Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold. They certainly don't advertise to the big box retailer that buys them "and it uses the customer's internet connection for fraud."
Hell, there's a section of comments that would probably going "hey, RELAX guy" because it's not US companies doing this. For any American companies that do this though, sure - block/suspend/prosecute.
If I open my own line of home improvement stores and do no oversight on what I sell and wind up selling really dangerous lawnmowers, I'm partly responsible.
Or if I open up a gas station and allow any company without oversight to sell "supplements" through my shelves and cops arrest me for selling heroin, I don't get a free pass.
Why should amazon or Walmart get a free pass just because they sell more items?
One problem I see with your analogy is that the dangerous lawnmower can cause an easily quantifiable harm.
You have to be able to show damages you incurred and assign a dollar value to them to sue people.
That doesn’t work at all for a something that sells your bandwidth to a proxy service. People wouldn’t even be aware that it was happening they weren’t told.
What about when the police show up because some highly illegal content was traced to your IP address? Will they believe that you were the unwitting victim of a rogue proxy server running on your streaming stick? Would you have even been aware of that possibility?
There's also always the flip side: When the police shows up because of your illegal acitivities, you have a rogue proxy server running. All bought in good faith of course.
Not legal advice.
(It would surprise me greatly if we as a society let these gadgets be sold openly from here on.)
Except the devices are not dangerous. Its the software installed on the device. Consumers have a choice. Pay for the trusted Apple TV or Amazon firestick, or go the wild west and see what's on offer.
with the devices mentioned in the article, there is no consent requested, and the malicious apps are installed either before the box is sold or after as a requirement for getting the streaming services to work.
> Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold.
You already answered it: block it from being sold.
1) Make Amazon responsible for the products they are selling. 2) Introduce a law banning malware tv sticks 3) Sue Amazon for a percentage of their yearly revenue when caught violating it 4) Amazon will finally start caring and do some kind of review on the crap they sell.
If it's malware, maybe existing laws apply already. I think the bigger problem is enforcement. In China, it's easy to close up shop if anything goes wrong and then just start over. Any liability dies with the brand name.
And if the first time you get it online it just updates itself to malware?
That's the biggest problem with any device that updates.
Yea, this will work for the moment and the seller will be covered in the sense that "well, it wasn't infected when we sold it".
But it is a retailer's responsibility to know what they are selling. If it was added after they started selling it and hidden in secret, sure a retailer might have an excuse. But it isn't really hidden, most often its put in their marketing materials as a benefit and have been knowingly doing it for many years now.
US retailers can be told they can't sell it here. If you buy it outside of that, well that is buyer beware, but 99% of people aren't buying things from Alibaba or ordering from some random foreign store, they are buying them off US Amazon, Walmart, big box retailers, etc. You don't have to ban things consumer level to deal with 99% of it, you just gotta tell big corporations no and stop dismissing any ideas that put responsibility or liability on big business.
The problem is that Amazon, Walmart & friends have said the "we are a platform, not a retailer" magic incantation, which means that through the power of friendship and unicorns they are now suddenly no longer responsible for the stuff they sell.
And the "retailer" on record is of course not a real company. They'll just pay some third-party to file a bunch of paperwork in Delaware, pay the $110 fee, and let it go bust if anyone tries to investigate it or make it liable.
>If it was added after they started selling it
While it's great we're getting the manufactures to just stop sending out straight malware and it should be stopped the next most obvious means of attack is just having the device update and add superaids to it's new functionality.
So, no, it won't stop 99% of it at all.
And honestly this isn't that much different from what US companies are already great at by providing updates that take away features we bought with the device.
And not just updating really doesn't save you, instead of being part of a factory botnet, you're just open to become part of some other botnet.