Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. New, by me: Read This Before You Buy That TV Streaming Stick

New, by me: Read This Before You Buy That TV Streaming Stick

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
68 Indlæg 49 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • maya_b@hachyderm.ioM maya_b@hachyderm.io

    @adamshostack

    there's an ad "blocking" plugin for FF browsers called adnauseum - it doesn't show you ads but clicks on every link on a page and does the poisoning you speak of.

    @briankrebs

    pandaninjas@infosec.exchangeP This user is from outside of this forum
    pandaninjas@infosec.exchangeP This user is from outside of this forum
    pandaninjas@infosec.exchange
    wrote sidst redigeret af
    #48

    @maya_b @adamshostack @briankrebs Ad Nauseam doesn't actually cost the advertisers any money, and it probably doesn't end up poisoning the data, because it sends a single AJAX request to the ad networks. Most ad networks ignore clicks where the browser didn't stay on the page for seconds.

    1 Reply Last reply
    0
    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

      New, by me: Read This Before You Buy That TV Streaming Stick

      Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

      https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

      h0ru2@cyberplace.socialH This user is from outside of this forum
      h0ru2@cyberplace.socialH This user is from outside of this forum
      h0ru2@cyberplace.social
      wrote sidst redigeret af
      #49

      @briankrebs Darknet Diaries had an episode on such a device, I think called Superbox. It was wild, it kicked other devices off the network and tried to take their place. Owners were trying to isolate or secure them, so they could keep using these things instead of throwing them out.

      1 Reply Last reply
      0
      • radioclash@retro.pizzaR radioclash@retro.pizza

        @acdha @tessarakt @briankrebs click fraud is endemic in the industry. if they are foolish enough to pay for CPC without researching it, after many many scandals including the ad networks (Google!) getting caught ripping folks off...

        ...then I really don't feel sad for them.

        acdha@code4lib.socialA This user is from outside of this forum
        acdha@code4lib.socialA This user is from outside of this forum
        acdha@code4lib.social
        wrote sidst redigeret af
        #50

        @radioclash @tessarakt @briankrebs I mean, many of them learn not to but that still doesn't change the fact that someone who's good at making coffee or giving haircuts mistakenly thought that a much larger company was selling what they claimed to be selling. We shouldn't celebrate market failures.

        1 Reply Last reply
        0
        • adamshostack@infosec.exchangeA adamshostack@infosec.exchange

          @briankrebs I meant feeding junk into the advertising/surveillance stream.

          n_dimension@infosec.exchangeN This user is from outside of this forum
          n_dimension@infosec.exchangeN This user is from outside of this forum
          n_dimension@infosec.exchange
          wrote sidst redigeret af
          #51

          @adamshostack @briankrebs

          As a small business owner we tried online advertising. Hundreds of dollars down the toilet.
          Not a single sale.

          1 Reply Last reply
          0
          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

            New, by me: Read This Before You Buy That TV Streaming Stick

            Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

            https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

            felix@mastodon.nzF This user is from outside of this forum
            felix@mastodon.nzF This user is from outside of this forum
            felix@mastodon.nz
            wrote sidst redigeret af
            #52

            @briankrebs thanks for this Brian, I really do enjoy your work

            1 Reply Last reply
            0
            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

              New, by me: Read This Before You Buy That TV Streaming Stick

              Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

              https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

              S This user is from outside of this forum
              S This user is from outside of this forum
              shadsterling@mastodon.social
              wrote sidst redigeret af
              #53

              @briankrebs I only vaguely remember, but several years ago I was reading about the possibility of TV sticks getting power from the TV’s HDMI port… I think I found that there was a spec for it but few devices supported it. If that had caught on this abuse would be harder, but maybe that’s why it didn’t. (Instead we have “smart TVs” that have the abuse built in!)

              1 Reply Last reply
              0
              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                New, by me: Read This Before You Buy That TV Streaming Stick

                Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                worik@mastodon.socialW This user is from outside of this forum
                worik@mastodon.socialW This user is from outside of this forum
                worik@mastodon.social
                wrote sidst redigeret af
                #54

                @briankrebs One of the fabulous side effects of the "AI" boom is the decay of the ad supported web

                Counting eyeballs is, was and always will be an awful metric

                1 Reply Last reply
                0
                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                  New, by me: Read This Before You Buy That TV Streaming Stick

                  Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                  https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                  pressure@surf.socialP This user is from outside of this forum
                  pressure@surf.socialP This user is from outside of this forum
                  pressure@surf.social
                  wrote sidst redigeret af
                  #55

                  @briankrebs

                  Did you guys see Jalen Milroe had his first really good practice?

                  1 Reply Last reply
                  0
                  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                    New, by me: Read This Before You Buy That TV Streaming Stick

                    Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                    https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                    w_hurless@mastodon.socialW This user is from outside of this forum
                    w_hurless@mastodon.socialW This user is from outside of this forum
                    w_hurless@mastodon.social
                    wrote sidst redigeret af
                    #56

                    @briankrebs A long time ago, around 2010, I would get a Android TV box, flash the firmware to something better, and then install a bunch of emulators, they worked great for a low cost emulation device.

                    1 Reply Last reply
                    0
                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                      New, by me: Read This Before You Buy That TV Streaming Stick

                      Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                      https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                      garlickles@infosec.exchangeG This user is from outside of this forum
                      garlickles@infosec.exchangeG This user is from outside of this forum
                      garlickles@infosec.exchange
                      wrote sidst redigeret af
                      #57

                      @briankrebs I linked this article to a family member, who finally became convinced to take it off his network. Thanks for writing this.

                      1 Reply Last reply
                      0
                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                        New, by me: Read This Before You Buy That TV Streaming Stick

                        Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                        https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                        bbbhltz@framapiaf.orgB This user is from outside of this forum
                        bbbhltz@framapiaf.orgB This user is from outside of this forum
                        bbbhltz@framapiaf.org
                        wrote sidst redigeret af
                        #58

                        @briankrebs My father-in-law uses things like this. He talks about them like they're amazing things. But the thing he bought charges a yearly fee and asked for ID too, so they have his banking info, address, passport, etc. He doesn't understand why I wouldn't want one...

                        1 Reply Last reply
                        0
                        • raymaccarthy@mastodon.ieR This user is from outside of this forum
                          raymaccarthy@mastodon.ieR This user is from outside of this forum
                          raymaccarthy@mastodon.ie
                          wrote sidst redigeret af
                          #59

                          @dryak @briankrebs
                          It's not like formatting a storage device. Or even like installing OpenWRT on a router. These may have locked or custom bootloaders. See variable difficulty of replacing ChromeOS.
                          I simply would never buy such a device and probably not the branded Amazon, Google etc varieties. It may be less convenient, but I'd use a laptop or PC. Some may use a Raspberry Pi, but I find a 10 year old laptop more functional.

                          I never connect TV WiFi or Ethernet for similar reasons.

                          1 Reply Last reply
                          0
                          • miff@fedi.miffthefox.infoM miff@fedi.miffthefox.info

                            I wonder if there's any F/OSS firmware you can flash onto a cheap streaming stick like you can do with GrapheneOS for phones or OpenWRT for routers. (Of course, there's always just a PC running Linux.)

                            jschwart@mas.toJ This user is from outside of this forum
                            jschwart@mas.toJ This user is from outside of this forum
                            jschwart@mas.to
                            wrote sidst redigeret af
                            #60

                            @miff @briankrebs on some of these boxes you can run Armbian. If an official build doesn't work, in the forum there are some unofficial builds for specific TV boxes. (They are not the intended target.)

                            Funny thing that the article mentions Google, but it's software is essentially malware as well and had best be disabled on Android devices. The only trustworthy source for applications on Android is F-Droid.

                            Also note that these boxes themselves are also used by legitimate TV services. The specifics is in the software and you can likely find a way to remove the malware if you happen to have an affected box. If that malware is tied to some illegitimate TV application, you'd possibly lose access to that service. Generally these boxes are simply cheap and won't be affected, but you're always taking a risk when any proprietary software is involved.

                            1 Reply Last reply
                            0
                            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                              New, by me: Read This Before You Buy That TV Streaming Stick

                              Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                              https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                              S This user is from outside of this forum
                              S This user is from outside of this forum
                              salvo@mastodon.social
                              wrote sidst redigeret af
                              #61

                              @briankrebs
                              ❌using people’s internet connections for fraud
                              ✅causing the collapse of the “Internet Advertising” industry

                              1 Reply Last reply
                              0
                              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                New, by me: Read This Before You Buy That TV Streaming Stick

                                Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                                https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                                glaskows@mastodon.gamedev.placeG This user is from outside of this forum
                                glaskows@mastodon.gamedev.placeG This user is from outside of this forum
                                glaskows@mastodon.gamedev.place
                                wrote sidst redigeret af
                                #62

                                @briankrebs If those can be rooted they could be a pretty nice Linux SBC.

                                amilatled@snac.la10cy.netA 1 Reply Last reply
                                0
                                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                  New, by me: Read This Before You Buy That TV Streaming Stick

                                  Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                                  https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                                  A This user is from outside of this forum
                                  A This user is from outside of this forum
                                  avincentinspace@furry.engineer
                                  wrote sidst redigeret af
                                  #63

                                  @briankrebs If you want unlimited access to content without recurring fees, there are only two ways.

                                  Buy physical media, or torrent.

                                  Neither are particularly hard.

                                  1 Reply Last reply
                                  0
                                  • mo@mastodon.mlM mo@mastodon.ml

                                    @briankrebs you 100% would fall under suspicion, because traces would end at your house

                                    and then it depends, if cops want to find a real criminal, or just increase KPI without doing much work

                                    Where I live, I would never trust cops with this

                                    @adamshostack

                                    lukefromdc@kolektiva.socialL This user is from outside of this forum
                                    lukefromdc@kolektiva.socialL This user is from outside of this forum
                                    lukefromdc@kolektiva.social
                                    wrote sidst redigeret af
                                    #64

                                    @mo @briankrebs @adamshostack Remember this: You do NOT fall into one of the widely known cases such as "tor exit node" or "open public wifi." If someone accesses CSAM through your TV and especially if you were previously unaware of this, you could sit in jail unable to post a huge bond until some investigator thinks to check out your TV. If that doesn't happen, you may even get convicted of CSAM you had nothing to do with.

                                    1 Reply Last reply
                                    0
                                    • glaskows@mastodon.gamedev.placeG glaskows@mastodon.gamedev.place

                                      @briankrebs If those can be rooted they could be a pretty nice Linux SBC.

                                      amilatled@snac.la10cy.netA This user is from outside of this forum
                                      amilatled@snac.la10cy.netA This user is from outside of this forum
                                      amilatled@snac.la10cy.net
                                      wrote sidst redigeret af
                                      #65
                                      @armbian@fosstodon.org has many community builds for SoC's used in those tv boxes (https://github.com/armbian/community/releases). My two boxes from 6-7 years ago with a quad AMLogic S905W and 2GB RAM are still running just fine with latest armbian 🙂 Speed for those is comparable to a RPI3

                                      CC: @briankrebs@infosec.exchange
                                      1 Reply Last reply
                                      0
                                      • radioclash@retro.pizzaR radioclash@retro.pizza

                                        @maya_b @devnull @adamshostack @briankrebs

                                        I have thoight about doing that, but wonder about lag?

                                        Sadly my router atm isn't OpenWRT but I think it can be? But I've not dared try to flash it. But I think you can do stuff like that on there if you do.

                                        lumiworx@mastodon.socialL This user is from outside of this forum
                                        lumiworx@mastodon.socialL This user is from outside of this forum
                                        lumiworx@mastodon.social
                                        wrote sidst redigeret af
                                        #66

                                        @radioclash @maya_b @devnull @adamshostack @briankrebs

                                        I've been using #Technitium for years now on a linux box and point it to Quad9 as the upstream DNS. I don't often get to say this, but so far it keeps happily doing its thing in the background with no muss or fuss.

                                        I watch the dashboard to check the stats and to watch for occasional updates, but it absolutely does the job it was designed for. 4 Million+ sites in blocklists, scheduled to auto update every 2 hours... & zero lag.

                                        1 Reply Last reply
                                        0
                                        • devnull@mamot.frD devnull@mamot.fr

                                          @maya_b Clicking ads, even if you don't see them, meant encouraging websites owners to put ads because clicked ads generate money and encourage surveillance capitalism, while leaking PII to crapvertising industry. Also, ads network have been spreading malwares and virus for years… Therefore, clicking randomly on ads is dangerous, especially when it's done automagically and massively (higher chance to get malwares)

                                          The only safe way to deal with ads is uBlock Origin.

                                          @adamshostack @briankrebs

                                          vatvslpr@c.imV This user is from outside of this forum
                                          vatvslpr@c.imV This user is from outside of this forum
                                          vatvslpr@c.im
                                          wrote sidst redigeret af
                                          #67

                                          @devnull @maya_b @adamshostack @briankrebs
                                          I've had excellent results with Privacy Badger from EFF. It technically blocks trackers rather than ads, but it's very rare to encounter an ad that doesn't track you these days.

                                          devnull@mamot.frD 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper