Live data from Hacker News

I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

404media.co

91–100 of 132 posts

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#91
post #87
post #85

Earlier quoted context omitted.

https://www.theverge.com/2013/3/1/4055758/why-does-apples-li...

Seems to have been debunked.

The premise (low end soc streaming video over usb) is not debunked at all.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#92
post #77

Earlier quoted context omitted.

Integrating everything into USB has been great at physical simplification, but it really opened up the attack surface. First party malware is the worst.

Can't wait for the consumer keyboard that saves everything that was typed to it and/or executes things on its own

Yeah, it was sold to schools in the 90s.

https://en.wikipedia.org/wiki/AlphaSmart

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#93
post #10

Earlier quoted context omitted.

Android apps used to need "location" access for bluetooth discovery. https://www.androidpolice.com/2021/05/19/android-12-apps-won...

The other poster already explained the old permission. There's also a new permission specifically for Bluetooth LE now as well for newer devices so location shouldn't be needed.

However, scanning and connecting to Wi-Fi IoT devices still requires it.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#94
post #15

Given that the device is plugged in, trusted, shows up as a computer, and requires external power, it has all the connections it needs spy on the screen (at minimum) and remote control the victim iPhone without permission in the worst case. (it has video feed, and can emulate USB keyboard and mouse) Yikes!

It's not THAT weird. Lightning can't carry HDMI at all so even Apple's official adaptor is essentially setting up an Airplay connection over USB and has an ARM SoC to handle it. I'm guessing 3rd parties can't do the same trick without Apple's blessing which results in scary seeming workarounds.

> I'm guessing 3rd parties can't do the same trick

There are lots of third-party Lightning to HDMI adapters for cheap on Amazon that work as a clone of Apple's with no need for any software. Whatever this cable is doing is out of the ordinary even for knockoffs.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#95
post #83
post #80

Earlier quoted context omitted.

I still find it hilarious that that’s how the old cable worked, the iPhone encoded an H.264 video stream and sent it to the dongle, which decoded it and sent it down HDMI. Now that iPhones have USB-C they no longer need a custom adapter. A standard USB-C to HDMI cable is supposed to work. I believe.

Thing is, I thought Lightning had that too? HDMI or DP over the wire? Guess I was wrong...

Nope. I don’t know if it put itself in some kind of analog mode for composite. I can’t remember if that was a thing around the switch to lightning. But the cool hack has always been how the HDMI adapter worked.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#96
post #15

Given that the device is plugged in, trusted, shows up as a computer, and requires external power, it has all the connections it needs spy on the screen (at minimum) and remote control the victim iPhone without permission in the worst case. (it has video feed, and can emulate USB keyboard and mouse) Yikes!

Integrating everything into USB has been great at physical simplification, but it really opened up the attack surface. First party malware is the worst.

Not at all.

Usbc is just the connector.

Running display port graphics over usbc is no less safe than using a bigger display port connector.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#97
post #7

The saluspa from "bestway" demands your location before allowing you to setup wifi remote control of the portable hot tub on the android app. I wonder how on android I can spoof the location used by an app, or if anyone figured out if you can control it without the app. I set it up away from my house and use a separate wifi network but it pissed me off.

The 4 outlet water timer I bought came with bluetooth remote functionality. It needs GPS location data for it to work. Nope. Should have known some shit like that would be part of the deal, and could have saved a few bucks by getting the version without remote. People need to just stop with this tracking bullshit.

Bluetooth permission implies location permission since you can use Bluetooth beacons to find your location.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#99

I say the big 404 and instinctively bounced. I can’t be the only one. I went back to find their 404 page and am quite satisfied with what I found: https://www.404media.co/i-te/

I’ve seen a few 404 Media articles on here as of late and I’ve been pleasantly surprised by the high quality of the content.

IIRC it's a bunch of former VICE producers/writers.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#100
post #96

Earlier quoted context omitted.

Integrating everything into USB has been great at physical simplification, but it really opened up the attack surface. First party malware is the worst.

Not at all. Usbc is just the connector. Running display port graphics over usbc is no less safe than using a bigger display port connector.

Can a rogue displayport peripheral present as a storage device, keyboard, etc?
Post reply on HN