Fast forward to last month, now I have started selling these in Barcelona, Spain where I am based out of and branched it into three use cases: digital signage, casting, and a portable computer for presentations at events. Here is the link with features: https://soljacast.com
I scanned the comments and I didn't see anyone suggesting that these companies should share any responsibility for selling these harmful products. Why is it that they seem to get a pass? Would we feel the same about giant retailers selling tainted food, or unsafe children's toys?
I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.
I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.
Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?
My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.
I expect many cameras of “dubious” origin are used for similar tasks, same with most “smart” devices with sufficient horsepower.
A guy in Vietnam mentioned that one of the largest ISPs there used these really dodgy Chinese modems which were so notoriously insecure that it was apparently common knowledge that you should replace them if performance was slow because that was a sign that yours was being used by a botnet. Apparently the cost of access to one of those nodes was so low that the spammers don’t even really monitor their bots.
Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.
What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.
How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:
- the user must be able to re-flash firmware with their own code.
- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.
- any telemetry or data collection, or updates must be opt-in only and disabled by default.
- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.
Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.
Hell, there's a section of comments that would probably going "hey, RELAX guy" because it's not US companies doing this. For any American companies that do this though, sure - block/suspend/prosecute.
Original with more details: https://www.bitsight.com/blog/fuyao-enterprise-building-ad-f...
Sorry, but "your tv stick does ad fraud" is just about the most innocent thing I've seen in a while. Everyone in this market is doing the shadiest shit you can imagine. There are no good brands left, you just get to pick what logo your Malware Entertainment Device has.
This is my surprised face.
Oh no! Not the advertising networks!
You had me at "But"! ::swoon::
Anyway, the box is powerful enough to do several things. You can install a IP tv if you want. If you don't, you still have a pretty good media center (you can hook up an external hd on it)
I use one but only when traveling at hotels - it’s one of the only sticks that can connect to captive WiFi networks at hotels
I’ve got barely anything on it so privacy be damned - but at this point this is why I just buy apple products
I have two apple tv’s which probably do shady things too, but I’m willing to play the probabilities and assume it’s the least bad of my options short of tinkering with flashing hardware and all that stuff that used to be fun in my teens (emphasis on used to)
We're called engineers brian.
And they would have caught them but those crafty criminals spoofed the user-agent. So how _could_ they know?
Both you, and the corrupt politicians, are eating away at the trust that underpins society. Certainly, you can argue, your bite is just a tiny one; the politician is eating the whole apple.
At the end of the day, everyone suffers from the decline of trust and casual acceptance of fraud.
Looks like cheap small computer with a remote control.
This is why I giggle when people talk about ending Section 230 in the USA (or various international counterparts thereof).
The largest companies on Earth are happily selling hacked piracy spyware botnet garbage. Not just hosting malicious posts for free like Section 230 protects, but selling illegal physical devices and taking a cut of the profit and excusing it with a pathetic whack-a-mole moderation system. It's already illegal and the law has already failed.
Sean Parker's mistake was that he wasn't rich enough.
Laws are for poor people.
Instead they're banning stuff willy nilly left and right without really solving the problem.
But there's good stuff coming out of China as well. I recently bought a cheap e-reader which has no WiFi or internet connection and it works stellar. And I bought some cheap Chinese sport cams which also lack internet and work great.
01: DDOS
10: Residential proxies
11: Somebody DDOSing residential proxies
This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.
That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.
It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique.
An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.
Compromised (or malicious from the factory) devices being recruited into bot farms for click fraud is ... a groundbreaking discovery in 2026?
> on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
To hell with AI-generated websites and advertising networks.
Say, where can I get the most effective malicious TV stick for click-frauding the fuck out of that shit? I will take fifteen! :)
Didn't know Krebs was a mainstream news puppet.
It reminds me of the saying: "It Is Difficult to Get a Man to Understand Something When His Salary Depends Upon His Not Understanding It".
If these people thought about it for a few minutes, they would understand, but they choose not to, as ignoring it is too advantageous.
I admit I was tempted, as the price of all streaming services goes up, and services become more and more fragmented. During the same period where I have not had a raise.
Anyway, I think some level of blame is warranted.
From a link above to the story on darknetdiaries:
> For Pokemon, there is a website that tells you how to watch this. You start off on Netflix, then swap over to the Pokemon streaming service, which is the only place that has Season 2, then swap over to Prime Video for Seasons 3 through 5, swap to Freevee, then Hoopla. Season 13 is only on Amazon, though. Then swap to Tubi, then Hulu, then Roku channel, and then finally back to the Pokemon streaming, and then Netflix. Easy.
That's 8 different streaming services to view one series.
Voters don’t like seeing themselves or their kids get hurt, but they do like lower cost live sports.
It's worth separating the two populations:
My users had money and had considered legal subscriptions. They paid me because the legal product was worse—in my case, sports blackouts, a bunch of different apps, etc. They knew what they were buying into and they had weighed the risk. I can tell you right now some of my former users have bought into this market.
Then there's the unwitting: a person buying one of these devices at a too-good-to-be-true price is treating it as a hardware purchase from Amazon, where the actual monetization isn't inferable from the listing. Calling it too good to be true assumes the buyer can see what shit they're standing in. They can't. There's no visible market here. It's just a product page with reviews.
To add to this: the proxy exit is exactly why these cost so little. Demand for residential IPs is booming (check some of the proxy subreddits to see what I mean).
The ironic part is that there's a chance the person who bought one of these boxes to watch pirated sports was the exit node I was using to acquire the feeds in the first place.
It's difficult to judge the price of media products. We have legal music streaming services that charges you an album's worth of money a month and lets you listen to millions of songs. You can pick up old AAA games for less than ten bucks. I'd say when people say that price tag, they don't think they get scammed into being a part of a botnet. They think the device manufacturer cut a good deal with the media rights holders.
It’s not like they’re buying these things out of a car trunk in a dark alley. These retailers need to be held liable for selling these things. If they sell this stuff, why not illicit drugs?
If they are unable to maintain control of 3rd party sellers, then they should end the 3rd party seller program. It has done nothing but damage Amazon’s reputation, and it just keeps getting worse.
The Snowden leaks showed that the US was already doing this. I'm certain that everything purchased is already infected with something. Most likely bugs and bad security.
Most Americans are at a greater threat of harm from their own government that a foreign one. What worries me is all the mass surveillance done by big tech which bypasses the 4th Amendment and gives the government Americans data without a warrant.
There's already a front door with the adtech for US alphabet boys. This could likely be collected by others as well. We saw this happened where foreign hackers exploited a backdoor designed for American authorities[1]. This is what experts are referring to when they say there's no backdoor only for me.
This could be compelling to politicians, though, and would certainly be a step in the right direction.
>- any telemetry or data collection, or updates must be opt-in only and disabled by default
This should be how it is for everything foreign made software or not. Would be very hard to get done with the big tech lobby in the US.
[1] https://techcrunch.com/2024/10/07/the-30-year-old-internet-b...
I hesitate to blame the victim here, but why on earth would you do that? “$40 Chinese-made” didn’t give you pause?
This is the problem with being an “everything store”. “Everything” includes a lot of things most consumers would like to be protected from, and assume they are due to the long history of retailers standing behind the products they sell. That history seems to have come to an end. They only stand behind it enough to offer a refund if there is a problem, not to ensure it’s good before selling it.
[1] Can someone explain what the theory of the product is here? It sounds like they’re marketing these things as ways for the customer to commit fraud, for example by connecting to someone else’s login. How else would the customer expect to be able to get free Netflix or whatever?
So yes, I do want to blame the purchasers of these things, sometimes. To prove her point that her stamps were legitimate, she mailed me a card using one of her half priced (but likely fake) stamps and it made it through!
There are lots of people alive who grew up during the days of broadcast TV and radio. I get why they might not understand the difference.
but compare running tor nodes, and especially exit nodes. that surely would be a good thing, so at least if you think tor is good then running a proxy should be the same and it should be normalized.
doing it in secret without the user knowing is what's bad
The only winner here is the scammers running the fake affiliate sites on which these sticks are "clicking". Or, am I missing some facet of this enterprise?
I mean, I don't believe VLAN's were designed with security as a goal, and I wonder how "strong" the virtual wall between two VLAN's actually is?
Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physical connection where packets from both VLANs happen to travel?
Just wondering.
Is it a graphic that's shared? Something else? I am sure we all know or have heard of people with these devices that promise free streaming.
Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys.
Could it be used for missiles? Sure. Is it obviously the intention? No.
I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.
Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.
Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?
> for every imported device having a CPU and Internet connectivity
Why limit this to imported devices?
Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks.
Pedro Falé is a threat researcher with the security firm Bitsight. Falé told KrebsOnSecurity he was able to peer inside a vast and complex ad fraud network by registering an expired domain name that was used to coordinate fake ad clicks across a particularly popular brand of these streaming devices known as H96.

An H96 TV streaming device currently advertised for sale on Amazon.
Falé said the domain he scooped up was previously used for telemetry, periodically collecting full hardware information and the entire list of installed apps from tens of thousands of H96 streaming sticks plugged into television sets around the globe. But upon inspecting the traffic being funneled to the domain, he discovered nearly all of the TV boxes transmitting data claimed to be mobile phone models from a variety of manufacturers, including Samsung, Vivo, Huawei, and Xiaomi.
“We noticed something was wildly wrong,” Falé said. “Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.'”

Image: Bitsight.
The researcher found all of the devices reported having the same two apps installed, and that those apps were made by a company called Zhejiang Fengwo IoT Technology Ltd, an entity founded in 2019 in mainland China which operates an ad-publishing portfolio under the name Fengwo Group. Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.
“Bitsight TRACE identified several Hong Kong, Singapore, and single person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group,” Falé wrote in a report released today about their findings.
Falé said an analysis of the apps shows they help to coordinate an ad fraud network that uses these H96 devices as a captive traffic source to click on ads at AI-generated websites operated by the Fengwo Group.
Bitsight discovered the websites contain machine-generated news articles and graphics across a range of categories, including finance, health, education, gaming, music and food blogs. But they also found none of those sites displayed ads unless the device visiting the page matched the spoofed mobile profile of these H96 devices.
The domain for the Fengwo Group — fwgcloud[.]com — claims the company is “redefining the boundaries of human-AI interaction,” and that it has created more than 120,000 “AI digital humans” available to rent for everything from emotional companionship to 24/7 customer service and creative design.

The homepage for fwgcloud dot com.
Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software.
According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work.

The Blockly homepage.
“An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type,” reads Bitsight’s report. “Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use.”
Bitsight even found one of the Fengwo Group app developers mentioning exactly these advantages, noting the developer remarked that “only a small number of highly-skilled developers are needed to build the template execution-unit images,” and that “developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company’s operating costs.”
Falé said if a user’s H96 streaming stick is selected for a specific fraud task, it will be pushed the appropriate Blockly module according to the task desired, which can include silently launching a web browser, visiting websites, browsing pages, managing tabs, and clicking on ads.
To ensure the TV boxes masquerading as mobile phones can reliably click on ads displayed via the AI-generated websites, the Fengwo group “fuses three vision and reasoning systems into a single interface,” allowing the bots to correctly identify an ad on the webpage and navigate the site much like a human would, the Bitsight report observed.

Examples of ad landing pages linked to the Fengwo Group. Image: Bitsight.
Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.
Falé said he believes the TV boxes are set up this way because its ad fraud activities are far more resource intensive and could interfere with the device’s stated purpose — streaming video content over the Internet.
Despite repeated warnings from the FBI and security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands that bundle unofficial versions of Google’s Android operating system and are frequently marketed (via online influencers) as a way to access a broad array of streaming services and live broadcasts without a subscription.

Image: fbi.gov.
In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed. This software rents the user’s Internet address out to anonymous paying customers, who run the gamut from aggressive content scraping firms to ticket scalpers and outright cybercriminals.
What’s more, because these generic (and generally dirt cheap) TV boxes are all horribly insecure by default and bereft of any kind of authentication, installing one on your home or office network only invites further mischief. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in both the residential proxy software and the streaming devices themselves.
Bitsight said it tracked approximately 38,000 TV boxes globally phoning home to the expired Fengwo Group domain, and based on that number the report estimates this ad fraud network brings in revenues of close to $50,000 a day (not counting substantial revenue from the residential proxy side of the business). However, Falé emphasized that these estimates are highly conservative and based on telemetry from just one of the Fengwo Group’s core (but older) domains.
As for the Fengwo Group’s claim to have 120,000 “digital humans” at their disposal, Bitsight’s report concludes it could be just a clever marketing scheme and/or a way to avoid drawing suspicion to the company’s operations.
“Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size,” Falé wrote in the report. “This could also be the case here.”
If the Fengwo Group truly does have tens of thousands of “AI humans” at its beck and call, it does not appear to have dedicated any of them to fielding inquiries from its own website. KrebsOnSecurity sought comment from the Fengwo Group by emailing the contact address listed on the company’s homepage, but the request bounced back with the reply, “Your message couldn’t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it’s getting too much mail right now.”
As Bitsight’s analysis shows, when it comes to TV boxes and streaming sticks, it’s best to stick to name brands from reputable manufacturers, and then to be sparing and careful with any apps you choose to install on the device — as many of those can bundle residential proxy software as well. Google says consumers can confirm whether or not a device is built with the official Android TV OS and Play Protect certification by following these instructions.
Additionally, Synthient maintains a running list of IoT devices that have been known to ship to consumers with residential proxy software and other malicious apps pre-installed. Careful readers will notice Synthient’s list includes other IoT devices apart from streaming sticks and boxes: As the FBI has warned, residential proxy software has also been found in other popular consumer IoT devices from random brands, particularly digital photo frames.
You already answered it: block it from being sold.
1) Make Amazon responsible for the products they are selling. 2) Introduce a law banning malware tv sticks 3) Sue Amazon for a percentage of their yearly revenue when caught violating it 4) Amazon will finally start caring and do some kind of review on the crap they sell.
US retailers can be told they can't sell it here. If you buy it outside of that, well that is buyer beware, but 99% of people aren't buying things from Alibaba or ordering from some random foreign store, they are buying them off US Amazon, Walmart, big box retailers, etc. You don't have to ban things consumer level to deal with 99% of it, you just gotta tell big corporations no and stop dismissing any ideas that put responsibility or liability on big business.
Or if I open up a gas station and allow any company without oversight to sell "supplements" through my shelves and cops arrest me for selling heroin, I don't get a free pass.
Why should amazon or Walmart get a free pass just because they sell more items?
If you just want to spam clicks on ads you don't financially be edit from, go for it.
https://github.com/synthient/public-research/blob/main/2026/...
That is not enough. You need to air gap devices that have legitimately no business communicating with anyone or anything outside the house. TVs, thermostats, and other Internet-of-Crap gadgets do not need "firmware updates." Either they work out of the box, offline or within the LAN, or they get sent back for a refund wherever they came from.
And don't forget about counterfeit products (which look like original but different in firmware) and supply chain attack vectors, which are really, really common.
If you want to buy something as simple as a feature phone, going to a store with 10 of them will give you at least 1/10 chance to buy a phone with a trojan/backdoor.
Keep in mind that it's your IP and identity associated with those clicks and anything else criminals decide to do with your IP address. That means you're identity is being linked to things you may or not want to be known as being interested/involved in. The ads your TV stick clicks on can cause data brokers to include your name in lists of people who are heavily into drugs, have mental disorders, belong to certain religions or political parties, etc. All of that can come back to haunt you later.
Depending on what other activity your connection is used for as a proxy it can also get you in trouble with the police or with your ISP.
Personally, I think every other country should ban any product made by Google, Amazon, and Microsoft since they all spy on the users of their products too.
I suspect these TVs either come with residential proxies set up from the factory, or they have such poor security that they’re instantly hacked. Either way, TV manufacturers (including reputable ones like LG) are to blame.
Remember, a significant portion of the population got angry (often violently so) when just asked to wear a mask to protect their neighbors. And the threat there was significantly easier to explain.
Apple: https://support.apple.com/en-us/102515
> If Location Services is on, your device will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers to Apple to augment Apple's crowd-sourced database of Wi-Fi hotspot and cell tower locations.
Google: https://support.google.com/android/answer/15157297?sjid=1648...
> When Location Accuracy is on, Google periodically collects information about the locations of wireless signals and sensors observed by your device to crowdsource location estimates. This helps everyone find locations better.
Mozilla used to run a very similar service: https://en.wikipedia.org/wiki/Mozilla_Location_Service
Not to mention truly crowd-sourced databases like wigle.net.
That's the biggest problem with any device that updates.
Yea, this will work for the moment and the seller will be covered in the sense that "well, it wasn't infected when we sold it".
Who is selling half-price stamps?
#1 How big is your potential market? It's people still mailing things from home, who haven't figured out how to do postage on their computer.
#2 Of the population in #1, it's those who find real stamps so expensive that it's worth bothering with discounts.
#3 Of the population in #2, it's those who would want to buy something fraudulant (or not know better) and who would want to risk using it.
#4 Considering the size of the #3 population, how many stamps do they use in a month?
#5 What is your margin on a half-price stamp? You have to pay for advertising, printing (we're talking a profit margin under $1), packaging, and your own time, but at least shipping is free!
And the "retailer" on record is of course not a real company. They'll just pay some third-party to file a bunch of paperwork in Delaware, pay the $110 fee, and let it go bust if anyone tries to investigate it or make it liable.
So is it greed? Yes, but I did it too so now that its more accessible I cannot really blame people.
It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.
> Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?
Cheap, slow-moving drones are the hot new missiles on the battlefield of today. This often talked-about model files at 115 mph (https://en.wikipedia.org/wiki/HESA_Shahed_136).
I mean: They just pay the money, plug the thing in, push some buttons, and: TV happens. Right?
You have to be able to show damages you incurred and assign a dollar value to them to sue people.
That doesn’t work at all for a something that sells your bandwidth to a proxy service. People wouldn’t even be aware that it was happening they weren’t told.
A bad switch or router (which almost certainly includes a ton of crappy home APs and routers, compromised by the same actors who ship these devices) could let clients see VLAN tags and ignore them.
And an Ethernet “hub” does no filtering at all.
While it's great we're getting the manufactures to just stop sending out straight malware and it should be stopped the next most obvious means of attack is just having the device update and add superaids to it's new functionality.
So, no, it won't stop 99% of it at all.
And honestly this isn't that much different from what US companies are already great at by providing updates that take away features we bought with the device.
And not just updating really doesn't save you, instead of being part of a factory botnet, you're just open to become part of some other botnet.
Yes. Chinese manufacturing is quite a phenomenon, useful and everywhere
But to be completely fair, a $40 video projector has a warning label. The price
It was a rabbit hole and in the end I got back using my NVIDIA Shield. This is about 10 years now, but it’s actually still the best option.
Of course theres good products made in China, and plenty of entirely Chinese brands killing it doing their thing.
Limiting what outbound access devices can/can't have is an important skill to learn.
These companies could use the info they gather on customers for their own use but they cannot (re)sell it to anyone, not even the government. The reason being that the information eventually ends up abroad after which you lose all control over it.
I want big companies to stop spying on me, which is a completely different issue.
like cigarettes?
And any kind of multicast (used for local service discovery and media streaming) has the same limitations.
To most people IPTV is a bunch of gibberish letters, indistinguishable from the gibberish brands on Amazon. Someone's grandma from Colorado doesn't deserve to get scammed because she didn't research the acronyms.
Thanks for liking my product enough to want to buy it right away :)
Really wish I could point Mythos at my router and just loop it until my router becomes literally unhackable.
If you told normal people that they could get free content with a TV streaming stick that would also constantly fake clicks on AI generated websites to screw advertisers over, they would think of it as a bonus. Also it would make them trust the stick more (fallaciously), because they would know how the people who sold it were getting paid.
Backdoors and spying are also a problem in theory except at this point you can't even trust "legitimate" companies on that front so it's a moot point.
So they trust literally everything they read. I still don't think my folks can fathom you can spin up a very real looking newspaper website with fake articles in about 10 minutes.
That was his justification for a satellite descrambler, they're sending me the signals, obviously I'm allowed to.
- How are these "legitimately free"? For example AMC is a commercial TV channel and as far as I know, they don't offer free streaming. Same goes for MGM, FilmBox etc.
- Strictly speaking this isn't IPTV, it's just web streams. IPTV is usually delivered via multicast (MPEG-TS/RTP/RTSP streams, over UDP mostly).
If they were using the system to rip off random people, I'd be 100% against it, if they are fucking Google and the giant corps that advertise with them, ehh.. not my problem and can't be assed to care. Google is not a positive force in the world. Hasn't been for many years.
Amazon will be notified they sold something illegal and will take it down and ban the seller who will immediately launch a new store under a new name.
The purchaser, on the other hand, will be fully liable for whatever horrible thing they bought.
How that actually works in practice is that your favorite sites make less money and your IP gets a bad reputation so you CAPTCHAs or outright blocked. There’s no “sticking it to the man” here, just contributing to the frictional grind making the internet worse for ordinary people.
Also, visitors on my wifi started getting strange ads. Yes I threw off the algo, but I'm a guy with wife, I'd rather get car ads than like divorce lawyers + gay dating sites.
> Roughly twice per second, a Roku TV captures video “snapshots” in 4K resolution. These snapshots are scanned through a database of content and ads, which allows the exposure to be matched to what is airing. For example, if a streamer is watching an NFL football game and sees an ad for a hard seltzer, Roku’s ACR will know that the ad has appeared on the TV being watched at that time. In this way, the content on screen is automatically recognized, as the technology’s name indicates. The data then is paired with user profile data to link the account watching with the content they’re watching. https://advertising.roku.com/learn/resources/acr-the-future-...
[1] https://support.google.com/android/answer/3467281?sjid=66634...
It is paid for via ads or subsidies, so there's no reason to block access to the stream, so they just don't bother, and make life easier for anyone building streaming devices wanting to integrate their channel.
Someone accessing the stream directly is not the originally intended use case, but it isn't any different from someone accessing it via their smart tv.
Not legal advice.
(It would surprise me greatly if we as a society let these gadgets be sold openly from here on.)
Sure, Google's paying but they get their money regardless.
> do it because they can get away with it.
Lots of people on HN download and upload copyrighted materials. Is it really different?
This is already a common feature for analytics toolkits.
Regarding the government, the problem is that many people do not fully understand the mechanism of collecting the data. I remember the case when members of US military disclosed the location of secret objects through fitness tracker app. And they were probably smarter than average smartphone user. Obviously it would be better if enabling GPS required an approval from their commander.
The USPS becomes directly involved only later, when someone tries to defraud them by using a fake stamp.
I think that makes a big difference.
Imagine if Amazon Video, Audible, and Kindle will all just pirate stores, where uploaders of the pirated content made money on the downloads, people paid for those downloads, and Amazon took a cut of everything. How long would that go on before they were in court and that was shutdown?
I tinkered with Dish Network descrambling 20 years ago. Not because I wanted to just watch a bunch of free TV (I hardly watched any TV anyway, we mostly watched DVDs from the video store and Netflix). More because it felt like an interesting rabbit hole. And it was pretty interesting!
I picked a good (newer!) satellite dish and LNB from the trash and had a friend help with the installation and alignment because that was his previous job. Normal people use some kind of tool to find the satellites' geosynchronous orbital station in the sky, but he did it often enough that he could simply look up into the sky and point at them.
There were a handful of grey-market satellite receivers you could buy that were technically capable of descrambling a commercial signal. Of course, they did not advertise themselves as such. They were marketed as FTA (free-to-air) DVB-S receivers. These were not illegal as they were fairly popular in regions of the world that actually _had_ a fair amount of FTA (unscrambled) satellite channels. The only satellites visible from North America, however, tended to carry religious, shopping, or Mexican/Central American programming. Oh, and NASA TV.
The receiver I bought had DVR functionality if you hooked up a USB drive to it. I think I still have some recorded shows on it. It would have been a great way to harvest and release pirated TV shows to the Internet, if you didn't mind editing out all of the ads and whatever.
DVB-S was basically a raw MPEG-2 TS stream that could be optionally encrypted. To use these grey-market receivers as descramblers, you install some custom firmware containing the descrambling modifications and keys. I'm failing to remember the technical details, but the encryption they used was not very good. Dish Network would rotate the keys occasionally, and when they did, you had to update them on your receiver. I can't remember now if the keys were part of the firmware, but I remember it being a pain in the ass.
The firmware/keys part of this had a very "colorful" community. You had to sign up to a very specific and somewhat exclusive web bulletin board in order to download the firmware/keys. I don't remember how I gained an account, but I remember it being non-trivial. IIRC, it was like one guy maintaining the firmware/keys and sometimes it took weeks for him to adapt to whatever thing DN did to thwart piracy. The board was moderated by a complete power-tripping asshat who enjoyed banning people for fun and then gloating about it. (I was not banned, that I recall.) I think they started requiring "donations" in order to view certain threads (like firmware releases) after a while. But I could be misremembering that. I just remember the community was very toxic.
After a few months of this setup, DN figured out how to rotate their keys too often for the casual pirate to keep up. I disconnected mine around that time and moved onto other things. Partly because the experiment ran its course and partly because migrating to real-time key updates would have meant buying a newer receiver. For a while, I flirted with the idea of getting a DVB-T PCI receiver card and working on breaking the encryption myself, but it was quite a bit above my skill level at the time and there did not seem to be anyone else working on it out in the open, since the DMCA was still pretty new then.
It was both a gateway into learning how the web works but also that literally anyone can post anything to the internet and it doesn't make it true. I like to think he's more savvy than many of his peers but we all have our blind spots.
I'll agree that militaries would prefer their soldiers to not to dumb things - but I don't agree that it's 'obviously' best if people needed permission to enable GPS! If that's the case depends a lot on which soldier is enabling the GPS and their relation to me. In general I would say that government control of people recording and distributing their observations is associated with the most authoritarian governments and by claiming we should get government permission you appear to be aligning yourself with an authoritarian approach to data controls.