New, by me: Read This Before You Buy That TV Streaming Stick
-
@radioclash @devnull @adamshostack @briankrebs
I actually use private sinkhole blocking DNS on my LAN so neither ublock or adnauseum actually have much to do.
I also use cookie auto delete plugin and anything that isn't whitelisted has their cookies deleted pretty much once the page is closed. Plus container browsing - so I only use their services in their isolated browser container.
I basically never see ads and when I see them on other people's machines I'm amazed they can used the web like that.
@maya_b @devnull @adamshostack @briankrebs I used to use Cookie but I think it's expired now - so need to look at other ways. The fact it kept weirdly failing and deleting the wrong whitelisted cookies was a faff though. But it's a good thing.
I do have some of that stuff - Privacy Badger, Ublock Origin with lots of cookie nuisance and extra lists, and adblocking via my VPN which I usually use- but the latter causes some very weird problems.
That said I rarely see ads, only on Twitch streams or sometimes YouTube....stream ads are harder to block.
-
@maya_b @devnull @adamshostack @briankrebs I used to use Cookie but I think it's expired now - so need to look at other ways. The fact it kept weirdly failing and deleting the wrong whitelisted cookies was a faff though. But it's a good thing.
I do have some of that stuff - Privacy Badger, Ublock Origin with lots of cookie nuisance and extra lists, and adblocking via my VPN which I usually use- but the latter causes some very weird problems.
That said I rarely see ads, only on Twitch streams or sometimes YouTube....stream ads are harder to block.
Yea I have a pihole DNS server, but also trying out technitium DNS as well - both seem pretty solid and making sure nothing gets through.
technitium is also a recursive DNS server that goes all the way back to the main nameserver for a site and doesn't just cache the nearest server it finds up the chain.
so instead of letting google or cloudflare (8.8.8.8 or 1.1.1.1 respectively) know where you're going, you can hide that extra bit of information as well
-
@tessarakt @briankrebs defrauding ad customers sounds worse: some of those are bottom-feeders selling dreck but almost every small business owner I've heard from has stories about paying for online ads, burning through their budget, and seeing absolutely no impact on sales. No matter how you feel about ads in general, that's not sending money to deserving parties and the ad networks still get their cut.
@acdha @tessarakt @briankrebs click fraud is endemic in the industry. if they are foolish enough to pay for CPC without researching it, after many many scandals including the ad networks (Google!) getting caught ripping folks off...
...then I really don't feel sad for them.
-
Yea I have a pihole DNS server, but also trying out technitium DNS as well - both seem pretty solid and making sure nothing gets through.
technitium is also a recursive DNS server that goes all the way back to the main nameserver for a site and doesn't just cache the nearest server it finds up the chain.
so instead of letting google or cloudflare (8.8.8.8 or 1.1.1.1 respectively) know where you're going, you can hide that extra bit of information as well
@maya_b @devnull @adamshostack @briankrebs
I have thoight about doing that, but wonder about lag?
Sadly my router atm isn't OpenWRT but I think it can be? But I've not dared try to flash it. But I think you can do stuff like that on there if you do.
-
@maya_b @devnull @adamshostack @briankrebs
I have thoight about doing that, but wonder about lag?
Sadly my router atm isn't OpenWRT but I think it can be? But I've not dared try to flash it. But I think you can do stuff like that on there if you do.
the initial first lookups take a fraction of a second, after that, they're instant as their local and on your lan.
you can also install it on a raspberry pi device (Pi-hole was designed with the rPi in mind) and just point your devices to that as the DNS.
depending on your router you can probably also specify the dns devices in your dhcp settings so down stream devices will get it automatically once you've set it all up.
-
there's an ad "blocking" plugin for FF browsers called adnauseum - it doesn't show you ads but clicks on every link on a page and does the poisoning you speak of.
@maya_b @adamshostack @briankrebs Ad Nauseam doesn't actually cost the advertisers any money, and it probably doesn't end up poisoning the data, because it sends a single AJAX request to the ad networks. Most ad networks ignore clicks where the browser didn't stay on the page for seconds.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs Darknet Diaries had an episode on such a device, I think called Superbox. It was wild, it kicked other devices off the network and tried to take their place. Owners were trying to isolate or secure them, so they could keep using these things instead of throwing them out.
-
@acdha @tessarakt @briankrebs click fraud is endemic in the industry. if they are foolish enough to pay for CPC without researching it, after many many scandals including the ad networks (Google!) getting caught ripping folks off...
...then I really don't feel sad for them.
@radioclash @tessarakt @briankrebs I mean, many of them learn not to but that still doesn't change the fact that someone who's good at making coffee or giving haircuts mistakenly thought that a much larger company was selling what they claimed to be selling. We shouldn't celebrate market failures.
-
@briankrebs I meant feeding junk into the advertising/surveillance stream.
As a small business owner we tried online advertising. Hundreds of dollars down the toilet.
Not a single sale. -
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs thanks for this Brian, I really do enjoy your work
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs I only vaguely remember, but several years ago I was reading about the possibility of TV sticks getting power from the TV’s HDMI port… I think I found that there was a spec for it but few devices supported it. If that had caught on this abuse would be harder, but maybe that’s why it didn’t. (Instead we have “smart TVs” that have the abuse built in!)
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs One of the fabulous side effects of the "AI" boom is the decay of the ad supported web
Counting eyeballs is, was and always will be an awful metric
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
Did you guys see Jalen Milroe had his first really good practice?
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs A long time ago, around 2010, I would get a Android TV box, flash the firmware to something better, and then install a bunch of emulators, they worked great for a low cost emulation device.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs I linked this article to a family member, who finally became convinced to take it off his network. Thanks for writing this.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs My father-in-law uses things like this. He talks about them like they're amazing things. But the thing he bought charges a yearly fee and asked for ID too, so they have his banking info, address, passport, etc. He doesn't understand why I wouldn't want one...
-
@dryak @briankrebs
It's not like formatting a storage device. Or even like installing OpenWRT on a router. These may have locked or custom bootloaders. See variable difficulty of replacing ChromeOS.
I simply would never buy such a device and probably not the branded Amazon, Google etc varieties. It may be less convenient, but I'd use a laptop or PC. Some may use a Raspberry Pi, but I find a 10 year old laptop more functional.I never connect TV WiFi or Ethernet for similar reasons.
-
I wonder if there's any F/OSS firmware you can flash onto a cheap streaming stick like you can do with GrapheneOS for phones or OpenWRT for routers. (Of course, there's always just a PC running Linux.)
@miff @briankrebs on some of these boxes you can run Armbian. If an official build doesn't work, in the forum there are some unofficial builds for specific TV boxes. (They are not the intended target.)
Funny thing that the article mentions Google, but it's software is essentially malware as well and had best be disabled on Android devices. The only trustworthy source for applications on Android is F-Droid.
Also note that these boxes themselves are also used by legitimate TV services. The specifics is in the software and you can likely find a way to remove the malware if you happen to have an affected box. If that malware is tied to some illegitimate TV application, you'd possibly lose access to that service. Generally these boxes are simply cheap and won't be affected, but you're always taking a risk when any proprietary software is involved.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs
using people’s internet connections for fraud
causing the collapse of the “Internet Advertising” industry -
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs If those can be rooted they could be a pretty nice Linux SBC.