick just has an HDMI output. It might have HDMI-in too so it can just be used as a screen for another device, but there are definitely some units out there that are network-play-only.

You aren't wrong about giving cheap crap like this access to your network (and via that the public network) is risky, but that convenience you (and I) would say no to is exactly what they are bought for.

Comment by breppp 3 days ago

You assume a lot of things, sometimes you have to connect it to the internet for it to work (such as robovacuums)

Comment by GJim 3 days ago

Why in the name of all that is holy would you need to connect a projector or vacuum cleaner to the internet in order for it to work?

Seriously, why do you think this is normal or acceptable?

This is bullshit needs to stop (and the scummy AdTech industry has a lot to answer for).

Comment by breppp 3 days ago

As far as I remember they mandate you connect to it in order for you to operate it.

We all know why, which is Adtech, but like cars or smart TVs, you as a customer either skip the entire segment or yield.

Comment by themaninthedark 3 days ago

Vacuum for "convenience" of being able to turn it on with a phone.

I could actually see hooking up a projector to wifi to allow it to stream videos.

Comment by dboreham 3 days ago

Capitalism!

Comment by wil421 3 days ago

Chinese!

Comment by Epa095 3 days ago

Chinese capitalism!

Comment by red-iron-pine 3 days ago

Communism with Chinese Characteristics

Comment by jojobas 3 days ago

At least in capitalism you have the choice to look for a malware-free alternative. 100% USSR, had it survived to the IoT era, would penalize you for not having a state-mandated surveillance device on at all times.

Comment by DoctorOetker 3 days ago

I agree fully with your assessment of USSR but basically any nation state with the power does such things.

Show me a COTS smartphone where the end-user can burn the OTP fuses for his personal public key, so they can have it boot their own custom signed firmware, and control exactly what runs in TrustZone's SW Secure World?

Comment by jojobas 3 days ago

You can flash yourself GrapheneOS with your own keys for the bootloader. Then again "I can't make sure all manufacturers aren't in collusion" when FBI sues Apple and others (and fails) over suspects' phone access is quite different from "every device sold in the country must have government malware", as it is in China.

Comment by inigyou 3 days ago

I can't find a device in the USA that doesn't come with government malware. Is this another instance of the USA accusing China of everything the USA is doing (like with the credit scores)?

Comment by breppp 3 days ago

You'd have to be a bit more specific of which government malware you found in Android/iOS devices, cause that would be interesting

Comment by inigyou 3 days ago

Android comes with something called Google Play Services, and iOS has a thing called iCloud. You may have heard of them.

Comment by breppp 3 days ago

I have, I still have not heard how the US government uses these as malware, but I would love to learn something new

Comment by inigyou 3 days ago

For instance, if you use an Apple phone and the government wants to see the pictures you took, they can just get a copy of them from Apple using iCloud.

Comment by breppp 3 days ago

Yes, using a warrant from a court. If the government wants to break into my house they can also do that with a warrant. Not exactly the same as having a key to my house though, and very far from a malware.

Also to be more specific, In apple ecosystem I can opt for encryption where they can't

Comment by inigyou 2 days ago

In the UK you can't opt for encryption.

Comment by jojobas 2 days ago

You still can install PGP/GPG and encrypt whatever you upload yourself.

Still waiting for anything comparable to what China does.

Comment by inigyou 2 days ago

> Still waiting for anything comparable to what China does.

Social credit scores. The USA inspired China to copy them. But in the USA they aren't called social.

Comment by jojobas 2 days ago

You're free to opt out of icloud/gcloud and the government will have a tough time extracting the pictures from your phone, as multiple lawsuits have shown.

Comment by anon48293 2 days ago

Without my encryption keys, which Apple doesn’t have? Don’t think so.

Please tell me how with Advanced Data Protection on they can access my data. I’d love to hear it.

Comment by red-iron-pine 3 days ago

show me anyone outside of HN or XDA devs that would ever want to do that

Comment by jjav 1 day ago

> At least in capitalism you have the choice to look for a malware-free alternative.

In the US capitalism, can you find a mobile phone OS that respects owner freedom?

Comment by azan_ 3 days ago

Absolutely, there's no scam outside capitalism!

Comment by jkahrs595 3 days ago

Outside of capitalism is outer space, so your snarky comment is actually true.

Comment by usef- 3 days ago

I think he meant the other kind of "outside", not physically. Plenty of bad stories.

Comment by azan_ 3 days ago

Of course, every socialist country is actually capitalism and that's why it fails.

Comment by inigyou 3 days ago

Which country is socialist?

Comment by ColdStream 3 days ago

Get the sarcasm, but of course there is scam outside of capitalism. Its just that the capitalistic model almost turns it from an inconvenient bug into a mainline feature.

Not saying there is an absolute perfect alternative, anyone who says that is usually shoveling smoke, but there are flaws with this economic model to be addressed.

Comment by azan_ 3 days ago

Not true at all. I'm from Poland which was occupied by communist for a long time, and I can guarantee you - the amount of scam we had under that rule was orders of magnitude larger than what we have now.

Comment by ColdStream 3 days ago

Yeah I did forget about that. When you flatten the pay structure across the board, it makes bribes and scams so much more desirable. But also, communist structure in practices is sort of the total opposite of capitalism at a distance.

It was said that Karl Marx was completely right about Capitalism and completely wrong about Communism. And that is fairly accurate, both have big flaws.

Most times, the opposite of one bad idea is another bad idea.

Comment by azan_ 3 days ago

I think it's really far fetched to say capitalism is bad idea. It's great system, it has some problems, but the upside is so big and alternatives are so bad that it's really unfair to call it bad system.

Comment by ndsipa_pomu 3 days ago

I think that encouraging corporations to destroy our environment (e.g. climate change) as fast as possible to maximise profits is a very good reason to call it a bad system. Yes, some goods and services become much more efficient, but now we're all going to have to pay the price for it.

Comment by inigyou 3 days ago

Like the current never-ending heat wave. It's predicted to go on for months btw and the ocean is 4 Kelvins warmer than it should be.

Comment by pbhjpbhj 3 days ago

Yh, the end of civilisation is a good thing after all, so enabling greedy fuckers to accelerate all life on Earth ever more rapidly towards destruction has to be good ...

Comment by azan_ 2 days ago

Civilization is thriving and we are living in the best times (thanks to capitalism).

Comment by mortenjorck 4 days ago

In this case it’s actual malice, that the streaming stick is set up for residential proxy and ad fraud straight from the factory. But incompetence can lead to the same place if it’s a poorly engineered, un-maintained device with an old version of Android that will never be patched and is always one no-click exploit away from being commandeered into residential proxy and ad fraud.

Comment by FinnKuhn 4 days ago

Those TV streaming boxes really are (from a cybersecurity perspective) probably one of the worst things you can buy. Here is the "Darknet Diaries" Episode on them: https://darknetdiaries.com/episode/172/

Comment by labbett 3 days ago

Superbox 3 is coming up at DEF CON next Friday!

https://hackertracker.app/defcon34/content/67257

Comment by doctorspazz 3 days ago

Thank you for sharing this. The superbox investigations have been incredibly interesting to follow.

Comment by acdha 3 days ago

I was trying to figure out why we saw so many fraudulent applications from Vietnam for a service which is restricted to the United States, especially because they were all getting rejected - it seemed like even the laziest spammer would lose interest in something they couldn’t monetize.

A guy in Vietnam mentioned that one of the largest ISPs there used these really dodgy Chinese modems which were so notoriously insecure that it was apparently common knowledge that you should replace them if performance was slow because that was a sign that yours was being used by a botnet. Apparently the cost of access to one of those nodes was so low that the spammers don’t even really monitor their bots.

Comment by frollogaston 3 days ago

Since these are poorly engineered, wonder how easy it'd be to reverse-engineer one and just get the free streaming on a non-scam device.

Comment by kiririn 3 days ago

See CoreELEC/LibreELEC/etc - totally replaces the (potentially dodgy) Android OS on these kind of streaming boxes with a stripped down Linux+Kodi setup

Comment by qmr 3 days ago

I thought those were for x86? They run on ARM TV boxes / sticks now?

Comment by tesnorindian 3 days ago

LibreElec also supports ARM builds than can run on SBC like Raspberry Pi. While CoreElec is exclusively for Amlogic ARM processors.

Comment by dpoloncsak 3 days ago

If it's something like a Firestick (or the knock-off featured in the article), you're really just connecting to Content Provider servers to handle auth and content streaming, right? They're just OSes designed to run Netflix and Hulu. Would be hard to spoof I think

Comment by mikepurvis 3 days ago

Indeed. Owning the streaming box lets you loose on whatever network it's on, but it doesn't actually get you inside the content gardens; those are separately managed by teams of people much more motivated to protect their IP.

Comment by wildzzz 3 days ago

Best case, you can grab the credentials off the Kodi box and use them on a clean install.

Worst case, everything is packaged up in a single app so it's all or nothing. Although you could just wipe the box and find another pirate TV provider.

Comment by alex_duf 4 days ago

I wonder to what degree malice can be engineered to look like incompetence?

Comment by abbeyj 4 days ago

Try examining the old entries from the https://en.wikipedia.org/wiki/Underhanded_C_Contest.

Comment by inigyou 3 days ago

What is the malice in those things?

Comment by 8note 3 days ago

consumers are however happy to buy a cheaper stick with an overall public bad

Comment by inigyou 3 days ago

I don't even think it's a public bad. I think attacking internet gatekeepers like Cloudflare is objectively a public good. So is attacking legal spam companies.

Comment by psd1 3 days ago

...ish. Attacking their monopoly, great. Attacking their workers by bombing an office, not so great. Throwing ever more spam traffic across the tubes isn't a attack, it's marketing on their behalf.

Comment by inigyou 3 days ago

In what way is clicking an ad like bombing an office?

Comment by psd1 2 days ago

I think i was clear, but I'll try again. You said this:

> attacking internet gatekeepers

I think we agree that you don't mean all kinds of attack. The agreed exception is bombs.

I put it to you that throwing bot traffic around is another kind of attack that you do not want, because it drives product sales. You would be doing them a favour.

Comment by pavel_lishin 4 days ago

> generic TV boxes that promise unlimited content streaming for a one-time fee

I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.

Comment by havaloc 4 days ago

I have an elderly client who sends me links of stuff to buy all the time. One day it's one of these streaming sticks, the next day it's half-price stamps, and I tell her every time, please don't buy this stuff. And yet she does anyway, as if I was almost being mean and saying no just to say no.

So yes, I do want to blame the purchasers of these things, sometimes. To prove her point that her stamps were legitimate, she mailed me a card using one of her half priced (but likely fake) stamps and it made it through!

Comment by Terr_ 3 days ago

Perhaps they grew up in a time/environment where "if it was that bad they wouldn't be allowed to advertise it", and they're still using that old calibration?

Comment by mhurron 3 days ago

My falther-in-law was less that and more, if I can get away with it, it's actually legal. Many know their fake, and do it because they can get away with it.

That was his justification for a satellite descrambler, they're sending me the signals, obviously I'm allowed to.

Comment by brewdad 3 days ago

There's an old Carlin joke about "If a cop didn't see it, I didn't do it."

Comment by mmooss 3 days ago

I can imagine many on HN having excited discussions about their satellite descramblers.

> do it because they can get away with it.

Lots of people on HN download and upload copyrighted materials. Is it really different?

Comment by bityard 3 days ago

Fine, you've nerd-sniped me.

I tinkered with Dish Network descrambling 20 years ago. Not because I wanted to just watch a bunch of free TV (I hardly watched any TV anyway, we mostly watched DVDs from the video store and Netflix). More because it felt like an interesting rabbit hole. And it was pretty interesting!

I picked a good (newer!) satellite dish and LNB from the trash and had a friend help with the installation and alignment because that was his previous job. Normal people use some kind of tool to find the satellites' geosynchronous orbital station in the sky, but he did it often enough that he could simply look up into the sky and point at them.

There were a handful of grey-market satellite receivers you could buy that were technically capable of descrambling a commercial signal. Of course, they did not advertise themselves as such. They were marketed as FTA (free-to-air) DVB-S receivers. These were not illegal as they were fairly popular in regions of the world that actually _had_ a fair amount of FTA (unscrambled) satellite channels. The only satellites visible from North America, however, tended to carry religious, shopping, or Mexican/Central American programming. Oh, and NASA TV.

The receiver I bought had DVR functionality if you hooked up a USB drive to it. I think I still have some recorded shows on it. It would have been a great way to harvest and release pirated TV shows to the Internet, if you didn't mind editing out all of the ads and whatever.

DVB-S was basically a raw MPEG-2 TS stream that could be optionally encrypted. To use these grey-market receivers as descramblers, you install some custom firmware containing the descrambling modifications and keys. I'm failing to remember the technical details, but the encryption they used was not very good. Dish Network would rotate the keys occasionally, and when they did, you had to update them on your receiver. I can't remember now if the keys were part of the firmware, but I remember it being a pain in the ass.

The firmware/keys part of this had a very "colorful" community. You had to sign up to a very specific and somewhat exclusive web bulletin board in order to download the firmware/keys. I don't remember how I gained an account, but I remember it being non-trivial. IIRC, it was like one guy maintaining the firmware/keys and sometimes it took weeks for him to adapt to whatever thing DN did to thwart piracy. The board was moderated by a complete power-tripping asshat who enjoyed banning people for fun and then gloating about it. (I was not banned, that I recall.) I think they started requiring "donations" in order to view certain threads (like firmware releases) after a while. But I could be misremembering that. I just remember the community was very toxic.

After a few months of this setup, DN figured out how to rotate their keys too often for the casual pirate to keep up. I disconnected mine around that time and moved onto other things. Partly because the experiment ran its course and partly because migrating to real-time key updates would have meant buying a newer receiver. For a while, I flirted with the idea of getting a DVB-T PCI receiver card and working on breaking the encryption myself, but it was quite a bit above my skill level at the time and there did not seem to be anyone else working on it out in the open, since the DMCA was still pretty new then.

Comment by wildzzz 3 days ago

Your experience describes lots of the kinds of communities you can use to access pirated media. You either pay for the legit service, pay for pirate streaming services, pay with your privacy with the free, dodgy pirate streaming services, or pay with your sanity in dealing with nutjobs.

Comment by Scoundreller 3 days ago

I recall the “free to air” receivers being pretty easy to configure. My main pita was getting a cheap ftdi usb->serial adapter because that’s how old the underlying tech was. Still easier than jtagging an official receiver.

I migrated into it from the earlier days involving iso7816 card programming and mitm cards so I guess I didn’t have trouble finding which sites to get the fta files. I have good memories of those places being quite welcoming if you did your reading but sometimes ephemeral. Plenty of freeware (but sometimes delayed access). But part of the “payment model” was sevurity vendors trying to destroy their competitors or sell more countermeasures and card swaps to their satellite tv broadcast clients (!!!).

A card swap (and some prosecutions on the nudge nudge “free to air receiver” importers) put an end to most of it unless you went to internet-key-sharing systems where I guess the shared keys come from a handful of slave receivers somewhere. Given the 2-way nature of those key “subscriptions” and network connections required, I could (moreso) understand the paranoia of the operators.

Broadband penetration ultimately killed sat cracking, Netflix et al too. Oh, and what people usually call “iptv”.

Comment by kotaKat 3 days ago

Yep. Gone are the days of running out for a "119 IKS" or hunting for Bev and Charlie, now everyone just grabs some pooched RTSP feeds and calls it a day.

Feels fitting recently to discover the Dish Network "Pirate TV" recordings. I should run my own in-home IPTV station and use the Pirate TV bug as the logo...

https://www.youtube.com/watch?v=zVXSxJ357pw

You're watching Dish Network's Pirate TV channel!... ... if you're watching me, you're a SATELLITE PIRATE!

Comment by Scoundreller 2 days ago

Dunno if admitting defeat like that is a sign of strength or weakness.

Comment by 3 days ago

Comment by al_borland 3 days ago

They aren’t downloading that content from a company with a $2.5T market cap. They presumably aren’t making a living by selling that copyrighted material via a retail that claims to run a legitimate business.

I think that makes a big difference.

Imagine if Amazon Video, Audible, and Kindle will all just pirate stores, where uploaders of the pirated content made money on the downloads, people paid for those downloads, and Amazon took a cut of everything. How long would that go on before they were in court and that was shutdown?

Comment by iamben 3 days ago

I think that's a default for a lot of the older (and some of the younger!) generation, same goes for news and media. They grew up in a time where there was a practical barrier to publishing and (largely) laws behind you doing it.

So they trust literally everything they read. I still don't think my folks can fathom you can spin up a very real looking newspaper website with fake articles in about 10 minutes.

Comment by mmooss 3 days ago

I find younger people are more likely to trust whatever they read - social media rumors, LLM output, Reddit threads - and older people looking for credible sources.

Comment by CM30 3 days ago

Honestly, my experience is that it's less age specific and more like 80-90% of the general public. A lot of people just can't recognise the difference between a credible source and a dubious/fake one, and will just share any old random page or social media post they come across online. Heck, the number of people I know that see things like ChatGPT as some magic encyclopedia/sage that knows everything is depressingly high...

Comment by brewdad 3 days ago

When my kid was young I set up a basic web server and taught him how to make a VERY basic web page. I let him write whatever nonsense he wanted to and then we made it live.

It was both a gateway into learning how the web works but also that literally anyone can post anything to the internet and it doesn't make it true. I like to think he's more savvy than many of his peers but we all have our blind spots.

Comment by doctorspazz 3 days ago

was the url for the website you set up for him www.creedthoughts.gov.www\creedthoughts

Comment by rrr_oh_man 3 days ago

> time/environment where "if it was that bad they wouldn't be allowed to advertise it"

like cigarettes?

Comment by dfxm12 3 days ago

I doubt there ever was a time/environment. Snake oil has been around consistently for a very long time.

Comment by Pxtl 3 days ago

Of course, what they're missing is that laws are for poor people.

Amazon will be notified they sold something illegal and will take it down and ban the seller who will immediately launch a new store under a new name.

The purchaser, on the other hand, will be fully liable for whatever horrible thing they bought.

Comment by 3 days ago

Comment by mmooss 3 days ago

> half-price stamps

Who is selling half-price stamps?

#1 How big is your potential market? It's people still mailing things from home, who haven't figured out how to do postage on their computer.

#2 Of the population in #1, it's those who find real stamps so expensive that it's worth bothering with discounts.

#3 Of the population in #2, it's those who would want to buy something fraudulant (or not know better) and who would want to risk using it.

#4 Considering the size of the #3 population, how many stamps do they use in a month?

#5 What is your margin on a half-price stamp? You have to pay for advertising, printing (we're talking a profit margin under $1), packaging, and your own time, but at least shipping is free!

Comment by wildzzz 3 days ago

Its the grandmas still sending you a $5 check in the mail for your birthday

Comment by mmooss 3 days ago

How can those few people - and again narrowed down to the population mailing letters AND needing stamps AND seeking discounts AND willing or ignorant enough to do/risk fraud - with that little revenue per item, make a half-price stamp operation worthwhile?

Comment by _carbyau_ 3 days ago

What is the world view (aka context) of this little old lady?

Watch the news and see CEO's with golden handshakes after the company is nailed for something. Wall street failures. Companies getting government bailouts. The current US president. It is all about getting away with what you can.

The news - being the news - doesn't show process as per normal. People doing the right thing most of the time.

In this context, fake stamps for the "little person" doesn't even rate a mention. Who the hell is going to raise a moral panic about an old lady with fake stamps...

And so the "little people" will keep buying fake whatevers as long as it stretches their dollar further.

Comment by Scroll_Swe 3 days ago

Then again I used to torrent everything under the sun and it actually rocks to have every tv show, movie, game ever released for free forever.

So is it greed? Yes, but I did it too so now that its more accessible I cannot really blame people.

Comment by hakfoo 2 days ago

Discounted stamps do exist.

Stamp collectors end up stuck with sheets and sheets of unpopular designs, and since the hobby (like many hobbies) has imploded, the dealers will pay less than face value for it; they in turn will sell it for a smaller discount for people who are willing to futz with wallpapering their envelope in 3-cent stamps and Fat Elvis.

Comment by floam 3 days ago

Half priced stamps work though, and nobody is going to prosecute grandma for counterfeiting postage stamps.

Comment by zeafoamrun 3 days ago

Yes they do. USPIS does not f around

Comment by Pxtl 3 days ago

Oddly they don't ever seem to prosecute the sites that profit from selling them. Funny, that.

Comment by kube-system 3 days ago

Makes sense to me, the only place I've ever seen them personally advertised are overseas websites.

Comment by Terr_ 3 days ago

It doesn't seem too weird to me: Selling someone fake stamps is a general act of fraud, between buyer and seller, and would be pursued by state/federal attorneys general.

The USPS becomes directly involved only later, when someone tries to defraud them by using a fake stamp.

Comment by floam 2 days ago

They are unable to do much. Look, their systems cannot distinguish them - not since the crooks figured out the phosphor tags. They aren’t detecting any during the course of business. There are no prosecutions of “duped cobsumers” buying cheap stamps claiming to be real online as far as I can find.

Comment by rrr_oh_man 3 days ago

What is your line of work, if I may ask?

Comment by al_borland 3 days ago

Why should anyone assume a product being sold by (or at least on) Amazon, the latest retailer in the country, is an illegal device?

It’s not like they’re buying these things out of a car trunk in a dark alley. These retailers need to be held liable for selling these things. If they sell this stuff, why not illicit drugs?

If they are unable to maintain control of 3rd party sellers, then they should end the 3rd party seller program. It has done nothing but damage Amazon’s reputation, and it just keeps getting worse.

Comment by nvme0n1p1 4 days ago

OTOH - TV, radio, and YouTube are all unlimited and free. Why not streaming?

There are lots of people alive who grew up during the days of broadcast TV and radio. I get why they might not understand the difference.

Comment by weberer 3 days ago

There are a ton of legitimately free IPTV streams. You can watch them through most media players like VLC without having to download anything shady.

https://github.com/iptv-org/iptv

Comment by nvme0n1p1 3 days ago

Ok but have fun explaining that to the average person. Buying a dongle is easier than installing software or typing URLs into their TV ("my TV doesn't even have a keyboard").

To most people IPTV is a bunch of gibberish letters, indistinguishable from the gibberish brands on Amazon. Someone's grandma from Colorado doesn't deserve to get scammed because she didn't research the acronyms.

Comment by kube-system 3 days ago

That is chock-full of pirated content.

Comment by crote 3 days ago

Most of it seems to be first-party streams of content which is also available as unencrypted over-the-air broadcasts.

It is paid for via ads or subsidies, so there's no reason to block access to the stream, so they just don't bother, and make life easier for anyone building streaming devices wanting to integrate their channel.

Someone accessing the stream directly is not the originally intended use case, but it isn't any different from someone accessing it via their smart tv.

Comment by nuxi 3 days ago

Two things:

- How are these "legitimately free"? For example AMC is a commercial TV channel and as far as I know, they don't offer free streaming. Same goes for MGM, FilmBox etc.

- Strictly speaking this isn't IPTV, it's just web streams. IPTV is usually delivered via multicast (MPEG-TS/RTP/RTSP streams, over UDP mostly).

Comment by 3 days ago

Comment by bluedino 3 days ago

Most people who buy these want to watch free movies, sports streams, etc that aren't on OTA or free services

Comment by Scoundreller 3 days ago

Or straight up unavailable on paid services. There’s often no way to legitimately subscribe to programming from $HomeCountry, especially if you’re not in a big Diaspora country.

Comment by Tangurena2 3 days ago

The streaming services have fractured and taken so many movies off their service so much that it is too hard for most people to figure out where that show/movie can be found.

From a link above to the story on darknetdiaries:

> For Pokemon, there is a website that tells you how to watch this. You start off on Netflix, then swap over to the Pokemon streaming service, which is the only place that has Season 2, then swap over to Prime Video for Seasons 3 through 5, swap to Freevee, then Hoopla. Season 13 is only on Amazon, though. Then swap to Tubi, then Hulu, then Roku channel, and then finally back to the Pokemon streaming, and then Netflix. Easy.

That's 8 different streaming services to view one series.

Comment by tomaskafka 3 days ago

And yet they can all be comfortably watched at a single place, with high quality and no ads.

Comment by fred_is_fred 4 days ago

If you offered most people free streaming for a $37 USB stick but directly told them it would be faking ad clicks when the TV is off, would any of them really care?

Comment by 1970-01-01 4 days ago

No, and that's is the root of the problem. The buyer is happy and so is the seller. They don't care to understand what they're allowing and everyone is allowing it to happen.

Comment by bayarearefugee 3 days ago

I wouldn't use a device like this for a lot of reasons, but the fact that what they are doing might be taking advantage of the incredibly predatory digital advertising system is neutral to positive for me, if I'm being fully honest.

If they were using the system to rip off random people, I'd be 100% against it, if they are fucking Google and the giant corps that advertise with them, ehh.. not my problem and can't be assed to care. Google is not a positive force in the world. Hasn't been for many years.

Comment by mschild 3 days ago

Wouldn't this ultimately make money FOR Google and only cost money to the company that placed the ad?

Sure, Google's paying but they get their money regardless.

Comment by chowells 3 days ago

It might damage Google's reputation with advertisers in the long term. I'm not convinced Google would even care about it, given their other behavior.

Comment by inigyou 3 days ago

Proctor & Gamble did an experiment: they cancelled all of their online advertising and watched their sales numbers. Sales didn't change. That sort of thing is downstream of this sort of thing. Online advertising is a money black hole, a sacrifice to the gods. It doesn't really do anything.

Comment by crote 3 days ago

It reduces the value of their ads.

Let's say you are an ad buyer. Previously 1M clicks resulted in 1000 sales, now 2M clicks result in the same 1000 sales. If you previously paid $1000 for 1M clicks, you paid $1/sale. If they are now asking you to pay the same $1000 / M clicks you'd be paying $2/sale, so Google would have to drop to $500 / M clicks to offer the same value to advertisers.

But the same applies to ad sellers as well. Google would have to slash payouts to websites displaying ads by the same 50% / click or they'd be cutting into their margins. A competing ad platform without fraudulent clicks would be able to slide into this space, offering both a better value to ad buyers and a better payout to ad sellers, so they'd be taking market share from Google without having to do anything themselves.

Of course that assumes a market in which the value of ad clicks, views, and placements is clear to everyone and switching between ad platforms is trivial, which is not even remotely the case.

Comment by wildzzz 3 days ago

Sure but for the ad network, it means they can brag to new clients about how many clicks they can get them. If the ad clicker isn't buying, that's the client's problem, you already did your job by getting them to click. Maybe the client needs a more direct campaign (which costs more) or needs to change their website/prices, people are walking into the store but they just aren't buying.

Its either the ad network running these click botnets or contracting someone to do it. If it was just impressions getting boosted, that just looks shady, those are barely worth anything.

Comment by inigyou 3 days ago

And why should they care? There is literally no reason they should care, it does not affect them in any way, if it causes ad companies to ban their IP address that's actually good for them personally, and most people outside of the ad business would agree that hurting ad companies is good.

Comment by pessimizer 3 days ago

> They don't care to understand what they're allowing

If you told normal people that they could get free content with a TV streaming stick that would also constantly fake clicks on AI generated websites to screw advertisers over, they would think of it as a bonus. Also it would make them trust the stick more (fallaciously), because they would know how the people who sold it were getting paid.

Comment by GolfPopper 4 days ago

They're just meeting the standards American society has set.

Comment by Scroll_Swe 3 days ago

[flagged]

Comment by dang 3 days ago

Could you please stop posting unsubstantive comments and flamebait, and also please stop using HN primarily for political/ideological battle?

These things are not what HN is for, and destroy what it is for, so we ban accounts that do them repeatedly.

If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here, we'd appreciate it.

Comment by ajnin 3 days ago

Maybe they wouldn't care about the ads but the residential proxy is another story. I'm sure lots of problematic stuff goes through that and you take the risk of being associated with it.

Comment by inigyou 3 days ago

Not really. Has anyone ever got in trouble for this?

Comment by tomjen3 3 days ago

There are probably quite a few others who consider that a bonus. I'm not going to support illegal actions, but it's also not one of the things I would really lose sleep over if I found out that it have been doing that.

Comment by pibaker 3 days ago

> it does seem like a Too Good To Be True situation

It's difficult to judge the price of media products. We have legal music streaming services that charges you an album's worth of money a month and lets you listen to millions of songs. You can pick up old AAA games for less than ten bucks. I'd say when people say that price tag, they don't think they get scammed into being a part of a botnet. They think the device manufacturer cut a good deal with the media rights holders.

Comment by joshmn 3 days ago

I had a streaming piracy site that I went to federal prison for. I can chime in on these people.

It's worth separating the two populations:

My users had money and had considered legal subscriptions. They paid me because the legal product was worse—in my case, sports blackouts, a bunch of different apps, etc. They knew what they were buying into and they had weighed the risk. I can tell you right now some of my former users have bought into this market.

Then there's the unwitting: a person buying one of these devices at a too-good-to-be-true price is treating it as a hardware purchase from Amazon, where the actual monetization isn't inferable from the listing. Calling it too good to be true assumes the buyer can see what shit they're standing in. They can't. There's no visible market here. It's just a product page with reviews.

To add to this: the proxy exit is exactly why these cost so little. Demand for residential IPs is booming (check some of the proxy subreddits to see what I mean).

The ironic part is that there's a chance the person who bought one of these boxes to watch pirated sports was the exit node I was using to acquire the feeds in the first place.

Comment by paultopia 3 days ago

Yeah, isn’t this a classic kind of scam the would-be scammer situation? If you think there’s some way to buy one cheap device and somehow get around subscribing to streaming services[1], then of course you’re going to be in a market with fraudsters…

[1] Can someone explain what the theory of the product is here? It sounds like they’re marketing these things as ways for the customer to commit fraud, for example by connecting to someone else’s login. How else would the customer expect to be able to get free Netflix or whatever?

Comment by chihuahua 3 days ago

It may be the case that these devices are front-ends for pirated content that's hosted in various places. They're not streaming it from Netflix servers. It's content similar to that offered by Netflix and other streaming services, pirated by someone else, and hosted by someone else for streaming by anyone who can figure out how to find it.

Comment by IncreasePosts 4 days ago

Maybe, but if they're a not-very-tech savvy older person buying this, they probably remember shows being free from over the air antennas and may think it is something like that.

Comment by ghostly_s 3 days ago

> they probably remember shows being free from over the air antennas

you are aware broadcast TV never ended?

Comment by IncreasePosts 3 days ago

Yes, in fact I have an antenna and a HDHomeRun nestled in my attic to record over the air shows that I occasionally consume.

But, I think it's far more common for people to have a TV service today, perhaps since comcast and their ilk push hard the TV/phone/internet bundle, and gone are the years when everyone would fiddle with the antennas on the back of their TV to get the right reception.

Comment by myself248 3 days ago

An awful, awful, awful lot of consumers think their old antennas don't work now that everything's gone digital. And they've simply never tried.

Comment by bdangubic 3 days ago

I watch TV over an antenna, shows are free still

Comment by iugtmkbdfil834 4 days ago

Uhh, I have an extended family member, who not only uses it, but now also tries to get other people to get into it. Since I was familiar with this practice ( and the issues it makes worse ), I noted those to him in an attempt to both politely decline and, hopefully, spare him, and society, some future problems. Without going into any identifying details, he didn't take it well ( and I don't think I got on my high horse ).

Anyway, I think some level of blame is warranted.

Comment by chihuahua 3 days ago

According to the Darknet Diaries podcast episode "Superbox", some of these devices are sold via multi-level marketing schemes, which would explain why there are random individuals selling these, collecting a commission for each device sold. Which is why the person you mentioned is unhappy when someone points out the problems with these devices.

Comment by elzbardico 3 days ago

I don't care about free streaming. But fucking advertisers? Humm... just found a reason to buy one of those boxes.

Comment by varispeed 3 days ago

I used to know someone doing this. They said they know it is too good to be true, but they hate corporations and it's their little way to stick one in.

Comment by croes 4 days ago

It sounds like scam

Comment by rng-concern 3 days ago

I know a few people who buy these, and they kind of know what they're doing. They just try and not think about it too hard.

It reminds me of the saying: "It Is Difficult to Get a Man to Understand Something When His Salary Depends Upon His Not Understanding It".

If these people thought about it for a few minutes, they would understand, but they choose not to, as ignoring it is too advantageous.

I admit I was tempted, as the price of all streaming services goes up, and services become more and more fragmented. During the same period where I have not had a raise.

Comment by acdha 3 days ago

In the 90s, there was a cottage industry selling CDs of bootleg software at swap meets and flea markets. A guy my dad knew was almost condescending to anyone who paid for software despite having been hit by viruses multiple times because it was so much cheaper. Even having to deal with a client(!) who naively called the vendor support only to be informed that they hadn’t actually purchased a license wasn’t enough to get him to resist that savings.

Comment by inigyou 3 days ago

On what grounds would they choose not to?

Comment by rng-concern 3 days ago

I won't argue the ethics of piracy. That was not my point, but if you want to I suppose I could.

My point was, their ethics WOULD have prevented them from doing the thing. But they chose not to think about it too hard. Perhaps subconsciously. I'm not above doing this sort of thing either. We all do it for various things.

I've added code that is bad for the user (overbearing telemetry for instance) because my salary depended on it. At the time I tried not to think about it too much, as it would cause cognitive dissonance.

Comment by flerchin 4 days ago

Well now I want one

Comment by Cider9986 4 days ago

Stremio+TorBox are the two words. ($3/month)

Comment by ghostly_s 3 days ago

That's not what these things are. They come preloaded with apps that stream pirate broadcast streams and on-demand servers operated out of China.

Comment by Cider9986 3 days ago

Absolutely correct. My comment intention was if you want to make one yourself and get the experience of all shows +movies.

Comment by ghostly_s 3 days ago

Did OP say "I want something vaguely similar that requires a greater investment of my time and money"? Did you in any way indicate that's what you were proposing?

Comment by 3 days ago

Comment by 1 day ago

Comment by 3 days ago

Comment by Cider9986 4 days ago

It could be possible, I haven't done the math though.

Stremio +Torbox is $3/month and they can probably share 10+ households on one TorBox account so it could work out. The seller could just stop paying the TorBox subscription at whatever point and they have an incentive to do so.

Comment by glitchc 4 days ago

Defrauding ad networks doesn't seem like a bad thing, although using my internet connection as a proxy is obviously terrible. It wouldn't surprise me to learn that my connection is being sold as a VPN service by the vendor.

Comment by alistairSH 4 days ago

It'll be a marginal effect, but fake clicks impacts the ad buyer, which then impacts their financials and pricing.

The only winner here is the scammers running the fake affiliate sites on which these sticks are "clicking". Or, am I missing some facet of this enterprise?

Comment by frollogaston 3 days ago

What this misses is the person buying the TV stick doesn't care about the impact on the ad market. The bigger problem is residential proxying, because their IP will end up getting used for something bad.

Comment by hnav 3 days ago

most residential proxying these days is used by the purveyors of AI

Comment by inigyou 3 days ago

And what does that cause? More captchas?

Comment by snickerbockers 3 days ago

Probably, but in the worst-case scenario you could unwittingly become an accessory to a felony if the proxy is used to access CSAM. Especially if the proxy ends up caching files.

Comment by inigyou 3 days ago

Has that ever happened?

Is Mullvad an accessory to downloading CSAM if someone does that?

Comment by snickerbockers 2 days ago

There have been cases of tor exit node operators being investigated for CSAM. Im not aware of any charges but that's the sort of thing where being in the vicinity of the investigation can be almost as bad.

Comment by elzbardico 3 days ago

They can stop paying for obtrusive ads where either they make everyone's life worse or get defrauded, save money using only ethical advertising and use this saved money to improve the quality of their products or pay their workers a little better.

Comment by ssl-3 3 days ago

Another winner is the person who gets to watch cheap digital TV, without putting together a usable antenna and limiting their reception to the broadcast channels that are nearby.

I mean: They just pay the money, plug the thing in, push some buttons, and: TV happens. Right?

Comment by cryzinger 3 days ago

You really don't want fraudulent clicks ("invalid traffic", per industry lingo) coming from your home network, because any publishers (apps and websites, per normal-people lingo) who use tools designed to block invalid traffic might start flagging legitimate traffic from your network.

Comment by frollogaston 3 days ago

Can confirm. I used to use Ad Nauseam (Firefox extension that clicks all ads), eventually stopped when I was getting captcha'd left and right.

Also, visitors on my wifi started getting strange ads. Yes I threw off the algo, but I'm a guy with wife, I'd rather get car ads than like divorce lawyers + gay dating sites.

Comment by picofarad 2 days ago

I use ad nauseam and pihole and I get nonesuch.

Comment by snickerbockers 3 days ago

Theres the question of whether or not the fraudulent advertisement clicking is using enough traffic to inconvenience or impose fees upon the user but otherwise I agree with you and am tempted to buy one just to fuck with advertisers.

Backdoors and spying are also a problem in theory except at this point you can't even trust "legitimate" companies on that front so it's a moot point.

Comment by acdha 3 days ago

> otherwise I agree with you and am tempted to buy one just to fuck with advertisers.

How that actually works in practice is that your favorite sites make less money and your IP gets a bad reputation so you CAPTCHAs or outright blocked. There’s no “sticking it to the man” here, just contributing to the frictional grind making the internet worse for ordinary people.

Comment by snickerbockers 3 days ago

You are drastically over-estimating how much fondness I have had for the web ever since social media companies and search providers colluded to drive everybody into their walled-off fiefdoms.

Comment by inigyou 3 days ago

My IP changes more than once a day. If Google captchas my whole ISP, good for them, hopefully it drives people away from Google.

Comment by DennisP 3 days ago

They make less money, but they also notice lower conversion rates on ads, which might make them rethink their strategy.

(IP reputation keeps me from doing it though.)

Comment by elzbardico 3 days ago

Frankly, I pay for most of the things I care about in the internet nowadays. Substack, Medium, newspapers, youtube premium, manning books, safari books. TV streaming.

The ad supported web is, with very few exceptions, useless.

Comment by 3 days ago

Comment by snickerbockers 3 days ago

If all they did was shove banner ads for boner-pills in my face like they used to 25 years ago I wouldn't mind and I might even turn off adblock. The problem is that modern advertisements on the internet are spyware at best and a malware vector at worst.

It's arguably fraudulent to even refer to it as "advertising" at this point, clearly that's just a cover to give them an excuse to sell data to silicon valley corporations that are unironically named after fictional devices used by sci-fi/fantasy villains to manipulate people.

Comment by kube-system 3 days ago

Fraud is also bad, even if you aren't fond of those being defrauded.

Comment by blackjack_ 3 days ago

Fraud that destroys market trust in a market that mostly deals in surveillance and selling intrusive data that was collected mostly unknowingly from the subject seems great to everyone who has any amount of integrity.

Comment by pixl97 3 days ago

So distilling an AI model of one of the big SOTA models is a bad thing now?

Comment by tjpnz 3 days ago

What about all the fraud committed by the online ad industry?

Comment by elzbardico 3 days ago

Exactly. I consider defrauding ad networks even a civic duty of legitimate resistance. The issue I see with those boxes is the risk of being involved in actual crimes due to the residencial proxy.

Comment by ColdStream 3 days ago

They took the idea of the 'Ad-nauseam' add-on for Firefox and used it for their own gains I see.

Comment by culi 3 days ago

Comment by em-bee 3 days ago

why is running a proxy a bad thing? someone profiting off it could be bad maybe, but even that is good if it pays for my subscription.

but compare running tor nodes, and especially exit nodes. that surely would be a good thing, so at least if you think tor is good then running a proxy should be the same and it should be normalized.

doing it in secret without the user knowing is what's bad

Comment by glitchc 3 days ago

Indeed without my permission is implied. Without it, you have no idea what traffic is being routed and could be on the hook for something nasty like CSAM.

Comment by Dylan16807 3 days ago

Those are different issues. Permission doesn't mean you know what the content is, and lack of permission doesn't mean they're going to load anything weird or bad. Lack of permission implies worse ethics overall, but an operation focused on clicking ads will be loading relatively normal sites.

Comment by inigyou 3 days ago

Has that ever actually happened? Has anyone gone to court for downloading child porn that was actually through a residential proxy?

Comment by iamnothere 3 days ago

No. You would not be “on the hook” for this as they implied. They are fearmongering. Even if a statute could somehow be stretched to cover it, it would be a nightmare to prosecute something like this. The media would jump all over it.

Comment by inigyou 3 days ago

That's what I thought but I want to see their evidence that it happens.

Comment by 3 days ago

Comment by corbet 3 days ago

https://lwn.net/Articles/1080822/ Do you really want to be a part of the scraper problem?

Comment by MrDrMcCoy 3 days ago

From the outside, I don't see the problem. The sites I visit, including LWN, never seem slow or have downtime as a result of this increase in traffic. I hear complaints from people hosting small sites, but they never seem to include concrete examples of downtime or measurably bad user experience. Why does it matter if the server load is high if everything stays functioning? Going from 5-20% to 60-80% load hardly seems like a catastrophe to me when the remaining headroom was not going to be used for anything else. Having your data that's public-enough to be scraped/cited/parodied/ridiculed included in a training set also doesn't seem like a problem. Are they struggling to pay bandwidth usage bills? Is there some actually-necessary intervention required to keep things running smooth, as opposed to panicking and taking unnecessary preventative action?

Comment by 40four 3 days ago

Because your home IP address is going to be associated with criminal activity. So if that’s acceptable “payment” then I guess there’s no issue

Comment by em-bee 2 days ago

if proxies are legal, then i am not associated with what goes through my proxy. ISPs ate not associated with the activity that goes through them either.

and what about tor? should that be shut down too? or is there a legitimate reason for it to use residential proxies?

Comment by inigyou 3 days ago

What concrete harm does this cause?

Comment by ta988 3 days ago

A familly member had one of those (he had to pay a yearly subscription in addition to the stick). Network would be unusable as soon as it was on for anyone else, and it also tried to scan things on the local network. It was indeed connecting to all kind of services all over the world (and saturating some tables in the router doing so which blocked other clients). Definitely evil, definitely on purpose.

Comment by deepfriedbits 3 days ago

Reading this, I caught myself wondering how we distill what's in this excellent write up into something the average consumer understands, including the dangers from buying and using devices like this.

Is it a graphic that's shared? Something else? I am sure we all know or have heard of people with these devices that promise free streaming.

Comment by Arainach 3 days ago

The bigger problem is convincing them to care. Botnets are abstract - where's the pain to them? Ad farms? That's "just hurting big corporations".

Remember, a significant portion of the population got angry (often violently so) when just asked to wear a mask to protect their neighbors. And the threat there was significantly easier to explain.

Comment by pibaker 3 days ago

Just tell the anti mask types the TV sticks come with CCP hacking software preinstalled.

Comment by inigyou 3 days ago

First you'd have to figure out what the dangers actually are. Most of what's cited in TFA and this comments section are only dangers to large evil companies, and why should anyone care about them?

Comment by ValdikSS 3 days ago

In the world of auto-updates of software and firmware, even the hardware which is now completely legal and crap-free, could convert itself to a proxy or ad network later any time.

And don't forget about counterfeit products (which look like original but different in firmware) and supply chain attack vectors, which are really, really common.

If you want to buy something as simple as a feature phone, going to a store with 10 of them will give you at least 1/10 chance to buy a phone with a trojan/backdoor.

Comment by 3 days ago

Comment by ta988 3 days ago

I warned them about the risk of those things and showed them what I found, they continued buying the next generation (that person and his two >40yo kids). They NEEDED to watch those soccer games more than they cared about security...

Comment by SecretDreams 3 days ago

You can't. This is a legitimate thing the government needs to step in and deal with on behalf of their people via legislation because their people cannot be reasonably taught to protect themselves.

Comment by inigyou 3 days ago

Protect themselves from what?

Comment by inigyou 3 days ago

If it wasn't scanning your own network or using all of your bandwidth, would you still consider it evil?

Comment by ta988 2 days ago

yes

Comment by scottydelta 3 days ago

After getting tired of ads on my PAID smart TV, 6 months ago I started building a casting device using raspberry pi for myself. A couple of months later one of my friends who is an AV technician ended up using it at the largest convention venue in Barcelona to play content on loop, here's a video of that: https://www.youtube.com/shorts/FF3I9EOs4AA.

Fast forward to last month, now I have started selling these in Barcelona, Spain where I am based out of and branched it into three use cases: digital signage, casting, and a portable computer for presentations at events. Here is the link with features: https://soljacast.com

Comment by emacdona 3 days ago

Clicked on the link, ready to buy one. “Contact sales”. Ew. No thanks.

Comment by scottydelta 3 days ago

We are literally new and only available in Barcelona at the moment which I mentioned in my comment as well. Not sure what's eww about that?

Comment by 0manrho 3 days ago

I believe they're referring to the friction point of this company/website not publicly listing a price. That's a huge barrier/red flag to a lot of people. Myself included. Last thing I want to do is waste time bouncing emails back and forth between sales just to figure out if the price range is even remotely in my wheelhouse.

However, if your target is B2B (Business to Business) as opposed to B2C/D2C (Business to Client/Direct to Client) and you're selling the install plus enterprise support, then the sales thing makes way more sense, and is more expected/palatable for B2B type customers than your everyday consumers, so depends on who you're targeting.

Comment by scottydelta 3 days ago

We are working on figuring out payments, logistics, hardware compliance (different countries have different requirements), state-level tax handling, customs clearance, etc. for D2C.

Also right now we are focusing on B2B here in Spain like you guessed, and once we have the other things figured out, we will start shipping to the US and Europe. And after that we plan on rolling out to the rest of the countries.

Comment by emacdona 3 days ago

Sorry, knee jerk reaction any time I see “contact sales” instead of a price.

Comment by scottydelta 3 days ago

No worries. If you message me via the contact form or chat support on the website, I will try my best to provide you with one. The more feedback I can get, the better.

Thanks for liking my product enough to want to buy it right away :)

Comment by crote 3 days ago

Your device seems to be an off-the-shelf Raspberry Pi running custom software. Have you considered making the platform available in a BYOD form, either for fulltime use or for evaluation?

Comment by scottydelta 3 days ago

Yes, we're using an off-the-shelf Raspberry Pi for v1. We are working on figuring out a custom board for v2, because we can't scale with Raspberry Pi as a dependency, especially with RPi prices constantly rising due to the RAM shortage.

Also, we want to test our OS extensively before we release it to be used with a BYOD model. We are launching soon and after that we will try to offer BYOD model as well.

If you are interested in trying it out and helping me in evaluation, please reach out to me via email on my HN profile. Thank you

Comment by cryptoegorophy 3 days ago

Sales friction is how you lose sales. Make your website one click purchase product page. One button - apply pay, customer pays with preset shipping and then you handle everything from there.

Comment by scottydelta 3 days ago

Trust me, I really wish it were that easy. We're based out of Spain, so to sell in the US (or other countries) we either need to figure out assembly of the device there, or we need to solve cross-border payments, logistics, customs clearance, tax remittance to individual states, and hardware compliance. That said, we're working hard on all of it and plan to go D2C as soon as possible.

Comment by throwawsy7273 3 days ago

I haven't used them myself, but it seems that services such as paddle.com takes care of the payment and tax compliance. There are probably similar sevices for logistics as well.

Comment by scottydelta 3 days ago

The thing is majority platforms like paddle.com don't supoort hardware products. I was looking at fastspring as well but hit the same wall. I will still try reaching out to paddle.com support to see if they will allow it. Thank you for the suggestion.

Comment by crooked-v 3 days ago

The "eww" part is that normally, anytime you see "talk to us for a price", that means someone is charging an absurdly high amount for the good or service.

Comment by scottydelta 3 days ago

I see, the thing is we are very new and plan on launching soon. We are still trying to figure out our B2C/D2C pricing.

Comment by crooked-v 3 days ago

I would suggest making the wording something more like "Launching soon, contact us for pre-release information". Same end result but it avoids the association with overpriced enterprise providers.

Comment by scottydelta 3 days ago

Thanks for the suggestions, I will add something like that to the website.

Comment by TiredOfLife 3 days ago

“contact sales” literally means expensive shitty product.

Comment by sajithdilshan 3 days ago

your product looks cool, but why do I need to contact sales to buy that device? can't you just open like a shopify shop and redirect end customers to that? Also showing the retail price on the page would be a plus one

Comment by scottydelta 3 days ago

Thank you for your kind words. I am pasting one of the comments I made on this thread regarding challenges with online sales at the moment:

> Trust me, I really wish it were that easy. We're based out of Spain, so to sell in the US (or other countries) we either need to figure out assembly of the device there, or we need to solve cross-border payments, logistics, customs clearance, tax remittance to individual states, and hardware compliance. That said, we're working hard on all of it and plan to go D2C as soon as possible.

For the pricing part, I am still trying to figure out the pricing for retail consumers. It was relatively easier to do for B2B but for retail, there are a lot of factors and moving parts such as import duties, taxes, shipping etc.

Comment by sajithdilshan 2 days ago

I guess it would be easier to start selling in EU and then expand. I'm looking for an alternative for my apple tv since I mostly use it for airplay looking forward to buying solijacast once it's available in Germany

Comment by scottydelta 2 days ago

If you email me (it's on my HN profile), I can send one to you the moment we are taking D2C orders. We still have to make it self-serve ready for end consumers. Really thanks for your interest :)

Comment by matheusmoreira 3 days ago

That reminds me, I need to configure VLANs in my router so that all my trusted computers are isolated from all the other garbage that makes it into the network.

Comment by russdill 3 days ago

Seems like a motivation to switch to using a VPN for such untrusted devices that still require internet access.

Comment by __turbobrew__ 3 days ago

Doesn’t help when the garbage starts proxying illegal traffic through your home ISP.

Comment by matheusmoreira 3 days ago

Yeah but at least the garbage can't attempt to exploit my laptop.

Comment by inigyou 3 days ago

What happens then?

Comment by __turbobrew__ 2 days ago

Feds come to your door asking why you downloaded/distributed CSAM

Comment by inigyou 2 days ago

Is there any evidence this ever happened?

Comment by __turbobrew__ 1 day ago

It has happened with tor exit nodes, so I imagine it is possible with shady unconsentual residential proxies.

Comment by ur-whale 3 days ago

Mmmh, I've always wondered ... as much as VLAN's are a very useful tools to - for example - route two separate LAN's traffic through a shared physical link ... are they any good when it come to security?

I mean, I don't believe VLAN's were designed with security as a goal, and I wonder how "strong" the virtual wall between two VLAN's actually is?

Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physical connection where packets from both VLANs happen to travel?

Just wondering.

Comment by rcoder 3 days ago

Depends on your networking setup. A good switch will simply refuse to route packets between clients on different VLANs, and hide the existence of the tags that determine which VLAN a host is on.

A bad switch or router (which almost certainly includes a ton of crappy home APs and routers, compromised by the same actors who ship these devices) could let clients see VLAN tags and ignore them.

And an Ethernet “hub” does no filtering at all.

Comment by rcoder 3 days ago

Also: if you need a streaming box to see your AirPlay or UPnP devices for “casting” it necessarily has to be on the same VLAN as the devices it’s connecting to. Sonos speakers have this problem when subject to client isolation setups based on VLANs or switch-level packet filters.

And any kind of multicast (used for local service discovery and media streaming) has the same limitations.

Comment by xorcist 3 days ago

Network switches typically aren't known for their outstanding security record, but the vlan tags themselves are trivial and should be hard to mess up. Should someone hack your switch all bets are off, but as long as you don't have management accessible in-band you should be fine. Security problems are more likely to stem from bad configuration.

> Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physical connection where packets from both VLANs happen to travel?

That would be an exceptionally weird configuration. If a device "sits on VLAN1" that typically means that it's on an "untagged" port where only VLAN1 traffic is allowed. Ports that carry multiple VLANs are "tagged" ports and you normally wouldn't say they "sit" on any specific VLAN, precisely because that port carries tagged traffic for multiple VLANs. It's at best an irregular use of the terminology but likely a misunderstanding somewhere.

Comment by inigyou 3 days ago

A VLAN is a virtual LAN. having two VLANs is like having two LANs but without as much duplicated wiring. It's quite well-supported and reliable.

You usually want to interconnect them at one central point, usually a router, and enforce a security policy there.

Comment by ahahs 3 days ago

this is a good question, i asked claude sonnet 5 and the answer is too big and complex for me to type out on mobile. but long story short, you absolutely need separate VLANs and Firewalls in conjuction to secure traffic between networks

Comment by matheusmoreira 3 days ago

Yeah, I've been using Claude to help me secure my home network. I applied to Anthropic's cyber program and got accepted despite being a hobbyist. I'm not very good at networks so I'm gonna try to make the most of it.

Really wish I could point Mythos at my router and just loop it until my router becomes literally unhackable.

Comment by TylerE 3 days ago

Making your router unhackable is trivial. Just pull the AC cord. You didn't specify that it had to be useable.

Comment by skinfaxi 4 days ago

Thankfully this seems limited to a specific device (H96). Darknet diaries has a good story about streaming devices https://www.youtube.com/watch?v=dS6PkuZuxJ4

Comment by krebsonsecurity 4 days ago

It's not just one device line; Have a look at the list maintained by the proxy tracking service Synthient, which tracks streaming boxes, digital picture frames and other IoT devices that have been known to bundle residential proxy software, among other malicious apps. They currently track almost 1,000 different makes and model numbers.

https://github.com/synthient/public-research/blob/main/2026/...

Comment by SoftTalker 3 days ago

> Despite repeated warnings from the FBI and security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands

I scanned the comments and I didn't see anyone suggesting that these companies should share any responsibility for selling these harmful products. Why is it that they seem to get a pass? Would we feel the same about giant retailers selling tainted food, or unsafe children's toys?

Comment by al_borland 3 days ago

One of the main value propositions for retailers in a world of endless cheap garbage being sold online, is to vet products so customers can trust that what their buying is from a legitimate company and not junk or stuff like these streaming sticks.

This is the problem with being an “everything store”. “Everything” includes a lot of things most consumers would like to be protected from, and assume they are due to the long history of retailers standing behind the products they sell. That history seems to have come to an end. They only stand behind it enough to offer a refund if there is a problem, not to ensure it’s good before selling it.

Comment by omilu 3 days ago

Costco vets their products very well, if I see something at costco and its something I need I just buy it. No need to research and I've never been burned. They only sell good quality stuff.

Comment by femto 3 days ago

Check their tomato paste. It turns out that nearly every tomato paste in Australia comes from Xinjiang in China, including those marked as Australian or Italian. Simplot (Leggos), the big US company, was the worst offender, so it's possible that tomato paste in Costco's US stores has been produced in Xinjiang using slave labour, irrespective of what the label says.

https://www.abc.net.au/news/2026-07-27/australian-tomatoes-l...

Comment by onionisafruit 3 days ago

According to this none of the samples tested from US retailers contained Chinese tomatoes. https://www.bbc.com/news/articles/crezlw4y152o It seems like the US ban on Xinjiang is working

Comment by femto 3 days ago

Thanks for that informative link. I looked to see if there was any data beyond the ABC article and didn't find it. Some of the truthful brands listed in the BBC article are available where I live. Kudos to the US that their labels match their contents.

Comment by stubish 3 days ago

The ABC just broke their story a few days ago. There will continue to be fallout over the next few months or years (much like their last one, where they found that many sunscreens did not meet their SPF ratings, a hot topic in the skin cancer capital of the world)

(edit: whoops, Choice did the SPF rating investigation. ABC just did a lot of reporting on it)

Comment by biztos 3 days ago

While it could of course be produced in Xinjiang without using "slave labor," the US government banned those tomatoes in 2021 because of that risk:

https://www.cbp.gov/newsroom/national-media-release/cbp-issu...

If Costco were circumventing the ban it'd be a pretty big deal. I couldn't google up any indications that they are, so on balance I'd say it's "possible" in the same way my winning the lottery is possible. Can't rule it out, but reasonable people should probably bet against it.

TIL: Xinjiang tomatoes are something like 15% of the global market!

Comment by seanmcdirmid 3 days ago

> TIL: Xinjiang tomatoes are something like 15% of the global market!

China consumes 37% of the world’s tomatoes. 80% of China’s processed tomatoes are from xinjiang. Fresh tomatoes are generally grown locally, but that is true around the world.

Comment by LordAtlas 3 days ago

China _produces_ 37% of the world's tomatoes, not consumes.

Comment by seanmcdirmid 3 days ago

[dead]

Comment by Nursie 3 days ago

> It turns out that nearly every tomato paste in Australia comes from Xinjiang in China

I think that might be a bit of a strong assertion, from your article there -

"It analysed 221 processed tomato products from 39 brands, including paste, passata and diced tomato.

Twenty-two per cent of the products failed country-of-origin testing, while a further 6 per cent were flagged for further testing."

So while 28 percent is scandalous, and those companies need to face consequences, the other 72 percent seem to be genuine.

Comment by femto 3 days ago

A big chunk of that 72% are legitimately labeled "Made in China" or niche brands. The brands that failed, plus the products that are actually labeled "Made in China", dominate Australia's four supermarkets with the majority of the market share. I've just done my weekly shop, so trawled their web sites looking for alternatives.

Summarising the Australian situation, taking the 4corners results into account, the following non-Chinese tomato pastes are available:

Coles (29% market share): 1 x 140g premium product in a tube (expensive with reduced market share) out of about 20 products.

Woolworths (38% market share): 1 x 140g premium product (Mutti) in a tube (expensive with reduced market share) out of about 20 products.

Aldi (10% market share): None out of about 4 products

IGA (7% market share): 5 of 16 products, being the same premium brands that Coles and Woolworths sell.

Maybe qualify my comment with "by market share and availability". The effect is that if you stand in front of an Australian supermarket shelf, every product, bar one or two in the corner, come from China. China is a proxy for Xianjing, in that sources say 80%-90% of tomato paste from China comes from Xinjiang.

Hence the assertion I made.

Market share data: https://www.accc.gov.au/system/files/supermarkets-inquiry_1....

Xianjing percentages: https://tomatonews.com/countries/china/

Comment by Nursie 3 days ago

> Woolworths (38% market share): 1 x 140g premium product (Mutti) in a tube (expensive with reduced market share) out of about 20 products.

Eh ...

"Well-known tomato brands that passed country-of-origin testing include Mutti, SPC, Woolworths, Providore D'Italia and Annalisa. Diced tomato cans and passata from Leggo's and Coles also passed."

So here are 4 tomato pastes in woolworths that would seem to pass the test of not being from China and not being liars, just from a quick search (and I have seen all these in my local) -

https://www.woolworths.com.au/shop/productdetails/290303/mut... https://www.woolworths.com.au/shop/productdetails/218066/mut... https://www.woolworths.com.au/shop/productdetails/901431/mac... https://www.woolworths.com.au/shop/productdetails/150875/pro...

I usually buy Mutti stuff because it's low-ish salt, and that claims to come from Italy and wasn't implicated in the report here. And while I understand those are at the 'premium' end, it's not like it's one product on the end of the shelf either.

It's true that "Leggo" occupies a lot of the shelf space and a lot of the cheaper 'own brand' stuff is labelled as coming from China. And coles appears to be in a weirder/worse spot that woollies, with only Providore being Italian and two brands of turkish tomato paste, which is interesting.

It's sad that I can't find an Australian tomato paste that isn't a liar.

So I'm still not fully on board with "nearly every", OTOH thanks for the further information. I shall continue to try to avoid these products!

Comment by p-e-w 3 days ago

The above thread was about quality issues, not ethical issues such as “slave labor” (a term somehow reserved for certain countries, even though most countries use unfree prison labor, including the US and much of the EU).

Comment by iamnothere 3 days ago

Our vocational training program, your prison labor, their slave labor.

Comment by femto 3 days ago

It's about trust.

Comment by perpetuallunch 3 days ago

Difficult to distinguish between actual slave labour and China-is-bad propaganda.

Harm to the end user: none^

Benefits to the end user: more affordable tomato paste

Government action to prevent slave labour products entering Australia: none^

^close enough.

Comment by stubish 3 days ago

It is perfectly legal to sell Chinese tomatoes in Australia (which is not necessarily a good thing, re: forced labour in Italy and China). The fraud is mislabeling them as Australian or similar, denying consumers from making their own ethical choice. Which is your harm to the end user and generally enforced by the ACCC.

Comment by kkotak 3 days ago

If you're going to start talking about mislabelling products, you're going doing a rabbit hole of hundreds if not thousands of products sold in reputable stores. Look up how FDA labels for Organic, Grass fed, Pasture raised, etc. are used through out the industry in the US and the world. You should also look up the requirements for "Made in X" labels for consumer products. Playing with word and people's emotions on what those labels mean when making a purchase decision is as old as commerce itself. Don't for a moment think of the US or a Western country being rightious about this.

Comment by stubish 2 days ago

How the FDA and US labels things is not relevant to Australia with its more consumer focused laws and the ACCC.

Comment by perpetuallunch 3 days ago

The information this is based on is reporting from the Australian ABC TV program Four Corners.

The ABC is a know, as in they don't even try to pretend propriety, propaganda outlet of the Australia Albanese federal Government.

I'm not saying this is definitely propaganda, but there's a non-zero chance it is.

The Albanese government has been very open about attacking industry.

Comment by stubish 2 days ago

It is anti-industry to report fraud and provide evidence to government enforcement bodies and shame them into acting? This is anti-government propaganda if anything, given the lack of proactive monitoring and serious enforcement. If anyone in politics benefits from this it will be One Nation or maybe the Nationals if they pick up on the Protect Australian Farmers angle, while sitting government gets to explain why they had failed to acknowledge the problem or act. The forced labor issue will be a particular thorn in their side, given it is one of the excuses for the latest round of US tariffs.

Comment by martimarkov 3 days ago

Negatives to end user: unknown pesticides or banned pesticides.

No propaganda - lack of validation, evidence and trust

Comment by perpetuallunch 3 days ago

What does slavery, real slavery or anti-China propaganda fake slavery, have to do with the with the presence or absence of pesticides, banned or otherwise?

Comment by neves 3 days ago

Chinese workers earn more than workers from latin America. At least their government isn't slave for billionaires

Comment by riddlemethat 3 days ago

We bought a Bosch dishwasher from Costco in January. It was defective and wouldn’t start after 10 days. Costco replaced it. The replacement came with a big gash on the front off the truck so we refused it and Costco sent a third replacement. Again, it was the same model and again it wouldn’t start after another 30 days. Costco took it back. No cost to us for any of these delivery or install attempts.

We bought a different model from Costco and it’s been rock solid. I expect I will never buy a major appliance from any other retailer as long as Costco continues to care like they do today.

Comment by fn-mote 3 days ago

> I will never buy a major appliance from any other retailer

Weird. You experienced failures of the manufacturer (failure to start) and the warehouse (huge scratch), and are still singing someone’s praises.

It sounds to me like the brand’s quality assurance is low and the retailer also isn’t taking care of their stock.

If I had to take three days off work to accept these deliveries, doubtless I would have a very different conclusion from yours.

Comment by dsr_ 3 days ago

He's singing the praises of CostCo, which made him whole.

Any dishwasher could have these problems; any warehouse could. How the seller handles the situation is key to whether you use them again.

CostCo has built a huge reputation for being trustworthy as a retailer. If they get purchased by private equity, I will stop renewing my membership, and think about how close the country is to decorating lampposts.

Comment by 542354234235 3 days ago

The issue is that with a sample size of one (or three), then it is basically bad luck. If you get a bad unit (or a good unit) it doesn't really tell you much how reliable the other 100,000+ units are and how reliable the brand is. If you have a product get damaged during delivery, it doesn't really tell you much how reliable the other 100,000+ deliveries are.

But most people have had a problem with some product they purchased and a company that stands by things and gives no questions asked support is very valuable.

Comment by rpdillon 3 days ago

Yep, I'm pretty much a lifetime member of Costco if this sort of prioritization doesn't change. A recent article put it well "Costco is the anti-Amazon".

I say this as a happy customer of both, though. I don't seem to have the problems others do with horrible products from Amazon, but I suspect my purchasing habits might be different as well.

Comment by _RPM 3 days ago

> I will never buy a major appliance from any other retailer

That's called stinking thinking.

Comment by Guvante 3 days ago

No one means that in the literal sense BTW it is shorthand for.

"The next purchase I make will be through X to avoid having to search for a new retailer"

Comment by contagiousflow 3 days ago

What is the alternative? Trust has been built, as long as the trust is not eroded it is safer than any other retailer?

Comment by 40four 3 days ago

I don’t disagree, Costco has a reputation for selling well vetted products, but that’s not a good comparison. I trust Costco (even their online only sales), but in no way do I trust the other merchants listed.

We’re specifically taking about merchants that have a super shady online presence. They will basically sell you anything and everything and don’t care if it harms you.

The ones mentioned (Amazon, Best Buy, New Egg), it’s going to be hard to argue they vet (or care about vetting) the digital products they sell. You might as well throw Walmart into group too, their online offerings have gotten super sketchy if you really do into it.

Comment by Uvix 3 days ago

Target as well. It was one thing when it was just Amazon acting as a sketchy third party storefront, but now everybody’s doing it.

Comment by SoftTalker 3 days ago

And third party listings on Walmart or Target (and throw eBay in here too) often end up being fulfilled by Amazon. These sellers just list their stuff on all the sites and effectively use Amazon as their drop shipper.

Comment by bell-cot 3 days ago

Compared to the big e-commerce retailers, Costco's total number of sku's isn't even a rounding error.

And most of Costco's sku's are food, clothing, housewares, bulk consumables, and such - vastly easier to test and vet than computer & internet-connected electronics.

Comment by ChoGGi 3 days ago

Sounds like you're agreeing that Costco is well curated?

Comment by bell-cot 3 days ago

Compared to Amazon and other e-tailers with hundreds of thousands of sku's of computer & internet-connected electronic stuff, 99% of which they do nothing whatever to curate? Yes.

But that's kinda like saying that Random Pond is safer for swimming than a lava lake.

Do I just assume nothing can go wrong when I myself shop at Costco? NO.

Comment by altruios 3 days ago

Costco isn't perfect, and things slip through still.

For example: this is a minor annoyance, but comes readily to mind.

https://www.costco.com/p/-/orgain-organic-protein-and-superf...

The problem is labeling conventions leading to inaccurate assumptions of what's even IN that "protein powder"...

you would think the protein, being the largest in print, is the primary ingredient but no. A serving is 51grams, and the protein makes up 21grams of that serving: less than half, that's not a 'protein powder' if the primary ingredient isn't protein.

It should be labeled "SUPERFOODS with protein" not the other way around.

There have been other things similar in scope less readily recalled. It may seem minor to some... but labeling accuracy and transparency is something we had to fight for collectively.

Comment by tejohnso 3 days ago

A 51 g serving might contain 40 g of the protein blend, making it a protein powder as the primary ingredient is protein blend.

However, this is plant-based protein, not pure way isolate. A plant-based protein powder from mung beans for example isn't going to be 100% protein. Chickpea powder contains roughly 20% protein.

So I don't know if that helps at all, but it doesn't seem as bad as you and you might be suggesting.

Comment by al_borland 3 days ago

Ingredients are listed in order from greatest to least amount. Protein is listed first. It seems it’s the creamer that throws off the ratio you’re looking at, which I’m assuming is there for consistency/taste.

Comment by tiltowait 3 days ago

The first ingredient is a plurality, not a majority.

Comment by Rickasaurus 3 days ago

I have to disagree, costco often has custom worse versions of better products, we recently had a costco air conditioner fail just to find out it wasn't built quite as robustly as the $50 more expensive midea sold elsewhere with an almost identical model number. Similarly had my costco GE washing machine fail last year right out of warranty. There's a real quality problem going on with costco right now.

Comment by onemoresoop 3 days ago

They’ll replace them if they break and the return policy is very good as well. It’s safe to buy from Costco

Comment by red-iron-pine 3 days ago

arguably it's part of their main value proposition: bulk, but not terrible, and generally decent.

fixed fee membership also means a very stable revenue stream and they can take the time to do this, while other places like newegg are herding 3rd parties to get cuts of ever cheaper 3rd party crap

Comment by Aerroon 3 days ago

You go to an online store to buy a hard drive. It's listed as "in stock" and you buy it and pay for it. A week later you get an email from the store that the specific hard drive is now available at a third party warehouse and they can order it from there, but the price is about 10% higher.

The above actually happened to me. That's what online retailers were like before Amazon's reach properly extended here. That's also the main value proposition for these retailers for me.

Also, online retailers are far more likely to accept returns compared to regular stores. If you get a bad product from a regular store you're often just screwed.

Comment by swatcoder 3 days ago

The late-Amazon process for this is to just send you whatever's marked as the hard drive in their warehouse, which may be that actual product, a counterfeit, or a brick in the hard drive's package.

Later, when you want to try the return, a black box algorithm asseses your transactional value to Amazon and decides whether your concerns are worth attending and to what degree.

Maybe that really is better than whatever you were used to in your own market, but it's a profound regression on the traditional retail experience for most of us here.

Comment by ephemeral67 3 days ago

interesting bit of information: most EV mower companies now do not provide replacement parts - if a mower dies within warranty, a 'certified' warranty repair shop does basic troubleshooting, and if it's beyond a piece of cheap plastic, the mfr just ships a new mower to the 'repair shop'. Once out of warranty, you're on your own.

Comment by bdamm 3 days ago

My electric mower has lasted longer than the gasoline mower before it, which literally had plastic valves inside the carbeurtator.

Comment by bluGill 3 days ago

There is a big difference in quality levels. If you want a good mower pay the price for a commercial mower, people who use them 8 hours a day need something that lasts.

30 years ago a friend of mine did the mold for a lawn mower. They put an engine on it and it ran for 120 hours before the deck failed. It took 7 more tries until the deck failed after 80 hours. Commercial mowers are expected to run over 1000 hours.

Comment by bigiain 3 days ago

I remember asking a chippie (carpenter tradesman) a while back why he was using Ozito brand power tools (the cheapest Chinese brand from the local tool barn). He said "The good gear like Milwaukee and Makita last years. The cheap Chinese junk lasts maybe six months. Whatever I buy it gets stolen about every 3 months. I'd rather have a spare $40 drill waiting at home when my van gets broken into, than have to go buy another $600 Milwaukee one that I'd otherwise rather be using."

Comment by zdragnar 3 days ago

Counter anecdote, I've had gas mowers survive decades and EV electrical equipment (in this case, a chainsaw and a battery pack for a mower) both die within 14 months of purchase.

Comment by Slash65 3 days ago

This is my experience as well. String trimmer battery went out (still in warranty and replaced) but my gas string trimmer I use at a bigger property came home with me and worked great. She’s only 15 years old, the battery was 6 months. I love my battery blower and string trimmer, but the gas ones are going strong but typically stay at the ranch property due to it being a bigger property to maintain. I would also need 3-4 battery’s out there to keep up with maintaining it, the gas is a whole lot cheaper than a grands worth of battery’s.

Comment by taneq 3 days ago

Counter counter anecdote, I was just tidying up the yard with my 18V whipper snipper and contemplating the fact that I bought it in 2012 and it hasn’t skipped a beat.

Comment by HDBaseT 3 days ago

I have a mower that my dad gave to me, which his dad gave to him.

It is in rough shape, but it still cuts grass perfectly fine.

I have a wippersnipper from before I was born which runs perfectly today. It was left out laying sideways in the rain for about a month. Quick clean and a new plug and it was going again.

I'm sure the electric devices can run a long time, but when they fail, they tend to be not repairable.

Comment by markdown 3 days ago

Makita, amirite?

Comment by taneq 3 days ago

Ryobi, but I have plenty of Makita gear too. :)

Comment by zhengyi13 3 days ago

Old Ryobi, or new Ryobi?

Serious question, as I understand the ex-Japanese market rights were sold to a Chinese corp over two decades ago, and the in-Japanese consumer device market rights went to a different Japanse company several years ago too.

Apparently they've gone back to focusing on their roots?

Comment by lazylester 3 days ago

almost all 2-stroke engines have had plastic flapper valves and a plastic fuel pump for as long as I can remember.

Comment by taneq 3 days ago

I think that’s “most mass produced item manufacturers”. It’s just cheaper to ship a new one than waste time trying to troubleshoot.

Comment by MostlyStable 3 days ago

These are the kinds of products I now just straight up refuse to buy.

Comment by drnick1 3 days ago

Thank you for reminding us that electric mowers are garbage.

Comment by classichasclass 3 days ago

My wife derides my Home Despot special plug-in mower as a Tonka toy, but it's basically just a motor, a blade and a bag, and I don't have a lot of lawn to mow.

Comment by nullhole 3 days ago

I mean, not all of them?

Mine's a fancy-pants Stihl battery mower, but it works quite well and has been doing so without problem since I bought it ~4 years ago. The other battery stuff from the same brand (trimmer, chainsaw, kombi-tool) have the same story.

Comment by bluGill 3 days ago

Stihl is a commercial product (mostly). They design for people using them as a full time job. You pay the price for quality.

Comment by zrobotics 3 days ago

No, they definitely have homeowner grade tools available.

For instance, the MS182 [0] is a $270, 2.2cu in saw with a 16" bar listed "For homeowners and light duty work".

Meanwhile, the MS201 [1] is $1100 for a 2.1cu in saw with a 16" bar listed as "The lightest professional gas chainsaw from STIHL Perfect for delimbing work in forestry".

Service interval on the 201 will be much longer, and it's expected to last longer but is priced accordingly. I ended up having to buy one of their homeowner grade saws 10 years ago when I was up in the mountains and my saw died, that was all that was available locally. I'm certainly not a professional, but at the time my primary heat source was wood and I had always used the stihl pro-grade saws. However, that cheap stihl was an absolute piece of junk, it was half wore out after cutting 2 cords of firewood that first time. Terrible ergonomics and poor power to boot, even after reserving the saw for light-duty work it only lasted 2 years and was miserable to start and run the entire time.

At least they explicitly say that they are for light duty though, a less honest company would market everything as pro-grade. But don't just buy the name, while they make good quality products they also sell cheap crap under the same name. It also isn't that clear in a retail store besides the price which ones are the homeowner grade saws.

[0] https://www.stihlusa.com/en/p/chainsaws-ms-182-gasoline-chai... [1] https://www.stihlusa.com/en/p/chainsaws-ms-201-gasoline-chai...

Comment by nullhole 3 days ago

Yeah, mine are the AP ('professional') class ones.

What matters is the amortized cost per year, I think - more expensive up front but cheaper in the long run.

Comment by timc3 3 days ago

My Makita one is excellent.

Comment by newAccount2025 3 days ago

Why? Mine is great. And light. And QUIET.

Comment by bigstrat2003 3 days ago

They really aren't particularly quiet imo. Yes, there's no motor, but it turns out that the whirring sound of blades rotating and cutting grass is quite loud even without a motor. I would say mine is perhaps 3/4 as loud as a gas mower, which isn't a very impressive reduction in noise.

Comment by maxerickson 3 days ago

With logarithmic perception, it's about a 50% reduction in sound energy.

My battery mower is quiet enough that I don't feel terribly rude mowing at twilight.

Comment by astura 3 days ago

I love mine.

Comment by Gigachad 3 days ago

Everything is garbage now. It’s the end state of unrestrained capitalism.

Comment by exe34 3 days ago

Surely not, the invisible hand of the market should crawl up their arse and make them do the right thing any day now.

Comment by actionfromafar 3 days ago

The invisible hand crawled up the arses of Congress and seems to enjoy it there.

Comment by 3 days ago

Comment by jon-wood 3 days ago

Amazon even have big "people commonly return this product" warning on some product pages. Anywhere halfway sensible would maybe reconsider stocking a product worthy of that but because they've set themselves up as a middleman without any of the risk they can just churn junk out of their warehouses.

Comment by zombot 3 days ago

Crooks will be crooks, but that the lawmakers let them get away with it is something that should change.

Comment by deaton 3 days ago

Online it still seems like for the most part if you buy from something a bit more specialty (e.g. McMaster, Digikey, etc) you still get really good vetting and high quality stuff, but amazon is more than happy to be filled with absolute garbage.

Comment by boondongle 3 days ago

Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold. They certainly don't advertise to the big box retailer that buys them "and it uses the customer's internet connection for fraud."

Hell, there's a section of comments that would probably going "hey, RELAX guy" because it's not US companies doing this. For any American companies that do this though, sure - block/suspend/prosecute.

Comment by malfist 3 days ago

If I open my own line of home improvement stores and do no oversight on what I sell and wind up selling really dangerous lawnmowers, I'm partly responsible.

Or if I open up a gas station and allow any company without oversight to sell "supplements" through my shelves and cops arrest me for selling heroin, I don't get a free pass.

Why should amazon or Walmart get a free pass just because they sell more items?

Comment by awakeasleep 3 days ago

One problem I see with your analogy is that the dangerous lawnmower can cause an easily quantifiable harm.

You have to be able to show damages you incurred and assign a dollar value to them to sue people.

That doesn’t work at all for a something that sells your bandwidth to a proxy service. People wouldn’t even be aware that it was happening they weren’t told.

Comment by SoftTalker 3 days ago

What about when the police show up because some highly illegal content was traced to your IP address? Will they believe that you were the unwitting victim of a rogue proxy server running on your streaming stick? Would you have even been aware of that possibility?

Comment by ndsipa_pomu 3 days ago

That shows the problem or trying to link an IP address to an individual.

Comment by xorcist 3 days ago

There's also always the flip side: When the police shows up because of your illegal acitivities, you have a rogue proxy server running. All bought in good faith of course.

Not legal advice.

(It would surprise me greatly if we as a society let these gadgets be sold openly from here on.)

Comment by inigyou 3 days ago

Believe it or not, that is what happens when the police show up to the house of a primary school teacher. They will think they have the wrong address. Even US police.

The cybercrime raids happen when they run into someone who looks like a hacker and has a lot of computers.

Comment by II2II 3 days ago

> If I open my own line of home improvement stores and do no oversight on what I sell and wind up selling really dangerous lawnmowers, I'm partly responsible.

While there would be oversight, it is highly unlikely that a person opening a home improvement store would perform any meaningful safety testing. They simply would not be qualified. The oversight would lay in selling certified products, pulling recalled products off the shelf, and (perhaps) removing products if there is a reason to suspect safety issues.

Now consider streaming sticks. There are safety standards for the physical device but, to my knowledge, there are no such standards for the software itself. Heck, there aren't even standards for the engineers who work on the software. One can make highly prejudiced decisions based upon the country of origin. Perhaps there are even good reasons to avoid products from certain countries. Yet the lack of standards also means that products from trustworthy sources can be suspect, since all it takes is a management decision to change things.

Comment by inigyou 3 days ago

But these products aren't dangerous. And proxying internet traffic isn't illegal. Fake ad clicks may be illegal but that falls on whoever is providing that service, which isn't the proxy or the resident. On what basis would you ban them?

Comment by wsintra2022 3 days ago

Except the devices are not dangerous. Its the software installed on the device. Consumers have a choice. Pay for the trusted Apple TV or Amazon firestick, or go the wild west and see what's on offer.

Comment by CrazyMusicians 3 days ago

with the devices mentioned in the article, there is no consent requested, and the malicious apps are installed either before the box is sold or after as a requirement for getting the streaming services to work.

Comment by inigyou 3 days ago

You call them malicious apps but what is the evidence they are more malicious than the things they fight against?

Comment by jon-wood 3 days ago

Really? You'd be ok with me putting a proxy server on your home network then, which anyone with a few bucks can use to attach your IP address and subscriber details to anything they choose to request from the internet? How about a Tor exit node?

Its incredibly obvious to anyone applying any thought at all to this that its a malicious to sell a product that labels itself as a TV streaming stick which is in fact a paid for relay server with the money made from providing the internet connection to a random third party unrelated to the person who bought the thing without ever telling the customer.

Comment by inigyou 3 days ago

Yeah I actually do several of those to earn a few bucks.

Comment by jon-wood 3 days ago

The typical consumer has no idea what they're buying, and they shouldn't have to because the retailer selling the product should have done some basic due diligence before stocking the thing. People aren't going to some clearly shady Chinese website and buying a device labelled "cheap TV streaming stick, will sublease your internet connection to criminals", they're putting "FireTV" into amazon.com and somehow being presented with these things alongside the Amazon FireTV they expect to find, or maybe "streaming stick" which really shouldn't be surfacing clearly malicious products.

Comment by inigyou 3 days ago

If the average consumer did get a disclaimer it would sublease their internet connection to a few criminals and a lot of people who aren't criminals, would they care?

Comment by crote 3 days ago

> Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold.

You already answered it: block it from being sold.

1) Make Amazon responsible for the products they are selling. 2) Introduce a law banning malware tv sticks 3) Sue Amazon for a percentage of their yearly revenue when caught violating it 4) Amazon will finally start caring and do some kind of review on the crap they sell.

Comment by pixl97 3 days ago

And if the first time you get it online it just updates itself to malware?

That's the biggest problem with any device that updates.

Yea, this will work for the moment and the seller will be covered in the sense that "well, it wasn't infected when we sold it".

Comment by deaton 3 days ago

The law is not software. It would be very easy to argue that a streaming stick that automatically downloads malware is no different from one that came with malware.

Comment by pixl97 3 days ago

And that's where the retailer is no longer in the loop, which is what this thread was about.

Comment by themaninthedark 3 days ago

I think a law that makes a marketplace responsible for items being sold if the qty of items is above a threshold would be a great idea.

You don't want to penalize someone selling their Xbox or lawnmower on Ebay but you want to stop what is going on here. A place like Etsy where people are selling their crafts is an interesting edge case but I think they should probably be a little regulated.

Comment by StilesCrisis 3 days ago

If it's malware, maybe existing laws apply already. I think the bigger problem is enforcement. In China, it's easy to close up shop if anything goes wrong and then just start over. Any liability dies with the brand name.

Comment by AngryData 3 days ago

But it is a retailer's responsibility to know what they are selling. If it was added after they started selling it and hidden in secret, sure a retailer might have an excuse. But it isn't really hidden, most often its put in their marketing materials as a benefit and have been knowingly doing it for many years now.

US retailers can be told they can't sell it here. If you buy it outside of that, well that is buyer beware, but 99% of people aren't buying things from Alibaba or ordering from some random foreign store, they are buying them off US Amazon, Walmart, big box retailers, etc. You don't have to ban things consumer level to deal with 99% of it, you just gotta tell big corporations no and stop dismissing any ideas that put responsibility or liability on big business.

Comment by crote 3 days ago

The problem is that Amazon, Walmart & friends have said the "we are a platform, not a retailer" magic incantation, which means that through the power of friendship and unicorns they are now suddenly no longer responsible for the stuff they sell.

And the "retailer" on record is of course not a real company. They'll just pay some third-party to file a bunch of paperwork in Delaware, pay the $110 fee, and let it go bust if anyone tries to investigate it or make it liable.

Comment by pixl97 3 days ago

>If it was added after they started selling it

While it's great we're getting the manufactures to just stop sending out straight malware and it should be stopped the next most obvious means of attack is just having the device update and add superaids to it's new functionality.

So, no, it won't stop 99% of it at all.

And honestly this isn't that much different from what US companies are already great at by providing updates that take away features we bought with the device.

And not just updating really doesn't save you, instead of being part of a factory botnet, you're just open to become part of some other botnet.

Comment by skybrian 3 days ago

The FCC tests electronics for radio interference. Perhaps they could test electronics for Internet behavior like this too?

Some manufacturers will try to cheat on the tests, but we have AI security checking now, so maybe that would make it harder to cheat?

Comment by iamnothere 3 days ago

That sounds like a fast track to government control of what operating systems are allowed. These aren’t just electronics, they are low power computers that happen to have an OS and software preinstalled.

(I’d be open to a rule that devices must allow users to wipe the devices and install their own OS.)

Comment by skybrian 3 days ago

On the other hand, I suppose if the OS on a TV stick ran in a hardware-enforced sandbox that restricted network access to certain necessary domains, it couldn't be used for scraping websites and ad fraud? It's not being sold as a general-purpose computer so maybe it shouldn't be one.

Comment by lesostep 3 days ago

Simple. Buy one, put it on a test stand, and look at connection log.

Buying in bulk for a resell without testing even one product is kinda insane.

Comment by ChuckMcM 3 days ago

In the US at least there is a lot (and by that I mean like maybe more than half) of civil case law around seller liability for defective or 'dual use' products. In the 70's some cities tried to sue hardware stores for selling spray paint that taggers were using, in several jurisdictions you can find authorities trying to sue vendors of lock picking and/or safe opening tools, etc. My non-lawyer reading of all that is that if it is reasonable to assume that the vendor didn't know, at the time of sale, what the customer was going to do with it, they aren't liable.

Once a vendor has been notified that these units are doing these sorts of things they will stop selling them. Its sadly very prescriptive in that if Newegg gets a notice that "WatchFunTV" streaming sticks are doing this, they will remove that brand but if the same hardware shows up from the same vendor as "SuperTVStreamer" or some such, that product won't be banned until someone does the test and then notifies the sellers. It's cat and mouse all the time.

Now the people who could do something about it, the ad networks like Google, do not do anything because ad revenue is ad revenue, people buying the ads cannot prove that the click was false so hey who can say it was? Which is why ad fraud is a perennial favorite of crooks. The people being ripped off don't have any way to prove it without a lot of support from the ad network traffic data which is "proprietary". Really stupid ad fraud gets shut down, but put a bit of care into it so that the Ad network and claim ignorance? You can do that all day. Just don't get greedy and try to pull in more than say 30 or 50 thousand dollars a month. Remember, the IAB said in 2025 alone Ad Revenue was $300B[1] so 2% of that is only $6B and any network with 2% or less of undetected fraud is considered a "high quality" ad network.

So yeah, ad fraud is the gift that keeps on giving.

[1] https://www.iab.com/insights/internet-advertising-revenue-re...

Comment by mattmcknight 3 days ago

This is why I hate the "marketplace" of these stores. In many cases these products never hit their inventory at all, they are functioning like a search engine and payments processor.

Comment by eddythompson80 3 days ago

That’s generally in their definition. “Amazon Marketplace” came out in 2000 allowing 3rd party sellers on their platform. However, until maybe the mid 2010s, they favored product sold by Amazon over 3rd party in their results and recommendations. I remember numerous forum and Reddit posts from the late 2000s about “How Amazon scams 3rd party sellers” by only wanting them there to give the illusion that they have everything but once some category starts selling, they will vendor it too and steal your customers.

At some point in the second half of the 2010s Amazon figured out they can’t compete with a million foreign randomly-generated companies on price, and their users didn’t seem to mind too much. They figured their users cared about delivery times, ease of returns, ease of dealing with Amazon instead of dozens of online sellers, etc and they leaned heavily into that. They will handle fulfillment and take their cut and let people buy whatever garbage they want. They still screw sellers too btw. Ask any one who is trying to sell something on Amazon and they will fill your ear with how much leverage amazon has over them. You can check r/FulfillmentByAmazon/ Or r/AmazonSellers for stories.

Comment by eightysixfour 3 days ago

Probably because we have little to no way to punish those companies. We can't even stop DJI from shipping their drones under other brands to get around the ban.

Comment by dessimus 3 days ago

Our government chooses to not punish those companies. Unfortunately, the lawmakers have decided that the donations to their PACs are more important than actually doing something about it.

Comment by tomjen3 3 days ago

Probably because doing so would mean a lot fewer product categories. It's a trade-off, to be sure. But if you need that odd thing — a screw of a certain type, a power supply that's 56 volt DC or whatever — then if there's only going to be sold, say, a few thousand of those a year, if Amazon was required to do product safety testing on them, they probably wouldn't be able to sell that category at all. And so the trade-off is they are not required to.

Now that's very different from "we are selling things that we know, or have good reason to know, specifically are dangerous" — here they might very well be liable.

Comment by ryandrake 3 days ago

I would very much be in favor of grocery stores sharing responsibility (and regulatory penalties) for selling tainted food! It's kind of mind boggling that this is controversial. "Buyer beware" is not an acceptable basis for society to function.

Comment by SoftTalker 3 days ago

I can't think of a case where a supermarket, upon becoming aware of a problem with a food product, didn't immediately pull it from the shelves, post a notice to customers, and offer a full refund to anyone who had purchased it.

Comment by StilesCrisis 3 days ago

This is unfortunately exactly how society operates in China. It is basically on the buyer to confirm that they're getting something acceptable. Once they've paid, it is what it is.

Comment by fragmede 3 days ago

Not exactly. In 2008 there was a huge scandal where melamine was in baby's milk, so it isn't always what it is.

https://en.wikipedia.org/wiki/2008_Chinese_milk_scandal

Comment by StilesCrisis 3 days ago

Yes, if your malfeasance is large enough to be on the front page of the New York Times, you'll be sentenced to life in prison or even death. But killing babies is a bit more heinous than fraudulent ad clicks!

(Also of note: WHY melamine in the baby formula? Because they knew the buyer would check the nitrogen content, because it's a caveat emptor culture.)

Comment by 3 days ago

Comment by lotsofpulp 3 days ago

Probably because most people don’t equate the damages from causing bodily harm to whatever these ad clicking networks do.

Voters don’t like seeing themselves or their kids get hurt, but they do like lower cost live sports.

Comment by tclancy 3 days ago

This is one of those things where I, as a suburban white kid, am so happy I discovered Public Enemy and similar bands as a kid.

"Money talks. And bullshit brothers walk a marathon."

Comment by bashtoni 3 days ago

Yes, fascinating that this is apparently all the fault of Chinese companies, and not the American companies distributing and retailing these products.

Comment by themaninthedark 3 days ago

Um...If I make an app that reroutes people's payments so that I can skim a percent off the top and release it for Android and IPhone as a shopping app, how would it be Google and Apple's fault?

Sure they try to vet the app but how does that absolve me from the liability?

Comment by sneak 3 days ago

Tainted food and unsafe children’s toys kill people.

Sketchy devices on your wi-fi don’t really harm anyone. They’re a minor inconvenience at best, mostly to large corporations that like to discern residential connections from business/corporate ones.

Comment by inigyou 3 days ago

I don't know why this is such an unpopular opinion on HN.

Comment by red-iron-pine 3 days ago

you don't get why a news aggregator for tech bros have problems with crappy devices hacking them?

Comment by sneak 2 days ago

Being on your LAN isn’t “hacking” anyone otherwise every hotel, airport, conference, and airplane would be unsafe.

Comment by inigyou 3 days ago

What is being hacked? The ad industry? I didn't know the average HNbreader had such deep compassion for the ad industry.

Comment by PufPufPuf 3 days ago

My "streaming device" of choice, ThinkCentre Tiny with Linux, always feels validated with news like these. It fits behind a TV, you can get it second hand for around $40 and depending on model it can even act as a retro game console as well.

Comment by CrimsonCape 3 days ago

Is there a good TV UI OS that runs desktop youtube under the hood for ad blocking?

Comment by PufPufPuf 3 days ago

I use the VacuumTube app (https://flathub.org/en/apps/rocks.shy.VacuumTube), which has ad block, sponsor block, and some more advanced settings! You can use GNOME with scaled up UI or KDE Bigscreen (recently resurrected) for the DE.

Comment by jojobas 3 days ago

There is Kodi Youtube plugin that takes a developer token and is then ad-free.

Comment by yumraj 3 days ago

Any way to identify or block these proxy and ad click services in the router? Say a Ubiquiti or even pfsense?

I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.

Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?

My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.

Comment by miohtama 3 days ago

This is why Google/Meta is pushing for "age verification".

1. They want more as targeting data on you

2. They want to reduce bot clicks

It's an unholy alliance with governments who want to know who writes what online.

Comment by inigyou 3 days ago

I'll take residential proxies over mass surveillance any day. It seems surveillance will always expand unless countered.

Comment by m3047 4 days ago

Brazil. Last year I effectively blocked Brazil for a while. Ultimately I settled on three possibilities for the traffic I was seeing:

01: DDOS

10: Residential proxies

11: Somebody DDOSing residential proxies

Comment by drdexebtjl 4 days ago

I can’t prove it, but I live in Brazil and after getting a smart TV from LG, I started receiving challenges across all Google services, indicating they received bot traffic from my network. I only used apps from streaming services I actually paid for.

I suspect these TVs either come with residential proxies set up from the factory, or they have such poor security that they’re instantly hacked. Either way, TV manufacturers (including reputable ones like LG) are to blame.

Comment by mikestew 3 days ago

There have been articles lately about the residential proxies loaded in apps for LG TVs. My LG has never seen a network connection, so I’m fuzzy on details.

Comment by inigyou 3 days ago

LG has been in the news just this week for a whole lot of shady practices, which cast light on their other shady practices. Yes, residential proxying is one of them.

I don't think residential proxying is all that shady since groups like Cloudflare have made it a necessity. However, having it out-of-the-box on a name-brand device is extremely shady.

Comment by cwillu 3 days ago

“as part of a sprawling operation that seeks to defraud online merchants and advertising networks.”

Oh no! Not the advertising networks!

Comment by neves 3 days ago

I really don't mind anymore. My Roku stick is now owned by extreme right Fox Corporation. Chinese ad click network are petty villain compared.

Comment by gxs 3 days ago

No mention of Roku

I use one but only when traveling at hotels - it’s one of the only sticks that can connect to captive WiFi networks at hotels

I’ve got barely anything on it so privacy be damned - but at this point this is why I just buy apple products

I have two apple tv’s which probably do shady things too, but I’m willing to play the probabilities and assume it’s the least bad of my options short of tinkering with flashing hardware and all that stuff that used to be fun in my teens (emphasis on used to)

Comment by hn_submit 3 days ago

I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.

Instead they're banning stuff willy nilly left and right without really solving the problem.

But there's good stuff coming out of China as well. I recently bought a cheap e-reader which has no WiFi or internet connection and it works stellar. And I bought some cheap Chinese sport cams which also lack internet and work great.

Comment by autoexec 3 days ago

> I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.

Personally, I think every other country should ban any product made by Google, Amazon, and Microsoft since they all spy on the users of their products too.

Comment by hn_submit 3 days ago

I've suggested legislation which would ban the sale of customer information to third-parties.

These companies could use the info they gather on customers for their own use but they cannot (re)sell it to anyone, not even the government. The reason being that the information eventually ends up abroad after which you lose all control over it.

Comment by atum47 3 days ago

Got myself a mi box with a custom launcher. Way better than any other Smart TV out there. Unless there's a smart tv that does not show ads right on the fing front page.

Anyway, the box is powerful enough to do several things. You can install a IP tv if you want. If you don't, you still have a pretty good media center (you can hook up an external hd on it)

Comment by aucisson_masque 3 days ago

The Xiaomi box also send lots of data to Xiaomi server but also ads/tracking network.

I switched to a Google box, this has no bloatware and this way I get tracked only by one company.

Comment by atum47 3 days ago

It is actually a Google box, at least the software is (don't know if it's modified by Xiaomi). The custom launcher gets rid of those shitty recommend videos on YouTube / Prime / Netflix...

Comment by Scoundreller 3 days ago

Though I do then wonder about some of the iptv apps even the ones provided through paid subscriptions but that’s already on the dark side; but not as dark as these “buy once” 1000s of pirated channels devices

Comment by utopiah 3 days ago

I bet this is much broader than we all realized because just earlier today I was reading on https://gist.github.com/probonopd/3ad6b7777caea1503f00d5fe77... in order to tinker with a cheap (like really cheap) Android video projector : "Device: Magcubic HY300 Pro Android Projector (ui_Veng.projector) Issue: Device was being used as a residential proxy node without consent, causing thousands of suspicious DNS requests and bandwidth usage." linked in there just few months ago.

It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique.

An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.

Comment by LetsGetTechnicl 3 days ago

Oh wow that's the same projector I have. Would be really cool to install a custom build on it, but for now I just have an Apple TV connected to it.

Comment by utopiah 3 days ago

You can already adb connect in dev mode then install .apks, e.g. termux, Fennec and change some settings. It does seem rootable but I didn't try.

Comment by thothless 3 days ago

roku is sniffing your farts. and reading your texts/emails.

https://docs.roku.com/published/userprivacypolicy

see: "olfactory", "content of"

or at least they're CYA while they're sniffing.

they definitely scan the entire local network.

Comment by Doohickey-d 3 days ago

Krebs' blog is nice, but quite often it's just re-reporting stuff from somewhere else:

Original with more details: https://www.bitsight.com/blog/fuyao-enterprise-building-ad-f...

Comment by RajT88 3 days ago

A pirate TV box from China presents a security threat?

This is my surprised face.

Comment by inigyou 3 days ago

No actual security threat was stated in TFA though. Only revenue threats.

Comment by stronglikedan 3 days ago

> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

You had me at "But"! ::swoon::

Comment by tomaskafka 3 days ago

At this point China probably has a botnet that can be turned on with a few deploys, and spans a majority of homes in US and RU (and thus is unblockable without disconnecting half of voters from the internet). Ready to attack the infrastructure.

Comment by bashtoni 3 days ago

I don't know where you get the idea this is a nation state attack.

The devices are used to sell proxy services and scam advertisers. This doesn't even need particularly large organised crime. It would certainly be easier than large scale illicit drug importation and retail, which is happening all the time.

Could China exploit these streaming sticks if it wanted to? Maybe, but no more than any other nation.

Comment by tossingafterxyz 3 days ago

Not necessarily correlated to this, but my perception is that china is generally ok with many types of crime as long as it’s not perpetrated on its citizens / aimed at foreigners (IP theft / counterfeit goods / cyber crime etc). However, I also think the state largely has a good sense of the actor or players and is perfectly capable of exerting force or coercing them to their cause at will.

Comment by coretx 3 days ago

The most relevant difference between using a TV and a "TV streaming stick" is corpos & the State controling the malware/surveillance device.

Being a ordinary person, I do not want criminals or the ( ads/data ) industry or the state to be in control of my property.

Also, any DRM not passed by a parliament undermines the rule of law & statehood. This is something Krebs and his Praetorian guard buddies must know.

Comment by giraffe_lady 4 days ago

> allowing low-skilled operators to drag blocks of code together in their editor — without any need to understand what the underlying code blocks do or how they work.

We're called engineers brian.

Comment by wao0uuno 3 days ago

If you have a Raspberry Pi 5 gathering dust somewhere and need a new streaming box then try LibreELEC. It decodes 4k content just fine. It has HDMI CEC. It can stream from local server or play directly from attached storage. There are no ads or tracking/profiling. It can play YouTube without ads but there is no support for Netflix, Apple TV or similar streaming services.

Comment by dspillett 3 days ago

A Pi4 does the job well too. They can be had noticeably cheaper than Pi5s ATM, if you don't have the luck of having a device lying around ready to be repurposed, and even the 1Gb models are plenty sufficient.

A Pi3 may suffice even, that is what I ran Kodi on before upgrading it to the Pi4, though the lack of hardware x265 decoding support is a limiting factor there (IIRC it'll manage 1080p in software, but only if you have some good cooling installed otherwise things get very skippy after a short while as thermal throttles kick in).

Comment by wao0uuno 1 day ago

I’m pretty sure Pi 4 struggles with 4k decoding. It can work but is less than ideal. I also wouldn’t recommend buying a new Pi these days. Prices are insane.

Comment by dspillett 1 day ago

Most of what I watch is 1080p (I don't really have 4K capable eyes!) but it definitely plays 4K 265 well.

Only 265 though, the hardware support for 264 is limited to 1080 so 4K there means software decoding which I imagine being a problem much like 265 on the Pi3. It is pretty rare to see 264 used for 4K content though, in my experience.

Comment by j45 4 days ago

Generally, it's advisable to create a dedicated wifi network for all potentially hostile devices.

This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.

That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.

Comment by drnick1 3 days ago

> That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home

That is not enough. You need to air gap devices that have legitimately no business communicating with anyone or anything outside the house. TVs, thermostats, and other Internet-of-Crap gadgets do not need "firmware updates." Either they work out of the box, offline or within the LAN, or they get sent back for a refund wherever they came from.

Comment by j45 3 days ago

Agreed. That usually comes as a step after getting these items on a separate SSID.

Comment by spelk 3 days ago

I don't think this would make a big difference for the threat model described in the OP? They'd still be able to use your IP Address and potentially do nefarious things through your role as an unwitting proxy.

Comment by j45 3 days ago

Using one device as a proxy is a few steps away from trying to exploit and infiltrate the other devices on your machine as well. An unwitting proxy is already crossing the line to putting a fox in the henhouse.

Limiting what outbound access devices can/can't have is an important skill to learn.

Comment by giantg2 4 days ago

So where can I get an actual privacy focused streaming box, even if the apps (Neflix etc) running on it are not?

Comment by ghostly_s 3 days ago

These are not "streaming boxes" in the sense you are talking about. Their appeal is that they come preloaded with chinese pirate streaming apps. Traditional streaming boxes - Apple TV, Fire stick, Roku - are not affected by this, though if you want privacy-focused Apple TV is the only remaining contender, and with Apple's continued descent into advertising vendor I'd guess that one is not long for this world, either.

Comment by giantg2 3 days ago

My understanding is that Roku bypasses DNS blocking with hardcoded tables so it can report back on various data they track on you.

Comment by autoexec 3 days ago

Roku collects an insane amount of data on users. Basically everything that they can get their hands on

> Roughly twice per second, a Roku TV captures video “snapshots” in 4K resolution. These snapshots are scanned through a database of content and ads, which allows the exposure to be matched to what is airing. For example, if a streamer is watching an NFL football game and sees an ad for a hard seltzer, Roku’s ACR will know that the ad has appeared on the TV being watched at that time. In this way, the content on screen is automatically recognized, as the technology’s name indicates. The data then is paired with user profile data to link the account watching with the content they’re watching. https://advertising.roku.com/learn/resources/acr-the-future-...

Comment by timbit42 3 days ago

Can you monitor its traffic and block by IP?

Comment by mikestew 3 days ago

I’m sure you could. At what point do you just rip out the thing that is trying so hard to work around your control of your network? An Apple TV doesn’t cost that much.

Comment by kube-system 3 days ago

The door is slowly closing on all of these blocking schemes by moving ad content to the same domains as the primary content.

This is already a common feature for analytics toolkits.

Comment by giantg2 3 days ago

I probably could, but haven't done so yet.

Comment by MattTheRealOne 4 days ago

Apple TV is currently the best balance of privacy and convenience. The only way to get more private is using a PC, but that limits the resolution for most streaming services to 720p or 1080p.

Comment by theshrike79 3 days ago

And longevity. It just keeps getting updated tvOS versions and every provider's apps keep working - unlike on random Android TVs that just fall out of support.

I'm on my second one and I've owned them since the first version. My current one is the first generation 4k that's ... seven years old? Still works like new.

Comment by PcChip 4 days ago

I assume apple TV doesn’t do malicious things like this, and we love the interface and it “just works” with HDR

Comment by noboostforyou 3 days ago

Besides setting up your own device, Apple TV would be the best bet from any of the large manufacturers.

Comment by cogman10 4 days ago

I'm increasingly being convinced the only way to do that is you do a media pc nuc. The problem, of course, is you probably won't have the netflix app. It's painful to setup such a box to stream from various services.

Comment by Tepix 3 days ago

What's wrong with Apple TV? It runs VLC if you want to stream something from your NAS.

Comment by mbmbn 4 days ago

I tried going that route, but most apps for streaming are Android. And that was only one of the issues.

It was a rabbit hole and in the end I got back using my NVIDIA Shield. This is about 10 years now, but it’s actually still the best option.

Comment by giantg2 3 days ago

I tried to look at setting up an stripped down privacy-focused Android based box for Netflix, but ran into issues. Seems like you need to be spied on to run Netflix.

Comment by dwaltrip 3 days ago

What about just using the Netflix desktop website? Or does that limit the resolution?

Comment by drnick1 3 days ago

If you want actual privacy (rather than promises from Apple or Google), what you need is a mini-PC running Linux with the Plasma Bigscreen DE. You then use a Web browser rather than invasive "apps" for your streaming. For Youtube, there is VacuumTube (an improved Youtube Leanback client). The main limitation is capped resolution on some commercial streaming services. I believe Windows does not have that restriction, so a VM could presumably be used for streaming (I have not tried).

Comment by 3 days ago

Comment by knowaveragejoe 3 days ago

The Onn TV devices from walmart seem fine, baseline google tracking not-withstanding... but no residential proxy or botnet participation without you knowing! You can just block them at the router and stream content locally.

Comment by Pxtl 3 days ago

kodi on an rpi5?

Comment by haunter 3 days ago

[dead]

Comment by ColdStream 3 days ago

Alternatively, if you are going to do some questionable things, just buy loads of these things and create a hundred back doors on the network to increase the noise.

Sounds good in theory but in practice, computers are good at sorting this stuff out. Kind of why they are so popular.

Comment by dxxvi 3 days ago

Ah, got it. Those devices are like computer virus which don't need a computer to live on.They can make DDOS attacks if they want to. So, buying these devices at a cheap price is like renting out your IP address and your Internet connection.

Comment by BigTTYGothGF 3 days ago

> these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks.

Every cloud has a silver lining.

Comment by theendisney 3 days ago

Long ago I ponder giving away free computers but an ethical formula is really hard. It seemed profit starts to scale exponentialy just beyond the line.

(Acepable would be something like 1TB worth of gamedemos)

Comment by cute_boi 3 days ago

The best solution to this problem is to block GeoIP traffic and monitor bandwidth consumption on a per-domain basis. If something is sending data during the night, it becomes much easier to identify suspicious activity.

Comment by joeisnotjane 3 days ago

Ah, it's about "China, China.."

Preparing casus belli.. first, open weights LLM which are "not secure", now "TV sticks"..

Oh joes and janes, who will put finally some sense into you..

Comment by Ikatza 3 days ago

Ah, yes, the great TV sticks war of 2028. We'll tell the stories.

Comment by joeisnotjane 3 days ago

It is about gradually, but constantly, creating the image of an "evil adversary".. Venome drop after venome drop..

China is not doing that as far as I know. Neither Russia did it before the war, though you were claiming the contrary (I know, since I live in the west and could compare news from both sides, being a native Russian speaker).

Comment by stevetron 3 days ago

Birds Nest soup with Chinese tomatoes?

Or Cinese noodles with Chinese tomatoes?

It sounds likw 2 domestic markets that China should use to rid themseves of their over-abundance of tomatoes.

Comment by a-dub 3 days ago

it's just like a phone. don't buy a crappy one with firmware of unknown provenance. make sure the one you do buy has an active and effective effort that you trust that ships timely security fixes.

Comment by Hasz 3 days ago

Hey that’s pretty smart! Fradulent, but very smart. I was honestly expecting botnet.

I expect many cameras of “dubious” origin are used for similar tasks, same with most “smart” devices with sufficient horsepower.

Comment by estebarb 3 days ago

Oh wow, even scammers care about usability and their employees' well-being. What's the excuse for bad UX in internal company software?

Comment by Mistletoe 4 days ago

I recently got an Apple TV 4K and have been really enjoying the ad free experience. Worth every penny. Our smart tv had turned into a Christmas tree of ads.

Comment by wewtyflakes 3 days ago

There are plenty of ads on Apple TV; huge banners right at the top of the UI, and ads that launch before you get to see the content of a show with no way to automatically disable them (you have to manually click through or just wait it out). It is infuriating (to me).

Comment by ls612 3 days ago

Apple TV the app has ads for Apple TV shows. Apple TV the device doesn’t have ads built in.

Comment by wewtyflakes 3 days ago

The TV app is baked into the device and is automatically focused if you press up too many times on the remote (and thereby triggering the large banner ads).

Comment by ocd 3 days ago

As much as I hate Apple for what they've done to the average consumer in regards to computing, it would be just impossible and dishonest to say anything other than Apple is the outright winner in streaming devices. The experience is so smooth.

Comment by trouve_search 3 days ago

The nvidia shield is pretty damn good as well, even if old at this point.

Comment by ghostly_s 3 days ago

Considering their recent decision to give up on building Apple Maps into a serious contender and instead enshittify it with ads, I don't have much faith Apple TV will be far behind.

Comment by dhosek 3 days ago

One hopes that the new CEO will realize the turn towards ads is ruining the Apple brand and pull back on that front.

Comment by inigyou 3 days ago

Ha! No company has ever reversed enshittification.

Comment by dhosek 3 days ago

Although Apple did undo the touchbar (although I think they gave up on it too soon—I actually liked it once they restored the esc key. I can never remember what all the F-keys are supposed to do and getting an app-specific set of graphical choices made more sense to me.

Comment by zeroq 3 days ago

tangent thought experiment

So you bought that top of the line security-as-a-product thingy you can stick in your rack and it will make sure that your network is impenetrable? You know, like those CISCO bricks everyone major company is buying.

So have you took an extra precautions to make sure that the firmware on the device is pristine? Do you know anyone who ever touched these devices who actually did?

Do you see the problem?

Comment by jojobas 3 days ago

Cisco bricks leave the factory as pristine as they can be. An intercept sort of attack is possible, but involve quite some effort and risk.

These sticks leave the factory with malware pre-flashed, the postman brings them to your door with zero risk for the beneficiary.

Comment by mring33621 3 days ago

Using low code tools to build click fraud logic FTW!

Comment by AlexandrB 3 days ago

This is only slightly more malicious than the software "Smart TVs" already ship with.

Comment by perpetuallunch 3 days ago

> rent the user’s Internet connection out to strangers.

Harm to the user: none^

> spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks

Harm to the user: none^

Cost to the dodgy service provides: none

Government action to prevent continued dodgy services: none^

This is why internet securityg doomers have a hard time selling their story. Changing behaviour has an upfront, immediate, cost. Not changing it doesn't.

^close enough

Comment by charonn0 3 days ago

>> rent the user’s Internet connection out to strangers.

> Harm to the user: none^

Well, they are losing some of their bandwidth. They might not notice, but something which is rightfully theirs is being taken without consent.

Comment by perpetuallunch 3 days ago

If they don't notice, and they're on an unlimited data plan, or the usage is such that it doesn't result in exceeding their data cap, what argument is there that harm occurred?

Comment by charonn0 2 days ago

I'm talking about bandwidth; connection speed.

The streaming stick in the article turns off its proxying feature while the user is actually streaming because the proxying feature consumes enough bandwidth to degrade streaming quality.

In other words, whenever the proxying feature is active every other device sharing the connection will suffer degraded performance.

Even if the user never notices, they're still worse off. They're still paying for bandwidth that someone else is using for profit. Money is flowing out of the user's pocket and into the pocket of the proxy operator. That makes the proxy operator a thief who is stealing from the user, and without even the Robin Hood-esque cover of defrauding ad networks.

Comment by 3 days ago

Comment by rawgabbit 3 days ago

What happens when you stick this malware into your windows PC? The PC is now an accomplice to fraud?

Comment by crote 3 days ago

LG televisions and monitors spy on their users and install unwanted software. Half of all smart tvs are running "residential proxy" malware. Google is banning sideloading but happily hosting apps using the Bright SDK.

Sorry, but "your tv stick does ad fraud" is just about the most innocent thing I've seen in a while. Everyone in this market is doing the shadiest shit you can imagine. There are no good brands left, you just get to pick what logo your Malware Entertainment Device has.

Comment by inigyou 3 days ago

Is it even really malware if it's harming advertising networks and not you?

Comment by kazinator 3 days ago

> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads ...

Compromised (or malicious from the factory) devices being recruited into bot farms for click fraud is ... a groundbreaking discovery in 2026?

> on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

To hell with AI-generated websites and advertising networks.

Say, where can I get the most effective malicious TV stick for click-frauding the fuck out of that shit? I will take fifteen! :)

Comment by snickerbockers 3 days ago

I'm imaging a largescale distributed project like folding@home except instead of doing scientific research everybody is working together to fuck with advertisers, tracking cookies, etc.

Comment by stuaxo 3 days ago

How hard is it to get something else on these ?

Looks like cheap small computer with a remote control.

Comment by cryo32 4 days ago

A better solution is just leech the content and stick it on a generic USB flash stick.

Comment by harvey9 3 days ago

These are popular for illegal live sports streams.

Comment by cryo32 3 days ago

I just go down the pub.

Comment by shevy-java 3 days ago

> they secretly rent the user’s Internet connection out to strangers

So the mafia is back.

Comment by phendrenad2 3 days ago

On the other hand, these are great little devices to root and put Linux on.

Comment by codedokode 4 days ago

I do not see problems with fake ad clicks and have no sympathy for ad companies.

Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.

What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.

How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:

- the user must be able to re-flash firmware with their own code.

- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.

- any telemetry or data collection, or updates must be opt-in only and disabled by default.

- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.

Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.

Comment by Thrymr 4 days ago

> I do not see problems with fake ad clicks and have no sympathy for ad companies.

I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.

Comment by jrm4 3 days ago

Sure. And you'll quite literally never be able to get any meaningful reduction in this practice unless you attack it at the level of big, publically known companies; the warnings about these local dinky things I suppose are not harmful and help individuals a bit -- but I'm concerned they give the entirely false impression that the extremely similar stuff coming from the big boys is definitely a-ok.

Comment by Dylan16807 3 days ago

Reduction in what practice? Are there big companies doing ad fraud?

I want big companies to stop spying on me, which is a completely different issue.

Comment by jrm4 3 days ago

They're not at all "completely different issues."

Both are well within the category of

"If you buy a device to do a thing, then the device does something else that is not readily apparent to the user that user would find objectionable if they had clearer knowledge."

This is immoral and harmful regardless of precise vector/action.

Comment by Dylan16807 2 days ago

That spying harms me while ad fraud harms random companies is already enough to separate them by a lot, I'd say.

But also the spying is expected by a lot of people. And a lot of people wouldn't object so much to screwing up internet ads.

Comment by Cider9986 3 days ago

>What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information.

Most Americans are at a greater threat of harm from their own government that a foreign one. What worries me is all the mass surveillance done by big tech which bypasses the 4th Amendment and gives the government Americans data without a warrant.

There's already a front door with the adtech for US alphabet boys. This could likely be collected by others as well. We saw this happened where foreign hackers exploited a backdoor designed for American authorities[1]. This is what experts are referring to when they say there's no backdoor only for me.

This could be compelling to politicians, though, and would certainly be a step in the right direction.

>- any telemetry or data collection, or updates must be opt-in only and disabled by default

This should be how it is for everything foreign made software or not. Would be very hard to get done with the big tech lobby in the US.

[1] https://techcrunch.com/2024/10/07/the-30-year-old-internet-b...

Comment by pavel_lishin 4 days ago

> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?

> for every imported device having a CPU and Internet connectivity

Why limit this to imported devices?

Comment by palmotea 4 days ago

>> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

> Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?

Cheap, slow-moving drones are the hot new missiles on the battlefield of today. This often talked-about model files at 115 mph (https://en.wikipedia.org/wiki/HESA_Shahed_136).

Comment by codedokode 3 days ago

In some areas GPS is spoofed and the displayed location is wrong. If, for example, a "smart" car gets a task from its manufacturer to film some secret object, it would fail if it relied only on GPS and did not use cell towers and WiFi points for determining its location. So knowing their location determines whether the mission would fail or succeed. So foreign devices should not be allowed to collect such information.

Comment by bee_rider 3 days ago

I think that might have been semi-sarcastic. I mean, there are lots of reasons to do this sort of thing, some are bad, some are not so bad, most are not war.

Comment by IncreasePosts 4 days ago

Fake ad clicks cost the advertiser money, not the ad company.

Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)

Comment by mcphage 4 days ago

> Fake ad clicks cost the advertiser money, not the ad company.

It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.

Comment by codedokode 3 days ago

Good products do not need much advertising. For example, when buying DRAM, I compare the specification and prices and do not look at the advertisement.

Comment by BoppreH 4 days ago

> a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys.

Could it be used for missiles? Sure. Is it obviously the intention? No.

Comment by meatmanek 3 days ago

Yeah this is extremely standard:

Apple: https://support.apple.com/en-us/102515

> If Location Services is on, your device will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers to Apple to augment Apple's crowd-sourced database of Wi-Fi hotspot and cell tower locations.

Google: https://support.google.com/android/answer/15157297?sjid=1648...

> When Location Accuracy is on, Google periodically collects information about the locations of wireless signals and sensors observed by your device to crowdsource location estimates. This helps everyone find locations better.

Mozilla used to run a very similar service: https://en.wikipedia.org/wiki/Mozilla_Location_Service

Not to mention truly crowd-sourced databases like wigle.net.

Comment by codedokode 3 days ago

They should ask the permission from device owner and local government before collecting the data.

Comment by aeturnum 3 days ago

They do ask the device owner - if you review the location services description on android[1] you will see they explicitly say they collect this information from your device. I strongly disagree that they need to get government permission for this - they are simply recording signals that reach the device, akin to making notes about what kinds of cars you see. This is not a thing a government should have control over people doing and not a thing that should be registered with the governement.

[1] https://support.google.com/android/answer/3467281?sjid=66634...

Comment by codedokode 3 days ago

In the article you refer to, I see no mention of asking user's permission. However, I remember, when using an old version of Android, there indeed was a popup nagging me to allow sharing location data with Google every time I enabled GPS. Very annoying, makes you want to never enable GPS in the first place.

Regarding the government, the problem is that many people do not fully understand the mechanism of collecting the data. I remember the case when members of US military disclosed the location of secret objects through fitness tracker app. And they were probably smarter than average smartphone user. Obviously it would be better if enabling GPS required an approval from their commander.

Comment by aeturnum 3 days ago

I suppose they don't "ask you" in the same way that gmail never presents the user with a dialog explaining that gmail needs to store their emails in order to provide their email service. Instead they explain how the location service works and you can decide if you want to enable or disable it.

I'll agree that militaries would prefer their soldiers to not to dumb things - but I don't agree that it's 'obviously' best if people needed permission to enable GPS! If that's the case depends a lot on which soldier is enabling the GPS and their relation to me. In general I would say that government control of people recording and distributing their observations is associated with the most authoritarian governments and by claiming we should get government permission you appear to be aligning yourself with an authoritarian approach to data controls.

Comment by codedokode 3 days ago

Should Google ask permission from the device owner, and from the local government before collecting the data? I heard a certain foreign mobile app was banned in US for doing less than that.

Comment by mcphage 4 days ago

> I do not see problems with fake ad clicks and have no sympathy for ad companies.

Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.

Comment by exe34 4 days ago

My pinenote runs the original spyware image - I don't have a problem with Winnie the Pooh reading along with me.

Comment by autoexec 3 days ago

> Yeah, it's like—a cheap streaming stick AND it poisons the advertising well?

Keep in mind that it's your IP and identity associated with those clicks and anything else criminals decide to do with your IP address. That means you're identity is being linked to things you may or not want to be known as being interested/involved in. The ads your TV stick clicks on can cause data brokers to include your name in lists of people who are heavily into drugs, have mental disorders, belong to certain religions or political parties, etc. All of that can come back to haunt you later.

Depending on what other activity your connection is used for as a proxy it can also get you in trouble with the police or with your ISP.

Comment by inigyou 3 days ago

So you're saying it's going to weaken the presumption that an IP can be easily tracked to an individual? Even better!

Comment by autoexec 3 days ago

No, your IP will be easily tracked to you as an individual. You'll just suffer the consequences of whatever your streaming stick does with your IP. If your stick clicks a bunch of ads for fast food your heath insurance bill goes up because their algorithm thinks you're a higher risk. If your streaming stick clicks a bunch of ads for high end luxury goods, online stores start charging you more than they charge your neighbor for the same items because their algorithms think you have money to burn. Your streaming stick clicks a bunch of ads for addiction recovery services, you don't get a call back for the next job you apply to because the HR department paid a data broker to run a background check looking for "red flags".

What you do on the internet has very real impacts on your life offline and it's going to happen more and more over time. AI will make it easier for companies to leverage the massive amounts of data avilable to them about you. Surveillance pricing is spreading. Consumer reputation services are spreading. Law enforcement is buying up data from data brokers. Extremists are using data brokers to decide who to target with violence.

Nobody cares if the data they have isn't 100% accurate. The data broker doesn't care. He gets paid either way. The companies buying your data don't care either. It's all a numbers game to them. They just have to be right enough times to justify the cost of the data.

Comment by inigyou 3 days ago

None of this is based on reality. Can you show any of this ever happened to anyone?

Comment by autoexec 3 days ago

This should get you started at least. Keep in mind that nobody is going to tell you that they charged you extra or didn't give you a job offer because of data collected from a data broker. No one is going to be transparent about how they use your data against you.

None of the data being collected about you ever goes away. It doesn't matter if the data comes from you. or your backdoored streaming stick, the more data they have associated with you, the more opportunists exist for you to be screwed over by it.

It's almost impossible for a person to know when or how their offline life is being influenced because of the dossiers containing their online activity, but it absolutely impacts the prices you pay, the policies businesses will tell you they have, the opportunities you are offered, and even how long companies leave you on hold when you call them on the phone.

https://www.cbsnews.com/news/data-brokers-selling-personal-i...

https://web.archive.org/web/20191130221040/https://www.nytim...

https://link.springer.com/content/pdf/10.1057/s41272-019-002...

https://www.mccarter.com/insights/ftc-surveillance-pricing-s...

https://www.npr.org/sections/health-shots/2018/07/17/6294415...

https://nypost.com/2022/12/20/how-employers-spy-on-your-sear...

https://www.cnbc.com/2014/04/16/data-mining-is-now-used-to-s...

https://www.wired.com/story/minnesota-lawmaker-shootings-peo...

https://www.wired.com/story/opinion-data-brokers-are-a-threa...

https://sites.sanford.duke.edu/techpolicy/wp-content/uploads...

https://epic.org/data-broker-helped-anti-abortion-group-targ...

https://www.foxnews.com/politics/nsa-purchases-americans-int...

https://www.ftc.gov/news-events/news/press-releases/2014/04/...

https://www.washingtonpost.com/technology/2023/02/13/mental-...

https://arstechnica.com/tech-policy/2017/03/senate-votes-to-...

https://www.vice.com/en/article/data-brokers-netflow-data-te...

https://www.eff.org/deeplinks/2023/11/debunking-myth-anonymo...

Comment by inigyou 2 days ago

Which one is about someone who had more expensive health insurance because they ran a residential proxy?

Comment by autoexec 2 days ago

The one titled: Health Insurers Are Vacuuming Up Details About You — And It Could Raise Your Rates

The article says that health insurance companies are buying data from data brokers and using algorithms to set prices according to what you do online and what your "personal interests are".

It makes no difference if you run a residential proxy or not, using your browsing history (or your streaming stick's browsing history) data brokers will give insurance companies information that can be used to set your health insurance rates. The more clicks made over your internet connection, the more data they have to make assumptions about you with.

Remember, you asked for evidence that "any of this ever happened to anyone". There are also links showing that employers are buying up data based on your online activity and using it for hiring decisions, that the prices for things you buy are determined by your online activity, that what you do online has real world impacts on your life offline, and that extremists are using data brokers to identify targets.

Comment by inigyou 2 days ago

So in other words it doesn't say someone got higher health insurance rates because they ran a residential proxy.

You know this argument works for everything, right? https://en.wikipedia.org/wiki/Proving_too_much

Do you buy processed food from the grocery store? You know that makes your insurance go up, right?

Comment by autoexec 2 days ago

It's reasonable that if health insurance companies are collecting data on the types of groceries people buy, that they will use that information in ways that they feel will benefit them. You can lead a man to data, but you can't make him think.

Comment by mcphage 3 days ago

Talk about the gift that keeps on giving…

Comment by arjie 3 days ago

Oh this was a failed device that Mozilla offered. I had a couple back in the day. It was called Matchstick. Sick t shirts. Basically an OSS chromecast.

Comment by Tangurena2 3 days ago

> What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information.

The Snowden leaks showed that the US was already doing this. I'm certain that everything purchased is already infected with something. Most likely bugs and bad security.

Comment by soulofmischief 3 days ago

The problem is that when you need these powers most as a citizen is when your government is least likely to allow it.

Comment by Pxtl 3 days ago

> major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands that bundle unofficial versions of Google’s Android operating system and are frequently marketed (via online influencers) as a way to access a broad array of streaming services and live broadcasts without a subscription.

This is why I giggle when people talk about ending Section 230 in the USA (or various international counterparts thereof).

The largest companies on Earth are happily selling hacked piracy spyware botnet garbage. Not just hosting malicious posts for free like Section 230 protects, but selling illegal physical devices and taking a cut of the profit and excusing it with a pathetic whack-a-mole moderation system. It's already illegal and the law has already failed.

Sean Parker's mistake was that he wasn't rich enough.

Laws are for poor people.

Comment by 3 days ago

Comment by jms703 3 days ago

You buy garbage, you get garbage. You can no longer depend on resellers or to protect you. They are unphased and unaffected by selling you this garbage. No one else has a financial incentive to protect you. Sorry if this sounds victim blamey. Don't mean it to be. Just trying to convey that we're on our own.

Comment by buellerbueller 3 days ago

To those who are OK with these devices: when you engage in corruption, do you have any moral standing against your politicians when they engage in corruption?

Both you, and the corrupt politicians, are eating away at the trust that underpins society. Certainly, you can argue, your bite is just a tiny one; the politician is eating the whole apple.

At the end of the day, everyone suffers from the decline of trust and casual acceptance of fraud.

Comment by munk-a 3 days ago

Read this:

Use a computer - you actually control the content that way.

Comment by byterivet 3 days ago

Good job.

Comment by inigyou 3 days ago

Krebs fails to make any case for why someone wanting to watch movies and TV should give a shit.

I get that these products are personally inconvenient to Brian Krebs and his work, and to companies that make money blocking people from accessing the internet, and to companies that make money spewing ads in people's faces. So? Why should anyone care about any of those? In fact I think some people would get one of these sticks just to inconvenience the latter two groups!

Comment by shmuli9 3 days ago

This is amazing. Kudos to the team behind it I mean, sucks for advertisers and is utterly deceitful… but genius!

Comment by burgreblast 3 days ago

Google clutches pearls and is shocked! Shocked! That anyone would violate its policies (while it pockets 30% of the fraudulent revenue). Shocked!

And they would have caught them but those crafty criminals spoofed the user-agent. So how _could_ they know?

Comment by SnipeOfficial 3 days ago

[flagged]

Comment by bronko_nagurski 4 days ago

[dead]

Comment by defmetrix 3 days ago

I didnt know anybody bought a streaming stick anymore

Comment by yunnpp 3 days ago

And which part of "ad fraud" is the fraud? As far as I can tell, ad networks and advertisers are the fraud and they are also part of the increasing surveillance state.

Didn't know Krebs was a mainstream news puppet.

Comment by brainwad 3 days ago

It's called fraud because the ad host colludes with (or directly controls) the botnet to get lots of clicks on ads hosted on their sites, making them money at the expense of advertisers.

If you just want to spam clicks on ads you don't financially be edit from, go for it.

Comment by AlotOfReading 4 days ago

Of all the evils normally associated with visual programming languages, enabling cybercrime isn't one I've previously considered. Now that I've seen it, I'm surprised it wasn't more common before LLMs appeared.