7 ms·
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy
- skinwill 3mo agoNot if my firewall blocks it from accessing the outside world. (But allows HomeAssistant to control it)
- asdff 3mo agoA lot of smart TVs bake in ads. I had a used sony bravia for like a frusterating three days before I put it on the side of the road, because it would just boot loop and the ui had like 3 seconds worth of input latency. I never connected it to the network, so it helpfully showed me ads for the various sony studio movies that were coming out at the time of the TVs manufacturing about 10 years ago.
- trumpdong 3mo agoI find Cloudflare to be more unethical than Bright Data.
- xg15 3mo agoBoth are causing a dynamic that will lock down the internet evermore for everything straying slightly from the corporate-approved line. If the divide was data center vs residential IPs, fine, but thanks to Bright Data and friends, residential IPs are getting suspicious as well, so I guess the next step is full-on client verification then...
- clvx 3mo agoI wish federal or state laws could force providing transparency because asking for privacy is a dead end at this point. Just force products and providers that run in my home where they phone in. Then, I can decide what to do with that whether I send them to a black hole or let them pass.
- trumpdong 3mo agoThese are legitimate client devices. Good luck with that.
- trumpdong 3mo agoDC and residential IPs aren't real categories that exist either. They are guesses by IP reputation companies. Nothing except practicality stops an ISP from mixing them both into the same DHCP pool.
- deleted 3mo ago[deleted]
- cobbzilla 3mo agoI never connect any “smart” device to wifi. If it doesn’t work without connectivity, I don’t want it. I use my TVs as display devices. They have HDMI-in and that’s it.
- lelandfe 3mo agoOn my TCL TV, you have to connect it to read the Google policies you are agreeing to. If you don't, you agree to policies unread. Thankfully, the blast radius of this is nothing without connectivity.
- idiotsecant 3mo agoBut it lets you continue without reading them? There's a lot of questionable terms of service rules but this one has to be unenforcable.
- lelandfe 3mo agoYou must check a checkbox in agreement to continue. To read the policies one agrees to, an internet connection is required. You may check the checkbox without reading. As far as I have found from a lot of menu spelunking, this agreement is irrevocable. If I ever go online, it will be used.
- trumpdong 3mo agoThat's the kind of thing that doesn't always hold up in court.
- deleted 3mo ago[deleted]
- rationalist 3mo agoThe reality is, no one is going to take the companies to court over things like this.
- skywhopper 3mo agoNot the one in my living room.
- xg15 3mo ago> After config fetch, the SDK opens a persistent WebSocket to: wss://proxyjs.brdtnet.com:443 This hostname resolves to AWS Global Accelerator IPs There is some irony that both the scrapers and the websites being scraped are probably hosted on AWS, while playing an elaborate cat-and-mouse game pretending that they weren't.
- cyanydeez 3mo agoKind how the American government needs commercial businesses which they poorly regulate so those businesses provide privacy invasions as a legal means to wash their hands.
- rootsudo 3mo agoSame for arms dealing, and every other industry.
- BLKNSLVR 3mo agoAdding to DNS block list immediately.
- xg15 3mo agoDon't forget the config endpoint before as well. > On every launch the SDK calls: GET <https://clientsdk.bright-sdk.com/sdk_config_ios.json https://clientsdk.bright-sdk.com/sdk_config_ios.json>?appid=<bundle>&ver=<sdk-version>&uuid=sdk-ios-<32hex>
- xoa 3mo ago>Adding to DNS block list immediately. Just making a note here for anyone else with the same thought: I went to ping the domains listed ITT, and nothing went through. I'm running OPNsense and amongst other things using some of the hagezi DNS block lists [0]. It looks like brdtnet.com, bright-sdk.com and various subdomains were already in there, which is a nice sanity check. That said, also worth noting that an Unbound or other resolver based DNS block list can prevent resolution but doesn't preventing connecting to the underlying IP, it's not the same thing as actually invoking your firewall itself. For that I think you need to stick the lists into something that will resolve them regularly and then actually Firewall that off. So for OPNsense you can setup an alias using the URL Table (plain text) or URL Table in JSON depending on format, or manage it externally directly if desired via external. Then the source will be updated and aliases will all be resolved on operator defined schedules, and can in turn be fed into regular firewall rules. Don't forget these can turn into massive lists, so make sure your internal resource limits (so for OPNsense that'd be Firewall Maximum Table Entries) are set sufficiently high and the hardware can handle it. Other systems may handle it differently, just it's important to double check what is actually happening including if something malicious tries to be sneakier. And ultimately for these sorts of untrustable embedded devices that lack owner control, it's probably a lot better and more sustainable, if more effort upfront, to isolate them into their own vlan/subnet and then whitelist instead of blacklist. So they can only access what you decide they need to and nothing else, vs access everything except what is disallowed. Still, blacklisting bad actors as a final layer for everything may still be useful. ---- 0: https://github.com/hagezi/dns-blocklists https://github.com/hagezi/dns-blocklists
- NewCzech 3mo agoOne of the problems I can see here is the problem that running a Tor exit node has: badly behaved users are going to be using it to hide their location. Imaging having the police show up at your door because they've figured out that you're trafficking child porn, when the actual culprit is someone that is using your TV as a proxy to trade child porn.
- iugtmkbdfil834 3mo agoI genuinely dislike how user hostile everything has become. I effectively have to become an expert in near everything and track all news on the off-change something major upends previous assumptions. And if I miss it somehow and complain about it, defenders will come out of the woodwork to defend, deflect or derail the conversation. If there is any good news about this, it is that the fatigue seems to be hitting normal people. Buddy from work complained to me how he now is now forced to be a full blown wifi/internet admin so that his kids' restrictions/limits are appropriately enforced. I am just venting, because I am not entirely certain what an appropriate solution here is.
- amelius 3mo agoSolution is more regulation, stronger consumer organizations, and privacy watchdogs with actual teeth.
- trumpdong 3mo agoGroups like Bright Data have pretty good KYC. After the scare of the police visit, the actual perpetrator would go to prison.
- calcifer 3mo ago> The SDK’s config ships a flag “use_netifs”: true. That flag triggers code in the SDK binary that constructs its NWConnection with a specific required interface: en0 (WiFi) or pdp_ip0 (cellular), rather than using the system default route. > On iOS, this bypasses any configured VPN’s tun0 interface entirely. The peer tunnel does not cross a user-configured VPN, even when the rest of the app’s HTTPS traffic does. What's a legitimate use case for this API? When/why should an app be allowed to bypass a user-configured VPN?
- picofarad 3mo ago> When/why should an app be allowed to bypass a user-configured VPN? temporarily if full tunnelling isn't working, one can split tunnel to route around issues due to VPN But imo an app should never bypass something like a network boundary.
- kotaKat 3mo agoLook at how far TikTok can go if you try blocking DNS. The hardcoded IPs, self-DNS-resolution and cat-and-mouse game of blocking is quite... interesting.
- vsgherzi 3mo agoIs there anywhere I could read more about this ?
- kotaKat 3mo agohttps://github.com/M4jx/TikTokBlocklist https://github.com/M4jx/TikTokBlocklist I think they may have scaled back from this, but they were running a 100% malware-style playbook to hit the Tiktok servers like it was some kinda sketchy C2 package. Lots of attempts of their own DoH (and DoT!) and normal DNS servers to try to get into the Tiktok network.
- chmod775 3mo ago> What's a legitimate use case for this API? When you're the application providing the VPN or when you're any app built to communicate with something on a local-ish network, not something actually reachable globally.
- yodon 3mo agoNaive question: what would I search for to find a tutorial on how to detect this on my devices, which are mostly iOS, or in my home network? I'd love to find and remove any apps from my devices that have this SDk active.
- tisdadd 3mo agoThere could be better, but this looked reasonable at first glance if you also have a Mac. https://www.thequantizer.com/tutorials/wireshark-iphone-traffic-capture/ https://www.thequantizer.com/tutorials/wireshark-iphone-traf... It has been a while since I personally did such traces, but Wireshark was very simple to use and once the network is exposed, it has lots of information available online if you need more. I found bypassing your VPN particularly appalling, as is the whole thing. Personally, it would be amazing if there were a limit on how much can be in Terms of Service, as no one wants to read that much anymore.
- ErroneousBosh 3mo agoSo wait a second then, it connects out using a websocket to its bot C&C server, right? Which presumably passes it a URL to scrape and waits for it to return the data. What happens if I write my own tool that connects to that C&C server, waits for a URL to scrape, and returns gigabytes of freshly brewed hot horseshit?
- woffoor 3mo agoMost scrapped websites have https, so you need to perform a MITM attack. Scrapers will probably notice that.
- voakbasda 3mo agoNo, you just need to stand up your own website and feed the scraper a URL to it.
- ErroneousBosh 3mo agoI would just generate scads of Markov chain output and make it look like a plausible web page.
- dreamcompiler 3mo agoThat's pretty much what the bots are scraping now, with all the AI slop websites out there.
- ErroneousBosh 3mo agoFair point well made.
- ErroneousBosh 3mo agoHow would https affect it? If they're making a request to my machine to go and curl a page, how do they even know whether or not it was https?
- hackrmn 3mo agoIf the kind of proxying isn't illegal, in my opinion it should be -- saying it's bordering on circumvention of fundamental assumptions about Internet routing and IP address leasing (and ownership), would be a sorry understatement compared to what Bright Data has managed to package into a product payment: > you are allowing Bright Data to occasionally use your device’s free resources and _IP address to download public web data from the internet_. (emphasis mine) I think the misleading part -- to the end-user -- is the "download public web data" part. If the data is public why can't Bright Data download it themselves? Well, because the other end doesn't want them to, apparently. The product is make you help Bright Data circumvent the undesired properties of the "public" data providers, on behalf of someone who happens to have the cash but as of yet is at the short end of the Internet stick (for all the right reasons, I'd say). This is absolutely deplorable, but knowing the directions this is heading, I am neither surprised nor concerned, frankly. People have long voted with their wallet -- it's not the privacy-conscious Joe the Hacker that is being proxied through here, it's our parents and millions of people who just want entertainment at the end of the working day, including _parents_ of small children. Day by day the dark Internet theory sounds more plausible, and frankly I am all there for it. The Internet will collapse into a feudal internetwork where any routing will need hop-by-hop key, so real people (and agents, frankly) can maintain a measure of trust that right now is being actively circumvented.
- trumpdong 3mo agoIt's completely legal and the law you mentioned about IP routing and address ownership does not exist.
- blakesterz 3mo agoAre there any defenses I can put in front of my websites that are good for stopping these things? The amount of traffic I see from residential proxies is just killing me. In particular defense against residential proxies.
- jappgar 3mo agoThe bots used by these proxies are detectable in a few ways. Remember the bot itself doesn't run on the proxy... There is discernible lag from proxy to c&c node. The individual bots don't have access to a lot of compute, and are sometimes restricted wrt feature set (e.g. proprietary video codecs). There are a few other techniques. It's a cat and mouse game though. And the bot owners are usually more motivated than you are.
- bakugo 3mo agoAdd a captcha or proof-of-work challenge in front of your website. Those are pretty much your only options.
- asdff 3mo agoThere's probably ways to go on the offensive too with pages that might be hidden from human users but still crawled by bots.
- trumpdong 3mo agoMake your server so efficient that a few extra requests doesn't bring it down. Alternatively, if it's the first time the IP is seen and it's a deep linked page with no referer, send a neverending chunked gzip data stream.
- asdff 3mo agoHave a link on your page that would be hidden by users via css. e.g. white text on white background. Have it just abuse compute or do something absolutely stupid for the bots that end up crawling over that link. Hell, just zip bomb them.
- Rasbora 3mo ago
- ddxv 3mo agoI found some 60 iOS apps that have the SDK mentioned in the article: https://appgoblin.info/sdks/brdsdk.framework https://appgoblin.info/sdks/brdsdk.framework (sorry this requires a free login due to heavy scraping, feel free to contact me for list) I was unable to find related Android SDKs. I tried looking at the various apps on AppGoblin to find the android versions, then looking through their unmapped SDK parts but didn't see anything. https://github.com/BrightSDK/bright-sdk-gradle-plugin-docs https://github.com/BrightSDK/bright-sdk-gradle-plugin-docs This looks like it should just be "com.brightdata" but I did not find anything. With 60 iOS apps there must be apps with Android SDK, but I'm not sure why I am not finding any. If anyone knows, or would like to chat feel free to connect. I'm happy to share data.
- NewsaHackO 3mo agoWhy can't you just post the list as a comment?
- trumpdong 3mo agoAndroid apps are usually obfuscated, ostensibly to make them smaller, and now obviously to hide what's inside. Only a basic level of obfuscation is typically used, so you would have more luck searching for strings.
- theturtle 3mo ago[dead]
- everybodyknows 3mo agoFTA: > MDM, mobile EDR Anyone care to ELI5 these?
- boilerupnc 3mo agoMDM: Mobile Device Management. Software that helps ops folks control a fleet of mobile devices like tablets, phones, etc… Mobile EDR: Endpoint detection and response. This is cybersecurity software to monitor and deal with network activity happening in mobile devices like tablets, phones, etc…
- tamimio 3mo agoYears ago I had smart TV, and while I never used anything “smart”, one day I connected it to the network to update it and forgot it, two days later I was checking my dns and 80% of the traffic and blocked queries in the past two days were from one device, after tracking it, it was the TV! So what I have now is a pre-smart TV I found at the thrift, still very good picture that’s more than enough for the few times I use it. There should be a way to disable the “smart” garbage in new TVs, or an option to buy normal ones at least.
- handle584 3mo ago[dead]
- metalman 3mo agoHaving never owned a telivision because of how much I didn't like advertising when tv was the primary delivery method, the feeling of having avoided a life sentence of bieng lashed to the tube is wierd, I know that people might catch me looking all to intently into there eyes trying to see if they are realy in there.
- trumpdong 3mo agoPhones do the same thing...
- deleted 3mo ago[deleted]
- rdtsc 3mo ago> The TLS certificate is CN=*.luminatinet.com — the domain for Luminati Networks, Bright Data’s pre-2018 corporate name Ah yes. The big privacy scraping company called themselves The Luminati. It’s like they are side-investing in tin foil hats or something.
- drchaim 3mo agoI just checked,I have AdGuard for the whole network. On the TV, 80% of requests are blocked; across the entire network, around 50%. crazy.
- maxgashkov 3mo agoProposed mitigations look weak: - DNS block & SNI filtering: I expect BrightData to rotate the endpoints if this issues gains enough attention. It will take some time once all the apps embedding the SDK catch up, but if they're smart SDK may already have a backup C&C connection they will try to reach out to after prolonged unavailability of the current endpoints. - TLS fingerprint: unless SDK pins it, it's the cheapest one to rotate continously. - MDM solution: almost unattainable to private users; not clear how stable the SDK name is to rely on. Not saying I have a better approach. It seems behavior like this should be explicitly banned on Apple/Google's side with immediate termination of their publisher accounts.
- wbshaw 3mo agoBlocking your tv on the local network is great in principle. However, didn't Amazon Fire devices start using Sidewalk to establish a route to the mother ship for a while? All it needed was a default config on your neighbor's ring doorbell and it was gtg
- jibaoproxy 3mo ago[flagged]