[HN Gopher] Read this before you buy that TV streaming stick
___________________________________________________________________
Read this before you buy that TV streaming stick
Author : speckx
Score : 780 points
Date : 2026-07-30 17:04 UTC (22 hours ago)
HTML web link (krebsonsecurity.com)
TEXT w3m dump (krebsonsecurity.com)
| mortenjorck wrote:
| In this case it's actual malice, that the streaming stick is set
| up for residential proxy and ad fraud straight from the factory.
| But incompetence can lead to the same place if it's a poorly
| engineered, un-maintained device with an old version of Android
| that will never be patched and is always one no-click exploit
| away from being commandeered into residential proxy and ad fraud.
| alex_duf wrote:
| I wonder to what degree malice can be engineered to look like
| incompetence?
| abbeyj wrote:
| Try examining the old entries from the
| https://en.wikipedia.org/wiki/Underhanded_C_Contest.
| FinnKuhn wrote:
| Those TV streaming boxes really are (from a cybersecurity
| perspective) probably one of the worst things you can buy. Here
| is the "Darknet Diaries" Episode on them:
| https://darknetdiaries.com/episode/172/
| labbett wrote:
| Superbox 3 is coming up at DEF CON next Friday!
|
| https://hackertracker.app/defcon34/content/67257
| doctorspazz wrote:
| Thank you for sharing this. The superbox investigations
| have been incredibly interesting to follow.
| frollogaston wrote:
| Since these are poorly engineered, wonder how easy it'd be to
| reverse-engineer one and just get the free streaming on a non-
| scam device.
| dpoloncsak wrote:
| If it's something like a Firestick (or the knock-off featured
| in the article), you're really just connecting to Content
| Provider servers to handle auth and content streaming, right?
| They're just OSes designed to run Netflix and Hulu. Would be
| hard to spoof I think
| mikepurvis wrote:
| Indeed. Owning the streaming box lets you loose on whatever
| network it's on, but it doesn't actually get you inside the
| content gardens; those are separately managed by teams of
| people much more motivated to protect their IP.
| kiririn wrote:
| See CoreELEC/LibreELEC/etc - totally replaces the
| (potentially dodgy) Android OS on these kind of streaming
| boxes with a stripped down Linux+Kodi setup
| qmr wrote:
| I thought those were for x86? They run on ARM TV boxes /
| sticks now?
| tesnorindian wrote:
| LibreElec also supports ARM builds than can run on SBC
| like Raspberry Pi. While CoreElec is exclusively for
| Amlogic ARM processors.
| wildzzz wrote:
| Best case, you can grab the credentials off the Kodi box and
| use them on a clean install.
|
| Worst case, everything is packaged up in a single app so it's
| all or nothing. Although you could just wipe the box and find
| another pirate TV provider.
| acdha wrote:
| I was trying to figure out why we saw so many fraudulent
| applications from Vietnam for a service which is restricted to
| the United States, especially because they were all getting
| rejected - it seemed like even the laziest spammer would lose
| interest in something they couldn't monetize.
|
| A guy in Vietnam mentioned that one of the largest ISPs there
| used these really dodgy Chinese modems which were so
| notoriously insecure that it was apparently common knowledge
| that you should replace them if performance was slow because
| that was a sign that yours was being used by a botnet.
| Apparently the cost of access to one of those nodes was so low
| that the spammers don't even really monitor their bots.
| 8note wrote:
| consumers are however happy to buy a cheaper stick with an
| overall public bad
| inigyou wrote:
| I don't even think it's a public bad. I think attacking
| internet gatekeepers like Cloudflare is objectively a public
| good. So is attacking legal spam companies.
| psd1 wrote:
| ...ish. Attacking their monopoly, great. Attacking their
| workers by bombing an office, not so great. Throwing ever
| more spam traffic across the tubes isn't a attack, it's
| marketing on their behalf.
| inigyou wrote:
| In what way is clicking an ad like bombing an office?
| inigyou wrote:
| What is the malice in those things?
| glitchc wrote:
| Defrauding ad networks doesn't seem like a bad thing, although
| using my internet connection as a proxy is obviously terrible. It
| wouldn't surprise me to learn that my connection is being sold as
| a VPN service by the vendor.
| alistairSH wrote:
| It'll be a marginal effect, but fake clicks impacts the ad
| buyer, which then impacts their financials and pricing.
|
| The only winner here is the scammers running the fake affiliate
| sites on which these sticks are "clicking". Or, am I missing
| some facet of this enterprise?
| ssl-3 wrote:
| Another winner is the person who gets to watch cheap digital
| TV, without putting together a usable antenna and limiting
| their reception to the broadcast channels that are nearby.
|
| I mean: They just pay the money, plug the thing in, push some
| buttons, and: TV happens. Right?
| snickerbockers wrote:
| Theres the question of whether or not the fraudulent
| advertisement clicking is using enough traffic to
| inconvenience or impose fees upon the user but otherwise I
| agree with you and am tempted to buy one just to fuck with
| advertisers.
|
| Backdoors and spying are also a problem in theory except at
| this point you can't even trust "legitimate" companies on
| that front so it's a moot point.
| acdha wrote:
| > otherwise I agree with you and am tempted to buy one
| just to fuck with advertisers.
|
| How that actually works in practice is that your favorite
| sites make less money and your IP gets a bad reputation
| so you CAPTCHAs or outright blocked. There's no "sticking
| it to the man" here, just contributing to the frictional
| grind making the internet worse for ordinary people.
| DennisP wrote:
| They make less money, but they also notice lower
| conversion rates on ads, which might make them rethink
| their strategy.
|
| (IP reputation keeps me from doing it though.)
| snickerbockers wrote:
| You are drastically over-estimating how much fondness I
| have had for the web ever since social media companies
| and search providers colluded to drive everybody into
| their walled-off fiefdoms.
| inigyou wrote:
| My IP changes more than once a day. If Google captchas my
| whole ISP, good for them, hopefully it drives people away
| from Google.
| elzbardico wrote:
| Frankly, I pay for most of the things I care about in the
| internet nowadays. Substack, Medium, newspapers, youtube
| premium, manning books, safari books. TV streaming.
|
| The ad supported web is, with very few exceptions,
| useless.
| cryzinger wrote:
| You really don't want fraudulent clicks ("invalid traffic",
| per industry lingo) coming from your home network, because
| any publishers (apps and websites, per normal-people lingo)
| who use tools designed to block invalid traffic might start
| flagging _legitimate_ traffic from your network.
| frollogaston wrote:
| Can confirm. I used to use Ad Nauseam (Firefox extension
| that clicks all ads), eventually stopped when I was
| getting captcha'd left and right.
|
| Also, visitors on my wifi started getting strange ads.
| Yes I threw off the algo, but I'm a guy with wife, I'd
| rather get car ads than like divorce lawyers + gay dating
| sites.
| frollogaston wrote:
| What this misses is the person buying the TV stick doesn't
| care about the impact on the ad market. The bigger problem is
| residential proxying, because their IP will end up getting
| used for something bad.
| hnav wrote:
| most residential proxying these days is used by the
| purveyors of AI
| inigyou wrote:
| And what does that cause? More captchas?
| snickerbockers wrote:
| Probably, but in the worst-case scenario you could
| unwittingly become an accessory to a felony if the proxy
| is used to access CSAM. Especially if the proxy ends up
| caching files.
| inigyou wrote:
| Has that ever happened?
|
| Is Mullvad an accessory to downloading CSAM if someone
| does that?
| snickerbockers wrote:
| If all they did was shove banner ads for boner-pills in my
| face like they used to 25 years ago I wouldn't mind and I
| might even turn off adblock. The problem is that modern
| advertisements on the internet are spyware at best and a
| malware vector at worst.
|
| It's arguably fraudulent to even refer to it as "advertising"
| at this point, clearly that's just a cover to give them an
| excuse to sell data to silicon valley corporations that are
| unironically named after fictional devices used by sci-
| fi/fantasy villains to manipulate people.
| elzbardico wrote:
| They can stop paying for obtrusive ads where either they make
| everyone's life worse or get defrauded, save money using only
| ethical advertising and use this saved money to improve the
| quality of their products or pay their workers a little
| better.
| em-bee wrote:
| why is running a proxy a bad thing? someone profiting off it
| could be bad maybe, but even that is good if it pays for my
| subscription.
|
| but compare running tor nodes, and especially exit nodes. that
| surely would be a good thing, so at least if you think tor is
| good then running a proxy should be the same and it should be
| normalized.
|
| doing it in secret without the user knowing is what's bad
| glitchc wrote:
| Indeed _without my permission_ is implied. Without it, you
| have no idea what traffic is being routed and could be on the
| hook for something nasty like CSAM.
| Dylan16807 wrote:
| Those are different issues. Permission doesn't mean you
| know what the content is, and lack of permission doesn't
| mean they're going to load anything weird or bad. Lack of
| permission implies worse ethics overall, but an operation
| focused on clicking ads will be loading relatively normal
| sites.
| inigyou wrote:
| Has that ever actually happened? Has anyone gone to court
| for downloading child porn that was actually through a
| residential proxy?
| iamnothere wrote:
| No. You would not be "on the hook" for this as they
| implied. They are fearmongering. Even if a statute could
| somehow be stretched to cover it, it would be a nightmare
| to prosecute something like this. The media would jump
| all over it.
| inigyou wrote:
| That's what I thought but I want to see their evidence
| that it happens.
| corbet wrote:
| https://lwn.net/Articles/1080822/ Do you really want to be a
| part of the scraper problem?
| MrDrMcCoy wrote:
| From the outside, I don't see the problem. The sites I
| visit, including LWN, never seem slow or have downtime as a
| result of this increase in traffic. I hear complaints from
| people hosting small sites, but they never seem to include
| concrete examples of downtime or measurably bad user
| experience. Why does it matter if the server load is high
| if everything stays functioning? Going from 5-20% to 60-80%
| load hardly seems like a catastrophe to me when the
| remaining headroom was not going to be used for anything
| else. Having your data that's public-enough to be
| scraped/cited/parodied/ridiculed included in a training set
| also doesn't seem like a problem. Are they struggling to
| pay bandwidth usage bills? Is there some actually-necessary
| intervention required to keep things running smooth, as
| opposed to panicking and taking unnecessary preventative
| action?
| 40four wrote:
| Because your home IP address is going to be associated with
| criminal activity. So if that's acceptable "payment" then I
| guess there's no issue
| inigyou wrote:
| What concrete harm does this cause?
| kube-system wrote:
| Fraud is also bad, even if you aren't fond of those being
| defrauded.
| blackjack_ wrote:
| Fraud that destroys market trust in a market that mostly
| deals in surveillance and selling intrusive data that was
| collected mostly unknowingly from the subject seems great to
| everyone who has any amount of integrity.
| pixl97 wrote:
| So distilling an AI model of one of the big SOTA models is a
| bad thing now?
| tjpnz wrote:
| What about all the fraud committed by the online ad industry?
| ColdStream wrote:
| They took the idea of the 'Ad-nauseam' add-on for Firefox and
| used it for their own gains I see.
| culi wrote:
| https://adnauseam.io/
| elzbardico wrote:
| Exactly. I consider defrauding ad networks even a civic duty of
| legitimate resistance. The issue I see with those boxes is the
| risk of being involved in actual crimes due to the residencial
| proxy.
| skinfaxi wrote:
| Thankfully this seems limited to a specific device (H96). Darknet
| diaries has a good story about streaming devices
| https://www.youtube.com/watch?v=dS6PkuZuxJ4
| krebsonsecurity wrote:
| It's not just one device line; Have a look at the list
| maintained by the proxy tracking service Synthient, which
| tracks streaming boxes, digital picture frames and other IoT
| devices that have been known to bundle residential proxy
| software, among other malicious apps. They currently track
| almost 1,000 different makes and model numbers.
|
| https://github.com/synthient/public-research/blob/main/2026/...
| pavel_lishin wrote:
| > _generic TV boxes that promise unlimited content streaming for
| a one-time fee_
|
| I don't want to blame the purchasers of these things - who are
| some of the victims - but at the same time, it does seem like a
| Too Good To Be True situation.
| croes wrote:
| It sounds like scam
| havaloc wrote:
| I have an elderly client who sends me links of stuff to buy all
| the time. One day it's one of these streaming sticks, the next
| day it's half-price stamps, and I tell her every time, please
| don't buy this stuff. And yet she does anyway, as if I was
| almost being mean and saying no just to say no.
|
| So yes, I do want to blame the purchasers of these things,
| sometimes. To prove her point that her stamps were legitimate,
| she mailed me a card using one of her half priced (but likely
| fake) stamps and it made it through!
| Terr_ wrote:
| Perhaps they grew up in a time/environment where "if it was
| that bad they wouldn't be allowed to advertise it", and
| they're still using that old calibration?
| mhurron wrote:
| My falther-in-law was less that and more, if I can get away
| with it, it's actually legal. Many know their fake, and do
| it because they can get away with it.
|
| That was his justification for a satellite descrambler,
| they're sending me the signals, obviously I'm allowed to.
| mmooss wrote:
| I can imagine many on HN having excited discussions about
| their satellite descramblers.
|
| > do it because they can get away with it.
|
| Lots of people on HN download and upload copyrighted
| materials. Is it really different?
| al_borland wrote:
| They aren't downloading that content from a company with
| a $2.5T market cap. They presumably aren't making a
| living by selling that copyrighted material via a retail
| that claims to run a legitimate business.
|
| I think that makes a big difference.
|
| Imagine if Amazon Video, Audible, and Kindle will all
| just pirate stores, where uploaders of the pirated
| content made money on the downloads, people paid for
| those downloads, and Amazon took a cut of everything. How
| long would that go on before they were in court and that
| was shutdown?
| bityard wrote:
| Fine, you've nerd-sniped me.
|
| I tinkered with Dish Network descrambling 20 years ago.
| Not because I wanted to just watch a bunch of free TV (I
| hardly watched any TV anyway, we mostly watched DVDs from
| the video store and Netflix). More because it felt like
| an interesting rabbit hole. And it was pretty
| interesting!
|
| I picked a good (newer!) satellite dish and LNB from the
| trash and had a friend help with the installation and
| alignment because that was his previous job. Normal
| people use some kind of tool to find the satellites'
| geosynchronous orbital station in the sky, but he did it
| often enough that he could simply look up into the sky
| and point at them.
|
| There were a handful of grey-market satellite receivers
| you could buy that were technically capable of
| descrambling a commercial signal. Of course, they did not
| advertise themselves as such. They were marketed as FTA
| (free-to-air) DVB-S receivers. These were not illegal as
| they were fairly popular in regions of the world that
| actually _had_ a fair amount of FTA (unscrambled)
| satellite channels. The only satellites visible from
| North America, however, tended to carry religious,
| shopping, or Mexican/Central American programming. Oh,
| and NASA TV.
|
| The receiver I bought had DVR functionality if you hooked
| up a USB drive to it. I think I still have some recorded
| shows on it. It would have been a great way to harvest
| and release pirated TV shows to the Internet, if you
| didn't mind editing out all of the ads and whatever.
|
| DVB-S was basically a raw MPEG-2 TS stream that could be
| optionally encrypted. To use these grey-market receivers
| as descramblers, you install some custom firmware
| containing the descrambling modifications and keys. I'm
| failing to remember the technical details, but the
| encryption they used was not very good. Dish Network
| would rotate the keys occasionally, and when they did,
| you had to update them on your receiver. I can't remember
| now if the keys were part of the firmware, but I remember
| it being a pain in the ass.
|
| The firmware/keys part of this had a very "colorful"
| community. You had to sign up to a very specific and
| somewhat exclusive web bulletin board in order to
| download the firmware/keys. I don't remember how I gained
| an account, but I remember it being non-trivial. IIRC, it
| was like one guy maintaining the firmware/keys and
| sometimes it took weeks for him to adapt to whatever
| thing DN did to thwart piracy. The board was moderated by
| a complete power-tripping asshat who enjoyed banning
| people for fun and then gloating about it. (I was not
| banned, that I recall.) I think they started requiring
| "donations" in order to view certain threads (like
| firmware releases) after a while. But I could be
| misremembering that. I just remember the community was
| very toxic.
|
| After a few months of this setup, DN figured out how to
| rotate their keys too often for the casual pirate to keep
| up. I disconnected mine around that time and moved onto
| other things. Partly because the experiment ran its
| course and partly because migrating to real-time key
| updates would have meant buying a newer receiver. For a
| while, I flirted with the idea of getting a DVB-T PCI
| receiver card and working on breaking the encryption
| myself, but it was quite a bit above my skill level at
| the time and there did not seem to be anyone else working
| on it out in the open, since the DMCA was still pretty
| new then.
| wildzzz wrote:
| Your experience describes lots of the kinds of
| communities you can use to access pirated media. You
| either pay for the legit service, pay for pirate
| streaming services, pay with your privacy with the free,
| dodgy pirate streaming services, or pay with your sanity
| in dealing with nutjobs.
| Scoundreller wrote:
| I recall the "free to air" receivers being pretty easy to
| configure. My main pita was getting a cheap ftdi
| usb->serial adapter because that's how old the underlying
| tech was. Still easier than jtagging an official
| receiver.
|
| I migrated into it from the earlier days involving
| iso7816 card programming and mitm cards so I guess I
| didn't have trouble finding which sites to get the fta
| files. I have good memories of those places being quite
| welcoming if you did your reading but sometimes
| ephemeral. Plenty of freeware (but sometimes delayed
| access). But part of the "payment model" was sevurity
| vendors trying to destroy their competitors or sell more
| countermeasures and card swaps to their satellite tv
| broadcast clients (!!!).
|
| A card swap (and some prosecutions on the nudge nudge
| "free to air receiver" importers) put an end to most of
| it unless you went to internet-key-sharing systems where
| I guess the shared keys come from a handful of slave
| receivers somewhere. Given the 2-way nature of those key
| "subscriptions" and network connections required, I could
| (moreso) understand the paranoia of the operators.
|
| Broadband penetration ultimately killed sat cracking,
| Netflix et al too. Oh, and what people usually call
| "iptv".
| kotaKat wrote:
| Yep. Gone are the days of running out for a "119 IKS" or
| hunting for Bev and Charlie, now everyone just grabs some
| pooched RTSP feeds and calls it a day.
|
| Feels fitting recently to discover the Dish Network
| "Pirate TV" recordings. I should run my own in-home IPTV
| station and use the Pirate TV bug as the logo...
|
| https://www.youtube.com/watch?v=zVXSxJ357pw
|
| _You 're watching Dish Network's Pirate TV channel!...
| ... if you're watching me, you're a SATELLITE PIRATE!_
| brewdad wrote:
| There's an old Carlin joke about "If a cop didn't see it,
| I didn't do it."
| Pxtl wrote:
| Of course, what they're missing is that laws are for poor
| people.
|
| Amazon will be notified they sold something illegal and
| will take it down and ban the seller who will immediately
| launch a new store under a new name.
|
| The purchaser, on the other hand, will be fully liable for
| whatever horrible thing they bought.
| iamben wrote:
| I think that's a default for a lot of the older (and some
| of the younger!) generation, same goes for news and media.
| They grew up in a time where there was a practical barrier
| to publishing and (largely) laws behind you doing it.
|
| So they trust literally everything they read. I still don't
| think my folks can fathom you can spin up a very real
| looking newspaper website with fake articles in about 10
| minutes.
| mmooss wrote:
| I find younger people are more likely to trust whatever
| they read - social media rumors, LLM output, Reddit
| threads - and older people looking for credible sources.
| brewdad wrote:
| When my kid was young I set up a basic web server and
| taught him how to make a VERY basic web page. I let him
| write whatever nonsense he wanted to and then we made it
| live.
|
| It was both a gateway into learning how the web works but
| also that literally anyone can post anything to the
| internet and it doesn't make it true. I like to think
| he's more savvy than many of his peers but we all have
| our blind spots.
| doctorspazz wrote:
| was the url for the website you set up for him
| www.creedthoughts.gov.www\creedthoughts
| CM30 wrote:
| Honestly, my experience is that it's less age specific
| and more like 80-90% of the general public. A lot of
| people just can't recognise the difference between a
| credible source and a dubious/fake one, and will just
| share any old random page or social media post they come
| across online. Heck, the number of people I know that see
| things like ChatGPT as some magic encyclopedia/sage that
| knows everything is depressingly high...
| rrr_oh_man wrote:
| > time/environment where "if it was that bad they wouldn't
| be allowed to advertise it"
|
| like cigarettes?
| magicalhippo wrote:
| Or heroin[1]?
|
| [1]: https://museum.dea.gov/museum-collection/collection-
| spotligh...
| dfxm12 wrote:
| I doubt there ever was a time/environment. Snake oil has
| been around consistently for a very long time.
| Scroll_Swe wrote:
| Then again I used to torrent everything under the sun and it
| actually rocks to have every tv show, movie, game ever
| released for free forever.
|
| So is it greed? Yes, but I did it too so now that its more
| accessible I cannot really blame people.
| floam wrote:
| Half priced stamps _work_ though, and nobody is going to
| prosecute grandma for counterfeiting postage stamps.
| zeafoamrun wrote:
| Yes they do. USPIS does not f around
| Pxtl wrote:
| Oddly they don't ever seem to prosecute the sites that
| profit from selling them. Funny, that.
| kube-system wrote:
| Makes sense to me, the only place I've ever seen them
| personally advertised are overseas websites.
| Terr_ wrote:
| It doesn't seem too weird to me: Selling someone fake
| stamps is a general act of fraud, between buyer and
| seller, and would be pursued by state/federal attorneys
| general.
|
| The USPS becomes directly involved only later, when
| someone tries to defraud _them_ by using a fake stamp.
| mmooss wrote:
| > half-price stamps
|
| Who is selling half-price stamps?
|
| #1 How big is your potential market? It's people still
| mailing things from home, who haven't figured out how to do
| postage on their computer.
|
| #2 Of the population in #1, it's those who find real stamps
| so expensive that it's worth bothering with discounts.
|
| #3 Of the population in #2, it's those who would want to buy
| something fraudulant (or not know better) and who would want
| to risk using it.
|
| #4 Considering the size of the #3 population, how many stamps
| do they use in a month?
|
| #5 What is your margin on a half-price stamp? You have to pay
| for advertising, printing (we're talking a profit margin
| under $1), packaging, and your own time, but at least
| shipping is free!
| wildzzz wrote:
| Its the grandmas still sending you a $5 check in the mail
| for your birthday
| mmooss wrote:
| How can those few people - and again narrowed down to the
| population mailing letters AND needing stamps AND seeking
| discounts AND willing or ignorant enough to do/risk fraud
| - with that little revenue per item, make a half-price
| stamp operation worthwhile?
| rrr_oh_man wrote:
| What is your line of work, if I may ask?
| _carbyau_ wrote:
| What is the world view (aka context) of this little old lady?
|
| Watch the news and see CEO's with golden handshakes after the
| company is nailed for something. Wall street failures.
| Companies getting government bailouts. The current US
| president. It is _all_ about getting away with what you can.
|
| The news - being the news - doesn't show process as per
| normal. People doing the right thing most of the time.
|
| In this context, fake stamps for the "little person" doesn't
| even rate a mention. Who the hell is going to raise a moral
| panic about an old lady with fake stamps...
|
| And so the "little people" will keep buying fake whatevers as
| long as it stretches their dollar further.
| nvme0n1p1 wrote:
| OTOH - TV, radio, and YouTube are all unlimited and free. Why
| not streaming?
|
| There are lots of people alive who grew up during the days of
| broadcast TV and radio. I get why they might not understand the
| difference.
| weberer wrote:
| There are a ton of legitimately free IPTV streams. You can
| watch them through most media players like VLC without having
| to download anything shady.
|
| https://github.com/iptv-org/iptv
| nuxi wrote:
| Two things:
|
| - How are these "legitimately free"? For example AMC is a
| commercial TV channel and as far as I know, they don't
| offer free streaming. Same goes for MGM, FilmBox etc.
|
| - Strictly speaking this isn't IPTV, it's just web streams.
| IPTV is usually delivered via multicast (MPEG-TS/RTP/RTSP
| streams, over UDP mostly).
| nvme0n1p1 wrote:
| Ok but have fun explaining that to the average person.
| Buying a dongle is easier than installing software or
| typing URLs into their TV ("my TV doesn't even have a
| keyboard").
|
| To most people IPTV is a bunch of gibberish letters,
| indistinguishable from the gibberish brands on Amazon.
| Someone's grandma from Colorado doesn't deserve to get
| scammed because she didn't research the acronyms.
| kube-system wrote:
| That is chock-full of pirated content.
| crote wrote:
| Most of it seems to be first-party streams of content
| which is also available as unencrypted over-the-air
| broadcasts.
|
| It is paid for via ads or subsidies, so there's no reason
| to block access to the stream, so they just _don 't
| bother_, and make life easier for anyone building
| streaming devices wanting to integrate their channel.
|
| Someone accessing the stream directly is not the
| originally intended use case, but it isn't any different
| from someone accessing it via their smart tv.
| bluedino wrote:
| Most people who buy these want to watch free movies, sports
| streams, etc that aren't on OTA or free services
| Scoundreller wrote:
| Or straight up unavailable on paid services. There's often
| no way to legitimately subscribe to programming from
| $HomeCountry, especially if you're not in a big Diaspora
| country.
| fred_is_fred wrote:
| If you offered most people free streaming for a $37 USB stick
| but directly told them it would be faking ad clicks when the TV
| is off, would any of them really care?
| 1970-01-01 wrote:
| No, and that's is the root of the problem. The buyer is happy
| and so is the seller. They don't care to understand what
| they're allowing and everyone is allowing it to happen.
| GolfPopper wrote:
| They're just meeting the standards American society has
| set.
| bayarearefugee wrote:
| I wouldn't use a device like this for a lot of reasons, but
| the fact that what they are doing might be taking advantage
| of the incredibly predatory digital advertising system is
| neutral to positive for me, if I'm being fully honest.
|
| If they were using the system to rip off random people, I'd
| be 100% against it, if they are fucking Google and the
| giant corps that advertise with them, ehh.. not my problem
| and can't be assed to care. Google is not a positive force
| in the world. Hasn't been for many years.
| mschild wrote:
| Wouldn't this ultimately make money FOR Google and only
| cost money to the company that placed the ad?
|
| Sure, Google's paying but they get their money
| regardless.
| chowells wrote:
| It might damage Google's reputation with advertisers in
| the long term. I'm not convinced Google would even care
| about it, given their other behavior.
| inigyou wrote:
| Proctor & Gamble did an experiment: they cancelled all of
| their online advertising and watched their sales numbers.
| Sales didn't change. That sort of thing is downstream of
| this sort of thing. Online advertising is a money black
| hole, a sacrifice to the gods. It doesn't really do
| anything.
| crote wrote:
| It reduces the value of their ads.
|
| Let's say you are an ad buyer. Previously 1M clicks
| resulted in 1000 sales, now 2M clicks result in the same
| 1000 sales. If you previously paid $1000 for 1M clicks,
| you paid $1/sale. If they are now asking you to pay the
| same $1000 / M clicks you'd be paying $2/sale, so Google
| would have to drop to $500 / M clicks to offer the same
| value to advertisers.
|
| But the same applies to ad _sellers_ as well. Google
| would have to slash payouts to websites displaying ads by
| the same 50% / click or they'd be cutting into their
| margins. A competing ad platform _without_ fraudulent
| clicks would be able to slide into this space, offering
| both a better value to ad buyers and a better payout to
| ad sellers, so they 'd be taking market share from Google
| without having to do anything themselves.
|
| Of course that assumes a market in which the value of ad
| clicks, views, and placements is clear to everyone and
| switching between ad platforms is trivial, which is not
| even _remotely_ the case.
| wildzzz wrote:
| Sure but for the ad network, it means they can brag to
| new clients about how many clicks they can get them. If
| the ad clicker isn't buying, that's the client's problem,
| you already did your job by getting them to click. Maybe
| the client needs a more direct campaign (which costs
| more) or needs to change their website/prices, people are
| walking into the store but they just aren't buying.
|
| Its either the ad network running these click botnets or
| contracting someone to do it. If it was just impressions
| getting boosted, that just looks shady, those are barely
| worth anything.
| pessimizer wrote:
| > They don't care to understand what they're allowing
|
| If you told normal people that they could get free content
| with a TV streaming stick that would also constantly fake
| clicks on AI generated websites to screw advertisers over,
| they would think of it as a bonus. Also it would make them
| trust the stick _more_ (fallaciously), because they would
| know how the people who sold it were getting paid.
| inigyou wrote:
| And why should they care? There is literally no reason they
| should care, it does not affect them in any way, if it
| causes ad companies to ban their IP address that's actually
| good for them personally, and most people outside of the ad
| business would agree that hurting ad companies is good.
| ajnin wrote:
| Maybe they wouldn't care about the ads but the residential
| proxy is another story. I'm sure lots of problematic stuff
| goes through that and you take the risk of being associated
| with it.
| inigyou wrote:
| Not really. Has anyone ever got in trouble for this?
| tomjen3 wrote:
| There are probably quite a few others who consider that a
| bonus. I'm not going to support illegal actions, but it's
| also not one of the things I would really lose sleep over if
| I found out that it have been doing that.
| flerchin wrote:
| Well now I want one
| Cider9986 wrote:
| Stremio+TorBox are the two words. ($3/month)
| ghostly_s wrote:
| That's not what these things are. They come preloaded with
| apps that stream pirate broadcast streams and on-demand
| servers operated out of China.
| Cider9986 wrote:
| Absolutely correct. My comment intention was if you want
| to make one yourself and get the experience of all shows
| +movies.
| ghostly_s wrote:
| Did OP say "I want something vaguely similar that
| requires a greater investment of my time and money"? Did
| you in any way indicate that's what you were proposing?
| iugtmkbdfil834 wrote:
| Uhh, I have an extended family member, who not only uses it,
| but now also tries to get other people to get into it. Since I
| was familiar with this practice ( and the issues it makes worse
| ), I noted those to him in an attempt to both politely decline
| and, hopefully, spare him, and society, some future problems.
| Without going into any identifying details, he didn't take it
| well ( and I don't think I got on my high horse ).
|
| Anyway, I think some level of blame is warranted.
| chihuahua wrote:
| According to the Darknet Diaries podcast episode "Superbox",
| some of these devices are sold via multi-level marketing
| schemes, which would explain why there are random individuals
| selling these, collecting a commission for each device sold.
| Which is why the person you mentioned is unhappy when someone
| points out the problems with these devices.
| Cider9986 wrote:
| It could be possible, I haven't done the math though.
|
| Stremio +Torbox is $3/month and they can probably share 10+
| households on one TorBox account so it could work out. The
| seller could just stop paying the TorBox subscription at
| whatever point and they have an incentive to do so.
| IncreasePosts wrote:
| Maybe, but if they're a not-very-tech savvy older person buying
| this, they probably remember shows being free from over the air
| antennas and may think it is something like that.
| ghostly_s wrote:
| > they probably remember shows being free from over the air
| antennas
|
| you are aware broadcast TV never ended?
| IncreasePosts wrote:
| Yes, in fact I have an antenna and a HDHomeRun nestled in
| my attic to record over the air shows that I occasionally
| consume.
|
| But, I think it's far more common for people to have a TV
| service today, perhaps since comcast and their ilk push
| hard the TV/phone/internet bundle, and gone are the years
| when everyone would fiddle with the antennas on the back of
| their TV to get the right reception.
| myself248 wrote:
| An awful, awful, _awful_ lot of consumers think their old
| antennas don 't work now that everything's gone digital.
| And they've simply never tried.
| bdangubic wrote:
| I watch TV over an antenna, shows are free still
| rng-concern wrote:
| I know a few people who buy these, and they kind of know what
| they're doing. They just try and not think about it too hard.
|
| It reminds me of the saying: "It Is Difficult to Get a Man to
| Understand Something When His Salary Depends Upon His Not
| Understanding It".
|
| If these people thought about it for a few minutes, they would
| understand, but they choose not to, as ignoring it is too
| advantageous.
|
| I admit I was tempted, as the price of all streaming services
| goes up, and services become more and more fragmented. During
| the same period where I have not had a raise.
| acdha wrote:
| In the 90s, there was a cottage industry selling CDs of
| bootleg software at swap meets and flea markets. A guy my dad
| knew was almost condescending to anyone who paid for software
| despite having been hit by viruses multiple times because it
| was so much cheaper. Even having to deal with a client(!) who
| naively called the vendor support only to be informed that
| they hadn't actually purchased a license wasn't enough to get
| him to resist that savings.
| inigyou wrote:
| On what grounds would they choose not to?
| rng-concern wrote:
| I won't argue the ethics of piracy. That was not my point,
| but if you want to I suppose I could.
|
| My point was, their ethics WOULD have prevented them from
| doing the thing. But they chose not to think about it too
| hard. Perhaps subconsciously. I'm not above doing this sort
| of thing either. We all do it for various things.
|
| I've added code that is bad for the user (overbearing
| telemetry for instance) because my salary depended on it.
| At the time I tried not to think about it too much, as it
| would cause cognitive dissonance.
| paultopia wrote:
| Yeah, isn't this a classic kind of scam the would-be scammer
| situation? If you think there's some way to buy one cheap
| device and somehow get around subscribing to streaming
| services[1], then of course you're going to be in a market with
| fraudsters...
|
| [1] Can someone explain what the theory of the product is here?
| It sounds like they're marketing these things as ways for the
| customer to commit fraud, for example by connecting to someone
| else's login. How else would the customer expect to be able to
| get free Netflix or whatever?
| chihuahua wrote:
| It may be the case that these devices are front-ends for
| pirated content that's hosted in various places. They're not
| streaming it from Netflix servers. It's content similar to
| that offered by Netflix and other streaming services, pirated
| by someone else, and hosted by someone else for streaming by
| anyone who can figure out how to find it.
| varispeed wrote:
| I used to know someone doing this. They said they know it is
| too good to be true, but they hate corporations and it's their
| little way to stick one in.
| pibaker wrote:
| > it does seem like a Too Good To Be True situation
|
| It's difficult to judge the price of media products. We have
| legal music streaming services that charges you an album's
| worth of money a month and lets you listen to millions of
| songs. You can pick up old AAA games for less than ten bucks.
| I'd say when people say that price tag, they don't think they
| get scammed into being a part of a botnet. They think the
| device manufacturer cut a good deal with the media rights
| holders.
| al_borland wrote:
| Why should anyone assume a product being sold by (or at least
| on) Amazon, the latest retailer in the country, is an illegal
| device?
|
| It's not like they're buying these things out of a car trunk in
| a dark alley. These retailers need to be held liable for
| selling these things. If they sell this stuff, why not illicit
| drugs?
|
| If they are unable to maintain control of 3rd party sellers,
| then they should end the 3rd party seller program. It has done
| nothing but damage Amazon's reputation, and it just keeps
| getting worse.
| Tangurena2 wrote:
| The streaming services have fractured and taken so many movies
| off their service so much that it is too hard for most people
| to figure out where that show/movie can be found.
|
| From a link above to the story on darknetdiaries:
|
| > _For Pokemon, there is a website that tells you how to watch
| this. You start off on Netflix, then swap over to the Pokemon
| streaming service, which is the only place that has Season 2,
| then swap over to Prime Video for Seasons 3 through 5, swap to
| Freevee, then Hoopla. Season 13 is only on Amazon, though. Then
| swap to Tubi, then Hulu, then Roku channel, and then finally
| back to the Pokemon streaming, and then Netflix. Easy._
|
| That's 8 different streaming services to view one series.
| tomaskafka wrote:
| And yet they can all be comfortably watched at a single
| place, with high quality and no ads.
| joshmn wrote:
| I had a streaming piracy site that I went to federal prison
| for. I can chime in on these people.
|
| It's worth separating the two populations:
|
| My users had money and had considered legal subscriptions. They
| paid me because the legal product was worse--in my case, sports
| blackouts, a bunch of different apps, etc. They knew what they
| were buying into and they had weighed the risk. I can tell you
| right now some of my former users have bought into this market.
|
| Then there's the unwitting: a person buying one of these
| devices at a too-good-to-be-true price is treating it as a
| hardware purchase from Amazon, where the actual monetization
| isn't inferable from the listing. Calling it too good to be
| true assumes the buyer can see what shit they're standing in.
| They can't. There's no visible market here. It's just a product
| page with reviews.
|
| To add to this: the proxy exit is exactly why these cost so
| little. Demand for residential IPs is booming (check some of
| the proxy subreddits to see what I mean).
|
| The ironic part is that there's a chance the person who bought
| one of these boxes to watch pirated sports was the exit node I
| was using to acquire the feeds in the first place.
| elzbardico wrote:
| I don't care about free streaming. But fucking advertisers?
| Humm... just found a reason to buy one of those boxes.
| giraffe_lady wrote:
| > allowing low-skilled operators to drag blocks of code together
| in their editor -- without any need to understand what the
| underlying code blocks do or how they work.
|
| We're called engineers brian.
| cryo32 wrote:
| A better solution is just leech the content and stick it on a
| generic USB flash stick.
| harvey9 wrote:
| These are popular for illegal live sports streams.
| cryo32 wrote:
| I just go down the pub.
| j45 wrote:
| Generally, it's advisable to create a dedicated wifi network for
| all potentially hostile devices.
|
| This dedicated wifi network can just be connecting your devices
| to your guest wifi while you figure it out, and limiting the rate
| of speed as needed.
|
| That can be cameras, tv's, thermostats, tv sticks and anything
| else that might not only call home, but actively scope what you
| have in your home network when it's none of it's business.
| spelk wrote:
| I don't think this would make a big difference for the threat
| model described in the OP? They'd still be able to use your IP
| Address and potentially do nefarious things through your role
| as an unwitting proxy.
| j45 wrote:
| Using one device as a proxy is a few steps away from trying
| to exploit and infiltrate the other devices on your machine
| as well. An unwitting proxy is already crossing the line to
| putting a fox in the henhouse.
|
| Limiting what outbound access devices can/can't have is an
| important skill to learn.
| drnick1 wrote:
| > That can be cameras, tv's, thermostats, tv sticks and
| anything else that might not only call home
|
| That is not enough. You need to air gap devices that have
| legitimately no business communicating with anyone or anything
| outside the house. TVs, thermostats, and other Internet-of-Crap
| gadgets do not need "firmware updates." Either they work out of
| the box, offline or within the LAN, or they get sent back for a
| refund wherever they came from.
| j45 wrote:
| Agreed. That usually comes as a step after getting these
| items on a separate SSID.
| giantg2 wrote:
| So where can I get an actual privacy focused streaming box, even
| if the apps (Neflix etc) running on it are not?
| cogman10 wrote:
| I'm increasingly being convinced the only way to do that is you
| do a media pc nuc. The problem, of course, is you probably
| won't have the netflix app. It's painful to setup such a box to
| stream from various services.
| mbmbn wrote:
| I tried going that route, but most apps for streaming are
| Android. And that was only one of the issues.
|
| It was a rabbit hole and in the end I got back using my
| NVIDIA Shield. This is about 10 years now, but it's actually
| still the best option.
| Tepix wrote:
| What's wrong with Apple TV? It runs VLC if you want to stream
| something from your NAS.
| giantg2 wrote:
| I tried to look at setting up an stripped down privacy-
| focused Android based box for Netflix, but ran into issues.
| Seems like you need to be spied on to run Netflix.
| dwaltrip wrote:
| What about just using the Netflix desktop website? Or does
| that limit the resolution?
| MattTheRealOne wrote:
| Apple TV is currently the best balance of privacy and
| convenience. The only way to get more private is using a PC,
| but that limits the resolution for most streaming services to
| 720p or 1080p.
| theshrike79 wrote:
| And longevity. It just keeps getting updated tvOS versions
| and every provider's apps keep working - unlike on random
| Android TVs that just fall out of support.
|
| I'm on my second one and I've owned them since the first
| version. My current one is the first generation 4k that's ...
| seven years old? Still works like new.
| PcChip wrote:
| I assume apple TV doesn't do malicious things like this, and we
| love the interface and it "just works" with HDR
| ghostly_s wrote:
| These are not "streaming boxes" in the sense you are talking
| about. Their appeal is that they come preloaded with chinese
| pirate streaming apps. Traditional streaming boxes - Apple TV,
| Fire stick, Roku - are not affected by this, though if you want
| privacy-focused Apple TV is the only remaining contender, and
| with Apple's continued descent into advertising vendor I'd
| guess that one is not long for this world, either.
| giantg2 wrote:
| My understanding is that Roku bypasses DNS blocking with
| hardcoded tables so it can report back on various data they
| track on you.
| timbit42 wrote:
| Can you monitor its traffic and block by IP?
| giantg2 wrote:
| I probably could, but haven't done so yet.
| mikestew wrote:
| I'm sure you could. At what point do you just rip out the
| thing that is trying so hard to work around _your_
| control of _your_ network? An Apple TV doesn't cost that
| much.
| kube-system wrote:
| The door is slowly closing on all of these blocking
| schemes by moving ad content to the same domains as the
| primary content.
|
| This is already a common feature for analytics toolkits.
| autoexec wrote:
| Roku collects an insane amount of data on users. Basically
| everything that they can get their hands on
|
| > Roughly twice per second, a Roku TV captures video
| "snapshots" in 4K resolution. These snapshots are scanned
| through a database of content and ads, which allows the
| exposure to be matched to what is airing. For example, if a
| streamer is watching an NFL football game and sees an ad
| for a hard seltzer, Roku's ACR will know that the ad has
| appeared on the TV being watched at that time. In this way,
| the content on screen is automatically recognized, as the
| technology's name indicates. The data then is paired with
| user profile data to link the account watching with the
| content they're watching.
| https://advertising.roku.com/learn/resources/acr-the-
| future-...
| noboostforyou wrote:
| Besides setting up your own device, Apple TV would be the best
| bet from any of the large manufacturers.
| Pxtl wrote:
| kodi on an rpi5?
| drnick1 wrote:
| If you want actual privacy (rather than promises from Apple or
| Google), what you need is a mini-PC running Linux with the
| Plasma Bigscreen DE. You then use a Web browser rather than
| invasive "apps" for your streaming. For Youtube, there is
| VacuumTube (an improved Youtube Leanback client). The main
| limitation is capped resolution on some commercial streaming
| services. I believe Windows does not have that restriction, so
| a VM could presumably be used for streaming (I have not tried).
| knowaveragejoe wrote:
| The Onn TV devices from walmart seem fine, baseline google
| tracking not-withstanding... but no residential proxy or botnet
| participation without you knowing! You can just block them at
| the router and stream content locally.
| m3047 wrote:
| Brazil. Last year I effectively blocked Brazil for a while.
| Ultimately I settled on three possibilities for the traffic I was
| seeing:
|
| 01: DDOS
|
| 10: Residential proxies
|
| 11: Somebody DDOSing residential proxies
| drdexebtjl wrote:
| I can't prove it, but I live in Brazil and after getting a
| smart TV from LG, I started receiving challenges across all
| Google services, indicating they received bot traffic from my
| network. I only used apps from streaming services I actually
| paid for.
|
| I suspect these TVs either come with residential proxies set up
| from the factory, or they have such poor security that they're
| instantly hacked. Either way, TV manufacturers (including
| reputable ones like LG) are to blame.
| mikestew wrote:
| There have been articles lately about the residential proxies
| loaded in apps for LG TVs. My LG has never seen a network
| connection, so I'm fuzzy on details.
| inigyou wrote:
| LG has been in the news just this week for a whole lot of
| shady practices, which cast light on their other shady
| practices. Yes, residential proxying is one of them.
|
| I don't think residential proxying is all _that_ shady since
| groups like Cloudflare have made it a necessity. However,
| having it out-of-the-box on a name-brand device is extremely
| shady.
| codedokode wrote:
| I do not see problems with fake ad clicks and have no sympathy
| for ad companies.
|
| Also pre-installed adware is not a surprise, I found adware in
| the official firmware image of a certain Chinese tablet.
|
| What worries me much more is backdoors from the foreign companies
| and governments that can be pre-installed at the factory to
| collect intelligence information. For example, I became aware
| that a certain maker of a popular mobile OS was collecting the
| cell tower IDs and WiFi access point identifiers along with GPS
| coordinates of a device. Obviously they collect this information
| to be able to guide missiles and drones when GPS signal is jammed
| (GPS is very low power and easy to jam). This is not acceptable.
|
| How can we prevent this? I think, for every imported device
| having a CPU and Internet connectivity:
|
| - the user must be able to re-flash firmware with their own code.
|
| - the local government must have access to the full source code
| and be able to search for vulnerabilities or backdoors, including
| using AI tools. Found vulnerabilities are considered a reward and
| may be used against countries not doing inspections. No access -
| no import permission.
|
| - any telemetry or data collection, or updates must be opt-in
| only and disabled by default.
|
| - any telemetry or updates must go through a server controlled by
| the local government, in unencrypted form, to detect attempts to
| collect intelligence information or install malicious update.
|
| Sadly our government instead only demands that manufacturers pre-
| install their closed-source software on all imported devices and
| that's all.
| BoppreH wrote:
| > a certain maker of a popular mobile OS was collecting the
| cell tower IDs and WiFi access point identifiers along with GPS
| coordinates of a device. Obviously they collect this
| information to be able to guide missiles and drones when GPS
| signal is jammed
|
| Is this sarcasm? GPS can take several minutes to get a
| location, and works poorly indoors. One of the reasons why
| Google Maps is so quick and precise is because Google has
| gathered exactly this data through users and Street View drive-
| bys.
|
| _Could_ it be used for missiles? Sure. Is it _obviously_ the
| intention? No.
| meatmanek wrote:
| Yeah this is extremely standard:
|
| Apple: https://support.apple.com/en-us/102515
|
| > If Location Services is on, your device will periodically
| send the geo-tagged locations of nearby Wi-Fi hotspots and
| cell towers to Apple to augment Apple's crowd-sourced
| database of Wi-Fi hotspot and cell tower locations.
|
| Google: https://support.google.com/android/answer/15157297?sj
| id=1648...
|
| > When Location Accuracy is on, Google periodically collects
| information about the locations of wireless signals and
| sensors observed by your device to crowdsource location
| estimates. This helps everyone find locations better.
|
| Mozilla used to run a very similar service:
| https://en.wikipedia.org/wiki/Mozilla_Location_Service
|
| Not to mention truly crowd-sourced databases like wigle.net.
| codedokode wrote:
| They should ask the permission from device owner and local
| government before collecting the data.
| aeturnum wrote:
| They do ask the device owner - if you review the location
| services description on android[1] you will see they
| explicitly say they collect this information from your
| device. I strongly disagree that they need to get
| government permission for this - they are simply
| recording signals that reach the device, akin to making
| notes about what kinds of cars you see. This is not a
| thing a government should have control over people doing
| and not a thing that should be registered with the
| governement.
|
| [1] https://support.google.com/android/answer/3467281?sji
| d=66634...
| codedokode wrote:
| In the article you refer to, I see no mention of asking
| user's permission. However, I remember, when using an old
| version of Android, there indeed was a popup nagging me
| to allow sharing location data with Google every time I
| enabled GPS. Very annoying, makes you want to never
| enable GPS in the first place.
|
| Regarding the government, the problem is that many people
| do not fully understand the mechanism of collecting the
| data. I remember the case when members of US military
| disclosed the location of secret objects through fitness
| tracker app. And they were probably smarter than average
| smartphone user. Obviously it would be better if enabling
| GPS required an approval from their commander.
| aeturnum wrote:
| I suppose they don't "ask you" in the same way that gmail
| never presents the user with a dialog explaining that
| gmail needs to store their emails in order to provide
| their email service. Instead they explain how the
| location service works and you can decide if you want to
| enable or disable it.
|
| I'll agree that militaries would prefer their soldiers to
| not to dumb things - but I don't agree that it's
| 'obviously' best if people needed permission to enable
| GPS! If that's the case depends a lot on which soldier is
| enabling the GPS and their relation to me. In general I
| would say that government control of people recording and
| distributing their observations is associated with the
| most authoritarian governments and by claiming we should
| get government permission you appear to be aligning
| yourself with an authoritarian approach to data controls.
| codedokode wrote:
| Should Google ask permission from the device owner, and from
| the local government before collecting the data? I heard a
| certain foreign mobile app was banned in US for doing less
| than that.
| pavel_lishin wrote:
| > _Obviously they collect this information to be able to guide
| missiles and drones when GPS signal is jammed_
|
| Are there a lot of missiles that travel slowly enough to be
| able to guide themselves via watching for nearby wifi signals?
|
| > _for every imported device having a CPU and Internet
| connectivity_
|
| Why limit this to imported devices?
| palmotea wrote:
| >> Obviously they collect this information to be able to
| guide missiles and drones when GPS signal is jammed
|
| > Are there a lot of missiles that travel slowly enough to be
| able to guide themselves via watching for nearby wifi
| signals?
|
| Cheap, slow-moving drones are the hot new missiles on the
| battlefield of today. This often talked-about model files at
| 115 mph (https://en.wikipedia.org/wiki/HESA_Shahed_136).
| bee_rider wrote:
| I think that might have been semi-sarcastic. I mean, there
| are lots of reasons to do this sort of thing, some are bad,
| some are not so bad, most are not war.
| codedokode wrote:
| In some areas GPS is spoofed and the displayed location is
| wrong. If, for example, a "smart" car gets a task from its
| manufacturer to film some secret object, it would fail if it
| relied only on GPS and did not use cell towers and WiFi
| points for determining its location. So knowing their
| location determines whether the mission would fail or
| succeed. So foreign devices should not be allowed to collect
| such information.
| IncreasePosts wrote:
| Fake ad clicks cost the advertiser money, not the ad company.
|
| Ad companies generally try to detect fake clicks, but any fake
| clicks that get through just earn money for the ad company (at
| the cost of making the advertisers campaign have a lower ROI)
| mcphage wrote:
| > Fake ad clicks cost the advertiser money, not the ad
| company.
|
| It also diminishes the value of the clicks provided by the ad
| company. It doesn't cost them dollars directly, but makes all
| their advertising worth less.
| codedokode wrote:
| Good products do not need much advertising. For example, when
| buying DRAM, I compare the specification and prices and do
| not look at the advertisement.
| Thrymr wrote:
| > I do not see problems with fake ad clicks and have no
| sympathy for ad companies.
|
| I am not shedding any tears for the ad companies, but I don't
| exactly expect or want a consumer device to be doing this in
| the background without the owner's knowledge.
| jrm4 wrote:
| Sure. And you'll quite literally never be able to get any
| meaningful reduction in this practice unless you attack it at
| the level of big, publically known companies; the warnings
| about these local dinky things I suppose are not harmful and
| help individuals a bit -- but I'm concerned they give the
| entirely false impression that the extremely similar stuff
| coming from the big boys is definitely a-ok.
| Dylan16807 wrote:
| Reduction in what practice? Are there big companies doing
| ad fraud?
|
| I want big companies to stop spying on me, which is a
| completely different issue.
| jrm4 wrote:
| They're not at all "completely different issues."
|
| Both are well within the category of
|
| "If you buy a device to do a thing, then the device does
| something else that is not readily apparent to the user
| that user would find objectionable if they had clearer
| knowledge."
|
| This is immoral and harmful regardless of precise
| vector/action.
| mcphage wrote:
| > I do not see problems with fake ad clicks and have no
| sympathy for ad companies.
|
| Yeah, it's like--a cheap streaming stick _AND_ it poisons the
| advertising well? I 'm pretty happy with my Fire TV Stick, but
| they're really tempting me here.
| exe34 wrote:
| My pinenote runs the original spyware image - I don't have a
| problem with Winnie the Pooh reading along with me.
| autoexec wrote:
| > Yeah, it's like--a cheap streaming stick AND it poisons the
| advertising well?
|
| Keep in mind that it's your IP and identity associated with
| those clicks and anything else criminals decide to do with
| your IP address. That means you're identity is being linked
| to things you may or not want to be known as being
| interested/involved in. The ads your TV stick clicks on can
| cause data brokers to include your name in lists of people
| who are heavily into drugs, have mental disorders, belong to
| certain religions or political parties, etc. All of that can
| come back to haunt you later.
|
| Depending on what other activity your connection is used for
| as a proxy it can also get you in trouble with the police or
| with your ISP.
| inigyou wrote:
| So you're saying it's going to weaken the presumption that
| an IP can be easily tracked to an individual? Even better!
| mcphage wrote:
| Talk about the gift that keeps on giving...
| autoexec wrote:
| No, your IP will be easily tracked to you as an
| individual. You'll just suffer the consequences of
| whatever your streaming stick does with your IP. If your
| stick clicks a bunch of ads for fast food your heath
| insurance bill goes up because their algorithm thinks
| you're a higher risk. If your streaming stick clicks a
| bunch of ads for high end luxury goods, online stores
| start charging you more than they charge your neighbor
| for the same items because their algorithms think you
| have money to burn. Your streaming stick clicks a bunch
| of ads for addiction recovery services, you don't get a
| call back for the next job you apply to because the HR
| department paid a data broker to run a background check
| looking for "red flags".
|
| What you do on the internet has very real impacts on your
| life offline and it's going to happen more and more over
| time. AI will make it easier for companies to leverage
| the massive amounts of data avilable to them about you.
| Surveillance pricing is spreading. Consumer reputation
| services are spreading. Law enforcement is buying up data
| from data brokers. Extremists are using data brokers to
| decide who to target with violence.
|
| Nobody cares if the data they have isn't 100% accurate.
| The data broker doesn't care. He gets paid either way.
| The companies buying your data don't care either. It's
| all a numbers game to them. They just have to be right
| enough times to justify the cost of the data.
| inigyou wrote:
| None of this is based on reality. Can you show any of
| this ever happened to anyone?
| Cider9986 wrote:
| >What worries me much more is backdoors from the foreign
| companies and governments that can be pre-installed at the
| factory to collect intelligence information.
|
| Most Americans are at a greater threat of harm from their own
| government that a foreign one. What worries me is all the mass
| surveillance done by big tech which bypasses the 4th Amendment
| and gives the government Americans data without a warrant.
|
| There's already a front door with the adtech for US alphabet
| boys. This could likely be collected by others as well. We saw
| this happened where foreign hackers exploited a backdoor
| designed for American authorities[1]. This is what experts are
| referring to when they say there's no backdoor only for me.
|
| This could be compelling to politicians, though, and would
| certainly be a step in the right direction.
|
| >- any telemetry or data collection, or updates must be opt-in
| only and disabled by default
|
| This should be how it is for everything foreign made software
| or not. Would be very hard to get done with the big tech lobby
| in the US.
|
| [1] https://techcrunch.com/2024/10/07/the-30-year-old-
| internet-b...
| arjie wrote:
| Oh this was a failed device that Mozilla offered. I had a
| couple back in the day. It was called Matchstick. Sick t
| shirts. Basically an OSS chromecast.
| soulofmischief wrote:
| The problem is that when you need these powers most as a
| citizen is when your government is least likely to allow it.
| Tangurena2 wrote:
| > _What worries me much more is backdoors from the foreign
| companies and governments that can be pre-installed at the
| factory to collect intelligence information._
|
| The Snowden leaks showed that the US was already doing this.
| I'm certain that everything purchased is already infected with
| _something_. Most likely bugs and bad security.
| Mistletoe wrote:
| I recently got an Apple TV 4K and have been really enjoying the
| ad free experience. Worth every penny. Our smart tv had turned
| into a Christmas tree of ads.
| ocd wrote:
| As much as I hate Apple for what they've done to the average
| consumer in regards to computing, it would be just impossible
| and dishonest to say anything other than Apple is the outright
| winner in streaming devices. The experience is so smooth.
| ghostly_s wrote:
| Considering their recent decision to give up on building
| Apple Maps into a serious contender and instead enshittify it
| with ads, I don't have much faith Apple TV will be far
| behind.
| dhosek wrote:
| One hopes that the new CEO will realize the turn towards
| ads is ruining the Apple brand and pull back on that front.
| inigyou wrote:
| Ha! No company has ever reversed enshittification.
| trouve_search wrote:
| The nvidia shield is pretty damn good as well, even if old at
| this point.
| wewtyflakes wrote:
| There are plenty of ads on Apple TV; huge banners right at the
| top of the UI, and ads that launch before you get to see the
| content of a show with no way to automatically disable them
| (you have to manually click through or just wait it out). It is
| infuriating (to me).
| ls612 wrote:
| Apple TV the app has ads for Apple TV shows. Apple TV the
| device doesn't have ads built in.
| wewtyflakes wrote:
| The TV app is baked into the device and is automatically
| focused if you press up too many times on the remote (and
| thereby triggering the large banner ads).
| AlotOfReading wrote:
| Of all the evils normally associated with visual programming
| languages, enabling cybercrime isn't one I've previously
| considered. Now that I've seen it, I'm surprised it wasn't more
| common before LLMs appeared.
| defmetrix wrote:
| I didnt know anybody bought a streaming stick anymore
| yunnpp wrote:
| And which part of "ad fraud" is the fraud? As far as I can tell,
| ad networks and advertisers are the fraud and they are also part
| of the increasing surveillance state.
|
| Didn't know Krebs was a mainstream news puppet.
| brainwad wrote:
| It's called fraud because the ad host colludes with (or
| directly controls) the botnet to get lots of clicks on ads
| hosted on their sites, making them money at the expense of
| advertisers.
|
| If you just want to spam clicks on ads you don't financially be
| edit from, go for it.
| yumraj wrote:
| Any way to identify or block these proxy and ad click services in
| the router? Say a Ubiquiti or even pfsense?
|
| I'm not using any of these boxes for especially this reason, but
| about 10-15 years ago had noticed my treadmill pinging a Chinese
| portal. I removed the WiFi access from the treadmill but am
| curious if there might be other devices.
|
| Any specific ports, etc these guys use or are they mostly
| impossible to distinguish from regular internet traffic?
|
| My another worry has been if these can monitor other Internet
| traffic, though I think HTTPS should mostly prevent that.
| utopiah wrote:
| I bet this is much broader than we all realized because just
| earlier today I was reading on
| https://gist.github.com/probonopd/3ad6b7777caea1503f00d5fe77...
| in order to tinker with a cheap (like really cheap) Android video
| projector : "Device: Magcubic HY300 Pro Android Projector
| (ui_Veng.projector) Issue: Device was being used as a residential
| proxy node without consent, causing thousands of suspicious DNS
| requests and bandwidth usage." linked in there just few months
| ago.
|
| It's not present on mine (AFAICT) which lead me to think either
| it was a genuine mistake or their bailed on that benefit or they
| upgraded to a harder to detect technique.
|
| An acquaintance mentioned they also bought a similar device few
| months ago. I believe there will be a lot MORE of these so we
| should soon be able to witness if it's an innocent mistake or the
| new normal.
| LetsGetTechnicl wrote:
| Oh wow that's the same projector I have. Would be really cool
| to install a custom build on it, but for now I just have an
| Apple TV connected to it.
| utopiah wrote:
| You can already adb connect in dev mode then install .apks,
| e.g. termux, Fennec and change some settings. It does seem
| rootable but I didn't try.
| stronglikedan wrote:
| > But a groundbreaking new analysis finds these devices also
| routinely spoof themselves as mobile phones clicking ads on AI-
| generated websites as part of sprawling operation that seeks to
| defraud online merchants and advertising networks.
|
| You had me at "But"! ::swoon::
| RajT88 wrote:
| A pirate TV box from China presents a security threat?
|
| This is my surprised face.
| inigyou wrote:
| No actual security threat was stated in TFA though. Only
| revenue threats.
| gxs wrote:
| No mention of Roku
|
| I use one but only when traveling at hotels - it's one of the
| only sticks that can connect to captive WiFi networks at hotels
|
| I've got barely anything on it so privacy be damned - but at this
| point this is why I just buy apple products
|
| I have two apple tv's which probably do shady things too, but I'm
| willing to play the probabilities and assume it's the least bad
| of my options short of tinkering with flashing hardware and all
| that stuff that used to be fun in my teens (emphasis on used to)
| kazinator wrote:
| > _But a groundbreaking new analysis finds these devices also
| routinely spoof themselves as mobile phones clicking ads ..._
|
| Compromised (or malicious from the factory) devices being
| recruited into bot farms for click fraud is ... a groundbreaking
| discovery in 2026?
|
| > _on AI-generated websites as part of sprawling operation that
| seeks to defraud online merchants and advertising networks._
|
| To hell with AI-generated websites and advertising networks.
|
| Say, where can I get the most effective malicious TV stick for
| click-frauding the fuck out of that shit? I will take fifteen! :)
| snickerbockers wrote:
| I'm imaging a largescale distributed project like folding@home
| except instead of doing scientific research everybody is
| working together to fuck with advertisers, tracking cookies,
| etc.
| cute_boi wrote:
| The best solution to this problem is to block GeoIP traffic and
| monitor bandwidth consumption on a per-domain basis. If something
| is sending data during the night, it becomes much easier to
| identify suspicious activity.
| Hasz wrote:
| Hey that's pretty smart! Fradulent, but very smart. I was
| honestly expecting botnet.
|
| I expect many cameras of "dubious" origin are used for similar
| tasks, same with most "smart" devices with sufficient horsepower.
| Pxtl wrote:
| > major e-commerce providers like Amazon, Best Buy, Newegg and
| others continue to sell hundreds of different models and brands
| that bundle unofficial versions of Google's Android operating
| system and are frequently marketed (via online influencers) as a
| way to access a broad array of streaming services and live
| broadcasts without a subscription.
|
| This is why I giggle when people talk about ending Section 230 in
| the USA (or various international counterparts thereof).
|
| The largest companies on Earth are happily selling hacked piracy
| spyware botnet garbage. Not just hosting malicious posts for free
| like Section 230 protects, but selling illegal physical devices
| and taking a cut of the profit and excusing it with a pathetic
| whack-a-mole moderation system. It's already illegal and the law
| has already failed.
|
| Sean Parker's mistake was that he wasn't rich enough.
|
| Laws are for poor people.
| a-dub wrote:
| it's just like a phone. don't buy a crappy one with firmware of
| unknown provenance. make sure the one you do buy has an active
| and effective effort that you trust that ships timely security
| fixes.
| matheusmoreira wrote:
| That reminds me, I need to configure VLANs in my router so that
| all my trusted computers are isolated from all the other garbage
| that makes it into the network.
| ur-whale wrote:
| Mmmh, I've always wondered ... as much as VLAN's are a very
| useful tools to - for example - route two separate LAN's
| traffic through a shared physical link ... are they any good
| when it come to security?
|
| I mean, I don't believe VLAN's were designed with security as a
| goal, and I wonder how "strong" the virtual wall between two
| VLAN's actually is?
|
| Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on
| physical connection where packets from both VLANs happen to
| travel?
|
| Just wondering.
| ahahs wrote:
| this is a good question, i asked claude sonnet 5 and the
| answer is too big and complex for me to type out on mobile.
| but long story short, you absolutely need separate VLANs and
| Firewalls in conjuction to secure traffic between networks
| matheusmoreira wrote:
| Yeah, I've been using Claude to help me secure my home
| network. I applied to Anthropic's cyber program and got
| accepted despite being a hobbyist. I'm not very good at
| networks so I'm gonna try to make the most of it.
|
| Really wish I could point Mythos at my router and just loop
| it until my router becomes literally unhackable.
| TylerE wrote:
| Making your router unhackable is trivial. Just pull the
| AC cord. You didn't specify that it had to be _useable_.
| rcoder wrote:
| Depends on your networking setup. A good switch will simply
| refuse to route packets between clients on different VLANs,
| and hide the existence of the tags that determine which VLAN
| a host is on.
|
| A bad switch or router (which almost certainly includes a ton
| of crappy home APs and routers, compromised by the same
| actors who ship these devices) could let clients see VLAN
| tags and ignore them.
|
| And an Ethernet "hub" does no filtering at all.
| rcoder wrote:
| Also: if you need a streaming box to see your AirPlay or
| UPnP devices for "casting" it necessarily has to be on the
| same VLAN as the devices it's connecting to. Sonos speakers
| have this problem when subject to client isolation setups
| based on VLANs or switch-level packet filters.
|
| And any kind of multicast (used for local service discovery
| and media streaming) has the same limitations.
| xorcist wrote:
| Network switches typically aren't known for their outstanding
| security record, but the vlan tags themselves are trivial and
| should be hard to mess up. Should someone hack your switch
| all bets are off, but as long as you don't have management
| accessible in-band you should be fine. Security problems are
| more likely to stem from bad configuration.
|
| > Can't a device on VLAN1 not peek at VLAN2 traffic if it
| sits on physical connection where packets from both VLANs
| happen to travel?
|
| That would be an exceptionally weird configuration. If a
| device "sits on VLAN1" that typically means that it's on an
| "untagged" port where only VLAN1 traffic is allowed. Ports
| that carry multiple VLANs are "tagged" ports and you normally
| wouldn't say they "sit" on any specific VLAN, precisely
| because that port carries tagged traffic for multiple VLANs.
| It's at best an irregular use of the terminology but likely a
| misunderstanding somewhere.
| inigyou wrote:
| A VLAN is a virtual LAN. having two VLANs is like having two
| LANs but without as much duplicated wiring. It's quite well-
| supported and reliable.
|
| You usually want to interconnect them at one central point,
| usually a router, and enforce a security policy there.
| russdill wrote:
| Seems like a motivation to switch to using a VPN for such
| untrusted devices that still require internet access.
| __turbobrew__ wrote:
| Doesn't help when the garbage starts proxying illegal traffic
| through your home ISP.
| inigyou wrote:
| What happens then?
| matheusmoreira wrote:
| Yeah but at least the garbage can't attempt to exploit my
| laptop.
| simojo wrote:
| We purchased a Chinese-made projector from Amazon, which was
| surprisingly inexpensive (~40 USD). Upon connecting it to the
| internet, it placed a constantly running feed of ads on the
| corner of the screen, even while movies were playing. There was
| no way to disable it either. Even though it's not a stick, it's a
| similar principle.
| Pxtl wrote:
| I mean, did you have to connect it to the internet though? Did
| it not just have a dp/hdmi port?
| mikestew wrote:
| _Upon connecting it to the internet..._
|
| I hesitate to blame the victim here, but why on earth would you
| do that? "$40 Chinese-made" didn't give you pause?
| bigmattystyles wrote:
| To be fair, everything is Chinese made. I would be even the
| Apple TV and NVIDIA Shield are made in China and if a state
| actor is determined to get a malicious payload in....
| miladyincontrol wrote:
| To play devil's advocate, when someone says "Chinese made"
| they're usually well aware of your point, and are more
| using it as a common way to describe product mills spitting
| out countless devices with dubious quality or
| configuration.
|
| Of course theres good products made in China, and plenty of
| entirely Chinese brands killing it doing their thing.
| 8note wrote:
| its pretty straight racism though.
|
| its US software companies that are the worst of the worst
| in terms of adware and malware being shipped under
| monopoly control
| Eisenstein wrote:
| Its based on the most common heuristic people have
| developed in regards to the phenomenon. What do you think
| about 'alphabet soup company' instead, referring to the
| tendency for names to be a mix of random letters?
| Otherwise, you can try and create a better term for
| 'unaccountable third parties using US platforms to dodge
| liability for their product made out of the cheapest
| components and software possible' and see if that catches
| on.
|
| Yes it is also the US companies that are a problem but
| these are two separate problems and need different terms.
| SecretDreams wrote:
| There's enough evil malware provider blame to go around.
| wvh wrote:
| It's not racism at all to be weary of (any) political
| system, its overreach and the incentives of the people
| living in it, be it China or America or Russia.
|
| The word racism is vastly overused these days.
| parineum wrote:
| > its pretty straight racism though.
|
| It's not. Firstly, because countries aren't races.
| Second, because it's just a leftover from a time where
| that was a good heuristic.
| fc417fc802 wrote:
| This isn't about state actors though. There's a world of
| difference between a name brand (possibly even a Chinese
| one) versus what I would term "chineseum". It's nothing to
| do with China per se and everything to do with purchasing
| from the extreme low end of the market. It just so happens
| that the vast majority of that segment is manufactured in
| China at present.
| worik wrote:
| > To be fair, everything is Chinese made
|
| Yes. Chinese manufacturing is quite a phenomenon, useful
| and everywhere
|
| But to be completely fair, a $40 video projector has a
| warning label. The price
| speerer wrote:
| I think normally when people say Chinese made in this way,
| what they're really communicating is that there's no
| (meaningful) brand. All they know about it is that it is
| from China.
| r_lee wrote:
| Made in China and random Chinese brands are two very
| different things
| ChrisRR wrote:
| Often they're exactly the same things
| inigyou wrote:
| Often the USA brand is just buying the random Chinese
| design from the same factory that brands it in random
| letters, and tripling the price.
| r_lee wrote:
| if you think the Apple TV or Nvidia shield example
| applies to this then I don't know what to say
| ponector wrote:
| My Samsung phone is made in Vietnam.
| SiempreViernes wrote:
| This is an age where even teacups demand internet
| connectivity to fetch firmware updates
| contravariant wrote:
| I mean I get why my cups need frequent java updates, but
| still.
| histriosum wrote:
| Finally, a legitimate use case for HTTP 418...
| red-iron-pine wrote:
| and they thought it was an April Fools joke, hah!
| Ballas wrote:
| And then what happens if someone accidentally pushes the
| saucer firmware to the cup update?
|
| https://hackaday.com/2022/03/18/welcome-to-the-future-
| where-...
| tollgategit wrote:
| And yet, it is now still just as stupid to do it as it was
| before we arrived here.
| xyx0826 wrote:
| I remember reading an analysis on one of those projectors; the
| author found a residential proxy running on their device. I
| would recommend keeping these things off the internet.
| simojo wrote:
| I'd be very interested to see it if you still have access to
| it.
| dhruvrrp wrote:
| Dunno if this is the same issue, but someone found malware
| in their projector. I'm not sure about the accuracy since
| the report is blatantly AI generated:
| https://github.com/jrm360seclab/aodin-vo1d-malware
| mrloopex wrote:
| Yes that's what the article is about.
| dboreham wrote:
| Capitalism!
| azan_ wrote:
| Absolutely, there's no scam outside capitalism!
| jkahrs595 wrote:
| Outside of capitalism is outer space, so your snarky
| comment is actually true.
| usef- wrote:
| I think he meant the other kind of "outside", not
| physically. Plenty of bad stories.
| azan_ wrote:
| Of course, every socialist country is actually capitalism
| and that's why it fails.
| inigyou wrote:
| Which country is socialist?
| ColdStream wrote:
| Get the sarcasm, but of course there is scam outside of
| capitalism. Its just that the capitalistic model almost
| turns it from an inconvenient bug into a mainline feature.
|
| Not saying there is an absolute perfect alternative, anyone
| who says that is usually shoveling smoke, but there are
| flaws with this economic model to be addressed.
| azan_ wrote:
| Not true at all. I'm from Poland which was occupied by
| communist for a long time, and I can guarantee you - the
| amount of scam we had under that rule was orders of
| magnitude larger than what we have now.
| ColdStream wrote:
| Yeah I did forget about that. When you flatten the pay
| structure across the board, it makes bribes and scams so
| much more desirable. But also, communist structure in
| practices is sort of the total opposite of capitalism at
| a distance.
|
| It was said that Karl Marx was completely right about
| Capitalism and completely wrong about Communism. And that
| is fairly accurate, both have big flaws.
|
| Most times, the opposite of one bad idea is another bad
| idea.
| azan_ wrote:
| I think it's really far fetched to say capitalism is bad
| idea. It's great system, it has some problems, but the
| upside is so big and alternatives are so bad that it's
| really unfair to call it bad system.
| ndsipa_pomu wrote:
| I think that encouraging corporations to destroy our
| environment (e.g. climate change) as fast as possible to
| maximise profits is a very good reason to call it a bad
| system. Yes, some goods and services become much more
| efficient, but now we're all going to have to pay the
| price for it.
| inigyou wrote:
| Like the current never-ending heat wave. It's predicted
| to go on for months btw and the ocean is 4 Kelvins warmer
| than it should be.
| pbhjpbhj wrote:
| Yh, the end of civilisation is a good thing after all, so
| enabling greedy fuckers to accelerate all life on Earth
| ever more rapidly towards destruction has to be good ...
| jojobas wrote:
| At least in capitalism you have the choice to look for a
| malware-free alternative. 100% USSR, had it survived to the
| IoT era, would penalize you for not having a state-mandated
| surveillance device on at all times.
| DoctorOetker wrote:
| I agree fully with your assessment of USSR but basically
| any nation state with the power does such things.
|
| Show me a COTS smartphone where the end-user can burn the
| OTP fuses for his personal public key, so they can have it
| boot their own custom signed firmware, and control exactly
| what runs in TrustZone's SW Secure World?
| jojobas wrote:
| You can flash yourself GrapheneOS with your own keys for
| the bootloader. Then again "I can't make sure all
| manufacturers aren't in collusion" when FBI sues Apple
| and others (and fails) over suspects' phone access is
| quite different from "every device sold in the country
| must have government malware", as it is in China.
| inigyou wrote:
| I can't find a device in the USA that doesn't come with
| government malware. Is this another instance of the USA
| accusing China of everything the USA is doing (like with
| the credit scores)?
| breppp wrote:
| You'd have to be a bit more specific of which government
| malware you found in Android/iOS devices, cause that
| would be interesting
| inigyou wrote:
| Android comes with something called Google Play Services,
| and iOS has a thing called iCloud. You may have heard of
| them.
| breppp wrote:
| I have, I still have not heard how the US government uses
| these as malware, but I would love to learn something new
| inigyou wrote:
| For instance, if you use an Apple phone and the
| government wants to see the pictures you took, they can
| just get a copy of them from Apple using iCloud.
| red-iron-pine wrote:
| show me anyone outside of HN or XDA devs that would ever
| want to do that
| wil421 wrote:
| Chinese!
| Epa095 wrote:
| Chinese capitalism!
| red-iron-pine wrote:
| Communism with Chinese Characteristics
| qmr wrote:
| ...firewall it then?
| __turbobrew__ wrote:
| You forgot to drink a verification can
| throwa356262 wrote:
| If the hardware is good and cheap, it should be a fun project
| to replace the OS with a custom Android build that is clean of
| adware.
|
| Do you have a link to the projector?
| tollgategit wrote:
| > Upon connecting it to the internet,
|
| I dare not ask why you would do such a thing, instead, I will
| simply ask if you now think the reason was good, and I will
| hint at you that if the reason was "convenience", then you
| should answer "No".
| breppp wrote:
| You assume a lot of things, sometimes you have to connect it
| to the internet for it to work (such as robovacuums)
| GJim wrote:
| Why in the name of all that is _holy_ would you need to
| connect a projector or vacuum cleaner to the internet in
| order for it to work?
|
| Seriously, why do you think this is normal or acceptable?
|
| This is bullshit needs to stop (and the scummy AdTech
| industry has a lot to answer for).
| themaninthedark wrote:
| Vacuum for "convenience" of being able to turn it on with
| a phone.
|
| I could actually see hooking up a projector to wifi to
| allow it to stream videos.
| breppp wrote:
| As far as I remember they mandate you connect to it in
| order for you to operate it.
|
| We all know why, which is Adtech, but like cars or smart
| TVs, you as a customer either skip the entire segment or
| yield.
| dspillett wrote:
| The streaming sticks the article is discussing basically need
| network access to function. They might support streaming from
| local media sources and file shares too, but that is also
| done over WiFi. Unless you have a properly firewall
| controlled home (very few people do, I'm pretty nerdy and
| most devices on my network can just NAT to the outside these
| days) then just giving it a WiFi connection gives it access
| to the wider network from your location.
|
| You'll probably find the projectors are pretty much the same
| hardware and OS as the sticks except with the projection
| device added where the stick just has an HDMI output. It
| might have HDMI-in too so it can just be used as a screen for
| another device, but there are definitely some units out there
| that are network-play-only.
|
| You aren't wrong about giving cheap crap like this access to
| your network (and via that the public network) is risky, but
| that convenience you (and I) would say no to is exactly what
| they are bought for.
| ubermonkey wrote:
| I'm still trying to figure out why you didn't see that coming.
| hn_submit wrote:
| I already suggested the U.S. government ban all Chinese products
| which have a computer in them that's connected to the internet.
|
| Instead they're banning stuff willy nilly left and right without
| really solving the problem.
|
| But there's good stuff coming out of China as well. I recently
| bought a cheap e-reader which has no WiFi or internet connection
| and it works stellar. And I bought some cheap Chinese sport cams
| which also lack internet and work great.
| autoexec wrote:
| > I already suggested the U.S. government ban all Chinese
| products which have a computer in them that's connected to the
| internet.
|
| Personally, I think every other country should ban any product
| made by Google, Amazon, and Microsoft since they all spy on the
| users of their products too.
| hn_submit wrote:
| I've suggested legislation which would ban the sale of
| customer information to third-parties.
|
| These companies could use the info they gather on customers
| for their own use but they cannot (re)sell it to _anyone_ ,
| not even the government. The reason being that the
| information eventually ends up abroad after which you lose
| all control over it.
| stuaxo wrote:
| How hard is it to get something else on these ?
|
| Looks like cheap small computer with a remote control.
| ta988 wrote:
| A familly member had one of those (he had to pay a yearly
| subscription in addition to the stick). Network would be unusable
| as soon as it was on for anyone else, and it also tried to scan
| things on the local network. It was indeed connecting to all kind
| of services all over the world (and saturating some tables in the
| router doing so which blocked other clients). Definitely evil,
| definitely on purpose.
| deepfriedbits wrote:
| Reading this, I caught myself wondering how we distill what's
| in this excellent write up into something the average consumer
| understands, including the dangers from buying and using
| devices like this.
|
| Is it a graphic that's shared? Something else? I am sure we all
| know or have heard of people with these devices that promise
| free streaming.
| ta988 wrote:
| I warned them about the risk of those things and showed them
| what I found, they continued buying the next generation (that
| person and his two >40yo kids). They NEEDED to watch those
| soccer games more than they cared about security...
| Arainach wrote:
| The bigger problem is convincing them to care. Botnets are
| abstract - where's the pain to them? Ad farms? That's "just
| hurting big corporations".
|
| Remember, a significant portion of the population got angry
| (often violently so) when just asked to wear a mask to
| protect their neighbors. And the threat there was
| significantly easier to explain.
| pibaker wrote:
| Just tell the anti mask types the TV sticks come with CCP
| hacking software preinstalled.
| ValdikSS wrote:
| In the world of auto-updates of software and firmware, even
| the hardware which is now completely legal and crap-free,
| could convert itself to a proxy or ad network later any time.
|
| And don't forget about counterfeit products (which look like
| original but different in firmware) and supply chain attack
| vectors, which are really, _really_ common.
|
| If you want to buy something as simple as a feature phone,
| going to a store with 10 of them will give you at least 1/10
| chance to buy a phone with a trojan/backdoor.
| SecretDreams wrote:
| You can't. This is a legitimate thing the government needs to
| step in and deal with on behalf of their people via
| legislation because their people cannot be reasonably taught
| to protect themselves.
| inigyou wrote:
| Protect themselves from what?
| inigyou wrote:
| First you'd have to figure out what the dangers actually are.
| Most of what's cited in TFA and this comments section are
| only dangers to large evil companies, and why should anyone
| care about them?
| inigyou wrote:
| If it wasn't scanning your own network or using all of your
| bandwidth, would you still consider it evil?
| mring33621 wrote:
| Using low code tools to build click fraud logic FTW!
| rawgabbit wrote:
| What happens when you stick this malware into your windows PC?
| The PC is now an accomplice to fraud?
| SoftTalker wrote:
| > Despite repeated warnings from the FBI and security industry
| leaders about the security and privacy risks of using these
| streaming devices, major e-commerce providers like Amazon, Best
| Buy, Newegg and others continue to sell hundreds of different
| models and brands
|
| I scanned the comments and I didn't see anyone suggesting that
| these companies should share any responsibility for selling these
| harmful products. Why is it that they seem to get a pass? Would
| we feel the same about giant retailers selling tainted food, or
| unsafe children's toys?
| eightysixfour wrote:
| Probably because we have little to no way to punish those
| companies. We can't even stop DJI from shipping their drones
| under other brands to get around the ban.
| dessimus wrote:
| Our government _chooses_ to not punish those companies.
| Unfortunately, the lawmakers have decided that the donations
| to their PACs are more important than actually doing
| something about it.
| lotsofpulp wrote:
| Probably because most people don't equate the damages from
| causing bodily harm to whatever these ad clicking networks do.
|
| Voters don't like seeing themselves or their kids get hurt, but
| they do like lower cost live sports.
| al_borland wrote:
| One of the main value propositions for retailers in a world of
| endless cheap garbage being sold online, is to vet products so
| customers can trust that what their buying is from a legitimate
| company and not junk or stuff like these streaming sticks.
|
| This is the problem with being an "everything store".
| "Everything" includes a lot of things most consumers would like
| to be protected from, and assume they are due to the long
| history of retailers standing behind the products they sell.
| That history seems to have come to an end. They only stand
| behind it enough to offer a refund if there is a problem, not
| to ensure it's good before selling it.
| ephemeral67 wrote:
| interesting bit of information: most EV mower companies now
| do not provide replacement parts - if a mower dies within
| warranty, a 'certified' warranty repair shop does basic
| troubleshooting, and if it's beyond a piece of cheap plastic,
| the mfr just ships a new mower to the 'repair shop'. Once out
| of warranty, you're on your own.
| drnick1 wrote:
| Thank you for reminding us that electric mowers are
| garbage.
| Gigachad wrote:
| Everything is garbage now. It's the end state of
| unrestrained capitalism.
| exe34 wrote:
| Surely not, the invisible hand of the market should crawl
| up their arse and make them do the right thing any day
| now.
| actionfromafar wrote:
| The invisible hand crawled up the arses of Congress and
| seems to enjoy it there.
| nullhole wrote:
| I mean, not all of them?
|
| Mine's a fancy-pants Stihl battery mower, but it works
| quite well and has been doing so without problem since I
| bought it ~4 years ago. The other battery stuff from the
| same brand (trimmer, chainsaw, kombi-tool) have the same
| story.
| bluGill wrote:
| Stihl is a commercial product (mostly). They design for
| people using them as a full time job. You pay the price
| for quality.
| nullhole wrote:
| Yeah, mine are the AP ('professional') class ones.
|
| What matters is the amortized cost per year, I think -
| more expensive up front but cheaper in the long run.
| zrobotics wrote:
| No, they definitely have homeowner grade tools available.
|
| For instance, the MS182 [0] is a $270, 2.2cu in saw with
| a 16" bar listed "For homeowners and light duty work".
|
| Meanwhile, the MS201 [1] is $1100 for a 2.1cu in saw with
| a 16" bar listed as "The lightest professional gas
| chainsaw from STIHL Perfect for delimbing work in
| forestry".
|
| Service interval on the 201 will be much longer, and it's
| expected to last longer but is priced accordingly. I
| ended up having to buy one of their homeowner grade saws
| 10 years ago when I was up in the mountains and my saw
| died, that was all that was available locally. I'm
| certainly not a professional, but at the time my primary
| heat source was wood and I had always used the stihl pro-
| grade saws. However, that cheap stihl was an absolute
| piece of junk, it was half wore out after cutting 2 cords
| of firewood that first time. Terrible ergonomics and poor
| power to boot, even after reserving the saw for light-
| duty work it only lasted 2 years and was miserable to
| start and run the entire time.
|
| At least they explicitly say that they are for light duty
| though, a less honest company would market everything as
| pro-grade. But don't just buy the name, while they make
| good quality products they also sell cheap crap under the
| same name. It also isn't that clear in a retail store
| besides the price which ones are the homeowner grade
| saws.
|
| [0] https://www.stihlusa.com/en/p/chainsaws-
| ms-182-gasoline-chai... [1]
| https://www.stihlusa.com/en/p/chainsaws-ms-201-gasoline-
| chai...
| newAccount2025 wrote:
| Why? Mine is great. And light. And QUIET.
| bigstrat2003 wrote:
| They really aren't particularly quiet imo. Yes, there's
| no motor, but it turns out that the whirring sound of
| blades rotating and cutting grass is quite loud even
| without a motor. I would say mine is perhaps 3/4 as loud
| as a gas mower, which isn't a very impressive reduction
| in noise.
| maxerickson wrote:
| With logarithmic perception, it's about a 50% reduction
| in sound energy.
|
| My battery mower is quiet enough that I don't feel
| terribly rude mowing at twilight.
| astura wrote:
| I love mine.
| classichasclass wrote:
| My wife derides my Home Despot special plug-in mower as a
| Tonka toy, but it's basically just a motor, a blade and a
| bag, and I don't have a lot of lawn to mow.
| timc3 wrote:
| My Makita one is excellent.
| bdamm wrote:
| My electric mower has lasted longer than the gasoline mower
| before it, which literally had plastic valves inside the
| carbeurtator.
| zdragnar wrote:
| Counter anecdote, I've had gas mowers survive decades and
| EV electrical equipment (in this case, a chainsaw and a
| battery pack for a mower) both die within 14 months of
| purchase.
| Slash65 wrote:
| This is my experience as well. String trimmer battery
| went out (still in warranty and replaced) but my gas
| string trimmer I use at a bigger property came home with
| me and worked great. She's only 15 years old, the battery
| was 6 months. I love my battery blower and string
| trimmer, but the gas ones are going strong but typically
| stay at the ranch property due to it being a bigger
| property to maintain. I would also need 3-4 battery's out
| there to keep up with maintaining it, the gas is a whole
| lot cheaper than a grands worth of battery's.
| taneq wrote:
| Counter counter anecdote, I was just tidying up the yard
| with my 18V whipper snipper and contemplating the fact
| that I bought it in 2012 and it hasn't skipped a beat.
| HDBaseT wrote:
| I have a mower that my dad gave to me, which his dad gave
| to him.
|
| It is in rough shape, but it still cuts grass perfectly
| fine.
|
| I have a wippersnipper from before I was born which runs
| perfectly today. It was left out laying sideways in the
| rain for about a month. Quick clean and a new plug and it
| was going again.
|
| I'm sure the electric devices can run a long time, but
| when they fail, they tend to be not repairable.
| markdown wrote:
| Makita, amirite?
| taneq wrote:
| Ryobi, but I have plenty of Makita gear too. :)
| lazylester wrote:
| almost all 2-stroke engines have had plastic flapper
| valves and a plastic fuel pump for as long as I can
| remember.
| bluGill wrote:
| There is a big difference in quality levels. If you want
| a good mower pay the price for a commercial mower, people
| who use them 8 hours a day need something that lasts.
|
| 30 years ago a friend of mine did the mold for a lawn
| mower. They put an engine on it and it ran for 120 hours
| before the deck failed. It took 7 more tries until the
| deck failed after 80 hours. Commercial mowers are
| expected to run over 1000 hours.
| bigiain wrote:
| I remember asking a chippie (carpenter tradesman) a while
| back why he was using Ozito brand power tools (the
| cheapest Chinese brand from the local tool barn). He said
| "The good gear like Milwaukee and Makita last years. The
| cheap Chinese junk lasts maybe six months. Whatever I buy
| it gets stolen about every 3 months. I'd rather have a
| spare $40 drill waiting at home when my van gets broken
| into, than have to go buy another $600 Milwaukee one that
| I'd otherwise rather be using."
| MostlyStable wrote:
| These are the kinds of products I now just straight up
| refuse to buy.
| taneq wrote:
| I think that's "most mass produced item manufacturers".
| It's just cheaper to ship a new one than waste time trying
| to troubleshoot.
| omilu wrote:
| Costco vets their products very well, if I see something at
| costco and its something I need I just buy it. No need to
| research and I've never been burned. They only sell good
| quality stuff.
| altruios wrote:
| Costco isn't perfect, and things slip through still.
|
| For example: this is a minor annoyance, but comes readily
| to mind.
|
| https://www.costco.com/p/-/orgain-organic-protein-and-
| superf...
|
| The problem is labeling conventions leading to inaccurate
| assumptions of what's even IN that "protein powder"...
|
| you would think the protein, being the largest in print, is
| the primary ingredient but no. A serving is 51grams, and
| the protein makes up 21grams of that serving: less than
| half, that's not a 'protein powder' if the primary
| ingredient isn't protein.
|
| It should be labeled "SUPERFOODS with protein" not the
| other way around.
|
| There have been other things similar in scope less readily
| recalled. It may seem minor to some... but labeling
| accuracy and transparency is something we had to fight for
| collectively.
| al_borland wrote:
| Ingredients are listed in order from greatest to least
| amount. Protein is listed first. It seems it's the
| creamer that throws off the ratio you're looking at,
| which I'm assuming is there for consistency/taste.
| tejohnso wrote:
| A 51 g serving might contain 40 g of the protein blend,
| making it a protein powder as the primary ingredient is
| protein blend.
|
| However, this is plant-based protein, not pure way
| isolate. A plant-based protein powder from mung beans for
| example isn't going to be 100% protein. Chickpea powder
| contains roughly 20% protein.
|
| So I don't know if that helps at all, but it doesn't seem
| as bad as you and you might be suggesting.
| tiltowait wrote:
| The first ingredient is a plurality, not a majority.
| femto wrote:
| Check their tomato paste. It turns out that nearly every
| tomato paste in Australia comes from Xinjiang in China,
| including those marked as Australian or Italian. Simplot
| (Leggos), the big US company, was the worst offender, so
| it's possible that tomato paste in Costco's US stores has
| been produced in Xinjiang using slave labour, irrespective
| of what the label says.
|
| https://www.abc.net.au/news/2026-07-27/australian-
| tomatoes-l...
| onionisafruit wrote:
| According to this none of the samples tested from US
| retailers contained Chinese tomatoes.
| https://www.bbc.com/news/articles/crezlw4y152o It seems
| like the US ban on Xinjiang is working
| femto wrote:
| Thanks for that informative link. I looked to see if
| there was any data beyond the ABC article and didn't find
| it. Some of the truthful brands listed in the BBC article
| are available where I live. Kudos to the US that their
| labels match their contents.
| stubish wrote:
| The ABC just broke their story a few days ago. There will
| continue to be fallout over the next few months or years
| (much like their last one, where they found that many
| sunscreens did not meet their SPF ratings, a hot topic in
| the skin cancer capital of the world)
|
| (edit: whoops, Choice did the SPF rating investigation.
| ABC just did a lot of reporting on it)
| p-e-w wrote:
| The above thread was about quality issues, not ethical
| issues such as "slave labor" (a term somehow reserved for
| certain countries, even though most countries use unfree
| prison labor, including the US and much of the EU).
| femto wrote:
| It's about trust.
| iamnothere wrote:
| Our vocational training program, your prison labor, their
| slave labor.
| Nursie wrote:
| > It turns out that nearly every tomato paste in
| Australia comes from Xinjiang in China
|
| I think that might be a bit of a strong assertion, from
| your article there -
|
| "It analysed 221 processed tomato products from 39
| brands, including paste, passata and diced tomato.
|
| Twenty-two per cent of the products failed country-of-
| origin testing, while a further 6 per cent were flagged
| for further testing."
|
| So while 28 percent is scandalous, and those companies
| need to face consequences, the other 72 percent seem to
| be genuine.
| femto wrote:
| A big chunk of that 72% are legitimately labeled "Made in
| China" or niche brands. The brands that failed, plus the
| products that are actually labeled "Made in China",
| dominate Australia's four supermarkets with the majority
| of the market share. I've just done my weekly shop, so
| trawled their web sites looking for alternatives.
|
| Summarising the Australian situation, taking the 4corners
| results into account, the following non-Chinese tomato
| pastes are available:
|
| Coles (29% market share): 1 x 140g premium product in a
| tube (expensive with reduced market share) out of about
| 20 products.
|
| Woolworths (38% market share): 1 x 140g premium product
| (Mutti) in a tube (expensive with reduced market share)
| out of about 20 products.
|
| Aldi (10% market share): None out of about 4 products
|
| IGA (7% market share): 5 of 16 products, being the same
| premium brands that Coles and Woolworths sell.
|
| Maybe qualify my comment with "by market share and
| availability". The effect is that if you stand in front
| of an Australian supermarket shelf, every product, bar
| one or two in the corner, come from China. China is a
| proxy for Xianjing, in that sources say 80%-90% of tomato
| paste from China comes from Xinjiang.
|
| Hence the assertion I made.
|
| Market share data:
| https://www.accc.gov.au/system/files/supermarkets-
| inquiry_1....
|
| Xianjing percentages:
| https://tomatonews.com/countries/china/
| Nursie wrote:
| > Woolworths (38% market share): 1 x 140g premium product
| (Mutti) in a tube (expensive with reduced market share)
| out of about 20 products.
|
| Eh ...
|
| "Well-known tomato brands that passed country-of-origin
| testing include Mutti, SPC, Woolworths, Providore
| D'Italia and Annalisa. Diced tomato cans and passata from
| Leggo's and Coles also passed."
|
| So here are 4 tomato pastes in woolworths that would seem
| to pass the test of not being from China and not being
| liars, just from a quick search (and I have seen all
| these in my local) -
|
| https://www.woolworths.com.au/shop/productdetails/290303/
| mut... https://www.woolworths.com.au/shop/productdetails/
| 218066/mut... https://www.woolworths.com.au/shop/productd
| etails/901431/mac... https://www.woolworths.com.au/shop/p
| roductdetails/150875/pro...
|
| I usually buy Mutti stuff because it's low-ish salt, and
| that claims to come from Italy and wasn't implicated in
| the report here. And while I understand those are at the
| 'premium' end, it's not like it's one product on the end
| of the shelf either.
|
| It's true that "Leggo" occupies a lot of the shelf space
| and a lot of the cheaper 'own brand' stuff is labelled as
| coming from China. And coles appears to be in a
| weirder/worse spot that woollies, with only Providore
| being Italian and two brands of turkish tomato paste,
| which is interesting.
|
| It's sad that I can't find an Australian tomato paste
| that isn't a liar.
|
| So I'm still not fully on board with "nearly every", OTOH
| thanks for the further information. I shall continue to
| try to avoid these products!
| perpetuallunch wrote:
| Difficult to distinguish between actual slave labour and
| China-is-bad propaganda.
|
| Harm to the end user: none^
|
| Benefits to the end user: more affordable tomato paste
|
| Government action to prevent slave labour products
| entering Australia: none^
|
| ^close enough.
| martimarkov wrote:
| Negatives to end user: unknown pesticides or banned
| pesticides.
|
| No propaganda - lack of validation, evidence and trust
| perpetuallunch wrote:
| What does slavery, real slavery or anti-China propaganda
| fake slavery, have to do with the with the presence or
| absence of pesticides, banned or otherwise?
| stubish wrote:
| It is perfectly legal to sell Chinese tomatoes in
| Australia (which is not necessarily a good thing, re:
| forced labour in Italy and China). The fraud is
| mislabeling them as Australian or similar, denying
| consumers from making their own ethical choice. Which is
| your harm to the end user and generally enforced by the
| ACCC.
| kkotak wrote:
| If you're going to start talking about mislabelling
| products, you're going doing a rabbit hole of hundreds if
| not thousands of products sold in reputable stores. Look
| up how FDA labels for Organic, Grass fed, Pasture raised,
| etc. are used through out the industry in the US and the
| world. You should also look up the requirements for "Made
| in X" labels for consumer products. Playing with word and
| people's emotions on what those labels mean when making a
| purchase decision is as old as commerce itself. Don't for
| a moment think of the US or a Western country being
| rightious about this.
| perpetuallunch wrote:
| The information this is based on is reporting from the
| Australian ABC TV program Four Corners.
|
| The ABC is a know, as in they don't even try to pretend
| propriety, propaganda outlet of the Australia Albanese
| federal Government.
|
| I'm not saying this is definitely propaganda, but there's
| a non-zero chance it _is_.
|
| The Albanese government has been very open about
| attacking industry.
| neves wrote:
| Chinese workers earn more than workers from latin
| America. At least their government isn't slave for
| billionaires
| biztos wrote:
| While it could of course be produced in Xinjiang
| _without_ using "slave labor," the US government banned
| those tomatoes in 2021 because of that risk:
|
| https://www.cbp.gov/newsroom/national-media-release/cbp-
| issu...
|
| If Costco were circumventing the ban it'd be a pretty big
| deal. I couldn't google up any indications that they are,
| so on balance I'd say it's "possible" in the same way my
| winning the lottery is possible. Can't rule it out, but
| reasonable people should probably bet against it.
|
| TIL: Xinjiang tomatoes are something like 15% of the
| global market!
| seanmcdirmid wrote:
| > TIL: Xinjiang tomatoes are something like 15% of the
| global market!
|
| China consumes 37% of the world's tomatoes. 80% of
| China's processed tomatoes are from xinjiang. Fresh
| tomatoes are generally grown locally, but that is true
| around the world.
| LordAtlas wrote:
| China _produces_ 37% of the world's tomatoes, not
| consumes.
| bell-cot wrote:
| Compared to the big e-commerce retailers, Costco's total
| number of sku's isn't even a rounding error.
|
| And most of Costco's sku's are food, clothing, housewares,
| bulk consumables, and such - vastly easier to test and vet
| than computer & internet-connected electronics.
| ChoGGi wrote:
| Sounds like you're agreeing that Costco is well curated?
| bell-cot wrote:
| _Compared to_ Amazon and other e-tailers with hundreds of
| thousands of sku 's of computer & internet-connected
| electronic stuff, 99% of which they do nothing whatever
| to curate? Yes.
|
| But that's kinda like saying that Random Pond is safer
| for swimming than a lava lake.
|
| Do I just assume nothing can go wrong when I myself shop
| at Costco? NO.
| 40four wrote:
| I don't disagree, Costco has a reputation for selling well
| vetted products, but that's not a good comparison. I trust
| Costco (even their online only sales), but in no way do I
| trust the other merchants listed.
|
| We're specifically taking about merchants that have a super
| shady online presence. They will basically sell you
| anything and everything and don't care if it harms you.
|
| The ones mentioned (Amazon, Best Buy, New Egg), it's going
| to be hard to argue they vet (or care about vetting) the
| digital products they sell. You might as well throw Walmart
| into group too, their online offerings have gotten super
| sketchy if you really do into it.
| Uvix wrote:
| Target as well. It was one thing when it was just Amazon
| acting as a sketchy third party storefront, but now
| everybody's doing it.
| riddlemethat wrote:
| We bought a Bosch dishwasher from Costco in January. It was
| defective and wouldn't start after 10 days. Costco replaced
| it. The replacement came with a big gash on the front off
| the truck so we refused it and Costco sent a third
| replacement. Again, it was the same model and again it
| wouldn't start after another 30 days. Costco took it back.
| No cost to us for any of these delivery or install
| attempts.
|
| We bought a different model from Costco and it's been rock
| solid. I expect I will never buy a major appliance from any
| other retailer as long as Costco continues to care like
| they do today.
| fn-mote wrote:
| > I will never buy a major appliance from any other
| retailer
|
| Weird. You experienced failures of the manufacturer
| (failure to start) and the warehouse (huge scratch), and
| are still singing someone's praises.
|
| It sounds to me like the brand's quality assurance is low
| and the retailer also isn't taking care of their stock.
|
| If I had to take three days off work to accept these
| deliveries, doubtless I would have a very different
| conclusion from yours.
| dsr_ wrote:
| He's singing the praises of CostCo, which made him whole.
|
| Any dishwasher could have these problems; any warehouse
| could. How the seller handles the situation is key to
| whether you use them again.
|
| CostCo has built a huge reputation for being trustworthy
| as a retailer. If they get purchased by private equity, I
| will stop renewing my membership, and think about how
| close the country is to decorating lampposts.
| _RPM wrote:
| > I will never buy a major appliance from any other
| retailer
|
| That's called stinking thinking.
| contagiousflow wrote:
| What is the alternative? Trust has been built, as long as
| the trust is not eroded it is safer than any other
| retailer?
| rpdillon wrote:
| Yep, I'm pretty much a lifetime member of Costco if this
| sort of prioritization doesn't change. A recent article
| put it well "Costco is the anti-Amazon".
|
| I say this as a happy customer of both, though. I don't
| seem to have the problems others do with horrible
| products from Amazon, but I suspect my purchasing habits
| might be different as well.
| red-iron-pine wrote:
| arguably it's part of their main value proposition: bulk,
| but not terrible, and generally decent.
|
| fixed fee membership also means a very stable revenue
| stream and they can take the time to do this, while other
| places like newegg are herding 3rd parties to get cuts of
| ever cheaper 3rd party crap
| Rickasaurus wrote:
| I have to disagree, costco often has custom worse versions
| of better products, we recently had a costco air
| conditioner fail just to find out it wasn't built quite as
| robustly as the $50 more expensive midea sold elsewhere
| with an almost identical model number. Similarly had my
| costco GE washing machine fail last year right out of
| warranty. There's a real quality problem going on with
| costco right now.
| onemoresoop wrote:
| They'll replace them if they break and the return policy
| is very good as well. It's safe to buy from Costco
| Aerroon wrote:
| You go to an online store to buy a hard drive. It's listed as
| "in stock" and you buy it and pay for it. A week later you
| get an email from the store that the specific hard drive is
| now available at a third party warehouse and they can order
| it from there, but the price is about 10% higher.
|
| The above actually happened to me. That's what online
| retailers were like before Amazon's reach properly extended
| here. That's also the main value proposition for these
| retailers for me.
|
| Also, online retailers are far more likely to accept returns
| compared to regular stores. If you get a bad product from a
| regular store you're often just screwed.
| swatcoder wrote:
| The late-Amazon process for this is to just send you
| whatever's marked as the hard drive in their warehouse,
| which may be that actual product, a counterfeit, or a brick
| in the hard drive's package.
|
| Later, when you want to try the return, a black box
| algorithm asseses your transactional value to Amazon and
| decides whether your concerns are worth attending and to
| what degree.
|
| Maybe that really is better than whatever you were used to
| in your own market, but it's a profound regression on the
| traditional retail experience for most of us here.
| zombot wrote:
| Crooks will be crooks, but that the lawmakers let them get
| away with it is something that should change.
| jon-wood wrote:
| Amazon even have big "people commonly return this product"
| warning on some product pages. Anywhere halfway sensible
| would maybe reconsider stocking a product worthy of that but
| because they've set themselves up as a middleman without any
| of the risk they can just churn junk out of their warehouses.
| deaton wrote:
| Online it still seems like for the most part if you buy from
| something a bit more specialty (e.g. McMaster, Digikey, etc)
| you still get really good vetting and high quality stuff, but
| amazon is more than happy to be filled with absolute garbage.
| boondongle wrote:
| Just being realistic here; many of these are of Chinese make so
| how exactly would you stop it other than blocking them from
| being sold. They certainly don't advertise to the big box
| retailer that buys them "and it uses the customer's internet
| connection for fraud."
|
| Hell, there's a section of comments that would probably going
| "hey, RELAX guy" because it's not US companies doing this. For
| any American companies that do this though, sure -
| block/suspend/prosecute.
| malfist wrote:
| If I open my own line of home improvement stores and do no
| oversight on what I sell and wind up selling really dangerous
| lawnmowers, I'm partly responsible.
|
| Or if I open up a gas station and allow any company without
| oversight to sell "supplements" through my shelves and cops
| arrest me for selling heroin, I don't get a free pass.
|
| Why should amazon or Walmart get a free pass just because
| they sell more items?
| awakeasleep wrote:
| One problem I see with your analogy is that the dangerous
| lawnmower can cause an easily quantifiable harm.
|
| You have to be able to show damages you incurred and assign
| a dollar value to them to sue people.
|
| That doesn't work at all for a something that sells your
| bandwidth to a proxy service. People wouldn't even be aware
| that it was happening they weren't told.
| SoftTalker wrote:
| What about when the police show up because some highly
| illegal content was traced to your IP address? Will they
| believe that you were the unwitting victim of a rogue
| proxy server running on your streaming stick? Would you
| have even been aware of that possibility?
| xorcist wrote:
| There's also always the flip side: When the police shows
| up because of your illegal acitivities, you have a rogue
| proxy server running. All bought in good faith of course.
|
| Not legal advice.
|
| (It would surprise me greatly if we as a society let
| these gadgets be sold openly from here on.)
| ndsipa_pomu wrote:
| That shows the problem or trying to link an IP address to
| an individual.
| inigyou wrote:
| Believe it or not, that is what happens when the police
| show up to the house of a primary school teacher. They
| will think they have the wrong address. Even US police.
|
| The cybercrime raids happen when they run into someone
| who looks like a hacker and has a lot of computers.
| wsintra2022 wrote:
| Except the devices are not dangerous. Its the software
| installed on the device. Consumers have a choice. Pay for
| the trusted Apple TV or Amazon firestick, or go the wild
| west and see what's on offer.
| CrazyMusicians wrote:
| with the devices mentioned in the article, there is no
| consent requested, and the malicious apps are installed
| either before the box is sold or after as a requirement
| for getting the streaming services to work.
| inigyou wrote:
| You call them malicious apps but what is the evidence
| they are more malicious than the things they fight
| against?
| jon-wood wrote:
| Really? You'd be ok with me putting a proxy server on
| your home network then, which anyone with a few bucks can
| use to attach your IP address and subscriber details to
| anything they choose to request from the internet? How
| about a Tor exit node?
|
| Its incredibly obvious to anyone applying any thought at
| all to this that its a malicious to sell a product that
| labels itself as a TV streaming stick which is in fact a
| paid for relay server with the money made from providing
| the internet connection to a random third party unrelated
| to the person who bought the thing without ever telling
| the customer.
| inigyou wrote:
| Yeah I actually do several of those to earn a few bucks.
| jon-wood wrote:
| The typical consumer has no idea what they're buying, and
| they shouldn't have to because the retailer selling the
| product should have done some basic due diligence before
| stocking the thing. People aren't going to some clearly
| shady Chinese website and buying a device labelled "cheap
| TV streaming stick, will sublease your internet
| connection to criminals", they're putting "FireTV" into
| amazon.com and somehow being presented with these things
| alongside the Amazon FireTV they expect to find, or maybe
| "streaming stick" which really shouldn't be surfacing
| clearly malicious products.
| inigyou wrote:
| If the average consumer did get a disclaimer it would
| sublease their internet connection to a few criminals and
| a lot of people who aren't criminals, would they care?
| II2II wrote:
| > If I open my own line of home improvement stores and do
| no oversight on what I sell and wind up selling really
| dangerous lawnmowers, I'm partly responsible.
|
| While there would be oversight, it is highly unlikely that
| a person opening a home improvement store would perform any
| meaningful safety testing. They simply would not be
| qualified. The oversight would lay in selling certified
| products, pulling recalled products off the shelf, and
| (perhaps) removing products if there is a reason to suspect
| safety issues.
|
| Now consider streaming sticks. There are safety standards
| for the physical device but, to my knowledge, there are no
| such standards for the software itself. Heck, there aren't
| even standards for the engineers who work on the software.
| One can make highly prejudiced decisions based upon the
| country of origin. Perhaps there are even good reasons to
| avoid products from certain countries. Yet the lack of
| standards also means that products from trustworthy sources
| can be suspect, since all it takes is a management decision
| to change things.
| inigyou wrote:
| But these products aren't dangerous. And proxying internet
| traffic isn't illegal. Fake ad clicks may be illegal but
| that falls on whoever is providing that service, which
| isn't the proxy or the resident. On what basis would you
| ban them?
| AngryData wrote:
| But it is a retailer's responsibility to know what they are
| selling. If it was added after they started selling it and
| hidden in secret, sure a retailer might have an excuse. But
| it isn't really hidden, most often its put in their marketing
| materials as a benefit and have been knowingly doing it for
| many years now.
|
| US retailers can be told they can't sell it here. If you buy
| it outside of that, well that is buyer beware, but 99% of
| people aren't buying things from Alibaba or ordering from
| some random foreign store, they are buying them off US
| Amazon, Walmart, big box retailers, etc. You don't have to
| ban things consumer level to deal with 99% of it, you just
| gotta tell big corporations no and stop dismissing any ideas
| that put responsibility or liability on big business.
| crote wrote:
| The problem is that Amazon, Walmart & friends have said the
| "we are a _platform_ , not a retailer" magic incantation,
| which means that through the power of friendship and
| unicorns they are now suddenly no longer responsible for
| the stuff they sell.
|
| And the "retailer" on record is of course not a real
| company. They'll just pay some third-party to file a bunch
| of paperwork in Delaware, pay the $110 fee, and let it go
| bust if anyone tries to investigate it or make it liable.
| pixl97 wrote:
| >If it was added after they started selling it
|
| While it's great we're getting the manufactures to just
| stop sending out straight malware and it should be stopped
| the next most obvious means of attack is just having the
| device update and add superaids to it's new functionality.
|
| So, no, it won't stop 99% of it at all.
|
| And honestly this isn't that much different from what US
| companies are already great at by providing updates that
| take away features we bought with the device.
|
| And not just updating really doesn't save you, instead of
| being part of a factory botnet, you're just open to become
| part of some other botnet.
| crote wrote:
| > Just being realistic here; many of these are of Chinese
| make so how exactly would you stop it other than blocking
| them from being sold.
|
| You already answered it: block it from being sold.
|
| 1) Make Amazon responsible for the products they are selling.
| 2) Introduce a law banning malware tv sticks 3) Sue Amazon
| for a percentage of their yearly revenue when caught
| violating it 4) Amazon will _finally_ start caring and do
| _some_ kind of review on the crap they sell.
| pixl97 wrote:
| And if the first time you get it online it just updates
| itself to malware?
|
| That's the biggest problem with any device that updates.
|
| Yea, this will work for the moment and the seller will be
| covered in the sense that "well, it wasn't infected when we
| sold it".
| deaton wrote:
| The law is not software. It would be very easy to argue
| that a streaming stick that automatically downloads
| malware is no different from one that came with malware.
| pixl97 wrote:
| And that's where the retailer is no longer in the loop,
| which is what this thread was about.
| StilesCrisis wrote:
| If it's malware, maybe existing laws apply already. I think
| the bigger problem is enforcement. In China, it's easy to
| close up shop if anything goes wrong and then just start
| over. Any liability dies with the brand name.
| themaninthedark wrote:
| I think a law that makes a marketplace responsible for
| items being sold if the qty of items is above a threshold
| would be a great idea.
|
| You don't want to penalize someone selling their Xbox or
| lawnmower on Ebay but you want to stop what is going on
| here. A place like Etsy where people are selling their
| crafts is an interesting edge case but I think they should
| probably be a little regulated.
| skybrian wrote:
| The FCC tests electronics for radio interference. Perhaps
| they could test electronics for Internet behavior like this
| too?
|
| Some manufacturers will try to cheat on the tests, but we
| have AI security checking now, so maybe that would make it
| harder to cheat?
| iamnothere wrote:
| That sounds like a fast track to government control of what
| operating systems are allowed. These aren't just
| electronics, they are low power computers that happen to
| have an OS and software preinstalled.
|
| (I'd be open to a rule that devices must allow users to
| wipe the devices and install their own OS.)
| skybrian wrote:
| On the other hand, I suppose if the OS on a TV stick ran
| in a hardware-enforced sandbox that restricted network
| access to certain necessary domains, it couldn't be used
| for scraping websites and ad fraud? It's not being sold
| as a general-purpose computer so maybe it shouldn't be
| one.
| lesostep wrote:
| Simple. Buy one, put it on a test stand, and look at
| connection log.
|
| Buying in bulk for a resell without testing even one product
| is kinda insane.
| ryandrake wrote:
| I would very much be in favor of grocery stores sharing
| responsibility (and regulatory penalties) for selling tainted
| food! It's kind of mind boggling that this is controversial.
| "Buyer beware" is not an acceptable basis for society to
| function.
| SoftTalker wrote:
| I can't think of a case where a supermarket, upon becoming
| aware of a problem with a food product, didn't immediately
| pull it from the shelves, post a notice to customers, and
| offer a full refund to anyone who had purchased it.
| StilesCrisis wrote:
| This is unfortunately exactly how society operates in China.
| It is basically on the buyer to confirm that they're getting
| something acceptable. Once they've paid, it is what it is.
| fragmede wrote:
| Not exactly. In 2008 there was a huge scandal where
| melamine was in baby's milk, so it isn't always what it is.
|
| https://en.wikipedia.org/wiki/2008_Chinese_milk_scandal
| StilesCrisis wrote:
| Yes, if your malfeasance is large enough to be on the
| front page of the New York Times, you'll be sentenced to
| life in prison or even death. But killing babies is a bit
| more heinous than fraudulent ad clicks!
|
| (Also of note: WHY melamine in the baby formula? Because
| they knew the buyer would check the nitrogen content,
| because it's a caveat emptor culture.)
| mattmcknight wrote:
| This is why I hate the "marketplace" of these stores. In many
| cases these products never hit their inventory at all, they are
| functioning like a search engine and payments processor.
| eddythompson80 wrote:
| That's generally in their definition. "Amazon Marketplace"
| came out in 2000 allowing 3rd party sellers on their
| platform. However, until maybe the mid 2010s, they favored
| product sold by Amazon over 3rd party in their results and
| recommendations. I remember numerous forum and Reddit posts
| from the late 2000s about "How Amazon scams 3rd party
| sellers" by only wanting them there to give the illusion that
| they have everything but once some category starts selling,
| they will vendor it too and steal your customers.
|
| At some point in the second half of the 2010s Amazon figured
| out they can't compete with a million foreign randomly-
| generated companies on price, and their users didn't seem to
| mind too much. They figured their users cared about delivery
| times, ease of returns, ease of dealing with Amazon instead
| of dozens of online sellers, etc and they leaned heavily into
| that. They will handle fulfillment and take their cut and let
| people buy whatever garbage they want. They still screw
| sellers too btw. Ask any one who is trying to sell something
| on Amazon and they will fill your ear with how much leverage
| amazon has over them. You can check r/FulfillmentByAmazon/ Or
| r/AmazonSellers for stories.
| bashtoni wrote:
| Yes, fascinating that this is apparently all the fault of
| Chinese companies, and not the American companies distributing
| and retailing these products.
| themaninthedark wrote:
| Um...If I make an app that reroutes people's payments so that
| I can skim a percent off the top and release it for Android
| and IPhone as a shopping app, how would it be Google and
| Apple's fault?
|
| Sure they try to vet the app but how does that absolve me
| from the liability?
| ChuckMcM wrote:
| In the US at least there is a lot (and by that I mean like
| maybe more than half) of civil case law around seller liability
| for defective or 'dual use' products. In the 70's some cities
| tried to sue hardware stores for selling spray paint that
| taggers were using, in several jurisdictions you can find
| authorities trying to sue vendors of lock picking and/or safe
| opening tools, etc. My non-lawyer reading of all that is that
| if it is reasonable to assume that the vendor didn't know, _at
| the time of sale_ , what the customer was going to do with it,
| they aren't liable.
|
| Once a vendor has been notified that these units are doing
| these sorts of things they will stop selling them. Its sadly
| very prescriptive in that if Newegg gets a notice that
| "WatchFunTV" streaming sticks are doing this, they will remove
| that brand but if the same hardware shows up from the same
| vendor as "SuperTVStreamer" or some such, _that_ product won 't
| be banned until someone does the test and then notifies the
| sellers. It's cat and mouse all the time.
|
| Now the people who _could_ do something about it, the ad
| networks like Google, do not do anything because ad revenue is
| ad revenue, people buying the ads cannot prove that the click
| was false so hey who can say it was? Which is why ad fraud is a
| perennial favorite of crooks. The people being ripped off don
| 't have any way to prove it without a lot of support from the
| ad network traffic data which is "proprietary". Really stupid
| ad fraud gets shut down, but put a bit of care into it so that
| the Ad network and claim ignorance? You can do that all day.
| Just don't get greedy and try to pull in more than say 30 or 50
| thousand dollars a month. Remember, the IAB said in 2025 alone
| Ad Revenue was $300B[1] so 2% of that is only $6B and any
| network with 2% or less of undetected fraud is considered a
| "high quality" ad network.
|
| So yeah, ad fraud is the gift that keeps on giving.
|
| [1] https://www.iab.com/insights/internet-advertising-revenue-
| re...
| sneak wrote:
| Tainted food and unsafe children's toys kill people.
|
| Sketchy devices on your wi-fi don't really harm anyone. They're
| a minor inconvenience at best, mostly to large corporations
| that like to discern residential connections from
| business/corporate ones.
| inigyou wrote:
| I don't know why this is such an unpopular opinion on HN.
| red-iron-pine wrote:
| you don't get why a news aggregator for tech bros have
| problems with crappy devices hacking them?
| inigyou wrote:
| What is being hacked? The ad industry? I didn't know the
| average HNbreader had such deep compassion for _the ad
| industry_.
| tclancy wrote:
| This is one of those things where I, as a suburban white kid,
| am so happy I discovered Public Enemy and similar bands as a
| kid.
|
| "Money talks. And bullshit brothers walk a marathon."
| tomjen3 wrote:
| Probably because doing so would mean a lot fewer product
| categories. It's a trade-off, to be sure. But if you need that
| odd thing -- a screw of a certain type, a power supply that's
| 56 volt DC or whatever -- then if there's only going to be
| sold, say, a few thousand of those a year, if Amazon was
| required to do product safety testing on them, they probably
| wouldn't be able to sell that category at all. And so the
| trade-off is they are not required to.
|
| Now that's very different from "we are selling things that we
| know, or have good reason to know, specifically are dangerous"
| -- here they might very well be liable.
| phendrenad2 wrote:
| On the other hand, these are great little devices to root and put
| Linux on.
| buellerbueller wrote:
| To those who are OK with these devices: when you engage in
| corruption, do you have any moral standing against your
| politicians when they engage in corruption?
|
| Both you, and the corrupt politicians, are eating away at the
| trust that underpins society. Certainly, you can argue, your bite
| is just a tiny one; the politician is eating the whole apple.
|
| At the end of the day, everyone suffers from the decline of trust
| and casual acceptance of fraud.
| PufPufPuf wrote:
| My "streaming device" of choice, ThinkCentre Tiny with Linux,
| always feels validated with news like these. It fits behind a TV,
| you can get it second hand for around $40 and depending on model
| it can even act as a retro game console as well.
| CrimsonCape wrote:
| Is there a good TV UI OS that runs desktop youtube under the
| hood for ad blocking?
| jojobas wrote:
| There is Kodi Youtube plugin that takes a developer token and
| is then ad-free.
| PufPufPuf wrote:
| I use the VacuumTube app
| (https://flathub.org/en/apps/rocks.shy.VacuumTube), which has
| ad block, sponsor block, and some more advanced settings! You
| can use GNOME with scaled up UI or KDE Bigscreen (recently
| resurrected) for the DE.
| burgreblast wrote:
| Google clutches pearls and is shocked! Shocked! That anyone would
| violate its policies (while it pockets 30% of the fraudulent
| revenue). Shocked!
|
| And they would have caught them but those crafty criminals
| spoofed the user-agent. So how _could_ they know?
| scottydelta wrote:
| After getting tired of ads on my PAID smart TV, 6 months ago I
| started building a casting device using raspberry pi for myself.
| A couple of months later one of my friends who is an AV
| technician ended up using it at the largest convention venue in
| Barcelona to play content on loop, here's a video of that:
| https://www.youtube.com/shorts/FF3I9EOs4AA.
|
| Fast forward to last month, now I have started selling these in
| Barcelona, Spain where I am based out of and branched it into
| three use cases: digital signage, casting, and a portable
| computer for presentations at events. Here is the link with
| features: https://soljacast.com
| emacdona wrote:
| Clicked on the link, ready to buy one. "Contact sales". Ew. No
| thanks.
| scottydelta wrote:
| We are literally new and only available in Barcelona at the
| moment which I mentioned in my comment as well. Not sure
| what's eww about that?
| emacdona wrote:
| Sorry, knee jerk reaction any time I see "contact sales"
| instead of a price.
| scottydelta wrote:
| No worries. If you message me via the contact form or
| chat support on the website, I will try my best to
| provide you with one. The more feedback I can get, the
| better.
|
| Thanks for liking my product enough to want to buy it
| right away :)
| cryptoegorophy wrote:
| Sales friction is how you lose sales. Make your website
| one click purchase product page. One button - apply pay,
| customer pays with preset shipping and then you handle
| everything from there.
| scottydelta wrote:
| Trust me, I really wish it were that easy. We're based
| out of Spain, so to sell in the US (or other countries)
| we either need to figure out assembly of the device
| there, or we need to solve cross-border payments,
| logistics, customs clearance, tax remittance to
| individual states, and hardware compliance. That said,
| we're working hard on all of it and plan to go D2C as
| soon as possible.
| throwawsy7273 wrote:
| I haven't used them myself, but it seems that services
| such as paddle.com takes care of the payment and tax
| compliance. There are probably similar sevices for
| logistics as well.
| scottydelta wrote:
| The thing is majority platforms like paddle.com don't
| supoort hardware products. I was looking at fastspring as
| well but hit the same wall. I will still try reaching out
| to paddle.com support to see if they will allow it. Thank
| you for the suggestion.
| crote wrote:
| Your device seems to be an off-the-shelf Raspberry Pi
| running custom software. Have you considered making the
| platform available in a BYOD form, either for fulltime
| use or for evaluation?
| scottydelta wrote:
| Yes, we're using an off-the-shelf Raspberry Pi for v1. We
| are working on figuring out a custom board for v2,
| because we can't scale with Raspberry Pi as a dependency,
| especially with RPi prices constantly rising due to the
| RAM shortage.
|
| Also, we want to test our OS extensively before we
| release it to be used with a BYOD model. We are launching
| soon and after that we will try to offer BYOD model as
| well.
|
| If you are interested in trying it out and helping me in
| evaluation, please reach out to me via email on my HN
| profile. Thank you
| 0manrho wrote:
| I believe they're referring to the friction point of this
| company/website not publicly listing a price. That's a huge
| barrier/red flag to a lot of people. Myself included. Last
| thing I want to do is waste time bouncing emails back and
| forth between sales just to figure out if the price range
| is even remotely in my wheelhouse.
|
| However, if your target is B2B (Business to Business) as
| opposed to B2C/D2C (Business to Client/Direct to Client)
| and you're selling the install plus enterprise support,
| then the sales thing makes way more sense, and is more
| expected/palatable for B2B type customers than your
| everyday consumers, so depends on who you're targeting.
| scottydelta wrote:
| We are working on figuring out payments, logistics,
| hardware compliance (different countries have different
| requirements), state-level tax handling, customs
| clearance, etc. for D2C.
|
| Also right now we are focusing on B2B here in Spain like
| you guessed, and once we have the other things figured
| out, we will start shipping to the US and Europe. And
| after that we plan on rolling out to the rest of the
| countries.
| crooked-v wrote:
| The "eww" part is that normally, anytime you see "talk to
| us for a price", that means someone is charging an absurdly
| high amount for the good or service.
| scottydelta wrote:
| I see, the thing is we are very new and plan on launching
| soon. We are still trying to figure out our B2C/D2C
| pricing.
| TiredOfLife wrote:
| "contact sales" literally means expensive shitty product.
| sajithdilshan wrote:
| your product looks cool, but why do I need to contact sales to
| buy that device? can't you just open like a shopify shop and
| redirect end customers to that? Also showing the retail price
| on the page would be a plus one
| scottydelta wrote:
| Thank you for your kind words. I am pasting one of the
| comments I made on this thread regarding challenges with
| online sales at the moment:
|
| > Trust me, I really wish it were that easy. We're based out
| of Spain, so to sell in the US (or other countries) we either
| need to figure out assembly of the device there, or we need
| to solve cross-border payments, logistics, customs clearance,
| tax remittance to individual states, and hardware compliance.
| That said, we're working hard on all of it and plan to go D2C
| as soon as possible.
|
| For the pricing part, I am still trying to figure out the
| pricing for retail consumers. It was relatively easier to do
| for B2B but for retail, there are a lot of factors and moving
| parts such as import duties, taxes, shipping etc.
| Doohickey-d wrote:
| Krebs' blog is nice, but quite often it's just re-reporting stuff
| from somewhere else:
|
| Original with more details: https://www.bitsight.com/blog/fuyao-
| enterprise-building-ad-f...
| crote wrote:
| LG televisions and monitors spy on their users and install
| unwanted software. _Half_ of all smart tvs are running
| "residential proxy" malware. Google is banning sideloading but
| happily hosting apps using the Bright SDK.
|
| Sorry, but "your tv stick does ad fraud" is just about the most
| innocent thing I've seen in a while. _Everyone_ in this market is
| doing the shadiest shit you can imagine. There are no good brands
| left, you just get to pick what logo your Malware Entertainment
| Device has.
| inigyou wrote:
| Is it even really malware if it's harming advertising networks
| and not you?
| cwillu wrote:
| "as part of a sprawling operation that seeks to defraud online
| merchants and advertising networks."
|
| Oh no! Not the advertising networks!
| atum47 wrote:
| Got myself a mi box with a custom launcher. Way better than any
| other Smart TV out there. Unless there's a smart tv that does not
| show ads right on the fing front page.
|
| Anyway, the box is powerful enough to do several things. You can
| install a IP tv if you want. If you don't, you still have a
| pretty good media center (you can hook up an external hd on it)
| Scoundreller wrote:
| Though I do then wonder about some of the iptv apps even the
| ones provided through paid subscriptions but that's already on
| the dark side; but not as dark as these "buy once" 1000s of
| pirated channels devices
| aucisson_masque wrote:
| The Xiaomi box also send lots of data to Xiaomi server but also
| ads/tracking network.
|
| I switched to a Google box, this has no bloatware and this way
| I get tracked only by one company.
| shmuli9 wrote:
| This is amazing. Kudos to the team behind it I mean, sucks for
| advertisers and is utterly deceitful... but genius!
| tomaskafka wrote:
| At this point China probably has a botnet that can be turned on
| with a few deploys, and spans a majority of homes in US and RU
| (and thus is unblockable without disconnecting half of voters
| from the internet). Ready to attack the infrastructure.
| bashtoni wrote:
| I don't know where you get the idea this is a nation state
| attack.
|
| The devices are used to sell proxy services and scam
| advertisers. This doesn't even need particularly large
| organised crime. It would certainly be easier than large scale
| illicit drug importation and retail, which is happening all the
| time.
|
| Could China exploit these streaming sticks if it wanted to?
| Maybe, but no more than any other nation.
| tossingafterxyz wrote:
| Not necessarily correlated to this, but my perception is that
| china is generally ok with many types of crime as long as
| it's not perpetrated on its citizens / aimed at foreigners
| (IP theft / counterfeit goods / cyber crime etc). However, I
| also think the state largely has a good sense of the actor or
| players and is perfectly capable of exerting force or
| coercing them to their cause at will.
| munk-a wrote:
| Read this:
|
| Use a computer - you actually control the content that way.
| zeroq wrote:
| tangent thought experiment
|
| So you bought that top of the line security-as-a-product thingy
| you can stick in your rack and it will make sure that your
| network is impenetrable? You know, like those CISCO bricks
| everyone major company is buying.
|
| So have you took an extra precautions to make sure that the
| firmware on the device is pristine? Do you know anyone who ever
| touched these devices who actually did?
|
| Do you see the problem?
| jojobas wrote:
| Cisco bricks leave the factory as pristine as they can be. An
| intercept sort of attack is possible, but involve quite some
| effort and risk.
|
| These sticks leave the factory with malware pre-flashed, the
| postman brings them to your door with zero risk for the
| beneficiary.
| shevy-java wrote:
| > they secretly rent the user's Internet connection out to
| strangers
|
| So the mafia is back.
| jms703 wrote:
| You buy garbage, you get garbage. You can no longer depend on
| resellers or to protect you. They are unphased and unaffected by
| selling you this garbage. No one else has a financial incentive
| to protect you. Sorry if this sounds victim blamey. Don't mean it
| to be. Just trying to convey that we're on our own.
| byterivet wrote:
| Good job.
| dxxvi wrote:
| Ah, got it. Those devices are like computer virus which don't
| need a computer to live on.They can make DDOS attacks if they
| want to. So, buying these devices at a cheap price is like
| renting out your IP address and your Internet connection.
| BigTTYGothGF wrote:
| > these devices also routinely spoof themselves as mobile phones
| clicking ads on AI-generated websites as part of a sprawling
| operation that seeks to defraud online merchants and advertising
| networks.
|
| Every cloud has a silver lining.
| ColdStream wrote:
| Alternatively, if you are going to do some questionable things,
| just buy loads of these things and create a hundred back doors on
| the network to increase the noise.
|
| Sounds good in theory but in practice, computers are good at
| sorting this stuff out. Kind of why they are so popular.
| estebarb wrote:
| Oh wow, even scammers care about usability and their employees'
| well-being. What's the excuse for bad UX in internal company
| software?
| perpetuallunch wrote:
| > rent the user's Internet connection out to strangers.
|
| Harm to the user: none^
|
| > spoof themselves as mobile phones clicking ads on AI-generated
| websites as part of a sprawling operation that seeks to defraud
| online merchants and advertising networks
|
| Harm to the user: none^
|
| Cost to the dodgy service provides: none
|
| Government action to prevent continued dodgy services: none^
|
| This is why internet securityg doomers have a hard time selling
| their story. Changing behaviour has an upfront, immediate, cost.
| Not changing it doesn't.
|
| ^close enough
| charonn0 wrote:
| >> rent the user's Internet connection out to strangers.
|
| > Harm to the user: none^
|
| Well, they _are_ losing some of their bandwidth. They might not
| notice, but something which is rightfully theirs is being taken
| without consent.
| perpetuallunch wrote:
| If they don't notice, and they're on an unlimited data plan,
| or the usage is such that it doesn't result in exceeding
| their data cap, what argument is there that harm occurred?
| thothless wrote:
| roku is sniffing your farts. and reading your texts/emails.
|
| https://docs.roku.com/published/userprivacypolicy
|
| see: "olfactory", "content of"
|
| or at least they're CYA while they're sniffing.
|
| they definitely scan the entire local network.
| theendisney wrote:
| Long ago I ponder giving away free computers but an ethical
| formula is really hard. It seemed profit starts to scale
| exponentialy just beyond the line.
|
| (Acepable would be something like 1TB worth of gamedemos)
| miohtama wrote:
| This is why Google/Meta is pushing for "age verification".
|
| 1. They want more as targeting data on you
|
| 2. They want to reduce bot clicks
|
| It's an unholy alliance with governments who want to know who
| writes what online.
| inigyou wrote:
| I'll take residential proxies over mass surveillance any day.
| It seems surveillance will always expand unless countered.
| neves wrote:
| I really don't mind anymore. My Roku stick is now owned by
| extreme right Fox Corporation. Chinese ad click network are petty
| villain compared.
| wao0uuno wrote:
| If you have a Raspberry Pi 5 gathering dust somewhere and need a
| new streaming box then try LibreELEC. It decodes 4k content just
| fine. It has HDMI CEC. It can stream from local server or play
| directly from attached storage. There are no ads or
| tracking/profiling. It can play YouTube without ads but there is
| no support for Netflix, Apple TV or similar streaming services.
| dspillett wrote:
| A Pi4 does the job well too. They can be had noticeably cheaper
| than Pi5s ATM, if you don't have the luck of having a device
| lying around ready to be repurposed, and even the 1Gb models
| are plenty sufficient.
|
| A Pi3 may suffice even, that is what I ran Kodi on before
| upgrading it to the Pi4, though the lack of hardware x265
| decoding support is a limiting factor there (IIRC it'll manage
| 1080p in software, but only if you have some good cooling
| installed otherwise things get very skippy after a short while
| as thermal throttles kick in).
| joeisnotjane wrote:
| Ah, it's about "China, China.."
|
| Preparing casus belli.. first, open weights LLM which are "not
| secure", now "TV sticks"..
|
| Oh joes and janes, who will put finally some sense into you..
| Ikatza wrote:
| Ah, yes, the great TV sticks war of 2028. We'll tell the
| stories.
| joeisnotjane wrote:
| It is about gradually, but constantly, creating the image of
| an "evil adversary".. Venome drop after venome drop..
|
| China is not doing that as far as I know. Neither Russia did
| it before the war, though you were claiming the contrary (I
| know, since I live in the west and could compare news from
| both sides, being a native Russian speaker).
| inigyou wrote:
| Krebs fails to make any case for why someone wanting to watch
| movies and TV should give a shit.
|
| I get that these products are personally inconvenient to Brian
| Krebs and his work, and to companies that make money blocking
| people from accessing the internet, and to companies that make
| money spewing ads in people's faces. So? Why should anyone care
| about any of those? In fact I think some people would get one of
| these sticks just to inconvenience the latter two groups!
| AlexandrB wrote:
| This is only _slightly_ more malicious than the software "Smart
| TVs" already ship with.
| stevetron wrote:
| Birds Nest soup with Chinese tomatoes?
|
| Or Cinese noodles with Chinese tomatoes?
|
| It sounds likw 2 domestic markets that China should use to rid
| themseves of their over-abundance of tomatoes.
| coretx wrote:
| The most relevant difference between using a TV and a "TV
| streaming stick" is corpos & the State controling the
| malware/surveillance device.
|
| Being a ordinary person, I do not want criminals or the (
| ads/data ) industry or the state to be in control of my property.
|
| Also, any DRM not passed by a parliament undermines the rule of
| law & statehood. This is something Krebs and his Praetorian guard
| buddies _must_ know.
___________________________________________________________________
(page generated 2026-07-31 16:01 UTC)