URI:
       [HN Gopher] Read this before you buy that TV streaming stick
       ___________________________________________________________________
        
       Read this before you buy that TV streaming stick
        
       Author : speckx
       Score  : 780 points
       Date   : 2026-07-30 17:04 UTC (22 hours ago)
        
  HTML web link (krebsonsecurity.com)
  TEXT w3m dump (krebsonsecurity.com)
        
       | mortenjorck wrote:
       | In this case it's actual malice, that the streaming stick is set
       | up for residential proxy and ad fraud straight from the factory.
       | But incompetence can lead to the same place if it's a poorly
       | engineered, un-maintained device with an old version of Android
       | that will never be patched and is always one no-click exploit
       | away from being commandeered into residential proxy and ad fraud.
        
         | alex_duf wrote:
         | I wonder to what degree malice can be engineered to look like
         | incompetence?
        
           | abbeyj wrote:
           | Try examining the old entries from the
           | https://en.wikipedia.org/wiki/Underhanded_C_Contest.
        
         | FinnKuhn wrote:
         | Those TV streaming boxes really are (from a cybersecurity
         | perspective) probably one of the worst things you can buy. Here
         | is the "Darknet Diaries" Episode on them:
         | https://darknetdiaries.com/episode/172/
        
           | labbett wrote:
           | Superbox 3 is coming up at DEF CON next Friday!
           | 
           | https://hackertracker.app/defcon34/content/67257
        
             | doctorspazz wrote:
             | Thank you for sharing this. The superbox investigations
             | have been incredibly interesting to follow.
        
         | frollogaston wrote:
         | Since these are poorly engineered, wonder how easy it'd be to
         | reverse-engineer one and just get the free streaming on a non-
         | scam device.
        
           | dpoloncsak wrote:
           | If it's something like a Firestick (or the knock-off featured
           | in the article), you're really just connecting to Content
           | Provider servers to handle auth and content streaming, right?
           | They're just OSes designed to run Netflix and Hulu. Would be
           | hard to spoof I think
        
             | mikepurvis wrote:
             | Indeed. Owning the streaming box lets you loose on whatever
             | network it's on, but it doesn't actually get you inside the
             | content gardens; those are separately managed by teams of
             | people much more motivated to protect their IP.
        
           | kiririn wrote:
           | See CoreELEC/LibreELEC/etc - totally replaces the
           | (potentially dodgy) Android OS on these kind of streaming
           | boxes with a stripped down Linux+Kodi setup
        
             | qmr wrote:
             | I thought those were for x86? They run on ARM TV boxes /
             | sticks now?
        
               | tesnorindian wrote:
               | LibreElec also supports ARM builds than can run on SBC
               | like Raspberry Pi. While CoreElec is exclusively for
               | Amlogic ARM processors.
        
           | wildzzz wrote:
           | Best case, you can grab the credentials off the Kodi box and
           | use them on a clean install.
           | 
           | Worst case, everything is packaged up in a single app so it's
           | all or nothing. Although you could just wipe the box and find
           | another pirate TV provider.
        
         | acdha wrote:
         | I was trying to figure out why we saw so many fraudulent
         | applications from Vietnam for a service which is restricted to
         | the United States, especially because they were all getting
         | rejected - it seemed like even the laziest spammer would lose
         | interest in something they couldn't monetize.
         | 
         | A guy in Vietnam mentioned that one of the largest ISPs there
         | used these really dodgy Chinese modems which were so
         | notoriously insecure that it was apparently common knowledge
         | that you should replace them if performance was slow because
         | that was a sign that yours was being used by a botnet.
         | Apparently the cost of access to one of those nodes was so low
         | that the spammers don't even really monitor their bots.
        
         | 8note wrote:
         | consumers are however happy to buy a cheaper stick with an
         | overall public bad
        
           | inigyou wrote:
           | I don't even think it's a public bad. I think attacking
           | internet gatekeepers like Cloudflare is objectively a public
           | good. So is attacking legal spam companies.
        
             | psd1 wrote:
             | ...ish. Attacking their monopoly, great. Attacking their
             | workers by bombing an office, not so great. Throwing ever
             | more spam traffic across the tubes isn't a attack, it's
             | marketing on their behalf.
        
               | inigyou wrote:
               | In what way is clicking an ad like bombing an office?
        
         | inigyou wrote:
         | What is the malice in those things?
        
       | glitchc wrote:
       | Defrauding ad networks doesn't seem like a bad thing, although
       | using my internet connection as a proxy is obviously terrible. It
       | wouldn't surprise me to learn that my connection is being sold as
       | a VPN service by the vendor.
        
         | alistairSH wrote:
         | It'll be a marginal effect, but fake clicks impacts the ad
         | buyer, which then impacts their financials and pricing.
         | 
         | The only winner here is the scammers running the fake affiliate
         | sites on which these sticks are "clicking". Or, am I missing
         | some facet of this enterprise?
        
           | ssl-3 wrote:
           | Another winner is the person who gets to watch cheap digital
           | TV, without putting together a usable antenna and limiting
           | their reception to the broadcast channels that are nearby.
           | 
           | I mean: They just pay the money, plug the thing in, push some
           | buttons, and: TV happens. Right?
        
             | snickerbockers wrote:
             | Theres the question of whether or not the fraudulent
             | advertisement clicking is using enough traffic to
             | inconvenience or impose fees upon the user but otherwise I
             | agree with you and am tempted to buy one just to fuck with
             | advertisers.
             | 
             | Backdoors and spying are also a problem in theory except at
             | this point you can't even trust "legitimate" companies on
             | that front so it's a moot point.
        
               | acdha wrote:
               | > otherwise I agree with you and am tempted to buy one
               | just to fuck with advertisers.
               | 
               | How that actually works in practice is that your favorite
               | sites make less money and your IP gets a bad reputation
               | so you CAPTCHAs or outright blocked. There's no "sticking
               | it to the man" here, just contributing to the frictional
               | grind making the internet worse for ordinary people.
        
               | DennisP wrote:
               | They make less money, but they also notice lower
               | conversion rates on ads, which might make them rethink
               | their strategy.
               | 
               | (IP reputation keeps me from doing it though.)
        
               | snickerbockers wrote:
               | You are drastically over-estimating how much fondness I
               | have had for the web ever since social media companies
               | and search providers colluded to drive everybody into
               | their walled-off fiefdoms.
        
               | inigyou wrote:
               | My IP changes more than once a day. If Google captchas my
               | whole ISP, good for them, hopefully it drives people away
               | from Google.
        
               | elzbardico wrote:
               | Frankly, I pay for most of the things I care about in the
               | internet nowadays. Substack, Medium, newspapers, youtube
               | premium, manning books, safari books. TV streaming.
               | 
               | The ad supported web is, with very few exceptions,
               | useless.
        
             | cryzinger wrote:
             | You really don't want fraudulent clicks ("invalid traffic",
             | per industry lingo) coming from your home network, because
             | any publishers (apps and websites, per normal-people lingo)
             | who use tools designed to block invalid traffic might start
             | flagging _legitimate_ traffic from your network.
        
               | frollogaston wrote:
               | Can confirm. I used to use Ad Nauseam (Firefox extension
               | that clicks all ads), eventually stopped when I was
               | getting captcha'd left and right.
               | 
               | Also, visitors on my wifi started getting strange ads.
               | Yes I threw off the algo, but I'm a guy with wife, I'd
               | rather get car ads than like divorce lawyers + gay dating
               | sites.
        
           | frollogaston wrote:
           | What this misses is the person buying the TV stick doesn't
           | care about the impact on the ad market. The bigger problem is
           | residential proxying, because their IP will end up getting
           | used for something bad.
        
             | hnav wrote:
             | most residential proxying these days is used by the
             | purveyors of AI
        
             | inigyou wrote:
             | And what does that cause? More captchas?
        
               | snickerbockers wrote:
               | Probably, but in the worst-case scenario you could
               | unwittingly become an accessory to a felony if the proxy
               | is used to access CSAM. Especially if the proxy ends up
               | caching files.
        
               | inigyou wrote:
               | Has that ever happened?
               | 
               | Is Mullvad an accessory to downloading CSAM if someone
               | does that?
        
           | snickerbockers wrote:
           | If all they did was shove banner ads for boner-pills in my
           | face like they used to 25 years ago I wouldn't mind and I
           | might even turn off adblock. The problem is that modern
           | advertisements on the internet are spyware at best and a
           | malware vector at worst.
           | 
           | It's arguably fraudulent to even refer to it as "advertising"
           | at this point, clearly that's just a cover to give them an
           | excuse to sell data to silicon valley corporations that are
           | unironically named after fictional devices used by sci-
           | fi/fantasy villains to manipulate people.
        
           | elzbardico wrote:
           | They can stop paying for obtrusive ads where either they make
           | everyone's life worse or get defrauded, save money using only
           | ethical advertising and use this saved money to improve the
           | quality of their products or pay their workers a little
           | better.
        
         | em-bee wrote:
         | why is running a proxy a bad thing? someone profiting off it
         | could be bad maybe, but even that is good if it pays for my
         | subscription.
         | 
         | but compare running tor nodes, and especially exit nodes. that
         | surely would be a good thing, so at least if you think tor is
         | good then running a proxy should be the same and it should be
         | normalized.
         | 
         | doing it in secret without the user knowing is what's bad
        
           | glitchc wrote:
           | Indeed _without my permission_ is implied. Without it, you
           | have no idea what traffic is being routed and could be on the
           | hook for something nasty like CSAM.
        
             | Dylan16807 wrote:
             | Those are different issues. Permission doesn't mean you
             | know what the content is, and lack of permission doesn't
             | mean they're going to load anything weird or bad. Lack of
             | permission implies worse ethics overall, but an operation
             | focused on clicking ads will be loading relatively normal
             | sites.
        
             | inigyou wrote:
             | Has that ever actually happened? Has anyone gone to court
             | for downloading child porn that was actually through a
             | residential proxy?
        
               | iamnothere wrote:
               | No. You would not be "on the hook" for this as they
               | implied. They are fearmongering. Even if a statute could
               | somehow be stretched to cover it, it would be a nightmare
               | to prosecute something like this. The media would jump
               | all over it.
        
               | inigyou wrote:
               | That's what I thought but I want to see their evidence
               | that it happens.
        
           | corbet wrote:
           | https://lwn.net/Articles/1080822/ Do you really want to be a
           | part of the scraper problem?
        
             | MrDrMcCoy wrote:
             | From the outside, I don't see the problem. The sites I
             | visit, including LWN, never seem slow or have downtime as a
             | result of this increase in traffic. I hear complaints from
             | people hosting small sites, but they never seem to include
             | concrete examples of downtime or measurably bad user
             | experience. Why does it matter if the server load is high
             | if everything stays functioning? Going from 5-20% to 60-80%
             | load hardly seems like a catastrophe to me when the
             | remaining headroom was not going to be used for anything
             | else. Having your data that's public-enough to be
             | scraped/cited/parodied/ridiculed included in a training set
             | also doesn't seem like a problem. Are they struggling to
             | pay bandwidth usage bills? Is there some actually-necessary
             | intervention required to keep things running smooth, as
             | opposed to panicking and taking unnecessary preventative
             | action?
        
           | 40four wrote:
           | Because your home IP address is going to be associated with
           | criminal activity. So if that's acceptable "payment" then I
           | guess there's no issue
        
             | inigyou wrote:
             | What concrete harm does this cause?
        
         | kube-system wrote:
         | Fraud is also bad, even if you aren't fond of those being
         | defrauded.
        
           | blackjack_ wrote:
           | Fraud that destroys market trust in a market that mostly
           | deals in surveillance and selling intrusive data that was
           | collected mostly unknowingly from the subject seems great to
           | everyone who has any amount of integrity.
        
           | pixl97 wrote:
           | So distilling an AI model of one of the big SOTA models is a
           | bad thing now?
        
           | tjpnz wrote:
           | What about all the fraud committed by the online ad industry?
        
         | ColdStream wrote:
         | They took the idea of the 'Ad-nauseam' add-on for Firefox and
         | used it for their own gains I see.
        
           | culi wrote:
           | https://adnauseam.io/
        
         | elzbardico wrote:
         | Exactly. I consider defrauding ad networks even a civic duty of
         | legitimate resistance. The issue I see with those boxes is the
         | risk of being involved in actual crimes due to the residencial
         | proxy.
        
       | skinfaxi wrote:
       | Thankfully this seems limited to a specific device (H96). Darknet
       | diaries has a good story about streaming devices
       | https://www.youtube.com/watch?v=dS6PkuZuxJ4
        
         | krebsonsecurity wrote:
         | It's not just one device line; Have a look at the list
         | maintained by the proxy tracking service Synthient, which
         | tracks streaming boxes, digital picture frames and other IoT
         | devices that have been known to bundle residential proxy
         | software, among other malicious apps. They currently track
         | almost 1,000 different makes and model numbers.
         | 
         | https://github.com/synthient/public-research/blob/main/2026/...
        
       | pavel_lishin wrote:
       | > _generic TV boxes that promise unlimited content streaming for
       | a one-time fee_
       | 
       | I don't want to blame the purchasers of these things - who are
       | some of the victims - but at the same time, it does seem like a
       | Too Good To Be True situation.
        
         | croes wrote:
         | It sounds like scam
        
         | havaloc wrote:
         | I have an elderly client who sends me links of stuff to buy all
         | the time. One day it's one of these streaming sticks, the next
         | day it's half-price stamps, and I tell her every time, please
         | don't buy this stuff. And yet she does anyway, as if I was
         | almost being mean and saying no just to say no.
         | 
         | So yes, I do want to blame the purchasers of these things,
         | sometimes. To prove her point that her stamps were legitimate,
         | she mailed me a card using one of her half priced (but likely
         | fake) stamps and it made it through!
        
           | Terr_ wrote:
           | Perhaps they grew up in a time/environment where "if it was
           | that bad they wouldn't be allowed to advertise it", and
           | they're still using that old calibration?
        
             | mhurron wrote:
             | My falther-in-law was less that and more, if I can get away
             | with it, it's actually legal. Many know their fake, and do
             | it because they can get away with it.
             | 
             | That was his justification for a satellite descrambler,
             | they're sending me the signals, obviously I'm allowed to.
        
               | mmooss wrote:
               | I can imagine many on HN having excited discussions about
               | their satellite descramblers.
               | 
               | > do it because they can get away with it.
               | 
               | Lots of people on HN download and upload copyrighted
               | materials. Is it really different?
        
               | al_borland wrote:
               | They aren't downloading that content from a company with
               | a $2.5T market cap. They presumably aren't making a
               | living by selling that copyrighted material via a retail
               | that claims to run a legitimate business.
               | 
               | I think that makes a big difference.
               | 
               | Imagine if Amazon Video, Audible, and Kindle will all
               | just pirate stores, where uploaders of the pirated
               | content made money on the downloads, people paid for
               | those downloads, and Amazon took a cut of everything. How
               | long would that go on before they were in court and that
               | was shutdown?
        
               | bityard wrote:
               | Fine, you've nerd-sniped me.
               | 
               | I tinkered with Dish Network descrambling 20 years ago.
               | Not because I wanted to just watch a bunch of free TV (I
               | hardly watched any TV anyway, we mostly watched DVDs from
               | the video store and Netflix). More because it felt like
               | an interesting rabbit hole. And it was pretty
               | interesting!
               | 
               | I picked a good (newer!) satellite dish and LNB from the
               | trash and had a friend help with the installation and
               | alignment because that was his previous job. Normal
               | people use some kind of tool to find the satellites'
               | geosynchronous orbital station in the sky, but he did it
               | often enough that he could simply look up into the sky
               | and point at them.
               | 
               | There were a handful of grey-market satellite receivers
               | you could buy that were technically capable of
               | descrambling a commercial signal. Of course, they did not
               | advertise themselves as such. They were marketed as FTA
               | (free-to-air) DVB-S receivers. These were not illegal as
               | they were fairly popular in regions of the world that
               | actually _had_ a fair amount of FTA (unscrambled)
               | satellite channels. The only satellites visible from
               | North America, however, tended to carry religious,
               | shopping, or Mexican/Central American programming. Oh,
               | and NASA TV.
               | 
               | The receiver I bought had DVR functionality if you hooked
               | up a USB drive to it. I think I still have some recorded
               | shows on it. It would have been a great way to harvest
               | and release pirated TV shows to the Internet, if you
               | didn't mind editing out all of the ads and whatever.
               | 
               | DVB-S was basically a raw MPEG-2 TS stream that could be
               | optionally encrypted. To use these grey-market receivers
               | as descramblers, you install some custom firmware
               | containing the descrambling modifications and keys. I'm
               | failing to remember the technical details, but the
               | encryption they used was not very good. Dish Network
               | would rotate the keys occasionally, and when they did,
               | you had to update them on your receiver. I can't remember
               | now if the keys were part of the firmware, but I remember
               | it being a pain in the ass.
               | 
               | The firmware/keys part of this had a very "colorful"
               | community. You had to sign up to a very specific and
               | somewhat exclusive web bulletin board in order to
               | download the firmware/keys. I don't remember how I gained
               | an account, but I remember it being non-trivial. IIRC, it
               | was like one guy maintaining the firmware/keys and
               | sometimes it took weeks for him to adapt to whatever
               | thing DN did to thwart piracy. The board was moderated by
               | a complete power-tripping asshat who enjoyed banning
               | people for fun and then gloating about it. (I was not
               | banned, that I recall.) I think they started requiring
               | "donations" in order to view certain threads (like
               | firmware releases) after a while. But I could be
               | misremembering that. I just remember the community was
               | very toxic.
               | 
               | After a few months of this setup, DN figured out how to
               | rotate their keys too often for the casual pirate to keep
               | up. I disconnected mine around that time and moved onto
               | other things. Partly because the experiment ran its
               | course and partly because migrating to real-time key
               | updates would have meant buying a newer receiver. For a
               | while, I flirted with the idea of getting a DVB-T PCI
               | receiver card and working on breaking the encryption
               | myself, but it was quite a bit above my skill level at
               | the time and there did not seem to be anyone else working
               | on it out in the open, since the DMCA was still pretty
               | new then.
        
               | wildzzz wrote:
               | Your experience describes lots of the kinds of
               | communities you can use to access pirated media. You
               | either pay for the legit service, pay for pirate
               | streaming services, pay with your privacy with the free,
               | dodgy pirate streaming services, or pay with your sanity
               | in dealing with nutjobs.
        
               | Scoundreller wrote:
               | I recall the "free to air" receivers being pretty easy to
               | configure. My main pita was getting a cheap ftdi
               | usb->serial adapter because that's how old the underlying
               | tech was. Still easier than jtagging an official
               | receiver.
               | 
               | I migrated into it from the earlier days involving
               | iso7816 card programming and mitm cards so I guess I
               | didn't have trouble finding which sites to get the fta
               | files. I have good memories of those places being quite
               | welcoming if you did your reading but sometimes
               | ephemeral. Plenty of freeware (but sometimes delayed
               | access). But part of the "payment model" was sevurity
               | vendors trying to destroy their competitors or sell more
               | countermeasures and card swaps to their satellite tv
               | broadcast clients (!!!).
               | 
               | A card swap (and some prosecutions on the nudge nudge
               | "free to air receiver" importers) put an end to most of
               | it unless you went to internet-key-sharing systems where
               | I guess the shared keys come from a handful of slave
               | receivers somewhere. Given the 2-way nature of those key
               | "subscriptions" and network connections required, I could
               | (moreso) understand the paranoia of the operators.
               | 
               | Broadband penetration ultimately killed sat cracking,
               | Netflix et al too. Oh, and what people usually call
               | "iptv".
        
               | kotaKat wrote:
               | Yep. Gone are the days of running out for a "119 IKS" or
               | hunting for Bev and Charlie, now everyone just grabs some
               | pooched RTSP feeds and calls it a day.
               | 
               | Feels fitting recently to discover the Dish Network
               | "Pirate TV" recordings. I should run my own in-home IPTV
               | station and use the Pirate TV bug as the logo...
               | 
               | https://www.youtube.com/watch?v=zVXSxJ357pw
               | 
               |  _You 're watching Dish Network's Pirate TV channel!...
               | ... if you're watching me, you're a SATELLITE PIRATE!_
        
               | brewdad wrote:
               | There's an old Carlin joke about "If a cop didn't see it,
               | I didn't do it."
        
             | Pxtl wrote:
             | Of course, what they're missing is that laws are for poor
             | people.
             | 
             | Amazon will be notified they sold something illegal and
             | will take it down and ban the seller who will immediately
             | launch a new store under a new name.
             | 
             | The purchaser, on the other hand, will be fully liable for
             | whatever horrible thing they bought.
        
             | iamben wrote:
             | I think that's a default for a lot of the older (and some
             | of the younger!) generation, same goes for news and media.
             | They grew up in a time where there was a practical barrier
             | to publishing and (largely) laws behind you doing it.
             | 
             | So they trust literally everything they read. I still don't
             | think my folks can fathom you can spin up a very real
             | looking newspaper website with fake articles in about 10
             | minutes.
        
               | mmooss wrote:
               | I find younger people are more likely to trust whatever
               | they read - social media rumors, LLM output, Reddit
               | threads - and older people looking for credible sources.
        
               | brewdad wrote:
               | When my kid was young I set up a basic web server and
               | taught him how to make a VERY basic web page. I let him
               | write whatever nonsense he wanted to and then we made it
               | live.
               | 
               | It was both a gateway into learning how the web works but
               | also that literally anyone can post anything to the
               | internet and it doesn't make it true. I like to think
               | he's more savvy than many of his peers but we all have
               | our blind spots.
        
               | doctorspazz wrote:
               | was the url for the website you set up for him
               | www.creedthoughts.gov.www\creedthoughts
        
               | CM30 wrote:
               | Honestly, my experience is that it's less age specific
               | and more like 80-90% of the general public. A lot of
               | people just can't recognise the difference between a
               | credible source and a dubious/fake one, and will just
               | share any old random page or social media post they come
               | across online. Heck, the number of people I know that see
               | things like ChatGPT as some magic encyclopedia/sage that
               | knows everything is depressingly high...
        
             | rrr_oh_man wrote:
             | > time/environment where "if it was that bad they wouldn't
             | be allowed to advertise it"
             | 
             | like cigarettes?
        
               | magicalhippo wrote:
               | Or heroin[1]?
               | 
               | [1]: https://museum.dea.gov/museum-collection/collection-
               | spotligh...
        
             | dfxm12 wrote:
             | I doubt there ever was a time/environment. Snake oil has
             | been around consistently for a very long time.
        
           | Scroll_Swe wrote:
           | Then again I used to torrent everything under the sun and it
           | actually rocks to have every tv show, movie, game ever
           | released for free forever.
           | 
           | So is it greed? Yes, but I did it too so now that its more
           | accessible I cannot really blame people.
        
           | floam wrote:
           | Half priced stamps _work_ though, and nobody is going to
           | prosecute grandma for counterfeiting postage stamps.
        
             | zeafoamrun wrote:
             | Yes they do. USPIS does not f around
        
               | Pxtl wrote:
               | Oddly they don't ever seem to prosecute the sites that
               | profit from selling them. Funny, that.
        
               | kube-system wrote:
               | Makes sense to me, the only place I've ever seen them
               | personally advertised are overseas websites.
        
               | Terr_ wrote:
               | It doesn't seem too weird to me: Selling someone fake
               | stamps is a general act of fraud, between buyer and
               | seller, and would be pursued by state/federal attorneys
               | general.
               | 
               | The USPS becomes directly involved only later, when
               | someone tries to defraud _them_ by using a fake stamp.
        
           | mmooss wrote:
           | > half-price stamps
           | 
           | Who is selling half-price stamps?
           | 
           | #1 How big is your potential market? It's people still
           | mailing things from home, who haven't figured out how to do
           | postage on their computer.
           | 
           | #2 Of the population in #1, it's those who find real stamps
           | so expensive that it's worth bothering with discounts.
           | 
           | #3 Of the population in #2, it's those who would want to buy
           | something fraudulant (or not know better) and who would want
           | to risk using it.
           | 
           | #4 Considering the size of the #3 population, how many stamps
           | do they use in a month?
           | 
           | #5 What is your margin on a half-price stamp? You have to pay
           | for advertising, printing (we're talking a profit margin
           | under $1), packaging, and your own time, but at least
           | shipping is free!
        
             | wildzzz wrote:
             | Its the grandmas still sending you a $5 check in the mail
             | for your birthday
        
               | mmooss wrote:
               | How can those few people - and again narrowed down to the
               | population mailing letters AND needing stamps AND seeking
               | discounts AND willing or ignorant enough to do/risk fraud
               | - with that little revenue per item, make a half-price
               | stamp operation worthwhile?
        
           | rrr_oh_man wrote:
           | What is your line of work, if I may ask?
        
           | _carbyau_ wrote:
           | What is the world view (aka context) of this little old lady?
           | 
           | Watch the news and see CEO's with golden handshakes after the
           | company is nailed for something. Wall street failures.
           | Companies getting government bailouts. The current US
           | president. It is _all_ about getting away with what you can.
           | 
           | The news - being the news - doesn't show process as per
           | normal. People doing the right thing most of the time.
           | 
           | In this context, fake stamps for the "little person" doesn't
           | even rate a mention. Who the hell is going to raise a moral
           | panic about an old lady with fake stamps...
           | 
           | And so the "little people" will keep buying fake whatevers as
           | long as it stretches their dollar further.
        
         | nvme0n1p1 wrote:
         | OTOH - TV, radio, and YouTube are all unlimited and free. Why
         | not streaming?
         | 
         | There are lots of people alive who grew up during the days of
         | broadcast TV and radio. I get why they might not understand the
         | difference.
        
           | weberer wrote:
           | There are a ton of legitimately free IPTV streams. You can
           | watch them through most media players like VLC without having
           | to download anything shady.
           | 
           | https://github.com/iptv-org/iptv
        
             | nuxi wrote:
             | Two things:
             | 
             | - How are these "legitimately free"? For example AMC is a
             | commercial TV channel and as far as I know, they don't
             | offer free streaming. Same goes for MGM, FilmBox etc.
             | 
             | - Strictly speaking this isn't IPTV, it's just web streams.
             | IPTV is usually delivered via multicast (MPEG-TS/RTP/RTSP
             | streams, over UDP mostly).
        
             | nvme0n1p1 wrote:
             | Ok but have fun explaining that to the average person.
             | Buying a dongle is easier than installing software or
             | typing URLs into their TV ("my TV doesn't even have a
             | keyboard").
             | 
             | To most people IPTV is a bunch of gibberish letters,
             | indistinguishable from the gibberish brands on Amazon.
             | Someone's grandma from Colorado doesn't deserve to get
             | scammed because she didn't research the acronyms.
        
             | kube-system wrote:
             | That is chock-full of pirated content.
        
               | crote wrote:
               | Most of it seems to be first-party streams of content
               | which is also available as unencrypted over-the-air
               | broadcasts.
               | 
               | It is paid for via ads or subsidies, so there's no reason
               | to block access to the stream, so they just _don 't
               | bother_, and make life easier for anyone building
               | streaming devices wanting to integrate their channel.
               | 
               | Someone accessing the stream directly is not the
               | originally intended use case, but it isn't any different
               | from someone accessing it via their smart tv.
        
           | bluedino wrote:
           | Most people who buy these want to watch free movies, sports
           | streams, etc that aren't on OTA or free services
        
             | Scoundreller wrote:
             | Or straight up unavailable on paid services. There's often
             | no way to legitimately subscribe to programming from
             | $HomeCountry, especially if you're not in a big Diaspora
             | country.
        
         | fred_is_fred wrote:
         | If you offered most people free streaming for a $37 USB stick
         | but directly told them it would be faking ad clicks when the TV
         | is off, would any of them really care?
        
           | 1970-01-01 wrote:
           | No, and that's is the root of the problem. The buyer is happy
           | and so is the seller. They don't care to understand what
           | they're allowing and everyone is allowing it to happen.
        
             | GolfPopper wrote:
             | They're just meeting the standards American society has
             | set.
        
             | bayarearefugee wrote:
             | I wouldn't use a device like this for a lot of reasons, but
             | the fact that what they are doing might be taking advantage
             | of the incredibly predatory digital advertising system is
             | neutral to positive for me, if I'm being fully honest.
             | 
             | If they were using the system to rip off random people, I'd
             | be 100% against it, if they are fucking Google and the
             | giant corps that advertise with them, ehh.. not my problem
             | and can't be assed to care. Google is not a positive force
             | in the world. Hasn't been for many years.
        
               | mschild wrote:
               | Wouldn't this ultimately make money FOR Google and only
               | cost money to the company that placed the ad?
               | 
               | Sure, Google's paying but they get their money
               | regardless.
        
               | chowells wrote:
               | It might damage Google's reputation with advertisers in
               | the long term. I'm not convinced Google would even care
               | about it, given their other behavior.
        
               | inigyou wrote:
               | Proctor & Gamble did an experiment: they cancelled all of
               | their online advertising and watched their sales numbers.
               | Sales didn't change. That sort of thing is downstream of
               | this sort of thing. Online advertising is a money black
               | hole, a sacrifice to the gods. It doesn't really do
               | anything.
        
               | crote wrote:
               | It reduces the value of their ads.
               | 
               | Let's say you are an ad buyer. Previously 1M clicks
               | resulted in 1000 sales, now 2M clicks result in the same
               | 1000 sales. If you previously paid $1000 for 1M clicks,
               | you paid $1/sale. If they are now asking you to pay the
               | same $1000 / M clicks you'd be paying $2/sale, so Google
               | would have to drop to $500 / M clicks to offer the same
               | value to advertisers.
               | 
               | But the same applies to ad _sellers_ as well. Google
               | would have to slash payouts to websites displaying ads by
               | the same 50%  / click or they'd be cutting into their
               | margins. A competing ad platform _without_ fraudulent
               | clicks would be able to slide into this space, offering
               | both a better value to ad buyers and a better payout to
               | ad sellers, so they 'd be taking market share from Google
               | without having to do anything themselves.
               | 
               | Of course that assumes a market in which the value of ad
               | clicks, views, and placements is clear to everyone and
               | switching between ad platforms is trivial, which is not
               | even _remotely_ the case.
        
               | wildzzz wrote:
               | Sure but for the ad network, it means they can brag to
               | new clients about how many clicks they can get them. If
               | the ad clicker isn't buying, that's the client's problem,
               | you already did your job by getting them to click. Maybe
               | the client needs a more direct campaign (which costs
               | more) or needs to change their website/prices, people are
               | walking into the store but they just aren't buying.
               | 
               | Its either the ad network running these click botnets or
               | contracting someone to do it. If it was just impressions
               | getting boosted, that just looks shady, those are barely
               | worth anything.
        
             | pessimizer wrote:
             | > They don't care to understand what they're allowing
             | 
             | If you told normal people that they could get free content
             | with a TV streaming stick that would also constantly fake
             | clicks on AI generated websites to screw advertisers over,
             | they would think of it as a bonus. Also it would make them
             | trust the stick _more_ (fallaciously), because they would
             | know how the people who sold it were getting paid.
        
             | inigyou wrote:
             | And why should they care? There is literally no reason they
             | should care, it does not affect them in any way, if it
             | causes ad companies to ban their IP address that's actually
             | good for them personally, and most people outside of the ad
             | business would agree that hurting ad companies is good.
        
           | ajnin wrote:
           | Maybe they wouldn't care about the ads but the residential
           | proxy is another story. I'm sure lots of problematic stuff
           | goes through that and you take the risk of being associated
           | with it.
        
             | inigyou wrote:
             | Not really. Has anyone ever got in trouble for this?
        
           | tomjen3 wrote:
           | There are probably quite a few others who consider that a
           | bonus. I'm not going to support illegal actions, but it's
           | also not one of the things I would really lose sleep over if
           | I found out that it have been doing that.
        
         | flerchin wrote:
         | Well now I want one
        
           | Cider9986 wrote:
           | Stremio+TorBox are the two words. ($3/month)
        
             | ghostly_s wrote:
             | That's not what these things are. They come preloaded with
             | apps that stream pirate broadcast streams and on-demand
             | servers operated out of China.
        
               | Cider9986 wrote:
               | Absolutely correct. My comment intention was if you want
               | to make one yourself and get the experience of all shows
               | +movies.
        
               | ghostly_s wrote:
               | Did OP say "I want something vaguely similar that
               | requires a greater investment of my time and money"? Did
               | you in any way indicate that's what you were proposing?
        
         | iugtmkbdfil834 wrote:
         | Uhh, I have an extended family member, who not only uses it,
         | but now also tries to get other people to get into it. Since I
         | was familiar with this practice ( and the issues it makes worse
         | ), I noted those to him in an attempt to both politely decline
         | and, hopefully, spare him, and society, some future problems.
         | Without going into any identifying details, he didn't take it
         | well ( and I don't think I got on my high horse ).
         | 
         | Anyway, I think some level of blame is warranted.
        
           | chihuahua wrote:
           | According to the Darknet Diaries podcast episode "Superbox",
           | some of these devices are sold via multi-level marketing
           | schemes, which would explain why there are random individuals
           | selling these, collecting a commission for each device sold.
           | Which is why the person you mentioned is unhappy when someone
           | points out the problems with these devices.
        
         | Cider9986 wrote:
         | It could be possible, I haven't done the math though.
         | 
         | Stremio +Torbox is $3/month and they can probably share 10+
         | households on one TorBox account so it could work out. The
         | seller could just stop paying the TorBox subscription at
         | whatever point and they have an incentive to do so.
        
         | IncreasePosts wrote:
         | Maybe, but if they're a not-very-tech savvy older person buying
         | this, they probably remember shows being free from over the air
         | antennas and may think it is something like that.
        
           | ghostly_s wrote:
           | > they probably remember shows being free from over the air
           | antennas
           | 
           | you are aware broadcast TV never ended?
        
             | IncreasePosts wrote:
             | Yes, in fact I have an antenna and a HDHomeRun nestled in
             | my attic to record over the air shows that I occasionally
             | consume.
             | 
             | But, I think it's far more common for people to have a TV
             | service today, perhaps since comcast and their ilk push
             | hard the TV/phone/internet bundle, and gone are the years
             | when everyone would fiddle with the antennas on the back of
             | their TV to get the right reception.
        
             | myself248 wrote:
             | An awful, awful, _awful_ lot of consumers think their old
             | antennas don 't work now that everything's gone digital.
             | And they've simply never tried.
        
           | bdangubic wrote:
           | I watch TV over an antenna, shows are free still
        
         | rng-concern wrote:
         | I know a few people who buy these, and they kind of know what
         | they're doing. They just try and not think about it too hard.
         | 
         | It reminds me of the saying: "It Is Difficult to Get a Man to
         | Understand Something When His Salary Depends Upon His Not
         | Understanding It".
         | 
         | If these people thought about it for a few minutes, they would
         | understand, but they choose not to, as ignoring it is too
         | advantageous.
         | 
         | I admit I was tempted, as the price of all streaming services
         | goes up, and services become more and more fragmented. During
         | the same period where I have not had a raise.
        
           | acdha wrote:
           | In the 90s, there was a cottage industry selling CDs of
           | bootleg software at swap meets and flea markets. A guy my dad
           | knew was almost condescending to anyone who paid for software
           | despite having been hit by viruses multiple times because it
           | was so much cheaper. Even having to deal with a client(!) who
           | naively called the vendor support only to be informed that
           | they hadn't actually purchased a license wasn't enough to get
           | him to resist that savings.
        
           | inigyou wrote:
           | On what grounds would they choose not to?
        
             | rng-concern wrote:
             | I won't argue the ethics of piracy. That was not my point,
             | but if you want to I suppose I could.
             | 
             | My point was, their ethics WOULD have prevented them from
             | doing the thing. But they chose not to think about it too
             | hard. Perhaps subconsciously. I'm not above doing this sort
             | of thing either. We all do it for various things.
             | 
             | I've added code that is bad for the user (overbearing
             | telemetry for instance) because my salary depended on it.
             | At the time I tried not to think about it too much, as it
             | would cause cognitive dissonance.
        
         | paultopia wrote:
         | Yeah, isn't this a classic kind of scam the would-be scammer
         | situation? If you think there's some way to buy one cheap
         | device and somehow get around subscribing to streaming
         | services[1], then of course you're going to be in a market with
         | fraudsters...
         | 
         | [1] Can someone explain what the theory of the product is here?
         | It sounds like they're marketing these things as ways for the
         | customer to commit fraud, for example by connecting to someone
         | else's login. How else would the customer expect to be able to
         | get free Netflix or whatever?
        
           | chihuahua wrote:
           | It may be the case that these devices are front-ends for
           | pirated content that's hosted in various places. They're not
           | streaming it from Netflix servers. It's content similar to
           | that offered by Netflix and other streaming services, pirated
           | by someone else, and hosted by someone else for streaming by
           | anyone who can figure out how to find it.
        
         | varispeed wrote:
         | I used to know someone doing this. They said they know it is
         | too good to be true, but they hate corporations and it's their
         | little way to stick one in.
        
         | pibaker wrote:
         | > it does seem like a Too Good To Be True situation
         | 
         | It's difficult to judge the price of media products. We have
         | legal music streaming services that charges you an album's
         | worth of money a month and lets you listen to millions of
         | songs. You can pick up old AAA games for less than ten bucks.
         | I'd say when people say that price tag, they don't think they
         | get scammed into being a part of a botnet. They think the
         | device manufacturer cut a good deal with the media rights
         | holders.
        
         | al_borland wrote:
         | Why should anyone assume a product being sold by (or at least
         | on) Amazon, the latest retailer in the country, is an illegal
         | device?
         | 
         | It's not like they're buying these things out of a car trunk in
         | a dark alley. These retailers need to be held liable for
         | selling these things. If they sell this stuff, why not illicit
         | drugs?
         | 
         | If they are unable to maintain control of 3rd party sellers,
         | then they should end the 3rd party seller program. It has done
         | nothing but damage Amazon's reputation, and it just keeps
         | getting worse.
        
         | Tangurena2 wrote:
         | The streaming services have fractured and taken so many movies
         | off their service so much that it is too hard for most people
         | to figure out where that show/movie can be found.
         | 
         | From a link above to the story on darknetdiaries:
         | 
         | > _For Pokemon, there is a website that tells you how to watch
         | this. You start off on Netflix, then swap over to the Pokemon
         | streaming service, which is the only place that has Season 2,
         | then swap over to Prime Video for Seasons 3 through 5, swap to
         | Freevee, then Hoopla. Season 13 is only on Amazon, though. Then
         | swap to Tubi, then Hulu, then Roku channel, and then finally
         | back to the Pokemon streaming, and then Netflix. Easy._
         | 
         | That's 8 different streaming services to view one series.
        
           | tomaskafka wrote:
           | And yet they can all be comfortably watched at a single
           | place, with high quality and no ads.
        
         | joshmn wrote:
         | I had a streaming piracy site that I went to federal prison
         | for. I can chime in on these people.
         | 
         | It's worth separating the two populations:
         | 
         | My users had money and had considered legal subscriptions. They
         | paid me because the legal product was worse--in my case, sports
         | blackouts, a bunch of different apps, etc. They knew what they
         | were buying into and they had weighed the risk. I can tell you
         | right now some of my former users have bought into this market.
         | 
         | Then there's the unwitting: a person buying one of these
         | devices at a too-good-to-be-true price is treating it as a
         | hardware purchase from Amazon, where the actual monetization
         | isn't inferable from the listing. Calling it too good to be
         | true assumes the buyer can see what shit they're standing in.
         | They can't. There's no visible market here. It's just a product
         | page with reviews.
         | 
         | To add to this: the proxy exit is exactly why these cost so
         | little. Demand for residential IPs is booming (check some of
         | the proxy subreddits to see what I mean).
         | 
         | The ironic part is that there's a chance the person who bought
         | one of these boxes to watch pirated sports was the exit node I
         | was using to acquire the feeds in the first place.
        
         | elzbardico wrote:
         | I don't care about free streaming. But fucking advertisers?
         | Humm... just found a reason to buy one of those boxes.
        
       | giraffe_lady wrote:
       | > allowing low-skilled operators to drag blocks of code together
       | in their editor -- without any need to understand what the
       | underlying code blocks do or how they work.
       | 
       | We're called engineers brian.
        
       | cryo32 wrote:
       | A better solution is just leech the content and stick it on a
       | generic USB flash stick.
        
         | harvey9 wrote:
         | These are popular for illegal live sports streams.
        
           | cryo32 wrote:
           | I just go down the pub.
        
       | j45 wrote:
       | Generally, it's advisable to create a dedicated wifi network for
       | all potentially hostile devices.
       | 
       | This dedicated wifi network can just be connecting your devices
       | to your guest wifi while you figure it out, and limiting the rate
       | of speed as needed.
       | 
       | That can be cameras, tv's, thermostats, tv sticks and anything
       | else that might not only call home, but actively scope what you
       | have in your home network when it's none of it's business.
        
         | spelk wrote:
         | I don't think this would make a big difference for the threat
         | model described in the OP? They'd still be able to use your IP
         | Address and potentially do nefarious things through your role
         | as an unwitting proxy.
        
           | j45 wrote:
           | Using one device as a proxy is a few steps away from trying
           | to exploit and infiltrate the other devices on your machine
           | as well. An unwitting proxy is already crossing the line to
           | putting a fox in the henhouse.
           | 
           | Limiting what outbound access devices can/can't have is an
           | important skill to learn.
        
         | drnick1 wrote:
         | > That can be cameras, tv's, thermostats, tv sticks and
         | anything else that might not only call home
         | 
         | That is not enough. You need to air gap devices that have
         | legitimately no business communicating with anyone or anything
         | outside the house. TVs, thermostats, and other Internet-of-Crap
         | gadgets do not need "firmware updates." Either they work out of
         | the box, offline or within the LAN, or they get sent back for a
         | refund wherever they came from.
        
           | j45 wrote:
           | Agreed. That usually comes as a step after getting these
           | items on a separate SSID.
        
       | giantg2 wrote:
       | So where can I get an actual privacy focused streaming box, even
       | if the apps (Neflix etc) running on it are not?
        
         | cogman10 wrote:
         | I'm increasingly being convinced the only way to do that is you
         | do a media pc nuc. The problem, of course, is you probably
         | won't have the netflix app. It's painful to setup such a box to
         | stream from various services.
        
           | mbmbn wrote:
           | I tried going that route, but most apps for streaming are
           | Android. And that was only one of the issues.
           | 
           | It was a rabbit hole and in the end I got back using my
           | NVIDIA Shield. This is about 10 years now, but it's actually
           | still the best option.
        
           | Tepix wrote:
           | What's wrong with Apple TV? It runs VLC if you want to stream
           | something from your NAS.
        
           | giantg2 wrote:
           | I tried to look at setting up an stripped down privacy-
           | focused Android based box for Netflix, but ran into issues.
           | Seems like you need to be spied on to run Netflix.
        
           | dwaltrip wrote:
           | What about just using the Netflix desktop website? Or does
           | that limit the resolution?
        
         | MattTheRealOne wrote:
         | Apple TV is currently the best balance of privacy and
         | convenience. The only way to get more private is using a PC,
         | but that limits the resolution for most streaming services to
         | 720p or 1080p.
        
           | theshrike79 wrote:
           | And longevity. It just keeps getting updated tvOS versions
           | and every provider's apps keep working - unlike on random
           | Android TVs that just fall out of support.
           | 
           | I'm on my second one and I've owned them since the first
           | version. My current one is the first generation 4k that's ...
           | seven years old? Still works like new.
        
         | PcChip wrote:
         | I assume apple TV doesn't do malicious things like this, and we
         | love the interface and it "just works" with HDR
        
         | ghostly_s wrote:
         | These are not "streaming boxes" in the sense you are talking
         | about. Their appeal is that they come preloaded with chinese
         | pirate streaming apps. Traditional streaming boxes - Apple TV,
         | Fire stick, Roku - are not affected by this, though if you want
         | privacy-focused Apple TV is the only remaining contender, and
         | with Apple's continued descent into advertising vendor I'd
         | guess that one is not long for this world, either.
        
           | giantg2 wrote:
           | My understanding is that Roku bypasses DNS blocking with
           | hardcoded tables so it can report back on various data they
           | track on you.
        
             | timbit42 wrote:
             | Can you monitor its traffic and block by IP?
        
               | giantg2 wrote:
               | I probably could, but haven't done so yet.
        
               | mikestew wrote:
               | I'm sure you could. At what point do you just rip out the
               | thing that is trying so hard to work around _your_
               | control of _your_ network? An Apple TV doesn't cost that
               | much.
        
               | kube-system wrote:
               | The door is slowly closing on all of these blocking
               | schemes by moving ad content to the same domains as the
               | primary content.
               | 
               | This is already a common feature for analytics toolkits.
        
             | autoexec wrote:
             | Roku collects an insane amount of data on users. Basically
             | everything that they can get their hands on
             | 
             | > Roughly twice per second, a Roku TV captures video
             | "snapshots" in 4K resolution. These snapshots are scanned
             | through a database of content and ads, which allows the
             | exposure to be matched to what is airing. For example, if a
             | streamer is watching an NFL football game and sees an ad
             | for a hard seltzer, Roku's ACR will know that the ad has
             | appeared on the TV being watched at that time. In this way,
             | the content on screen is automatically recognized, as the
             | technology's name indicates. The data then is paired with
             | user profile data to link the account watching with the
             | content they're watching.
             | https://advertising.roku.com/learn/resources/acr-the-
             | future-...
        
         | noboostforyou wrote:
         | Besides setting up your own device, Apple TV would be the best
         | bet from any of the large manufacturers.
        
         | Pxtl wrote:
         | kodi on an rpi5?
        
         | drnick1 wrote:
         | If you want actual privacy (rather than promises from Apple or
         | Google), what you need is a mini-PC running Linux with the
         | Plasma Bigscreen DE. You then use a Web browser rather than
         | invasive "apps" for your streaming. For Youtube, there is
         | VacuumTube (an improved Youtube Leanback client). The main
         | limitation is capped resolution on some commercial streaming
         | services. I believe Windows does not have that restriction, so
         | a VM could presumably be used for streaming (I have not tried).
        
         | knowaveragejoe wrote:
         | The Onn TV devices from walmart seem fine, baseline google
         | tracking not-withstanding... but no residential proxy or botnet
         | participation without you knowing! You can just block them at
         | the router and stream content locally.
        
       | m3047 wrote:
       | Brazil. Last year I effectively blocked Brazil for a while.
       | Ultimately I settled on three possibilities for the traffic I was
       | seeing:
       | 
       | 01: DDOS
       | 
       | 10: Residential proxies
       | 
       | 11: Somebody DDOSing residential proxies
        
         | drdexebtjl wrote:
         | I can't prove it, but I live in Brazil and after getting a
         | smart TV from LG, I started receiving challenges across all
         | Google services, indicating they received bot traffic from my
         | network. I only used apps from streaming services I actually
         | paid for.
         | 
         | I suspect these TVs either come with residential proxies set up
         | from the factory, or they have such poor security that they're
         | instantly hacked. Either way, TV manufacturers (including
         | reputable ones like LG) are to blame.
        
           | mikestew wrote:
           | There have been articles lately about the residential proxies
           | loaded in apps for LG TVs. My LG has never seen a network
           | connection, so I'm fuzzy on details.
        
           | inigyou wrote:
           | LG has been in the news just this week for a whole lot of
           | shady practices, which cast light on their other shady
           | practices. Yes, residential proxying is one of them.
           | 
           | I don't think residential proxying is all _that_ shady since
           | groups like Cloudflare have made it a necessity. However,
           | having it out-of-the-box on a name-brand device is extremely
           | shady.
        
       | codedokode wrote:
       | I do not see problems with fake ad clicks and have no sympathy
       | for ad companies.
       | 
       | Also pre-installed adware is not a surprise, I found adware in
       | the official firmware image of a certain Chinese tablet.
       | 
       | What worries me much more is backdoors from the foreign companies
       | and governments that can be pre-installed at the factory to
       | collect intelligence information. For example, I became aware
       | that a certain maker of a popular mobile OS was collecting the
       | cell tower IDs and WiFi access point identifiers along with GPS
       | coordinates of a device. Obviously they collect this information
       | to be able to guide missiles and drones when GPS signal is jammed
       | (GPS is very low power and easy to jam). This is not acceptable.
       | 
       | How can we prevent this? I think, for every imported device
       | having a CPU and Internet connectivity:
       | 
       | - the user must be able to re-flash firmware with their own code.
       | 
       | - the local government must have access to the full source code
       | and be able to search for vulnerabilities or backdoors, including
       | using AI tools. Found vulnerabilities are considered a reward and
       | may be used against countries not doing inspections. No access -
       | no import permission.
       | 
       | - any telemetry or data collection, or updates must be opt-in
       | only and disabled by default.
       | 
       | - any telemetry or updates must go through a server controlled by
       | the local government, in unencrypted form, to detect attempts to
       | collect intelligence information or install malicious update.
       | 
       | Sadly our government instead only demands that manufacturers pre-
       | install their closed-source software on all imported devices and
       | that's all.
        
         | BoppreH wrote:
         | > a certain maker of a popular mobile OS was collecting the
         | cell tower IDs and WiFi access point identifiers along with GPS
         | coordinates of a device. Obviously they collect this
         | information to be able to guide missiles and drones when GPS
         | signal is jammed
         | 
         | Is this sarcasm? GPS can take several minutes to get a
         | location, and works poorly indoors. One of the reasons why
         | Google Maps is so quick and precise is because Google has
         | gathered exactly this data through users and Street View drive-
         | bys.
         | 
         |  _Could_ it be used for missiles? Sure. Is it _obviously_ the
         | intention? No.
        
           | meatmanek wrote:
           | Yeah this is extremely standard:
           | 
           | Apple: https://support.apple.com/en-us/102515
           | 
           | > If Location Services is on, your device will periodically
           | send the geo-tagged locations of nearby Wi-Fi hotspots and
           | cell towers to Apple to augment Apple's crowd-sourced
           | database of Wi-Fi hotspot and cell tower locations.
           | 
           | Google: https://support.google.com/android/answer/15157297?sj
           | id=1648...
           | 
           | > When Location Accuracy is on, Google periodically collects
           | information about the locations of wireless signals and
           | sensors observed by your device to crowdsource location
           | estimates. This helps everyone find locations better.
           | 
           | Mozilla used to run a very similar service:
           | https://en.wikipedia.org/wiki/Mozilla_Location_Service
           | 
           | Not to mention truly crowd-sourced databases like wigle.net.
        
             | codedokode wrote:
             | They should ask the permission from device owner and local
             | government before collecting the data.
        
               | aeturnum wrote:
               | They do ask the device owner - if you review the location
               | services description on android[1] you will see they
               | explicitly say they collect this information from your
               | device. I strongly disagree that they need to get
               | government permission for this - they are simply
               | recording signals that reach the device, akin to making
               | notes about what kinds of cars you see. This is not a
               | thing a government should have control over people doing
               | and not a thing that should be registered with the
               | governement.
               | 
               | [1] https://support.google.com/android/answer/3467281?sji
               | d=66634...
        
               | codedokode wrote:
               | In the article you refer to, I see no mention of asking
               | user's permission. However, I remember, when using an old
               | version of Android, there indeed was a popup nagging me
               | to allow sharing location data with Google every time I
               | enabled GPS. Very annoying, makes you want to never
               | enable GPS in the first place.
               | 
               | Regarding the government, the problem is that many people
               | do not fully understand the mechanism of collecting the
               | data. I remember the case when members of US military
               | disclosed the location of secret objects through fitness
               | tracker app. And they were probably smarter than average
               | smartphone user. Obviously it would be better if enabling
               | GPS required an approval from their commander.
        
               | aeturnum wrote:
               | I suppose they don't "ask you" in the same way that gmail
               | never presents the user with a dialog explaining that
               | gmail needs to store their emails in order to provide
               | their email service. Instead they explain how the
               | location service works and you can decide if you want to
               | enable or disable it.
               | 
               | I'll agree that militaries would prefer their soldiers to
               | not to dumb things - but I don't agree that it's
               | 'obviously' best if people needed permission to enable
               | GPS! If that's the case depends a lot on which soldier is
               | enabling the GPS and their relation to me. In general I
               | would say that government control of people recording and
               | distributing their observations is associated with the
               | most authoritarian governments and by claiming we should
               | get government permission you appear to be aligning
               | yourself with an authoritarian approach to data controls.
        
           | codedokode wrote:
           | Should Google ask permission from the device owner, and from
           | the local government before collecting the data? I heard a
           | certain foreign mobile app was banned in US for doing less
           | than that.
        
         | pavel_lishin wrote:
         | > _Obviously they collect this information to be able to guide
         | missiles and drones when GPS signal is jammed_
         | 
         | Are there a lot of missiles that travel slowly enough to be
         | able to guide themselves via watching for nearby wifi signals?
         | 
         | > _for every imported device having a CPU and Internet
         | connectivity_
         | 
         | Why limit this to imported devices?
        
           | palmotea wrote:
           | >> Obviously they collect this information to be able to
           | guide missiles and drones when GPS signal is jammed
           | 
           | > Are there a lot of missiles that travel slowly enough to be
           | able to guide themselves via watching for nearby wifi
           | signals?
           | 
           | Cheap, slow-moving drones are the hot new missiles on the
           | battlefield of today. This often talked-about model files at
           | 115 mph (https://en.wikipedia.org/wiki/HESA_Shahed_136).
        
           | bee_rider wrote:
           | I think that might have been semi-sarcastic. I mean, there
           | are lots of reasons to do this sort of thing, some are bad,
           | some are not so bad, most are not war.
        
           | codedokode wrote:
           | In some areas GPS is spoofed and the displayed location is
           | wrong. If, for example, a "smart" car gets a task from its
           | manufacturer to film some secret object, it would fail if it
           | relied only on GPS and did not use cell towers and WiFi
           | points for determining its location. So knowing their
           | location determines whether the mission would fail or
           | succeed. So foreign devices should not be allowed to collect
           | such information.
        
         | IncreasePosts wrote:
         | Fake ad clicks cost the advertiser money, not the ad company.
         | 
         | Ad companies generally try to detect fake clicks, but any fake
         | clicks that get through just earn money for the ad company (at
         | the cost of making the advertisers campaign have a lower ROI)
        
           | mcphage wrote:
           | > Fake ad clicks cost the advertiser money, not the ad
           | company.
           | 
           | It also diminishes the value of the clicks provided by the ad
           | company. It doesn't cost them dollars directly, but makes all
           | their advertising worth less.
        
           | codedokode wrote:
           | Good products do not need much advertising. For example, when
           | buying DRAM, I compare the specification and prices and do
           | not look at the advertisement.
        
         | Thrymr wrote:
         | > I do not see problems with fake ad clicks and have no
         | sympathy for ad companies.
         | 
         | I am not shedding any tears for the ad companies, but I don't
         | exactly expect or want a consumer device to be doing this in
         | the background without the owner's knowledge.
        
           | jrm4 wrote:
           | Sure. And you'll quite literally never be able to get any
           | meaningful reduction in this practice unless you attack it at
           | the level of big, publically known companies; the warnings
           | about these local dinky things I suppose are not harmful and
           | help individuals a bit -- but I'm concerned they give the
           | entirely false impression that the extremely similar stuff
           | coming from the big boys is definitely a-ok.
        
             | Dylan16807 wrote:
             | Reduction in what practice? Are there big companies doing
             | ad fraud?
             | 
             | I want big companies to stop spying on me, which is a
             | completely different issue.
        
               | jrm4 wrote:
               | They're not at all "completely different issues."
               | 
               | Both are well within the category of
               | 
               | "If you buy a device to do a thing, then the device does
               | something else that is not readily apparent to the user
               | that user would find objectionable if they had clearer
               | knowledge."
               | 
               | This is immoral and harmful regardless of precise
               | vector/action.
        
         | mcphage wrote:
         | > I do not see problems with fake ad clicks and have no
         | sympathy for ad companies.
         | 
         | Yeah, it's like--a cheap streaming stick _AND_ it poisons the
         | advertising well? I 'm pretty happy with my Fire TV Stick, but
         | they're really tempting me here.
        
           | exe34 wrote:
           | My pinenote runs the original spyware image - I don't have a
           | problem with Winnie the Pooh reading along with me.
        
           | autoexec wrote:
           | > Yeah, it's like--a cheap streaming stick AND it poisons the
           | advertising well?
           | 
           | Keep in mind that it's your IP and identity associated with
           | those clicks and anything else criminals decide to do with
           | your IP address. That means you're identity is being linked
           | to things you may or not want to be known as being
           | interested/involved in. The ads your TV stick clicks on can
           | cause data brokers to include your name in lists of people
           | who are heavily into drugs, have mental disorders, belong to
           | certain religions or political parties, etc. All of that can
           | come back to haunt you later.
           | 
           | Depending on what other activity your connection is used for
           | as a proxy it can also get you in trouble with the police or
           | with your ISP.
        
             | inigyou wrote:
             | So you're saying it's going to weaken the presumption that
             | an IP can be easily tracked to an individual? Even better!
        
               | mcphage wrote:
               | Talk about the gift that keeps on giving...
        
               | autoexec wrote:
               | No, your IP will be easily tracked to you as an
               | individual. You'll just suffer the consequences of
               | whatever your streaming stick does with your IP. If your
               | stick clicks a bunch of ads for fast food your heath
               | insurance bill goes up because their algorithm thinks
               | you're a higher risk. If your streaming stick clicks a
               | bunch of ads for high end luxury goods, online stores
               | start charging you more than they charge your neighbor
               | for the same items because their algorithms think you
               | have money to burn. Your streaming stick clicks a bunch
               | of ads for addiction recovery services, you don't get a
               | call back for the next job you apply to because the HR
               | department paid a data broker to run a background check
               | looking for "red flags".
               | 
               | What you do on the internet has very real impacts on your
               | life offline and it's going to happen more and more over
               | time. AI will make it easier for companies to leverage
               | the massive amounts of data avilable to them about you.
               | Surveillance pricing is spreading. Consumer reputation
               | services are spreading. Law enforcement is buying up data
               | from data brokers. Extremists are using data brokers to
               | decide who to target with violence.
               | 
               | Nobody cares if the data they have isn't 100% accurate.
               | The data broker doesn't care. He gets paid either way.
               | The companies buying your data don't care either. It's
               | all a numbers game to them. They just have to be right
               | enough times to justify the cost of the data.
        
               | inigyou wrote:
               | None of this is based on reality. Can you show any of
               | this ever happened to anyone?
        
         | Cider9986 wrote:
         | >What worries me much more is backdoors from the foreign
         | companies and governments that can be pre-installed at the
         | factory to collect intelligence information.
         | 
         | Most Americans are at a greater threat of harm from their own
         | government that a foreign one. What worries me is all the mass
         | surveillance done by big tech which bypasses the 4th Amendment
         | and gives the government Americans data without a warrant.
         | 
         | There's already a front door with the adtech for US alphabet
         | boys. This could likely be collected by others as well. We saw
         | this happened where foreign hackers exploited a backdoor
         | designed for American authorities[1]. This is what experts are
         | referring to when they say there's no backdoor only for me.
         | 
         | This could be compelling to politicians, though, and would
         | certainly be a step in the right direction.
         | 
         | >- any telemetry or data collection, or updates must be opt-in
         | only and disabled by default
         | 
         | This should be how it is for everything foreign made software
         | or not. Would be very hard to get done with the big tech lobby
         | in the US.
         | 
         | [1] https://techcrunch.com/2024/10/07/the-30-year-old-
         | internet-b...
        
         | arjie wrote:
         | Oh this was a failed device that Mozilla offered. I had a
         | couple back in the day. It was called Matchstick. Sick t
         | shirts. Basically an OSS chromecast.
        
         | soulofmischief wrote:
         | The problem is that when you need these powers most as a
         | citizen is when your government is least likely to allow it.
        
         | Tangurena2 wrote:
         | > _What worries me much more is backdoors from the foreign
         | companies and governments that can be pre-installed at the
         | factory to collect intelligence information._
         | 
         | The Snowden leaks showed that the US was already doing this.
         | I'm certain that everything purchased is already infected with
         | _something_. Most likely bugs and bad security.
        
       | Mistletoe wrote:
       | I recently got an Apple TV 4K and have been really enjoying the
       | ad free experience. Worth every penny. Our smart tv had turned
       | into a Christmas tree of ads.
        
         | ocd wrote:
         | As much as I hate Apple for what they've done to the average
         | consumer in regards to computing, it would be just impossible
         | and dishonest to say anything other than Apple is the outright
         | winner in streaming devices. The experience is so smooth.
        
           | ghostly_s wrote:
           | Considering their recent decision to give up on building
           | Apple Maps into a serious contender and instead enshittify it
           | with ads, I don't have much faith Apple TV will be far
           | behind.
        
             | dhosek wrote:
             | One hopes that the new CEO will realize the turn towards
             | ads is ruining the Apple brand and pull back on that front.
        
               | inigyou wrote:
               | Ha! No company has ever reversed enshittification.
        
           | trouve_search wrote:
           | The nvidia shield is pretty damn good as well, even if old at
           | this point.
        
         | wewtyflakes wrote:
         | There are plenty of ads on Apple TV; huge banners right at the
         | top of the UI, and ads that launch before you get to see the
         | content of a show with no way to automatically disable them
         | (you have to manually click through or just wait it out). It is
         | infuriating (to me).
        
           | ls612 wrote:
           | Apple TV the app has ads for Apple TV shows. Apple TV the
           | device doesn't have ads built in.
        
             | wewtyflakes wrote:
             | The TV app is baked into the device and is automatically
             | focused if you press up too many times on the remote (and
             | thereby triggering the large banner ads).
        
       | AlotOfReading wrote:
       | Of all the evils normally associated with visual programming
       | languages, enabling cybercrime isn't one I've previously
       | considered. Now that I've seen it, I'm surprised it wasn't more
       | common before LLMs appeared.
        
       | defmetrix wrote:
       | I didnt know anybody bought a streaming stick anymore
        
       | yunnpp wrote:
       | And which part of "ad fraud" is the fraud? As far as I can tell,
       | ad networks and advertisers are the fraud and they are also part
       | of the increasing surveillance state.
       | 
       | Didn't know Krebs was a mainstream news puppet.
        
         | brainwad wrote:
         | It's called fraud because the ad host colludes with (or
         | directly controls) the botnet to get lots of clicks on ads
         | hosted on their sites, making them money at the expense of
         | advertisers.
         | 
         | If you just want to spam clicks on ads you don't financially be
         | edit from, go for it.
        
       | yumraj wrote:
       | Any way to identify or block these proxy and ad click services in
       | the router? Say a Ubiquiti or even pfsense?
       | 
       | I'm not using any of these boxes for especially this reason, but
       | about 10-15 years ago had noticed my treadmill pinging a Chinese
       | portal. I removed the WiFi access from the treadmill but am
       | curious if there might be other devices.
       | 
       | Any specific ports, etc these guys use or are they mostly
       | impossible to distinguish from regular internet traffic?
       | 
       | My another worry has been if these can monitor other Internet
       | traffic, though I think HTTPS should mostly prevent that.
        
       | utopiah wrote:
       | I bet this is much broader than we all realized because just
       | earlier today I was reading on
       | https://gist.github.com/probonopd/3ad6b7777caea1503f00d5fe77...
       | in order to tinker with a cheap (like really cheap) Android video
       | projector : "Device: Magcubic HY300 Pro Android Projector
       | (ui_Veng.projector) Issue: Device was being used as a residential
       | proxy node without consent, causing thousands of suspicious DNS
       | requests and bandwidth usage." linked in there just few months
       | ago.
       | 
       | It's not present on mine (AFAICT) which lead me to think either
       | it was a genuine mistake or their bailed on that benefit or they
       | upgraded to a harder to detect technique.
       | 
       | An acquaintance mentioned they also bought a similar device few
       | months ago. I believe there will be a lot MORE of these so we
       | should soon be able to witness if it's an innocent mistake or the
       | new normal.
        
         | LetsGetTechnicl wrote:
         | Oh wow that's the same projector I have. Would be really cool
         | to install a custom build on it, but for now I just have an
         | Apple TV connected to it.
        
           | utopiah wrote:
           | You can already adb connect in dev mode then install .apks,
           | e.g. termux, Fennec and change some settings. It does seem
           | rootable but I didn't try.
        
       | stronglikedan wrote:
       | > But a groundbreaking new analysis finds these devices also
       | routinely spoof themselves as mobile phones clicking ads on AI-
       | generated websites as part of sprawling operation that seeks to
       | defraud online merchants and advertising networks.
       | 
       | You had me at "But"! ::swoon::
        
       | RajT88 wrote:
       | A pirate TV box from China presents a security threat?
       | 
       | This is my surprised face.
        
         | inigyou wrote:
         | No actual security threat was stated in TFA though. Only
         | revenue threats.
        
       | gxs wrote:
       | No mention of Roku
       | 
       | I use one but only when traveling at hotels - it's one of the
       | only sticks that can connect to captive WiFi networks at hotels
       | 
       | I've got barely anything on it so privacy be damned - but at this
       | point this is why I just buy apple products
       | 
       | I have two apple tv's which probably do shady things too, but I'm
       | willing to play the probabilities and assume it's the least bad
       | of my options short of tinkering with flashing hardware and all
       | that stuff that used to be fun in my teens (emphasis on used to)
        
       | kazinator wrote:
       | > _But a groundbreaking new analysis finds these devices also
       | routinely spoof themselves as mobile phones clicking ads ..._
       | 
       | Compromised (or malicious from the factory) devices being
       | recruited into bot farms for click fraud is ... a groundbreaking
       | discovery in 2026?
       | 
       | > _on AI-generated websites as part of sprawling operation that
       | seeks to defraud online merchants and advertising networks._
       | 
       | To hell with AI-generated websites and advertising networks.
       | 
       | Say, where can I get the most effective malicious TV stick for
       | click-frauding the fuck out of that shit? I will take fifteen! :)
        
         | snickerbockers wrote:
         | I'm imaging a largescale distributed project like folding@home
         | except instead of doing scientific research everybody is
         | working together to fuck with advertisers, tracking cookies,
         | etc.
        
       | cute_boi wrote:
       | The best solution to this problem is to block GeoIP traffic and
       | monitor bandwidth consumption on a per-domain basis. If something
       | is sending data during the night, it becomes much easier to
       | identify suspicious activity.
        
       | Hasz wrote:
       | Hey that's pretty smart! Fradulent, but very smart. I was
       | honestly expecting botnet.
       | 
       | I expect many cameras of "dubious" origin are used for similar
       | tasks, same with most "smart" devices with sufficient horsepower.
        
       | Pxtl wrote:
       | > major e-commerce providers like Amazon, Best Buy, Newegg and
       | others continue to sell hundreds of different models and brands
       | that bundle unofficial versions of Google's Android operating
       | system and are frequently marketed (via online influencers) as a
       | way to access a broad array of streaming services and live
       | broadcasts without a subscription.
       | 
       | This is why I giggle when people talk about ending Section 230 in
       | the USA (or various international counterparts thereof).
       | 
       | The largest companies on Earth are happily selling hacked piracy
       | spyware botnet garbage. Not just hosting malicious posts for free
       | like Section 230 protects, but selling illegal physical devices
       | and taking a cut of the profit and excusing it with a pathetic
       | whack-a-mole moderation system. It's already illegal and the law
       | has already failed.
       | 
       | Sean Parker's mistake was that he wasn't rich enough.
       | 
       | Laws are for poor people.
        
       | a-dub wrote:
       | it's just like a phone. don't buy a crappy one with firmware of
       | unknown provenance. make sure the one you do buy has an active
       | and effective effort that you trust that ships timely security
       | fixes.
        
       | matheusmoreira wrote:
       | That reminds me, I need to configure VLANs in my router so that
       | all my trusted computers are isolated from all the other garbage
       | that makes it into the network.
        
         | ur-whale wrote:
         | Mmmh, I've always wondered ... as much as VLAN's are a very
         | useful tools to - for example - route two separate LAN's
         | traffic through a shared physical link ... are they any good
         | when it come to security?
         | 
         | I mean, I don't believe VLAN's were designed with security as a
         | goal, and I wonder how "strong" the virtual wall between two
         | VLAN's actually is?
         | 
         | Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on
         | physical connection where packets from both VLANs happen to
         | travel?
         | 
         | Just wondering.
        
           | ahahs wrote:
           | this is a good question, i asked claude sonnet 5 and the
           | answer is too big and complex for me to type out on mobile.
           | but long story short, you absolutely need separate VLANs and
           | Firewalls in conjuction to secure traffic between networks
        
             | matheusmoreira wrote:
             | Yeah, I've been using Claude to help me secure my home
             | network. I applied to Anthropic's cyber program and got
             | accepted despite being a hobbyist. I'm not very good at
             | networks so I'm gonna try to make the most of it.
             | 
             | Really wish I could point Mythos at my router and just loop
             | it until my router becomes literally unhackable.
        
               | TylerE wrote:
               | Making your router unhackable is trivial. Just pull the
               | AC cord. You didn't specify that it had to be _useable_.
        
           | rcoder wrote:
           | Depends on your networking setup. A good switch will simply
           | refuse to route packets between clients on different VLANs,
           | and hide the existence of the tags that determine which VLAN
           | a host is on.
           | 
           | A bad switch or router (which almost certainly includes a ton
           | of crappy home APs and routers, compromised by the same
           | actors who ship these devices) could let clients see VLAN
           | tags and ignore them.
           | 
           | And an Ethernet "hub" does no filtering at all.
        
             | rcoder wrote:
             | Also: if you need a streaming box to see your AirPlay or
             | UPnP devices for "casting" it necessarily has to be on the
             | same VLAN as the devices it's connecting to. Sonos speakers
             | have this problem when subject to client isolation setups
             | based on VLANs or switch-level packet filters.
             | 
             | And any kind of multicast (used for local service discovery
             | and media streaming) has the same limitations.
        
           | xorcist wrote:
           | Network switches typically aren't known for their outstanding
           | security record, but the vlan tags themselves are trivial and
           | should be hard to mess up. Should someone hack your switch
           | all bets are off, but as long as you don't have management
           | accessible in-band you should be fine. Security problems are
           | more likely to stem from bad configuration.
           | 
           | > Can't a device on VLAN1 not peek at VLAN2 traffic if it
           | sits on physical connection where packets from both VLANs
           | happen to travel?
           | 
           | That would be an exceptionally weird configuration. If a
           | device "sits on VLAN1" that typically means that it's on an
           | "untagged" port where only VLAN1 traffic is allowed. Ports
           | that carry multiple VLANs are "tagged" ports and you normally
           | wouldn't say they "sit" on any specific VLAN, precisely
           | because that port carries tagged traffic for multiple VLANs.
           | It's at best an irregular use of the terminology but likely a
           | misunderstanding somewhere.
        
           | inigyou wrote:
           | A VLAN is a virtual LAN. having two VLANs is like having two
           | LANs but without as much duplicated wiring. It's quite well-
           | supported and reliable.
           | 
           | You usually want to interconnect them at one central point,
           | usually a router, and enforce a security policy there.
        
         | russdill wrote:
         | Seems like a motivation to switch to using a VPN for such
         | untrusted devices that still require internet access.
        
         | __turbobrew__ wrote:
         | Doesn't help when the garbage starts proxying illegal traffic
         | through your home ISP.
        
           | inigyou wrote:
           | What happens then?
        
           | matheusmoreira wrote:
           | Yeah but at least the garbage can't attempt to exploit my
           | laptop.
        
       | simojo wrote:
       | We purchased a Chinese-made projector from Amazon, which was
       | surprisingly inexpensive (~40 USD). Upon connecting it to the
       | internet, it placed a constantly running feed of ads on the
       | corner of the screen, even while movies were playing. There was
       | no way to disable it either. Even though it's not a stick, it's a
       | similar principle.
        
         | Pxtl wrote:
         | I mean, did you have to connect it to the internet though? Did
         | it not just have a dp/hdmi port?
        
         | mikestew wrote:
         | _Upon connecting it to the internet..._
         | 
         | I hesitate to blame the victim here, but why on earth would you
         | do that? "$40 Chinese-made" didn't give you pause?
        
           | bigmattystyles wrote:
           | To be fair, everything is Chinese made. I would be even the
           | Apple TV and NVIDIA Shield are made in China and if a state
           | actor is determined to get a malicious payload in....
        
             | miladyincontrol wrote:
             | To play devil's advocate, when someone says "Chinese made"
             | they're usually well aware of your point, and are more
             | using it as a common way to describe product mills spitting
             | out countless devices with dubious quality or
             | configuration.
             | 
             | Of course theres good products made in China, and plenty of
             | entirely Chinese brands killing it doing their thing.
        
               | 8note wrote:
               | its pretty straight racism though.
               | 
               | its US software companies that are the worst of the worst
               | in terms of adware and malware being shipped under
               | monopoly control
        
               | Eisenstein wrote:
               | Its based on the most common heuristic people have
               | developed in regards to the phenomenon. What do you think
               | about 'alphabet soup company' instead, referring to the
               | tendency for names to be a mix of random letters?
               | Otherwise, you can try and create a better term for
               | 'unaccountable third parties using US platforms to dodge
               | liability for their product made out of the cheapest
               | components and software possible' and see if that catches
               | on.
               | 
               | Yes it is also the US companies that are a problem but
               | these are two separate problems and need different terms.
        
               | SecretDreams wrote:
               | There's enough evil malware provider blame to go around.
        
               | wvh wrote:
               | It's not racism at all to be weary of (any) political
               | system, its overreach and the incentives of the people
               | living in it, be it China or America or Russia.
               | 
               | The word racism is vastly overused these days.
        
               | parineum wrote:
               | > its pretty straight racism though.
               | 
               | It's not. Firstly, because countries aren't races.
               | Second, because it's just a leftover from a time where
               | that was a good heuristic.
        
             | fc417fc802 wrote:
             | This isn't about state actors though. There's a world of
             | difference between a name brand (possibly even a Chinese
             | one) versus what I would term "chineseum". It's nothing to
             | do with China per se and everything to do with purchasing
             | from the extreme low end of the market. It just so happens
             | that the vast majority of that segment is manufactured in
             | China at present.
        
             | worik wrote:
             | > To be fair, everything is Chinese made
             | 
             | Yes. Chinese manufacturing is quite a phenomenon, useful
             | and everywhere
             | 
             | But to be completely fair, a $40 video projector has a
             | warning label. The price
        
             | speerer wrote:
             | I think normally when people say Chinese made in this way,
             | what they're really communicating is that there's no
             | (meaningful) brand. All they know about it is that it is
             | from China.
        
             | r_lee wrote:
             | Made in China and random Chinese brands are two very
             | different things
        
               | ChrisRR wrote:
               | Often they're exactly the same things
        
               | inigyou wrote:
               | Often the USA brand is just buying the random Chinese
               | design from the same factory that brands it in random
               | letters, and tripling the price.
        
               | r_lee wrote:
               | if you think the Apple TV or Nvidia shield example
               | applies to this then I don't know what to say
        
             | ponector wrote:
             | My Samsung phone is made in Vietnam.
        
           | SiempreViernes wrote:
           | This is an age where even teacups demand internet
           | connectivity to fetch firmware updates
        
             | contravariant wrote:
             | I mean I get why my cups need frequent java updates, but
             | still.
        
             | histriosum wrote:
             | Finally, a legitimate use case for HTTP 418...
        
               | red-iron-pine wrote:
               | and they thought it was an April Fools joke, hah!
        
             | Ballas wrote:
             | And then what happens if someone accidentally pushes the
             | saucer firmware to the cup update?
             | 
             | https://hackaday.com/2022/03/18/welcome-to-the-future-
             | where-...
        
             | tollgategit wrote:
             | And yet, it is now still just as stupid to do it as it was
             | before we arrived here.
        
         | xyx0826 wrote:
         | I remember reading an analysis on one of those projectors; the
         | author found a residential proxy running on their device. I
         | would recommend keeping these things off the internet.
        
           | simojo wrote:
           | I'd be very interested to see it if you still have access to
           | it.
        
             | dhruvrrp wrote:
             | Dunno if this is the same issue, but someone found malware
             | in their projector. I'm not sure about the accuracy since
             | the report is blatantly AI generated:
             | https://github.com/jrm360seclab/aodin-vo1d-malware
        
           | mrloopex wrote:
           | Yes that's what the article is about.
        
         | dboreham wrote:
         | Capitalism!
        
           | azan_ wrote:
           | Absolutely, there's no scam outside capitalism!
        
             | jkahrs595 wrote:
             | Outside of capitalism is outer space, so your snarky
             | comment is actually true.
        
               | usef- wrote:
               | I think he meant the other kind of "outside", not
               | physically. Plenty of bad stories.
        
               | azan_ wrote:
               | Of course, every socialist country is actually capitalism
               | and that's why it fails.
        
               | inigyou wrote:
               | Which country is socialist?
        
             | ColdStream wrote:
             | Get the sarcasm, but of course there is scam outside of
             | capitalism. Its just that the capitalistic model almost
             | turns it from an inconvenient bug into a mainline feature.
             | 
             | Not saying there is an absolute perfect alternative, anyone
             | who says that is usually shoveling smoke, but there are
             | flaws with this economic model to be addressed.
        
               | azan_ wrote:
               | Not true at all. I'm from Poland which was occupied by
               | communist for a long time, and I can guarantee you - the
               | amount of scam we had under that rule was orders of
               | magnitude larger than what we have now.
        
               | ColdStream wrote:
               | Yeah I did forget about that. When you flatten the pay
               | structure across the board, it makes bribes and scams so
               | much more desirable. But also, communist structure in
               | practices is sort of the total opposite of capitalism at
               | a distance.
               | 
               | It was said that Karl Marx was completely right about
               | Capitalism and completely wrong about Communism. And that
               | is fairly accurate, both have big flaws.
               | 
               | Most times, the opposite of one bad idea is another bad
               | idea.
        
               | azan_ wrote:
               | I think it's really far fetched to say capitalism is bad
               | idea. It's great system, it has some problems, but the
               | upside is so big and alternatives are so bad that it's
               | really unfair to call it bad system.
        
               | ndsipa_pomu wrote:
               | I think that encouraging corporations to destroy our
               | environment (e.g. climate change) as fast as possible to
               | maximise profits is a very good reason to call it a bad
               | system. Yes, some goods and services become much more
               | efficient, but now we're all going to have to pay the
               | price for it.
        
               | inigyou wrote:
               | Like the current never-ending heat wave. It's predicted
               | to go on for months btw and the ocean is 4 Kelvins warmer
               | than it should be.
        
               | pbhjpbhj wrote:
               | Yh, the end of civilisation is a good thing after all, so
               | enabling greedy fuckers to accelerate all life on Earth
               | ever more rapidly towards destruction has to be good ...
        
           | jojobas wrote:
           | At least in capitalism you have the choice to look for a
           | malware-free alternative. 100% USSR, had it survived to the
           | IoT era, would penalize you for not having a state-mandated
           | surveillance device on at all times.
        
             | DoctorOetker wrote:
             | I agree fully with your assessment of USSR but basically
             | any nation state with the power does such things.
             | 
             | Show me a COTS smartphone where the end-user can burn the
             | OTP fuses for his personal public key, so they can have it
             | boot their own custom signed firmware, and control exactly
             | what runs in TrustZone's SW Secure World?
        
               | jojobas wrote:
               | You can flash yourself GrapheneOS with your own keys for
               | the bootloader. Then again "I can't make sure all
               | manufacturers aren't in collusion" when FBI sues Apple
               | and others (and fails) over suspects' phone access is
               | quite different from "every device sold in the country
               | must have government malware", as it is in China.
        
               | inigyou wrote:
               | I can't find a device in the USA that doesn't come with
               | government malware. Is this another instance of the USA
               | accusing China of everything the USA is doing (like with
               | the credit scores)?
        
               | breppp wrote:
               | You'd have to be a bit more specific of which government
               | malware you found in Android/iOS devices, cause that
               | would be interesting
        
               | inigyou wrote:
               | Android comes with something called Google Play Services,
               | and iOS has a thing called iCloud. You may have heard of
               | them.
        
               | breppp wrote:
               | I have, I still have not heard how the US government uses
               | these as malware, but I would love to learn something new
        
               | inigyou wrote:
               | For instance, if you use an Apple phone and the
               | government wants to see the pictures you took, they can
               | just get a copy of them from Apple using iCloud.
        
               | red-iron-pine wrote:
               | show me anyone outside of HN or XDA devs that would ever
               | want to do that
        
           | wil421 wrote:
           | Chinese!
        
             | Epa095 wrote:
             | Chinese capitalism!
        
               | red-iron-pine wrote:
               | Communism with Chinese Characteristics
        
         | qmr wrote:
         | ...firewall it then?
        
         | __turbobrew__ wrote:
         | You forgot to drink a verification can
        
         | throwa356262 wrote:
         | If the hardware is good and cheap, it should be a fun project
         | to replace the OS with a custom Android build that is clean of
         | adware.
         | 
         | Do you have a link to the projector?
        
         | tollgategit wrote:
         | > Upon connecting it to the internet,
         | 
         | I dare not ask why you would do such a thing, instead, I will
         | simply ask if you now think the reason was good, and I will
         | hint at you that if the reason was "convenience", then you
         | should answer "No".
        
           | breppp wrote:
           | You assume a lot of things, sometimes you have to connect it
           | to the internet for it to work (such as robovacuums)
        
             | GJim wrote:
             | Why in the name of all that is _holy_ would you need to
             | connect a projector or vacuum cleaner to the internet in
             | order for it to work?
             | 
             | Seriously, why do you think this is normal or acceptable?
             | 
             | This is bullshit needs to stop (and the scummy AdTech
             | industry has a lot to answer for).
        
               | themaninthedark wrote:
               | Vacuum for "convenience" of being able to turn it on with
               | a phone.
               | 
               | I could actually see hooking up a projector to wifi to
               | allow it to stream videos.
        
               | breppp wrote:
               | As far as I remember they mandate you connect to it in
               | order for you to operate it.
               | 
               | We all know why, which is Adtech, but like cars or smart
               | TVs, you as a customer either skip the entire segment or
               | yield.
        
           | dspillett wrote:
           | The streaming sticks the article is discussing basically need
           | network access to function. They might support streaming from
           | local media sources and file shares too, but that is also
           | done over WiFi. Unless you have a properly firewall
           | controlled home (very few people do, I'm pretty nerdy and
           | most devices on my network can just NAT to the outside these
           | days) then just giving it a WiFi connection gives it access
           | to the wider network from your location.
           | 
           | You'll probably find the projectors are pretty much the same
           | hardware and OS as the sticks except with the projection
           | device added where the stick just has an HDMI output. It
           | might have HDMI-in too so it can just be used as a screen for
           | another device, but there are definitely some units out there
           | that are network-play-only.
           | 
           | You aren't wrong about giving cheap crap like this access to
           | your network (and via that the public network) is risky, but
           | that convenience you (and I) would say no to is exactly what
           | they are bought for.
        
         | ubermonkey wrote:
         | I'm still trying to figure out why you didn't see that coming.
        
       | hn_submit wrote:
       | I already suggested the U.S. government ban all Chinese products
       | which have a computer in them that's connected to the internet.
       | 
       | Instead they're banning stuff willy nilly left and right without
       | really solving the problem.
       | 
       | But there's good stuff coming out of China as well. I recently
       | bought a cheap e-reader which has no WiFi or internet connection
       | and it works stellar. And I bought some cheap Chinese sport cams
       | which also lack internet and work great.
        
         | autoexec wrote:
         | > I already suggested the U.S. government ban all Chinese
         | products which have a computer in them that's connected to the
         | internet.
         | 
         | Personally, I think every other country should ban any product
         | made by Google, Amazon, and Microsoft since they all spy on the
         | users of their products too.
        
           | hn_submit wrote:
           | I've suggested legislation which would ban the sale of
           | customer information to third-parties.
           | 
           | These companies could use the info they gather on customers
           | for their own use but they cannot (re)sell it to _anyone_ ,
           | not even the government. The reason being that the
           | information eventually ends up abroad after which you lose
           | all control over it.
        
       | stuaxo wrote:
       | How hard is it to get something else on these ?
       | 
       | Looks like cheap small computer with a remote control.
        
       | ta988 wrote:
       | A familly member had one of those (he had to pay a yearly
       | subscription in addition to the stick). Network would be unusable
       | as soon as it was on for anyone else, and it also tried to scan
       | things on the local network. It was indeed connecting to all kind
       | of services all over the world (and saturating some tables in the
       | router doing so which blocked other clients). Definitely evil,
       | definitely on purpose.
        
         | deepfriedbits wrote:
         | Reading this, I caught myself wondering how we distill what's
         | in this excellent write up into something the average consumer
         | understands, including the dangers from buying and using
         | devices like this.
         | 
         | Is it a graphic that's shared? Something else? I am sure we all
         | know or have heard of people with these devices that promise
         | free streaming.
        
           | ta988 wrote:
           | I warned them about the risk of those things and showed them
           | what I found, they continued buying the next generation (that
           | person and his two >40yo kids). They NEEDED to watch those
           | soccer games more than they cared about security...
        
           | Arainach wrote:
           | The bigger problem is convincing them to care. Botnets are
           | abstract - where's the pain to them? Ad farms? That's "just
           | hurting big corporations".
           | 
           | Remember, a significant portion of the population got angry
           | (often violently so) when just asked to wear a mask to
           | protect their neighbors. And the threat there was
           | significantly easier to explain.
        
             | pibaker wrote:
             | Just tell the anti mask types the TV sticks come with CCP
             | hacking software preinstalled.
        
           | ValdikSS wrote:
           | In the world of auto-updates of software and firmware, even
           | the hardware which is now completely legal and crap-free,
           | could convert itself to a proxy or ad network later any time.
           | 
           | And don't forget about counterfeit products (which look like
           | original but different in firmware) and supply chain attack
           | vectors, which are really, _really_ common.
           | 
           | If you want to buy something as simple as a feature phone,
           | going to a store with 10 of them will give you at least 1/10
           | chance to buy a phone with a trojan/backdoor.
        
           | SecretDreams wrote:
           | You can't. This is a legitimate thing the government needs to
           | step in and deal with on behalf of their people via
           | legislation because their people cannot be reasonably taught
           | to protect themselves.
        
             | inigyou wrote:
             | Protect themselves from what?
        
           | inigyou wrote:
           | First you'd have to figure out what the dangers actually are.
           | Most of what's cited in TFA and this comments section are
           | only dangers to large evil companies, and why should anyone
           | care about them?
        
         | inigyou wrote:
         | If it wasn't scanning your own network or using all of your
         | bandwidth, would you still consider it evil?
        
       | mring33621 wrote:
       | Using low code tools to build click fraud logic FTW!
        
       | rawgabbit wrote:
       | What happens when you stick this malware into your windows PC?
       | The PC is now an accomplice to fraud?
        
       | SoftTalker wrote:
       | > Despite repeated warnings from the FBI and security industry
       | leaders about the security and privacy risks of using these
       | streaming devices, major e-commerce providers like Amazon, Best
       | Buy, Newegg and others continue to sell hundreds of different
       | models and brands
       | 
       | I scanned the comments and I didn't see anyone suggesting that
       | these companies should share any responsibility for selling these
       | harmful products. Why is it that they seem to get a pass? Would
       | we feel the same about giant retailers selling tainted food, or
       | unsafe children's toys?
        
         | eightysixfour wrote:
         | Probably because we have little to no way to punish those
         | companies. We can't even stop DJI from shipping their drones
         | under other brands to get around the ban.
        
           | dessimus wrote:
           | Our government _chooses_ to not punish those companies.
           | Unfortunately, the lawmakers have decided that the donations
           | to their PACs are more important than actually doing
           | something about it.
        
         | lotsofpulp wrote:
         | Probably because most people don't equate the damages from
         | causing bodily harm to whatever these ad clicking networks do.
         | 
         | Voters don't like seeing themselves or their kids get hurt, but
         | they do like lower cost live sports.
        
         | al_borland wrote:
         | One of the main value propositions for retailers in a world of
         | endless cheap garbage being sold online, is to vet products so
         | customers can trust that what their buying is from a legitimate
         | company and not junk or stuff like these streaming sticks.
         | 
         | This is the problem with being an "everything store".
         | "Everything" includes a lot of things most consumers would like
         | to be protected from, and assume they are due to the long
         | history of retailers standing behind the products they sell.
         | That history seems to have come to an end. They only stand
         | behind it enough to offer a refund if there is a problem, not
         | to ensure it's good before selling it.
        
           | ephemeral67 wrote:
           | interesting bit of information: most EV mower companies now
           | do not provide replacement parts - if a mower dies within
           | warranty, a 'certified' warranty repair shop does basic
           | troubleshooting, and if it's beyond a piece of cheap plastic,
           | the mfr just ships a new mower to the 'repair shop'. Once out
           | of warranty, you're on your own.
        
             | drnick1 wrote:
             | Thank you for reminding us that electric mowers are
             | garbage.
        
               | Gigachad wrote:
               | Everything is garbage now. It's the end state of
               | unrestrained capitalism.
        
               | exe34 wrote:
               | Surely not, the invisible hand of the market should crawl
               | up their arse and make them do the right thing any day
               | now.
        
               | actionfromafar wrote:
               | The invisible hand crawled up the arses of Congress and
               | seems to enjoy it there.
        
               | nullhole wrote:
               | I mean, not all of them?
               | 
               | Mine's a fancy-pants Stihl battery mower, but it works
               | quite well and has been doing so without problem since I
               | bought it ~4 years ago. The other battery stuff from the
               | same brand (trimmer, chainsaw, kombi-tool) have the same
               | story.
        
               | bluGill wrote:
               | Stihl is a commercial product (mostly). They design for
               | people using them as a full time job. You pay the price
               | for quality.
        
               | nullhole wrote:
               | Yeah, mine are the AP ('professional') class ones.
               | 
               | What matters is the amortized cost per year, I think -
               | more expensive up front but cheaper in the long run.
        
               | zrobotics wrote:
               | No, they definitely have homeowner grade tools available.
               | 
               | For instance, the MS182 [0] is a $270, 2.2cu in saw with
               | a 16" bar listed "For homeowners and light duty work".
               | 
               | Meanwhile, the MS201 [1] is $1100 for a 2.1cu in saw with
               | a 16" bar listed as "The lightest professional gas
               | chainsaw from STIHL Perfect for delimbing work in
               | forestry".
               | 
               | Service interval on the 201 will be much longer, and it's
               | expected to last longer but is priced accordingly. I
               | ended up having to buy one of their homeowner grade saws
               | 10 years ago when I was up in the mountains and my saw
               | died, that was all that was available locally. I'm
               | certainly not a professional, but at the time my primary
               | heat source was wood and I had always used the stihl pro-
               | grade saws. However, that cheap stihl was an absolute
               | piece of junk, it was half wore out after cutting 2 cords
               | of firewood that first time. Terrible ergonomics and poor
               | power to boot, even after reserving the saw for light-
               | duty work it only lasted 2 years and was miserable to
               | start and run the entire time.
               | 
               | At least they explicitly say that they are for light duty
               | though, a less honest company would market everything as
               | pro-grade. But don't just buy the name, while they make
               | good quality products they also sell cheap crap under the
               | same name. It also isn't that clear in a retail store
               | besides the price which ones are the homeowner grade
               | saws.
               | 
               | [0] https://www.stihlusa.com/en/p/chainsaws-
               | ms-182-gasoline-chai... [1]
               | https://www.stihlusa.com/en/p/chainsaws-ms-201-gasoline-
               | chai...
        
               | newAccount2025 wrote:
               | Why? Mine is great. And light. And QUIET.
        
               | bigstrat2003 wrote:
               | They really aren't particularly quiet imo. Yes, there's
               | no motor, but it turns out that the whirring sound of
               | blades rotating and cutting grass is quite loud even
               | without a motor. I would say mine is perhaps 3/4 as loud
               | as a gas mower, which isn't a very impressive reduction
               | in noise.
        
               | maxerickson wrote:
               | With logarithmic perception, it's about a 50% reduction
               | in sound energy.
               | 
               | My battery mower is quiet enough that I don't feel
               | terribly rude mowing at twilight.
        
               | astura wrote:
               | I love mine.
        
               | classichasclass wrote:
               | My wife derides my Home Despot special plug-in mower as a
               | Tonka toy, but it's basically just a motor, a blade and a
               | bag, and I don't have a lot of lawn to mow.
        
               | timc3 wrote:
               | My Makita one is excellent.
        
             | bdamm wrote:
             | My electric mower has lasted longer than the gasoline mower
             | before it, which literally had plastic valves inside the
             | carbeurtator.
        
               | zdragnar wrote:
               | Counter anecdote, I've had gas mowers survive decades and
               | EV electrical equipment (in this case, a chainsaw and a
               | battery pack for a mower) both die within 14 months of
               | purchase.
        
               | Slash65 wrote:
               | This is my experience as well. String trimmer battery
               | went out (still in warranty and replaced) but my gas
               | string trimmer I use at a bigger property came home with
               | me and worked great. She's only 15 years old, the battery
               | was 6 months. I love my battery blower and string
               | trimmer, but the gas ones are going strong but typically
               | stay at the ranch property due to it being a bigger
               | property to maintain. I would also need 3-4 battery's out
               | there to keep up with maintaining it, the gas is a whole
               | lot cheaper than a grands worth of battery's.
        
               | taneq wrote:
               | Counter counter anecdote, I was just tidying up the yard
               | with my 18V whipper snipper and contemplating the fact
               | that I bought it in 2012 and it hasn't skipped a beat.
        
               | HDBaseT wrote:
               | I have a mower that my dad gave to me, which his dad gave
               | to him.
               | 
               | It is in rough shape, but it still cuts grass perfectly
               | fine.
               | 
               | I have a wippersnipper from before I was born which runs
               | perfectly today. It was left out laying sideways in the
               | rain for about a month. Quick clean and a new plug and it
               | was going again.
               | 
               | I'm sure the electric devices can run a long time, but
               | when they fail, they tend to be not repairable.
        
               | markdown wrote:
               | Makita, amirite?
        
               | taneq wrote:
               | Ryobi, but I have plenty of Makita gear too. :)
        
               | lazylester wrote:
               | almost all 2-stroke engines have had plastic flapper
               | valves and a plastic fuel pump for as long as I can
               | remember.
        
               | bluGill wrote:
               | There is a big difference in quality levels. If you want
               | a good mower pay the price for a commercial mower, people
               | who use them 8 hours a day need something that lasts.
               | 
               | 30 years ago a friend of mine did the mold for a lawn
               | mower. They put an engine on it and it ran for 120 hours
               | before the deck failed. It took 7 more tries until the
               | deck failed after 80 hours. Commercial mowers are
               | expected to run over 1000 hours.
        
               | bigiain wrote:
               | I remember asking a chippie (carpenter tradesman) a while
               | back why he was using Ozito brand power tools (the
               | cheapest Chinese brand from the local tool barn). He said
               | "The good gear like Milwaukee and Makita last years. The
               | cheap Chinese junk lasts maybe six months. Whatever I buy
               | it gets stolen about every 3 months. I'd rather have a
               | spare $40 drill waiting at home when my van gets broken
               | into, than have to go buy another $600 Milwaukee one that
               | I'd otherwise rather be using."
        
             | MostlyStable wrote:
             | These are the kinds of products I now just straight up
             | refuse to buy.
        
             | taneq wrote:
             | I think that's "most mass produced item manufacturers".
             | It's just cheaper to ship a new one than waste time trying
             | to troubleshoot.
        
           | omilu wrote:
           | Costco vets their products very well, if I see something at
           | costco and its something I need I just buy it. No need to
           | research and I've never been burned. They only sell good
           | quality stuff.
        
             | altruios wrote:
             | Costco isn't perfect, and things slip through still.
             | 
             | For example: this is a minor annoyance, but comes readily
             | to mind.
             | 
             | https://www.costco.com/p/-/orgain-organic-protein-and-
             | superf...
             | 
             | The problem is labeling conventions leading to inaccurate
             | assumptions of what's even IN that "protein powder"...
             | 
             | you would think the protein, being the largest in print, is
             | the primary ingredient but no. A serving is 51grams, and
             | the protein makes up 21grams of that serving: less than
             | half, that's not a 'protein powder' if the primary
             | ingredient isn't protein.
             | 
             | It should be labeled "SUPERFOODS with protein" not the
             | other way around.
             | 
             | There have been other things similar in scope less readily
             | recalled. It may seem minor to some... but labeling
             | accuracy and transparency is something we had to fight for
             | collectively.
        
               | al_borland wrote:
               | Ingredients are listed in order from greatest to least
               | amount. Protein is listed first. It seems it's the
               | creamer that throws off the ratio you're looking at,
               | which I'm assuming is there for consistency/taste.
        
               | tejohnso wrote:
               | A 51 g serving might contain 40 g of the protein blend,
               | making it a protein powder as the primary ingredient is
               | protein blend.
               | 
               | However, this is plant-based protein, not pure way
               | isolate. A plant-based protein powder from mung beans for
               | example isn't going to be 100% protein. Chickpea powder
               | contains roughly 20% protein.
               | 
               | So I don't know if that helps at all, but it doesn't seem
               | as bad as you and you might be suggesting.
        
               | tiltowait wrote:
               | The first ingredient is a plurality, not a majority.
        
             | femto wrote:
             | Check their tomato paste. It turns out that nearly every
             | tomato paste in Australia comes from Xinjiang in China,
             | including those marked as Australian or Italian. Simplot
             | (Leggos), the big US company, was the worst offender, so
             | it's possible that tomato paste in Costco's US stores has
             | been produced in Xinjiang using slave labour, irrespective
             | of what the label says.
             | 
             | https://www.abc.net.au/news/2026-07-27/australian-
             | tomatoes-l...
        
               | onionisafruit wrote:
               | According to this none of the samples tested from US
               | retailers contained Chinese tomatoes.
               | https://www.bbc.com/news/articles/crezlw4y152o It seems
               | like the US ban on Xinjiang is working
        
               | femto wrote:
               | Thanks for that informative link. I looked to see if
               | there was any data beyond the ABC article and didn't find
               | it. Some of the truthful brands listed in the BBC article
               | are available where I live. Kudos to the US that their
               | labels match their contents.
        
               | stubish wrote:
               | The ABC just broke their story a few days ago. There will
               | continue to be fallout over the next few months or years
               | (much like their last one, where they found that many
               | sunscreens did not meet their SPF ratings, a hot topic in
               | the skin cancer capital of the world)
               | 
               | (edit: whoops, Choice did the SPF rating investigation.
               | ABC just did a lot of reporting on it)
        
               | p-e-w wrote:
               | The above thread was about quality issues, not ethical
               | issues such as "slave labor" (a term somehow reserved for
               | certain countries, even though most countries use unfree
               | prison labor, including the US and much of the EU).
        
               | femto wrote:
               | It's about trust.
        
               | iamnothere wrote:
               | Our vocational training program, your prison labor, their
               | slave labor.
        
               | Nursie wrote:
               | > It turns out that nearly every tomato paste in
               | Australia comes from Xinjiang in China
               | 
               | I think that might be a bit of a strong assertion, from
               | your article there -
               | 
               | "It analysed 221 processed tomato products from 39
               | brands, including paste, passata and diced tomato.
               | 
               | Twenty-two per cent of the products failed country-of-
               | origin testing, while a further 6 per cent were flagged
               | for further testing."
               | 
               | So while 28 percent is scandalous, and those companies
               | need to face consequences, the other 72 percent seem to
               | be genuine.
        
               | femto wrote:
               | A big chunk of that 72% are legitimately labeled "Made in
               | China" or niche brands. The brands that failed, plus the
               | products that are actually labeled "Made in China",
               | dominate Australia's four supermarkets with the majority
               | of the market share. I've just done my weekly shop, so
               | trawled their web sites looking for alternatives.
               | 
               | Summarising the Australian situation, taking the 4corners
               | results into account, the following non-Chinese tomato
               | pastes are available:
               | 
               | Coles (29% market share): 1 x 140g premium product in a
               | tube (expensive with reduced market share) out of about
               | 20 products.
               | 
               | Woolworths (38% market share): 1 x 140g premium product
               | (Mutti) in a tube (expensive with reduced market share)
               | out of about 20 products.
               | 
               | Aldi (10% market share): None out of about 4 products
               | 
               | IGA (7% market share): 5 of 16 products, being the same
               | premium brands that Coles and Woolworths sell.
               | 
               | Maybe qualify my comment with "by market share and
               | availability". The effect is that if you stand in front
               | of an Australian supermarket shelf, every product, bar
               | one or two in the corner, come from China. China is a
               | proxy for Xianjing, in that sources say 80%-90% of tomato
               | paste from China comes from Xinjiang.
               | 
               | Hence the assertion I made.
               | 
               | Market share data:
               | https://www.accc.gov.au/system/files/supermarkets-
               | inquiry_1....
               | 
               | Xianjing percentages:
               | https://tomatonews.com/countries/china/
        
               | Nursie wrote:
               | > Woolworths (38% market share): 1 x 140g premium product
               | (Mutti) in a tube (expensive with reduced market share)
               | out of about 20 products.
               | 
               | Eh ...
               | 
               | "Well-known tomato brands that passed country-of-origin
               | testing include Mutti, SPC, Woolworths, Providore
               | D'Italia and Annalisa. Diced tomato cans and passata from
               | Leggo's and Coles also passed."
               | 
               | So here are 4 tomato pastes in woolworths that would seem
               | to pass the test of not being from China and not being
               | liars, just from a quick search (and I have seen all
               | these in my local) -
               | 
               | https://www.woolworths.com.au/shop/productdetails/290303/
               | mut... https://www.woolworths.com.au/shop/productdetails/
               | 218066/mut... https://www.woolworths.com.au/shop/productd
               | etails/901431/mac... https://www.woolworths.com.au/shop/p
               | roductdetails/150875/pro...
               | 
               | I usually buy Mutti stuff because it's low-ish salt, and
               | that claims to come from Italy and wasn't implicated in
               | the report here. And while I understand those are at the
               | 'premium' end, it's not like it's one product on the end
               | of the shelf either.
               | 
               | It's true that "Leggo" occupies a lot of the shelf space
               | and a lot of the cheaper 'own brand' stuff is labelled as
               | coming from China. And coles appears to be in a
               | weirder/worse spot that woollies, with only Providore
               | being Italian and two brands of turkish tomato paste,
               | which is interesting.
               | 
               | It's sad that I can't find an Australian tomato paste
               | that isn't a liar.
               | 
               | So I'm still not fully on board with "nearly every", OTOH
               | thanks for the further information. I shall continue to
               | try to avoid these products!
        
               | perpetuallunch wrote:
               | Difficult to distinguish between actual slave labour and
               | China-is-bad propaganda.
               | 
               | Harm to the end user: none^
               | 
               | Benefits to the end user: more affordable tomato paste
               | 
               | Government action to prevent slave labour products
               | entering Australia: none^
               | 
               | ^close enough.
        
               | martimarkov wrote:
               | Negatives to end user: unknown pesticides or banned
               | pesticides.
               | 
               | No propaganda - lack of validation, evidence and trust
        
               | perpetuallunch wrote:
               | What does slavery, real slavery or anti-China propaganda
               | fake slavery, have to do with the with the presence or
               | absence of pesticides, banned or otherwise?
        
               | stubish wrote:
               | It is perfectly legal to sell Chinese tomatoes in
               | Australia (which is not necessarily a good thing, re:
               | forced labour in Italy and China). The fraud is
               | mislabeling them as Australian or similar, denying
               | consumers from making their own ethical choice. Which is
               | your harm to the end user and generally enforced by the
               | ACCC.
        
               | kkotak wrote:
               | If you're going to start talking about mislabelling
               | products, you're going doing a rabbit hole of hundreds if
               | not thousands of products sold in reputable stores. Look
               | up how FDA labels for Organic, Grass fed, Pasture raised,
               | etc. are used through out the industry in the US and the
               | world. You should also look up the requirements for "Made
               | in X" labels for consumer products. Playing with word and
               | people's emotions on what those labels mean when making a
               | purchase decision is as old as commerce itself. Don't for
               | a moment think of the US or a Western country being
               | rightious about this.
        
               | perpetuallunch wrote:
               | The information this is based on is reporting from the
               | Australian ABC TV program Four Corners.
               | 
               | The ABC is a know, as in they don't even try to pretend
               | propriety, propaganda outlet of the Australia Albanese
               | federal Government.
               | 
               | I'm not saying this is definitely propaganda, but there's
               | a non-zero chance it _is_.
               | 
               | The Albanese government has been very open about
               | attacking industry.
        
               | neves wrote:
               | Chinese workers earn more than workers from latin
               | America. At least their government isn't slave for
               | billionaires
        
               | biztos wrote:
               | While it could of course be produced in Xinjiang
               | _without_ using  "slave labor," the US government banned
               | those tomatoes in 2021 because of that risk:
               | 
               | https://www.cbp.gov/newsroom/national-media-release/cbp-
               | issu...
               | 
               | If Costco were circumventing the ban it'd be a pretty big
               | deal. I couldn't google up any indications that they are,
               | so on balance I'd say it's "possible" in the same way my
               | winning the lottery is possible. Can't rule it out, but
               | reasonable people should probably bet against it.
               | 
               | TIL: Xinjiang tomatoes are something like 15% of the
               | global market!
        
               | seanmcdirmid wrote:
               | > TIL: Xinjiang tomatoes are something like 15% of the
               | global market!
               | 
               | China consumes 37% of the world's tomatoes. 80% of
               | China's processed tomatoes are from xinjiang. Fresh
               | tomatoes are generally grown locally, but that is true
               | around the world.
        
               | LordAtlas wrote:
               | China _produces_ 37% of the world's tomatoes, not
               | consumes.
        
             | bell-cot wrote:
             | Compared to the big e-commerce retailers, Costco's total
             | number of sku's isn't even a rounding error.
             | 
             | And most of Costco's sku's are food, clothing, housewares,
             | bulk consumables, and such - vastly easier to test and vet
             | than computer & internet-connected electronics.
        
               | ChoGGi wrote:
               | Sounds like you're agreeing that Costco is well curated?
        
               | bell-cot wrote:
               | _Compared to_ Amazon and other e-tailers with hundreds of
               | thousands of sku 's of computer & internet-connected
               | electronic stuff, 99% of which they do nothing whatever
               | to curate? Yes.
               | 
               | But that's kinda like saying that Random Pond is safer
               | for swimming than a lava lake.
               | 
               | Do I just assume nothing can go wrong when I myself shop
               | at Costco? NO.
        
             | 40four wrote:
             | I don't disagree, Costco has a reputation for selling well
             | vetted products, but that's not a good comparison. I trust
             | Costco (even their online only sales), but in no way do I
             | trust the other merchants listed.
             | 
             | We're specifically taking about merchants that have a super
             | shady online presence. They will basically sell you
             | anything and everything and don't care if it harms you.
             | 
             | The ones mentioned (Amazon, Best Buy, New Egg), it's going
             | to be hard to argue they vet (or care about vetting) the
             | digital products they sell. You might as well throw Walmart
             | into group too, their online offerings have gotten super
             | sketchy if you really do into it.
        
               | Uvix wrote:
               | Target as well. It was one thing when it was just Amazon
               | acting as a sketchy third party storefront, but now
               | everybody's doing it.
        
             | riddlemethat wrote:
             | We bought a Bosch dishwasher from Costco in January. It was
             | defective and wouldn't start after 10 days. Costco replaced
             | it. The replacement came with a big gash on the front off
             | the truck so we refused it and Costco sent a third
             | replacement. Again, it was the same model and again it
             | wouldn't start after another 30 days. Costco took it back.
             | No cost to us for any of these delivery or install
             | attempts.
             | 
             | We bought a different model from Costco and it's been rock
             | solid. I expect I will never buy a major appliance from any
             | other retailer as long as Costco continues to care like
             | they do today.
        
               | fn-mote wrote:
               | > I will never buy a major appliance from any other
               | retailer
               | 
               | Weird. You experienced failures of the manufacturer
               | (failure to start) and the warehouse (huge scratch), and
               | are still singing someone's praises.
               | 
               | It sounds to me like the brand's quality assurance is low
               | and the retailer also isn't taking care of their stock.
               | 
               | If I had to take three days off work to accept these
               | deliveries, doubtless I would have a very different
               | conclusion from yours.
        
               | dsr_ wrote:
               | He's singing the praises of CostCo, which made him whole.
               | 
               | Any dishwasher could have these problems; any warehouse
               | could. How the seller handles the situation is key to
               | whether you use them again.
               | 
               | CostCo has built a huge reputation for being trustworthy
               | as a retailer. If they get purchased by private equity, I
               | will stop renewing my membership, and think about how
               | close the country is to decorating lampposts.
        
               | _RPM wrote:
               | > I will never buy a major appliance from any other
               | retailer
               | 
               | That's called stinking thinking.
        
               | contagiousflow wrote:
               | What is the alternative? Trust has been built, as long as
               | the trust is not eroded it is safer than any other
               | retailer?
        
               | rpdillon wrote:
               | Yep, I'm pretty much a lifetime member of Costco if this
               | sort of prioritization doesn't change. A recent article
               | put it well "Costco is the anti-Amazon".
               | 
               | I say this as a happy customer of both, though. I don't
               | seem to have the problems others do with horrible
               | products from Amazon, but I suspect my purchasing habits
               | might be different as well.
        
             | red-iron-pine wrote:
             | arguably it's part of their main value proposition: bulk,
             | but not terrible, and generally decent.
             | 
             | fixed fee membership also means a very stable revenue
             | stream and they can take the time to do this, while other
             | places like newegg are herding 3rd parties to get cuts of
             | ever cheaper 3rd party crap
        
             | Rickasaurus wrote:
             | I have to disagree, costco often has custom worse versions
             | of better products, we recently had a costco air
             | conditioner fail just to find out it wasn't built quite as
             | robustly as the $50 more expensive midea sold elsewhere
             | with an almost identical model number. Similarly had my
             | costco GE washing machine fail last year right out of
             | warranty. There's a real quality problem going on with
             | costco right now.
        
               | onemoresoop wrote:
               | They'll replace them if they break and the return policy
               | is very good as well. It's safe to buy from Costco
        
           | Aerroon wrote:
           | You go to an online store to buy a hard drive. It's listed as
           | "in stock" and you buy it and pay for it. A week later you
           | get an email from the store that the specific hard drive is
           | now available at a third party warehouse and they can order
           | it from there, but the price is about 10% higher.
           | 
           | The above actually happened to me. That's what online
           | retailers were like before Amazon's reach properly extended
           | here. That's also the main value proposition for these
           | retailers for me.
           | 
           | Also, online retailers are far more likely to accept returns
           | compared to regular stores. If you get a bad product from a
           | regular store you're often just screwed.
        
             | swatcoder wrote:
             | The late-Amazon process for this is to just send you
             | whatever's marked as the hard drive in their warehouse,
             | which may be that actual product, a counterfeit, or a brick
             | in the hard drive's package.
             | 
             | Later, when you want to try the return, a black box
             | algorithm asseses your transactional value to Amazon and
             | decides whether your concerns are worth attending and to
             | what degree.
             | 
             | Maybe that really is better than whatever you were used to
             | in your own market, but it's a profound regression on the
             | traditional retail experience for most of us here.
        
           | zombot wrote:
           | Crooks will be crooks, but that the lawmakers let them get
           | away with it is something that should change.
        
           | jon-wood wrote:
           | Amazon even have big "people commonly return this product"
           | warning on some product pages. Anywhere halfway sensible
           | would maybe reconsider stocking a product worthy of that but
           | because they've set themselves up as a middleman without any
           | of the risk they can just churn junk out of their warehouses.
        
           | deaton wrote:
           | Online it still seems like for the most part if you buy from
           | something a bit more specialty (e.g. McMaster, Digikey, etc)
           | you still get really good vetting and high quality stuff, but
           | amazon is more than happy to be filled with absolute garbage.
        
         | boondongle wrote:
         | Just being realistic here; many of these are of Chinese make so
         | how exactly would you stop it other than blocking them from
         | being sold. They certainly don't advertise to the big box
         | retailer that buys them "and it uses the customer's internet
         | connection for fraud."
         | 
         | Hell, there's a section of comments that would probably going
         | "hey, RELAX guy" because it's not US companies doing this. For
         | any American companies that do this though, sure -
         | block/suspend/prosecute.
        
           | malfist wrote:
           | If I open my own line of home improvement stores and do no
           | oversight on what I sell and wind up selling really dangerous
           | lawnmowers, I'm partly responsible.
           | 
           | Or if I open up a gas station and allow any company without
           | oversight to sell "supplements" through my shelves and cops
           | arrest me for selling heroin, I don't get a free pass.
           | 
           | Why should amazon or Walmart get a free pass just because
           | they sell more items?
        
             | awakeasleep wrote:
             | One problem I see with your analogy is that the dangerous
             | lawnmower can cause an easily quantifiable harm.
             | 
             | You have to be able to show damages you incurred and assign
             | a dollar value to them to sue people.
             | 
             | That doesn't work at all for a something that sells your
             | bandwidth to a proxy service. People wouldn't even be aware
             | that it was happening they weren't told.
        
               | SoftTalker wrote:
               | What about when the police show up because some highly
               | illegal content was traced to your IP address? Will they
               | believe that you were the unwitting victim of a rogue
               | proxy server running on your streaming stick? Would you
               | have even been aware of that possibility?
        
               | xorcist wrote:
               | There's also always the flip side: When the police shows
               | up because of your illegal acitivities, you have a rogue
               | proxy server running. All bought in good faith of course.
               | 
               | Not legal advice.
               | 
               | (It would surprise me greatly if we as a society let
               | these gadgets be sold openly from here on.)
        
               | ndsipa_pomu wrote:
               | That shows the problem or trying to link an IP address to
               | an individual.
        
               | inigyou wrote:
               | Believe it or not, that is what happens when the police
               | show up to the house of a primary school teacher. They
               | will think they have the wrong address. Even US police.
               | 
               | The cybercrime raids happen when they run into someone
               | who looks like a hacker and has a lot of computers.
        
             | wsintra2022 wrote:
             | Except the devices are not dangerous. Its the software
             | installed on the device. Consumers have a choice. Pay for
             | the trusted Apple TV or Amazon firestick, or go the wild
             | west and see what's on offer.
        
               | CrazyMusicians wrote:
               | with the devices mentioned in the article, there is no
               | consent requested, and the malicious apps are installed
               | either before the box is sold or after as a requirement
               | for getting the streaming services to work.
        
               | inigyou wrote:
               | You call them malicious apps but what is the evidence
               | they are more malicious than the things they fight
               | against?
        
               | jon-wood wrote:
               | Really? You'd be ok with me putting a proxy server on
               | your home network then, which anyone with a few bucks can
               | use to attach your IP address and subscriber details to
               | anything they choose to request from the internet? How
               | about a Tor exit node?
               | 
               | Its incredibly obvious to anyone applying any thought at
               | all to this that its a malicious to sell a product that
               | labels itself as a TV streaming stick which is in fact a
               | paid for relay server with the money made from providing
               | the internet connection to a random third party unrelated
               | to the person who bought the thing without ever telling
               | the customer.
        
               | inigyou wrote:
               | Yeah I actually do several of those to earn a few bucks.
        
               | jon-wood wrote:
               | The typical consumer has no idea what they're buying, and
               | they shouldn't have to because the retailer selling the
               | product should have done some basic due diligence before
               | stocking the thing. People aren't going to some clearly
               | shady Chinese website and buying a device labelled "cheap
               | TV streaming stick, will sublease your internet
               | connection to criminals", they're putting "FireTV" into
               | amazon.com and somehow being presented with these things
               | alongside the Amazon FireTV they expect to find, or maybe
               | "streaming stick" which really shouldn't be surfacing
               | clearly malicious products.
        
               | inigyou wrote:
               | If the average consumer did get a disclaimer it would
               | sublease their internet connection to a few criminals and
               | a lot of people who aren't criminals, would they care?
        
             | II2II wrote:
             | > If I open my own line of home improvement stores and do
             | no oversight on what I sell and wind up selling really
             | dangerous lawnmowers, I'm partly responsible.
             | 
             | While there would be oversight, it is highly unlikely that
             | a person opening a home improvement store would perform any
             | meaningful safety testing. They simply would not be
             | qualified. The oversight would lay in selling certified
             | products, pulling recalled products off the shelf, and
             | (perhaps) removing products if there is a reason to suspect
             | safety issues.
             | 
             | Now consider streaming sticks. There are safety standards
             | for the physical device but, to my knowledge, there are no
             | such standards for the software itself. Heck, there aren't
             | even standards for the engineers who work on the software.
             | One can make highly prejudiced decisions based upon the
             | country of origin. Perhaps there are even good reasons to
             | avoid products from certain countries. Yet the lack of
             | standards also means that products from trustworthy sources
             | can be suspect, since all it takes is a management decision
             | to change things.
        
             | inigyou wrote:
             | But these products aren't dangerous. And proxying internet
             | traffic isn't illegal. Fake ad clicks may be illegal but
             | that falls on whoever is providing that service, which
             | isn't the proxy or the resident. On what basis would you
             | ban them?
        
           | AngryData wrote:
           | But it is a retailer's responsibility to know what they are
           | selling. If it was added after they started selling it and
           | hidden in secret, sure a retailer might have an excuse. But
           | it isn't really hidden, most often its put in their marketing
           | materials as a benefit and have been knowingly doing it for
           | many years now.
           | 
           | US retailers can be told they can't sell it here. If you buy
           | it outside of that, well that is buyer beware, but 99% of
           | people aren't buying things from Alibaba or ordering from
           | some random foreign store, they are buying them off US
           | Amazon, Walmart, big box retailers, etc. You don't have to
           | ban things consumer level to deal with 99% of it, you just
           | gotta tell big corporations no and stop dismissing any ideas
           | that put responsibility or liability on big business.
        
             | crote wrote:
             | The problem is that Amazon, Walmart & friends have said the
             | "we are a _platform_ , not a retailer" magic incantation,
             | which means that through the power of friendship and
             | unicorns they are now suddenly no longer responsible for
             | the stuff they sell.
             | 
             | And the "retailer" on record is of course not a real
             | company. They'll just pay some third-party to file a bunch
             | of paperwork in Delaware, pay the $110 fee, and let it go
             | bust if anyone tries to investigate it or make it liable.
        
             | pixl97 wrote:
             | >If it was added after they started selling it
             | 
             | While it's great we're getting the manufactures to just
             | stop sending out straight malware and it should be stopped
             | the next most obvious means of attack is just having the
             | device update and add superaids to it's new functionality.
             | 
             | So, no, it won't stop 99% of it at all.
             | 
             | And honestly this isn't that much different from what US
             | companies are already great at by providing updates that
             | take away features we bought with the device.
             | 
             | And not just updating really doesn't save you, instead of
             | being part of a factory botnet, you're just open to become
             | part of some other botnet.
        
           | crote wrote:
           | > Just being realistic here; many of these are of Chinese
           | make so how exactly would you stop it other than blocking
           | them from being sold.
           | 
           | You already answered it: block it from being sold.
           | 
           | 1) Make Amazon responsible for the products they are selling.
           | 2) Introduce a law banning malware tv sticks 3) Sue Amazon
           | for a percentage of their yearly revenue when caught
           | violating it 4) Amazon will _finally_ start caring and do
           | _some_ kind of review on the crap they sell.
        
             | pixl97 wrote:
             | And if the first time you get it online it just updates
             | itself to malware?
             | 
             | That's the biggest problem with any device that updates.
             | 
             | Yea, this will work for the moment and the seller will be
             | covered in the sense that "well, it wasn't infected when we
             | sold it".
        
               | deaton wrote:
               | The law is not software. It would be very easy to argue
               | that a streaming stick that automatically downloads
               | malware is no different from one that came with malware.
        
               | pixl97 wrote:
               | And that's where the retailer is no longer in the loop,
               | which is what this thread was about.
        
             | StilesCrisis wrote:
             | If it's malware, maybe existing laws apply already. I think
             | the bigger problem is enforcement. In China, it's easy to
             | close up shop if anything goes wrong and then just start
             | over. Any liability dies with the brand name.
        
             | themaninthedark wrote:
             | I think a law that makes a marketplace responsible for
             | items being sold if the qty of items is above a threshold
             | would be a great idea.
             | 
             | You don't want to penalize someone selling their Xbox or
             | lawnmower on Ebay but you want to stop what is going on
             | here. A place like Etsy where people are selling their
             | crafts is an interesting edge case but I think they should
             | probably be a little regulated.
        
           | skybrian wrote:
           | The FCC tests electronics for radio interference. Perhaps
           | they could test electronics for Internet behavior like this
           | too?
           | 
           | Some manufacturers will try to cheat on the tests, but we
           | have AI security checking now, so maybe that would make it
           | harder to cheat?
        
             | iamnothere wrote:
             | That sounds like a fast track to government control of what
             | operating systems are allowed. These aren't just
             | electronics, they are low power computers that happen to
             | have an OS and software preinstalled.
             | 
             | (I'd be open to a rule that devices must allow users to
             | wipe the devices and install their own OS.)
        
               | skybrian wrote:
               | On the other hand, I suppose if the OS on a TV stick ran
               | in a hardware-enforced sandbox that restricted network
               | access to certain necessary domains, it couldn't be used
               | for scraping websites and ad fraud? It's not being sold
               | as a general-purpose computer so maybe it shouldn't be
               | one.
        
           | lesostep wrote:
           | Simple. Buy one, put it on a test stand, and look at
           | connection log.
           | 
           | Buying in bulk for a resell without testing even one product
           | is kinda insane.
        
         | ryandrake wrote:
         | I would very much be in favor of grocery stores sharing
         | responsibility (and regulatory penalties) for selling tainted
         | food! It's kind of mind boggling that this is controversial.
         | "Buyer beware" is not an acceptable basis for society to
         | function.
        
           | SoftTalker wrote:
           | I can't think of a case where a supermarket, upon becoming
           | aware of a problem with a food product, didn't immediately
           | pull it from the shelves, post a notice to customers, and
           | offer a full refund to anyone who had purchased it.
        
           | StilesCrisis wrote:
           | This is unfortunately exactly how society operates in China.
           | It is basically on the buyer to confirm that they're getting
           | something acceptable. Once they've paid, it is what it is.
        
             | fragmede wrote:
             | Not exactly. In 2008 there was a huge scandal where
             | melamine was in baby's milk, so it isn't always what it is.
             | 
             | https://en.wikipedia.org/wiki/2008_Chinese_milk_scandal
        
               | StilesCrisis wrote:
               | Yes, if your malfeasance is large enough to be on the
               | front page of the New York Times, you'll be sentenced to
               | life in prison or even death. But killing babies is a bit
               | more heinous than fraudulent ad clicks!
               | 
               | (Also of note: WHY melamine in the baby formula? Because
               | they knew the buyer would check the nitrogen content,
               | because it's a caveat emptor culture.)
        
         | mattmcknight wrote:
         | This is why I hate the "marketplace" of these stores. In many
         | cases these products never hit their inventory at all, they are
         | functioning like a search engine and payments processor.
        
           | eddythompson80 wrote:
           | That's generally in their definition. "Amazon Marketplace"
           | came out in 2000 allowing 3rd party sellers on their
           | platform. However, until maybe the mid 2010s, they favored
           | product sold by Amazon over 3rd party in their results and
           | recommendations. I remember numerous forum and Reddit posts
           | from the late 2000s about "How Amazon scams 3rd party
           | sellers" by only wanting them there to give the illusion that
           | they have everything but once some category starts selling,
           | they will vendor it too and steal your customers.
           | 
           | At some point in the second half of the 2010s Amazon figured
           | out they can't compete with a million foreign randomly-
           | generated companies on price, and their users didn't seem to
           | mind too much. They figured their users cared about delivery
           | times, ease of returns, ease of dealing with Amazon instead
           | of dozens of online sellers, etc and they leaned heavily into
           | that. They will handle fulfillment and take their cut and let
           | people buy whatever garbage they want. They still screw
           | sellers too btw. Ask any one who is trying to sell something
           | on Amazon and they will fill your ear with how much leverage
           | amazon has over them. You can check r/FulfillmentByAmazon/ Or
           | r/AmazonSellers for stories.
        
         | bashtoni wrote:
         | Yes, fascinating that this is apparently all the fault of
         | Chinese companies, and not the American companies distributing
         | and retailing these products.
        
           | themaninthedark wrote:
           | Um...If I make an app that reroutes people's payments so that
           | I can skim a percent off the top and release it for Android
           | and IPhone as a shopping app, how would it be Google and
           | Apple's fault?
           | 
           | Sure they try to vet the app but how does that absolve me
           | from the liability?
        
         | ChuckMcM wrote:
         | In the US at least there is a lot (and by that I mean like
         | maybe more than half) of civil case law around seller liability
         | for defective or 'dual use' products. In the 70's some cities
         | tried to sue hardware stores for selling spray paint that
         | taggers were using, in several jurisdictions you can find
         | authorities trying to sue vendors of lock picking and/or safe
         | opening tools, etc. My non-lawyer reading of all that is that
         | if it is reasonable to assume that the vendor didn't know, _at
         | the time of sale_ , what the customer was going to do with it,
         | they aren't liable.
         | 
         | Once a vendor has been notified that these units are doing
         | these sorts of things they will stop selling them. Its sadly
         | very prescriptive in that if Newegg gets a notice that
         | "WatchFunTV" streaming sticks are doing this, they will remove
         | that brand but if the same hardware shows up from the same
         | vendor as "SuperTVStreamer" or some such, _that_ product won 't
         | be banned until someone does the test and then notifies the
         | sellers. It's cat and mouse all the time.
         | 
         | Now the people who _could_ do something about it, the ad
         | networks like Google, do not do anything because ad revenue is
         | ad revenue, people buying the ads cannot prove that the click
         | was false so hey who can say it was? Which is why ad fraud is a
         | perennial favorite of crooks. The people being ripped off don
         | 't have any way to prove it without a lot of support from the
         | ad network traffic data which is "proprietary". Really stupid
         | ad fraud gets shut down, but put a bit of care into it so that
         | the Ad network and claim ignorance? You can do that all day.
         | Just don't get greedy and try to pull in more than say 30 or 50
         | thousand dollars a month. Remember, the IAB said in 2025 alone
         | Ad Revenue was $300B[1] so 2% of that is only $6B and any
         | network with 2% or less of undetected fraud is considered a
         | "high quality" ad network.
         | 
         | So yeah, ad fraud is the gift that keeps on giving.
         | 
         | [1] https://www.iab.com/insights/internet-advertising-revenue-
         | re...
        
         | sneak wrote:
         | Tainted food and unsafe children's toys kill people.
         | 
         | Sketchy devices on your wi-fi don't really harm anyone. They're
         | a minor inconvenience at best, mostly to large corporations
         | that like to discern residential connections from
         | business/corporate ones.
        
           | inigyou wrote:
           | I don't know why this is such an unpopular opinion on HN.
        
             | red-iron-pine wrote:
             | you don't get why a news aggregator for tech bros have
             | problems with crappy devices hacking them?
        
               | inigyou wrote:
               | What is being hacked? The ad industry? I didn't know the
               | average HNbreader had such deep compassion for _the ad
               | industry_.
        
         | tclancy wrote:
         | This is one of those things where I, as a suburban white kid,
         | am so happy I discovered Public Enemy and similar bands as a
         | kid.
         | 
         | "Money talks. And bullshit brothers walk a marathon."
        
         | tomjen3 wrote:
         | Probably because doing so would mean a lot fewer product
         | categories. It's a trade-off, to be sure. But if you need that
         | odd thing -- a screw of a certain type, a power supply that's
         | 56 volt DC or whatever -- then if there's only going to be
         | sold, say, a few thousand of those a year, if Amazon was
         | required to do product safety testing on them, they probably
         | wouldn't be able to sell that category at all. And so the
         | trade-off is they are not required to.
         | 
         | Now that's very different from "we are selling things that we
         | know, or have good reason to know, specifically are dangerous"
         | -- here they might very well be liable.
        
       | phendrenad2 wrote:
       | On the other hand, these are great little devices to root and put
       | Linux on.
        
       | buellerbueller wrote:
       | To those who are OK with these devices: when you engage in
       | corruption, do you have any moral standing against your
       | politicians when they engage in corruption?
       | 
       | Both you, and the corrupt politicians, are eating away at the
       | trust that underpins society. Certainly, you can argue, your bite
       | is just a tiny one; the politician is eating the whole apple.
       | 
       | At the end of the day, everyone suffers from the decline of trust
       | and casual acceptance of fraud.
        
       | PufPufPuf wrote:
       | My "streaming device" of choice, ThinkCentre Tiny with Linux,
       | always feels validated with news like these. It fits behind a TV,
       | you can get it second hand for around $40 and depending on model
       | it can even act as a retro game console as well.
        
         | CrimsonCape wrote:
         | Is there a good TV UI OS that runs desktop youtube under the
         | hood for ad blocking?
        
           | jojobas wrote:
           | There is Kodi Youtube plugin that takes a developer token and
           | is then ad-free.
        
           | PufPufPuf wrote:
           | I use the VacuumTube app
           | (https://flathub.org/en/apps/rocks.shy.VacuumTube), which has
           | ad block, sponsor block, and some more advanced settings! You
           | can use GNOME with scaled up UI or KDE Bigscreen (recently
           | resurrected) for the DE.
        
       | burgreblast wrote:
       | Google clutches pearls and is shocked! Shocked! That anyone would
       | violate its policies (while it pockets 30% of the fraudulent
       | revenue). Shocked!
       | 
       | And they would have caught them but those crafty criminals
       | spoofed the user-agent. So how _could_ they know?
        
       | scottydelta wrote:
       | After getting tired of ads on my PAID smart TV, 6 months ago I
       | started building a casting device using raspberry pi for myself.
       | A couple of months later one of my friends who is an AV
       | technician ended up using it at the largest convention venue in
       | Barcelona to play content on loop, here's a video of that:
       | https://www.youtube.com/shorts/FF3I9EOs4AA.
       | 
       | Fast forward to last month, now I have started selling these in
       | Barcelona, Spain where I am based out of and branched it into
       | three use cases: digital signage, casting, and a portable
       | computer for presentations at events. Here is the link with
       | features: https://soljacast.com
        
         | emacdona wrote:
         | Clicked on the link, ready to buy one. "Contact sales". Ew. No
         | thanks.
        
           | scottydelta wrote:
           | We are literally new and only available in Barcelona at the
           | moment which I mentioned in my comment as well. Not sure
           | what's eww about that?
        
             | emacdona wrote:
             | Sorry, knee jerk reaction any time I see "contact sales"
             | instead of a price.
        
               | scottydelta wrote:
               | No worries. If you message me via the contact form or
               | chat support on the website, I will try my best to
               | provide you with one. The more feedback I can get, the
               | better.
               | 
               | Thanks for liking my product enough to want to buy it
               | right away :)
        
               | cryptoegorophy wrote:
               | Sales friction is how you lose sales. Make your website
               | one click purchase product page. One button - apply pay,
               | customer pays with preset shipping and then you handle
               | everything from there.
        
               | scottydelta wrote:
               | Trust me, I really wish it were that easy. We're based
               | out of Spain, so to sell in the US (or other countries)
               | we either need to figure out assembly of the device
               | there, or we need to solve cross-border payments,
               | logistics, customs clearance, tax remittance to
               | individual states, and hardware compliance. That said,
               | we're working hard on all of it and plan to go D2C as
               | soon as possible.
        
               | throwawsy7273 wrote:
               | I haven't used them myself, but it seems that services
               | such as paddle.com takes care of the payment and tax
               | compliance. There are probably similar sevices for
               | logistics as well.
        
               | scottydelta wrote:
               | The thing is majority platforms like paddle.com don't
               | supoort hardware products. I was looking at fastspring as
               | well but hit the same wall. I will still try reaching out
               | to paddle.com support to see if they will allow it. Thank
               | you for the suggestion.
        
               | crote wrote:
               | Your device seems to be an off-the-shelf Raspberry Pi
               | running custom software. Have you considered making the
               | platform available in a BYOD form, either for fulltime
               | use or for evaluation?
        
               | scottydelta wrote:
               | Yes, we're using an off-the-shelf Raspberry Pi for v1. We
               | are working on figuring out a custom board for v2,
               | because we can't scale with Raspberry Pi as a dependency,
               | especially with RPi prices constantly rising due to the
               | RAM shortage.
               | 
               | Also, we want to test our OS extensively before we
               | release it to be used with a BYOD model. We are launching
               | soon and after that we will try to offer BYOD model as
               | well.
               | 
               | If you are interested in trying it out and helping me in
               | evaluation, please reach out to me via email on my HN
               | profile. Thank you
        
             | 0manrho wrote:
             | I believe they're referring to the friction point of this
             | company/website not publicly listing a price. That's a huge
             | barrier/red flag to a lot of people. Myself included. Last
             | thing I want to do is waste time bouncing emails back and
             | forth between sales just to figure out if the price range
             | is even remotely in my wheelhouse.
             | 
             | However, if your target is B2B (Business to Business) as
             | opposed to B2C/D2C (Business to Client/Direct to Client)
             | and you're selling the install plus enterprise support,
             | then the sales thing makes way more sense, and is more
             | expected/palatable for B2B type customers than your
             | everyday consumers, so depends on who you're targeting.
        
               | scottydelta wrote:
               | We are working on figuring out payments, logistics,
               | hardware compliance (different countries have different
               | requirements), state-level tax handling, customs
               | clearance, etc. for D2C.
               | 
               | Also right now we are focusing on B2B here in Spain like
               | you guessed, and once we have the other things figured
               | out, we will start shipping to the US and Europe. And
               | after that we plan on rolling out to the rest of the
               | countries.
        
             | crooked-v wrote:
             | The "eww" part is that normally, anytime you see "talk to
             | us for a price", that means someone is charging an absurdly
             | high amount for the good or service.
        
               | scottydelta wrote:
               | I see, the thing is we are very new and plan on launching
               | soon. We are still trying to figure out our B2C/D2C
               | pricing.
        
             | TiredOfLife wrote:
             | "contact sales" literally means expensive shitty product.
        
         | sajithdilshan wrote:
         | your product looks cool, but why do I need to contact sales to
         | buy that device? can't you just open like a shopify shop and
         | redirect end customers to that? Also showing the retail price
         | on the page would be a plus one
        
           | scottydelta wrote:
           | Thank you for your kind words. I am pasting one of the
           | comments I made on this thread regarding challenges with
           | online sales at the moment:
           | 
           | > Trust me, I really wish it were that easy. We're based out
           | of Spain, so to sell in the US (or other countries) we either
           | need to figure out assembly of the device there, or we need
           | to solve cross-border payments, logistics, customs clearance,
           | tax remittance to individual states, and hardware compliance.
           | That said, we're working hard on all of it and plan to go D2C
           | as soon as possible.
           | 
           | For the pricing part, I am still trying to figure out the
           | pricing for retail consumers. It was relatively easier to do
           | for B2B but for retail, there are a lot of factors and moving
           | parts such as import duties, taxes, shipping etc.
        
       | Doohickey-d wrote:
       | Krebs' blog is nice, but quite often it's just re-reporting stuff
       | from somewhere else:
       | 
       | Original with more details: https://www.bitsight.com/blog/fuyao-
       | enterprise-building-ad-f...
        
       | crote wrote:
       | LG televisions and monitors spy on their users and install
       | unwanted software. _Half_ of all smart tvs are running
       | "residential proxy" malware. Google is banning sideloading but
       | happily hosting apps using the Bright SDK.
       | 
       | Sorry, but "your tv stick does ad fraud" is just about the most
       | innocent thing I've seen in a while. _Everyone_ in this market is
       | doing the shadiest shit you can imagine. There are no good brands
       | left, you just get to pick what logo your Malware Entertainment
       | Device has.
        
         | inigyou wrote:
         | Is it even really malware if it's harming advertising networks
         | and not you?
        
       | cwillu wrote:
       | "as part of a sprawling operation that seeks to defraud online
       | merchants and advertising networks."
       | 
       | Oh no! Not the advertising networks!
        
       | atum47 wrote:
       | Got myself a mi box with a custom launcher. Way better than any
       | other Smart TV out there. Unless there's a smart tv that does not
       | show ads right on the fing front page.
       | 
       | Anyway, the box is powerful enough to do several things. You can
       | install a IP tv if you want. If you don't, you still have a
       | pretty good media center (you can hook up an external hd on it)
        
         | Scoundreller wrote:
         | Though I do then wonder about some of the iptv apps even the
         | ones provided through paid subscriptions but that's already on
         | the dark side; but not as dark as these "buy once" 1000s of
         | pirated channels devices
        
         | aucisson_masque wrote:
         | The Xiaomi box also send lots of data to Xiaomi server but also
         | ads/tracking network.
         | 
         | I switched to a Google box, this has no bloatware and this way
         | I get tracked only by one company.
        
       | shmuli9 wrote:
       | This is amazing. Kudos to the team behind it I mean, sucks for
       | advertisers and is utterly deceitful... but genius!
        
       | tomaskafka wrote:
       | At this point China probably has a botnet that can be turned on
       | with a few deploys, and spans a majority of homes in US and RU
       | (and thus is unblockable without disconnecting half of voters
       | from the internet). Ready to attack the infrastructure.
        
         | bashtoni wrote:
         | I don't know where you get the idea this is a nation state
         | attack.
         | 
         | The devices are used to sell proxy services and scam
         | advertisers. This doesn't even need particularly large
         | organised crime. It would certainly be easier than large scale
         | illicit drug importation and retail, which is happening all the
         | time.
         | 
         | Could China exploit these streaming sticks if it wanted to?
         | Maybe, but no more than any other nation.
        
           | tossingafterxyz wrote:
           | Not necessarily correlated to this, but my perception is that
           | china is generally ok with many types of crime as long as
           | it's not perpetrated on its citizens / aimed at foreigners
           | (IP theft / counterfeit goods / cyber crime etc). However, I
           | also think the state largely has a good sense of the actor or
           | players and is perfectly capable of exerting force or
           | coercing them to their cause at will.
        
       | munk-a wrote:
       | Read this:
       | 
       | Use a computer - you actually control the content that way.
        
       | zeroq wrote:
       | tangent thought experiment
       | 
       | So you bought that top of the line security-as-a-product thingy
       | you can stick in your rack and it will make sure that your
       | network is impenetrable? You know, like those CISCO bricks
       | everyone major company is buying.
       | 
       | So have you took an extra precautions to make sure that the
       | firmware on the device is pristine? Do you know anyone who ever
       | touched these devices who actually did?
       | 
       | Do you see the problem?
        
         | jojobas wrote:
         | Cisco bricks leave the factory as pristine as they can be. An
         | intercept sort of attack is possible, but involve quite some
         | effort and risk.
         | 
         | These sticks leave the factory with malware pre-flashed, the
         | postman brings them to your door with zero risk for the
         | beneficiary.
        
       | shevy-java wrote:
       | > they secretly rent the user's Internet connection out to
       | strangers
       | 
       | So the mafia is back.
        
       | jms703 wrote:
       | You buy garbage, you get garbage. You can no longer depend on
       | resellers or to protect you. They are unphased and unaffected by
       | selling you this garbage. No one else has a financial incentive
       | to protect you. Sorry if this sounds victim blamey. Don't mean it
       | to be. Just trying to convey that we're on our own.
        
       | byterivet wrote:
       | Good job.
        
       | dxxvi wrote:
       | Ah, got it. Those devices are like computer virus which don't
       | need a computer to live on.They can make DDOS attacks if they
       | want to. So, buying these devices at a cheap price is like
       | renting out your IP address and your Internet connection.
        
       | BigTTYGothGF wrote:
       | > these devices also routinely spoof themselves as mobile phones
       | clicking ads on AI-generated websites as part of a sprawling
       | operation that seeks to defraud online merchants and advertising
       | networks.
       | 
       | Every cloud has a silver lining.
        
       | ColdStream wrote:
       | Alternatively, if you are going to do some questionable things,
       | just buy loads of these things and create a hundred back doors on
       | the network to increase the noise.
       | 
       | Sounds good in theory but in practice, computers are good at
       | sorting this stuff out. Kind of why they are so popular.
        
       | estebarb wrote:
       | Oh wow, even scammers care about usability and their employees'
       | well-being. What's the excuse for bad UX in internal company
       | software?
        
       | perpetuallunch wrote:
       | > rent the user's Internet connection out to strangers.
       | 
       | Harm to the user: none^
       | 
       | > spoof themselves as mobile phones clicking ads on AI-generated
       | websites as part of a sprawling operation that seeks to defraud
       | online merchants and advertising networks
       | 
       | Harm to the user: none^
       | 
       | Cost to the dodgy service provides: none
       | 
       | Government action to prevent continued dodgy services: none^
       | 
       | This is why internet securityg doomers have a hard time selling
       | their story. Changing behaviour has an upfront, immediate, cost.
       | Not changing it doesn't.
       | 
       | ^close enough
        
         | charonn0 wrote:
         | >> rent the user's Internet connection out to strangers.
         | 
         | > Harm to the user: none^
         | 
         | Well, they _are_ losing some of their bandwidth. They might not
         | notice, but something which is rightfully theirs is being taken
         | without consent.
        
           | perpetuallunch wrote:
           | If they don't notice, and they're on an unlimited data plan,
           | or the usage is such that it doesn't result in exceeding
           | their data cap, what argument is there that harm occurred?
        
       | thothless wrote:
       | roku is sniffing your farts. and reading your texts/emails.
       | 
       | https://docs.roku.com/published/userprivacypolicy
       | 
       | see: "olfactory", "content of"
       | 
       | or at least they're CYA while they're sniffing.
       | 
       | they definitely scan the entire local network.
        
       | theendisney wrote:
       | Long ago I ponder giving away free computers but an ethical
       | formula is really hard. It seemed profit starts to scale
       | exponentialy just beyond the line.
       | 
       | (Acepable would be something like 1TB worth of gamedemos)
        
       | miohtama wrote:
       | This is why Google/Meta is pushing for "age verification".
       | 
       | 1. They want more as targeting data on you
       | 
       | 2. They want to reduce bot clicks
       | 
       | It's an unholy alliance with governments who want to know who
       | writes what online.
        
         | inigyou wrote:
         | I'll take residential proxies over mass surveillance any day.
         | It seems surveillance will always expand unless countered.
        
       | neves wrote:
       | I really don't mind anymore. My Roku stick is now owned by
       | extreme right Fox Corporation. Chinese ad click network are petty
       | villain compared.
        
       | wao0uuno wrote:
       | If you have a Raspberry Pi 5 gathering dust somewhere and need a
       | new streaming box then try LibreELEC. It decodes 4k content just
       | fine. It has HDMI CEC. It can stream from local server or play
       | directly from attached storage. There are no ads or
       | tracking/profiling. It can play YouTube without ads but there is
       | no support for Netflix, Apple TV or similar streaming services.
        
         | dspillett wrote:
         | A Pi4 does the job well too. They can be had noticeably cheaper
         | than Pi5s ATM, if you don't have the luck of having a device
         | lying around ready to be repurposed, and even the 1Gb models
         | are plenty sufficient.
         | 
         | A Pi3 may suffice even, that is what I ran Kodi on before
         | upgrading it to the Pi4, though the lack of hardware x265
         | decoding support is a limiting factor there (IIRC it'll manage
         | 1080p in software, but only if you have some good cooling
         | installed otherwise things get very skippy after a short while
         | as thermal throttles kick in).
        
       | joeisnotjane wrote:
       | Ah, it's about "China, China.."
       | 
       | Preparing casus belli.. first, open weights LLM which are "not
       | secure", now "TV sticks"..
       | 
       | Oh joes and janes, who will put finally some sense into you..
        
         | Ikatza wrote:
         | Ah, yes, the great TV sticks war of 2028. We'll tell the
         | stories.
        
           | joeisnotjane wrote:
           | It is about gradually, but constantly, creating the image of
           | an "evil adversary".. Venome drop after venome drop..
           | 
           | China is not doing that as far as I know. Neither Russia did
           | it before the war, though you were claiming the contrary (I
           | know, since I live in the west and could compare news from
           | both sides, being a native Russian speaker).
        
       | inigyou wrote:
       | Krebs fails to make any case for why someone wanting to watch
       | movies and TV should give a shit.
       | 
       | I get that these products are personally inconvenient to Brian
       | Krebs and his work, and to companies that make money blocking
       | people from accessing the internet, and to companies that make
       | money spewing ads in people's faces. So? Why should anyone care
       | about any of those? In fact I think some people would get one of
       | these sticks just to inconvenience the latter two groups!
        
       | AlexandrB wrote:
       | This is only _slightly_ more malicious than the software  "Smart
       | TVs" already ship with.
        
       | stevetron wrote:
       | Birds Nest soup with Chinese tomatoes?
       | 
       | Or Cinese noodles with Chinese tomatoes?
       | 
       | It sounds likw 2 domestic markets that China should use to rid
       | themseves of their over-abundance of tomatoes.
        
       | coretx wrote:
       | The most relevant difference between using a TV and a "TV
       | streaming stick" is corpos & the State controling the
       | malware/surveillance device.
       | 
       | Being a ordinary person, I do not want criminals or the (
       | ads/data ) industry or the state to be in control of my property.
       | 
       | Also, any DRM not passed by a parliament undermines the rule of
       | law & statehood. This is something Krebs and his Praetorian guard
       | buddies _must_ know.
        
       ___________________________________________________________________
       (page generated 2026-07-31 16:01 UTC)