Read this before you buy that TV streaming stick
speckx
658 points
376 comments
July 30, 2026
Related Discussions
Found 5 related stories in 769.2ms across 15,510 title embeddings via pgvector HNSW
- The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy nikcub · 203 pts · June 06, 2026 · 53% similar
- LG to ban residential proxies from smart TV apps DemiGuru · 165 pts · July 22, 2026 · 51% similar
- 50% of LG and Samsung smart TV apps embed residential proxies Cider9986 · 25 pts · June 24, 2026 · 50% similar
- Codex Hacked a Samsung TV campuscodi · 234 pts · April 16, 2026 · 50% similar
- Amazon won't release Fire Sticks that support sideloading anymore pjmlp · 73 pts · April 18, 2026 · 49% similar
Discussion Highlights (20 comments)
mortenjorck
In this case it’s actual malice, that the streaming stick is set up for residential proxy and ad fraud straight from the factory. But incompetence can lead to the same place if it’s a poorly engineered, un-maintained device with an old version of Android that will never be patched and is always one no-click exploit away from being commandeered into residential proxy and ad fraud.
glitchc
Defrauding ad networks doesn't seem like a bad thing, although using my internet connection as a proxy is obviously terrible. It wouldn't surprise me to learn that my connection is being sold as a VPN service by the vendor.
skinfaxi
Thankfully this seems limited to a specific device (H96). Darknet diaries has a good story about streaming devices https://www.youtube.com/watch?v=dS6PkuZuxJ4
pavel_lishin
> generic TV boxes that promise unlimited content streaming for a one-time fee I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.
giraffe_lady
> allowing low-skilled operators to drag blocks of code together in their editor — without any need to understand what the underlying code blocks do or how they work. We're called engineers brian.
cryo32
A better solution is just leech the content and stick it on a generic USB flash stick.
j45
Generally, it's advisable to create a dedicated wifi network for all potentially hostile devices. This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed. That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.
giantg2
So where can I get an actual privacy focused streaming box, even if the apps (Neflix etc) running on it are not?
m3047
Brazil. Last year I effectively blocked Brazil for a while. Ultimately I settled on three possibilities for the traffic I was seeing: 01: DDOS 10: Residential proxies 11: Somebody DDOSing residential proxies
codedokode
I do not see problems with fake ad clicks and have no sympathy for ad companies. Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet. What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable. How can we prevent this? I think, for every imported device having a CPU and Internet connectivity: - the user must be able to re-flash firmware with their own code. - the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission. - any telemetry or data collection, or updates must be opt-in only and disabled by default. - any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update. Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.
Mistletoe
I recently got an Apple TV 4K and have been really enjoying the ad free experience. Worth every penny. Our smart tv had turned into a Christmas tree of ads.
AlotOfReading
Of all the evils normally associated with visual programming languages, enabling cybercrime isn't one I've previously considered. Now that I've seen it, I'm surprised it wasn't more common before LLMs appeared.
defmetrix
I didnt know anybody bought a streaming stick anymore
yunnpp
And which part of "ad fraud" is the fraud? As far as I can tell, ad networks and advertisers are the fraud and they are also part of the increasing surveillance state. Didn't know Krebs was a mainstream news puppet.
yumraj
Any way to identify or block these proxy and ad click services in the router? Say a Ubiquiti or even pfsense? I’m not using any of these boxes for especially this reason, but about 10-15 years ago had noticed my treadmill pinging a Chinese portal. I removed the WiFi access from the treadmill but am curious if there might be other devices. Any specific ports, etc these guys use or are they mostly impossible to distinguish from regular internet traffic? My another worry has been if these can monitor other Internet traffic, though I think HTTPS should mostly prevent that.
utopiah
I bet this is much broader than we all realized because just earlier today I was reading on https://gist.github.com/probonopd/3ad6b7777caea1503f00d5fe77... in order to tinker with a cheap (like really cheap) Android video projector : "Device: Magcubic HY300 Pro Android Projector (ui_Veng.projector) Issue: Device was being used as a residential proxy node without consent, causing thousands of suspicious DNS requests and bandwidth usage." linked in there just few months ago. It's not present on mine (AFAICT) which lead me to think either it was a genuine mistake or their bailed on that benefit or they upgraded to a harder to detect technique. An acquaintance mentioned they also bought a similar device few months ago. I believe there will be a lot MORE of these so we should soon be able to witness if it's an innocent mistake or the new normal.
stronglikedan
> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks. You had me at "But"! ::swoon::
RajT88
A pirate TV box from China presents a security threat? This is my surprised face.
gxs
No mention of Roku I use one but only when traveling at hotels - it’s one of the only sticks that can connect to captive WiFi networks at hotels I’ve got barely anything on it so privacy be damned - but at this point this is why I just buy apple products I have two apple tv’s which probably do shady things too, but I’m willing to play the probabilities and assume it’s the least bad of my options short of tinkering with flashing hardware and all that stuff that used to be fun in my teens (emphasis on used to)
kazinator
> But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads ... Compromised (or malicious from the factory) devices being recruited into bot farms for click fraud is ... a groundbreaking discovery in 2026? > on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks. To hell with AI-generated websites and advertising networks. Say, where can I get the most effective malicious TV stick for click-frauding the fuck out of that shit? I will take fifteen! :)