Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. New, by me: Read This Before You Buy That TV Streaming Stick

New, by me: Read This Before You Buy That TV Streaming Stick

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
68 Indlæg 49 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchange
    wrote sidst redigeret af
    #1

    New, by me: Read This Before You Buy That TV Streaming Stick

    Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

    https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

    adamshostack@infosec.exchangeA tessarakt@mastodon.socialT timo21@mastodon.sdf.orgT cbleslie@hachyderm.ioC briankrebs@infosec.exchangeB 30 Replies Last reply
    1
    0
    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

      New, by me: Read This Before You Buy That TV Streaming Stick

      Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

      https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

      adamshostack@infosec.exchangeA This user is from outside of this forum
      adamshostack@infosec.exchangeA This user is from outside of this forum
      adamshostack@infosec.exchange
      wrote sidst redigeret af
      #2

      @briankrebs So you're saying there's pros and cons? 😇

      briankrebs@infosec.exchangeB gary_alderson@infosec.exchangeG drwho@masto.hackers.townD mo@mastodon.mlM bithive@social.tchncs.deB 6 Replies Last reply
      0
      • adamshostack@infosec.exchangeA adamshostack@infosec.exchange

        @briankrebs So you're saying there's pros and cons? 😇

        briankrebs@infosec.exchangeB This user is from outside of this forum
        briankrebs@infosec.exchangeB This user is from outside of this forum
        briankrebs@infosec.exchange
        wrote sidst redigeret af
        #3

        @adamshostack well, you probably do get to watch some shows without paying.

        adamshostack@infosec.exchangeA 1 Reply Last reply
        0
        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

          @adamshostack well, you probably do get to watch some shows without paying.

          adamshostack@infosec.exchangeA This user is from outside of this forum
          adamshostack@infosec.exchangeA This user is from outside of this forum
          adamshostack@infosec.exchange
          wrote sidst redigeret af
          #4

          @briankrebs I meant feeding junk into the advertising/surveillance stream.

          maya_b@hachyderm.ioM n_dimension@infosec.exchangeN 2 Replies Last reply
          0
          • adamshostack@infosec.exchangeA adamshostack@infosec.exchange

            @briankrebs I meant feeding junk into the advertising/surveillance stream.

            maya_b@hachyderm.ioM This user is from outside of this forum
            maya_b@hachyderm.ioM This user is from outside of this forum
            maya_b@hachyderm.io
            wrote sidst redigeret af
            #5

            @adamshostack

            there's an ad "blocking" plugin for FF browsers called adnauseum - it doesn't show you ads but clicks on every link on a page and does the poisoning you speak of.

            @briankrebs

            devnull@mamot.frD pandaninjas@infosec.exchangeP 2 Replies Last reply
            0
            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

              New, by me: Read This Before You Buy That TV Streaming Stick

              Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

              https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

              tessarakt@mastodon.socialT This user is from outside of this forum
              tessarakt@mastodon.socialT This user is from outside of this forum
              tessarakt@mastodon.social
              wrote sidst redigeret af
              #6

              @briankrebs Defrauding advertising networks? That doesn't sound so bad.

              acdha@code4lib.socialA 1 Reply Last reply
              0
              • adamshostack@infosec.exchangeA adamshostack@infosec.exchange

                @briankrebs So you're saying there's pros and cons? 😇

                gary_alderson@infosec.exchangeG This user is from outside of this forum
                gary_alderson@infosec.exchangeG This user is from outside of this forum
                gary_alderson@infosec.exchange
                wrote sidst redigeret af
                #7

                @adamshostack @briankrebs free tv but digital life threatening diseases - can be a fair tradeoff depending on your circumstances

                1 Reply Last reply
                0
                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                  New, by me: Read This Before You Buy That TV Streaming Stick

                  Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                  https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                  timo21@mastodon.sdf.orgT This user is from outside of this forum
                  timo21@mastodon.sdf.orgT This user is from outside of this forum
                  timo21@mastodon.sdf.org
                  wrote sidst redigeret af
                  #8

                  @briankrebs This makes me wonder what Murdoch's intention is in buying ROKU.

                  1 Reply Last reply
                  0
                  • adamshostack@infosec.exchangeA adamshostack@infosec.exchange

                    @briankrebs So you're saying there's pros and cons? 😇

                    drwho@masto.hackers.townD This user is from outside of this forum
                    drwho@masto.hackers.townD This user is from outside of this forum
                    drwho@masto.hackers.town
                    wrote sidst redigeret af
                    #9

                    @adamshostack @briankrebs Depends on how cheap they are and how hackable they are.

                    1 Reply Last reply
                    0
                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                      New, by me: Read This Before You Buy That TV Streaming Stick

                      Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                      https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                      cbleslie@hachyderm.ioC This user is from outside of this forum
                      cbleslie@hachyderm.ioC This user is from outside of this forum
                      cbleslie@hachyderm.io
                      wrote sidst redigeret af
                      #10

                      @briankrebs

                      We desperately need a good opensource streaming Android Rom (distro).

                      Lineage OS has just started work on this sort of thing, but the applicability is narrow. One of the reasons is that most of these devices need "exploits" to get the rom swapped out.

                      Proprietary hardware is annoying. Self repair laws can't come fast enough. 😐

                      1 Reply Last reply
                      0
                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                        New, by me: Read This Before You Buy That TV Streaming Stick

                        Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                        https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                        briankrebs@infosec.exchangeB This user is from outside of this forum
                        briankrebs@infosec.exchangeB This user is from outside of this forum
                        briankrebs@infosec.exchange
                        wrote sidst redigeret af
                        #11

                        A couple of teasers from the story:

                        Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.

                        Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software.

                        According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work.

                        dalias@hachyderm.ioD chuckmcmanis@chaos.socialC 2 Replies Last reply
                        0
                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                          New, by me: Read This Before You Buy That TV Streaming Stick

                          Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                          https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                          justinderrick@infosec.exchangeJ This user is from outside of this forum
                          justinderrick@infosec.exchangeJ This user is from outside of this forum
                          justinderrick@infosec.exchange
                          wrote sidst redigeret af
                          #12

                          @briankrebs To me, it sounds like they’re losing money on each device sale, knowing they can make the money back after the sale (“The secret ingredient is *crime*…”)

                          I wonder if any of these sell at a price point that make a compelling argument for buying them to flash custom firmware for some other purpose.

                          1 Reply Last reply
                          0
                          • maya_b@hachyderm.ioM maya_b@hachyderm.io

                            @adamshostack

                            there's an ad "blocking" plugin for FF browsers called adnauseum - it doesn't show you ads but clicks on every link on a page and does the poisoning you speak of.

                            @briankrebs

                            devnull@mamot.frD This user is from outside of this forum
                            devnull@mamot.frD This user is from outside of this forum
                            devnull@mamot.fr
                            wrote sidst redigeret af
                            #13

                            @maya_b Clicking ads, even if you don't see them, meant encouraging websites owners to put ads because clicked ads generate money and encourage surveillance capitalism, while leaking PII to crapvertising industry. Also, ads network have been spreading malwares and virus for years… Therefore, clicking randomly on ads is dangerous, especially when it's done automagically and massively (higher chance to get malwares)

                            The only safe way to deal with ads is uBlock Origin.

                            @adamshostack @briankrebs

                            radioclash@retro.pizzaR vatvslpr@c.imV 2 Replies Last reply
                            0
                            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                              New, by me: Read This Before You Buy That TV Streaming Stick

                              Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                              https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                              leeloo@c.imL This user is from outside of this forum
                              leeloo@c.imL This user is from outside of this forum
                              leeloo@c.im
                              wrote sidst redigeret af
                              #14

                              @briankrebs
                              I can get behind defrauding advertising networks. 😛

                              1 Reply Last reply
                              0
                              • adamshostack@infosec.exchangeA adamshostack@infosec.exchange

                                @briankrebs So you're saying there's pros and cons? 😇

                                mo@mastodon.mlM This user is from outside of this forum
                                mo@mastodon.mlM This user is from outside of this forum
                                mo@mastodon.ml
                                wrote sidst redigeret af
                                #15

                                @adamshostack yeah, but a cons is, you may be accused of committing a cybercrime someone did through this proxy

                                @briankrebs

                                briankrebs@infosec.exchangeB 1 Reply Last reply
                                0
                                • mo@mastodon.mlM mo@mastodon.ml

                                  @adamshostack yeah, but a cons is, you may be accused of committing a cybercrime someone did through this proxy

                                  @briankrebs

                                  briankrebs@infosec.exchangeB This user is from outside of this forum
                                  briankrebs@infosec.exchangeB This user is from outside of this forum
                                  briankrebs@infosec.exchange
                                  wrote sidst redigeret af
                                  #16

                                  @mo @adamshostack Well, IDK about getting accused, but your device almost certainly will at some point be leased by cybercriminals.

                                  mo@mastodon.mlM 1 Reply Last reply
                                  0
                                  • adamshostack@infosec.exchangeA adamshostack@infosec.exchange

                                    @briankrebs So you're saying there's pros and cons? 😇

                                    bithive@social.tchncs.deB This user is from outside of this forum
                                    bithive@social.tchncs.deB This user is from outside of this forum
                                    bithive@social.tchncs.de
                                    wrote sidst redigeret af
                                    #17

                                    @adamshostack @briankrebs Cons? /s

                                    1 Reply Last reply
                                    0
                                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                      @mo @adamshostack Well, IDK about getting accused, but your device almost certainly will at some point be leased by cybercriminals.

                                      mo@mastodon.mlM This user is from outside of this forum
                                      mo@mastodon.mlM This user is from outside of this forum
                                      mo@mastodon.ml
                                      wrote sidst redigeret af
                                      #18

                                      @briankrebs you 100% would fall under suspicion, because traces would end at your house

                                      and then it depends, if cops want to find a real criminal, or just increase KPI without doing much work

                                      Where I live, I would never trust cops with this

                                      @adamshostack

                                      lukefromdc@kolektiva.socialL 1 Reply Last reply
                                      0
                                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                        New, by me: Read This Before You Buy That TV Streaming Stick

                                        Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

                                        https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/

                                        dalias@hachyderm.ioD This user is from outside of this forum
                                        dalias@hachyderm.ioD This user is from outside of this forum
                                        dalias@hachyderm.io
                                        wrote sidst redigeret af
                                        #19

                                        @briankrebs IOW they rent out your ip address as a residential proxy but they also defraud adtech companies, so who can tell if they're good or bad?

                                        briankrebs@infosec.exchangeB 1 Reply Last reply
                                        0
                                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                          A couple of teasers from the story:

                                          Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.

                                          Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software.

                                          According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work.

                                          dalias@hachyderm.ioD This user is from outside of this forum
                                          dalias@hachyderm.ioD This user is from outside of this forum
                                          dalias@hachyderm.io
                                          wrote sidst redigeret af
                                          #20

                                          @briankrebs Oooh even better! So if you just don't attach them to a TV, they do adtech fraud fulltime! Where do we sign up?

                                          ariadne@social.treehouse.systemsA lanodan@queer.hacktivis.meL 2 Replies Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper