Top
Best
New

Posted by speckx 4 hours ago

Read this before you buy that TV streaming stick(krebsonsecurity.com)
307 points | 148 commentspage 2
yumraj 2 hours ago|
Any way to identify or block these proxy and ad click services in the router? Say a Ubiquiti or even pfsense?

I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices.

Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic?

My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.

hn_submit 1 hour ago||
I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.

Instead they're banning stuff willy nilly left and right without really solving the problem.

But there's good stuff coming out of China as well. I recently bought a cheap e-reader which has no WiFi or internet connection and it works stellar. And I bought some cheap Chinese sport cams which also lack internet and work great.

autoexec 46 minutes ago|
> I already suggested the U.S. government ban all Chinese products which have a computer in them that's connected to the internet.

Personally, I think every other country should ban any product made by Google, Amazon, and Microsoft since they all spy on the users of their products too.

hn_submit 23 minutes ago||
I've suggested legislation which would ban the sale of customer information to third-parties.

These companies could use the info they gather on customers for their own use but they cannot (re)sell it to anyone, not even the government. The reason being that the information eventually ends up abroad after which you lose all control over it.

utopiah 2 hours ago||
I bet this is much broader than we all realized because just earlier today I was reading on https://gist.github.com/probonopd/3ad6b7777caea1503f00d5fe77... in order to tinker with a cheap (like really cheap) Android video projector : "Device: Magcubic HY300 Pro Android Projector (ui_Veng.projector) Issue: Device was being used as a residential proxy node without consent, causing thousands of suspicious DNS requests and bandwidth usage." linked in there just few months ago.

It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique.

An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.

RajT88 2 hours ago||
A pirate TV box from China presents a security threat?

This is my surprised face.

mring33621 1 hour ago||
Using low code tools to build click fraud logic FTW!
m3047 3 hours ago||
Brazil. Last year I effectively blocked Brazil for a while. Ultimately I settled on three possibilities for the traffic I was seeing:

01: DDOS

10: Residential proxies

11: Somebody DDOSing residential proxies

drdexebtjl 3 hours ago|
I can’t prove it, but I live in Brazil and after getting a smart TV from LG, I started receiving challenges across all Google services, indicating they received bot traffic from my network. I only used apps from streaming services I actually paid for.

I suspect these TVs either come with residential proxies set up from the factory, or they have such poor security that they’re instantly hacked. Either way, TV manufacturers (including reputable ones like LG) are to blame.

mikestew 1 hour ago||
There have been articles lately about the residential proxies loaded in apps for LG TVs. My LG has never seen a network connection, so I’m fuzzy on details.
a-dub 2 hours ago||
it's just like a phone. don't buy a crappy one with firmware of unknown provenance. make sure the one you do buy has an active and effective effort that you trust that ships timely security fixes.
stuaxo 1 hour ago||
How hard is it to get something else on these ?

Looks like cheap small computer with a remote control.

stronglikedan 2 hours ago||
> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

You had me at "But"! ::swoon::

Hasz 2 hours ago|
Hey that’s pretty smart! Fradulent, but very smart. I was honestly expecting botnet.

I expect many cameras of “dubious” origin are used for similar tasks, same with most “smart” devices with sufficient horsepower.

More comments...