back
552 comments
We purchased a Chinese-made projector from Amazon, which was surprisingly inexpensive (~40 USD). Upon connecting it to the internet, it placed a constantly running feed of ads on the corner of the screen, even while movies were playing. There was no way to disable it either. Even though it's not a stick, it's a similar principle.
I remember reading an analysis on one of those projectors; the author found a residential proxy running on their device. I would recommend keeping these things off the internet.
If the hardware is good and cheap, it should be a fun project to replace the OS with a custom Android build that is clean of adware.

Do you have a link to the projector?

You forgot to drink a verification can
I mean, did you have to connect it to the internet though? Did it not just have a dp/hdmi port?
I'm still trying to figure out why you didn't see that coming.
Upon connecting it to the internet…

I hesitate to blame the victim here, but why on earth would you do that? “$40 Chinese-made” didn’t give you pause?

...firewall it then?
> Upon connecting it to the internet,

I dare not ask why you would do such a thing, instead, I will simply ask if you now think the reason was good, and I will hint at you that if the reason was "convenience", then you should answer "No".

In this case it’s actual malice, that the streaming stick is set up for residential proxy and ad fraud straight from the factory. But incompetence can lead to the same place if it’s a poorly engineered, un-maintained device with an old version of Android that will never be patched and is always one no-click exploit away from being commandeered into residential proxy and ad fraud.
> generic TV boxes that promise unlimited content streaming for a one-time fee

I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.

Defrauding ad networks doesn't seem like a bad thing, although using my internet connection as a proxy is obviously terrible. It wouldn't surprise me to learn that my connection is being sold as a VPN service by the vendor.
A familly member had one of those (he had to pay a yearly subscription in addition to the stick). Network would be unusable as soon as it was on for anyone else, and it also tried to scan things on the local network. It was indeed connecting to all kind of services all over the world (and saturating some tables in the router doing so which blocked other clients). Definitely evil, definitely on purpose.
After getting tired of ads on my PAID smart TV, 6 months ago I started building a casting device using raspberry pi for myself. A couple of months later one of my friends who is an AV technician ended up using it at the largest convention venue in Barcelona to play content on loop, here's a video of that: https://www.youtube.com/shorts/FF3I9EOs4AA.

Fast forward to last month, now I have started selling these in Barcelona, Spain where I am based out of and branched it into three use cases: digital signage, casting, and a portable computer for presentations at events. Here is the link with features: https://soljacast.com

That reminds me, I need to configure VLANs in my router so that all my trusted computers are isolated from all the other garbage that makes it into the network.
Thankfully this seems limited to a specific device (H96). Darknet diaries has a good story about streaming devices https://www.youtube.com/watch?v=dS6PkuZuxJ4
My "streaming device" of choice, ThinkCentre Tiny with Linux, always feels validated with news like these. It fits behind a TV, you can get it second hand for around $40 and depending on model it can even act as a retro game console as well.
> Despite repeated warnings from the FBI and security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands

I scanned the comments and I didn't see anyone suggesting that these companies should share any responsibility for selling these harmful products. Why is it that they seem to get a pass? Would we feel the same about giant retailers selling tainted food, or unsafe children's toys?

Any way to identify or block these proxy and ad click services in the router? Say a Ubiquiti or even pfsense?

I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.

Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?

My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.

I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.

Instead they're banning stuff willy nilly left and right without really solving the problem.

But there's good stuff coming out of China as well. I recently bought a cheap e-reader which has no WiFi or internet connection and it works stellar. And I bought some cheap Chinese sport cams which also lack internet and work great.

This is why Google/Meta is pushing for "age verification".

1. They want more as targeting data on you

2. They want to reduce bot clicks

It's an unholy alliance with governments who want to know who writes what online.

Krebs' blog is nice, but quite often it's just re-reporting stuff from somewhere else:

Original with more details: https://www.bitsight.com/blog/fuyao-enterprise-building-ad-f...

Brazil. Last year I effectively blocked Brazil for a while. Ultimately I settled on three possibilities for the traffic I was seeing:

01: DDOS

10: Residential proxies

11: Somebody DDOSing residential proxies

“as part of a sprawling operation that seeks to defraud online merchants and advertising networks.”

Oh no! Not the advertising networks!

No mention of Roku

I use one but only when traveling at hotels - it’s one of the only sticks that can connect to captive WiFi networks at hotels

I’ve got barely anything on it so privacy be damned - but at this point this is why I just buy apple products

I have two apple tv’s which probably do shady things too, but I’m willing to play the probabilities and assume it’s the least bad of my options short of tinkering with flashing hardware and all that stuff that used to be fun in my teens (emphasis on used to)

I really don't mind anymore. My Roku stick is now owned by extreme right Fox Corporation. Chinese ad click network are petty villain compared.
If you have a Raspberry Pi 5 gathering dust somewhere and need a new streaming box then try LibreELEC. It decodes 4k content just fine. It has HDMI CEC. It can stream from local server or play directly from attached storage. There are no ads or tracking/profiling. It can play YouTube without ads but there is no support for Netflix, Apple TV or similar streaming services.
I bet this is much broader than we all realized because just earlier today I was reading on https://gist.github.com/probonopd/3ad6b7777caea1503f00d5fe77... in order to tinker with a cheap (like really cheap) Android video projector : "Device: Magcubic HY300 Pro Android Projector (ui_Veng.projector) Issue: Device was being used as a residential proxy node without consent, causing thousands of suspicious DNS requests and bandwidth usage." linked in there just few months ago.

It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique.

An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.

Got myself a mi box with a custom launcher. Way better than any other Smart TV out there. Unless there's a smart tv that does not show ads right on the fing front page.

Anyway, the box is powerful enough to do several things. You can install a IP tv if you want. If you don't, you still have a pretty good media center (you can hook up an external hd on it)

roku is sniffing your farts. and reading your texts/emails.

https://docs.roku.com/published/userprivacypolicy

see: "olfactory", "content of"

or at least they're CYA while they're sniffing.

they definitely scan the entire local network.

A pirate TV box from China presents a security threat?

This is my surprised face.

> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

You had me at "But"! ::swoon::

At this point China probably has a botnet that can be turned on with a few deploys, and spans a majority of homes in US and RU (and thus is unblockable without disconnecting half of voters from the internet). Ready to attack the infrastructure.
> allowing low-skilled operators to drag blocks of code together in their editor — without any need to understand what the underlying code blocks do or how they work.

We're called engineers brian.

The most relevant difference between using a TV and a "TV streaming stick" is corpos & the State controling the malware/surveillance device.

Being a ordinary person, I do not want criminals or the ( ads/data ) industry or the state to be in control of my property.

Also, any DRM not passed by a parliament undermines the rule of law & statehood. This is something Krebs and his Praetorian guard buddies must know.

Generally, it's advisable to create a dedicated wifi network for all potentially hostile devices.

This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.

That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.

So where can I get an actual privacy focused streaming box, even if the apps (Neflix etc) running on it are not?
This is only slightly more malicious than the software "Smart TVs" already ship with.
Alternatively, if you are going to do some questionable things, just buy loads of these things and create a hundred back doors on the network to increase the noise.

Sounds good in theory but in practice, computers are good at sorting this stuff out. Kind of why they are so popular.

Ah, got it. Those devices are like computer virus which don't need a computer to live on.They can make DDOS attacks if they want to. So, buying these devices at a cheap price is like renting out your IP address and your Internet connection.
LG televisions and monitors spy on their users and install unwanted software. Half of all smart tvs are running "residential proxy" malware. Google is banning sideloading but happily hosting apps using the Bright SDK.

Sorry, but "your tv stick does ad fraud" is just about the most innocent thing I've seen in a while. Everyone in this market is doing the shadiest shit you can imagine. There are no good brands left, you just get to pick what logo your Malware Entertainment Device has.

> these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks.

Every cloud has a silver lining.

The best solution to this problem is to block GeoIP traffic and monitor bandwidth consumption on a per-domain basis. If something is sending data during the night, it becomes much easier to identify suspicious activity.
it's just like a phone. don't buy a crappy one with firmware of unknown provenance. make sure the one you do buy has an active and effective effort that you trust that ships timely security fixes.
Long ago I ponder giving away free computers but an ethical formula is really hard. It seemed profit starts to scale exponentialy just beyond the line.

(Acepable would be something like 1TB worth of gamedemos)

Hey that’s pretty smart! Fradulent, but very smart. I was honestly expecting botnet.

I expect many cameras of “dubious” origin are used for similar tasks, same with most “smart” devices with sufficient horsepower.

Ah, it's about "China, China.."

Preparing casus belli.. first, open weights LLM which are "not secure", now "TV sticks"..

Oh joes and janes, who will put finally some sense into you..

Birds Nest soup with Chinese tomatoes?

Or Cinese noodles with Chinese tomatoes?

It sounds likw 2 domestic markets that China should use to rid themseves of their over-abundance of tomatoes.