Top
Best
New

Posted by speckx 6 hours ago

Read this before you buy that TV streaming stick(krebsonsecurity.com)
448 points | 262 commentspage 5
burgreblast 2 hours ago|
Google clutches pearls and is shocked! Shocked! That anyone would violate its policies (while it pockets 30% of the fraudulent revenue). Shocked!

And they would have caught them but those crafty criminals spoofed the user-agent. So how _could_ they know?

j45 6 hours ago||
Generally, it's advisable to create a dedicated wifi network for all potentially hostile devices.

This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.

That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.

drnick1 3 hours ago||
> That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home

That is not enough. You need to air gap devices that have legitimately no business communicating with anyone or anything outside the house. TVs, thermostats, and other Internet-of-Crap gadgets do not need "firmware updates." Either they work out of the box, offline or within the LAN, or they get sent back for a refund wherever they came from.

spelk 4 hours ago||
I don't think this would make a big difference for the threat model described in the OP? They'd still be able to use your IP Address and potentially do nefarious things through your role as an unwitting proxy.
j45 4 hours ago||
Using one device as a proxy is a few steps away from trying to exploit and infiltrate the other devices on your machine as well. An unwitting proxy is already crossing the line to putting a fox in the henhouse.

Limiting what outbound access devices can/can't have is an important skill to learn.

buellerbueller 2 hours ago||
To those who are OK with these devices: when you engage in corruption, do you have any moral standing against your politicians when they engage in corruption?

Both you, and the corrupt politicians, are eating away at the trust that underpins society. Certainly, you can argue, your bite is just a tiny one; the politician is eating the whole apple.

At the end of the day, everyone suffers from the decline of trust and casual acceptance of fraud.

Pxtl 4 hours ago||
> major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands that bundle unofficial versions of Google’s Android operating system and are frequently marketed (via online influencers) as a way to access a broad array of streaming services and live broadcasts without a subscription.

This is why I giggle when people talk about ending Section 230 in the USA (or various international counterparts thereof).

The largest companies on Earth are happily selling hacked piracy spyware botnet garbage. Not just hosting malicious posts for free like Section 230 protects, but selling illegal physical devices and taking a cut of the profit and excusing it with a pathetic whack-a-mole moderation system. It's already illegal and the law has already failed.

Sean Parker's mistake was that he wasn't rich enough.

Laws are for poor people.

bronko_nagurski 6 hours ago||
[dead]
defmetrix 5 hours ago||
I didnt know anybody bought a streaming stick anymore
AlotOfReading 5 hours ago||
Of all the evils normally associated with visual programming languages, enabling cybercrime isn't one I've previously considered. Now that I've seen it, I'm surprised it wasn't more common before LLMs appeared.
yunnpp 4 hours ago|
And which part of "ad fraud" is the fraud? As far as I can tell, ad networks and advertisers are the fraud and they are also part of the increasing surveillance state.

Didn't know Krebs was a mainstream news puppet.

brainwad 4 hours ago|
It's called fraud because the ad host colludes with (or directly controls) the botnet to get lots of clicks on ads hosted on their sites, making them money at the expense of advertisers.

If you just want to spam clicks on ads you don't financially be edit from, go for it.