Walmart router, others on Amazon, eBay have hidden backdoors to control devices
cybernews.com
cybernews.com
It doesn't make sense to tie the lifespan of a display to the lifespan of software support when the computing hardware is so ubiquitous outside of the TV anyway.
This is a field that cries out "decent regulation". Terrible IoT security? Please see massive fines, Senators on TV claiming national security at risk, never allow that brand to be sold "on our soil" again.
I know there is no obvious technical framework that can be applied as " best practise", that IoT is a horrible wild west and governments choosing winners will lead down sub optimal paths but it's hard to see a real alternative fix.
>The European Telecommunications Standards Institute (ETSI) has released what it calls a globally applicable standard for cybersecurity in the Internet of Things (IoT). The new specification, TS 103645, seeks to establish a security baseline for internet-connected consumer products and provide a basis for future IoT certification schemes. https://futureiot.tech/europe-gets-first-global-consumer-iot...
Maybe if that works other places will follow.
This conversation happens on HN every week, and each time, commenters point out the numerous flaws in this plan:
Manufacturer requiring a firmware update or internet connection for the TV to work, quietly connecting to internet over HDMI, connecting automatically to neighbour's unsecured wifi, shipping with an internal cell modem, and many other methods that might be around the corner as privacy norms drift and certain technologies become cheaper.
Bonus: This way, you don't have to worry about open wifi networks.
I live near a BK, my TV could dl some auto auth for the wifi and just upload my habits... if it wasn't specifically chosen to reduce that probability.
How is it possible that your TV could automatically log into your wifi?
Where I live I can see a few dozen networks active. At any one time at least a few are public.
Is that legal where you are, assuming your neighbour has not granted permission to do it?
AFAIK, violating the CFAA would involve actively circumventing a mechanism intended to restrict access.
My understanding is that lots of them aggressively sniff and try to hop on any unsecured network that they can find.
Don't connect your TV to the internet, buy an Apple TV.
Giving google my viewing habits is bad, but giving Hisense + DodgyAdBroker.biz + CCP/PLA is even worse.
While the advertising / data sharing revenue is valuable to them, the vast majority of those are going into homes where they're going to be internet connected already. The cost of a modem + service fees for it wouldn't be worth it for most of them.
Amazon is starting to ship their Sidewalk protocol[1] which will be embedded into a bunch of their devices - but that seems to be mainly for low-power/remote devices to connect back to a Sidewalk access point, rather than to provide an alternative data-path for (say) customer metrics.
I do not agree with any of that, though.
Consider the beancounters at the manufacturer:
We are shipping a SmartTV, we expect our users to therefore have internet access, because the device is mostly non-working without it.
Why would we then include: a cellular radio AND make us pay for a cellular data service on an ongoing basis? Is the data from some small fraction of users who don't already have wifi valuable enough to pay off the hardware and service costs in every other TV? Seems unlikely.
I think what'll really happen is they'll become always online devices where if you're offline for more than X days they quit working and claim they need an update - please connect to the internet.
Look at how much an ESP32 can do and what it costs.
At scale, the cost of the additional electronics is negligible, especially if it is being subsidized.
Nobody is making you pay for service. It will simply send back fingerprints of your screen image and usage data, and can probably load ads, as well.
You'll note though that getting a Kindle with 3G nowdays means paying for the more expensive models - Paperwhite or Oasis.
> Nobody is making you pay for service
I think you missed what I said. I was talking from the perspective of a manufacturer.
The cost of buying and integration the new hardware, and also an ongoing monthly sim cost for the benefit of getting analytics and ads from a tiny fraction of your userbase that does NOT already have their TV hooked up to wifi is significant, and I doubt it comes close to the added revenue you might get from that fraction of users.
That also assumes that those who don't have their Smart TV hooked up to wifi are going to be in cellular range.
Some of the technologies are specifically intended to give "phone home" connectivity to low-power devices: https://en.wikipedia.org/wiki/Narrowband_IoT https://en.wikipedia.org/wiki/LTE-M
I tend to go with US-based companies because they would legally be liable for damages, which would in theory mean they'd be less likely to knowingly ship malware and security disasters.
I am not sure under what legal basis you draw this conclusion given the EULA's and other laws explicitly shield them from said liability
you would have to prove intentional malicious intent not simply negligence
One of the big problems I have with more US Companies is they are a network of vendor Lock-in proprietary ecosystems that often do not work well together at all.
I prefer Open protocols, which sadly seem to be only adopted by non-US Companies.
Either your devices and hub don't need to be exposed to the net (so why are you even using a router connected to the web?), or they do.
If they do, it's because that's how you control them, via the web. If that's the case, it doesn't matter what network your phone is on; command and control is done via the web.
Now, in terms of infecting each other, sure. But the point is to keep my data devices and such separate from my IoT devices. Yes, the whole IoT infrastructure may get infected and need a purge, but my goal is to keep infection of those from getting, say, my banking information. And yes, it assumes that the command and control app is reasonably secure, but that's a whole different issue (and one reason why I would rely on Amazon or Alexa as a hub, and not some random no name company).
I'm curious if you have suggestions for a hackable home automation/IoT hub that I can use without giving it access to the internet. I'm happy to DIY anything that doesn't deal with mains voltage.
[0]: https://www.home-assistant.io/ [1]: https://hubitat.com/
Homebridge: https://homebridge.io HOOBS: https://hoobs.org
it should be automated, you have controls in the house that trigger actions, ie a door opens, or a light switch is triggers.
If I have to use my phone to control it, I have failed at automation
I have a small arcade in my basement and the ability to control the lights from my phone would be way better than using the wall switch, mostly because of outlet placement and the fact the switch has to stay on.
My living room only has one switched outlet and it is the one closest to the switch. The lights across the room have to be manually controlled.
I've done some research into wifi controlled outlets and I have some very old radio controlled ones but I need more. Do you have any suggestions for hackable wifi plugs that do not connect to the internet? Maybe something that connects to a hub?
My dream would be something where I can make my own sensors and talk over wifi to outlets that are UL listed, without involving the internet. I'm happy to DIY anything that doesn't interact with mains voltage.
Zigbee/Zwave is controlled via Nortek USB interface connected to a rPI
Though I do have a couple of Shelly Devices, and some custom ESP8266 things
With Black Friday/Cyber Monday coming up I’m trying to compile a shopping list of good gear.
Let's say the customer connects their own Wifi router to the ISP modem/router via Ethernet cable. There is no need for the ISP modem/router's Wifi AP. Does the ISP modem/router allow the customer to disable it?
what exactly do you mean? I tought piHole sits "between" the tv and your modem? I mean it probably can easily firewall those ips.
Edit: nvm PiHole is only a dns thingy.
So if say your TV calls out to backdoor.example.com - then PiHole can block it.
If instead it calls out to 1.2.3.4 (i.e no DNS lookup) - then PiHole won't block it for you, you'd have to instead set up controls on the firewall/router/etc to filter traffic.
Wanted: Firewall blocking all traffic directed at IP addresses not obtained from OS DNS resolver.
aka dynamic application level FQDN Egress Filtering. Mayor Cloud providers (aws, azure) and bigger firewalls (fortinet, cisco, paloalto) already offer ~half of what I want.
I want a little deamon that listens for DNS queries/replies and modifies firewall rules accordingly.
So, it could still bypass piHole and still resolve hostnames.
At the router level, I then forced all 8.8.8.8 traffic to be transformed into traffic to my pihole.
You can do the next step, but you need a router that supports it and the patience to handle it.
You shouldn’t need to do this.
So, if it is using HTTPS for DNS resolution, I don’t know how you would block that.
If you could install a self-signed cert onto the device, you could MitM the HTTPS traffic and see what it is doing.
By filtering traffic sent from that particular device based on a query to your DNS filter to approve or deny the destination address. (Some implementation work probably required.)
For example, iOS to Apple, mac to Apple, Win10 to MS, etc. These connections are much difficult to ban nowadays. What we could do might be limiting their upstream connection via physical firewall router with built-in good web-based GUI.
AT&T pushed an update that added an "Application Statistics" page to the router which keeps track of ports and sites visited and is basically hostile to privacy.
thing is - this is a rented router, so what can the customer do?
Also every time they push an update wifi turns itself back on. So I go in and disable it and then I get a giant warning email "AT&T wifi gateway settings updated".
Or someone to create a standard where the Panel is now working more like a Monitor and All electronics are into a separate box.
There's no winning with IoT.
There's no winning when a third party controls the lowest-level software of a thing on the internet. That includes your general purpose computers.
Unless you are the owner of the signing keys down to the bottom of the stack, your system can be remote-controlled.
By a stand-alone Roku for apps?
The top device on my network being blocked from reaching it's mothership are my Roku devices. This is the top analytics from my NextDNS console for the past two weeks:
scribe.logs.roku.com 417,115
stats.gc.apple.com 24,752
ssl.google-analytics.com 16,178
track.sr.roku.com 7,534
Roku is easily on the top of my list on spying devices on my network. The Apple ones, while still worrying, are on a network with tons of Apple devices between phones, MacBooks, watches, iPads, etc whereas there are three Roku's making all that traffic.
Apple TV is what you want if you don’t want to have your data/viewing habits sold to outside companies.
YouTube or Netflix or whatever can still do whatever they want with your 'viewing habits'.
(When I say slammed I mostly mean "pay big fines", maybe jail time if the flaw was known, and it should result in real reputational damage to Wal-Mart and its willingness to sell anything with a network connected computer in it. At the very least, if the buy cost is even less than the china price, that difference is coming from somewhere. Wal Mart should have spotted that.)
As far as I can tell, that's the company who imported and sold it. If Amazon and Walmart are liable, I won't need to worry about fake Sandisk memory cards, fake medicines, fake clothing, and other fake products there.
I'd love that.
Maybe I just had a really bad 6 months with Amazon, but it seems everything that comes is a fake or a scam.
I'd gladly pay 10% more for real products than 10% less for 50-50. Right now, I switched to mostly buying off-brands direct from China for a lot of products, since I get the same thing as Amazon, but at a lower price and with an honest label.
Or buying direct from manufacturers if I want something real.
I got screwed once doing even that, though. I ordered a brand-name headset. They did... fulfillment by Amazon. The headset is barely usable, so I'm assuming Amazon did commingled products. Or perhaps I got a defective copy. In either case, not worth fighting for 50 bucks.
Contact your state's AG, they usually have a consumer protection office that handles complaints like this.
Fake and flawed (a vulnerability) are not in the same category. The first is fraud, the second is just standard flaws in the product.
What is the industry-accepted, “will pass muster by a judge and jury”, level of due diligence that is considered minimally acceptable when purchasing Internet-connected devices from a supplier for resale to consumers?
The current answer as I understand is, simply, “no level of due diligence is expected with regards to network functionality, as the relevant UL/CE standards for ‘networking’ only concern themselves with RF interference at most”.
Should all computer resellers of any business size, whether Walmart nationwide or PC Hand-Me-Downs in a single city, be required to hire specialists to disassemble device firmwares for auditing purposes? Should this burden be placed on importers? Is this even legal under the DMCA?
Should the UL certification be found at fault here, since clearly they did not audit nor certify the device’s preinstalled firmware?
Walmart keeps on getting caught selling unethically produced goods. We need stronger laws to punish them when that happens. It doesn't seem to be enough to allow them to self govern.
Ditto for the likes of Amazon.
I can come up with examples of unethical production, I doubt I could come up with a solid definition of unethical which covers all definitions of an unethically produced good.
For now, it's easy enough to say "Goods produced by slave and child labor". From there, I think it is healthy to expand the law and regulations to capture missed or current unethical production practices. For example, production which produces a lot of CO2. Or production which pollutes the local environment. You could even go so far as saying "production where anyone in a company is making more than 10x anyone else".
Some may disagree with my examples of what are unethical. Which is fine. I think there are sections, though, that nobody should disagree with (and if you do, you're a monster).
Michael Hayden: "We Kill People Based on Metadata"
Yes, Walmart should be slammed for this. It's the Walmart's responsibility to protect its customers by sourcing secure electronics--especially when they're advertising the router as a Walmart exclusive. They're explicitly aligning themselves with the vendor.
But Walmart won't be slammed for this. Because the people who buy cheap routers from Walmart typically aren't the most tech savvy bunch.
You’re not realistically patching Windows without Microsoft’s cooperation.
Meanwhile, the router both A) Comes with an OS that you may or may not be able to patch, and B) You may or may not be able to replace it with something you can.
Consumers buying cheap shite is also a problem.
It's really just a symptom of the race-to-the-bottom that Wal-Mart has been strongly championing for a couple decades. Everything must be manufactured in China at the lowest BOM cost possible. And, of course, it's us consumers that fuel this race.
So for example, if you buy a defective helmet for your kid from Walmart, the kid gets into an accident, and the kid dies, you sue Walmart for damages commensurate to the death of the child. For the router, you have to show the compromise that resulted from the vulnerability and the damages that ensued. If there was no compromise and just the potential for compromise the damages may be quite limited.
So Walmart might have some good faith defenses and it might be challenging to show enough damages.
There may also be some fines that the FTC could levy related to this because of the deceptive trade practices associated with selling a fatally defective product that could pose serious risks to privacy.
But where do they get...
> This backdoor would allow an attacker the ability to remotely control not only the routers, but also any devices connected to that network.
How do you gain "control" of a device (presumably a PC) merely by having access to the router it is connected to? Is it just that we're assuming that a typical home network will be a soft target of PC's? What about windows defender firewall, and all that stuff?(Personally, the best way to accomplish that goal in would be to require the owner to install an app to complete the router installation. The old, unpatched Android phones Wal-Mart shoppers use are generally easy to exploit I imagine. Although I expect that your app could ask for total control over the phone and all data sources, and people will just answer yes because they want their thing to work, and Wal Mart wouldn't sell it if it wasn't safe.)
In short, once the remote has gained access to your internal network, many types of attacks become possible.
Wow, Microsoft added TLS to RDP way back in Windows Vista (cite: I worked on it), and they apparently still don't have it required by default, based on some blog posts I see from 2019 explaining how to force it on. That's shameful.
Since you seem to be an expert on this, can you explain how exactly it's implemented? When connecting to a remote machine, the sequence of events goes something like this:
1. enter ip, click "connect"
2. login prompt shows up
3. enter username/password, click "ok"
4. self signed certificate warning shows up, asks me to accept/reject the certificate
5. after accepting the certificate, the connection succeeds and I can see the other machine.
This sequence of events makes me think that the password authentication step isn't done over TLS at all, or is done over TLS but is vulnerable to MITM attacks. Can you confirm/deny whether this is accurate?
One could, for example, deny all windows updates... then just wait for patch day and a new live exploit...
Another thing is one could deny access to something you want to harm, such as walmart.com or whatever (in favor of ali baba)
With so much poorly supported “smart” devices on the market, a great deal of your life is easily compromised once somebody is inside your network.
There’s no great promise that your PC is secure unless you’re rather well brushed up on security best practices.
ARP spoofing, DNS spoofing, UPnP...
People flock to "free" services and give away all their data to do so.
People buy "cheap" printers, and sign up for extortionate ink programs to do so.
We have a car maker to "takes back" software options sold when the car was new on re-sale of that car.
No we have people buying "cheap" Wi-Fi routers which are subsidized by their ability to be used by third parties for nefarious purposes.
Caveat Emptor only goes so far. The ability to fleece people through technology has been known and exploited for a long time, I wonder if we will ever see a consensus backlash against it.
"WiFi routers always seem to make you sacrifice something, don't they?
You're either paying for speed and spending an ungodly amount of money, or opting for the budget pick and waiting forever for things to load.
You shouldn't have to make that choice. One bright spot on the WiFi landscape could come from an unlikely place: Walmart. The big box store is gearing up to save you money and headaches by launching a line of store-exclusive routers that minimize cost and maximize performance."
The cheap end were $35.
If you just want a simple 2.4Ghz access point for a typical 60mbit dsl you could probably get away with something like https://mikrotik.com/product/RB931-2nD for $20.
Obviously supports all the essentials you need from a home router (dhcp servers, natting, ospf+bgp, various vpns, etc), as well as things like mpls and vpls capability.
This is key. The general public has a very basic understanding of tech generally and even less about what can be done with their data.
You're assuming a) that the router is subsidized, and b) that the flaws are intentional. Neither are necessary, and neither make a lot of sense (why add a backdoor that anyone can exploit?)
It makes way more sense to consider this just another poorly made budget product. Same as anything else where sticker price is all that matters.
Free services win because everyone can start using it and depending on it in 5 minutes, instead of having to pay for and download a comparable product, or worse, maintain an OSS alternative on a home server. The only time a consumer chooses to pay for something is when it's as entrenched into their minds as MS Office is, or when their employer/school demands it (also MS Office).
HP's ink is so successful since you can now just have it show up at your door when you're low on ink instead of having to make a trip to best buy. The extortionate price of unit-sold cartridges is only extra motivation.
And Tesla is only big because they have an appealing product; if other car manufacturers could offer the same (EV) range, software experience, and minimalistic design, they'd blow Tesla out of the water with superior service and build quality.
Now this cheap Wi-Fi router isn't something people are buying because it's comparatively better or offers some features, it's just a cheap Chinese wifi router that some corporate Wal-Mart manager decided to stock since it would be high-margin and, as far as they know, offered basic wifi functionality. Your argument would work for any other (high end) router like Nest WiFi, Netgear, etc.
Now I'm a free market kind of guy and don't mind that people make such TVs and that some people choose to buy them over ones that don't do this. But I am saddened by the ability of this larger chunk of market to eliminate the option of a TV that isn't smart and doesn't do this. I have no idea how to fix that or even put pressure on it from happening.
The article seems to imply this is a malicious tool, but it seems more likely to me that this is just another poorly designed router instead.
That original research only looked at one Wavlink router. This is the extended research with the help of two other researchers. And of course the attempted exploit from a malicious IP address which was detected only recently
This comment I'm replying to, though... you don't need to do this. If it had been the only reply you posted, I would have come away from our exchange with a very different opinion of you, and that would've been a bit unfair. Just something to think about for the future.
There's no mention if this is vulnerable to XSS which is the more interesting issue.
Not to knock the researcher's work too much, but what he did was what people installing OpenWRT on devices have been doing for 15 years, and what he found is pretty typical. Except for the password in JS. That was just weird.
>So what does that get us from the perspective of a remote attacker? We have the ability to get the current admin credentials, and we can get a shell if the telnet binary is started. However, most remote attackers wont be able to solder on any wires, so I wasn’t going to stop there.
>Going through the rest of the pages in the www directory, there is another web page that provides this interface:
So you don't need telnet, but the creds being on the page + knowledge of the system command page would be enough to do whatever you wanted.
Also see this follow-up research page on the same devices:
https://james-clee.com/2020/04/23/more-information-disclosur...
>Just a reminder – every screenshot below is of a web page that is externally accessible without requiring authentication and contains sensitive data.
But who is "you" here? Are you assuming the attacker needs to be physically present on your network? can any malicious script running on browser's victim make an xhr request to "192.168.0.1/page-which-exposes-password"?
> a remote attacker can achieve RCE via a POST request to adm.cgi. There are several conditions required, including proper parameters and an active session. However, these conditions can all be met without any initial authentication required thanks to several specific exposed “live_(string).shtml” endpoints – so an attacker with the right background information about the device could achieve RCE fairly easily.
Anyway, back then, a lot of these devices had really bad security. Some where so bad that you could do an XSS attack that gains root access to someone's router. Someone could definitely have intentionally added a backdoor, but I agree that it's pretty likely that developers working on a router with the goal of being cheap were lazy, rushed, or just didn't care, and left development backdoor open, allowed admin access on LAN and WAN, or something else.
[1] https://cybernews.com/security/walmart-exclusive-routers-oth...
"The Jetstream and Wavlink routers showcase a simple GUI (or user-friendly interface) for its backdoors that is different from the interface presented to router admins."
I won't buy home networking equipment if I can't put OpenWRT on it.
That one might be better updated than others - but if it is, they don't seem to update the version number making tracking difficult, a lot of the vendors will stop providing updates to old devices. The other problem is that if you have a Mediatek, Broadcom, Ralink, Hisilicon vulnerability (all have their own kernel forks and driver forks) then every device downstream using that kernel or driver is vulnerable, and not all devices will get fixed. Even if the vendor or upstream fixes it, who upgrades their router firmware?
>Low and behold, there was my super secret password in plain text, with the admin username in plain text, on a page that requires no authentication of any kind to view.
It is so fucking dumb that there is no other explanation other than an intentional backdoor. If anyone quotes Occam's Razor, you've been asleep for the past 5 years or so.
This researcher isn't doing anything that complicated to find this page, and the page needs no authentication at all so it's not restricted to e.g. authentication via a secret that's held by the manufacturer.
If you want to make a backdoor, at least put some effort into it. This doesn't have the features I'd expect in a good backdoor.
Can someone explain what we get by assuming the Chinese are just so inept at technology (they aren't) that we give them the benefit of the doubt that this is a naive mistake here?
The incentives for quality code here are incredibly weak, and the incentives for caring about security are basically zero. What damage does this vulnerability cause to Jetstream as a brand? It's not like they're going to lose many sales from people who read tech news sites.
If you need to get something working at the cheapest price point possible, you cut all the corners you can - especially in the ways that don't manifest until outside the return period. Paying senior developers and doing external code audits are luxuries you can't really afford.
Just look at IoT crap produced around the world. Are they inept, or is security an after thought?
On other hand I believe that companies like Huawei are capable of very special things just like western counterparts.
Hardware manufacturers in general have a pretty poor reputation for security & software engineering, Chinese or otherwise. It’s not like Cisco has been vulnerability free.
You probably mean Hanlon's Razor¹, which has been used so much it no longer cuts².
Maybe you have more faith in developers than I do because this sounds exactly like a dumb mistake/cutting corners to me.
In the CVE, it details the call it executes to retrieve the password from nvram.
It is a hard problem to solve. It is of advantage to China to flood US and European markets with cheap AND insecure hardware.
Someone would have to try hard to make a case that that is not the case.
Not sure what to recommend for non tech-savvy users though. The overwhelming majority of routers in the market that are targeted to consumers are hot garbage. Some TP-Link models? Maybe... Google(if are ok with your most important device being from them)? Are Linksys still good? My last one was a WRT54G. It was ok out of the box, pretty good with custom firmware (that takes it outside the end-user territory once again).
The configuration after a reset/as shipped (at least on all my old models) is a local network at 192.168.88.0/24 with NAT and DHCP set up, wireless enabled and bridged to lan, etc.
Only time it's going to get a bit dicey is if they want to customize the configuration (e.g., forward ports). But for 90% of people that's not going to be an issue.
For instance, I wanted working NAT reflection and since my external IPv4 address is dynamic I wanted to construct a static ruleset that didn't specifically reference it. The solution there required me to exclude traffic destined for my LAN address range in my dnat forwarding rules to get it working properly. Fun stuff.
The app that comes with Asus router is littered with button which if you accidentally click will make you accept EULA.
The story explains that the companies in question have access to RPC functions similar to those that an ISP might use but that they are not ISPs. Then later on the article states that one of the companies described itself as an ISP.
The story also questions why there is a GUI for running remote commands and why a device would need to scan for nearby networks. I can think of a few legitimate reasons for both but no reason a decent backdoor would have a server side backdoor GUI.
Just my opinion but I get the feeling this whole situation was created by IP theft in the form of firmware duplication. It seems these companies have used a very insecure firmware possibly made intentionally bad to trap or setup these Chinese manufacturers.
If these are in fact intentional backdoors they were made with an incredible amount of effort to look like sloppy 0day exploits.
I should add that I don't doubt that these vulnerabilities are real, just the intent behind them.
If I was having my products manufactured in China, I might provide a similar bad firmware for the factory too, then patch the devices before providing them to my customers to prevent IP theft.
Normally, one should not attribute to malice what can simply be attributed to stupidity or probably laziness here.
Even then, however, it's a bit too suspicious though. Of course, we asked the manufacturers behind these devices for comment and -- surprise! -- no comment. In past experience with Chinese vendors, we've had similar results.
Of course, we'll update with any information we get.
Thanks for reading!
Having thought about this story for a while now, I also think it is worth investigation, I might purchase an extender off Amazon.
The one part of the story I can't reconcile is how the Chinese IP attacker managed to find the device. I doubt this could have occured just from random port scanning so there must be a call home, possibly by loading a hidden image on the "Backdoor GUI"?
The story was well written, just not sure it made me thristy enough to drink the koolaid...or maybe it did! :P
[0]: https://isc.sans.edu/forums/diary/An+Update+On+DVR+Malware+A...
And there were no devices attached to it and nor anyone use any of these sites.
I was really concerned at this in time what other that it might be doing I'm not even aware of.
> Basically, the first IP address you see there – 222.141.xx.xxx, which comes from China – was trying to upload a malicious file on the router using the vulnerabilities.
Since when does a router respond to the whole world on port 80 by default?
I've also heard that products such as TV's are usually lower quality compared to sold elsewhere; usually the manufacturer creates a model speficially for walmart, using lower quality parts, display panels which don't pass QA and are binned, SoC's which may have issues, etc
I started watching the video, but it just looks like self-congratulatory nonsense.
Sounds shady when whoever's making it is apparently distancing themselves from their own product.
China is not our friend.
China is not our friend... I hope that by repeating this often enough and loud enough that peoples, politicians, and companies will get the hint.
Government sponsored, or not, it doesn't matter. The anti-world behavior exhibited by China and its populace clearly shows they are not a friend to anyone by themselves.
Trade with China should be reconsidered on a global scale.