Read this before you buy that TV streaming stick
Posted by speckx 4 days ago
Comments
Comment by simojo 3 days ago
Comment by xyx0826 3 days ago
Comment by mrloopex 3 days ago
Comment by simojo 3 days ago
Comment by dhruvrrp 3 days ago
Comment by throwa356262 3 days ago
Do you have a link to the projector?
Comment by __turbobrew__ 3 days ago
Comment by Pxtl 3 days ago
Comment by ubermonkey 3 days ago
Comment by mikestew 3 days ago
I hesitate to blame the victim here, but why on earth would you do that? “$40 Chinese-made” didn’t give you pause?
Comment by bigmattystyles 3 days ago
Comment by miladyincontrol 3 days ago
Of course theres good products made in China, and plenty of entirely Chinese brands killing it doing their thing.
Comment by 8note 3 days ago
its US software companies that are the worst of the worst in terms of adware and malware being shipped under monopoly control
Comment by wvh 3 days ago
The word racism is vastly overused these days.
Comment by parineum 3 days ago
It's not. Firstly, because countries aren't races. Second, because it's just a leftover from a time where that was a good heuristic.
Comment by Eisenstein 3 days ago
Yes it is also the US companies that are a problem but these are two separate problems and need different terms.
Comment by SecretDreams 3 days ago
Comment by handle584 3 days ago
Comment by r_lee 3 days ago
Comment by ChrisRR 3 days ago
Comment by worik 3 days ago
Yes. Chinese manufacturing is quite a phenomenon, useful and everywhere
But to be completely fair, a $40 video projector has a warning label. The price
Comment by fc417fc802 3 days ago
Comment by speerer 3 days ago
Comment by ponector 3 days ago
Comment by SiempreViernes 3 days ago
Comment by Ballas 3 days ago
https://hackaday.com/2022/03/18/welcome-to-the-future-where-...
Comment by earleybird 2 days ago
Comment by histriosum 3 days ago
Comment by red-iron-pine 3 days ago
Comment by contravariant 3 days ago
Comment by tollgategit 3 days ago
Comment by handle584 3 days ago
Comment by qmr 3 days ago
Comment by tollgategit 3 days ago
I dare not ask why you would do such a thing, instead, I will simply ask if you now think the reason was good, and I will hint at you that if the reason was "convenience", then you should answer "No".
Comment by dspillett 3 days ago
You'll probably find the projectors are pretty much the same hardware and OS as the sticks except with the projection device added where the stick just has an HDMI output. It might have HDMI-in too so it can just be used as a screen for another device, but there are definitely some units out there that are network-play-only.
You aren't wrong about giving cheap crap like this access to your network (and via that the public network) is risky, but that convenience you (and I) would say no to is exactly what they are bought for.
Comment by breppp 3 days ago
Comment by GJim 3 days ago
Seriously, why do you think this is normal or acceptable?
This is bullshit needs to stop (and the scummy AdTech industry has a lot to answer for).
Comment by breppp 3 days ago
We all know why, which is Adtech, but like cars or smart TVs, you as a customer either skip the entire segment or yield.
Comment by themaninthedark 3 days ago
I could actually see hooking up a projector to wifi to allow it to stream videos.
Comment by dboreham 3 days ago
Comment by wil421 3 days ago
Comment by Epa095 3 days ago
Comment by red-iron-pine 3 days ago
Comment by jojobas 3 days ago
Comment by DoctorOetker 3 days ago
Show me a COTS smartphone where the end-user can burn the OTP fuses for his personal public key, so they can have it boot their own custom signed firmware, and control exactly what runs in TrustZone's SW Secure World?
Comment by jojobas 3 days ago
Comment by inigyou 3 days ago
Comment by breppp 3 days ago
Comment by inigyou 3 days ago
Comment by breppp 3 days ago
Comment by inigyou 3 days ago
Comment by breppp 3 days ago
Also to be more specific, In apple ecosystem I can opt for encryption where they can't
Comment by inigyou 2 days ago
Comment by jojobas 2 days ago
Still waiting for anything comparable to what China does.
Comment by inigyou 2 days ago
Social credit scores. The USA inspired China to copy them. But in the USA they aren't called social.
Comment by jojobas 2 days ago
Comment by anon48293 2 days ago
Please tell me how with Advanced Data Protection on they can access my data. I’d love to hear it.
Comment by red-iron-pine 3 days ago
Comment by jjav 1 day ago
In the US capitalism, can you find a mobile phone OS that respects owner freedom?
Comment by azan_ 3 days ago
Comment by jkahrs595 3 days ago
Comment by ColdStream 3 days ago
Not saying there is an absolute perfect alternative, anyone who says that is usually shoveling smoke, but there are flaws with this economic model to be addressed.
Comment by azan_ 3 days ago
Comment by ColdStream 3 days ago
It was said that Karl Marx was completely right about Capitalism and completely wrong about Communism. And that is fairly accurate, both have big flaws.
Most times, the opposite of one bad idea is another bad idea.
Comment by azan_ 3 days ago
Comment by ndsipa_pomu 3 days ago
Comment by inigyou 3 days ago
Comment by pbhjpbhj 3 days ago
Comment by azan_ 2 days ago
Comment by mortenjorck 4 days ago
Comment by FinnKuhn 4 days ago
Comment by labbett 3 days ago
Comment by doctorspazz 3 days ago
Comment by acdha 3 days ago
A guy in Vietnam mentioned that one of the largest ISPs there used these really dodgy Chinese modems which were so notoriously insecure that it was apparently common knowledge that you should replace them if performance was slow because that was a sign that yours was being used by a botnet. Apparently the cost of access to one of those nodes was so low that the spammers don’t even really monitor their bots.
Comment by frollogaston 3 days ago
Comment by kiririn 3 days ago
Comment by qmr 3 days ago
Comment by tesnorindian 3 days ago
Comment by dpoloncsak 3 days ago
Comment by mikepurvis 3 days ago
Comment by wildzzz 3 days ago
Worst case, everything is packaged up in a single app so it's all or nothing. Although you could just wipe the box and find another pirate TV provider.
Comment by alex_duf 4 days ago
Comment by abbeyj 4 days ago
Comment by inigyou 3 days ago
Comment by 8note 3 days ago
Comment by inigyou 3 days ago
Comment by psd1 3 days ago
Comment by inigyou 3 days ago
Comment by psd1 2 days ago
> attacking internet gatekeepers
I think we agree that you don't mean all kinds of attack. The agreed exception is bombs.
I put it to you that throwing bot traffic around is another kind of attack that you do not want, because it drives product sales. You would be doing them a favour.
Comment by pavel_lishin 4 days ago
I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.
Comment by havaloc 4 days ago
So yes, I do want to blame the purchasers of these things, sometimes. To prove her point that her stamps were legitimate, she mailed me a card using one of her half priced (but likely fake) stamps and it made it through!
Comment by Terr_ 3 days ago
Comment by mhurron 3 days ago
That was his justification for a satellite descrambler, they're sending me the signals, obviously I'm allowed to.
Comment by brewdad 3 days ago
Comment by mmooss 3 days ago
> do it because they can get away with it.
Lots of people on HN download and upload copyrighted materials. Is it really different?
Comment by bityard 3 days ago
I tinkered with Dish Network descrambling 20 years ago. Not because I wanted to just watch a bunch of free TV (I hardly watched any TV anyway, we mostly watched DVDs from the video store and Netflix). More because it felt like an interesting rabbit hole. And it was pretty interesting!
I picked a good (newer!) satellite dish and LNB from the trash and had a friend help with the installation and alignment because that was his previous job. Normal people use some kind of tool to find the satellites' geosynchronous orbital station in the sky, but he did it often enough that he could simply look up into the sky and point at them.
There were a handful of grey-market satellite receivers you could buy that were technically capable of descrambling a commercial signal. Of course, they did not advertise themselves as such. They were marketed as FTA (free-to-air) DVB-S receivers. These were not illegal as they were fairly popular in regions of the world that actually _had_ a fair amount of FTA (unscrambled) satellite channels. The only satellites visible from North America, however, tended to carry religious, shopping, or Mexican/Central American programming. Oh, and NASA TV.
The receiver I bought had DVR functionality if you hooked up a USB drive to it. I think I still have some recorded shows on it. It would have been a great way to harvest and release pirated TV shows to the Internet, if you didn't mind editing out all of the ads and whatever.
DVB-S was basically a raw MPEG-2 TS stream that could be optionally encrypted. To use these grey-market receivers as descramblers, you install some custom firmware containing the descrambling modifications and keys. I'm failing to remember the technical details, but the encryption they used was not very good. Dish Network would rotate the keys occasionally, and when they did, you had to update them on your receiver. I can't remember now if the keys were part of the firmware, but I remember it being a pain in the ass.
The firmware/keys part of this had a very "colorful" community. You had to sign up to a very specific and somewhat exclusive web bulletin board in order to download the firmware/keys. I don't remember how I gained an account, but I remember it being non-trivial. IIRC, it was like one guy maintaining the firmware/keys and sometimes it took weeks for him to adapt to whatever thing DN did to thwart piracy. The board was moderated by a complete power-tripping asshat who enjoyed banning people for fun and then gloating about it. (I was not banned, that I recall.) I think they started requiring "donations" in order to view certain threads (like firmware releases) after a while. But I could be misremembering that. I just remember the community was very toxic.
After a few months of this setup, DN figured out how to rotate their keys too often for the casual pirate to keep up. I disconnected mine around that time and moved onto other things. Partly because the experiment ran its course and partly because migrating to real-time key updates would have meant buying a newer receiver. For a while, I flirted with the idea of getting a DVB-T PCI receiver card and working on breaking the encryption myself, but it was quite a bit above my skill level at the time and there did not seem to be anyone else working on it out in the open, since the DMCA was still pretty new then.
Comment by wildzzz 3 days ago
Comment by Scoundreller 3 days ago
I migrated into it from the earlier days involving iso7816 card programming and mitm cards so I guess I didn’t have trouble finding which sites to get the fta files. I have good memories of those places being quite welcoming if you did your reading but sometimes ephemeral. Plenty of freeware (but sometimes delayed access). But part of the “payment model” was sevurity vendors trying to destroy their competitors or sell more countermeasures and card swaps to their satellite tv broadcast clients (!!!).
A card swap (and some prosecutions on the nudge nudge “free to air receiver” importers) put an end to most of it unless you went to internet-key-sharing systems where I guess the shared keys come from a handful of slave receivers somewhere. Given the 2-way nature of those key “subscriptions” and network connections required, I could (moreso) understand the paranoia of the operators.
Broadband penetration ultimately killed sat cracking, Netflix et al too. Oh, and what people usually call “iptv”.
Comment by kotaKat 3 days ago
Feels fitting recently to discover the Dish Network "Pirate TV" recordings. I should run my own in-home IPTV station and use the Pirate TV bug as the logo...
https://www.youtube.com/watch?v=zVXSxJ357pw
You're watching Dish Network's Pirate TV channel!... ... if you're watching me, you're a SATELLITE PIRATE!
Comment by Scoundreller 2 days ago
Comment by al_borland 3 days ago
I think that makes a big difference.
Imagine if Amazon Video, Audible, and Kindle will all just pirate stores, where uploaders of the pirated content made money on the downloads, people paid for those downloads, and Amazon took a cut of everything. How long would that go on before they were in court and that was shutdown?
Comment by iamben 3 days ago
So they trust literally everything they read. I still don't think my folks can fathom you can spin up a very real looking newspaper website with fake articles in about 10 minutes.
Comment by mmooss 3 days ago
Comment by CM30 3 days ago
Comment by brewdad 3 days ago
It was both a gateway into learning how the web works but also that literally anyone can post anything to the internet and it doesn't make it true. I like to think he's more savvy than many of his peers but we all have our blind spots.
Comment by doctorspazz 3 days ago
Comment by rrr_oh_man 3 days ago
like cigarettes?
Comment by magicalhippo 3 days ago
[1]: https://museum.dea.gov/museum-collection/collection-spotligh...
Comment by dfxm12 3 days ago
Comment by Pxtl 3 days ago
Amazon will be notified they sold something illegal and will take it down and ban the seller who will immediately launch a new store under a new name.
The purchaser, on the other hand, will be fully liable for whatever horrible thing they bought.
Comment by mmooss 3 days ago
Who is selling half-price stamps?
#1 How big is your potential market? It's people still mailing things from home, who haven't figured out how to do postage on their computer.
#2 Of the population in #1, it's those who find real stamps so expensive that it's worth bothering with discounts.
#3 Of the population in #2, it's those who would want to buy something fraudulant (or not know better) and who would want to risk using it.
#4 Considering the size of the #3 population, how many stamps do they use in a month?
#5 What is your margin on a half-price stamp? You have to pay for advertising, printing (we're talking a profit margin under $1), packaging, and your own time, but at least shipping is free!
Comment by wildzzz 3 days ago
Comment by mmooss 3 days ago
Comment by _carbyau_ 3 days ago
Watch the news and see CEO's with golden handshakes after the company is nailed for something. Wall street failures. Companies getting government bailouts. The current US president. It is all about getting away with what you can.
The news - being the news - doesn't show process as per normal. People doing the right thing most of the time.
In this context, fake stamps for the "little person" doesn't even rate a mention. Who the hell is going to raise a moral panic about an old lady with fake stamps...
And so the "little people" will keep buying fake whatevers as long as it stretches their dollar further.
Comment by Scroll_Swe 3 days ago
So is it greed? Yes, but I did it too so now that its more accessible I cannot really blame people.
Comment by hakfoo 2 days ago
Stamp collectors end up stuck with sheets and sheets of unpopular designs, and since the hobby (like many hobbies) has imploded, the dealers will pay less than face value for it; they in turn will sell it for a smaller discount for people who are willing to futz with wallpapering their envelope in 3-cent stamps and Fat Elvis.
Comment by floam 3 days ago
Comment by zeafoamrun 3 days ago
Comment by Pxtl 3 days ago
Comment by kube-system 3 days ago
Comment by Terr_ 3 days ago
The USPS becomes directly involved only later, when someone tries to defraud them by using a fake stamp.
Comment by floam 2 days ago
Comment by rrr_oh_man 3 days ago
Comment by al_borland 3 days ago
It’s not like they’re buying these things out of a car trunk in a dark alley. These retailers need to be held liable for selling these things. If they sell this stuff, why not illicit drugs?
If they are unable to maintain control of 3rd party sellers, then they should end the 3rd party seller program. It has done nothing but damage Amazon’s reputation, and it just keeps getting worse.
Comment by nvme0n1p1 4 days ago
There are lots of people alive who grew up during the days of broadcast TV and radio. I get why they might not understand the difference.
Comment by weberer 3 days ago
Comment by nvme0n1p1 3 days ago
To most people IPTV is a bunch of gibberish letters, indistinguishable from the gibberish brands on Amazon. Someone's grandma from Colorado doesn't deserve to get scammed because she didn't research the acronyms.
Comment by kube-system 3 days ago
Comment by crote 3 days ago
It is paid for via ads or subsidies, so there's no reason to block access to the stream, so they just don't bother, and make life easier for anyone building streaming devices wanting to integrate their channel.
Someone accessing the stream directly is not the originally intended use case, but it isn't any different from someone accessing it via their smart tv.
Comment by nuxi 3 days ago
- How are these "legitimately free"? For example AMC is a commercial TV channel and as far as I know, they don't offer free streaming. Same goes for MGM, FilmBox etc.
- Strictly speaking this isn't IPTV, it's just web streams. IPTV is usually delivered via multicast (MPEG-TS/RTP/RTSP streams, over UDP mostly).
Comment by bluedino 3 days ago
Comment by Scoundreller 3 days ago
Comment by Tangurena2 3 days ago
From a link above to the story on darknetdiaries:
> For Pokemon, there is a website that tells you how to watch this. You start off on Netflix, then swap over to the Pokemon streaming service, which is the only place that has Season 2, then swap over to Prime Video for Seasons 3 through 5, swap to Freevee, then Hoopla. Season 13 is only on Amazon, though. Then swap to Tubi, then Hulu, then Roku channel, and then finally back to the Pokemon streaming, and then Netflix. Easy.
That's 8 different streaming services to view one series.
Comment by tomaskafka 3 days ago
Comment by fred_is_fred 4 days ago
Comment by 1970-01-01 4 days ago
Comment by bayarearefugee 3 days ago
If they were using the system to rip off random people, I'd be 100% against it, if they are fucking Google and the giant corps that advertise with them, ehh.. not my problem and can't be assed to care. Google is not a positive force in the world. Hasn't been for many years.
Comment by mschild 3 days ago
Sure, Google's paying but they get their money regardless.
Comment by chowells 3 days ago
Comment by inigyou 3 days ago
Comment by crote 3 days ago
Let's say you are an ad buyer. Previously 1M clicks resulted in 1000 sales, now 2M clicks result in the same 1000 sales. If you previously paid $1000 for 1M clicks, you paid $1/sale. If they are now asking you to pay the same $1000 / M clicks you'd be paying $2/sale, so Google would have to drop to $500 / M clicks to offer the same value to advertisers.
But the same applies to ad sellers as well. Google would have to slash payouts to websites displaying ads by the same 50% / click or they'd be cutting into their margins. A competing ad platform without fraudulent clicks would be able to slide into this space, offering both a better value to ad buyers and a better payout to ad sellers, so they'd be taking market share from Google without having to do anything themselves.
Of course that assumes a market in which the value of ad clicks, views, and placements is clear to everyone and switching between ad platforms is trivial, which is not even remotely the case.
Comment by wildzzz 3 days ago
Its either the ad network running these click botnets or contracting someone to do it. If it was just impressions getting boosted, that just looks shady, those are barely worth anything.
Comment by inigyou 3 days ago
Comment by pessimizer 3 days ago
If you told normal people that they could get free content with a TV streaming stick that would also constantly fake clicks on AI generated websites to screw advertisers over, they would think of it as a bonus. Also it would make them trust the stick more (fallaciously), because they would know how the people who sold it were getting paid.
Comment by GolfPopper 4 days ago
Comment by Scroll_Swe 3 days ago
Comment by dang 3 days ago
These things are not what HN is for, and destroy what it is for, so we ban accounts that do them repeatedly.
If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here, we'd appreciate it.
Comment by ajnin 3 days ago
Comment by inigyou 3 days ago
Comment by tomjen3 3 days ago
Comment by pibaker 3 days ago
It's difficult to judge the price of media products. We have legal music streaming services that charges you an album's worth of money a month and lets you listen to millions of songs. You can pick up old AAA games for less than ten bucks. I'd say when people say that price tag, they don't think they get scammed into being a part of a botnet. They think the device manufacturer cut a good deal with the media rights holders.
Comment by joshmn 3 days ago
It's worth separating the two populations:
My users had money and had considered legal subscriptions. They paid me because the legal product was worse—in my case, sports blackouts, a bunch of different apps, etc. They knew what they were buying into and they had weighed the risk. I can tell you right now some of my former users have bought into this market.
Then there's the unwitting: a person buying one of these devices at a too-good-to-be-true price is treating it as a hardware purchase from Amazon, where the actual monetization isn't inferable from the listing. Calling it too good to be true assumes the buyer can see what shit they're standing in. They can't. There's no visible market here. It's just a product page with reviews.
To add to this: the proxy exit is exactly why these cost so little. Demand for residential IPs is booming (check some of the proxy subreddits to see what I mean).
The ironic part is that there's a chance the person who bought one of these boxes to watch pirated sports was the exit node I was using to acquire the feeds in the first place.
Comment by paultopia 3 days ago
[1] Can someone explain what the theory of the product is here? It sounds like they’re marketing these things as ways for the customer to commit fraud, for example by connecting to someone else’s login. How else would the customer expect to be able to get free Netflix or whatever?
Comment by chihuahua 3 days ago
Comment by IncreasePosts 4 days ago
Comment by ghostly_s 3 days ago
you are aware broadcast TV never ended?
Comment by IncreasePosts 3 days ago
But, I think it's far more common for people to have a TV service today, perhaps since comcast and their ilk push hard the TV/phone/internet bundle, and gone are the years when everyone would fiddle with the antennas on the back of their TV to get the right reception.
Comment by myself248 3 days ago
Comment by bdangubic 3 days ago
Comment by iugtmkbdfil834 4 days ago
Anyway, I think some level of blame is warranted.
Comment by chihuahua 3 days ago
Comment by elzbardico 3 days ago
Comment by varispeed 3 days ago
Comment by croes 4 days ago
Comment by rng-concern 3 days ago
It reminds me of the saying: "It Is Difficult to Get a Man to Understand Something When His Salary Depends Upon His Not Understanding It".
If these people thought about it for a few minutes, they would understand, but they choose not to, as ignoring it is too advantageous.
I admit I was tempted, as the price of all streaming services goes up, and services become more and more fragmented. During the same period where I have not had a raise.
Comment by acdha 3 days ago
Comment by inigyou 3 days ago
Comment by rng-concern 3 days ago
My point was, their ethics WOULD have prevented them from doing the thing. But they chose not to think about it too hard. Perhaps subconsciously. I'm not above doing this sort of thing either. We all do it for various things.
I've added code that is bad for the user (overbearing telemetry for instance) because my salary depended on it. At the time I tried not to think about it too much, as it would cause cognitive dissonance.
Comment by flerchin 4 days ago
Comment by Cider9986 4 days ago
Comment by ghostly_s 3 days ago
Comment by Cider9986 3 days ago
Comment by ghostly_s 3 days ago
Comment by Cider9986 4 days ago
Stremio +Torbox is $3/month and they can probably share 10+ households on one TorBox account so it could work out. The seller could just stop paying the TorBox subscription at whatever point and they have an incentive to do so.
Comment by glitchc 4 days ago
Comment by alistairSH 4 days ago
The only winner here is the scammers running the fake affiliate sites on which these sticks are "clicking". Or, am I missing some facet of this enterprise?
Comment by frollogaston 3 days ago
Comment by hnav 3 days ago
Comment by inigyou 3 days ago
Comment by snickerbockers 3 days ago
Comment by inigyou 3 days ago
Is Mullvad an accessory to downloading CSAM if someone does that?
Comment by snickerbockers 2 days ago
Comment by elzbardico 3 days ago
Comment by ssl-3 3 days ago
I mean: They just pay the money, plug the thing in, push some buttons, and: TV happens. Right?
Comment by cryzinger 3 days ago
Comment by frollogaston 3 days ago
Also, visitors on my wifi started getting strange ads. Yes I threw off the algo, but I'm a guy with wife, I'd rather get car ads than like divorce lawyers + gay dating sites.
Comment by picofarad 2 days ago
Comment by snickerbockers 3 days ago
Backdoors and spying are also a problem in theory except at this point you can't even trust "legitimate" companies on that front so it's a moot point.
Comment by acdha 3 days ago
How that actually works in practice is that your favorite sites make less money and your IP gets a bad reputation so you CAPTCHAs or outright blocked. There’s no “sticking it to the man” here, just contributing to the frictional grind making the internet worse for ordinary people.
Comment by snickerbockers 3 days ago
Comment by inigyou 3 days ago
Comment by DennisP 3 days ago
(IP reputation keeps me from doing it though.)
Comment by elzbardico 3 days ago
The ad supported web is, with very few exceptions, useless.
Comment by snickerbockers 3 days ago
It's arguably fraudulent to even refer to it as "advertising" at this point, clearly that's just a cover to give them an excuse to sell data to silicon valley corporations that are unironically named after fictional devices used by sci-fi/fantasy villains to manipulate people.
Comment by kube-system 3 days ago
Comment by blackjack_ 3 days ago
Comment by pixl97 3 days ago
Comment by tjpnz 3 days ago
Comment by elzbardico 3 days ago
Comment by ColdStream 3 days ago
Comment by culi 3 days ago
Comment by em-bee 3 days ago
but compare running tor nodes, and especially exit nodes. that surely would be a good thing, so at least if you think tor is good then running a proxy should be the same and it should be normalized.
doing it in secret without the user knowing is what's bad
Comment by glitchc 3 days ago
Comment by Dylan16807 3 days ago
Comment by inigyou 3 days ago
Comment by iamnothere 3 days ago
Comment by inigyou 3 days ago
Comment by corbet 3 days ago
Comment by MrDrMcCoy 3 days ago
Comment by 40four 3 days ago
Comment by em-bee 2 days ago
and what about tor? should that be shut down too? or is there a legitimate reason for it to use residential proxies?
Comment by inigyou 3 days ago
Comment by ta988 3 days ago
Comment by deepfriedbits 3 days ago
Is it a graphic that's shared? Something else? I am sure we all know or have heard of people with these devices that promise free streaming.
Comment by Arainach 3 days ago
Remember, a significant portion of the population got angry (often violently so) when just asked to wear a mask to protect their neighbors. And the threat there was significantly easier to explain.
Comment by pibaker 3 days ago
Comment by inigyou 3 days ago
Comment by ValdikSS 3 days ago
And don't forget about counterfeit products (which look like original but different in firmware) and supply chain attack vectors, which are really, really common.
If you want to buy something as simple as a feature phone, going to a store with 10 of them will give you at least 1/10 chance to buy a phone with a trojan/backdoor.
Comment by ta988 3 days ago
Comment by SecretDreams 3 days ago
Comment by inigyou 3 days ago
Comment by scottydelta 3 days ago
Fast forward to last month, now I have started selling these in Barcelona, Spain where I am based out of and branched it into three use cases: digital signage, casting, and a portable computer for presentations at events. Here is the link with features: https://soljacast.com
Comment by emacdona 3 days ago
Comment by scottydelta 3 days ago
Comment by 0manrho 3 days ago
However, if your target is B2B (Business to Business) as opposed to B2C/D2C (Business to Client/Direct to Client) and you're selling the install plus enterprise support, then the sales thing makes way more sense, and is more expected/palatable for B2B type customers than your everyday consumers, so depends on who you're targeting.
Comment by scottydelta 3 days ago
Also right now we are focusing on B2B here in Spain like you guessed, and once we have the other things figured out, we will start shipping to the US and Europe. And after that we plan on rolling out to the rest of the countries.
Comment by emacdona 3 days ago
Comment by scottydelta 3 days ago
Thanks for liking my product enough to want to buy it right away :)
Comment by crote 3 days ago
Comment by scottydelta 3 days ago
Also, we want to test our OS extensively before we release it to be used with a BYOD model. We are launching soon and after that we will try to offer BYOD model as well.
If you are interested in trying it out and helping me in evaluation, please reach out to me via email on my HN profile. Thank you
Comment by cryptoegorophy 3 days ago
Comment by scottydelta 3 days ago
Comment by throwawsy7273 3 days ago
Comment by scottydelta 3 days ago
Comment by crooked-v 3 days ago
Comment by scottydelta 3 days ago
Comment by crooked-v 3 days ago
Comment by scottydelta 3 days ago
Comment by TiredOfLife 3 days ago
Comment by sajithdilshan 3 days ago
Comment by scottydelta 3 days ago
> Trust me, I really wish it were that easy. We're based out of Spain, so to sell in the US (or other countries) we either need to figure out assembly of the device there, or we need to solve cross-border payments, logistics, customs clearance, tax remittance to individual states, and hardware compliance. That said, we're working hard on all of it and plan to go D2C as soon as possible.
For the pricing part, I am still trying to figure out the pricing for retail consumers. It was relatively easier to do for B2B but for retail, there are a lot of factors and moving parts such as import duties, taxes, shipping etc.
Comment by sajithdilshan 2 days ago
Comment by scottydelta 2 days ago
Comment by matheusmoreira 3 days ago
Comment by russdill 3 days ago
Comment by __turbobrew__ 3 days ago
Comment by matheusmoreira 3 days ago
Comment by inigyou 3 days ago
Comment by __turbobrew__ 2 days ago
Comment by inigyou 2 days ago
Comment by __turbobrew__ 1 day ago
Comment by ur-whale 3 days ago
I mean, I don't believe VLAN's were designed with security as a goal, and I wonder how "strong" the virtual wall between two VLAN's actually is?
Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physical connection where packets from both VLANs happen to travel?
Just wondering.
Comment by rcoder 3 days ago
A bad switch or router (which almost certainly includes a ton of crappy home APs and routers, compromised by the same actors who ship these devices) could let clients see VLAN tags and ignore them.
And an Ethernet “hub” does no filtering at all.
Comment by rcoder 3 days ago
And any kind of multicast (used for local service discovery and media streaming) has the same limitations.
Comment by xorcist 3 days ago
> Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physical connection where packets from both VLANs happen to travel?
That would be an exceptionally weird configuration. If a device "sits on VLAN1" that typically means that it's on an "untagged" port where only VLAN1 traffic is allowed. Ports that carry multiple VLANs are "tagged" ports and you normally wouldn't say they "sit" on any specific VLAN, precisely because that port carries tagged traffic for multiple VLANs. It's at best an irregular use of the terminology but likely a misunderstanding somewhere.
Comment by inigyou 3 days ago
You usually want to interconnect them at one central point, usually a router, and enforce a security policy there.
Comment by ahahs 3 days ago
Comment by matheusmoreira 3 days ago
Really wish I could point Mythos at my router and just loop it until my router becomes literally unhackable.
Comment by TylerE 3 days ago
Comment by skinfaxi 4 days ago
Comment by krebsonsecurity 4 days ago
https://github.com/synthient/public-research/blob/main/2026/...
Comment by SoftTalker 3 days ago
I scanned the comments and I didn't see anyone suggesting that these companies should share any responsibility for selling these harmful products. Why is it that they seem to get a pass? Would we feel the same about giant retailers selling tainted food, or unsafe children's toys?
Comment by al_borland 3 days ago
This is the problem with being an “everything store”. “Everything” includes a lot of things most consumers would like to be protected from, and assume they are due to the long history of retailers standing behind the products they sell. That history seems to have come to an end. They only stand behind it enough to offer a refund if there is a problem, not to ensure it’s good before selling it.
Comment by omilu 3 days ago
Comment by femto 3 days ago
https://www.abc.net.au/news/2026-07-27/australian-tomatoes-l...
Comment by onionisafruit 3 days ago
Comment by femto 3 days ago
Comment by stubish 3 days ago
(edit: whoops, Choice did the SPF rating investigation. ABC just did a lot of reporting on it)
Comment by biztos 3 days ago
https://www.cbp.gov/newsroom/national-media-release/cbp-issu...
If Costco were circumventing the ban it'd be a pretty big deal. I couldn't google up any indications that they are, so on balance I'd say it's "possible" in the same way my winning the lottery is possible. Can't rule it out, but reasonable people should probably bet against it.
TIL: Xinjiang tomatoes are something like 15% of the global market!
Comment by seanmcdirmid 3 days ago
China consumes 37% of the world’s tomatoes. 80% of China’s processed tomatoes are from xinjiang. Fresh tomatoes are generally grown locally, but that is true around the world.
Comment by LordAtlas 3 days ago
Comment by seanmcdirmid 3 days ago
Comment by Nursie 3 days ago
I think that might be a bit of a strong assertion, from your article there -
"It analysed 221 processed tomato products from 39 brands, including paste, passata and diced tomato.
Twenty-two per cent of the products failed country-of-origin testing, while a further 6 per cent were flagged for further testing."
So while 28 percent is scandalous, and those companies need to face consequences, the other 72 percent seem to be genuine.
Comment by femto 3 days ago
Summarising the Australian situation, taking the 4corners results into account, the following non-Chinese tomato pastes are available:
Coles (29% market share): 1 x 140g premium product in a tube (expensive with reduced market share) out of about 20 products.
Woolworths (38% market share): 1 x 140g premium product (Mutti) in a tube (expensive with reduced market share) out of about 20 products.
Aldi (10% market share): None out of about 4 products
IGA (7% market share): 5 of 16 products, being the same premium brands that Coles and Woolworths sell.
Maybe qualify my comment with "by market share and availability". The effect is that if you stand in front of an Australian supermarket shelf, every product, bar one or two in the corner, come from China. China is a proxy for Xianjing, in that sources say 80%-90% of tomato paste from China comes from Xinjiang.
Hence the assertion I made.
Market share data: https://www.accc.gov.au/system/files/supermarkets-inquiry_1....
Xianjing percentages: https://tomatonews.com/countries/china/
Comment by Nursie 3 days ago
Eh ...
"Well-known tomato brands that passed country-of-origin testing include Mutti, SPC, Woolworths, Providore D'Italia and Annalisa. Diced tomato cans and passata from Leggo's and Coles also passed."
So here are 4 tomato pastes in woolworths that would seem to pass the test of not being from China and not being liars, just from a quick search (and I have seen all these in my local) -
https://www.woolworths.com.au/shop/productdetails/290303/mut... https://www.woolworths.com.au/shop/productdetails/218066/mut... https://www.woolworths.com.au/shop/productdetails/901431/mac... https://www.woolworths.com.au/shop/productdetails/150875/pro...
I usually buy Mutti stuff because it's low-ish salt, and that claims to come from Italy and wasn't implicated in the report here. And while I understand those are at the 'premium' end, it's not like it's one product on the end of the shelf either.
It's true that "Leggo" occupies a lot of the shelf space and a lot of the cheaper 'own brand' stuff is labelled as coming from China. And coles appears to be in a weirder/worse spot that woollies, with only Providore being Italian and two brands of turkish tomato paste, which is interesting.
It's sad that I can't find an Australian tomato paste that isn't a liar.
So I'm still not fully on board with "nearly every", OTOH thanks for the further information. I shall continue to try to avoid these products!
Comment by p-e-w 3 days ago
Comment by iamnothere 3 days ago
Comment by femto 3 days ago
Comment by perpetuallunch 3 days ago
Harm to the end user: none^
Benefits to the end user: more affordable tomato paste
Government action to prevent slave labour products entering Australia: none^
^close enough.
Comment by stubish 3 days ago
Comment by kkotak 3 days ago
Comment by stubish 2 days ago
Comment by perpetuallunch 3 days ago
The ABC is a know, as in they don't even try to pretend propriety, propaganda outlet of the Australia Albanese federal Government.
I'm not saying this is definitely propaganda, but there's a non-zero chance it is.
The Albanese government has been very open about attacking industry.
Comment by stubish 2 days ago
Comment by martimarkov 3 days ago
No propaganda - lack of validation, evidence and trust
Comment by perpetuallunch 3 days ago
Comment by neves 3 days ago
Comment by riddlemethat 3 days ago
We bought a different model from Costco and it’s been rock solid. I expect I will never buy a major appliance from any other retailer as long as Costco continues to care like they do today.
Comment by fn-mote 3 days ago
Weird. You experienced failures of the manufacturer (failure to start) and the warehouse (huge scratch), and are still singing someone’s praises.
It sounds to me like the brand’s quality assurance is low and the retailer also isn’t taking care of their stock.
If I had to take three days off work to accept these deliveries, doubtless I would have a very different conclusion from yours.
Comment by dsr_ 3 days ago
Any dishwasher could have these problems; any warehouse could. How the seller handles the situation is key to whether you use them again.
CostCo has built a huge reputation for being trustworthy as a retailer. If they get purchased by private equity, I will stop renewing my membership, and think about how close the country is to decorating lampposts.
Comment by 542354234235 3 days ago
But most people have had a problem with some product they purchased and a company that stands by things and gives no questions asked support is very valuable.
Comment by rpdillon 3 days ago
I say this as a happy customer of both, though. I don't seem to have the problems others do with horrible products from Amazon, but I suspect my purchasing habits might be different as well.
Comment by _RPM 3 days ago
That's called stinking thinking.
Comment by Guvante 3 days ago
"The next purchase I make will be through X to avoid having to search for a new retailer"
Comment by contagiousflow 3 days ago
Comment by 40four 3 days ago
We’re specifically taking about merchants that have a super shady online presence. They will basically sell you anything and everything and don’t care if it harms you.
The ones mentioned (Amazon, Best Buy, New Egg), it’s going to be hard to argue they vet (or care about vetting) the digital products they sell. You might as well throw Walmart into group too, their online offerings have gotten super sketchy if you really do into it.
Comment by Uvix 3 days ago
Comment by SoftTalker 3 days ago
Comment by bell-cot 3 days ago
And most of Costco's sku's are food, clothing, housewares, bulk consumables, and such - vastly easier to test and vet than computer & internet-connected electronics.
Comment by ChoGGi 3 days ago
Comment by bell-cot 3 days ago
But that's kinda like saying that Random Pond is safer for swimming than a lava lake.
Do I just assume nothing can go wrong when I myself shop at Costco? NO.
Comment by altruios 3 days ago
For example: this is a minor annoyance, but comes readily to mind.
https://www.costco.com/p/-/orgain-organic-protein-and-superf...
The problem is labeling conventions leading to inaccurate assumptions of what's even IN that "protein powder"...
you would think the protein, being the largest in print, is the primary ingredient but no. A serving is 51grams, and the protein makes up 21grams of that serving: less than half, that's not a 'protein powder' if the primary ingredient isn't protein.
It should be labeled "SUPERFOODS with protein" not the other way around.
There have been other things similar in scope less readily recalled. It may seem minor to some... but labeling accuracy and transparency is something we had to fight for collectively.
Comment by tejohnso 3 days ago
However, this is plant-based protein, not pure way isolate. A plant-based protein powder from mung beans for example isn't going to be 100% protein. Chickpea powder contains roughly 20% protein.
So I don't know if that helps at all, but it doesn't seem as bad as you and you might be suggesting.
Comment by al_borland 3 days ago
Comment by tiltowait 3 days ago
Comment by Rickasaurus 3 days ago
Comment by onemoresoop 3 days ago
Comment by red-iron-pine 3 days ago
fixed fee membership also means a very stable revenue stream and they can take the time to do this, while other places like newegg are herding 3rd parties to get cuts of ever cheaper 3rd party crap
Comment by Aerroon 3 days ago
The above actually happened to me. That's what online retailers were like before Amazon's reach properly extended here. That's also the main value proposition for these retailers for me.
Also, online retailers are far more likely to accept returns compared to regular stores. If you get a bad product from a regular store you're often just screwed.
Comment by swatcoder 3 days ago
Later, when you want to try the return, a black box algorithm asseses your transactional value to Amazon and decides whether your concerns are worth attending and to what degree.
Maybe that really is better than whatever you were used to in your own market, but it's a profound regression on the traditional retail experience for most of us here.
Comment by ephemeral67 3 days ago
Comment by bdamm 3 days ago
Comment by bluGill 3 days ago
30 years ago a friend of mine did the mold for a lawn mower. They put an engine on it and it ran for 120 hours before the deck failed. It took 7 more tries until the deck failed after 80 hours. Commercial mowers are expected to run over 1000 hours.
Comment by bigiain 3 days ago
Comment by zdragnar 3 days ago
Comment by Slash65 3 days ago
Comment by taneq 3 days ago
Comment by HDBaseT 3 days ago
It is in rough shape, but it still cuts grass perfectly fine.
I have a wippersnipper from before I was born which runs perfectly today. It was left out laying sideways in the rain for about a month. Quick clean and a new plug and it was going again.
I'm sure the electric devices can run a long time, but when they fail, they tend to be not repairable.
Comment by markdown 3 days ago
Comment by taneq 3 days ago
Comment by zhengyi13 3 days ago
Serious question, as I understand the ex-Japanese market rights were sold to a Chinese corp over two decades ago, and the in-Japanese consumer device market rights went to a different Japanse company several years ago too.
Apparently they've gone back to focusing on their roots?
Comment by lazylester 3 days ago
Comment by taneq 3 days ago
Comment by MostlyStable 3 days ago
Comment by drnick1 3 days ago
Comment by classichasclass 3 days ago
Comment by nullhole 3 days ago
Mine's a fancy-pants Stihl battery mower, but it works quite well and has been doing so without problem since I bought it ~4 years ago. The other battery stuff from the same brand (trimmer, chainsaw, kombi-tool) have the same story.
Comment by bluGill 3 days ago
Comment by zrobotics 3 days ago
For instance, the MS182 [0] is a $270, 2.2cu in saw with a 16" bar listed "For homeowners and light duty work".
Meanwhile, the MS201 [1] is $1100 for a 2.1cu in saw with a 16" bar listed as "The lightest professional gas chainsaw from STIHL Perfect for delimbing work in forestry".
Service interval on the 201 will be much longer, and it's expected to last longer but is priced accordingly. I ended up having to buy one of their homeowner grade saws 10 years ago when I was up in the mountains and my saw died, that was all that was available locally. I'm certainly not a professional, but at the time my primary heat source was wood and I had always used the stihl pro-grade saws. However, that cheap stihl was an absolute piece of junk, it was half wore out after cutting 2 cords of firewood that first time. Terrible ergonomics and poor power to boot, even after reserving the saw for light-duty work it only lasted 2 years and was miserable to start and run the entire time.
At least they explicitly say that they are for light duty though, a less honest company would market everything as pro-grade. But don't just buy the name, while they make good quality products they also sell cheap crap under the same name. It also isn't that clear in a retail store besides the price which ones are the homeowner grade saws.
[0] https://www.stihlusa.com/en/p/chainsaws-ms-182-gasoline-chai... [1] https://www.stihlusa.com/en/p/chainsaws-ms-201-gasoline-chai...
Comment by nullhole 3 days ago
What matters is the amortized cost per year, I think - more expensive up front but cheaper in the long run.
Comment by timc3 3 days ago
Comment by newAccount2025 3 days ago
Comment by bigstrat2003 3 days ago
Comment by maxerickson 3 days ago
My battery mower is quiet enough that I don't feel terribly rude mowing at twilight.
Comment by astura 3 days ago
Comment by Gigachad 3 days ago
Comment by exe34 3 days ago
Comment by actionfromafar 3 days ago
Comment by jon-wood 3 days ago
Comment by zombot 3 days ago
Comment by deaton 3 days ago
Comment by boondongle 3 days ago
Hell, there's a section of comments that would probably going "hey, RELAX guy" because it's not US companies doing this. For any American companies that do this though, sure - block/suspend/prosecute.
Comment by malfist 3 days ago
Or if I open up a gas station and allow any company without oversight to sell "supplements" through my shelves and cops arrest me for selling heroin, I don't get a free pass.
Why should amazon or Walmart get a free pass just because they sell more items?
Comment by awakeasleep 3 days ago
You have to be able to show damages you incurred and assign a dollar value to them to sue people.
That doesn’t work at all for a something that sells your bandwidth to a proxy service. People wouldn’t even be aware that it was happening they weren’t told.
Comment by SoftTalker 3 days ago
Comment by ndsipa_pomu 3 days ago
Comment by xorcist 3 days ago
Not legal advice.
(It would surprise me greatly if we as a society let these gadgets be sold openly from here on.)
Comment by inigyou 3 days ago
The cybercrime raids happen when they run into someone who looks like a hacker and has a lot of computers.
Comment by II2II 3 days ago
While there would be oversight, it is highly unlikely that a person opening a home improvement store would perform any meaningful safety testing. They simply would not be qualified. The oversight would lay in selling certified products, pulling recalled products off the shelf, and (perhaps) removing products if there is a reason to suspect safety issues.
Now consider streaming sticks. There are safety standards for the physical device but, to my knowledge, there are no such standards for the software itself. Heck, there aren't even standards for the engineers who work on the software. One can make highly prejudiced decisions based upon the country of origin. Perhaps there are even good reasons to avoid products from certain countries. Yet the lack of standards also means that products from trustworthy sources can be suspect, since all it takes is a management decision to change things.
Comment by inigyou 3 days ago
Comment by wsintra2022 3 days ago
Comment by CrazyMusicians 3 days ago
Comment by inigyou 3 days ago
Comment by jon-wood 3 days ago
Its incredibly obvious to anyone applying any thought at all to this that its a malicious to sell a product that labels itself as a TV streaming stick which is in fact a paid for relay server with the money made from providing the internet connection to a random third party unrelated to the person who bought the thing without ever telling the customer.
Comment by inigyou 3 days ago
Comment by jon-wood 3 days ago
Comment by inigyou 3 days ago
Comment by crote 3 days ago
You already answered it: block it from being sold.
1) Make Amazon responsible for the products they are selling. 2) Introduce a law banning malware tv sticks 3) Sue Amazon for a percentage of their yearly revenue when caught violating it 4) Amazon will finally start caring and do some kind of review on the crap they sell.
Comment by pixl97 3 days ago
That's the biggest problem with any device that updates.
Yea, this will work for the moment and the seller will be covered in the sense that "well, it wasn't infected when we sold it".
Comment by deaton 3 days ago
Comment by pixl97 3 days ago
Comment by themaninthedark 3 days ago
You don't want to penalize someone selling their Xbox or lawnmower on Ebay but you want to stop what is going on here. A place like Etsy where people are selling their crafts is an interesting edge case but I think they should probably be a little regulated.
Comment by StilesCrisis 3 days ago
Comment by AngryData 3 days ago
US retailers can be told they can't sell it here. If you buy it outside of that, well that is buyer beware, but 99% of people aren't buying things from Alibaba or ordering from some random foreign store, they are buying them off US Amazon, Walmart, big box retailers, etc. You don't have to ban things consumer level to deal with 99% of it, you just gotta tell big corporations no and stop dismissing any ideas that put responsibility or liability on big business.
Comment by crote 3 days ago
And the "retailer" on record is of course not a real company. They'll just pay some third-party to file a bunch of paperwork in Delaware, pay the $110 fee, and let it go bust if anyone tries to investigate it or make it liable.
Comment by pixl97 3 days ago
While it's great we're getting the manufactures to just stop sending out straight malware and it should be stopped the next most obvious means of attack is just having the device update and add superaids to it's new functionality.
So, no, it won't stop 99% of it at all.
And honestly this isn't that much different from what US companies are already great at by providing updates that take away features we bought with the device.
And not just updating really doesn't save you, instead of being part of a factory botnet, you're just open to become part of some other botnet.
Comment by skybrian 3 days ago
Some manufacturers will try to cheat on the tests, but we have AI security checking now, so maybe that would make it harder to cheat?
Comment by iamnothere 3 days ago
(I’d be open to a rule that devices must allow users to wipe the devices and install their own OS.)
Comment by skybrian 3 days ago
Comment by lesostep 3 days ago
Buying in bulk for a resell without testing even one product is kinda insane.
Comment by ChuckMcM 3 days ago
Once a vendor has been notified that these units are doing these sorts of things they will stop selling them. Its sadly very prescriptive in that if Newegg gets a notice that "WatchFunTV" streaming sticks are doing this, they will remove that brand but if the same hardware shows up from the same vendor as "SuperTVStreamer" or some such, that product won't be banned until someone does the test and then notifies the sellers. It's cat and mouse all the time.
Now the people who could do something about it, the ad networks like Google, do not do anything because ad revenue is ad revenue, people buying the ads cannot prove that the click was false so hey who can say it was? Which is why ad fraud is a perennial favorite of crooks. The people being ripped off don't have any way to prove it without a lot of support from the ad network traffic data which is "proprietary". Really stupid ad fraud gets shut down, but put a bit of care into it so that the Ad network and claim ignorance? You can do that all day. Just don't get greedy and try to pull in more than say 30 or 50 thousand dollars a month. Remember, the IAB said in 2025 alone Ad Revenue was $300B[1] so 2% of that is only $6B and any network with 2% or less of undetected fraud is considered a "high quality" ad network.
So yeah, ad fraud is the gift that keeps on giving.
[1] https://www.iab.com/insights/internet-advertising-revenue-re...
Comment by mattmcknight 3 days ago
Comment by eddythompson80 3 days ago
At some point in the second half of the 2010s Amazon figured out they can’t compete with a million foreign randomly-generated companies on price, and their users didn’t seem to mind too much. They figured their users cared about delivery times, ease of returns, ease of dealing with Amazon instead of dozens of online sellers, etc and they leaned heavily into that. They will handle fulfillment and take their cut and let people buy whatever garbage they want. They still screw sellers too btw. Ask any one who is trying to sell something on Amazon and they will fill your ear with how much leverage amazon has over them. You can check r/FulfillmentByAmazon/ Or r/AmazonSellers for stories.
Comment by eightysixfour 3 days ago
Comment by dessimus 3 days ago
Comment by tomjen3 3 days ago
Now that's very different from "we are selling things that we know, or have good reason to know, specifically are dangerous" — here they might very well be liable.
Comment by ryandrake 3 days ago
Comment by SoftTalker 3 days ago
Comment by StilesCrisis 3 days ago
Comment by fragmede 3 days ago
Comment by StilesCrisis 3 days ago
(Also of note: WHY melamine in the baby formula? Because they knew the buyer would check the nitrogen content, because it's a caveat emptor culture.)
Comment by lotsofpulp 3 days ago
Voters don’t like seeing themselves or their kids get hurt, but they do like lower cost live sports.
Comment by tclancy 3 days ago
"Money talks. And bullshit brothers walk a marathon."
Comment by bashtoni 3 days ago
Comment by themaninthedark 3 days ago
Sure they try to vet the app but how does that absolve me from the liability?
Comment by sneak 3 days ago
Sketchy devices on your wi-fi don’t really harm anyone. They’re a minor inconvenience at best, mostly to large corporations that like to discern residential connections from business/corporate ones.
Comment by inigyou 3 days ago
Comment by red-iron-pine 3 days ago
Comment by PufPufPuf 3 days ago
Comment by CrimsonCape 3 days ago
Comment by PufPufPuf 3 days ago
Comment by jojobas 3 days ago
Comment by yumraj 3 days ago
I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.
Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?
My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.
Comment by miohtama 3 days ago
1. They want more as targeting data on you
2. They want to reduce bot clicks
It's an unholy alliance with governments who want to know who writes what online.
Comment by inigyou 3 days ago
Comment by m3047 4 days ago
01: DDOS
10: Residential proxies
11: Somebody DDOSing residential proxies
Comment by drdexebtjl 4 days ago
I suspect these TVs either come with residential proxies set up from the factory, or they have such poor security that they’re instantly hacked. Either way, TV manufacturers (including reputable ones like LG) are to blame.
Comment by mikestew 3 days ago
Comment by inigyou 3 days ago
I don't think residential proxying is all that shady since groups like Cloudflare have made it a necessity. However, having it out-of-the-box on a name-brand device is extremely shady.
Comment by cwillu 3 days ago
Oh no! Not the advertising networks!
Comment by neves 3 days ago
Comment by gxs 3 days ago
I use one but only when traveling at hotels - it’s one of the only sticks that can connect to captive WiFi networks at hotels
I’ve got barely anything on it so privacy be damned - but at this point this is why I just buy apple products
I have two apple tv’s which probably do shady things too, but I’m willing to play the probabilities and assume it’s the least bad of my options short of tinkering with flashing hardware and all that stuff that used to be fun in my teens (emphasis on used to)
Comment by hn_submit 3 days ago
Instead they're banning stuff willy nilly left and right without really solving the problem.
But there's good stuff coming out of China as well. I recently bought a cheap e-reader which has no WiFi or internet connection and it works stellar. And I bought some cheap Chinese sport cams which also lack internet and work great.
Comment by autoexec 3 days ago
Personally, I think every other country should ban any product made by Google, Amazon, and Microsoft since they all spy on the users of their products too.
Comment by hn_submit 3 days ago
These companies could use the info they gather on customers for their own use but they cannot (re)sell it to anyone, not even the government. The reason being that the information eventually ends up abroad after which you lose all control over it.
Comment by atum47 3 days ago
Anyway, the box is powerful enough to do several things. You can install a IP tv if you want. If you don't, you still have a pretty good media center (you can hook up an external hd on it)
Comment by aucisson_masque 3 days ago
I switched to a Google box, this has no bloatware and this way I get tracked only by one company.
Comment by atum47 3 days ago
Comment by Scoundreller 3 days ago
Comment by utopiah 3 days ago
It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique.
An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.
Comment by LetsGetTechnicl 3 days ago
Comment by utopiah 3 days ago
Comment by thothless 3 days ago
https://docs.roku.com/published/userprivacypolicy
see: "olfactory", "content of"
or at least they're CYA while they're sniffing.
they definitely scan the entire local network.
Comment by Doohickey-d 3 days ago
Original with more details: https://www.bitsight.com/blog/fuyao-enterprise-building-ad-f...
Comment by RajT88 3 days ago
This is my surprised face.
Comment by inigyou 3 days ago
Comment by stronglikedan 3 days ago
You had me at "But"! ::swoon::
Comment by tomaskafka 3 days ago
Comment by bashtoni 3 days ago
The devices are used to sell proxy services and scam advertisers. This doesn't even need particularly large organised crime. It would certainly be easier than large scale illicit drug importation and retail, which is happening all the time.
Could China exploit these streaming sticks if it wanted to? Maybe, but no more than any other nation.
Comment by tossingafterxyz 3 days ago
Comment by coretx 3 days ago
Being a ordinary person, I do not want criminals or the ( ads/data ) industry or the state to be in control of my property.
Also, any DRM not passed by a parliament undermines the rule of law & statehood. This is something Krebs and his Praetorian guard buddies must know.
Comment by giraffe_lady 4 days ago
We're called engineers brian.
Comment by wao0uuno 3 days ago
Comment by dspillett 3 days ago
A Pi3 may suffice even, that is what I ran Kodi on before upgrading it to the Pi4, though the lack of hardware x265 decoding support is a limiting factor there (IIRC it'll manage 1080p in software, but only if you have some good cooling installed otherwise things get very skippy after a short while as thermal throttles kick in).
Comment by wao0uuno 1 day ago
Comment by dspillett 1 day ago
Only 265 though, the hardware support for 264 is limited to 1080 so 4K there means software decoding which I imagine being a problem much like 265 on the Pi3. It is pretty rare to see 264 used for 4K content though, in my experience.
Comment by j45 4 days ago
This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.
That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.
Comment by drnick1 3 days ago
That is not enough. You need to air gap devices that have legitimately no business communicating with anyone or anything outside the house. TVs, thermostats, and other Internet-of-Crap gadgets do not need "firmware updates." Either they work out of the box, offline or within the LAN, or they get sent back for a refund wherever they came from.
Comment by j45 3 days ago
Comment by spelk 3 days ago
Comment by j45 3 days ago
Limiting what outbound access devices can/can't have is an important skill to learn.
Comment by giantg2 4 days ago
Comment by ghostly_s 3 days ago
Comment by giantg2 3 days ago
Comment by autoexec 3 days ago
> Roughly twice per second, a Roku TV captures video “snapshots” in 4K resolution. These snapshots are scanned through a database of content and ads, which allows the exposure to be matched to what is airing. For example, if a streamer is watching an NFL football game and sees an ad for a hard seltzer, Roku’s ACR will know that the ad has appeared on the TV being watched at that time. In this way, the content on screen is automatically recognized, as the technology’s name indicates. The data then is paired with user profile data to link the account watching with the content they’re watching. https://advertising.roku.com/learn/resources/acr-the-future-...
Comment by timbit42 3 days ago
Comment by mikestew 3 days ago
Comment by kube-system 3 days ago
This is already a common feature for analytics toolkits.
Comment by giantg2 3 days ago
Comment by MattTheRealOne 4 days ago
Comment by theshrike79 3 days ago
I'm on my second one and I've owned them since the first version. My current one is the first generation 4k that's ... seven years old? Still works like new.
Comment by PcChip 4 days ago
Comment by noboostforyou 3 days ago
Comment by cogman10 4 days ago
Comment by Tepix 3 days ago
Comment by mbmbn 4 days ago
It was a rabbit hole and in the end I got back using my NVIDIA Shield. This is about 10 years now, but it’s actually still the best option.
Comment by giantg2 3 days ago
Comment by dwaltrip 3 days ago
Comment by drnick1 3 days ago
Comment by knowaveragejoe 3 days ago
Comment by Pxtl 3 days ago
Comment by haunter 3 days ago
Comment by ColdStream 3 days ago
Sounds good in theory but in practice, computers are good at sorting this stuff out. Kind of why they are so popular.
Comment by dxxvi 3 days ago
Comment by BigTTYGothGF 3 days ago
Every cloud has a silver lining.
Comment by theendisney 3 days ago
(Acepable would be something like 1TB worth of gamedemos)
Comment by cute_boi 3 days ago
Comment by joeisnotjane 3 days ago
Preparing casus belli.. first, open weights LLM which are "not secure", now "TV sticks"..
Oh joes and janes, who will put finally some sense into you..
Comment by Ikatza 3 days ago
Comment by joeisnotjane 3 days ago
China is not doing that as far as I know. Neither Russia did it before the war, though you were claiming the contrary (I know, since I live in the west and could compare news from both sides, being a native Russian speaker).
Comment by stevetron 3 days ago
Or Cinese noodles with Chinese tomatoes?
It sounds likw 2 domestic markets that China should use to rid themseves of their over-abundance of tomatoes.
Comment by a-dub 3 days ago
Comment by Hasz 3 days ago
I expect many cameras of “dubious” origin are used for similar tasks, same with most “smart” devices with sufficient horsepower.
Comment by estebarb 3 days ago
Comment by Mistletoe 4 days ago
Comment by wewtyflakes 3 days ago
Comment by ls612 3 days ago
Comment by wewtyflakes 3 days ago
Comment by ocd 3 days ago
Comment by trouve_search 3 days ago
Comment by ghostly_s 3 days ago
Comment by dhosek 3 days ago
Comment by inigyou 3 days ago
Comment by dhosek 3 days ago
Comment by zeroq 3 days ago
So you bought that top of the line security-as-a-product thingy you can stick in your rack and it will make sure that your network is impenetrable? You know, like those CISCO bricks everyone major company is buying.
So have you took an extra precautions to make sure that the firmware on the device is pristine? Do you know anyone who ever touched these devices who actually did?
Do you see the problem?
Comment by jojobas 3 days ago
These sticks leave the factory with malware pre-flashed, the postman brings them to your door with zero risk for the beneficiary.
Comment by mring33621 3 days ago
Comment by AlexandrB 3 days ago
Comment by perpetuallunch 3 days ago
Harm to the user: none^
> spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks
Harm to the user: none^
Cost to the dodgy service provides: none
Government action to prevent continued dodgy services: none^
This is why internet securityg doomers have a hard time selling their story. Changing behaviour has an upfront, immediate, cost. Not changing it doesn't.
^close enough
Comment by charonn0 3 days ago
> Harm to the user: none^
Well, they are losing some of their bandwidth. They might not notice, but something which is rightfully theirs is being taken without consent.
Comment by perpetuallunch 3 days ago
Comment by charonn0 2 days ago
The streaming stick in the article turns off its proxying feature while the user is actually streaming because the proxying feature consumes enough bandwidth to degrade streaming quality.
In other words, whenever the proxying feature is active every other device sharing the connection will suffer degraded performance.
Even if the user never notices, they're still worse off. They're still paying for bandwidth that someone else is using for profit. Money is flowing out of the user's pocket and into the pocket of the proxy operator. That makes the proxy operator a thief who is stealing from the user, and without even the Robin Hood-esque cover of defrauding ad networks.
Comment by rawgabbit 3 days ago
Comment by crote 3 days ago
Sorry, but "your tv stick does ad fraud" is just about the most innocent thing I've seen in a while. Everyone in this market is doing the shadiest shit you can imagine. There are no good brands left, you just get to pick what logo your Malware Entertainment Device has.
Comment by inigyou 3 days ago
Comment by kazinator 3 days ago
Compromised (or malicious from the factory) devices being recruited into bot farms for click fraud is ... a groundbreaking discovery in 2026?
> on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
To hell with AI-generated websites and advertising networks.
Say, where can I get the most effective malicious TV stick for click-frauding the fuck out of that shit? I will take fifteen! :)
Comment by snickerbockers 3 days ago
Comment by stuaxo 3 days ago
Looks like cheap small computer with a remote control.
Comment by cryo32 4 days ago
Comment by shevy-java 3 days ago
So the mafia is back.
Comment by phendrenad2 3 days ago
Comment by codedokode 4 days ago
Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.
What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.
How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:
- the user must be able to re-flash firmware with their own code.
- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.
- any telemetry or data collection, or updates must be opt-in only and disabled by default.
- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.
Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.
Comment by Thrymr 4 days ago
I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.
Comment by jrm4 3 days ago
Comment by Dylan16807 3 days ago
I want big companies to stop spying on me, which is a completely different issue.
Comment by jrm4 3 days ago
Both are well within the category of
"If you buy a device to do a thing, then the device does something else that is not readily apparent to the user that user would find objectionable if they had clearer knowledge."
This is immoral and harmful regardless of precise vector/action.
Comment by Dylan16807 2 days ago
But also the spying is expected by a lot of people. And a lot of people wouldn't object so much to screwing up internet ads.
Comment by Cider9986 3 days ago
Most Americans are at a greater threat of harm from their own government that a foreign one. What worries me is all the mass surveillance done by big tech which bypasses the 4th Amendment and gives the government Americans data without a warrant.
There's already a front door with the adtech for US alphabet boys. This could likely be collected by others as well. We saw this happened where foreign hackers exploited a backdoor designed for American authorities[1]. This is what experts are referring to when they say there's no backdoor only for me.
This could be compelling to politicians, though, and would certainly be a step in the right direction.
>- any telemetry or data collection, or updates must be opt-in only and disabled by default
This should be how it is for everything foreign made software or not. Would be very hard to get done with the big tech lobby in the US.
[1] https://techcrunch.com/2024/10/07/the-30-year-old-internet-b...
Comment by pavel_lishin 4 days ago
Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?
> for every imported device having a CPU and Internet connectivity
Why limit this to imported devices?
Comment by palmotea 4 days ago
> Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?
Cheap, slow-moving drones are the hot new missiles on the battlefield of today. This often talked-about model files at 115 mph (https://en.wikipedia.org/wiki/HESA_Shahed_136).
Comment by codedokode 3 days ago
Comment by bee_rider 3 days ago
Comment by IncreasePosts 4 days ago
Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)
Comment by mcphage 4 days ago
It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.
Comment by codedokode 3 days ago
Comment by BoppreH 4 days ago
Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys.
Could it be used for missiles? Sure. Is it obviously the intention? No.
Comment by meatmanek 3 days ago
Apple: https://support.apple.com/en-us/102515
> If Location Services is on, your device will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers to Apple to augment Apple's crowd-sourced database of Wi-Fi hotspot and cell tower locations.
Google: https://support.google.com/android/answer/15157297?sjid=1648...
> When Location Accuracy is on, Google periodically collects information about the locations of wireless signals and sensors observed by your device to crowdsource location estimates. This helps everyone find locations better.
Mozilla used to run a very similar service: https://en.wikipedia.org/wiki/Mozilla_Location_Service
Not to mention truly crowd-sourced databases like wigle.net.
Comment by codedokode 3 days ago
Comment by aeturnum 3 days ago
[1] https://support.google.com/android/answer/3467281?sjid=66634...
Comment by codedokode 3 days ago
Regarding the government, the problem is that many people do not fully understand the mechanism of collecting the data. I remember the case when members of US military disclosed the location of secret objects through fitness tracker app. And they were probably smarter than average smartphone user. Obviously it would be better if enabling GPS required an approval from their commander.
Comment by aeturnum 3 days ago
I'll agree that militaries would prefer their soldiers to not to dumb things - but I don't agree that it's 'obviously' best if people needed permission to enable GPS! If that's the case depends a lot on which soldier is enabling the GPS and their relation to me. In general I would say that government control of people recording and distributing their observations is associated with the most authoritarian governments and by claiming we should get government permission you appear to be aligning yourself with an authoritarian approach to data controls.
Comment by codedokode 3 days ago
Comment by mcphage 4 days ago
Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.
Comment by exe34 4 days ago
Comment by autoexec 3 days ago
Keep in mind that it's your IP and identity associated with those clicks and anything else criminals decide to do with your IP address. That means you're identity is being linked to things you may or not want to be known as being interested/involved in. The ads your TV stick clicks on can cause data brokers to include your name in lists of people who are heavily into drugs, have mental disorders, belong to certain religions or political parties, etc. All of that can come back to haunt you later.
Depending on what other activity your connection is used for as a proxy it can also get you in trouble with the police or with your ISP.
Comment by inigyou 3 days ago
Comment by autoexec 3 days ago
What you do on the internet has very real impacts on your life offline and it's going to happen more and more over time. AI will make it easier for companies to leverage the massive amounts of data avilable to them about you. Surveillance pricing is spreading. Consumer reputation services are spreading. Law enforcement is buying up data from data brokers. Extremists are using data brokers to decide who to target with violence.
Nobody cares if the data they have isn't 100% accurate. The data broker doesn't care. He gets paid either way. The companies buying your data don't care either. It's all a numbers game to them. They just have to be right enough times to justify the cost of the data.
Comment by inigyou 3 days ago
Comment by autoexec 3 days ago
None of the data being collected about you ever goes away. It doesn't matter if the data comes from you. or your backdoored streaming stick, the more data they have associated with you, the more opportunists exist for you to be screwed over by it.
It's almost impossible for a person to know when or how their offline life is being influenced because of the dossiers containing their online activity, but it absolutely impacts the prices you pay, the policies businesses will tell you they have, the opportunities you are offered, and even how long companies leave you on hold when you call them on the phone.
https://www.cbsnews.com/news/data-brokers-selling-personal-i...
https://web.archive.org/web/20191130221040/https://www.nytim...
https://link.springer.com/content/pdf/10.1057/s41272-019-002...
https://www.mccarter.com/insights/ftc-surveillance-pricing-s...
https://www.npr.org/sections/health-shots/2018/07/17/6294415...
https://nypost.com/2022/12/20/how-employers-spy-on-your-sear...
https://www.cnbc.com/2014/04/16/data-mining-is-now-used-to-s...
https://www.wired.com/story/minnesota-lawmaker-shootings-peo...
https://www.wired.com/story/opinion-data-brokers-are-a-threa...
https://sites.sanford.duke.edu/techpolicy/wp-content/uploads...
https://epic.org/data-broker-helped-anti-abortion-group-targ...
https://www.foxnews.com/politics/nsa-purchases-americans-int...
https://www.ftc.gov/news-events/news/press-releases/2014/04/...
https://www.washingtonpost.com/technology/2023/02/13/mental-...
https://arstechnica.com/tech-policy/2017/03/senate-votes-to-...
https://www.vice.com/en/article/data-brokers-netflow-data-te...
https://www.eff.org/deeplinks/2023/11/debunking-myth-anonymo...
Comment by inigyou 2 days ago
Comment by autoexec 2 days ago
The article says that health insurance companies are buying data from data brokers and using algorithms to set prices according to what you do online and what your "personal interests are".
It makes no difference if you run a residential proxy or not, using your browsing history (or your streaming stick's browsing history) data brokers will give insurance companies information that can be used to set your health insurance rates. The more clicks made over your internet connection, the more data they have to make assumptions about you with.
Remember, you asked for evidence that "any of this ever happened to anyone". There are also links showing that employers are buying up data based on your online activity and using it for hiring decisions, that the prices for things you buy are determined by your online activity, that what you do online has real world impacts on your life offline, and that extremists are using data brokers to identify targets.
Comment by inigyou 2 days ago
You know this argument works for everything, right? https://en.wikipedia.org/wiki/Proving_too_much
Do you buy processed food from the grocery store? You know that makes your insurance go up, right?
Comment by autoexec 2 days ago
Comment by mcphage 3 days ago
Comment by arjie 3 days ago
Comment by Tangurena2 3 days ago
The Snowden leaks showed that the US was already doing this. I'm certain that everything purchased is already infected with something. Most likely bugs and bad security.
Comment by soulofmischief 3 days ago
Comment by Pxtl 3 days ago
This is why I giggle when people talk about ending Section 230 in the USA (or various international counterparts thereof).
The largest companies on Earth are happily selling hacked piracy spyware botnet garbage. Not just hosting malicious posts for free like Section 230 protects, but selling illegal physical devices and taking a cut of the profit and excusing it with a pathetic whack-a-mole moderation system. It's already illegal and the law has already failed.
Sean Parker's mistake was that he wasn't rich enough.
Laws are for poor people.
Comment by jms703 3 days ago
Comment by buellerbueller 3 days ago
Both you, and the corrupt politicians, are eating away at the trust that underpins society. Certainly, you can argue, your bite is just a tiny one; the politician is eating the whole apple.
At the end of the day, everyone suffers from the decline of trust and casual acceptance of fraud.
Comment by munk-a 3 days ago
Use a computer - you actually control the content that way.
Comment by byterivet 3 days ago
Comment by inigyou 3 days ago
I get that these products are personally inconvenient to Brian Krebs and his work, and to companies that make money blocking people from accessing the internet, and to companies that make money spewing ads in people's faces. So? Why should anyone care about any of those? In fact I think some people would get one of these sticks just to inconvenience the latter two groups!
Comment by shmuli9 3 days ago
Comment by burgreblast 3 days ago
And they would have caught them but those crafty criminals spoofed the user-agent. So how _could_ they know?
Comment by SnipeOfficial 3 days ago
Comment by bronko_nagurski 4 days ago
Comment by defmetrix 3 days ago
Comment by yunnpp 3 days ago
Didn't know Krebs was a mainstream news puppet.
Comment by brainwad 3 days ago
If you just want to spam clicks on ads you don't financially be edit from, go for it.
Comment by AlotOfReading 4 days ago