New, by me: Read This Before You Buy That TV Streaming Stick
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
Did you guys see Jalen Milroe had his first really good practice?
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs A long time ago, around 2010, I would get a Android TV box, flash the firmware to something better, and then install a bunch of emulators, they worked great for a low cost emulation device.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs I linked this article to a family member, who finally became convinced to take it off his network. Thanks for writing this.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs My father-in-law uses things like this. He talks about them like they're amazing things. But the thing he bought charges a yearly fee and asked for ID too, so they have his banking info, address, passport, etc. He doesn't understand why I wouldn't want one...
-
@dryak @briankrebs
It's not like formatting a storage device. Or even like installing OpenWRT on a router. These may have locked or custom bootloaders. See variable difficulty of replacing ChromeOS.
I simply would never buy such a device and probably not the branded Amazon, Google etc varieties. It may be less convenient, but I'd use a laptop or PC. Some may use a Raspberry Pi, but I find a 10 year old laptop more functional.I never connect TV WiFi or Ethernet for similar reasons.
-
I wonder if there's any F/OSS firmware you can flash onto a cheap streaming stick like you can do with GrapheneOS for phones or OpenWRT for routers. (Of course, there's always just a PC running Linux.)
@miff @briankrebs on some of these boxes you can run Armbian. If an official build doesn't work, in the forum there are some unofficial builds for specific TV boxes. (They are not the intended target.)
Funny thing that the article mentions Google, but it's software is essentially malware as well and had best be disabled on Android devices. The only trustworthy source for applications on Android is F-Droid.
Also note that these boxes themselves are also used by legitimate TV services. The specifics is in the software and you can likely find a way to remove the malware if you happen to have an affected box. If that malware is tied to some illegitimate TV application, you'd possibly lose access to that service. Generally these boxes are simply cheap and won't be affected, but you're always taking a risk when any proprietary software is involved.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs
using people’s internet connections for fraud
causing the collapse of the “Internet Advertising” industry -
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs If those can be rooted they could be a pretty nice Linux SBC.
-
New, by me: Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
@briankrebs If you want unlimited access to content without recurring fees, there are only two ways.
Buy physical media, or torrent.
Neither are particularly hard.
-
@briankrebs you 100% would fall under suspicion, because traces would end at your house
and then it depends, if cops want to find a real criminal, or just increase KPI without doing much work
Where I live, I would never trust cops with this
@mo @briankrebs @adamshostack Remember this: You do NOT fall into one of the widely known cases such as "tor exit node" or "open public wifi." If someone accesses CSAM through your TV and especially if you were previously unaware of this, you could sit in jail unable to post a huge bond until some investigator thinks to check out your TV. If that doesn't happen, you may even get convicted of CSAM you had nothing to do with.
-
@briankrebs If those can be rooted they could be a pretty nice Linux SBC.
@armbian@fosstodon.org has many community builds for SoC's used in those tv boxes (https://github.com/armbian/community/releases). My two boxes from 6-7 years ago with a quad AMLogic S905W and 2GB RAM are still running just fine with latest armbian
Speed for those is comparable to a RPI3
CC: @briankrebs@infosec.exchange
-
@maya_b @devnull @adamshostack @briankrebs
I have thoight about doing that, but wonder about lag?
Sadly my router atm isn't OpenWRT but I think it can be? But I've not dared try to flash it. But I think you can do stuff like that on there if you do.
@radioclash @maya_b @devnull @adamshostack @briankrebs
I've been using #Technitium for years now on a linux box and point it to Quad9 as the upstream DNS. I don't often get to say this, but so far it keeps happily doing its thing in the background with no muss or fuss.
I watch the dashboard to check the stats and to watch for occasional updates, but it absolutely does the job it was designed for. 4 Million+ sites in blocklists, scheduled to auto update every 2 hours... & zero lag.
-
@maya_b Clicking ads, even if you don't see them, meant encouraging websites owners to put ads because clicked ads generate money and encourage surveillance capitalism, while leaking PII to crapvertising industry. Also, ads network have been spreading malwares and virus for years… Therefore, clicking randomly on ads is dangerous, especially when it's done automagically and massively (higher chance to get malwares)
The only safe way to deal with ads is uBlock Origin.
@devnull @maya_b @adamshostack @briankrebs
I've had excellent results with Privacy Badger from EFF. It technically blocks trackers rather than ads, but it's very rare to encounter an ad that doesn't track you these days. -
@devnull @maya_b @adamshostack @briankrebs
I've had excellent results with Privacy Badger from EFF. It technically blocks trackers rather than ads, but it's very rare to encounter an ad that doesn't track you these days.@VATVSLPR Ads ARE trackers and have been for a looong time, though not all trackers are ads (many trackers are not even visible).
uBlock Origin isn't "an adblocker" either. It's a security tool. It blocks of course ads but also trackers and all kind of shit with multiple optional lists provided by default as well as the ability the have custom lists. Some people even provide blocklist for LLM-generated slopsites or french fascist billionaire owned ones.
-
K kramse@helvede.net shared this topic