> Despite repeated warnings from the FBI and security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands
I scanned the comments and I didn't see anyone suggesting that these companies should share any responsibility for selling these harmful products. Why is it that they seem to get a pass? Would we feel the same about giant retailers selling tainted food, or unsafe children's toys?
One of the main value propositions for retailers in a world of endless cheap garbage being sold online, is to vet products so customers can trust that what their buying is from a legitimate company and not junk or stuff like these streaming sticks.
This is the problem with being an “everything store”. “Everything” includes a lot of things most consumers would like to be protected from, and assume they are due to the long history of retailers standing behind the products they sell. That history seems to have come to an end. They only stand behind it enough to offer a refund if there is a problem, not to ensure it’s good before selling it.
Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold. They certainly don't advertise to the big box retailer that buys them "and it uses the customer's internet connection for fraud."
Hell, there's a section of comments that would probably going "hey, RELAX guy" because it's not US companies doing this. For any American companies that do this though, sure - block/suspend/prosecute.
> Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold.
You already answered it: block it from being sold.
1) Make Amazon responsible for the products they are selling. 2) Introduce a law banning malware tv sticks 3) Sue Amazon for a percentage of their yearly revenue when caught violating it 4) Amazon will finally start caring and do some kind of review on the crap they sell.
If I open my own line of home improvement stores and do no oversight on what I sell and wind up selling really dangerous lawnmowers, I'm partly responsible.
Or if I open up a gas station and allow any company without oversight to sell "supplements" through my shelves and cops arrest me for selling heroin, I don't get a free pass.
Why should amazon or Walmart get a free pass just because they sell more items?
One problem I see with your analogy is that the dangerous lawnmower can cause an easily quantifiable harm.
You have to be able to show damages you incurred and assign a dollar value to them to sue people.
That doesn’t work at all for a something that sells your bandwidth to a proxy service. People wouldn’t even be aware that it was happening they weren’t told.
What about when the police show up because some highly illegal content was traced to your IP address? Will they believe that you were the unwitting victim of a rogue proxy server running on your streaming stick? Would you have even been aware of that possibility?
Except the devices are not dangerous. Its the software installed on the device. Consumers have a choice. Pay for the trusted Apple TV or Amazon firestick, or go the wild west and see what's on offer.
But it is a retailer's responsibility to know what they are selling. If it was added after they started selling it and hidden in secret, sure a retailer might have an excuse. But it isn't really hidden, most often its put in their marketing materials as a benefit and have been knowingly doing it for many years now.
US retailers can be told they can't sell it here. If you buy it outside of that, well that is buyer beware, but 99% of people aren't buying things from Alibaba or ordering from some random foreign store, they are buying them off US Amazon, Walmart, big box retailers, etc. You don't have to ban things consumer level to deal with 99% of it, you just gotta tell big corporations no and stop dismissing any ideas that put responsibility or liability on big business.
I would very much be in favor of grocery stores sharing responsibility (and regulatory penalties) for selling tainted food! It's kind of mind boggling that this is controversial. "Buyer beware" is not an acceptable basis for society to function.
I can't think of a case where a supermarket, upon becoming aware of a problem with a food product, didn't immediately pull it from the shelves, post a notice to customers, and offer a full refund to anyone who had purchased it.
This is why I hate the "marketplace" of these stores. In many cases these products never hit their inventory at all, they are functioning like a search engine and payments processor.
Probably because we have little to no way to punish those companies. We can't even stop DJI from shipping their drones under other brands to get around the ban.
Our government chooses to not punish those companies. Unfortunately, the lawmakers have decided that the donations to their PACs are more important than actually doing something about it.
We purchased a Chinese-made projector from Amazon, which was surprisingly inexpensive (~40 USD). Upon connecting it to the internet, it placed a constantly running feed of ads on the corner of the screen, even while movies were playing. There was no way to disable it either. Even though it's not a stick, it's a similar principle.
I remember reading an analysis on one of those projectors; the author found a residential proxy running on their device. I would recommend keeping these things off the internet.
To be fair, everything is Chinese made. I would be even the Apple TV and NVIDIA Shield are made in China and if a state actor is determined to get a malicious payload in....
To play devil's advocate, when someone says "Chinese made" they're usually well aware of your point, and are more using it as a common way to describe product mills spitting out countless devices with dubious quality or configuration.
Of course theres good products made in China, and plenty of entirely Chinese brands killing it doing their thing.
This isn't about state actors though. There's a world of difference between a name brand (possibly even a Chinese one) versus what I would term "chineseum". It's nothing to do with China per se and everything to do with purchasing from the extreme low end of the market. It just so happens that the vast majority of that segment is manufactured in China at present.
I think normally when people say Chinese made in this way, what they're really communicating is that there's no (meaningful) brand. All they know about it is that it is from China.
In this case it’s actual malice, that the streaming stick is set up for residential proxy and ad fraud straight from the factory. But incompetence can lead to the same place if it’s a poorly engineered, un-maintained device with an old version of Android that will never be patched and is always one no-click exploit away from being commandeered into residential proxy and ad fraud.
Those TV streaming boxes really are (from a cybersecurity perspective) probably one of the worst things you can buy. Here is the "Darknet Diaries" Episode on them: https://darknetdiaries.com/episode/172/
I was trying to figure out why we saw so many fraudulent applications from Vietnam for a service which is restricted to the United States, especially because they were all getting rejected - it seemed like even the laziest spammer would lose interest in something they couldn’t monetize.
A guy in Vietnam mentioned that one of the largest ISPs there used these really dodgy Chinese modems which were so notoriously insecure that it was apparently common knowledge that you should replace them if performance was slow because that was a sign that yours was being used by a botnet. Apparently the cost of access to one of those nodes was so low that the spammers don’t even really monitor their bots.
If it's something like a Firestick (or the knock-off featured in the article), you're really just connecting to Content Provider servers to handle auth and content streaming, right? They're just OSes designed to run Netflix and Hulu. Would be hard to spoof I think
Indeed. Owning the streaming box lets you loose on whatever network it's on, but it doesn't actually get you inside the content gardens; those are separately managed by teams of people much more motivated to protect their IP.
See CoreELEC/LibreELEC/etc - totally replaces the (potentially dodgy) Android OS on these kind of streaming boxes with a stripped down Linux+Kodi setup
After getting tired of ads on my PAID smart TV, 6 months ago I started building a casting device using raspberry pi for myself. A couple of months later one of my friends who is an AV technician ended up using it at the largest convention venue in Barcelona to play content on loop, here's a video of that: https://www.youtube.com/shorts/FF3I9EOs4AA.
Fast forward to last month, now I have started selling these in Barcelona, Spain where I am based out of and branched it into three use cases: digital signage, casting, and a portable computer for presentations at events. Here is the link with features: https://soljacast.com
> generic TV boxes that promise unlimited content streaming for a one-time fee
I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.
I have an elderly client who sends me links of stuff to buy all the time. One day it's one of these streaming sticks, the next day it's half-price stamps, and I tell her every time, please don't buy this stuff. And yet she does anyway, as if I was almost being mean and saying no just to say no.
So yes, I do want to blame the purchasers of these things, sometimes. To prove her point that her stamps were legitimate, she mailed me a card using one of her half priced (but likely fake) stamps and it made it through!
Perhaps they grew up in a time/environment where "if it was that bad they wouldn't be allowed to advertise it", and they're still using that old calibration?
My falther-in-law was less that and more, if I can get away with it, it's actually legal. Many know their fake, and do it because they can get away with it.
That was his justification for a satellite descrambler, they're sending me the signals, obviously I'm allowed to.
They are downloading that content from a company with a $2.5T market cap. They presumably aren’t making a living by selling that copyrighted material via a retail that claims to run a legitimate business.
I think that makes a big difference.
Imagine if Amazon Video, Audible, and Kindle will all just pirate stores, where uploaders of the pirated content made money on the downloads, people paid for those downloads, and Amazon took a cut of everything. How long would that go on before they were in court and that was shutdown?
I think that's a default for a lot of the older (and some of the younger!) generation, same goes for news and media. They grew up in a time where there was a practical barrier to publishing and (largely) laws behind you doing it.
So they trust literally everything they read. I still don't think my folks can fathom you can spin up a very real looking newspaper website with fake articles in about 10 minutes.
I find younger people are more likely to trust whatever they read - social media rumors, LLM output, Reddit threads - and older people looking for credible sources.
When my kid was young I set up a basic web server and taught him how to make a VERY basic web page. I let him write whatever nonsense he wanted to and then we made it live.
It was both a gateway into learning how the web works but also that literally anyone can post anything to the internet and it doesn't make it true. I like to think he's more savvy than many of his peers but we all have our blind spots.
It doesn't seem too weird to me: Selling someone fake stamps is a general act of fraud, between buyer and seller, and would be pursued by state/federal attorneys general.
The USPS becomes directly involved only later, when someone tries to defraud them by using a fake stamp.
#1 How big is your potential market? It's people still mailing things from home, who haven't figured out how to do postage on their computer.
#2 Of the population in #1, it's those who find real stamps so expensive that it's worth bothering with discounts.
#3 Of the population in #2, it's those who would want to buy something fraudulant (or not know better) and who would want to risk using it.
#4 Considering the size of the #3 population, how many stamps do they use in a month?
#5 What is your margin on a half-price stamp? You have to pay for advertising, printing (we're talking a profit margin under $1), packaging, and your own time, but at least shipping is free!
Why should anyone assume a product being sold by (or at least on) Amazon, the latest retailer in the country, is an illegal device?
It’s not like they’re buying these things out of a car trunk in a dark alley. These retailers need to be held liable for selling these things. If they sell this stuff, why not illicit drugs?
If they are unable to maintain control of 3rd party sellers, then they should end the 3rd party seller program. It has done nothing but damage Amazon’s reputation, and it just keeps getting worse.
The streaming services have fractured and taken so many movies off their service so much that it is too hard for most people to figure out where that show/movie can be found.
From a link above to the story on darknetdiaries:
> For Pokemon, there is a website that tells you how to watch this. You start off on Netflix, then swap over to the Pokemon streaming service, which is the only place that has Season 2, then swap over to Prime Video for Seasons 3 through 5, swap to Freevee, then Hoopla. Season 13 is only on Amazon, though. Then swap to Tubi, then Hulu, then Roku channel, and then finally back to the Pokemon streaming, and then Netflix. Easy.
That's 8 different streaming services to view one series.
Ok but have fun explaining that to the average person. Buying a dongle is easier than installing software or typing URLs into their TV ("my TV doesn't even have a keyboard").
To most people IPTV is a bunch of gibberish letters, indistinguishable from the gibberish brands on Amazon. Someone's grandma from Colorado doesn't deserve to get scammed because she didn't research the acronyms.
- How are these "legitimately free"? For example AMC is a commercial TV channel and as far as I know, they don't offer free streaming. Same goes for MGM, FilmBox etc.
- Strictly speaking this isn't IPTV, it's just web streams. IPTV is usually delivered via multicast (MPEG-TS/RTP/RTSP streams, over UDP mostly).
Yeah, isn’t this a classic kind of scam the would-be scammer situation? If you think there’s some way to buy one cheap device and somehow get around subscribing to streaming services[1], then of course you’re going to be in a market with fraudsters…
[1] Can someone explain what the theory of the product is here? It sounds like they’re marketing these things as ways for the customer to commit fraud, for example by connecting to someone else’s login. How else would the customer expect to be able to get free Netflix or whatever?
> it does seem like a Too Good To Be True situation
It's difficult to judge the price of media products. We have legal music streaming services that charges you an album's worth of money a month and lets you listen to millions of songs. You can pick up old AAA games for less than ten bucks. I'd say when people say that price tag, they don't think they get scammed into being a part of a botnet. They think the device manufacturer cut a good deal with the media rights holders.
Uhh, I have an extended family member, who not only uses it, but now also tries to get other people to get into it. Since I was familiar with this practice ( and the issues it makes worse ), I noted those to him in an attempt to both politely decline and, hopefully, spare him, and society, some future problems. Without going into any identifying details, he didn't take it well ( and I don't think I got on my high horse ).
If you offered most people free streaming for a $37 USB stick but directly told them it would be faking ad clicks when the TV is off, would any of them really care?
No, and that's is the root of the problem. The buyer is happy and so is the seller. They don't care to understand what they're allowing and everyone is allowing it to happen.
I wouldn't use a device like this for a lot of reasons, but the fact that what they are doing might be taking advantage of the incredibly predatory digital advertising system is neutral to positive for me, if I'm being fully honest.
If they were using the system to rip off random people, I'd be 100% against it, if they are fucking Google and the giant corps that advertise with them, ehh.. not my problem and can't be assed to care. Google is not a positive force in the world. Hasn't been for many years.
Maybe they wouldn't care about the ads but the residential proxy is another story. I'm sure lots of problematic stuff goes through that and you take the risk of being associated with it.
I know a few people who buy these, and they kind of know what they're doing. They just try and not think about it too hard.
It reminds me of the saying: "It Is Difficult to Get a Man to Understand Something When His Salary Depends Upon His Not Understanding It".
If these people thought about it for a few minutes, they would understand, but they choose not to, as ignoring it is too advantageous.
I admit I was tempted, as the price of all streaming services goes up, and services become more and more fragmented. During the same period where I have not had a raise.
In the 90s, there was a cottage industry selling CDs of bootleg software at swap meets and flea markets. A guy my dad knew was almost condescending to anyone who paid for software despite having been hit by viruses multiple times because it was so much cheaper. Even having to deal with a client(!) who naively called the vendor support only to be informed that they hadn’t actually purchased a license wasn’t enough to get him to resist that savings.
I used to know someone doing this. They said they know it is too good to be true, but they hate corporations and it's their little way to stick one in.
Maybe, but if they're a not-very-tech savvy older person buying this, they probably remember shows being free from over the air antennas and may think it is something like that.
Yes, in fact I have an antenna and a HDHomeRun nestled in my attic to record over the air shows that I occasionally consume.
But, I think it's far more common for people to have a TV service today, perhaps since comcast and their ilk push hard the TV/phone/internet bundle, and gone are the years when everyone would fiddle with the antennas on the back of their TV to get the right reception.
It could be possible, I haven't done the math though.
Stremio +Torbox is $3/month and they can probably share 10+ households on one TorBox account so it could work out. The seller could just stop paying the TorBox subscription at whatever point and they have an incentive to do so.
That reminds me, I need to configure VLANs in my router so that all my trusted computers are isolated from all the other garbage that makes it into the network.
Mmmh, I've always wondered ... as much as VLAN's are a very useful tools to - for example - route two separate LAN's traffic through a shared physical link ... are they any good when it come to security?
I mean, I don't believe VLAN's were designed with security as a goal, and I wonder how "strong" the virtual wall between two VLAN's actually is?
Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physical connection where packets from both VLANs happen to travel?
Defrauding ad networks doesn't seem like a bad thing, although using my internet connection as a proxy is obviously terrible. It wouldn't surprise me to learn that my connection is being sold as a VPN service by the vendor.
Fraud that destroys market trust in a market that mostly deals in surveillance and selling intrusive data that was collected mostly unknowingly from the subject seems great to everyone who has any amount of integrity.
It'll be a marginal effect, but fake clicks impacts the ad buyer, which then impacts their financials and pricing.
The only winner here is the scammers running the fake affiliate sites on which these sticks are "clicking". Or, am I missing some facet of this enterprise?
What this misses is the person buying the TV stick doesn't care about the impact on the ad market. The bigger problem is residential proxying, because their IP will end up getting used for something bad.
Another winner is the person who gets to watch cheap digital TV, without putting together a usable antenna and limiting their reception to the broadcast channels that are nearby.
I mean: They just pay the money, plug the thing in, push some buttons, and: TV happens. Right?
You really don't want fraudulent clicks ("invalid traffic", per industry lingo) coming from your home network, because any publishers (apps and websites, per normal-people lingo) who use tools designed to block invalid traffic might start flagging legitimate traffic from your network.
Can confirm. I used to use Ad Nauseam (Firefox extension that clicks all ads), eventually stopped when I was getting captcha'd left and right.
Also, visitors on my wifi started getting strange ads. Yes I threw off the algo, but I'm a guy with wife, I'd rather get car ads than like divorce lawyers + gay dating sites.
Theres the question of whether or not the fraudulent advertisement clicking is using enough traffic to inconvenience or impose fees upon the user but otherwise I agree with you and am tempted to buy one just to fuck with advertisers.
Backdoors and spying are also a problem in theory except at this point you can't even trust "legitimate" companies on that front so it's a moot point.
> otherwise I agree with you and am tempted to buy one just to fuck with advertisers.
How that actually works in practice is that your favorite sites make less money and your IP gets a bad reputation so you CAPTCHAs or outright blocked. There’s no “sticking it to the man” here, just contributing to the frictional grind making the internet worse for ordinary people.
why is running a proxy a bad thing? someone profiting off it could be bad maybe, but even that is good if it pays for my subscription.
but compare running tor nodes, and especially exit nodes. that surely would be a good thing, so at least if you think tor is good then running a proxy should be the same and it should be normalized.
doing it in secret without the user knowing is what's bad
Indeed without my permission is implied. Without it, you have no idea what traffic is being routed and could be on the hook for something nasty like CSAM.
Those are different issues. Permission doesn't mean you know what the content is, and lack of permission doesn't mean they're going to load anything weird or bad. Lack of permission implies worse ethics overall, but an operation focused on clicking ads will be loading relatively normal sites.
A familly member had one of those (he had to pay a yearly subscription in addition to the stick). Network would be unusable as soon as it was on for anyone else, and it also tried to scan things on the local network. It was indeed connecting to all kind of services all over the world (and saturating some tables in the router doing so which blocked other clients). Definitely evil, definitely on purpose.
Reading this, I caught myself wondering how we distill what's in this excellent write up into something the average consumer understands, including the dangers from buying and using devices like this.
Is it a graphic that's shared? Something else? I am sure we all know or have heard of people with these devices that promise free streaming.
The bigger problem is convincing them to care. Botnets are abstract - where's the pain to them? Ad farms? That's "just hurting big corporations".
Remember, a significant portion of the population got angry (often violently so) when just asked to wear a mask to protect their neighbors. And the threat there was significantly easier to explain.
I warned them about the risk of those things and showed them what I found, they continued buying the next generation (that person and his two >40yo kids). They NEEDED to watch those soccer games more than they cared about security...
My "streaming device" of choice, ThinkCentre Tiny with Linux, always feels validated with news like these. It fits behind a TV, you can get it second hand for around $40 and depending on model it can even act as a retro game console as well.
LG televisions and monitors spy on their users and install unwanted software. Half of all smart tvs are running "residential proxy" malware. Google is banning sideloading but happily hosting apps using the Bright SDK.
Sorry, but "your tv stick does ad fraud" is just about the most innocent thing I've seen in a while. Everyone in this market is doing the shadiest shit you can imagine. There are no good brands left, you just get to pick what logo your Malware Entertainment Device has.
Any way to identify or block these proxy and ad click services in the router? Say a Ubiquiti or even pfsense?
I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.
Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?
My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.
It's not just one device line; Have a look at the list maintained by the proxy tracking service Synthient, which tracks streaming boxes, digital picture frames and other IoT devices that have been known to bundle residential proxy software, among other malicious apps. They currently track almost 1,000 different makes and model numbers.
I bet this is much broader than we all realized because just earlier today I was reading on https://gist.github.com/probonopd/3ad6b7777caea1503f00d5fe77... in order to tinker with a cheap (like really cheap) Android video projector : "Device: Magcubic HY300 Pro Android Projector (ui_Veng.projector) Issue: Device was being used as a residential proxy node without consent, causing thousands of suspicious DNS requests and bandwidth usage." linked in there just few months ago.
It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique.
An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.
I do not see problems with fake ad clicks and have no sympathy for ad companies.
Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.
What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.
How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:
- the user must be able to re-flash firmware with their own code.
- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.
- any telemetry or data collection, or updates must be opt-in only and disabled by default.
- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.
Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.
> I do not see problems with fake ad clicks and have no sympathy for ad companies.
I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.
Sure. And you'll quite literally never be able to get any meaningful reduction in this practice unless you attack it at the level of big, publically known companies; the warnings about these local dinky things I suppose are not harmful and help individuals a bit -- but I'm concerned they give the entirely false impression that the extremely similar stuff coming from the big boys is definitely a-ok.
> What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information.
The Snowden leaks showed that the US was already doing this. I'm certain that everything purchased is already infected with something. Most likely bugs and bad security.
>What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information.
Most Americans are at a greater threat of harm from their own government that a foreign one. What worries me is all the mass surveillance done by big tech which bypasses the 4th Amendment and gives the government Americans data without a warrant.
There's already a front door with the adtech for US alphabet boys. This could likely be collected by others as well. We saw this happened where foreign hackers exploited a backdoor designed for American authorities[1]. This is what experts are referring to when they say there's no backdoor only for me.
This could be compelling to politicians, though, and would certainly be a step in the right direction.
>- any telemetry or data collection, or updates must be opt-in only and disabled by default
This should be how it is for everything foreign made software or not. Would be very hard to get done with the big tech lobby in the US.
In some areas GPS is spoofed and the displayed location is wrong. If, for example, a "smart" car gets a task from its manufacturer to film some secret object, it would fail if it relied only on GPS and did not use cell towers and WiFi points for determining its location. So knowing their location determines whether the mission would fail or succeed. So foreign devices should not be allowed to collect such information.
I think that might have been semi-sarcastic. I mean, there are lots of reasons to do this sort of thing, some are bad, some are not so bad, most are not war.
> a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed
Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys.
Could it be used for missiles? Sure. Is it obviously the intention? No.
> If Location Services is on, your device will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers to Apple to augment Apple's crowd-sourced database of Wi-Fi hotspot and cell tower locations.
> When Location Accuracy is on, Google periodically collects information about the locations of wireless signals and sensors observed by your device to crowdsource location estimates. This helps everyone find locations better.
They do ask the device owner - if you review the location services description on android[1] you will see they explicitly say they collect this information from your device. I strongly disagree that they need to get government permission for this - they are simply recording signals that reach the device, akin to making notes about what kinds of cars you see. This is not a thing a government should have control over people doing and not a thing that should be registered with the governement.
In the article you refer to, I see no mention of asking user's permission. However, I remember, when using an old version of Android, there indeed was a popup nagging me to allow sharing location data with Google every time I enabled GPS. Very annoying, makes you want to never enable GPS in the first place.
Regarding the government, the problem is that many people do not fully understand the mechanism of collecting the data. I remember the case when members of US military disclosed the location of secret objects through fitness tracker app. And they were probably smarter than average smartphone user. Obviously it would be better if enabling GPS required an approval from their commander.
Should Google ask permission from the device owner, and from the local government before collecting the data? I heard a certain foreign mobile app was banned in US for doing less than that.
Oh this was a failed device that Mozilla offered. I had a couple back in the day. It was called Matchstick. Sick t shirts. Basically an OSS chromecast.
Fake ad clicks cost the advertiser money, not the ad company.
Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)
> Fake ad clicks cost the advertiser money, not the ad company.
It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.
Good products do not need much advertising. For example, when buying DRAM, I compare the specification and prices and do not look at the advertisement.
> I do not see problems with fake ad clicks and have no sympathy for ad companies.
Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.
> Yeah, it's like—a cheap streaming stick AND it poisons the advertising well?
Keep in mind that it's your IP and identity associated with those clicks and anything else criminals decide to do with your IP address. That means you're identity is being linked to things you may or not want to be known as being interested/involved in. The ads your TV stick clicks on can cause data brokers to include your name in lists of people who are heavily into drugs, have mental disorders, belong to certain religions or political parties, etc. All of that can come back to haunt you later.
Depending on what other activity your connection is used for as a proxy it can also get you in trouble with the police or with your ISP.
I can’t prove it, but I live in Brazil and after getting a smart TV from LG, I started receiving challenges across all Google services, indicating they received bot traffic from my network. I only used apps from streaming services I actually paid for.
I suspect these TVs either come with residential proxies set up from the factory, or they have such poor security that they’re instantly hacked. Either way, TV manufacturers (including reputable ones like LG) are to blame.
There have been articles lately about the residential proxies loaded in apps for LG TVs. My LG has never seen a network connection, so I’m fuzzy on details.
it's just like a phone. don't buy a crappy one with firmware of unknown provenance. make sure the one you do buy has an active and effective effort that you trust that ships timely security fixes.
> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.
Instead they're banning stuff willy nilly left and right without really solving the problem.
But there's good stuff coming out of China as well. I recently bought a cheap e-reader which has no WiFi or internet connection and it works stellar. And I bought some cheap Chinese sport cams which also lack internet and work great.
> I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.
Personally, I think every other country should ban any product made by Google, Amazon, and Microsoft since they all spy on the users of their products too.
I've suggested legislation which would ban the sale of customer information to third-parties.
These companies could use the info they gather on customers for their own use but they cannot (re)sell it to anyone, not even the government. The reason being that the information eventually ends up abroad after which you lose all control over it.
These are not "streaming boxes" in the sense you are talking about. Their appeal is that they come preloaded with chinese pirate streaming apps. Traditional streaming boxes - Apple TV, Fire stick, Roku - are not affected by this, though if you want privacy-focused Apple TV is the only remaining contender, and with Apple's continued descent into advertising vendor I'd guess that one is not long for this world, either.
Roku collects an insane amount of data on users. Basically everything that they can get their hands on
> Roughly twice per second, a Roku TV captures video “snapshots” in 4K resolution. These snapshots are scanned through a database of content and ads, which allows the exposure to be matched to what is airing. For example, if a streamer is watching an NFL football game and sees an ad for a hard seltzer, Roku’s ACR will know that the ad has appeared on the TV being watched at that time. In this way, the content on screen is automatically recognized, as the technology’s name indicates. The data then is paired with user profile data to link the account watching with the content they’re watching. https://advertising.roku.com/learn/resources/acr-the-future-...
I’m sure you could. At what point do you just rip out the thing that is trying so hard to work around your control of your network? An Apple TV doesn’t cost that much.
Apple TV is currently the best balance of privacy and convenience. The only way to get more private is using a PC, but that limits the resolution for most streaming services to 720p or 1080p.
If you want actual privacy (rather than promises from Apple or Google), what you need is a mini-PC running Linux with the Plasma Bigscreen DE. You then use a Web browser rather than invasive "apps" for your streaming. For Youtube, there is VacuumTube (an improved Youtube Leanback client). The main limitation is capped resolution on some commercial streaming services. I believe Windows does not have that restriction, so a VM could presumably be used for streaming (I have not tried).
I'm increasingly being convinced the only way to do that is you do a media pc nuc. The problem, of course, is you probably won't have the netflix app. It's painful to setup such a box to stream from various services.
I tried to look at setting up an stripped down privacy-focused Android based box for Netflix, but ran into issues. Seems like you need to be spied on to run Netflix.
The Onn TV devices from walmart seem fine, baseline google tracking not-withstanding... but no residential proxy or botnet participation without you knowing! You can just block them at the router and stream content locally.
I recently got an Apple TV 4K and have been really enjoying the ad free experience. Worth every penny. Our smart tv had turned into a Christmas tree of ads.
There are plenty of ads on Apple TV; huge banners right at the top of the UI, and ads that launch before you get to see the content of a show with no way to automatically disable them (you have to manually click through or just wait it out). It is infuriating (to me).
As much as I hate Apple for what they've done to the average consumer in regards to computing, it would be just impossible and dishonest to say anything other than Apple is the outright winner in streaming devices. The experience is so smooth.
Considering their recent decision to give up on building Apple Maps into a serious contender and instead enshittify it with ads, I don't have much faith Apple TV will be far behind.
I'm imaging a largescale distributed project like folding@home except instead of doing scientific research everybody is working together to fuck with advertisers, tracking cookies, etc.
I use one but only when traveling at hotels - it’s one of the only sticks that can connect to captive WiFi networks at hotels
I’ve got barely anything on it so privacy be damned - but at this point this is why I just buy apple products
I have two apple tv’s which probably do shady things too, but I’m willing to play the probabilities and assume it’s the least bad of my options short of tinkering with flashing hardware and all that stuff that used to be fun in my teens (emphasis on used to)
The best solution to this problem is to block GeoIP traffic and monitor bandwidth consumption on a per-domain basis. If something is sending data during the night, it becomes much easier to identify suspicious activity.
Generally, it's advisable to create a dedicated wifi network for all potentially hostile devices.
This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.
That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.
> That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home
That is not enough. You need to air gap devices that have legitimately no business communicating with anyone or anything outside the house. TVs, thermostats, and other Internet-of-Crap gadgets do not need "firmware updates." Either they work out of the box, offline or within the LAN, or they get sent back for a refund wherever they came from.
I don't think this would make a big difference for the threat model described in the OP? They'd still be able to use your IP Address and potentially do nefarious things through your role as an unwitting proxy.
Using one device as a proxy is a few steps away from trying to exploit and infiltrate the other devices on your machine as well. An unwitting proxy is already crossing the line to putting a fox in the henhouse.
Limiting what outbound access devices can/can't have is an important skill to learn.
> allowing low-skilled operators to drag blocks of code together in their editor — without any need to understand what the underlying code blocks do or how they work.
To those who are OK with these devices: when you engage in corruption, do you have any moral standing against your politicians when they engage in corruption?
Both you, and the corrupt politicians, are eating away at the trust that underpins society. Certainly, you can argue, your bite is just a tiny one; the politician is eating the whole apple.
At the end of the day, everyone suffers from the decline of trust and casual acceptance of fraud.
> major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands that bundle unofficial versions of Google’s Android operating system and are frequently marketed (via online influencers) as a way to access a broad array of streaming services and live broadcasts without a subscription.
This is why I giggle when people talk about ending Section 230 in the USA (or various international counterparts thereof).
The largest companies on Earth are happily selling hacked piracy spyware botnet garbage. Not just hosting malicious posts for free like Section 230 protects, but selling illegal physical devices and taking a cut of the profit and excusing it with a pathetic whack-a-mole moderation system. It's already illegal and the law has already failed.
Sean Parker's mistake was that he wasn't rich enough.
Of all the evils normally associated with visual programming languages, enabling cybercrime isn't one I've previously considered. Now that I've seen it, I'm surprised it wasn't more common before LLMs appeared.
And which part of "ad fraud" is the fraud? As far as I can tell, ad networks and advertisers are the fraud and they are also part of the increasing surveillance state.
It's called fraud because the ad host colludes with (or directly controls) the botnet to get lots of clicks on ads hosted on their sites, making them money at the expense of advertisers.
If you just want to spam clicks on ads you don't financially be edit from, go for it.
> Despite repeated warnings from the FBI and security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands
I scanned the comments and I didn't see anyone suggesting that these companies should share any responsibility for selling these harmful products. Why is it that they seem to get a pass? Would we feel the same about giant retailers selling tainted food, or unsafe children's toys?
One of the main value propositions for retailers in a world of endless cheap garbage being sold online, is to vet products so customers can trust that what their buying is from a legitimate company and not junk or stuff like these streaming sticks.
This is the problem with being an “everything store”. “Everything” includes a lot of things most consumers would like to be protected from, and assume they are due to the long history of retailers standing behind the products they sell. That history seems to have come to an end. They only stand behind it enough to offer a refund if there is a problem, not to ensure it’s good before selling it.
Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold. They certainly don't advertise to the big box retailer that buys them "and it uses the customer's internet connection for fraud."
Hell, there's a section of comments that would probably going "hey, RELAX guy" because it's not US companies doing this. For any American companies that do this though, sure - block/suspend/prosecute.
> Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold.
You already answered it: block it from being sold.
1) Make Amazon responsible for the products they are selling. 2) Introduce a law banning malware tv sticks 3) Sue Amazon for a percentage of their yearly revenue when caught violating it 4) Amazon will finally start caring and do some kind of review on the crap they sell.
If I open my own line of home improvement stores and do no oversight on what I sell and wind up selling really dangerous lawnmowers, I'm partly responsible.
Or if I open up a gas station and allow any company without oversight to sell "supplements" through my shelves and cops arrest me for selling heroin, I don't get a free pass.
Why should amazon or Walmart get a free pass just because they sell more items?
One problem I see with your analogy is that the dangerous lawnmower can cause an easily quantifiable harm.
You have to be able to show damages you incurred and assign a dollar value to them to sue people.
That doesn’t work at all for a something that sells your bandwidth to a proxy service. People wouldn’t even be aware that it was happening they weren’t told.
What about when the police show up because some highly illegal content was traced to your IP address? Will they believe that you were the unwitting victim of a rogue proxy server running on your streaming stick? Would you have even been aware of that possibility?
Except the devices are not dangerous. Its the software installed on the device. Consumers have a choice. Pay for the trusted Apple TV or Amazon firestick, or go the wild west and see what's on offer.
But it is a retailer's responsibility to know what they are selling. If it was added after they started selling it and hidden in secret, sure a retailer might have an excuse. But it isn't really hidden, most often its put in their marketing materials as a benefit and have been knowingly doing it for many years now.
US retailers can be told they can't sell it here. If you buy it outside of that, well that is buyer beware, but 99% of people aren't buying things from Alibaba or ordering from some random foreign store, they are buying them off US Amazon, Walmart, big box retailers, etc. You don't have to ban things consumer level to deal with 99% of it, you just gotta tell big corporations no and stop dismissing any ideas that put responsibility or liability on big business.
I would very much be in favor of grocery stores sharing responsibility (and regulatory penalties) for selling tainted food! It's kind of mind boggling that this is controversial. "Buyer beware" is not an acceptable basis for society to function.
I can't think of a case where a supermarket, upon becoming aware of a problem with a food product, didn't immediately pull it from the shelves, post a notice to customers, and offer a full refund to anyone who had purchased it.
This is why I hate the "marketplace" of these stores. In many cases these products never hit their inventory at all, they are functioning like a search engine and payments processor.
Probably because we have little to no way to punish those companies. We can't even stop DJI from shipping their drones under other brands to get around the ban.
Our government chooses to not punish those companies. Unfortunately, the lawmakers have decided that the donations to their PACs are more important than actually doing something about it.
Probably because most people don’t equate the damages from causing bodily harm to whatever these ad clicking networks do.
Voters don’t like seeing themselves or their kids get hurt, but they do like lower cost live sports.
We purchased a Chinese-made projector from Amazon, which was surprisingly inexpensive (~40 USD). Upon connecting it to the internet, it placed a constantly running feed of ads on the corner of the screen, even while movies were playing. There was no way to disable it either. Even though it's not a stick, it's a similar principle.
I remember reading an analysis on one of those projectors; the author found a residential proxy running on their device. I would recommend keeping these things off the internet.
I'd be very interested to see it if you still have access to it.
I mean, did you have to connect it to the internet though? Did it not just have a dp/hdmi port?
Capitalism!
Upon connecting it to the internet…
I hesitate to blame the victim here, but why on earth would you do that? “$40 Chinese-made” didn’t give you pause?
To be fair, everything is Chinese made. I would be even the Apple TV and NVIDIA Shield are made in China and if a state actor is determined to get a malicious payload in....
My Samsung phone is made in Vietnam.
To play devil's advocate, when someone says "Chinese made" they're usually well aware of your point, and are more using it as a common way to describe product mills spitting out countless devices with dubious quality or configuration.
Of course theres good products made in China, and plenty of entirely Chinese brands killing it doing their thing.
This isn't about state actors though. There's a world of difference between a name brand (possibly even a Chinese one) versus what I would term "chineseum". It's nothing to do with China per se and everything to do with purchasing from the extreme low end of the market. It just so happens that the vast majority of that segment is manufactured in China at present.
I think normally when people say Chinese made in this way, what they're really communicating is that there's no (meaningful) brand. All they know about it is that it is from China.
Made in China and random Chinese brands are two very different things
> To be fair, everything is Chinese made
Yes. Chinese manufacturing is quite a phenomenon, useful and everywhere
But to be completely fair, a $40 video projector has a warning label. The price
This is an age where even teacups demand internet connectivity to fetch firmware updates
I mean I get why my cups need frequent java updates, but still.
In this case it’s actual malice, that the streaming stick is set up for residential proxy and ad fraud straight from the factory. But incompetence can lead to the same place if it’s a poorly engineered, un-maintained device with an old version of Android that will never be patched and is always one no-click exploit away from being commandeered into residential proxy and ad fraud.
Those TV streaming boxes really are (from a cybersecurity perspective) probably one of the worst things you can buy. Here is the "Darknet Diaries" Episode on them: https://darknetdiaries.com/episode/172/
Superbox 3 is coming up at DEF CON next Friday!
https://hackertracker.app/defcon34/content/67257
Thank you for sharing this. The superbox investigations have been incredibly interesting to follow.
I was trying to figure out why we saw so many fraudulent applications from Vietnam for a service which is restricted to the United States, especially because they were all getting rejected - it seemed like even the laziest spammer would lose interest in something they couldn’t monetize.
A guy in Vietnam mentioned that one of the largest ISPs there used these really dodgy Chinese modems which were so notoriously insecure that it was apparently common knowledge that you should replace them if performance was slow because that was a sign that yours was being used by a botnet. Apparently the cost of access to one of those nodes was so low that the spammers don’t even really monitor their bots.
Since these are poorly engineered, wonder how easy it'd be to reverse-engineer one and just get the free streaming on a non-scam device.
If it's something like a Firestick (or the knock-off featured in the article), you're really just connecting to Content Provider servers to handle auth and content streaming, right? They're just OSes designed to run Netflix and Hulu. Would be hard to spoof I think
Indeed. Owning the streaming box lets you loose on whatever network it's on, but it doesn't actually get you inside the content gardens; those are separately managed by teams of people much more motivated to protect their IP.
See CoreELEC/LibreELEC/etc - totally replaces the (potentially dodgy) Android OS on these kind of streaming boxes with a stripped down Linux+Kodi setup
I wonder to what degree malice can be engineered to look like incompetence?
Try examining the old entries from the https://en.wikipedia.org/wiki/Underhanded_C_Contest.
After getting tired of ads on my PAID smart TV, 6 months ago I started building a casting device using raspberry pi for myself. A couple of months later one of my friends who is an AV technician ended up using it at the largest convention venue in Barcelona to play content on loop, here's a video of that: https://www.youtube.com/shorts/FF3I9EOs4AA. Fast forward to last month, now I have started selling these in Barcelona, Spain where I am based out of and branched it into three use cases: digital signage, casting, and a portable computer for presentations at events. Here is the link with features: https://soljacast.com
Clicked on the link, ready to buy one. “Contact sales”. Ew. No thanks.
> generic TV boxes that promise unlimited content streaming for a one-time fee
I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.
I have an elderly client who sends me links of stuff to buy all the time. One day it's one of these streaming sticks, the next day it's half-price stamps, and I tell her every time, please don't buy this stuff. And yet she does anyway, as if I was almost being mean and saying no just to say no.
So yes, I do want to blame the purchasers of these things, sometimes. To prove her point that her stamps were legitimate, she mailed me a card using one of her half priced (but likely fake) stamps and it made it through!
Perhaps they grew up in a time/environment where "if it was that bad they wouldn't be allowed to advertise it", and they're still using that old calibration?
My falther-in-law was less that and more, if I can get away with it, it's actually legal. Many know their fake, and do it because they can get away with it.
That was his justification for a satellite descrambler, they're sending me the signals, obviously I'm allowed to.
There's an old Carlin joke about "If a cop didn't see it, I didn't do it."
I can imagine many on HN having excited discussions about their satellite descramblers.
> do it because they can get away with it.
Lots of people on HN download and upload copyrighted materials. Is it really different?
They are downloading that content from a company with a $2.5T market cap. They presumably aren’t making a living by selling that copyrighted material via a retail that claims to run a legitimate business.
I think that makes a big difference.
Imagine if Amazon Video, Audible, and Kindle will all just pirate stores, where uploaders of the pirated content made money on the downloads, people paid for those downloads, and Amazon took a cut of everything. How long would that go on before they were in court and that was shutdown?
I think that's a default for a lot of the older (and some of the younger!) generation, same goes for news and media. They grew up in a time where there was a practical barrier to publishing and (largely) laws behind you doing it.
So they trust literally everything they read. I still don't think my folks can fathom you can spin up a very real looking newspaper website with fake articles in about 10 minutes.
I find younger people are more likely to trust whatever they read - social media rumors, LLM output, Reddit threads - and older people looking for credible sources.
When my kid was young I set up a basic web server and taught him how to make a VERY basic web page. I let him write whatever nonsense he wanted to and then we made it live.
It was both a gateway into learning how the web works but also that literally anyone can post anything to the internet and it doesn't make it true. I like to think he's more savvy than many of his peers but we all have our blind spots.
> time/environment where "if it was that bad they wouldn't be allowed to advertise it"
like cigarettes?
Of course, what they're missing is that laws are for poor people.
Amazon will be notified they sold something illegal and will take it down and ban the seller who will immediately launch a new store under a new name.
The purchaser, on the other hand, will be fully liable for whatever horrible thing they bought.
What is your line of work, if I may ask?
Half priced stamps work though, and nobody is going to prosecute grandma for counterfeiting postage stamps.
Yes they do. USPIS does not f around
Oddly they don't ever seem to prosecute the sites that profit from selling them. Funny, that.
It doesn't seem too weird to me: Selling someone fake stamps is a general act of fraud, between buyer and seller, and would be pursued by state/federal attorneys general.
The USPS becomes directly involved only later, when someone tries to defraud them by using a fake stamp.
Makes sense to me, the only place I've ever seen them personally advertised are overseas websites.
> half-price stamps
Who is selling half-price stamps?
#1 How big is your potential market? It's people still mailing things from home, who haven't figured out how to do postage on their computer.
#2 Of the population in #1, it's those who find real stamps so expensive that it's worth bothering with discounts.
#3 Of the population in #2, it's those who would want to buy something fraudulant (or not know better) and who would want to risk using it.
#4 Considering the size of the #3 population, how many stamps do they use in a month?
#5 What is your margin on a half-price stamp? You have to pay for advertising, printing (we're talking a profit margin under $1), packaging, and your own time, but at least shipping is free!
Then again I used to torrent everything under the sun and it actually rocks to have every tv show, movie, game ever released for free forever.
So is it greed? Yes, but I did it too so now that its more accessible I cannot really blame people.
Why should anyone assume a product being sold by (or at least on) Amazon, the latest retailer in the country, is an illegal device?
It’s not like they’re buying these things out of a car trunk in a dark alley. These retailers need to be held liable for selling these things. If they sell this stuff, why not illicit drugs?
If they are unable to maintain control of 3rd party sellers, then they should end the 3rd party seller program. It has done nothing but damage Amazon’s reputation, and it just keeps getting worse.
The streaming services have fractured and taken so many movies off their service so much that it is too hard for most people to figure out where that show/movie can be found.
From a link above to the story on darknetdiaries:
> For Pokemon, there is a website that tells you how to watch this. You start off on Netflix, then swap over to the Pokemon streaming service, which is the only place that has Season 2, then swap over to Prime Video for Seasons 3 through 5, swap to Freevee, then Hoopla. Season 13 is only on Amazon, though. Then swap to Tubi, then Hulu, then Roku channel, and then finally back to the Pokemon streaming, and then Netflix. Easy.
That's 8 different streaming services to view one series.
OTOH - TV, radio, and YouTube are all unlimited and free. Why not streaming?
There are lots of people alive who grew up during the days of broadcast TV and radio. I get why they might not understand the difference.
There are a ton of legitimately free IPTV streams. You can watch them through most media players like VLC without having to download anything shady.
https://github.com/iptv-org/iptv
Ok but have fun explaining that to the average person. Buying a dongle is easier than installing software or typing URLs into their TV ("my TV doesn't even have a keyboard").
To most people IPTV is a bunch of gibberish letters, indistinguishable from the gibberish brands on Amazon. Someone's grandma from Colorado doesn't deserve to get scammed because she didn't research the acronyms.
That is chock-full of pirated content.
Two things:
- How are these "legitimately free"? For example AMC is a commercial TV channel and as far as I know, they don't offer free streaming. Same goes for MGM, FilmBox etc.
- Strictly speaking this isn't IPTV, it's just web streams. IPTV is usually delivered via multicast (MPEG-TS/RTP/RTSP streams, over UDP mostly).
Most people who buy these want to watch free movies, sports streams, etc that aren't on OTA or free services
Yeah, isn’t this a classic kind of scam the would-be scammer situation? If you think there’s some way to buy one cheap device and somehow get around subscribing to streaming services[1], then of course you’re going to be in a market with fraudsters…
[1] Can someone explain what the theory of the product is here? It sounds like they’re marketing these things as ways for the customer to commit fraud, for example by connecting to someone else’s login. How else would the customer expect to be able to get free Netflix or whatever?
> it does seem like a Too Good To Be True situation
It's difficult to judge the price of media products. We have legal music streaming services that charges you an album's worth of money a month and lets you listen to millions of songs. You can pick up old AAA games for less than ten bucks. I'd say when people say that price tag, they don't think they get scammed into being a part of a botnet. They think the device manufacturer cut a good deal with the media rights holders.
Uhh, I have an extended family member, who not only uses it, but now also tries to get other people to get into it. Since I was familiar with this practice ( and the issues it makes worse ), I noted those to him in an attempt to both politely decline and, hopefully, spare him, and society, some future problems. Without going into any identifying details, he didn't take it well ( and I don't think I got on my high horse ).
Anyway, I think some level of blame is warranted.
If you offered most people free streaming for a $37 USB stick but directly told them it would be faking ad clicks when the TV is off, would any of them really care?
No, and that's is the root of the problem. The buyer is happy and so is the seller. They don't care to understand what they're allowing and everyone is allowing it to happen.
I wouldn't use a device like this for a lot of reasons, but the fact that what they are doing might be taking advantage of the incredibly predatory digital advertising system is neutral to positive for me, if I'm being fully honest.
If they were using the system to rip off random people, I'd be 100% against it, if they are fucking Google and the giant corps that advertise with them, ehh.. not my problem and can't be assed to care. Google is not a positive force in the world. Hasn't been for many years.
Wouldn't this ultimately make money FOR Google and only cost money to the company that placed the ad?
Sure, Google's paying but they get their money regardless.
It might damage Google's reputation with advertisers in the long term. I'm not convinced Google would even care about it, given their other behavior.
They're just meeting the standards American society has set.
Ah yes there was no rampant piracy in eastern europe during/after Soviet lmao
Tankies like this make me laugh
Could you please stop posting unsubstantive comments and flamebait, and also please stop using HN primarily for political/ideological battle?
These things are not what HN is for, and destroy what it is for, so we ban accounts that do them repeatedly.
If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here, we'd appreciate it.
Maybe they wouldn't care about the ads but the residential proxy is another story. I'm sure lots of problematic stuff goes through that and you take the risk of being associated with it.
I know a few people who buy these, and they kind of know what they're doing. They just try and not think about it too hard.
It reminds me of the saying: "It Is Difficult to Get a Man to Understand Something When His Salary Depends Upon His Not Understanding It".
If these people thought about it for a few minutes, they would understand, but they choose not to, as ignoring it is too advantageous.
I admit I was tempted, as the price of all streaming services goes up, and services become more and more fragmented. During the same period where I have not had a raise.
In the 90s, there was a cottage industry selling CDs of bootleg software at swap meets and flea markets. A guy my dad knew was almost condescending to anyone who paid for software despite having been hit by viruses multiple times because it was so much cheaper. Even having to deal with a client(!) who naively called the vendor support only to be informed that they hadn’t actually purchased a license wasn’t enough to get him to resist that savings.
I used to know someone doing this. They said they know it is too good to be true, but they hate corporations and it's their little way to stick one in.
Maybe, but if they're a not-very-tech savvy older person buying this, they probably remember shows being free from over the air antennas and may think it is something like that.
> they probably remember shows being free from over the air antennas
you are aware broadcast TV never ended?
Yes, in fact I have an antenna and a HDHomeRun nestled in my attic to record over the air shows that I occasionally consume.
But, I think it's far more common for people to have a TV service today, perhaps since comcast and their ilk push hard the TV/phone/internet bundle, and gone are the years when everyone would fiddle with the antennas on the back of their TV to get the right reception.
I watch TV over an antenna, shows are free still
It sounds like scam
Well now I want one
Stremio+TorBox are the two words. ($3/month)
That's not what these things are. They come preloaded with apps that stream pirate broadcast streams and on-demand servers operated out of China.
It could be possible, I haven't done the math though.
Stremio +Torbox is $3/month and they can probably share 10+ households on one TorBox account so it could work out. The seller could just stop paying the TorBox subscription at whatever point and they have an incentive to do so.
That reminds me, I need to configure VLANs in my router so that all my trusted computers are isolated from all the other garbage that makes it into the network.
Mmmh, I've always wondered ... as much as VLAN's are a very useful tools to - for example - route two separate LAN's traffic through a shared physical link ... are they any good when it come to security?
I mean, I don't believe VLAN's were designed with security as a goal, and I wonder how "strong" the virtual wall between two VLAN's actually is?
Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physical connection where packets from both VLANs happen to travel?
Just wondering.
Krebs' blog is nice, but quite often it's just re-reporting stuff from somewhere else:
Original with more details: https://www.bitsight.com/blog/fuyao-enterprise-building-ad-f...
Defrauding ad networks doesn't seem like a bad thing, although using my internet connection as a proxy is obviously terrible. It wouldn't surprise me to learn that my connection is being sold as a VPN service by the vendor.
Fraud is also bad, even if you aren't fond of those being defrauded.
Fraud that destroys market trust in a market that mostly deals in surveillance and selling intrusive data that was collected mostly unknowingly from the subject seems great to everyone who has any amount of integrity.
It'll be a marginal effect, but fake clicks impacts the ad buyer, which then impacts their financials and pricing.
The only winner here is the scammers running the fake affiliate sites on which these sticks are "clicking". Or, am I missing some facet of this enterprise?
What this misses is the person buying the TV stick doesn't care about the impact on the ad market. The bigger problem is residential proxying, because their IP will end up getting used for something bad.
Another winner is the person who gets to watch cheap digital TV, without putting together a usable antenna and limiting their reception to the broadcast channels that are nearby.
I mean: They just pay the money, plug the thing in, push some buttons, and: TV happens. Right?
You really don't want fraudulent clicks ("invalid traffic", per industry lingo) coming from your home network, because any publishers (apps and websites, per normal-people lingo) who use tools designed to block invalid traffic might start flagging legitimate traffic from your network.
Can confirm. I used to use Ad Nauseam (Firefox extension that clicks all ads), eventually stopped when I was getting captcha'd left and right.
Also, visitors on my wifi started getting strange ads. Yes I threw off the algo, but I'm a guy with wife, I'd rather get car ads than like divorce lawyers + gay dating sites.
Theres the question of whether or not the fraudulent advertisement clicking is using enough traffic to inconvenience or impose fees upon the user but otherwise I agree with you and am tempted to buy one just to fuck with advertisers.
Backdoors and spying are also a problem in theory except at this point you can't even trust "legitimate" companies on that front so it's a moot point.
> otherwise I agree with you and am tempted to buy one just to fuck with advertisers.
How that actually works in practice is that your favorite sites make less money and your IP gets a bad reputation so you CAPTCHAs or outright blocked. There’s no “sticking it to the man” here, just contributing to the frictional grind making the internet worse for ordinary people.
why is running a proxy a bad thing? someone profiting off it could be bad maybe, but even that is good if it pays for my subscription.
but compare running tor nodes, and especially exit nodes. that surely would be a good thing, so at least if you think tor is good then running a proxy should be the same and it should be normalized.
doing it in secret without the user knowing is what's bad
https://lwn.net/Articles/1080822/ Do you really want to be a part of the scraper problem?
Because your home IP address is going to be associated with criminal activity. So if that’s acceptable “payment” then I guess there’s no issue
Indeed without my permission is implied. Without it, you have no idea what traffic is being routed and could be on the hook for something nasty like CSAM.
Those are different issues. Permission doesn't mean you know what the content is, and lack of permission doesn't mean they're going to load anything weird or bad. Lack of permission implies worse ethics overall, but an operation focused on clicking ads will be loading relatively normal sites.
A familly member had one of those (he had to pay a yearly subscription in addition to the stick). Network would be unusable as soon as it was on for anyone else, and it also tried to scan things on the local network. It was indeed connecting to all kind of services all over the world (and saturating some tables in the router doing so which blocked other clients). Definitely evil, definitely on purpose.
Reading this, I caught myself wondering how we distill what's in this excellent write up into something the average consumer understands, including the dangers from buying and using devices like this.
Is it a graphic that's shared? Something else? I am sure we all know or have heard of people with these devices that promise free streaming.
The bigger problem is convincing them to care. Botnets are abstract - where's the pain to them? Ad farms? That's "just hurting big corporations".
Remember, a significant portion of the population got angry (often violently so) when just asked to wear a mask to protect their neighbors. And the threat there was significantly easier to explain.
Just tell the anti mask types the TV sticks come with CCP hacking software preinstalled.
I warned them about the risk of those things and showed them what I found, they continued buying the next generation (that person and his two >40yo kids). They NEEDED to watch those soccer games more than they cared about security...
My "streaming device" of choice, ThinkCentre Tiny with Linux, always feels validated with news like these. It fits behind a TV, you can get it second hand for around $40 and depending on model it can even act as a retro game console as well.
LG televisions and monitors spy on their users and install unwanted software. Half of all smart tvs are running "residential proxy" malware. Google is banning sideloading but happily hosting apps using the Bright SDK.
Sorry, but "your tv stick does ad fraud" is just about the most innocent thing I've seen in a while. Everyone in this market is doing the shadiest shit you can imagine. There are no good brands left, you just get to pick what logo your Malware Entertainment Device has.
Any way to identify or block these proxy and ad click services in the router? Say a Ubiquiti or even pfsense?
I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.
Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?
My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.
Thankfully this seems limited to a specific device (H96). Darknet diaries has a good story about streaming devices https://www.youtube.com/watch?v=dS6PkuZuxJ4
It's not just one device line; Have a look at the list maintained by the proxy tracking service Synthient, which tracks streaming boxes, digital picture frames and other IoT devices that have been known to bundle residential proxy software, among other malicious apps. They currently track almost 1,000 different makes and model numbers.
https://github.com/synthient/public-research/blob/main/2026/...
I bet this is much broader than we all realized because just earlier today I was reading on https://gist.github.com/probonopd/3ad6b7777caea1503f00d5fe77... in order to tinker with a cheap (like really cheap) Android video projector : "Device: Magcubic HY300 Pro Android Projector (ui_Veng.projector) Issue: Device was being used as a residential proxy node without consent, causing thousands of suspicious DNS requests and bandwidth usage." linked in there just few months ago.
It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique.
An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.
I do not see problems with fake ad clicks and have no sympathy for ad companies.
Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.
What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.
How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:
- the user must be able to re-flash firmware with their own code.
- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.
- any telemetry or data collection, or updates must be opt-in only and disabled by default.
- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.
Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.
> I do not see problems with fake ad clicks and have no sympathy for ad companies.
I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.
Sure. And you'll quite literally never be able to get any meaningful reduction in this practice unless you attack it at the level of big, publically known companies; the warnings about these local dinky things I suppose are not harmful and help individuals a bit -- but I'm concerned they give the entirely false impression that the extremely similar stuff coming from the big boys is definitely a-ok.
Reduction in what practice? Are there big companies doing ad fraud?
I want big companies to stop spying on me, which is a completely different issue.
> What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information.
The Snowden leaks showed that the US was already doing this. I'm certain that everything purchased is already infected with something. Most likely bugs and bad security.
>What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information.
Most Americans are at a greater threat of harm from their own government that a foreign one. What worries me is all the mass surveillance done by big tech which bypasses the 4th Amendment and gives the government Americans data without a warrant.
There's already a front door with the adtech for US alphabet boys. This could likely be collected by others as well. We saw this happened where foreign hackers exploited a backdoor designed for American authorities[1]. This is what experts are referring to when they say there's no backdoor only for me.
This could be compelling to politicians, though, and would certainly be a step in the right direction.
>- any telemetry or data collection, or updates must be opt-in only and disabled by default
This should be how it is for everything foreign made software or not. Would be very hard to get done with the big tech lobby in the US.
[1] https://techcrunch.com/2024/10/07/the-30-year-old-internet-b...
> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed
Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?
> for every imported device having a CPU and Internet connectivity
Why limit this to imported devices?
>> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed
> Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?
Cheap, slow-moving drones are the hot new missiles on the battlefield of today. This often talked-about model files at 115 mph (https://en.wikipedia.org/wiki/HESA_Shahed_136).
In some areas GPS is spoofed and the displayed location is wrong. If, for example, a "smart" car gets a task from its manufacturer to film some secret object, it would fail if it relied only on GPS and did not use cell towers and WiFi points for determining its location. So knowing their location determines whether the mission would fail or succeed. So foreign devices should not be allowed to collect such information.
I think that might have been semi-sarcastic. I mean, there are lots of reasons to do this sort of thing, some are bad, some are not so bad, most are not war.
> a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed
Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys.
Could it be used for missiles? Sure. Is it obviously the intention? No.
Yeah this is extremely standard:
Apple: https://support.apple.com/en-us/102515
> If Location Services is on, your device will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers to Apple to augment Apple's crowd-sourced database of Wi-Fi hotspot and cell tower locations.
Google: https://support.google.com/android/answer/15157297?sjid=1648...
> When Location Accuracy is on, Google periodically collects information about the locations of wireless signals and sensors observed by your device to crowdsource location estimates. This helps everyone find locations better.
Mozilla used to run a very similar service: https://en.wikipedia.org/wiki/Mozilla_Location_Service
Not to mention truly crowd-sourced databases like wigle.net.
They should ask the permission from device owner and local government before collecting the data.
They do ask the device owner - if you review the location services description on android[1] you will see they explicitly say they collect this information from your device. I strongly disagree that they need to get government permission for this - they are simply recording signals that reach the device, akin to making notes about what kinds of cars you see. This is not a thing a government should have control over people doing and not a thing that should be registered with the governement.
[1] https://support.google.com/android/answer/3467281?sjid=66634...
In the article you refer to, I see no mention of asking user's permission. However, I remember, when using an old version of Android, there indeed was a popup nagging me to allow sharing location data with Google every time I enabled GPS. Very annoying, makes you want to never enable GPS in the first place.
Regarding the government, the problem is that many people do not fully understand the mechanism of collecting the data. I remember the case when members of US military disclosed the location of secret objects through fitness tracker app. And they were probably smarter than average smartphone user. Obviously it would be better if enabling GPS required an approval from their commander.
Should Google ask permission from the device owner, and from the local government before collecting the data? I heard a certain foreign mobile app was banned in US for doing less than that.
Oh this was a failed device that Mozilla offered. I had a couple back in the day. It was called Matchstick. Sick t shirts. Basically an OSS chromecast.
Fake ad clicks cost the advertiser money, not the ad company.
Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)
> Fake ad clicks cost the advertiser money, not the ad company.
It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.
Good products do not need much advertising. For example, when buying DRAM, I compare the specification and prices and do not look at the advertisement.
The problem is that when you need these powers most as a citizen is when your government is least likely to allow it.
> I do not see problems with fake ad clicks and have no sympathy for ad companies.
Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.
> Yeah, it's like—a cheap streaming stick AND it poisons the advertising well?
Keep in mind that it's your IP and identity associated with those clicks and anything else criminals decide to do with your IP address. That means you're identity is being linked to things you may or not want to be known as being interested/involved in. The ads your TV stick clicks on can cause data brokers to include your name in lists of people who are heavily into drugs, have mental disorders, belong to certain religions or political parties, etc. All of that can come back to haunt you later.
Depending on what other activity your connection is used for as a proxy it can also get you in trouble with the police or with your ISP.
My pinenote runs the original spyware image - I don't have a problem with Winnie the Pooh reading along with me.
A pirate TV box from China presents a security threat?
This is my surprised face.
Brazil. Last year I effectively blocked Brazil for a while. Ultimately I settled on three possibilities for the traffic I was seeing:
01: DDOS
10: Residential proxies
11: Somebody DDOSing residential proxies
I can’t prove it, but I live in Brazil and after getting a smart TV from LG, I started receiving challenges across all Google services, indicating they received bot traffic from my network. I only used apps from streaming services I actually paid for.
I suspect these TVs either come with residential proxies set up from the factory, or they have such poor security that they’re instantly hacked. Either way, TV manufacturers (including reputable ones like LG) are to blame.
There have been articles lately about the residential proxies loaded in apps for LG TVs. My LG has never seen a network connection, so I’m fuzzy on details.
Using low code tools to build click fraud logic FTW!
What happens when you stick this malware into your windows PC? The PC is now an accomplice to fraud?
it's just like a phone. don't buy a crappy one with firmware of unknown provenance. make sure the one you do buy has an active and effective effort that you trust that ships timely security fixes.
> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
You had me at "But"! ::swoon::
Hey that’s pretty smart! Fradulent, but very smart. I was honestly expecting botnet.
I expect many cameras of “dubious” origin are used for similar tasks, same with most “smart” devices with sufficient horsepower.
I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.
Instead they're banning stuff willy nilly left and right without really solving the problem.
But there's good stuff coming out of China as well. I recently bought a cheap e-reader which has no WiFi or internet connection and it works stellar. And I bought some cheap Chinese sport cams which also lack internet and work great.
> I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.
Personally, I think every other country should ban any product made by Google, Amazon, and Microsoft since they all spy on the users of their products too.
I've suggested legislation which would ban the sale of customer information to third-parties.
These companies could use the info they gather on customers for their own use but they cannot (re)sell it to anyone, not even the government. The reason being that the information eventually ends up abroad after which you lose all control over it.
So where can I get an actual privacy focused streaming box, even if the apps (Neflix etc) running on it are not?
These are not "streaming boxes" in the sense you are talking about. Their appeal is that they come preloaded with chinese pirate streaming apps. Traditional streaming boxes - Apple TV, Fire stick, Roku - are not affected by this, though if you want privacy-focused Apple TV is the only remaining contender, and with Apple's continued descent into advertising vendor I'd guess that one is not long for this world, either.
My understanding is that Roku bypasses DNS blocking with hardcoded tables so it can report back on various data they track on you.
Roku collects an insane amount of data on users. Basically everything that they can get their hands on
> Roughly twice per second, a Roku TV captures video “snapshots” in 4K resolution. These snapshots are scanned through a database of content and ads, which allows the exposure to be matched to what is airing. For example, if a streamer is watching an NFL football game and sees an ad for a hard seltzer, Roku’s ACR will know that the ad has appeared on the TV being watched at that time. In this way, the content on screen is automatically recognized, as the technology’s name indicates. The data then is paired with user profile data to link the account watching with the content they’re watching. https://advertising.roku.com/learn/resources/acr-the-future-...
Can you monitor its traffic and block by IP?
I’m sure you could. At what point do you just rip out the thing that is trying so hard to work around your control of your network? An Apple TV doesn’t cost that much.
The door is slowly closing on all of these blocking schemes by moving ad content to the same domains as the primary content.
This is already a common feature for analytics toolkits.
I probably could, but haven't done so yet.
Apple TV is currently the best balance of privacy and convenience. The only way to get more private is using a PC, but that limits the resolution for most streaming services to 720p or 1080p.
If you want actual privacy (rather than promises from Apple or Google), what you need is a mini-PC running Linux with the Plasma Bigscreen DE. You then use a Web browser rather than invasive "apps" for your streaming. For Youtube, there is VacuumTube (an improved Youtube Leanback client). The main limitation is capped resolution on some commercial streaming services. I believe Windows does not have that restriction, so a VM could presumably be used for streaming (I have not tried).
I assume apple TV doesn’t do malicious things like this, and we love the interface and it “just works” with HDR
Besides setting up your own device, Apple TV would be the best bet from any of the large manufacturers.
I'm increasingly being convinced the only way to do that is you do a media pc nuc. The problem, of course, is you probably won't have the netflix app. It's painful to setup such a box to stream from various services.
What's wrong with Apple TV? It runs VLC if you want to stream something from your NAS.
I tried to look at setting up an stripped down privacy-focused Android based box for Netflix, but ran into issues. Seems like you need to be spied on to run Netflix.
I tried going that route, but most apps for streaming are Android. And that was only one of the issues.
It was a rabbit hole and in the end I got back using my NVIDIA Shield. This is about 10 years now, but it’s actually still the best option.
The Onn TV devices from walmart seem fine, baseline google tracking not-withstanding... but no residential proxy or botnet participation without you knowing! You can just block them at the router and stream content locally.
kodi on an rpi5?
How hard is it to get something else on these ?
Looks like cheap small computer with a remote control.
Google clutches pearls and is shocked! Shocked! That anyone would violate its policies (while it pockets 30% of the fraudulent revenue). Shocked!
And they would have caught them but those crafty criminals spoofed the user-agent. So how _could_ they know?
I recently got an Apple TV 4K and have been really enjoying the ad free experience. Worth every penny. Our smart tv had turned into a Christmas tree of ads.
There are plenty of ads on Apple TV; huge banners right at the top of the UI, and ads that launch before you get to see the content of a show with no way to automatically disable them (you have to manually click through or just wait it out). It is infuriating (to me).
Apple TV the app has ads for Apple TV shows. Apple TV the device doesn’t have ads built in.
As much as I hate Apple for what they've done to the average consumer in regards to computing, it would be just impossible and dishonest to say anything other than Apple is the outright winner in streaming devices. The experience is so smooth.
The nvidia shield is pretty damn good as well, even if old at this point.
Considering their recent decision to give up on building Apple Maps into a serious contender and instead enshittify it with ads, I don't have much faith Apple TV will be far behind.
One hopes that the new CEO will realize the turn towards ads is ruining the Apple brand and pull back on that front.
On the other hand, these are great little devices to root and put Linux on.
A better solution is just leech the content and stick it on a generic USB flash stick.
These are popular for illegal live sports streams.
> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads ...
Compromised (or malicious from the factory) devices being recruited into bot farms for click fraud is ... a groundbreaking discovery in 2026?
> on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
To hell with AI-generated websites and advertising networks.
Say, where can I get the most effective malicious TV stick for click-frauding the fuck out of that shit? I will take fifteen! :)
I'm imaging a largescale distributed project like folding@home except instead of doing scientific research everybody is working together to fuck with advertisers, tracking cookies, etc.
No mention of Roku
I use one but only when traveling at hotels - it’s one of the only sticks that can connect to captive WiFi networks at hotels
I’ve got barely anything on it so privacy be damned - but at this point this is why I just buy apple products
I have two apple tv’s which probably do shady things too, but I’m willing to play the probabilities and assume it’s the least bad of my options short of tinkering with flashing hardware and all that stuff that used to be fun in my teens (emphasis on used to)
The best solution to this problem is to block GeoIP traffic and monitor bandwidth consumption on a per-domain basis. If something is sending data during the night, it becomes much easier to identify suspicious activity.
Generally, it's advisable to create a dedicated wifi network for all potentially hostile devices.
This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.
That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.
> That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home
That is not enough. You need to air gap devices that have legitimately no business communicating with anyone or anything outside the house. TVs, thermostats, and other Internet-of-Crap gadgets do not need "firmware updates." Either they work out of the box, offline or within the LAN, or they get sent back for a refund wherever they came from.
I don't think this would make a big difference for the threat model described in the OP? They'd still be able to use your IP Address and potentially do nefarious things through your role as an unwitting proxy.
Using one device as a proxy is a few steps away from trying to exploit and infiltrate the other devices on your machine as well. An unwitting proxy is already crossing the line to putting a fox in the henhouse.
Limiting what outbound access devices can/can't have is an important skill to learn.
> allowing low-skilled operators to drag blocks of code together in their editor — without any need to understand what the underlying code blocks do or how they work.
We're called engineers brian.
To those who are OK with these devices: when you engage in corruption, do you have any moral standing against your politicians when they engage in corruption?
Both you, and the corrupt politicians, are eating away at the trust that underpins society. Certainly, you can argue, your bite is just a tiny one; the politician is eating the whole apple.
At the end of the day, everyone suffers from the decline of trust and casual acceptance of fraud.
> major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands that bundle unofficial versions of Google’s Android operating system and are frequently marketed (via online influencers) as a way to access a broad array of streaming services and live broadcasts without a subscription.
This is why I giggle when people talk about ending Section 230 in the USA (or various international counterparts thereof).
The largest companies on Earth are happily selling hacked piracy spyware botnet garbage. Not just hosting malicious posts for free like Section 230 protects, but selling illegal physical devices and taking a cut of the profit and excusing it with a pathetic whack-a-mole moderation system. It's already illegal and the law has already failed.
Sean Parker's mistake was that he wasn't rich enough.
Laws are for poor people.
I didnt know anybody bought a streaming stick anymore
Of all the evils normally associated with visual programming languages, enabling cybercrime isn't one I've previously considered. Now that I've seen it, I'm surprised it wasn't more common before LLMs appeared.
And which part of "ad fraud" is the fraud? As far as I can tell, ad networks and advertisers are the fraud and they are also part of the increasing surveillance state.
Didn't know Krebs was a mainstream news puppet.
It's called fraud because the ad host colludes with (or directly controls) the botnet to get lots of clicks on ads hosted on their sites, making them money at the expense of advertisers.
If you just want to spam clicks on ads you don't financially be edit from, go for it.