Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. New, by me: Read This Before You Buy That TV Streaming Stick

New, by me: Read This Before You Buy That TV Streaming Stick

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
68 Indlæg 49 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

    New, by me: Read This Before You Buy That TV Streaming Stick

    Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

    https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

    leeloo@c.imL This user is from outside of this forum
    leeloo@c.imL This user is from outside of this forum
    leeloo@c.im
    wrote sidst redigeret af
    #14

    @briankrebs
    I can get behind defrauding advertising networks. 😛

    1 Reply Last reply
    0
    • adamshostack@infosec.exchangeA adamshostack@infosec.exchange

      @briankrebs So you're saying there's pros and cons? 😇

      mo@mastodon.mlM This user is from outside of this forum
      mo@mastodon.mlM This user is from outside of this forum
      mo@mastodon.ml
      wrote sidst redigeret af
      #15

      @adamshostack yeah, but a cons is, you may be accused of committing a cybercrime someone did through this proxy

      @briankrebs

      briankrebs@infosec.exchangeB 1 Reply Last reply
      0
      • mo@mastodon.mlM mo@mastodon.ml

        @adamshostack yeah, but a cons is, you may be accused of committing a cybercrime someone did through this proxy

        @briankrebs

        briankrebs@infosec.exchangeB This user is from outside of this forum
        briankrebs@infosec.exchangeB This user is from outside of this forum
        briankrebs@infosec.exchange
        wrote sidst redigeret af
        #16

        @mo @adamshostack Well, IDK about getting accused, but your device almost certainly will at some point be leased by cybercriminals.

        mo@mastodon.mlM 1 Reply Last reply
        0
        • adamshostack@infosec.exchangeA adamshostack@infosec.exchange

          @briankrebs So you're saying there's pros and cons? 😇

          bithive@social.tchncs.deB This user is from outside of this forum
          bithive@social.tchncs.deB This user is from outside of this forum
          bithive@social.tchncs.de
          wrote sidst redigeret af
          #17

          @adamshostack @briankrebs Cons? /s

          1 Reply Last reply
          0
          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

            @mo @adamshostack Well, IDK about getting accused, but your device almost certainly will at some point be leased by cybercriminals.

            mo@mastodon.mlM This user is from outside of this forum
            mo@mastodon.mlM This user is from outside of this forum
            mo@mastodon.ml
            wrote sidst redigeret af
            #18

            @briankrebs you 100% would fall under suspicion, because traces would end at your house

            and then it depends, if cops want to find a real criminal, or just increase KPI without doing much work

            Where I live, I would never trust cops with this

            @adamshostack

            lukefromdc@kolektiva.socialL 1 Reply Last reply
            0
            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

              New, by me: Read This Before You Buy That TV Streaming Stick

              Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

              https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

              dalias@hachyderm.ioD This user is from outside of this forum
              dalias@hachyderm.ioD This user is from outside of this forum
              dalias@hachyderm.io
              wrote sidst redigeret af
              #19

              @briankrebs IOW they rent out your ip address as a residential proxy but they also defraud adtech companies, so who can tell if they're good or bad?

              briankrebs@infosec.exchangeB 1 Reply Last reply
              0
              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                A couple of teasers from the story:

                Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.

                Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software.

                According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work.

                dalias@hachyderm.ioD This user is from outside of this forum
                dalias@hachyderm.ioD This user is from outside of this forum
                dalias@hachyderm.io
                wrote sidst redigeret af
                #20

                @briankrebs Oooh even better! So if you just don't attach them to a TV, they do adtech fraud fulltime! Where do we sign up?

                ariadne@social.treehouse.systemsA lanodan@queer.hacktivis.meL 2 Replies Last reply
                0
                • dalias@hachyderm.ioD dalias@hachyderm.io

                  @briankrebs Oooh even better! So if you just don't attach them to a TV, they do adtech fraud fulltime! Where do we sign up?

                  ariadne@social.treehouse.systemsA This user is from outside of this forum
                  ariadne@social.treehouse.systemsA This user is from outside of this forum
                  ariadne@social.treehouse.systems
                  wrote sidst redigeret af
                  #21

                  @dalias @briankrebs i'll take 100

                  jernej__s@infosec.exchangeJ 1 Reply Last reply
                  0
                  • dalias@hachyderm.ioD dalias@hachyderm.io

                    @briankrebs IOW they rent out your ip address as a residential proxy but they also defraud adtech companies, so who can tell if they're good or bad?

                    briankrebs@infosec.exchangeB This user is from outside of this forum
                    briankrebs@infosec.exchangeB This user is from outside of this forum
                    briankrebs@infosec.exchange
                    wrote sidst redigeret af
                    #22

                    @dalias it is said you can tell the quality of a tree by its fruit, and by that yardstick the fruit is primarily traffic tied to account takeover attempts, ad fraud, mass content scraping for AI projects, or outright cybercrime.

                    The residential proxy services enabled by these devices are sold and resold under a number of agreements, and some have multiple proxy SDKs funneling traffic. And these devices are a shitshow on security because the underlying hardware has not even basic authentication requirements.

                    1 Reply Last reply
                    0
                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                      New, by me: Read This Before You Buy That TV Streaming Stick

                      Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                      https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                      ag100pct@infosec.exchangeA This user is from outside of this forum
                      ag100pct@infosec.exchangeA This user is from outside of this forum
                      ag100pct@infosec.exchange
                      wrote sidst redigeret af
                      #23

                      @briankrebs
                      Nice article.
                      Just no end to people inventing new products to abuse consumers.

                      1 Reply Last reply
                      0
                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                        New, by me: Read This Before You Buy That TV Streaming Stick

                        Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                        https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                        pattykimura@beige.partyP This user is from outside of this forum
                        pattykimura@beige.partyP This user is from outside of this forum
                        pattykimura@beige.party
                        wrote sidst redigeret af
                        #24

                        @briankrebs

                        Dang it! Sometimes being a procrastinating elderly Luddite does have a silver lining. I still have a mechanical answering machine and a copper wire DC (POTS) landline rotary phone stuck to the kitchen wall. No sticks, no V-mo, no streaming.

                        1 Reply Last reply
                        0
                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                          A couple of teasers from the story:

                          Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.

                          Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software.

                          According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work.

                          chuckmcmanis@chaos.socialC This user is from outside of this forum
                          chuckmcmanis@chaos.socialC This user is from outside of this forum
                          chuckmcmanis@chaos.social
                          wrote sidst redigeret af
                          #25

                          @briankrebs Reminding us once again that ad fraud is the best fraud because the people who could stop it don't because it makes them money too!

                          1 Reply Last reply
                          0
                          • dalias@hachyderm.ioD dalias@hachyderm.io

                            @briankrebs Oooh even better! So if you just don't attach them to a TV, they do adtech fraud fulltime! Where do we sign up?

                            lanodan@queer.hacktivis.meL This user is from outside of this forum
                            lanodan@queer.hacktivis.meL This user is from outside of this forum
                            lanodan@queer.hacktivis.me
                            wrote sidst redigeret af
                            #26
                            @dalias @briankrebs Kind of thing where it could make sense to get one to publish the IPs they're controlling it from, plus any sort of protocol fingerprints.
                            1 Reply Last reply
                            0
                            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                              New, by me: Read This Before You Buy That TV Streaming Stick

                              Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                              https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                              nixcraft@mastodon.socialN This user is from outside of this forum
                              nixcraft@mastodon.socialN This user is from outside of this forum
                              nixcraft@mastodon.social
                              wrote sidst redigeret af
                              #27

                              @briankrebs Nothing good come out this AI generated bullshit while people losing jobs and their work is stolen by AI companies.

                              radioclash@retro.pizzaR 1 Reply Last reply
                              0
                              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                New, by me: Read This Before You Buy That TV Streaming Stick

                                Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                                https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                                johnefrancis@cosocial.caJ This user is from outside of this forum
                                johnefrancis@cosocial.caJ This user is from outside of this forum
                                johnefrancis@cosocial.ca
                                wrote sidst redigeret af
                                #28

                                @briankrebs the clickfraud is a nice feature, but pretty shady overall

                                1 Reply Last reply
                                0
                                • adamshostack@infosec.exchangeA adamshostack@infosec.exchange

                                  @briankrebs So you're saying there's pros and cons? 😇

                                  M This user is from outside of this forum
                                  M This user is from outside of this forum
                                  mweiss@infosec.exchange
                                  wrote sidst redigeret af
                                  #29

                                  @adamshostack @briankrebs yes, it does seem to be an operation run by pro cons.

                                  1 Reply Last reply
                                  0
                                  • tessarakt@mastodon.socialT tessarakt@mastodon.social

                                    @briankrebs Defrauding advertising networks? That doesn't sound so bad.

                                    acdha@code4lib.socialA This user is from outside of this forum
                                    acdha@code4lib.socialA This user is from outside of this forum
                                    acdha@code4lib.social
                                    wrote sidst redigeret af
                                    #30

                                    @tessarakt @briankrebs defrauding ad customers sounds worse: some of those are bottom-feeders selling dreck but almost every small business owner I've heard from has stories about paying for online ads, burning through their budget, and seeing absolutely no impact on sales. No matter how you feel about ads in general, that's not sending money to deserving parties and the ad networks still get their cut.

                                    radioclash@retro.pizzaR 1 Reply Last reply
                                    0
                                    • ariadne@social.treehouse.systemsA ariadne@social.treehouse.systems

                                      @dalias @briankrebs i'll take 100

                                      jernej__s@infosec.exchangeJ This user is from outside of this forum
                                      jernej__s@infosec.exchangeJ This user is from outside of this forum
                                      jernej__s@infosec.exchange
                                      wrote sidst redigeret af
                                      #31

                                      @ariadne @dalias @briankrebs Me, too!

                                      1 Reply Last reply
                                      0
                                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                        New, by me: Read This Before You Buy That TV Streaming Stick

                                        Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                                        https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                                        lukefromdc@kolektiva.socialL This user is from outside of this forum
                                        lukefromdc@kolektiva.socialL This user is from outside of this forum
                                        lukefromdc@kolektiva.social
                                        wrote sidst redigeret af
                                        #32

                                        @briankrebs I love seeing ad supported parasite apps and devices start eating each other. With luck this will lead to corporate execs doing time, getting a small taste of what we would get if we cloned their phones for free service and got caught.

                                        Stuff like this though does make me glad I don't watch TV at all though.

                                        1 Reply Last reply
                                        0
                                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                          New, by me: Read This Before You Buy That TV Streaming Stick

                                          Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                                          https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                                          miff@fedi.miffthefox.infoM This user is from outside of this forum
                                          miff@fedi.miffthefox.infoM This user is from outside of this forum
                                          miff@fedi.miffthefox.info
                                          wrote sidst redigeret af
                                          #33

                                          I wonder if there's any F/OSS firmware you can flash onto a cheap streaming stick like you can do with GrapheneOS for phones or OpenWRT for routers. (Of course, there's always just a PC running Linux.)

                                          jschwart@mas.toJ 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper