New, by me: Read This Before You Buy That TV Streaming Stick
-
@dalias @briankrebs i'll take 100
@ariadne @dalias @briankrebs Me, too!
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs I love seeing ad supported parasite apps and devices start eating each other. With luck this will lead to corporate execs doing time, getting a small taste of what we would get if we cloned their phones for free service and got caught.
Stuff like this though does make me glad I don't watch TV at all though.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
I wonder if there's any F/OSS firmware you can flash onto a cheap streaming stick like you can do with GrapheneOS for phones or OpenWRT for routers. (Of course, there's always just a PC running Linux.)
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs Brian, My in-laws'


swear by it.
I told em, they don't care as long as they can watch
Grace and Frankie, The Great British Baking Show, and The Crown 4 free.

-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs We used a "real" FireStick but I still don't trust it. Makes me really glad that our whole TV/stereo setup is on a switched outlet and stays off when not in use.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs "ad fraud" is just botnets fighting one another, change my mind -
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs so I get to watch free movies *and* it autonomously fucks with the ad ecosystem *and* I get free plausible deniability for when something fishy happens in my network? ngl that doesn't actually sound that bad

-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs you mean the AI generated traffic and websites clicks on the AI generated ads for AI generated products no-one really wants?
Can anyone hear a tiny violin playing somewhere?
But yes, these are dodgy cos of the DDOS and hacking botnets they bolster. Real cybercrime unlike ad fraud.
But I aint crying about Google losing revenue...or really most online merchants. They are mostly all shady IME.
(I used to work in the online ad industry so know my way around Doubleclick et al. And the morals and ethics of that industry are corrupt at best).
-
@maya_b Clicking ads, even if you don't see them, meant encouraging websites owners to put ads because clicked ads generate money and encourage surveillance capitalism, while leaking PII to crapvertising industry. Also, ads network have been spreading malwares and virus for years… Therefore, clicking randomly on ads is dangerous, especially when it's done automagically and massively (higher chance to get malwares)
The only safe way to deal with ads is uBlock Origin.
@devnull @maya_b @adamshostack @briankrebs
This is the way. I was using Ublock back to when I was working in online advertising! Embarassing sometimes when the client was wondering why the advert wasn't showing and it was my blocking plugin...
...but can confirm, industry is shady af. Block EVERYTHING.
-
@briankrebs Nothing good come out this AI generated bullshit while people losing jobs and their work is stolen by AI companies.
@nixCraft @briankrebs I dunno, I used to work in that industry and I say AI robot master overlords, please completely annhilate it.
I am pro creative, pro artist, anti-AI - but the online ad industry was one of the most shady, toxic, unethical and soul-destroying jobs as a freelance creative.
Some industries SHOULD be burned to the ground. SEO is one, that's another.
-
@tanavit @leeloo @briankrebs no not really, they pay a certain CPC (cost per click), according to the campaign, it just means the campaign will tank but they don't pay more than what they've allocated.
It just maybe reduces the company's reach - which depends what it is, might be a good thing.
Coca Cola, McD's and other companies supporting Israel or junk food/products etc - good. Waste their money. They are evil.
Smaller companies less good, but I'd guess they'd target the bigger accounts cos it wouldn't be worth setting up for a small campaign.
The company will allocate a certain ad spend then use it up, regardless. So I don't think prices will go up. They might go down actually as they try to attract more people if their advertising fails. More people doesn't necessarily mean lower prices. Usually the opposite, more people means trying to increase profit margins, rather than reduce prices at scale.
Capitalism!
Source: used to work in online advertising.
-
@devnull @maya_b @adamshostack @briankrebs
This is the way. I was using Ublock back to when I was working in online advertising! Embarassing sometimes when the client was wondering why the advert wasn't showing and it was my blocking plugin...
...but can confirm, industry is shady af. Block EVERYTHING.
@radioclash @devnull @adamshostack @briankrebs
I actually use private sinkhole blocking DNS on my LAN so neither ublock or adnauseum actually have much to do.
I also use cookie auto delete plugin and anything that isn't whitelisted has their cookies deleted pretty much once the page is closed. Plus container browsing - so I only use their services in their isolated browser container.
I basically never see ads and when I see them on other people's machines I'm amazed they can used the web like that.
-
@radioclash @devnull @adamshostack @briankrebs
I actually use private sinkhole blocking DNS on my LAN so neither ublock or adnauseum actually have much to do.
I also use cookie auto delete plugin and anything that isn't whitelisted has their cookies deleted pretty much once the page is closed. Plus container browsing - so I only use their services in their isolated browser container.
I basically never see ads and when I see them on other people's machines I'm amazed they can used the web like that.
@maya_b @devnull @adamshostack @briankrebs I used to use Cookie but I think it's expired now - so need to look at other ways. The fact it kept weirdly failing and deleting the wrong whitelisted cookies was a faff though. But it's a good thing.
I do have some of that stuff - Privacy Badger, Ublock Origin with lots of cookie nuisance and extra lists, and adblocking via my VPN which I usually use- but the latter causes some very weird problems.
That said I rarely see ads, only on Twitch streams or sometimes YouTube....stream ads are harder to block.
-
@maya_b @devnull @adamshostack @briankrebs I used to use Cookie but I think it's expired now - so need to look at other ways. The fact it kept weirdly failing and deleting the wrong whitelisted cookies was a faff though. But it's a good thing.
I do have some of that stuff - Privacy Badger, Ublock Origin with lots of cookie nuisance and extra lists, and adblocking via my VPN which I usually use- but the latter causes some very weird problems.
That said I rarely see ads, only on Twitch streams or sometimes YouTube....stream ads are harder to block.
Yea I have a pihole DNS server, but also trying out technitium DNS as well - both seem pretty solid and making sure nothing gets through.
technitium is also a recursive DNS server that goes all the way back to the main nameserver for a site and doesn't just cache the nearest server it finds up the chain.
so instead of letting google or cloudflare (8.8.8.8 or 1.1.1.1 respectively) know where you're going, you can hide that extra bit of information as well
-
@tessarakt @briankrebs defrauding ad customers sounds worse: some of those are bottom-feeders selling dreck but almost every small business owner I've heard from has stories about paying for online ads, burning through their budget, and seeing absolutely no impact on sales. No matter how you feel about ads in general, that's not sending money to deserving parties and the ad networks still get their cut.
@acdha @tessarakt @briankrebs click fraud is endemic in the industry. if they are foolish enough to pay for CPC without researching it, after many many scandals including the ad networks (Google!) getting caught ripping folks off...
...then I really don't feel sad for them.
-
Yea I have a pihole DNS server, but also trying out technitium DNS as well - both seem pretty solid and making sure nothing gets through.
technitium is also a recursive DNS server that goes all the way back to the main nameserver for a site and doesn't just cache the nearest server it finds up the chain.
so instead of letting google or cloudflare (8.8.8.8 or 1.1.1.1 respectively) know where you're going, you can hide that extra bit of information as well
@maya_b @devnull @adamshostack @briankrebs
I have thoight about doing that, but wonder about lag?
Sadly my router atm isn't OpenWRT but I think it can be? But I've not dared try to flash it. But I think you can do stuff like that on there if you do.
-
@maya_b @devnull @adamshostack @briankrebs
I have thoight about doing that, but wonder about lag?
Sadly my router atm isn't OpenWRT but I think it can be? But I've not dared try to flash it. But I think you can do stuff like that on there if you do.
the initial first lookups take a fraction of a second, after that, they're instant as their local and on your lan.
you can also install it on a raspberry pi device (Pi-hole was designed with the rPi in mind) and just point your devices to that as the DNS.
depending on your router you can probably also specify the dns devices in your dhcp settings so down stream devices will get it automatically once you've set it all up.
-
there's an ad "blocking" plugin for FF browsers called adnauseum - it doesn't show you ads but clicks on every link on a page and does the poisoning you speak of.
@maya_b @adamshostack @briankrebs Ad Nauseam doesn't actually cost the advertisers any money, and it probably doesn't end up poisoning the data, because it sends a single AJAX request to the ad networks. Most ad networks ignore clicks where the browser didn't stay on the page for seconds.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs Darknet Diaries had an episode on such a device, I think called Superbox. It was wild, it kicked other devices off the network and tried to take their place. Owners were trying to isolate or secure them, so they could keep using these things instead of throwing them out.
-
@acdha @tessarakt @briankrebs click fraud is endemic in the industry. if they are foolish enough to pay for CPC without researching it, after many many scandals including the ad networks (Google!) getting caught ripping folks off...
...then I really don't feel sad for them.
@radioclash @tessarakt @briankrebs I mean, many of them learn not to but that still doesn't change the fact that someone who's good at making coffee or giving haircuts mistakenly thought that a much larger company was selling what they claimed to be selling. We shouldn't celebrate market failures.