Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.

    Instead they're banning stuff willy nilly left and right without really solving the problem.

    But there's good stuff coming out of China as well. I recently bought a cheap e-reader which has no WiFi or internet connection and it works stellar. And I bought some cheap Chinese sport cams which also lack internet and work great.

  • > I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.

    Personally, I think every other country should ban any product made by Google, Amazon, and Microsoft since they all spy on the users of their products too.

  • Any way to identify or block these proxy and ad click services in the router? Say a Ubiquiti or even pfsense?

    I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.

    Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?

    My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.

  • > Despite repeated warnings from the FBI and security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands

    I scanned the comments and I didn't see anyone suggesting that these companies should share any responsibility for selling these harmful products. Why is it that they seem to get a pass? Would we feel the same about giant retailers selling tainted food, or unsafe children's toys?

  • Probably because most people don’t equate the damages from causing bodily harm to whatever these ad clicking networks do.

    Voters don’t like seeing themselves or their kids get hurt, but they do like lower cost live sports.

  • Probably because doing so would mean a lot fewer product categories. It's a trade-off, to be sure. But if you need that odd thing — a screw of a certain type, a power supply that's 56 volt DC or whatever — then if there's only going to be sold, say, a few thousand of those a year, if Amazon was required to do product safety testing on them, they probably wouldn't be able to sell that category at all. And so the trade-off is they are not required to.

    Now that's very different from "we are selling things that we know, or have good reason to know, specifically are dangerous" — here they might very well be liable.

  • I would very much be in favor of grocery stores sharing responsibility (and regulatory penalties) for selling tainted food! It's kind of mind boggling that this is controversial. "Buyer beware" is not an acceptable basis for society to function.
  • Probably because we have little to no way to punish those companies. We can't even stop DJI from shipping their drones under other brands to get around the ban.
  • This is why I hate the "marketplace" of these stores. In many cases these products never hit their inventory at all, they are functioning like a search engine and payments processor.
  • In the US at least there is a lot (and by that I mean like maybe more than half) of civil case law around seller liability for defective or 'dual use' products. In the 70's some cities tried to sue hardware stores for selling spray paint that taggers were using, in several jurisdictions you can find authorities trying to sue vendors of lock picking and/or safe opening tools, etc. My non-lawyer reading of all that is that if it is reasonable to assume that the vendor didn't know, at the time of sale, what the customer was going to do with it, they aren't liable.

    Once a vendor has been notified that these units are doing these sorts of things they will stop selling them. Its sadly very prescriptive in that if Newegg gets a notice that "WatchFunTV" streaming sticks are doing this, they will remove that brand but if the same hardware shows up from the same vendor as "SuperTVStreamer" or some such, that product won't be banned until someone does the test and then notifies the sellers. It's cat and mouse all the time.

    Now the people who could do something about it, the ad networks like Google, do not do anything because ad revenue is ad revenue, people buying the ads cannot prove that the click was false so hey who can say it was? Which is why ad fraud is a perennial favorite of crooks. The people being ripped off don't have any way to prove it without a lot of support from the ad network traffic data which is "proprietary". Really stupid ad fraud gets shut down, but put a bit of care into it so that the Ad network and claim ignorance? You can do that all day. Just don't get greedy and try to pull in more than say 30 or 50 thousand dollars a month. Remember, the IAB said in 2025 alone Ad Revenue was $300B[1] so 2% of that is only $6B and any network with 2% or less of undetected fraud is considered a "high quality" ad network.

    So yeah, ad fraud is the gift that keeps on giving.

    [1] https://www.iab.com/insights/internet-advertising-revenue-re...

  • Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold. They certainly don't advertise to the big box retailer that buys them "and it uses the customer's internet connection for fraud."

    Hell, there's a section of comments that would probably going "hey, RELAX guy" because it's not US companies doing this. For any American companies that do this though, sure - block/suspend/prosecute.

  • One of the main value propositions for retailers in a world of endless cheap garbage being sold online, is to vet products so customers can trust that what their buying is from a legitimate company and not junk or stuff like these streaming sticks.

    This is the problem with being an “everything store”. “Everything” includes a lot of things most consumers would like to be protected from, and assume they are due to the long history of retailers standing behind the products they sell. That history seems to have come to an end. They only stand behind it enough to offer a refund if there is a problem, not to ensure it’s good before selling it.

  • My "streaming device" of choice, ThinkCentre Tiny with Linux, always feels validated with news like these. It fits behind a TV, you can get it second hand for around $40 and depending on model it can even act as a retro game console as well.
  • Is there a good TV UI OS that runs desktop youtube under the hood for ad blocking?
  • Thankfully this seems limited to a specific device (H96). Darknet diaries has a good story about streaming devices https://www.youtube.com/watch?v=dS6PkuZuxJ4
  • It's not just one device line; Have a look at the list maintained by the proxy tracking service Synthient, which tracks streaming boxes, digital picture frames and other IoT devices that have been known to bundle residential proxy software, among other malicious apps. They currently track almost 1,000 different makes and model numbers.

    https://github.com/synthient/public-research/blob/main/2026/...

  • That reminds me, I need to configure VLANs in my router so that all my trusted computers are isolated from all the other garbage that makes it into the network.
  • Mmmh, I've always wondered ... as much as VLAN's are a very useful tools to - for example - route two separate LAN's traffic through a shared physical link ... are they any good when it come to security?

    I mean, I don't believe VLAN's were designed with security as a goal, and I wonder how "strong" the virtual wall between two VLAN's actually is?

    Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physical connection where packets from both VLANs happen to travel?

    Just wondering.

  • Seems like a motivation to switch to using a VPN for such untrusted devices that still require internet access.
  • Doesn’t help when the garbage starts proxying illegal traffic through your home ISP.
  • After getting tired of ads on my PAID smart TV, 6 months ago I started building a casting device using raspberry pi for myself. A couple of months later one of my friends who is an AV technician ended up using it at the largest convention venue in Barcelona to play content on loop, here's a video of that: https://www.youtube.com/shorts/FF3I9EOs4AA.

    Fast forward to last month, now I have started selling these in Barcelona, Spain where I am based out of and branched it into three use cases: digital signage, casting, and a portable computer for presentations at events. Here is the link with features: https://soljacast.com

  • your product looks cool, but why do I need to contact sales to buy that device? can't you just open like a shopify shop and redirect end customers to that? Also showing the retail price on the page would be a plus one
  • Clicked on the link, ready to buy one. “Contact sales”. Ew. No thanks.
  • A familly member had one of those (he had to pay a yearly subscription in addition to the stick). Network would be unusable as soon as it was on for anyone else, and it also tried to scan things on the local network. It was indeed connecting to all kind of services all over the world (and saturating some tables in the router doing so which blocked other clients). Definitely evil, definitely on purpose.
  • If it wasn't scanning your own network or using all of your bandwidth, would you still consider it evil?
  • Reading this, I caught myself wondering how we distill what's in this excellent write up into something the average consumer understands, including the dangers from buying and using devices like this.

    Is it a graphic that's shared? Something else? I am sure we all know or have heard of people with these devices that promise free streaming.

  • Defrauding ad networks doesn't seem like a bad thing, although using my internet connection as a proxy is obviously terrible. It wouldn't surprise me to learn that my connection is being sold as a VPN service by the vendor.
  • why is running a proxy a bad thing? someone profiting off it could be bad maybe, but even that is good if it pays for my subscription.

    but compare running tor nodes, and especially exit nodes. that surely would be a good thing, so at least if you think tor is good then running a proxy should be the same and it should be normalized.

    doing it in secret without the user knowing is what's bad

  • They took the idea of the 'Ad-nauseam' add-on for Firefox and used it for their own gains I see.
  • Exactly. I consider defrauding ad networks even a civic duty of legitimate resistance. The issue I see with those boxes is the risk of being involved in actual crimes due to the residencial proxy.