Live data from Hacker News

Read this before you buy that TV streaming stick

krebsonsecurity.com

221–230 of 575 posts

Re: Read this before you buy that TV streaming stick

#221
post #214

Earlier quoted context omitted.

Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold. They certainly don't advertise to the big box retailer that buys them "and it uses the customer's internet connection for fraud." Hell, there's a section of comments that would probably going "hey, RELAX guy" because it's not US companies doing this. For any American companies that d…

> Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold. You already answered it: block it from being sold. 1) Make Amazon responsible for the products they are selling. 2) Introduce a law banning malware tv sticks 3) Sue Amazon for a percentage of their yearly revenue when caught violating it 4) Amazon will finally start caring and do s…

And if the first time you get it online it just updates itself to malware?

That's the biggest problem with any device that updates.

Yea, this will work for the moment and the seller will be covered in the sense that "well, it wasn't infected when we sold it".

Re: Read this before you buy that TV streaming stick

#222

Earlier quoted context omitted.

Clicked on the link, ready to buy one. “Contact sales”. Ew. No thanks.

We are literally new and only available in Barcelona at the moment which I mentioned in my comment as well. Not sure what's eww about that?

Sorry, knee jerk reaction any time I see “contact sales” instead of a price.

Re: Read this before you buy that TV streaming stick

#223

That reminds me, I need to configure VLANs in my router so that all my trusted computers are isolated from all the other garbage that makes it into the network.

Mmmh, I've always wondered ... as much as VLAN's are a very useful tools to - for example - route two separate LAN's traffic through a shared physical link ... are they any good when it come to security? I mean, I don't believe VLAN's were designed with security as a goal, and I wonder how "strong" the virtual wall between two VLAN's actually is? Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physica…

Depends on your networking setup. A good switch will simply refuse to route packets between clients on different VLANs, and hide the existence of the tags that determine which VLAN a host is on.

A bad switch or router (which almost certainly includes a ton of crappy home APs and routers, compromised by the same actors who ship these devices) could let clients see VLAN tags and ignore them.

And an Ethernet “hub” does no filtering at all.

Re: Read this before you buy that TV streaming stick

#224
post #199

Earlier quoted context omitted.

I remember reading an analysis on one of those projectors; the author found a residential proxy running on their device. I would recommend keeping these things off the internet.

I'd be very interested to see it if you still have access to it.

Dunno if this is the same issue, but someone found malware in their projector. I'm not sure about the accuracy since the report is blatantly AI generated: https://github.com/jrm360seclab/aodin-vo1d-malware

Re: Read this before you buy that TV streaming stick

#225
post #160
post #85

Earlier quoted context omitted.

My falther-in-law was less that and more, if I can get away with it, it's actually legal. Many know their fake, and do it because they can get away with it. That was his justification for a satellite descrambler, they're sending me the signals, obviously I'm allowed to.

I can imagine many on HN having excited discussions about their satellite descramblers. > do it because they can get away with it. Lots of people on HN download and upload copyrighted materials. Is it really different?

Fine, you've nerd-sniped me.

I tinkered with Dish Network descrambling 20 years ago. Not because I wanted to just watch a bunch of free TV (I hardly watched any TV anyway, we mostly watched DVDs from the video store and Netflix). More because it felt like an interesting rabbit hole. And it was pretty interesting!

I picked a good (newer!) satellite dish and LNB from the trash and had a friend help with the installation and alignment because that was his previous job. Normal people use some kind of tool to find the satellites' geosynchronous orbital station in the sky, but he did it often enough that he could simply look up into the sky and point at them.

There were a handful of grey-market satellite receivers you could buy that were technically capable of descrambling a commercial signal. Of course, they did not advertise themselves as such. They were marketed as FTA (free-to-air) DVB-S receivers. These were not illegal as they were fairly popular in regions of the world that actually _had_ a fair amount of FTA (unscrambled) satellite channels. The only satellites visible from North America, however, tended to carry religious, shopping, or Mexican/Central American programming. Oh, and NASA TV.

The receiver I bought had DVR functionality if you hooked up a USB drive to it. I think I still have some recorded shows on it. It would have been a great way to harvest and release pirated TV shows to the Internet, if you didn't mind editing out all of the ads and whatever.

DVB-S was basically a raw MPEG-2 TS stream that could be optionally encrypted. To use these grey-market receivers as descramblers, you install some custom firmware containing the descrambling modifications and keys. I'm failing to remember the technical details, but the encryption they used was not very good. Dish Network would rotate the keys occasionally, and when they did, you had to update them on your receiver. I can't remember now if the keys were part of the firmware, but I remember it being a pain in the ass.

The firmware/keys part of this had a very "colorful" community. You had to sign up to a very specific and somewhat exclusive web bulletin board in order to download the firmware/keys. I don't remember how I gained an account, but I remember it being non-trivial. IIRC, it was like one guy maintaining the firmware/keys and sometimes it took weeks for him to adapt to whatever thing DN did to thwart piracy. The board was moderated by a complete power-tripping asshat who enjoyed banning people for fun and then gloating about it. (I was not banned, that I recall.) I think they started requiring "donations" in order to view certain threads (like firmware releases) after a while. But I could be misremembering that. I just remember the community was very toxic.

After a few months of this setup, DN figured out how to rotate their keys too often for the casual pirate to keep up. I disconnected mine around that time and moved onto other things. Partly because the experiment ran its course and partly because migrating to real-time key updates would have meant buying a newer receiver. For a while, I flirted with the idea of getting a DVB-T PCI receiver card and working on breaking the encryption myself, but it was quite a bit above my skill level at the time and there did not seem to be anyone else working on it out in the open, since the DMCA was still pretty new then.

Re: Read this before you buy that TV streaming stick

#226
post #223

Earlier quoted context omitted.

Mmmh, I've always wondered ... as much as VLAN's are a very useful tools to - for example - route two separate LAN's traffic through a shared physical link ... are they any good when it come to security? I mean, I don't believe VLAN's were designed with security as a goal, and I wonder how "strong" the virtual wall between two VLAN's actually is? Can't a device on VLAN1 not peek at VLAN2 traffic if it sits on physica…

Depends on your networking setup. A good switch will simply refuse to route packets between clients on different VLANs, and hide the existence of the tags that determine which VLAN a host is on. A bad switch or router (which almost certainly includes a ton of crappy home APs and routers, compromised by the same actors who ship these devices) could let clients see VLAN tags and ignore them. And an Ethernet “hub” does…

Also: if you need a streaming box to see your AirPlay or UPnP devices for “casting” it necessarily has to be on the same VLAN as the devices it’s connecting to. Sonos speakers have this problem when subject to client isolation setups based on VLANs or switch-level packet filters.

And any kind of multicast (used for local service discovery and media streaming) has the same limitations.

Re: Read this before you buy that TV streaming stick

#227

Earlier quoted context omitted.

Just being realistic here; many of these are of Chinese make so how exactly would you stop it other than blocking them from being sold. They certainly don't advertise to the big box retailer that buys them "and it uses the customer's internet connection for fraud." Hell, there's a section of comments that would probably going "hey, RELAX guy" because it's not US companies doing this. For any American companies that d…

But it is a retailer's responsibility to know what they are selling. If it was added after they started selling it and hidden in secret, sure a retailer might have an excuse. But it isn't really hidden, most often its put in their marketing materials as a benefit and have been knowingly doing it for many years now. US retailers can be told they can't sell it here. If you buy it outside of that, well that is buyer bew…

>If it was added after they started selling it

While it's great we're getting the manufactures to just stop sending out straight malware and it should be stopped the next most obvious means of attack is just having the device update and add superaids to it's new functionality.

So, no, it won't stop 99% of it at all.

And honestly this isn't that much different from what US companies are already great at by providing updates that take away features we bought with the device.

And not just updating really doesn't save you, instead of being part of a factory botnet, you're just open to become part of some other botnet.

Re: Read this before you buy that TV streaming stick

#228

Earlier quoted context omitted.

If I open my own line of home improvement stores and do no oversight on what I sell and wind up selling really dangerous lawnmowers, I'm partly responsible. Or if I open up a gas station and allow any company without oversight to sell "supplements" through my shelves and cops arrest me for selling heroin, I don't get a free pass. Why should amazon or Walmart get a free pass just because they sell more items?

Except the devices are not dangerous. Its the software installed on the device. Consumers have a choice. Pay for the trusted Apple TV or Amazon firestick, or go the wild west and see what's on offer.

with the devices mentioned in the article, there is no consent requested, and the malicious apps are installed either before the box is sold or after as a requirement for getting the streaming services to work.

Re: Read this before you buy that TV streaming stick

#229
post #127

A familly member had one of those (he had to pay a yearly subscription in addition to the stick). Network would be unusable as soon as it was on for anyone else, and it also tried to scan things on the local network. It was indeed connecting to all kind of services all over the world (and saturating some tables in the router doing so which blocked other clients). Definitely evil, definitely on purpose.

Reading this, I caught myself wondering how we distill what's in this excellent write up into something the average consumer understands, including the dangers from buying and using devices like this. Is it a graphic that's shared? Something else? I am sure we all know or have heard of people with these devices that promise free streaming.

In the world of auto-updates of software and firmware, even the hardware which is now completely legal and crap-free, could convert itself to a proxy or ad network later any time.

And don't forget about counterfeit products (which look like original but different in firmware) and supply chain attack vectors, which are really, really common.

If you want to buy something as simple as a feature phone, going to a store with 10 of them will give you at least 1/10 chance to buy a phone with a trojan/backdoor.

Re: Read this before you buy that TV streaming stick

#230

Earlier quoted context omitted.

We are literally new and only available in Barcelona at the moment which I mentioned in my comment as well. Not sure what's eww about that?

Sorry, knee jerk reaction any time I see “contact sales” instead of a price.

No worries. If you message me via the contact form or chat support on the website, I will try my best to provide you with one. The more feedback I can get, the better.

Thanks for liking my product enough to want to buy it right away :)

Post reply on HN