Live data from Hacker News

The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

blog.includesecurity.com

61–70 of 114 posts

Re: The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

#61

Earlier quoted context omitted.

But it lets you continue without reading them? There's a lot of questionable terms of service rules but this one has to be unenforcable.

You must check a checkbox in agreement to continue. To read the policies one agrees to, an internet connection is required. You may check the checkbox without reading. As far as I have found from a lot of menu spelunking, this agreement is irrevocable. If I ever go online, it will be used.

That's the kind of thing that doesn't always hold up in court.

Re: The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

#62

Are there any defenses I can put in front of my websites that are good for stopping these things? The amount of traffic I see from residential proxies is just killing me. In particular defense against residential proxies.

Make your server so efficient that a few extra requests doesn't bring it down.

Alternatively, if it's the first time the IP is seen and it's a deep linked page with no referer, send a neverending chunked gzip data stream.

Re: The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

#63
post #8

One of the problems I can see here is the problem that running a Tor exit node has: badly behaved users are going to be using it to hide their location. Imaging having the police show up at your door because they've figured out that you're trafficking child porn, when the actual culprit is someone that is using your TV as a proxy to trade child porn.

Groups like Bright Data have pretty good KYC. After the scare of the police visit, the actual perpetrator would go to prison.

Re: The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

#64
post #49

Earlier quoted context omitted.

I have a smart TV that's never spoken to the internet after exiting the factory, but it's a pretty tenuous state of affairs. I have this fear that someone staying over is going to see the "Services unavailable, press [menu] to troubleshoot" toast that shows up overtop the HDMI feed for a few seconds and think they're helping me by connecting it. 4-5 years worth of firmware updates all at once... half a decade of watc…

Find the TV’s MAC address and block it on your router. My brother home network had this system where your MAC address had to be whitelisted on the router to communicate with the network, as the days go by I see how in hindsight how this might be for the best in the end.

I split my network(s) into subnets (sharing the same wire, not to be confused with the actual subnets which don't share the same wire) which correspond to routability policies. This in turn involves firewall rules, routing table entries, and DHCP configs corresponding to those subnets.

I give away the software which does the following. I get this (and a lot more) for every host on my network, and I know what every host is.

    # peers upstairs-roku.m3047 +addr +serv
    dns.google [8.8.4.4]                                              domain [53]     
    dns.google [8.8.8.8]                                              domain [53]     
    athena.m3047 [10.0.0.220]                                         domain [53]     
    mediaservices.cdn-apple.com [23.46.228.133]                       https [443]     
    mediaservices.cdn-apple.com [23.46.228.134]                       https [443]     
    mediaservices.cdn-apple.com [23.46.228.135]                       https [443]     
    mediaservices.cdn-apple.com [23.46.228.137]                       https [443]     
    mediaservices.cdn-apple.com [23.46.228.138]                       https [443]     
    mediaservices.cdn-apple.com [23.46.228.139]                       https [443]     
    mediaservices.cdn-apple.com [23.46.228.140]                       https [443]     
    mediaservices.cdn-apple.com [23.46.228.142]                       https [443]     
    mediaservices.cdn-apple.com [23.46.228.143]                       https [443]     
    mediaservices.cdn-apple.com [23.46.228.144]                       https [443]     
    mediaservices.cdn-apple.com [23.46.228.145]                       https [443]     
    mediaservices.cdn-apple.com [23.213.34.169]                       https [443]     
    mediaservices.cdn-apple.com [23.213.34.176]                       https [443]     
    mediaservices.cdn-apple.com [23.213.34.178]                       https [443]     
    mediaservices.cdn-apple.com [23.213.34.185]                       https [443]     
    mediaservices.cdn-apple.com [23.213.34.186]                       https [443]     
    mediaservices.cdn-apple.com [23.213.34.187]                       https [443]     
    mediaservices.cdn-apple.com [23.213.34.188]                       https [443]     
    mediaservices.cdn-apple.com [23.213.34.193]                       https [443]     
    mediaservices.cdn-apple.com [23.213.34.196]                       https [443]     
    mediaservices.cdn-apple.com [23.213.34.201]                       https [443]     
    mediaservices.cdn-apple.com [23.213.34.203]                       https [443]     
    nrdp.push.prod.netflix.com [35.81.198.46]                         www [80]        
    ec2-35-86-100-253.us-west-2.compute.amazonaws.com [35.86.100.253] psbserver [2350]
    austin.logs.roku.com [35.212.27.142]                              https [443]     
    scribe.logs.roku.com [35.212.34.174]                              https [443]     
    austin.logs.roku.com [35.212.72.105]                              https [443]     
    austin.logs.roku.com [35.212.119.44]                              https [443]     
    display.ravm.tv [35.212.178.254]                                  https [443]     
    logs.netflix.com [44.226.179.188]                                 https [443]     
    logs.netflix.com [44.228.67.58]                                   https [443]     
    nrdp.push.prod.netflix.com [44.229.50.4]                          www [80]        
    logs.netflix.com [44.229.122.169]                                 https [443]     
    nrdp.push.prod.netflix.com [44.232.75.216]                        www [80]        
    api.roku.com [44.249.213.211]                                     https [443]     
    nrdp.prod.ftl.netflix.com [45.57.40.1]                            https [443]     
    nrdp.prod.ftl.netflix.com [45.57.41.1]                            https [443]     
    nrdp.push.prod.netflix.com [52.24.26.117]                         www [80]        
    logs.netflix.com [52.33.247.19]                                   https [443]     
    themes-service.sr.roku.com [54.200.214.141]                       https [443]     
    occ-0-1009-1007.1.nflxso.net [198.38.112.135]                     www [80]        
    occ-0-1009-1007.1.nflxso.net [198.38.112.144]                     www [80]        
    occ-0-1009-1007.1.nflxso.net [198.38.112.145]                     www [80]        
    occ-0-1009-1007.1.nflxso.net [198.38.112.165]                     www [80]        
    occ-0-1009-1007.1.nflxso.net [198.38.112.169]                     www [80]        
    occ-0-1009-1007.1.nflxso.net [198.38.112.170]                     www [80]        
    occ-0-1009-1007.1.nflxso.net [198.38.112.172]                     www [80]        
    occ-0-1009-1007.1.nflxso.net [198.38.112.178]                     www [80]        
    mdns.mcast.net [224.0.0.251]                                      mdns [5353]     
    239.255.255.250 [239.255.255.250]                                 ssdp [1900]

Re: The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

#65
post #23

If the kind of proxying isn't illegal, in my opinion it should be -- saying it's bordering on circumvention of fundamental assumptions about Internet routing and IP address leasing (and ownership), would be a sorry understatement compared to what Bright Data has managed to package into a product payment: > you are allowing Bright Data to occasionally use your device’s free resources and _IP address to download public…

It's completely legal and the law you mentioned about IP routing and address ownership does not exist.

Re: The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

#66
post #30

I found some 60 iOS apps that have the SDK mentioned in the article: https://appgoblin.info/sdks/brdsdk.framework (sorry this requires a free login due to heavy scraping, feel free to contact me for list) I was unable to find related Android SDKs. I tried looking at the various apps on AppGoblin to find the android versions, then looking through their unmapped SDK parts but didn't see anything. https://github.com/Bri…

Android apps are usually obfuscated, ostensibly to make them smaller, and now obviously to hide what's inside. Only a basic level of obfuscation is typically used, so you would have more luck searching for strings.

Re: The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

#67

Having never owned a telivision because of how much I didn't like advertising when tv was the primary delivery method, the feeling of having avoided a life sentence of bieng lashed to the tube is wierd, I know that people might catch me looking all to intently into there eyes trying to see if they are realy in there.

Phones do the same thing...

Re: The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

#68
post #22

Earlier quoted context omitted.

Most scrapped websites have https, so you need to perform a MITM attack. Scrapers will probably notice that.

How would https affect it? If they're making a request to my machine to go and curl a page, how do they even know whether or not it was https?

Not sure about Bright Data but these are usually SOCKS or HTTP CONNECT proxies because that's most flexible. But the customer might be paying by the gigabyte, so you can still feed them nonsense, maybe a 4 gigabyte TLS certificate.

Re: The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

#69
post #59

Earlier quoted context omitted.

I have a smart TV that's never spoken to the internet after exiting the factory, but it's a pretty tenuous state of affairs. I have this fear that someone staying over is going to see the "Services unavailable, press [menu] to troubleshoot" toast that shows up overtop the HDMI feed for a few seconds and think they're helping me by connecting it. 4-5 years worth of firmware updates all at once... half a decade of watc…

I fear the same but made sure I block basically everything at the network level. First thing I do is hook the tv to the network and black hole its mac.

Or open up the TV and disable its wifi hardware.

Re: The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

#70
post #6

I find Cloudflare to be more unethical than Bright Data.

Both are causing a dynamic that will lock down the internet evermore for everything straying slightly from the corporate-approved line. If the divide was data center vs residential IPs, fine, but thanks to Bright Data and friends, residential IPs are getting suspicious as well, so I guess the next step is full-on client verification then...

DC and residential IPs aren't real categories that exist either. They are guesses by IP reputation companies. Nothing except practicality stops an ISP from mixing them both into the same DHCP pool.
Post reply on HN