Elektrine lite

← Feed

@Hex@kolektiva.social

Post #3158016

2026-06-07 04:08 UTC

But if *I* hijack *their* devices it's a "felony." https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/

Replies (13)

  • @Hex@kolektiva.social 2026-06-07 04:19

    The good side of this is that there's a hijack-able data stream that anyone can use to poison LLM training sets, and they can't do shit because it's on *your* network.

    Open ##3293934

  • @klausi@mastodon.social 2026-06-07 06:28

    @Hex@kolektiva.social oh boy, this explains exactly what I see on our network at work. Millions of IP addresses from global residential networks making exactly 1 request. With a human-looking, but old user agent header. We had to implement a JavaScript cookie challenge for all users, which is sad but works.

    Open ##3293958

  • @wolf480pl@mstdn.io 2026-06-07 07:54

    @Hex@kolektiva.social > with the user’s consent, turns their phone or smart TV into one of those exit nodes. isn't there someone they forgot to ask? Idk about other countries, but at least in Poland, ISPs typically forbid customers from "letting other people outside of customer premises use the service" in their ToS. These proxies wouldn't exist if ISPs enforced their own ToS. Also, why aren't we holding ISPs accountable for the relayed traffic?

    Open ##3293959

  • @nunesgh@mastodon.social 2026-06-07 09:39

    @Hex@kolektiva.social I am surprised by how easy it is to bypass a VPN on iOS! "The SDK’s config ships a flag “use_netifs”: true. That flag triggers code in the SDK binary that constructs its NWConnection with a specific required interface: en0 (WiFi) or pdp_ip0 (cellular), rather than using the system default route. On iOS, this bypasses any configured VPN’s tun0 interface entirely. The peer tunnel does not cross a user-configured VPN, even when the rest of the app’s HTTPS traffic does." #VPN #iOS #privacy

    Open ##3293960

  • @tokyo_0@mas.to 2026-06-07 10:53

    @Hex@kolektiva.social Very interesting. I disconnected my "smart" TV from my wireless router years ago when I noticed it had been sending gigabytes of data without any good reason.

    Open ##3293962

  • @Hex@kolektiva.social I should be the one watching the TV. It should not be watching back.

    Open ##3293963

  • @Hex@kolektiva.social I solved that issue years ago. All my TVs are dumb. And things like my DVD player and TV are not on the internet. Fuck progress and spyware.

    Open ##3293965

  • @DukeDuke@mastodon.social 2026-06-07 11:16

    @Hex@kolektiva.social When I needed a new dumbbox last year, I specifically ordered the 2024 version. They shipped me the '25 version of that same model. Before opening, I looked it up and it was wall-to-wall AI trash. I immediately returned it, then ordered the '24 from someone else.

    Open ##3293966

  • @mntmn@mastodon.social 2026-06-07 11:43

    @Hex@kolektiva.social omg so that's the explanation for what's hitting our gitlab, i already blocked over 1.5 million IPs! > Bright Data is a data-collection company that sells access to what it markets as the world’s largest residential proxy network of 400M+ home IP addresses that its customers route web-scraping traffic through.

    Open ##3293967

  • @Aradayn@mastodon.social 2026-06-07 14:35

    @Hex@kolektiva.social Huh? Residential internet is not free of data caps in the USA. Using 200 GB is massive! It could easily cause people to blow past their caps and owe their ISPs money.

    Open ##3293970

  • @womble@infosec.exchange 2026-06-07 22:51

    @Hex@kolektiva.social your malware needs a ToS. Then it's all legit.

    Open ##3293971

  • @masukomi@connectified.com 2026-06-08 13:38

    @Hex@kolektiva.social 🧐 I think all you have to do to make it legal, is to get one of their representatives to click through yet another EULA that they can't avoid that gives you permission. That's what made it legal for them to do it to you after all.

    Open ##3293972

  • @rae_knowler@swiss.social 2026-06-09 17:11

    @Hex@kolektiva.social I got an unsolicited sales email from this kind of company last week (https://shifter.io) and felt a wash of anger that the people who are trying to take down the open data sites I support now want me to give them money as well

    Open ##3293973