Top
Best
New

Posted by speckx 3 hours ago

Read this before you buy that TV streaming stick(krebsonsecurity.com)
307 points | 148 comments
SoftTalker 9 minutes ago|
> Despite repeated warnings from the FBI and security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands

I scanned the comments and I didn't see anyone suggesting that these companies should share any responsibility for selling these harmful products. Why is it that they seem to get a pass? Would we feel the same about giant retailers selling tainted food, or unsafe children's toys?

simojo 57 minutes ago||
We purchased a Chinese-made projector from Amazon, which was surprisingly inexpensive (~40 USD). Upon connecting it to the internet, it placed a constantly running feed of ads on the corner of the screen, even while movies were playing. There was no way to disable it either. Even though it's not a stick, it's a similar principle.
xyx0826 31 minutes ago||
I remember reading an analysis on one of those projectors; the author found a residential proxy running on their device. I would recommend keeping these things off the internet.
Pxtl 56 minutes ago|||
I mean, did you have to connect it to the internet though? Did it not just have a dp/hdmi port?
mikestew 49 minutes ago||
Upon connecting it to the internet…

I hesitate to blame the victim here, but why on earth would you do that? “$40 Chinese-made” didn’t give you pause?

bigmattystyles 31 minutes ago||
To be fair, everything is Chinese made. I would be even the Apple TV and NVIDIA Shield are made in China and if a state actor is determined to get a malicious payload in....
miladyincontrol 8 minutes ago|||
To play devil's advocate, when someone says "Chinese made" they're usually well aware of your point, and are more using it as a common way to describe product mills spitting out countless devices with dubious quality or configuration.

Of course theres good products made in China, and plenty of entirely Chinese brands killing it doing their thing.

fc417fc802 6 minutes ago||||
This isn't about state actors though. There's a world of difference between a name brand (possibly even a Chinese one) versus what I would term "chineseum". It's nothing to do with China per se and everything to do with purchasing from the extreme low end of the market. It just so happens that the vast majority of that segment is manufactured in China at present.
worik 4 minutes ago|||
> To be fair, everything is Chinese made

Yes. Chinese manufacturing is quite a phenomenon, useful and everywhere

But to be completely fair, a $40 video projector has a warning label. The price

mortenjorck 3 hours ago||
In this case it’s actual malice, that the streaming stick is set up for residential proxy and ad fraud straight from the factory. But incompetence can lead to the same place if it’s a poorly engineered, un-maintained device with an old version of Android that will never be patched and is always one no-click exploit away from being commandeered into residential proxy and ad fraud.
FinnKuhn 3 hours ago||
Those TV streaming boxes really are (from a cybersecurity perspective) probably one of the worst things you can buy. Here is the "Darknet Diaries" Episode on them: https://darknetdiaries.com/episode/172/
labbett 26 minutes ago||
Superbox 3 is coming up at DEF CON next Friday!

https://hackertracker.app/defcon34/content/67257

frollogaston 35 minutes ago|||
Since these are poorly engineered, wonder how easy it'd be to reverse-engineer one and just get the free streaming on a non-scam device.
kiririn 2 minutes ago|||
See CoreELEC/LibreELEC/etc - totally replaces the (potentially dodgy) Android OS on these kind of streaming boxes with a stripped down Linux+Kodi setup
dpoloncsak 28 minutes ago|||
If it's something like a Firestick (or the knock-off featured in the article), you're really just connecting to Content Provider servers to handle auth and content streaming, right? They're just OSes designed to run Netflix and Hulu. Would be hard to spoof I think
mikepurvis 25 minutes ago||
Indeed. Owning the streaming box lets you loose on whatever network it's on, but it doesn't actually get you inside the content gardens; those are separately managed by teams of people much more motivated to protect their IP.
alex_duf 3 hours ago||
I wonder to what degree malice can be engineered to look like incompetence?
abbeyj 3 hours ago||
Try examining the old entries from the https://en.wikipedia.org/wiki/Underhanded_C_Contest.
matheusmoreira 1 hour ago||
That reminds me, I need to configure VLANs in my router so that all my trusted computers are isolated from all the other garbage that makes it into the network.
pavel_lishin 3 hours ago||
> generic TV boxes that promise unlimited content streaming for a one-time fee

I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.

havaloc 3 hours ago||
I have an elderly client who sends me links of stuff to buy all the time. One day it's one of these streaming sticks, the next day it's half-price stamps, and I tell her every time, please don't buy this stuff. And yet she does anyway, as if I was almost being mean and saying no just to say no.

So yes, I do want to blame the purchasers of these things, sometimes. To prove her point that her stamps were legitimate, she mailed me a card using one of her half priced (but likely fake) stamps and it made it through!

Terr_ 2 hours ago|||
Perhaps they grew up in a time/environment where "if it was that bad they wouldn't be allowed to advertise it", and they're still using that old calibration?
mhurron 1 hour ago|||
My falther-in-law was less that and more, if I can get away with it, it's actually legal. Many know their fake, and do it because they can get away with it.

That was his justification for a satellite descrambler, they're sending me the signals, obviously I'm allowed to.

iamben 34 minutes ago||||
I think that's a default for a lot of the older (and some of the younger!) generation, same goes for news and media. They grew up in a time where there was a practical barrier to publishing and (largely) laws behind you doing it.

So they trust literally everything they read. I still don't think my folks can fathom you can spin up a very real looking newspaper website with fake articles in about 10 minutes.

Pxtl 1 hour ago|||
Of course, what they're missing is that laws are for poor people.

Amazon will be notified they sold something illegal and will take it down and ban the seller who will immediately launch a new store under a new name.

The purchaser, on the other hand, will be fully liable for whatever horrible thing they bought.

floam 59 minutes ago||||
Half priced stamps work though, and nobody is going to prosecute grandma for counterfeiting postage stamps.
zeafoamrun 28 minutes ago||
Yes they do. USPIS does not f around
Pxtl 19 minutes ago||
Oddly they don't ever seem to prosecute the sites that profit from selling them. Funny, that.
Scroll_Swe 1 hour ago|||
Then again I used to torrent everything under the sun and it actually rocks to have every tv show, movie, game ever released for free forever.

So is it greed? Yes, but I did it too so now that its more accessible I cannot really blame people.

nvme0n1p1 3 hours ago|||
OTOH - TV, radio, and YouTube are all unlimited and free. Why not streaming?

There are lots of people alive who grew up during the days of broadcast TV and radio. I get why they might not understand the difference.

weberer 1 hour ago|||
There are a ton of legitimately free IPTV streams. You can watch them through most media players like VLC without having to download anything shady.

https://github.com/iptv-org/iptv

nvme0n1p1 22 minutes ago|||
Ok but have fun explaining that to the average person. Buying a dongle is easier than installing software or typing URLs into their TV ("my TV doesn't even have a keyboard").

To most people IPTV is a bunch of gibberish letters, indistinguishable from the gibberish brands on Amazon. Someone's grandma from Colorado doesn't deserve to get scammed because she didn't research the acronyms.

nuxi 33 minutes ago|||
Two things:

- How are these "legitimately free"? For example AMC is a commercial TV channel and as far as I know, they don't offer free streaming. Same goes for MGM, FilmBox etc.

- Strictly speaking this isn't IPTV, it's just web streams. IPTV is usually delivered via multicast (MPEG-TS/RTP/RTSP streams, over UDP mostly).

bluedino 43 minutes ago|||
Most people who buy these want to watch free movies, sports streams, etc that aren't on OTA or free services
paultopia 1 hour ago|||
Yeah, isn’t this a classic kind of scam the would-be scammer situation? If you think there’s some way to buy one cheap device and somehow get around subscribing to streaming services[1], then of course you’re going to be in a market with fraudsters…

[1] Can someone explain what the theory of the product is here? It sounds like they’re marketing these things as ways for the customer to commit fraud, for example by connecting to someone else’s login. How else would the customer expect to be able to get free Netflix or whatever?

rng-concern 1 hour ago|||
I know a few people who buy these, and they kind of know what they're doing. They just try and not think about it too hard.

It reminds me of the saying: "It Is Difficult to Get a Man to Understand Something When His Salary Depends Upon His Not Understanding It".

If these people thought about it for a few minutes, they would understand, but they choose not to, as ignoring it is too advantageous.

I admit I was tempted, as the price of all streaming services goes up, and services become more and more fragmented. During the same period where I have not had a raise.

varispeed 39 minutes ago|||
I used to know someone doing this. They said they know it is too good to be true, but they hate corporations and it's their little way to stick one in.
iugtmkbdfil834 3 hours ago|||
Uhh, I have an extended family member, who not only uses it, but now also tries to get other people to get into it. Since I was familiar with this practice ( and the issues it makes worse ), I noted those to him in an attempt to both politely decline and, hopefully, spare him, and society, some future problems. Without going into any identifying details, he didn't take it well ( and I don't think I got on my high horse ).

Anyway, I think some level of blame is warranted.

IncreasePosts 2 hours ago|||
Maybe, but if they're a not-very-tech savvy older person buying this, they probably remember shows being free from over the air antennas and may think it is something like that.
ghostly_s 2 hours ago|||
> they probably remember shows being free from over the air antennas

you are aware broadcast TV never ended?

IncreasePosts 2 hours ago||
Yes, in fact I have an antenna and a HDHomeRun nestled in my attic to record over the air shows that I occasionally consume.

But, I think it's far more common for people to have a TV service today, perhaps since comcast and their ilk push hard the TV/phone/internet bundle, and gone are the years when everyone would fiddle with the antennas on the back of their TV to get the right reception.

bdangubic 2 hours ago|||
I watch TV over an antenna, shows are free still
fred_is_fred 3 hours ago|||
If you offered most people free streaming for a $37 USB stick but directly told them it would be faking ad clicks when the TV is off, would any of them really care?
ajnin 12 minutes ago|||
Maybe they wouldn't care about the ads but the residential proxy is another story. I'm sure lots of problematic stuff goes through that and you take the risk of being associated with it.
1970-01-01 3 hours ago|||
No, and that's is the root of the problem. The buyer is happy and so is the seller. They don't care to understand what they're allowing and everyone is allowing it to happen.
bayarearefugee 53 minutes ago|||
I wouldn't use a device like this for a lot of reasons, but the fact that what they are doing might be taking advantage of the incredibly predatory digital advertising system is neutral to positive for me, if I'm being fully honest.

If they were using the system to rip off random people, I'd be 100% against it, if they are fucking Google and the giant corps that advertise with them, ehh.. not my problem and can't be assed to care. Google is not a positive force in the world. Hasn't been for many years.

mschild 29 minutes ago||
Wouldn't this ultimately make money FOR Google and only cost money to the company that placed the ad?

Sure, Google's paying but they get their money regardless.

chowells 4 minutes ago||
It might damage Google's reputation with advertisers in the long term. I'm not convinced Google would even care about it, given their other behavior.
GolfPopper 2 hours ago|||
They're just meeting the standards American society has set.
Scroll_Swe 1 hour ago||
Ah yes there was no rampant piracy in eastern europe during/after Soviet lmao

Tankies like this make me laugh

croes 3 hours ago|||
It sounds like scam
flerchin 3 hours ago|||
Well now I want one
Cider9986 2 hours ago||
Stremio+TorBox are the two words. ($3/month)
ghostly_s 2 hours ago||
That's not what these things are. They come preloaded with apps that stream pirate broadcast streams and on-demand servers operated out of China.
Cider9986 2 hours ago||
It could be possible, I haven't done the math though.

Stremio +Torbox is $3/month and they can probably share 10+ households on one TorBox account so it could work out. The seller could just stop paying the TorBox subscription at whatever point and they have an incentive to do so.

glitchc 3 hours ago||
Defrauding ad networks doesn't seem like a bad thing, although using my internet connection as a proxy is obviously terrible. It wouldn't surprise me to learn that my connection is being sold as a VPN service by the vendor.
kube-system 5 minutes ago||
Fraud is also bad, even if you aren't fond of those being defrauded.
alistairSH 2 hours ago|||
It'll be a marginal effect, but fake clicks impacts the ad buyer, which then impacts their financials and pricing.

The only winner here is the scammers running the fake affiliate sites on which these sticks are "clicking". Or, am I missing some facet of this enterprise?

frollogaston 52 minutes ago|||
What this misses is the person buying the TV stick doesn't care about the impact on the ad market. The bigger problem is residential proxying, because their IP will end up getting used for something bad.
ssl-3 2 hours ago|||
Another winner is the person who gets to watch cheap digital TV, without putting together a usable antenna and limiting their reception to the broadcast channels that are nearby.

I mean: They just pay the money, plug the thing in, push some buttons, and: TV happens. Right?

cryzinger 1 hour ago|||
You really don't want fraudulent clicks ("invalid traffic", per industry lingo) coming from your home network, because any publishers (apps and websites, per normal-people lingo) who use tools designed to block invalid traffic might start flagging legitimate traffic from your network.
frollogaston 43 minutes ago||
Can confirm. I used to use Ad Nauseam (Firefox extension that clicks all ads), eventually stopped when I was getting captcha'd left and right.

Also, visitors on my wifi started getting strange ads. Yes I threw off the algo, but I'm a guy with wife, I'd rather get car ads than like divorce lawyers + gay dating sites.

snickerbockers 1 hour ago||||
Theres the question of whether or not the fraudulent advertisement clicking is using enough traffic to inconvenience or impose fees upon the user but otherwise I agree with you and am tempted to buy one just to fuck with advertisers.

Backdoors and spying are also a problem in theory except at this point you can't even trust "legitimate" companies on that front so it's a moot point.

em-bee 2 hours ago||
why is running a proxy a bad thing? someone profiting off it could be bad maybe, but even that is good if it pays for my subscription.

but compare running tor nodes, and especially exit nodes. that surely would be a good thing, so at least if you think tor is good then running a proxy should be the same and it should be normalized.

doing it in secret without the user knowing is what's bad

40four 7 minutes ago|||
Because your home IP address is going to be associated with criminal activity. So if that’s acceptable “payment” then I guess there’s no issue
corbet 49 minutes ago||||
https://lwn.net/Articles/1080822/ Do you really want to be a part of the scraper problem?
glitchc 1 hour ago|||
Indeed without my permission is implied. Without it, you have no idea what traffic is being routed and could be on the hook for something nasty like CSAM.
ta988 34 minutes ago||
A familly member had one of those (he had to pay a yearly subscription in addition to the stick). Network would be unusable as soon as it was on for anyone else, and it also tried to scan things on the local network. It was indeed connecting to all kind of services all over the world (and saturating some tables in the router doing so which blocked other clients). Definitely evil, definitely on purpose.
deepfriedbits 25 minutes ago|
Reading this, I caught myself wondering how we distill what's in this excellent write up into something the average consumer understands, including the dangers from buying and using devices like this.

Is it a graphic that's shared? Something else? I am sure we all know or have heard of people with these devices that promise free streaming.

ta988 22 minutes ago||
I warned them about the risk of those things and showed them what I found, they continued buying the next generation (that person and his two >40yo kids). They NEEDED to watch those soccer games more than they cared about security...
rawgabbit 11 minutes ago||
What happens when you stick this malware into your windows PC? The PC is now an accomplice to fraud?
skinfaxi 3 hours ago||
Thankfully this seems limited to a specific device (H96). Darknet diaries has a good story about streaming devices https://www.youtube.com/watch?v=dS6PkuZuxJ4
krebsonsecurity 3 hours ago|
It's not just one device line; Have a look at the list maintained by the proxy tracking service Synthient, which tracks streaming boxes, digital picture frames and other IoT devices that have been known to bundle residential proxy software, among other malicious apps. They currently track almost 1,000 different makes and model numbers.

https://github.com/synthient/public-research/blob/main/2026/...

codedokode 3 hours ago|
I do not see problems with fake ad clicks and have no sympathy for ad companies.

Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.

What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.

How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:

- the user must be able to re-flash firmware with their own code.

- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.

- any telemetry or data collection, or updates must be opt-in only and disabled by default.

- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.

Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.

Thrymr 2 hours ago||
> I do not see problems with fake ad clicks and have no sympathy for ad companies.

I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.

jrm4 1 hour ago||
Sure. And you'll quite literally never be able to get any meaningful reduction in this practice unless you attack it at the level of big, publically known companies; the warnings about these local dinky things I suppose are not harmful and help individuals a bit -- but I'm concerned they give the entirely false impression that the extremely similar stuff coming from the big boys is definitely a-ok.
Cider9986 2 hours ago|||
>What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information.

Most Americans are at a greater threat of harm from their own government that a foreign one. What worries me is all the mass surveillance done by big tech which bypasses the 4th Amendment and gives the government Americans data without a warrant.

There's already a front door with the adtech for US alphabet boys. This could likely be collected by others as well. We saw this happened where foreign hackers exploited a backdoor designed for American authorities[1]. This is what experts are referring to when they say there's no backdoor only for me.

This could be compelling to politicians, though, and would certainly be a step in the right direction.

>- any telemetry or data collection, or updates must be opt-in only and disabled by default

This should be how it is for everything foreign made software or not. Would be very hard to get done with the big tech lobby in the US.

[1] https://techcrunch.com/2024/10/07/the-30-year-old-internet-b...

pavel_lishin 2 hours ago|||
> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?

> for every imported device having a CPU and Internet connectivity

Why limit this to imported devices?

palmotea 2 hours ago|||
>> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

> Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?

Cheap, slow-moving drones are the hot new missiles on the battlefield of today. This often talked-about model files at 115 mph (https://en.wikipedia.org/wiki/HESA_Shahed_136).

codedokode 2 hours ago||||
In some areas GPS is spoofed and the displayed location is wrong. If, for example, a "smart" car gets a task from its manufacturer to film some secret object, it would fail if it relied only on GPS and did not use cell towers and WiFi points for determining its location. So knowing their location determines whether the mission would fail or succeed. So foreign devices should not be allowed to collect such information.
bee_rider 2 hours ago|||
I think that might have been semi-sarcastic. I mean, there are lots of reasons to do this sort of thing, some are bad, some are not so bad, most are not war.
BoppreH 2 hours ago|||
> a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys.

Could it be used for missiles? Sure. Is it obviously the intention? No.

meatmanek 2 hours ago|||
Yeah this is extremely standard:

Apple: https://support.apple.com/en-us/102515

> If Location Services is on, your device will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers to Apple to augment Apple's crowd-sourced database of Wi-Fi hotspot and cell tower locations.

Google: https://support.google.com/android/answer/15157297?sjid=1648...

> When Location Accuracy is on, Google periodically collects information about the locations of wireless signals and sensors observed by your device to crowdsource location estimates. This helps everyone find locations better.

Mozilla used to run a very similar service: https://en.wikipedia.org/wiki/Mozilla_Location_Service

Not to mention truly crowd-sourced databases like wigle.net.

codedokode 2 hours ago||
They should ask the permission from device owner and local government before collecting the data.
aeturnum 2 hours ago||
They do ask the device owner - if you review the location services description on android[1] you will see they explicitly say they collect this information from your device. I strongly disagree that they need to get government permission for this - they are simply recording signals that reach the device, akin to making notes about what kinds of cars you see. This is not a thing a government should have control over people doing and not a thing that should be registered with the governement.

[1] https://support.google.com/android/answer/3467281?sjid=66634...

codedokode 1 hour ago||
In the article you refer to, I see no mention of asking user's permission. However, I remember, when using an old version of Android, there indeed was a popup nagging me to allow sharing location data with Google every time I enabled GPS. Very annoying, makes you want to never enable GPS in the first place.

Regarding the government, the problem is that many people do not fully understand the mechanism of collecting the data. I remember the case when members of US military disclosed the location of secret objects through fitness tracker app. And they were probably smarter than average smartphone user. Obviously it would be better if enabling GPS required an approval from their commander.

codedokode 2 hours ago|||
Should Google ask permission from the device owner, and from the local government before collecting the data? I heard a certain foreign mobile app was banned in US for doing less than that.
arjie 2 hours ago|||
Oh this was a failed device that Mozilla offered. I had a couple back in the day. It was called Matchstick. Sick t shirts. Basically an OSS chromecast.
IncreasePosts 2 hours ago|||
Fake ad clicks cost the advertiser money, not the ad company.

Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)

mcphage 2 hours ago|||
> Fake ad clicks cost the advertiser money, not the ad company.

It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.

codedokode 2 hours ago|||
Good products do not need much advertising. For example, when buying DRAM, I compare the specification and prices and do not look at the advertisement.
mcphage 2 hours ago|||
> I do not see problems with fake ad clicks and have no sympathy for ad companies.

Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.

autoexec 3 minutes ago|||
> Yeah, it's like—a cheap streaming stick AND it poisons the advertising well?

Keep in mind that it's your IP and identity associated with those clicks and anything else criminals decide to do with your IP address. That means you're identity is being linked to things you may or not want to be known as being interested/involved in. The ads your TV clicks on can cause data brokers to include your name in lists of people who are heavily into drugs, have mental disorders, belong to certain religions or political parties, etc. All of that can come back to haunt you later.

Depending on what other activity your connection is used for it can also get you in trouble with the police or with your ISP.

exe34 2 hours ago|||
My pinenote runs the original spyware image - I don't have a problem with Winnie the Pooh reading along with me.
soulofmischief 1 hour ago||
The problem is that when you need these powers most as a citizen is when your government is least likely to allow it.
More comments...