with the devices mentioned in the article, there is no consent requested, and the malicious apps are installed either before the box is sold or after as a requirement for getting the streaming services to work.
Really? You'd be ok with me putting a proxy server on your home network then, which anyone with a few bucks can use to attach your IP address and subscriber details to anything they choose to request from the internet? How about a Tor exit node?
Its incredibly obvious to anyone applying any thought at all to this that its a malicious to sell a product that labels itself as a TV streaming stick which is in fact a paid for relay server with the money made from providing the internet connection to a random third party unrelated to the person who bought the thing without ever telling the customer.