Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. New, by me: Read This Before You Buy That TV Streaming Stick

New, by me: Read This Before You Buy That TV Streaming Stick

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
68 Indlæg 49 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

    New, by me: Read This Before You Buy That TV Streaming Stick

    Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

    https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

    pattykimura@beige.partyP This user is from outside of this forum
    pattykimura@beige.partyP This user is from outside of this forum
    pattykimura@beige.party
    wrote sidst redigeret af
    #24

    @briankrebs

    Dang it! Sometimes being a procrastinating elderly Luddite does have a silver lining. I still have a mechanical answering machine and a copper wire DC (POTS) landline rotary phone stuck to the kitchen wall. No sticks, no V-mo, no streaming.

    1 Reply Last reply
    0
    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

      A couple of teasers from the story:

      Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.

      Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software.

      According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work.

      chuckmcmanis@chaos.socialC This user is from outside of this forum
      chuckmcmanis@chaos.socialC This user is from outside of this forum
      chuckmcmanis@chaos.social
      wrote sidst redigeret af
      #25

      @briankrebs Reminding us once again that ad fraud is the best fraud because the people who could stop it don't because it makes them money too!

      1 Reply Last reply
      0
      • dalias@hachyderm.ioD dalias@hachyderm.io

        @briankrebs Oooh even better! So if you just don't attach them to a TV, they do adtech fraud fulltime! Where do we sign up?

        lanodan@queer.hacktivis.meL This user is from outside of this forum
        lanodan@queer.hacktivis.meL This user is from outside of this forum
        lanodan@queer.hacktivis.me
        wrote sidst redigeret af
        #26
        @dalias @briankrebs Kind of thing where it could make sense to get one to publish the IPs they're controlling it from, plus any sort of protocol fingerprints.
        1 Reply Last reply
        0
        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

          New, by me: Read This Before You Buy That TV Streaming Stick

          Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

          https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

          nixcraft@mastodon.socialN This user is from outside of this forum
          nixcraft@mastodon.socialN This user is from outside of this forum
          nixcraft@mastodon.social
          wrote sidst redigeret af
          #27

          @briankrebs Nothing good come out this AI generated bullshit while people losing jobs and their work is stolen by AI companies.

          radioclash@retro.pizzaR 1 Reply Last reply
          0
          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

            New, by me: Read This Before You Buy That TV Streaming Stick

            Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

            https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

            johnefrancis@cosocial.caJ This user is from outside of this forum
            johnefrancis@cosocial.caJ This user is from outside of this forum
            johnefrancis@cosocial.ca
            wrote sidst redigeret af
            #28

            @briankrebs the clickfraud is a nice feature, but pretty shady overall

            1 Reply Last reply
            0
            • adamshostack@infosec.exchangeA adamshostack@infosec.exchange

              @briankrebs So you're saying there's pros and cons? 😇

              M This user is from outside of this forum
              M This user is from outside of this forum
              mweiss@infosec.exchange
              wrote sidst redigeret af
              #29

              @adamshostack @briankrebs yes, it does seem to be an operation run by pro cons.

              1 Reply Last reply
              0
              • tessarakt@mastodon.socialT tessarakt@mastodon.social

                @briankrebs Defrauding advertising networks? That doesn't sound so bad.

                acdha@code4lib.socialA This user is from outside of this forum
                acdha@code4lib.socialA This user is from outside of this forum
                acdha@code4lib.social
                wrote sidst redigeret af
                #30

                @tessarakt @briankrebs defrauding ad customers sounds worse: some of those are bottom-feeders selling dreck but almost every small business owner I've heard from has stories about paying for online ads, burning through their budget, and seeing absolutely no impact on sales. No matter how you feel about ads in general, that's not sending money to deserving parties and the ad networks still get their cut.

                radioclash@retro.pizzaR 1 Reply Last reply
                0
                • ariadne@social.treehouse.systemsA ariadne@social.treehouse.systems

                  @dalias @briankrebs i'll take 100

                  jernej__s@infosec.exchangeJ This user is from outside of this forum
                  jernej__s@infosec.exchangeJ This user is from outside of this forum
                  jernej__s@infosec.exchange
                  wrote sidst redigeret af
                  #31

                  @ariadne @dalias @briankrebs Me, too!

                  1 Reply Last reply
                  0
                  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                    New, by me: Read This Before You Buy That TV Streaming Stick

                    Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                    https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                    lukefromdc@kolektiva.socialL This user is from outside of this forum
                    lukefromdc@kolektiva.socialL This user is from outside of this forum
                    lukefromdc@kolektiva.social
                    wrote sidst redigeret af
                    #32

                    @briankrebs I love seeing ad supported parasite apps and devices start eating each other. With luck this will lead to corporate execs doing time, getting a small taste of what we would get if we cloned their phones for free service and got caught.

                    Stuff like this though does make me glad I don't watch TV at all though.

                    1 Reply Last reply
                    0
                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                      New, by me: Read This Before You Buy That TV Streaming Stick

                      Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                      https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                      miff@fedi.miffthefox.infoM This user is from outside of this forum
                      miff@fedi.miffthefox.infoM This user is from outside of this forum
                      miff@fedi.miffthefox.info
                      wrote sidst redigeret af
                      #33

                      I wonder if there's any F/OSS firmware you can flash onto a cheap streaming stick like you can do with GrapheneOS for phones or OpenWRT for routers. (Of course, there's always just a PC running Linux.)

                      jschwart@mas.toJ 1 Reply Last reply
                      0
                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                        New, by me: Read This Before You Buy That TV Streaming Stick

                        Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                        https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                        tycoontom@infosec.exchangeT This user is from outside of this forum
                        tycoontom@infosec.exchangeT This user is from outside of this forum
                        tycoontom@infosec.exchange
                        wrote sidst redigeret af
                        #34

                        @briankrebs Brian, My in-laws' 👴🏼 👵🏼 swear by it.🤷🏼 I told em, they don't care as long as they can watch📺 Grace and Frankie, The Great British Baking Show, and The Crown 4 free.🤦🏼

                        1 Reply Last reply
                        0
                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                          New, by me: Read This Before You Buy That TV Streaming Stick

                          Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                          https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                          chertridge@beige.partyC This user is from outside of this forum
                          chertridge@beige.partyC This user is from outside of this forum
                          chertridge@beige.party
                          wrote sidst redigeret af
                          #35

                          @briankrebs We used a "real" FireStick but I still don't trust it. Makes me really glad that our whole TV/stereo setup is on a switched outlet and stays off when not in use.

                          1 Reply Last reply
                          0
                          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                            New, by me: Read This Before You Buy That TV Streaming Stick

                            Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                            https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                            rairii@labyrinth.zoneR This user is from outside of this forum
                            rairii@labyrinth.zoneR This user is from outside of this forum
                            rairii@labyrinth.zone
                            wrote sidst redigeret af
                            #36
                            @briankrebs "ad fraud" is just botnets fighting one another, change my mind
                            1 Reply Last reply
                            0
                            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                              New, by me: Read This Before You Buy That TV Streaming Stick

                              Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                              https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                              jaseg@chaos.socialJ This user is from outside of this forum
                              jaseg@chaos.socialJ This user is from outside of this forum
                              jaseg@chaos.social
                              wrote sidst redigeret af
                              #37

                              @briankrebs so I get to watch free movies *and* it autonomously fucks with the ad ecosystem *and* I get free plausible deniability for when something fishy happens in my network? ngl that doesn't actually sound that bad 🤣

                              1 Reply Last reply
                              0
                              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                New, by me: Read This Before You Buy That TV Streaming Stick

                                Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                                https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                                radioclash@retro.pizzaR This user is from outside of this forum
                                radioclash@retro.pizzaR This user is from outside of this forum
                                radioclash@retro.pizza
                                wrote sidst redigeret af
                                #38

                                @briankrebs you mean the AI generated traffic and websites clicks on the AI generated ads for AI generated products no-one really wants?

                                Can anyone hear a tiny violin playing somewhere?

                                But yes, these are dodgy cos of the DDOS and hacking botnets they bolster. Real cybercrime unlike ad fraud.

                                But I aint crying about Google losing revenue...or really most online merchants. They are mostly all shady IME.

                                (I used to work in the online ad industry so know my way around Doubleclick et al. And the morals and ethics of that industry are corrupt at best).

                                1 Reply Last reply
                                0
                                • devnull@mamot.frD devnull@mamot.fr

                                  @maya_b Clicking ads, even if you don't see them, meant encouraging websites owners to put ads because clicked ads generate money and encourage surveillance capitalism, while leaking PII to crapvertising industry. Also, ads network have been spreading malwares and virus for years… Therefore, clicking randomly on ads is dangerous, especially when it's done automagically and massively (higher chance to get malwares)

                                  The only safe way to deal with ads is uBlock Origin.

                                  @adamshostack @briankrebs

                                  radioclash@retro.pizzaR This user is from outside of this forum
                                  radioclash@retro.pizzaR This user is from outside of this forum
                                  radioclash@retro.pizza
                                  wrote sidst redigeret af
                                  #39

                                  @devnull @maya_b @adamshostack @briankrebs

                                  This is the way. I was using Ublock back to when I was working in online advertising! Embarassing sometimes when the client was wondering why the advert wasn't showing and it was my blocking plugin...

                                  ...but can confirm, industry is shady af. Block EVERYTHING.

                                  maya_b@hachyderm.ioM 1 Reply Last reply
                                  0
                                  • nixcraft@mastodon.socialN nixcraft@mastodon.social

                                    @briankrebs Nothing good come out this AI generated bullshit while people losing jobs and their work is stolen by AI companies.

                                    radioclash@retro.pizzaR This user is from outside of this forum
                                    radioclash@retro.pizzaR This user is from outside of this forum
                                    radioclash@retro.pizza
                                    wrote sidst redigeret af
                                    #40

                                    @nixCraft @briankrebs I dunno, I used to work in that industry and I say AI robot master overlords, please completely annhilate it.

                                    I am pro creative, pro artist, anti-AI - but the online ad industry was one of the most shady, toxic, unethical and soul-destroying jobs as a freelance creative.

                                    Some industries SHOULD be burned to the ground. SEO is one, that's another.

                                    1 Reply Last reply
                                    0
                                    • radioclash@retro.pizzaR This user is from outside of this forum
                                      radioclash@retro.pizzaR This user is from outside of this forum
                                      radioclash@retro.pizza
                                      wrote sidst redigeret af
                                      #41

                                      @tanavit @leeloo @briankrebs no not really, they pay a certain CPC (cost per click), according to the campaign, it just means the campaign will tank but they don't pay more than what they've allocated.

                                      It just maybe reduces the company's reach - which depends what it is, might be a good thing.

                                      Coca Cola, McD's and other companies supporting Israel or junk food/products etc - good. Waste their money. They are evil.

                                      Smaller companies less good, but I'd guess they'd target the bigger accounts cos it wouldn't be worth setting up for a small campaign.

                                      The company will allocate a certain ad spend then use it up, regardless. So I don't think prices will go up. They might go down actually as they try to attract more people if their advertising fails. More people doesn't necessarily mean lower prices. Usually the opposite, more people means trying to increase profit margins, rather than reduce prices at scale.

                                      Capitalism!

                                      Source: used to work in online advertising.

                                      1 Reply Last reply
                                      0
                                      • radioclash@retro.pizzaR radioclash@retro.pizza

                                        @devnull @maya_b @adamshostack @briankrebs

                                        This is the way. I was using Ublock back to when I was working in online advertising! Embarassing sometimes when the client was wondering why the advert wasn't showing and it was my blocking plugin...

                                        ...but can confirm, industry is shady af. Block EVERYTHING.

                                        maya_b@hachyderm.ioM This user is from outside of this forum
                                        maya_b@hachyderm.ioM This user is from outside of this forum
                                        maya_b@hachyderm.io
                                        wrote sidst redigeret af
                                        #42

                                        @radioclash @devnull @adamshostack @briankrebs

                                        I actually use private sinkhole blocking DNS on my LAN so neither ublock or adnauseum actually have much to do.

                                        I also use cookie auto delete plugin and anything that isn't whitelisted has their cookies deleted pretty much once the page is closed. Plus container browsing - so I only use their services in their isolated browser container.

                                        I basically never see ads and when I see them on other people's machines I'm amazed they can used the web like that.

                                        radioclash@retro.pizzaR 1 Reply Last reply
                                        0
                                        • maya_b@hachyderm.ioM maya_b@hachyderm.io

                                          @radioclash @devnull @adamshostack @briankrebs

                                          I actually use private sinkhole blocking DNS on my LAN so neither ublock or adnauseum actually have much to do.

                                          I also use cookie auto delete plugin and anything that isn't whitelisted has their cookies deleted pretty much once the page is closed. Plus container browsing - so I only use their services in their isolated browser container.

                                          I basically never see ads and when I see them on other people's machines I'm amazed they can used the web like that.

                                          radioclash@retro.pizzaR This user is from outside of this forum
                                          radioclash@retro.pizzaR This user is from outside of this forum
                                          radioclash@retro.pizza
                                          wrote sidst redigeret af
                                          #43

                                          @maya_b @devnull @adamshostack @briankrebs I used to use Cookie but I think it's expired now - so need to look at other ways. The fact it kept weirdly failing and deleting the wrong whitelisted cookies was a faff though. But it's a good thing.

                                          I do have some of that stuff - Privacy Badger, Ublock Origin with lots of cookie nuisance and extra lists, and adblocking via my VPN which I usually use- but the latter causes some very weird problems.

                                          That said I rarely see ads, only on Twitch streams or sometimes YouTube....stream ads are harder to block.

                                          maya_b@hachyderm.ioM 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper