New, by me: Read This Before You Buy That TV Streaming Stick
-
Yea I have a pihole DNS server, but also trying out technitium DNS as well - both seem pretty solid and making sure nothing gets through.
technitium is also a recursive DNS server that goes all the way back to the main nameserver for a site and doesn't just cache the nearest server it finds up the chain.
so instead of letting google or cloudflare (8.8.8.8 or 1.1.1.1 respectively) know where you're going, you can hide that extra bit of information as well
@maya_b @devnull @adamshostack @briankrebs
I have thoight about doing that, but wonder about lag?
Sadly my router atm isn't OpenWRT but I think it can be? But I've not dared try to flash it. But I think you can do stuff like that on there if you do.
-
@maya_b @devnull @adamshostack @briankrebs
I have thoight about doing that, but wonder about lag?
Sadly my router atm isn't OpenWRT but I think it can be? But I've not dared try to flash it. But I think you can do stuff like that on there if you do.
the initial first lookups take a fraction of a second, after that, they're instant as their local and on your lan.
you can also install it on a raspberry pi device (Pi-hole was designed with the rPi in mind) and just point your devices to that as the DNS.
depending on your router you can probably also specify the dns devices in your dhcp settings so down stream devices will get it automatically once you've set it all up.
-
there's an ad "blocking" plugin for FF browsers called adnauseum - it doesn't show you ads but clicks on every link on a page and does the poisoning you speak of.
@maya_b @adamshostack @briankrebs Ad Nauseam doesn't actually cost the advertisers any money, and it probably doesn't end up poisoning the data, because it sends a single AJAX request to the ad networks. Most ad networks ignore clicks where the browser didn't stay on the page for seconds.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs Darknet Diaries had an episode on such a device, I think called Superbox. It was wild, it kicked other devices off the network and tried to take their place. Owners were trying to isolate or secure them, so they could keep using these things instead of throwing them out.
-
@acdha @tessarakt @briankrebs click fraud is endemic in the industry. if they are foolish enough to pay for CPC without researching it, after many many scandals including the ad networks (Google!) getting caught ripping folks off...
...then I really don't feel sad for them.
@radioclash @tessarakt @briankrebs I mean, many of them learn not to but that still doesn't change the fact that someone who's good at making coffee or giving haircuts mistakenly thought that a much larger company was selling what they claimed to be selling. We shouldn't celebrate market failures.
-
@briankrebs I meant feeding junk into the advertising/surveillance stream.
As a small business owner we tried online advertising. Hundreds of dollars down the toilet.
Not a single sale. -
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs thanks for this Brian, I really do enjoy your work
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs I only vaguely remember, but several years ago I was reading about the possibility of TV sticks getting power from the TV’s HDMI port… I think I found that there was a spec for it but few devices supported it. If that had caught on this abuse would be harder, but maybe that’s why it didn’t. (Instead we have “smart TVs” that have the abuse built in!)
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs One of the fabulous side effects of the "AI" boom is the decay of the ad supported web
Counting eyeballs is, was and always will be an awful metric
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
Did you guys see Jalen Milroe had his first really good practice?
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs A long time ago, around 2010, I would get a Android TV box, flash the firmware to something better, and then install a bunch of emulators, they worked great for a low cost emulation device.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs I linked this article to a family member, who finally became convinced to take it off his network. Thanks for writing this.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs My father-in-law uses things like this. He talks about them like they're amazing things. But the thing he bought charges a yearly fee and asked for ID too, so they have his banking info, address, passport, etc. He doesn't understand why I wouldn't want one...
-
@dryak @briankrebs
It's not like formatting a storage device. Or even like installing OpenWRT on a router. These may have locked or custom bootloaders. See variable difficulty of replacing ChromeOS.
I simply would never buy such a device and probably not the branded Amazon, Google etc varieties. It may be less convenient, but I'd use a laptop or PC. Some may use a Raspberry Pi, but I find a 10 year old laptop more functional.I never connect TV WiFi or Ethernet for similar reasons.
-
I wonder if there's any F/OSS firmware you can flash onto a cheap streaming stick like you can do with GrapheneOS for phones or OpenWRT for routers. (Of course, there's always just a PC running Linux.)
@miff @briankrebs on some of these boxes you can run Armbian. If an official build doesn't work, in the forum there are some unofficial builds for specific TV boxes. (They are not the intended target.)
Funny thing that the article mentions Google, but it's software is essentially malware as well and had best be disabled on Android devices. The only trustworthy source for applications on Android is F-Droid.
Also note that these boxes themselves are also used by legitimate TV services. The specifics is in the software and you can likely find a way to remove the malware if you happen to have an affected box. If that malware is tied to some illegitimate TV application, you'd possibly lose access to that service. Generally these boxes are simply cheap and won't be affected, but you're always taking a risk when any proprietary software is involved.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs
using people’s internet connections for fraud
causing the collapse of the “Internet Advertising” industry -
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs If those can be rooted they could be a pretty nice Linux SBC.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs If you want unlimited access to content without recurring fees, there are only two ways.
Buy physical media, or torrent.
Neither are particularly hard.
-
@briankrebs you 100% would fall under suspicion, because traces would end at your house
and then it depends, if cops want to find a real criminal, or just increase KPI without doing much work
Where I live, I would never trust cops with this
@mo @briankrebs @adamshostack Remember this: You do NOT fall into one of the widely known cases such as "tor exit node" or "open public wifi." If someone accesses CSAM through your TV and especially if you were previously unaware of this, you could sit in jail unable to post a huge bond until some investigator thinks to check out your TV. If that doesn't happen, you may even get convicted of CSAM you had nothing to do with.
-
@briankrebs If those can be rooted they could be a pretty nice Linux SBC.
@armbian@fosstodon.org has many community builds for SoC's used in those tv boxes (https://github.com/armbian/community/releases). My two boxes from 6-7 years ago with a quad AMLogic S905W and 2GB RAM are still running just fine with latest armbian
Speed for those is comparable to a RPI3
CC: @briankrebs@infosec.exchange