frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/
89•nikcub•4h ago

Comments

trumpdong•1h ago
I find Cloudflare to be more unethical than Bright Data.
xg15•1h ago
Both are causing a dynamic that will lock down the internet evermore for everything straying slightly from the corporate-approved line.

If the divide was data center vs residential IPs, fine, but thanks to Bright Data and friends, residential IPs are getting suspicious as well, so I guess the next step is full-on client verification then...

clvx•1h ago
I wish federal or state laws could force providing transparency because asking for privacy is a dead end at this point. Just force products and providers that run in my home where they phone in. Then, I can decide what to do with that whether I send them to a black hole or let them pass.
cobbzilla•1h ago
I never connect any “smart” device to wifi. If it doesn’t work without connectivity, I don’t want it. I use my TVs as display devices. They have HDMI-in and that’s it.
lelandfe•1h ago
On my TCL TV, you have to connect it to read the Google policies you are agreeing to. If you don't, you agree to policies unread.

Thankfully, the blast radius of this is nothing without connectivity.

idiotsecant•36m ago
But it lets you continue without reading them? There's a lot of questionable terms of service rules but this one has to be unenforcable.
drhike•16m ago
If it has an Ethernet port I would use that then unplug it. It still gets to phone home once but you don't have to worry about it maliciously saving your Wi-Fi password for later
skywhopper•1h ago
Not the one in my living room.
xg15•1h ago
> After config fetch, the SDK opens a persistent WebSocket to:

wss://proxyjs.brdtnet.com:443

This hostname resolves to AWS Global Accelerator IPs

There is some irony that both the scrapers and the websites being scraped are probably hosted on AWS, while playing an elaborate cat-and-mouse game pretending that they weren't.

cyanydeez•21m ago
Kind how the American government needs commercial businesses which they poorly regulate so those businesses provide privacy invasions as a legal means to wash their hands.
NewCzech•1h ago
One of the problems I can see here is the problem that running a Tor exit node has: badly behaved users are going to be using it to hide their location.

Imaging having the police show up at your door because they've figured out that you're trafficking child porn, when the actual culprit is someone that is using your TV as a proxy to trade child porn.

iugtmkbdfil834•20m ago
I genuinely dislike how user hostile everything has become. I effectively have to become an expert in near everything and track all news on the off-change something major upends previous assumptions. And if I miss it somehow and complain about it, defenders will come out of the woodwork to defend, deflect or derail the conversation.

If there is any good news about this, it is that the fatigue seems to be hitting normal people. Buddy from work complained to me how he now is now forced to be a full blown wifi/internet admin so that his kids' restrictions/limits are appropriately enforced.

I am just venting, because I am not entirely certain what an appropriate solution here is.

skinwill•1h ago
Not if my firewall blocks it from accessing the outside world. (But allows HomeAssistant to control it)
calcifer•53m ago
> The SDK’s config ships a flag “use_netifs”: true. That flag triggers code in the SDK binary that constructs its NWConnection with a specific required interface: en0 (WiFi) or pdp_ip0 (cellular), rather than using the system default route.

> On iOS, this bypasses any configured VPN’s tun0 interface entirely. The peer tunnel does not cross a user-configured VPN, even when the rest of the app’s HTTPS traffic does.

What's a legitimate use case for this API? When/why should an app be allowed to bypass a user-configured VPN?

picofarad•30m ago
> When/why should an app be allowed to bypass a user-configured VPN?

temporarily if full tunnelling isn't working, one can split tunnel to route around issues due to VPN

But imo an app should never bypass something like a network boundary.

chmod775•21m ago
> What's a legitimate use case for this API?

When you're the application providing the VPN or when you're any app built to communicate with something on a local-ish network, not something actually reachable globally.

yodon•35m ago
Naive question: what would I search for to find a tutorial on how to detect this on my devices, which are mostly iOS, or in my home network?

I'd love to find and remove any apps from my devices that have this SDk active.

tisdadd•23m ago
There could be better, but this looked reasonable at first glance if you also have a Mac.

https://www.thequantizer.com/tutorials/wireshark-iphone-traf...

It has been a while since I personally did such traces, but Wireshark was very simple to use and once the network is exposed, it has lots of information available online if you need more.

I found bypassing your VPN particularly appalling, as is the whole thing. Personally, it would be amazing if there were a limit on how much can be in Terms of Service, as no one wants to read that much anymore.

ErroneousBosh•28m ago
So wait a second then, it connects out using a websocket to its bot C&C server, right?

Which presumably passes it a URL to scrape and waits for it to return the data.

What happens if I write my own tool that connects to that C&C server, waits for a URL to scrape, and returns gigabytes of freshly brewed hot horseshit?

woffoor•6m ago
Most scrapped websites have https, so you need to perform a MITM attack. Scrapers will probably notice that.
hackrmn•5m ago
If the kind of proxying isn't illegal, in my opinion it should be -- saying it's bordering on circumvention of fundamental assumptions about Internet routing and IP address leasing (and ownership), would be a sorry understatement compared to what Bright Data has managed to package into a product payment:

> you are allowing Bright Data to occasionally use your device’s free resources and _IP address to download public web data from the internet_.

I think the misleading part -- to the end-user -- is the "download public web data". If the data is public why can't Bright Data download it themselves. Well because the other end doesn't want it to. The product is make you help Bright Data circumvent the undesired properties of the "public" data providers, on behalf of someone who happens to have the cash but as of yet is at the short end of the Internet stick (for all the right reasons, I'd say).

This is absolutely deplorable, but knowing the directions this is heading, I am neither surprised nor concerned, frankly. People have long voted with their wallet -- it's not the privacy-conscious Joe the Hacker that is being proxied through here, it's our parents and millions of people who just want entertainment at the end of the working day, including _parents_ of small children.

How LLMs work

https://www.0xkato.xyz/how-llms-actually-work/
473•0xkato•2d ago•144 comments

S&P 500 rejects SpaceX, also blocking entry for OpenAI and Anthropic

https://arstechnica.com/tech-policy/2026/06/sp-500-blocks-fast-spacex-entry-wont-waive-rule-for-u...
733•maltalex•8h ago•239 comments

The intracies of modern camera lens repair (2024)

https://salvagedcircuitry.com/sigma-45mm.html
193•transistor-man•12h ago•66 comments

The new bibliomaniacs

https://engelsbergideas.com/notebook/the-new-bibliomaniacs/
5•RickJWagner•1h ago•3 comments

Google will pay SpaceX $920M per month for compute

https://techcrunch.com/2026/06/05/google-will-pay-spacex-920m-per-month-for-compute/
80•ramanan•1h ago•82 comments

Pokemon Emerald Ported to WebAssembly (100k FPS)

https://pokeemerald.com/
7•tripplyons•2h ago•2 comments

Pre-Modern Armies for Worldbuilders, Part I: Why They Fight

https://acoup.blog/2026/06/05/collections-pre-modern-armies-for-worldbuilders-part-i-why-they-fight/
106•gostsamo•9h ago•36 comments

Mbodi AI (YC P25) Is Hiring Founding Machine Learning Engineer (Robotics)

https://www.ycombinator.com/companies/mbodi-ai/jobs/WYAcNkX-founding-machine-learning-engineer
1•chitianhao•1h ago

New method turns ocean water into drinking water, without waste

https://www.rochester.edu/newscenter/what-is-desalination-definition-ocean-water-704732/
415•speckx•22h ago•173 comments

Social Cache Busting

https://www.autodidacts.io/social-cache-busting/
68•surprisetalk•4d ago•14 comments

Ask HN: What was your "oh shit" moment with GenAI?

390•andrehacker•1d ago•715 comments

Astronauts told to return to ISS after sheltering over air leak repairs

https://www.bbc.com/news/live/c4g44ew3g1kt
408•janpot•22h ago•252 comments

pg_durable: Microsoft open sources in-database durable execution

https://github.com/microsoft/pg_durable
419•coffeemug•21h ago•93 comments

Do women’s mate preferences change across the ovulatory cycle? (2014) [pdf]

https://www.martiehaselton.com/_files/ugd/3ae410_aeb76edab75f457aae0c14c4c68d93c0.pdf
32•rzk•2h ago•26 comments

Did Claude increase bugs in rsync?

https://alexispurslane.github.io/rsync-analysis/
449•logicprog•1d ago•458 comments

The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy

https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscrap...
93•nikcub•4h ago•21 comments

Gemma 4 QAT models: Optimizing compression for mobile and laptop efficiency

https://blog.google/innovation-and-ai/technology/developers-tools/quantization-aware-training-gem...
364•theanonymousone•20h ago•110 comments

HISE – Toolkit for building VST plugins

https://hise.dev
10•hyperific•2d ago•1 comments

Mouseless – keyboard-driven control of macOS/Linux/Windows

https://mouseless.click
544•riddley•2d ago•220 comments

Introduction – Rust for Python Programmers

https://microsoft.github.io/RustTraining/python-book/
23•linhns•2h ago•8 comments

Zig Zen Update

https://codeberg.org/ziglang/zig/commit/621844bde551ee1a9b8142d7d146d1fa804247a2
100•tosh•4h ago•35 comments

The back cover of C++: The Language raises questions not answered by front cover

https://devblogs.microsoft.com/oldnewthing/20260605-01/?p=112391
113•paulmooreparks•9h ago•36 comments

Azure Linux Desktop

https://www.boxofcables.dev/azure-linux-desktop-a-build-2026-mashup-of-wslc-winui-reactor-and-azu...
25•haydenbarnes•5h ago•11 comments

Mathematician solves origami donut efficiency challenge with fewest folds

https://phys.org/news/2026-06-mathematician-origami-donut-efficiency-fewest.html
3•pseudolus•4d ago•1 comments

Ten Years of Franz

https://meetfranz.com/blog/ten-years-of-franz
45•tosh•3d ago•25 comments

My Agent Skill for Test-Driven Development

https://www.saturnci.com/my-agent-skill-for-test-driven-development.html
199•laxmena•1d ago•86 comments

Lockdown Mode

https://help.openai.com/en/articles/20001061-lockdown-mode
71•berlianta•9h ago•31 comments

Gov.uk has replaced Stripe with Dutch provider Adyen

https://www.theregister.com/public-sector/2026/06/04/govuk-goes-dutch-on-payments-as-it-dumps-str...
497•toomuchtodo•20h ago•190 comments

Nine Ways to Do Inheritance in Rust, a Language Without Inheritance

https://medium.com/@carlmkadie/nine-ways-to-do-inheritance-in-rust-a-language-without-inheritance...
62•pjmlp•2d ago•13 comments

Conventional Commits encourages focus on the wrong things

https://sumnerevans.com/posts/software-engineering/stop-using-conventional-commits/
331•jsve•21h ago•238 comments