Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

52% Positive

Analyzed from 2837 words in the discussion.

Trending Topics

#apple#streaming#device#devices#clicks#https#fake#wifi#gps#able

Discussion (79 Comments)Read Original on HackerNews

Hasz3 minutes ago
Hey that’s pretty smart! Fradulent, but very smart. I was honestly expecting botnet.

I expect many cameras of “dubious” origin are used for similar tasks, same with most “smart” devices with sufficient horsepower.

codedokodeabout 2 hours ago
I do not see problems with fake ad clicks and have no sympathy for ad companies.

Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.

What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.

How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:

- the user must be able to re-flash firmware with their own code.

- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.

- any telemetry or data collection, or updates must be opt-in only and disabled by default.

- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.

Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.

Cider998643 minutes ago
>What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information.

Most Americans are at a greater threat of harm from their own government that a foreign one. What worries me is all the mass surveillance done by big tech which bypasses the 4th Amendment and gives the government Americans data without a warrant.

There's already a front door with the adtech for US alphabet boys. This could likely be collected by others as well. We saw this happened where foreign hackers exploited a backdoor designed for American authorities[1]. This is what experts are referring to when they say there's no backdoor only for me.

This could be compelling to politicians, though, and would certainly be a step in the right direction.

>- any telemetry or data collection, or updates must be opt-in only and disabled by default

This should be how it is for everything foreign made software or not. Would be very hard to get done with the big tech lobby in the US.

[1] https://techcrunch.com/2024/10/07/the-30-year-old-internet-b...

Thrymrabout 1 hour ago
> I do not see problems with fake ad clicks and have no sympathy for ad companies.

I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.

jrm415 minutes ago
Sure. And you'll quite literally never be able to get any meaningful reduction in this practice unless you attack it at the level of big, publically known companies; the warnings about these local dinky things I suppose are not harmful and help individuals a bit -- but I'm concerned they give the entirely false impression that the extremely similar stuff coming from the big boys is definitely a-ok.
pavel_lishinabout 1 hour ago
> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?

> for every imported device having a CPU and Internet connectivity

Why limit this to imported devices?

palmoteaabout 1 hour ago
>> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

> Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?

Cheap, slow-moving drones are the hot new missiles on the battlefield of today. This often talked-about model files at 115 mph (https://en.wikipedia.org/wiki/HESA_Shahed_136).

codedokode29 minutes ago
In some areas GPS is spoofed and the displayed location is wrong. If, for example, a "smart" car gets a task from its manufacturer to film some secret object, it would fail if it relied only on GPS and did not use cell towers and WiFi points for determining its location. So knowing their location determines whether the mission would fail or succeed. So foreign devices should not be allowed to collect such information.
bee_rider39 minutes ago
I think that might have been semi-sarcastic. I mean, there are lots of reasons to do this sort of thing, some are bad, some are not so bad, most are not war.
arjie36 minutes ago
Oh this was a failed device that Mozilla offered. I had a couple back in the day. It was called Matchstick. Sick t shirts. Basically an OSS chromecast.
BoppreHabout 1 hour ago
> a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys.

Could it be used for missiles? Sure. Is it obviously the intention? No.

meatmanekabout 1 hour ago
Yeah this is extremely standard:

Apple: https://support.apple.com/en-us/102515

> If Location Services is on, your device will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers to Apple to augment Apple's crowd-sourced database of Wi-Fi hotspot and cell tower locations.

Google: https://support.google.com/android/answer/15157297?sjid=1648...

> When Location Accuracy is on, Google periodically collects information about the locations of wireless signals and sensors observed by your device to crowdsource location estimates. This helps everyone find locations better.

Mozilla used to run a very similar service: https://en.wikipedia.org/wiki/Mozilla_Location_Service

Not to mention truly crowd-sourced databases like wigle.net.

codedokodeabout 1 hour ago
They should ask the permission from device owner and local government before collecting the data.
codedokodeabout 1 hour ago
Should Google ask permission from the device owner, and from the local government before collecting the data? I heard a certain foreign mobile app was banned in US for doing less than that.
mcphageabout 1 hour ago
> I do not see problems with fake ad clicks and have no sympathy for ad companies.

Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.

exe34about 1 hour ago
My pinenote runs the original spyware image - I don't have a problem with Winnie the Pooh reading along with me.
IncreasePostsabout 1 hour ago
Fake ad clicks cost the advertiser money, not the ad company.

Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)

mcphageabout 1 hour ago
> Fake ad clicks cost the advertiser money, not the ad company.

It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.

codedokodeabout 1 hour ago
Good products do not need much advertising. For example, when buying DRAM, I compare the specification and prices and do not look at the advertisement.
mortenjorckabout 2 hours ago
In this case it’s actual malice, that the streaming stick is set up for residential proxy and ad fraud straight from the factory. But incompetence can lead to the same place if it’s a poorly engineered, un-maintained device with an old version of Android that will never be patched and is always one no-click exploit away from being commandeered into residential proxy and ad fraud.
FinnKuhnabout 2 hours ago
Those TV streaming boxes really are (from a cybersecurity perspective) probably one of the worst things you can buy. Here is the "Darknet Diaries" Episode on them: https://darknetdiaries.com/episode/172/
alex_dufabout 2 hours ago
I wonder to what degree malice can be engineered to look like incompetence?
abbeyjabout 2 hours ago
Try examining the old entries from the https://en.wikipedia.org/wiki/Underhanded_C_Contest.
yumraj28 minutes ago
Any way to identify or block these proxy and ad click services in the router? Say a Ubiquiti or even pfsense?

I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.

Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?

My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.

pavel_lishinabout 2 hours ago
> generic TV boxes that promise unlimited content streaming for a one-time fee

I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.

havalocabout 2 hours ago
I have an elderly client who sends me links of stuff to buy all the time. One day it's one of these streaming sticks, the next day it's half-price stamps, and I tell her every time, please don't buy this stuff. And yet she does anyway, as if I was almost being mean and saying no just to say no.

So yes, I do want to blame the purchasers of these things, sometimes. To prove her point that her stamps were legitimate, she mailed me a card using one of her half priced (but likely fake) stamps and it made it through!

Terr_about 1 hour ago
Perhaps they grew up in a time/environment where "if it was that bad they wouldn't be allowed to advertise it", and they're still using that old calibration?
nvme0n1p1about 2 hours ago
OTOH - TV, radio, and YouTube are all unlimited and free. Why not streaming?

There are lots of people alive who grew up during the days of broadcast TV and radio. I get why they might not understand the difference.

Cider9986about 1 hour ago
It could be possible, I haven't done the math though.

Stremio +Torbox is $3/month and they can probably share 10+ households on one TorBox account so it could work out. The seller could just stop paying the TorBox subscription at whatever point and they have an incentive to do so.

iugtmkbdfil834about 2 hours ago
Uhh, I have an extended family member, who not only uses it, but now also tries to get other people to get into it. Since I was familiar with this practice ( and the issues it makes worse ), I noted those to him in an attempt to both politely decline and, hopefully, spare him, and society, some future problems. Without going into any identifying details, he didn't take it well ( and I don't think I got on my high horse ).

Anyway, I think some level of blame is warranted.

IncreasePostsabout 1 hour ago
Maybe, but if they're a not-very-tech savvy older person buying this, they probably remember shows being free from over the air antennas and may think it is something like that.
ghostly_sabout 1 hour ago
> they probably remember shows being free from over the air antennas

you are aware broadcast TV never ended?

IncreasePosts42 minutes ago
Yes, in fact I have an antenna and a HDHomeRun nestled in my attic to record over the air shows that I occasionally consume.

But, I think it's far more common for people to have a TV service today, perhaps since comcast and their ilk push hard the TV/phone/internet bundle, and gone are the years when everyone would fiddle with the antennas on the back of their TV to get the right reception.

bdangubic43 minutes ago
I watch TV over an antenna, shows are free still
fred_is_fredabout 2 hours ago
If you offered most people free streaming for a $37 USB stick but directly told them it would be faking ad clicks when the TV is off, would any of them really care?
1970-01-01about 2 hours ago
No, and that's is the root of the problem. The buyer is happy and so is the seller. They don't care to understand what they're allowing and everyone is allowing it to happen.
GolfPopperabout 1 hour ago
They're just meeting the standards American society has set.
croesabout 2 hours ago
It sounds like scam
flerchinabout 2 hours ago
Well now I want one
Cider9986about 1 hour ago
Stremio+TorBox are the two words. ($3/month)
ghostly_sabout 1 hour ago
That's not what these things are. They come preloaded with apps that stream pirate broadcast streams and on-demand servers operated out of China.
utopiah24 minutes ago
I bet this is much broader than we all realized because just earlier today I was reading on https://gist.github.com/probonopd/3ad6b7777caea1503f00d5fe77... in order to tinker with a cheap (like really cheap) Android video projector : "Device: Magcubic HY300 Pro Android Projector (ui_Veng.projector) Issue: Device was being used as a residential proxy node without consent, causing thousands of suspicious DNS requests and bandwidth usage." linked in there just few months ago.

It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique.

An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.

skinfaxiabout 2 hours ago
Thankfully this seems limited to a specific device (H96). Darknet diaries has a good story about streaming devices https://www.youtube.com/watch?v=dS6PkuZuxJ4
krebsonsecurityabout 2 hours ago
It's not just one device line; Have a look at the list maintained by the proxy tracking service Synthient, which tracks streaming boxes, digital picture frames and other IoT devices that have been known to bundle residential proxy software, among other malicious apps. They currently track almost 1,000 different makes and model numbers.

https://github.com/synthient/public-research/blob/main/2026/...

glitchcabout 2 hours ago
Defrauding ad networks doesn't seem like a bad thing, although using my internet connection as a proxy is obviously terrible. It wouldn't surprise me to learn that my connection is being sold as a VPN service by the vendor.
alistairSHabout 1 hour ago
It'll be a marginal effect, but fake clicks impacts the ad buyer, which then impacts their financials and pricing.

The only winner here is the scammers running the fake affiliate sites on which these sticks are "clicking". Or, am I missing some facet of this enterprise?

ssl-329 minutes ago
Another winner is the person who gets to watch cheap digital TV, without putting together a usable antenna and limiting their reception to the broadcast channels that are nearby.

I mean: They just pay the money, plug the thing in, push some buttons, and: TV happens. Right?

em-beeabout 1 hour ago
why is running a proxy a bad thing? someone profiting off it could be bad maybe, but even that is good if it pays for my subscription.

but compare running tor nodes, and especially exit nodes. that surely would be a good thing, so at least if you think tor is good then running a proxy should be the same and it should be normalized.

doing it in secret without the user knowing is what's bad

glitchc16 minutes ago
Indeed without my permission is implied. Without it, you have no idea what traffic is being routed and could be on the hook for something nasty like CSAM.
stronglikedan24 minutes ago
> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

You had me at "But"! ::swoon::

m3047about 2 hours ago
Brazil. Last year I effectively blocked Brazil for a while. Ultimately I settled on three possibilities for the traffic I was seeing:

01: DDOS

10: Residential proxies

11: Somebody DDOSing residential proxies

drdexebtjlabout 1 hour ago
I can’t prove it, but I live in Brazil and after getting a smart TV from LG, I started receiving challenges across all Google services, indicating they received bot traffic from my network. I only used apps from streaming services I actually paid for.

I suspect these TVs either come with residential proxies set up from the factory, or they have such poor security that they’re instantly hacked. Either way, TV manufacturers (including reputable ones like LG) are to blame.

kazinator12 minutes ago
> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads ...

Compromised (or malicious from the factory) devices being recruited into bot farms for click fraud is ... a groundbreaking discovery in 2026?

> on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

To hell with AI-generated websites and advertising networks.

Say, where can I get the most effective malicious TV stick for click-frauding the fuck out of that shit? I will get fifteen of them!

Advertisement
RajT8820 minutes ago
A pirate TV box from China presents a security threat?

This is my surprised face.

cute_boi8 minutes ago
The best solution to this problem is to block GeoIP traffic and monitor bandwidth consumption on a per-domain basis. If something is sending data during the night, it becomes much easier to identify suspicious activity.
gxs15 minutes ago
No mention of Roku

I use one but only when traveling at hotels - it’s one of the only sticks that can connect to captive WiFi networks at hotels

I’ve got barely anything on it so privacy be damned - but at this point this is why I just buy apple products

I have two apple tv’s which probably do shady things too, but I’m willing to play the probabilities and assume it’s the least bad of my options short of tinkering with flashing hardware and all that stuff that used to be fun in my teens (emphasis on used to)

giantg2about 2 hours ago
So where can I get an actual privacy focused streaming box, even if the apps (Neflix etc) running on it are not?
noboostforyou8 minutes ago
Besides setting up your own device, Apple TV would be the best bet from any of the large manufacturers.
ghostly_s40 minutes ago
These are not "streaming boxes" in the sense you are talking about. Their appeal is that they come preloaded with chinese pirate streaming apps. Traditional streaming boxes - Apple TV, Fire stick, Roku - are not affected by this, though if you want privacy-focused Apple TV is the only remaining contender, and with Apple's continued descent into advertising vendor I'd guess that one is not long for this world, either.
giantg224 minutes ago
My understanding is that Roku bypasses DNS blocking with hardcoded tables so it can report back on various data they track on you.
timbit4210 minutes ago
Can you monitor its traffic and block by IP?
MattTheRealOneabout 2 hours ago
Apple TV is currently the best balance of privacy and convenience. The only way to get more private is using a PC, but that limits the resolution for most streaming services to 720p or 1080p.
cogman10about 2 hours ago
I'm increasingly being convinced the only way to do that is you do a media pc nuc. The problem, of course, is you probably won't have the netflix app. It's painful to setup such a box to stream from various services.
Tepix14 minutes ago
What's wrong with Apple TV? It runs VLC if you want to stream something from your NAS.
mbmbnabout 2 hours ago
I tried going that route, but most apps for streaming are Android. And that was only one of the issues.

It was a rabbit hole and in the end I got back using my NVIDIA Shield. This is about 10 years now, but it’s actually still the best option.

PcChipabout 2 hours ago
I assume apple TV doesn’t do malicious things like this, and we love the interface and it “just works” with HDR
cryo32about 2 hours ago
A better solution is just leech the content and stick it on a generic USB flash stick.
defmetrixabout 1 hour ago
I didnt know anybody bought a streaming stick anymore
Mistletoeabout 1 hour ago
I recently got an Apple TV 4K and have been really enjoying the ad free experience. Worth every penny. Our smart tv had turned into a Christmas tree of ads.
ocdabout 1 hour ago
As much as I hate Apple for what they've done to the average consumer in regards to computing, it would be just impossible and dishonest to say anything other than Apple is the outright winner in streaming devices. The experience is so smooth.
ghostly_s38 minutes ago
Considering their recent decision to give up on building Apple Maps into a serious contender and instead enshittify it with ads, I don't have much faith Apple TV will be far behind.
dhosek14 minutes ago
One hopes that the new CEO will realize the turn towards ads is ruining the Apple brand and pull back on that front.
j45about 2 hours ago
Generally, it's advisable to create a dedicated wifi network for all potentially hostile devices.

This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.

That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.

giraffe_ladyabout 2 hours ago
> allowing low-skilled operators to drag blocks of code together in their editor — without any need to understand what the underlying code blocks do or how they work.

We're called engineers brian.

AlotOfReadingabout 1 hour ago
Of all the evils normally associated with visual programming languages, enabling cybercrime isn't one I've previously considered. Now that I've seen it, I'm surprised it wasn't more common before LLMs appeared.
Advertisement
yunnpp28 minutes ago
And which part of "ad fraud" is the fraud? As far as I can tell, ad networks and advertisers are the fraud and they are also part of the increasing surveillance state.

Didn't know Krebs was a mainstream news puppet.

brainwad21 minutes ago
It's called fraud because the ad host colludes with (or directly controls) the botnet to get lots of clicks on ads hosted on their sites, making them money at the expense of advertisers.

If you just want to spam clicks on ads you don't financially be edit from, go for it.