Advertisement
Help Keep Boards Alive. Support us by going ad free today. See here: https://subscriptions.boards.ie/.
https://www.boards.ie/group/1878-subscribers-forum

Private Group for paid up members of Boards.ie. Join the club.
Hi all, please see this major site announcement: https://www.boards.ie/discussion/2058427594/boards-ie-2026

Clampdown on TV 'Dodgy Boxes'

1215216218220221240

Comments

  • Registered Users, Registered Users 2 Posts: 10,022 ✭✭✭✭irishgeo


    Cheap smarthome and IOT devices are just as likely as Android bixes.



  • Registered Users, Registered Users 2 Posts: 5,363 ✭✭✭FishOnABike


    Could be any type of device and a malicious device is not likely to report user-agent correctly or may even use random user-agent switching to appear as multiple different devices. It's anybody's guess.



  • Registered Users, Registered Users 2 Posts: 118 ✭✭longrunn


    FWIW, I have both an Nvidia Shield and a Strong IPTV box. The Strong box is a cheap Chinese one from DID. They're on a separate VLAN and SSID to the rest of my network with client isolation and very strict firewall rules. I force all DNS through my own DNS server for logging and blocking and don't see anything suspicious indicating they're part of a botnet.

    I don't allow anything Chinese on my regular home network but this device is isolated and controlled. I actually didn't realise Strong was Chinese when I did a bit of quick research before buying it. Their website is strong.eu, and looking at their website it really comes across that they are a native European company. A bit of deeper research shows they were bought out by a Chinese company a number of years ago. It seems that the strong.eu really try to deceive and make it look like they are European. For a cheap box it's fairly capable though still nowhere as good as the Shield.



  • Registered Users, Registered Users 2 Posts: 8,898 ✭✭✭jmcc


    Most of them would have been compromised Windows devices. There was a long list of shipped as compromised Android devices linked from that Krebs on Security article I linked earlier in the thread.

    Regards…jmcc



  • Registered Users, Registered Users 2 Posts: 8,898 ✭✭✭jmcc


    Even iPhones. The User Agent string is one of the easiest things to spoof and it is done all the time. This botnet (and there may have been a number of them) seemed to be using these compromised devices as a web proxy so that they could each download a single webpage. When it comes to content, residential and mobile web proxies (compromised or willing) are used to steal content for AI. Most large websites have blocked Chinese and Singaporean datacentres (Tencent/Aliyun/Acevulle etc). What some of these AI operations are doing now is to use compromised devices on residential and mobile phone networks. Compromised low end Android devices may be part of those botnets.

    Regards…jmcc



  • Advertisement
  • Registered Users, Registered Users 2, Paid Member Posts: 8,037 ✭✭✭jj880


    When this topic comes up I always wonder if the HSE still have machines using Windows XP. Probably.

    >>> BOARDS IS IN TROUBLE - SUBSCRIPTIONS NEEDED <<<

    Info 👉️ Important News!!

    Progress 👉 https://keepboardsalive.com/

    Subscribe 👉️ https://subscriptions.boards.ie/



  • Registered Users, Registered Users 2 Posts: 8,898 ✭✭✭jmcc


    A better approach. There is a list of the low end Android devices that are shipped in a compromised state posted on Github. It is linked from the Krebs on Security article. It is an amazing bit of research.

    The Chinese companies tend to do a lot of acquisitions. That country/regional branding is very common with marketing and the .EU ccTLD is used primarily for that kind of website or for redirects to the company's relevant country level website. A cheap .EU domain name can serve all EU countries without having to buy the domain name in each EU country's ccTLD. It can be very difficult for European companies to compete with cheap Chinese hardware.

    The main reason that Chinese equipment is so common is because of the cost. Much of it is reliable and does not give any problems. It is those low end Android devices that were shipped as compromised that are risky. With well known brands like Nvidia and Firestick, there is an expectation of quality.

    Post edited by jmcc on

    Regards…jmcc



  • Registered Users, Registered Users 2 Posts: 118 ✭✭longrunn


    Tbf, the XP and Win7 devices in hospitals are usually medical devices that can costs anywhere from €10k to €1.5m. Take a catscan for example, it could have been bought 10-20 years ago for €1m but has a control panel running XP or 7. You can't replace all of the machines just because there's an EOL OS, it's not affordable or realistic. There are ways to mitigate the risk using certain security controls, the issue is that many hospitals don't know because these are clinical/medical devices, not IT devices.

    Going forward, the CRA regulation should improve this situation as it shifts some responsibility onto the vendor of the devices. This will also have a big impact on dodgy Chinese gear, as the vendor can face regulatory punishments for shipping insecure devices into Europe.



  • Registered Users, Registered Users 2 Posts: 3,786 ✭✭✭dubrov


    Plus they aren't internet facing. They might be vulnerable but there likely is no path to get at them



  • Registered Users, Registered Users 2 Posts: 118 ✭✭longrunn


    Sure, they're not the initial point of entry, that's likely to be a phishing email. But they can still be exploited by an attacker when on the network and then ransomwared. The HSE had a flat network. You might (or might not) be surprised at the amount of flat networks with legacy equipment that exist in many different organisations.

    On the topic of dodgy boxes, in my line of work especially throughout the past few years, I have found cheap dodgy boxes in use within critical infrastructure, utilities, and manufacturing plants. Employees bring them in for use in the canteen, etc, as the TV would usually only have saorview or whatever FTA. When found, if on the plant network they are flagged as high-risk and prioritised for remediation, but sometimes they're on the guest network and just ignored.



  • Advertisement
  • Registered Users, Registered Users 2 Posts: 286 ✭✭DXR


    Looks like Amazon Firesticks are finished as being the chosen "dodgy" box — well new ones anyway, according to this.

    I can whole heatedly recommend the "Onn" devices that Walmart sell in the US, they're region locked, but if you are even half way Tec savvy you'll unlock them in 5 mins with a VPN and a laptop (needs to be a WiFi connection generated from the laptop with a VPN on, set to USA)

    If they sound a bit daunting, go for the Thomson models available here, they're the same hardware, just repackaged and far more expensive.

    Post edited by DXR on


  • Registered Users, Registered Users 2, Paid Member Posts: 8,037 ✭✭✭jj880


    I think twas inevitable Amazon would switch all new devices over.

    Google are supposed to start app blocking measures later this year.

    Ive 3 boxes but none are running Google TV. I wonder can you skip adding a google account for Google TV devices and install your own apks…

    >>> BOARDS IS IN TROUBLE - SUBSCRIPTIONS NEEDED <<<

    Info 👉️ Important News!!

    Progress 👉 https://keepboardsalive.com/

    Subscribe 👉️ https://subscriptions.boards.ie/



  • Registered Users, Registered Users 2 Posts: 1,967 ✭✭✭Benedict XVI


    I read the article and it says that Vega OS is Linux based.

    So I'm sure someone has already found a way of side loading.

    That's the great thing about Linux, it's so configurable if you know how.

    I'd say there could be good business breaking them to sell to the dodgy box suppliers to then prep for the customer.

    Because Joe Soap is not going to be able to break them.



  • Registered Users, Registered Users 2 Posts: 3,012 ✭✭✭Dr Robert


    There'll be another way available within 5 minutes of one being stopped.



  • Registered Users, Registered Users 2 Posts: 286 ✭✭DXR


    I'm not sure guys, the select models have been out for a number of months now, and I'm not aware of any methods yet to get any IPTV apps on to them yet.

    I'm not saying there's not a way.... Yet.....

    Just that I'm not aware of any, I'm on record of saying eventually some dev should figure out a method, but I haven't seen one yet.



  • Registered Users, Registered Users 2 Posts: 5,616 ✭✭✭wassie


    Unlikley. Because Amazon owns the entire tech stack from the kernel to the UI, they will be able to push mandatory security updates more efficeintly & quickly, making it harder for users to block updates or maintain older, exploitable firmware versions.

    Also means for app developers, they must build their apps developers using the Vega SDK. Amazon will have total contorl over what software can exist on the platform, as there is no back door to install unapproved software.

    There may well be workarounds developed, but I wouldnt expect them to be long lasting as Amazon have designed this OS to counter this. Playing constant wack-a-mole for the end user gets tiring.



  • Registered Users, Registered Users 2 Posts: 7,860 ✭✭✭SteM


    Why do you keep posting ai slop on various threads? Any thoughts of your own?



  • Registered Users, Registered Users 2 Posts: 7,860 ✭✭✭SteM




  • Registered Users, Registered Users 2, Paid Member Posts: 22,620 ✭✭✭✭Bass Reeves


    Up until I became semi retired in 2018 for one type of equipment I helped maintain I had a Windows 95 ( or 98 but think it was 95) labtop. We had stopped using that suppier and revieved no further updates. IT used to be going bannas. They could not comprehend why it could not be updated or replace. Equipment was not linked to internet, it had limited remote managment.

    I remember trying to explain to a an IT head we were not going to spend a couple million replacing or upgrading equipment when a replacement labtop to maintain it was a couple thousand. He could not grasp the concept

    Slava Ukrainii



  • Registered Users, Registered Users 2 Posts: 467 ✭✭Banjo Carney


    Thank you 👍



  • Advertisement
  • Moderators, Computer Games Moderators, Social & Fun Moderators, Paid Member Posts: 81,524 Mod ✭✭✭✭Sephiroth_dude


    Mod

    I've deleted a couple of off topic posts, @Manc-Red_ please stick to the topic of the thread and stop posting game listings.

    "The robin in the garden,

    That was me,

    I'm still here, Loving you..

    Until we meet again. "



  • Registered Users, Registered Users 2 Posts: 611 ✭✭✭mrm


    https://www.boards.ie/discussion/comment/124430454#Comment_124430454

    Thanks for that @Manc-Red_ .

    And where do you suggest we go for the Clampdown on the TV 'dodgy boxes'? :) 'Cos there's absolutely zero progress in here on this relatively stagnant topic since thread inception in August 2023.

    Or…….maybe the clampdown is complete!

    Actually your football postings were great as they had totally drowned out the bullsh1t posting from the usual suspects.



  • Registered Users, Registered Users 2, Paid Member Posts: 2,201 ✭✭✭Manc-Red_


    I’ll say no more on it as the minority of the vote won.

    Anyways let’s hope someone sets up something that’s on topic regarding the listings and I’ll gladly post there.

    Better Born Lucky Than Rich.



  • Moderators, Recreation & Hobbies Moderators, Paid Member Posts: 19,491 Mod ✭✭✭✭Trigger


    Or you could just set up your own thread over in Sports and post them there, people from here can then follow it? 🤔



  • Registered Users, Registered Users 2, Paid Member Posts: 2,201 ✭✭✭Manc-Red_


    would it be ok to post a link to it on here and never post about it again here?

    Better Born Lucky Than Rich.



  • Moderators, Recreation & Hobbies Moderators, Paid Member Posts: 19,491 Mod ✭✭✭✭Trigger


    I can't see why not, but I don't mod AH, best to PM @Sephiroth_dude and he can advise



  • Registered Users, Registered Users 2 Posts: 611 ✭✭✭mrm


    Must be a real power trip for the chosen few.

    Wagging fingers at others for using dodgy boxes.

    Deciding what can and cannot be posted.

    Setting the quota for voting (2/3rds is not sufficient).

    Keeping this dead topic alive with their wishful thinking - ' ok not today…but next week, wait til you see…next week'. A lot of 'next weeks' seems to have past.



  • Registered Users, Registered Users 2, Paid Member Posts: 8,037 ✭✭✭jj880


    Former mods union. Necro PMs mods. Within an hour the hammer comes down. Ive seen plenty of other former mods at the same shyite. Sad enough carry on.

    >>> BOARDS IS IN TROUBLE - SUBSCRIPTIONS NEEDED <<<

    Info 👉️ Important News!!

    Progress 👉 https://keepboardsalive.com/

    Subscribe 👉️ https://subscriptions.boards.ie/



  • Registered Users, Registered Users 2 Posts: 4,284 ✭✭✭selectamatic


    Firestick thread maybe?

    https://www.boards.ie/discussion/2058088307/firestick-general-discussion-thread#latest



  • Advertisement
  • Registered Users, Registered Users 2, Paid Member Posts: 58,685 ✭✭✭✭Necro


    There's always the ignore button. Isn't that what you said😉



Advertisement
Advertisement