Hacker News new | ask | show | jobs
by boondongle 1 day ago
Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold. They certainly don't advertise to the big box retailer that buys them "and it uses the customer's internet connection for fraud."

Hell, there's a section of comments that would probably going "hey, RELAX guy" because it's not US companies doing this. For any American companies that do this though, sure - block/suspend/prosecute.

5 comments

If I open my own line of home improvement stores and do no oversight on what I sell and wind up selling really dangerous lawnmowers, I'm partly responsible.

Or if I open up a gas station and allow any company without oversight to sell "supplements" through my shelves and cops arrest me for selling heroin, I don't get a free pass.

Why should amazon or Walmart get a free pass just because they sell more items?

One problem I see with your analogy is that the dangerous lawnmower can cause an easily quantifiable harm.

You have to be able to show damages you incurred and assign a dollar value to them to sue people.

That doesn’t work at all for a something that sells your bandwidth to a proxy service. People wouldn’t even be aware that it was happening they weren’t told.

What about when the police show up because some highly illegal content was traced to your IP address? Will they believe that you were the unwitting victim of a rogue proxy server running on your streaming stick? Would you have even been aware of that possibility?
There's also always the flip side: When the police shows up because of your illegal acitivities, you have a rogue proxy server running. All bought in good faith of course.

Not legal advice.

(It would surprise me greatly if we as a society let these gadgets be sold openly from here on.)

That shows the problem or trying to link an IP address to an individual.
Believe it or not, that is what happens when the police show up to the house of a primary school teacher. They will think they have the wrong address. Even US police.

The cybercrime raids happen when they run into someone who looks like a hacker and has a lot of computers.

> If I open my own line of home improvement stores and do no oversight on what I sell and wind up selling really dangerous lawnmowers, I'm partly responsible.

While there would be oversight, it is highly unlikely that a person opening a home improvement store would perform any meaningful safety testing. They simply would not be qualified. The oversight would lay in selling certified products, pulling recalled products off the shelf, and (perhaps) removing products if there is a reason to suspect safety issues.

Now consider streaming sticks. There are safety standards for the physical device but, to my knowledge, there are no such standards for the software itself. Heck, there aren't even standards for the engineers who work on the software. One can make highly prejudiced decisions based upon the country of origin. Perhaps there are even good reasons to avoid products from certain countries. Yet the lack of standards also means that products from trustworthy sources can be suspect, since all it takes is a management decision to change things.

But these products aren't dangerous. And proxying internet traffic isn't illegal. Fake ad clicks may be illegal but that falls on whoever is providing that service, which isn't the proxy or the resident. On what basis would you ban them?
Except the devices are not dangerous. Its the software installed on the device. Consumers have a choice. Pay for the trusted Apple TV or Amazon firestick, or go the wild west and see what's on offer.
with the devices mentioned in the article, there is no consent requested, and the malicious apps are installed either before the box is sold or after as a requirement for getting the streaming services to work.
You call them malicious apps but what is the evidence they are more malicious than the things they fight against?
Really? You'd be ok with me putting a proxy server on your home network then, which anyone with a few bucks can use to attach your IP address and subscriber details to anything they choose to request from the internet? How about a Tor exit node?

Its incredibly obvious to anyone applying any thought at all to this that its a malicious to sell a product that labels itself as a TV streaming stick which is in fact a paid for relay server with the money made from providing the internet connection to a random third party unrelated to the person who bought the thing without ever telling the customer.

Yeah I actually do several of those to earn a few bucks.
The typical consumer has no idea what they're buying, and they shouldn't have to because the retailer selling the product should have done some basic due diligence before stocking the thing. People aren't going to some clearly shady Chinese website and buying a device labelled "cheap TV streaming stick, will sublease your internet connection to criminals", they're putting "FireTV" into amazon.com and somehow being presented with these things alongside the Amazon FireTV they expect to find, or maybe "streaming stick" which really shouldn't be surfacing clearly malicious products.
If the average consumer did get a disclaimer it would sublease their internet connection to a few criminals and a lot of people who aren't criminals, would they care?
> Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold.

You already answered it: block it from being sold.

1) Make Amazon responsible for the products they are selling. 2) Introduce a law banning malware tv sticks 3) Sue Amazon for a percentage of their yearly revenue when caught violating it 4) Amazon will finally start caring and do some kind of review on the crap they sell.

And if the first time you get it online it just updates itself to malware?

That's the biggest problem with any device that updates.

Yea, this will work for the moment and the seller will be covered in the sense that "well, it wasn't infected when we sold it".

The law is not software. It would be very easy to argue that a streaming stick that automatically downloads malware is no different from one that came with malware.
And that's where the retailer is no longer in the loop, which is what this thread was about.
I think a law that makes a marketplace responsible for items being sold if the qty of items is above a threshold would be a great idea.

You don't want to penalize someone selling their Xbox or lawnmower on Ebay but you want to stop what is going on here. A place like Etsy where people are selling their crafts is an interesting edge case but I think they should probably be a little regulated.

If it's malware, maybe existing laws apply already. I think the bigger problem is enforcement. In China, it's easy to close up shop if anything goes wrong and then just start over. Any liability dies with the brand name.
But it is a retailer's responsibility to know what they are selling. If it was added after they started selling it and hidden in secret, sure a retailer might have an excuse. But it isn't really hidden, most often its put in their marketing materials as a benefit and have been knowingly doing it for many years now.

US retailers can be told they can't sell it here. If you buy it outside of that, well that is buyer beware, but 99% of people aren't buying things from Alibaba or ordering from some random foreign store, they are buying them off US Amazon, Walmart, big box retailers, etc. You don't have to ban things consumer level to deal with 99% of it, you just gotta tell big corporations no and stop dismissing any ideas that put responsibility or liability on big business.

The problem is that Amazon, Walmart & friends have said the "we are a platform, not a retailer" magic incantation, which means that through the power of friendship and unicorns they are now suddenly no longer responsible for the stuff they sell.

And the "retailer" on record is of course not a real company. They'll just pay some third-party to file a bunch of paperwork in Delaware, pay the $110 fee, and let it go bust if anyone tries to investigate it or make it liable.

>If it was added after they started selling it

While it's great we're getting the manufactures to just stop sending out straight malware and it should be stopped the next most obvious means of attack is just having the device update and add superaids to it's new functionality.

So, no, it won't stop 99% of it at all.

And honestly this isn't that much different from what US companies are already great at by providing updates that take away features we bought with the device.

And not just updating really doesn't save you, instead of being part of a factory botnet, you're just open to become part of some other botnet.

The FCC tests electronics for radio interference. Perhaps they could test electronics for Internet behavior like this too?

Some manufacturers will try to cheat on the tests, but we have AI security checking now, so maybe that would make it harder to cheat?

That sounds like a fast track to government control of what operating systems are allowed. These aren’t just electronics, they are low power computers that happen to have an OS and software preinstalled.

(I’d be open to a rule that devices must allow users to wipe the devices and install their own OS.)

On the other hand, I suppose if the OS on a TV stick ran in a hardware-enforced sandbox that restricted network access to certain necessary domains, it couldn't be used for scraping websites and ad fraud? It's not being sold as a general-purpose computer so maybe it shouldn't be one.
Simple. Buy one, put it on a test stand, and look at connection log.

Buying in bulk for a resell without testing even one product is kinda insane.