I hesitate to blame the victim here, but why on earth would you do that? “$40 Chinese-made” didn’t give you pause?
Of course theres good products made in China, and plenty of entirely Chinese brands killing it doing their thing.
A guy in Vietnam mentioned that one of the largest ISPs there used these really dodgy Chinese modems which were so notoriously insecure that it was apparently common knowledge that you should replace them if performance was slow because that was a sign that yours was being used by a botnet. Apparently the cost of access to one of those nodes was so low that the spammers don’t even really monitor their bots.
Is it a graphic that's shared? Something else? I am sure we all know or have heard of people with these devices that promise free streaming.
Remember, a significant portion of the population got angry (often violently so) when just asked to wear a mask to protect their neighbors. And the threat there was significantly easier to explain.
I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.
It's difficult to judge the price of media products. We have legal music streaming services that charges you an album's worth of money a month and lets you listen to millions of songs. You can pick up old AAA games for less than ten bucks. I'd say when people say that price tag, they don't think they get scammed into being a part of a botnet. They think the device manufacturer cut a good deal with the media rights holders.
So yes, I do want to blame the purchasers of these things, sometimes. To prove her point that her stamps were legitimate, she mailed me a card using one of her half priced (but likely fake) stamps and it made it through!
That was his justification for a satellite descrambler, they're sending me the signals, obviously I'm allowed to.
So they trust literally everything they read. I still don't think my folks can fathom you can spin up a very real looking newspaper website with fake articles in about 10 minutes.
Amazon will be notified they sold something illegal and will take it down and ban the seller who will immediately launch a new store under a new name.
The purchaser, on the other hand, will be fully liable for whatever horrible thing they bought.
So is it greed? Yes, but I did it too so now that its more accessible I cannot really blame people.
There are lots of people alive who grew up during the days of broadcast TV and radio. I get why they might not understand the difference.
To most people IPTV is a bunch of gibberish letters, indistinguishable from the gibberish brands on Amazon. Someone's grandma from Colorado doesn't deserve to get scammed because she didn't research the acronyms.
- How are these "legitimately free"? For example AMC is a commercial TV channel and as far as I know, they don't offer free streaming. Same goes for MGM, FilmBox etc.
- Strictly speaking this isn't IPTV, it's just web streams. IPTV is usually delivered via multicast (MPEG-TS/RTP/RTSP streams, over UDP mostly).
[1] Can someone explain what the theory of the product is here? It sounds like they’re marketing these things as ways for the customer to commit fraud, for example by connecting to someone else’s login. How else would the customer expect to be able to get free Netflix or whatever?
Anyway, I think some level of blame is warranted.
It reminds me of the saying: "It Is Difficult to Get a Man to Understand Something When His Salary Depends Upon His Not Understanding It".
If these people thought about it for a few minutes, they would understand, but they choose not to, as ignoring it is too advantageous.
I admit I was tempted, as the price of all streaming services goes up, and services become more and more fragmented. During the same period where I have not had a raise.
you are aware broadcast TV never ended?
But, I think it's far more common for people to have a TV service today, perhaps since comcast and their ilk push hard the TV/phone/internet bundle, and gone are the years when everyone would fiddle with the antennas on the back of their TV to get the right reception.
If they were using the system to rip off random people, I'd be 100% against it, if they are fucking Google and the giant corps that advertise with them, ehh.. not my problem and can't be assed to care. Google is not a positive force in the world. Hasn't been for many years.
Tankies like this make me laugh
These things are not what HN is for, and destroy what it is for, so we ban accounts that do them repeatedly.
If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here, we'd appreciate it.
Stremio +Torbox is $3/month and they can probably share 10+ households on one TorBox account so it could work out. The seller could just stop paying the TorBox subscription at whatever point and they have an incentive to do so.
The only winner here is the scammers running the fake affiliate sites on which these sticks are "clicking". Or, am I missing some facet of this enterprise?
I mean: They just pay the money, plug the thing in, push some buttons, and: TV happens. Right?
Also, visitors on my wifi started getting strange ads. Yes I threw off the algo, but I'm a guy with wife, I'd rather get car ads than like divorce lawyers + gay dating sites.
Backdoors and spying are also a problem in theory except at this point you can't even trust "legitimate" companies on that front so it's a moot point.
but compare running tor nodes, and especially exit nodes. that surely would be a good thing, so at least if you think tor is good then running a proxy should be the same and it should be normalized.
doing it in secret without the user knowing is what's bad
https://github.com/synthient/public-research/blob/main/2026/...
Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.
What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.
How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:
- the user must be able to re-flash firmware with their own code.
- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.
- any telemetry or data collection, or updates must be opt-in only and disabled by default.
- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.
Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.
I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.
Most Americans are at a greater threat of harm from their own government that a foreign one. What worries me is all the mass surveillance done by big tech which bypasses the 4th Amendment and gives the government Americans data without a warrant.
There's already a front door with the adtech for US alphabet boys. This could likely be collected by others as well. We saw this happened where foreign hackers exploited a backdoor designed for American authorities[1]. This is what experts are referring to when they say there's no backdoor only for me.
This could be compelling to politicians, though, and would certainly be a step in the right direction.
>- any telemetry or data collection, or updates must be opt-in only and disabled by default
This should be how it is for everything foreign made software or not. Would be very hard to get done with the big tech lobby in the US.
[1] https://techcrunch.com/2024/10/07/the-30-year-old-internet-b...
Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?
> for every imported device having a CPU and Internet connectivity
Why limit this to imported devices?
> Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?
Cheap, slow-moving drones are the hot new missiles on the battlefield of today. This often talked-about model files at 115 mph (https://en.wikipedia.org/wiki/HESA_Shahed_136).
Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys.
Could it be used for missiles? Sure. Is it obviously the intention? No.
Apple: https://support.apple.com/en-us/102515
> If Location Services is on, your device will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers to Apple to augment Apple's crowd-sourced database of Wi-Fi hotspot and cell tower locations.
Google: https://support.google.com/android/answer/15157297?sjid=1648...
> When Location Accuracy is on, Google periodically collects information about the locations of wireless signals and sensors observed by your device to crowdsource location estimates. This helps everyone find locations better.
Mozilla used to run a very similar service: https://en.wikipedia.org/wiki/Mozilla_Location_Service
Not to mention truly crowd-sourced databases like wigle.net.
[1] https://support.google.com/android/answer/3467281?sjid=66634...
Regarding the government, the problem is that many people do not fully understand the mechanism of collecting the data. I remember the case when members of US military disclosed the location of secret objects through fitness tracker app. And they were probably smarter than average smartphone user. Obviously it would be better if enabling GPS required an approval from their commander.
Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)
It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.
Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.
Keep in mind that it's your IP and identity associated with those clicks and anything else criminals decide to do with your IP address. That means you're identity is being linked to things you may or not want to be known as being interested/involved in. The ads your TV clicks on can cause data brokers to include your name in lists of people who are heavily into drugs, have mental disorders, belong to certain religions or political parties, etc. All of that can come back to haunt you later.
Depending on what other activity your connection is used for it can also get you in trouble with the police or with your ISP.
I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.
Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?
My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.
Instead they're banning stuff willy nilly left and right without really solving the problem.
But there's good stuff coming out of China as well. I recently bought a cheap e-reader which has no WiFi or internet connection and it works stellar. And I bought some cheap Chinese sport cams which also lack internet and work great.
Personally, I think every other country should ban any product made by Google, Amazon, and Microsoft since they all spy on the users of their products too.
It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique.
An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.
This is my surprised face.
01: DDOS
10: Residential proxies
11: Somebody DDOSing residential proxies
I suspect these TVs either come with residential proxies set up from the factory, or they have such poor security that they’re instantly hacked. Either way, TV manufacturers (including reputable ones like LG) are to blame.
You had me at "But"! ::swoon::
I expect many cameras of “dubious” origin are used for similar tasks, same with most “smart” devices with sufficient horsepower.
Looks like cheap small computer with a remote control.
This is already a common feature for analytics toolkits.
Both you, and the corrupt politicians, are eating away at the trust that underpins society. Certainly, you can argue, your bite is just a tiny one; the politician is eating the whole apple.
At the end of the day, everyone suffers from the decline of trust and casual acceptance of fraud.
Compromised (or malicious from the factory) devices being recruited into bot farms for click fraud is ... a groundbreaking discovery in 2026?
> on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
To hell with AI-generated websites and advertising networks.
Say, where can I get the most effective malicious TV stick for click-frauding the fuck out of that shit? I will take fifteen! :)
This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.
That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.
That is not enough. You need to air gap devices that have legitimately no business communicating with anyone or anything outside the house. TVs, thermostats, and other Internet-of-Crap gadgets do not need "firmware updates." Either they work out of the box, offline or within the LAN, or they get sent back for a refund wherever they came from.
Limiting what outbound access devices can/can't have is an important skill to learn.
I use one but only when traveling at hotels - it’s one of the only sticks that can connect to captive WiFi networks at hotels
I’ve got barely anything on it so privacy be damned - but at this point this is why I just buy apple products
I have two apple tv’s which probably do shady things too, but I’m willing to play the probabilities and assume it’s the least bad of my options short of tinkering with flashing hardware and all that stuff that used to be fun in my teens (emphasis on used to)
We're called engineers brian.
This is why I giggle when people talk about ending Section 230 in the USA (or various international counterparts thereof).
The largest companies on Earth are happily selling hacked piracy spyware botnet garbage. Not just hosting malicious posts for free like Section 230 protects, but selling illegal physical devices and taking a cut of the profit and excusing it with a pathetic whack-a-mole moderation system. It's already illegal and the law has already failed.
Sean Parker's mistake was that he wasn't rich enough.
Laws are for poor people.
I scanned the comments and I didn't see anyone suggesting that these companies should share any responsibility for selling these harmful products. Why is it that they seem to get a pass? Would we feel the same about giant retailers selling tainted food, or unsafe children's toys?
Voters don’t like seeing themselves or their kids get hurt, but they do like lower cost live sports.