upvote
I was trying to figure out why we saw so many fraudulent applications from Vietnam for a service which is restricted to the United States, especially because they were all getting rejected - it seemed like even the laziest spammer would lose interest in something they couldn’t monetize.

A guy in Vietnam mentioned that one of the largest ISPs there used these really dodgy Chinese modems which were so notoriously insecure that it was apparently common knowledge that you should replace them if performance was slow because that was a sign that yours was being used by a botnet. Apparently the cost of access to one of those nodes was so low that the spammers don’t even really monitor their bots.

reply
Those TV streaming boxes really are (from a cybersecurity perspective) probably one of the worst things you can buy. Here is the "Darknet Diaries" Episode on them: https://darknetdiaries.com/episode/172/
reply
Superbox 3 is coming up at DEF CON next Friday!

https://hackertracker.app/defcon34/content/67257

reply
Since these are poorly engineered, wonder how easy it'd be to reverse-engineer one and just get the free streaming on a non-scam device.
reply
See CoreELEC/LibreELEC/etc - totally replaces the (potentially dodgy) Android OS on these kind of streaming boxes with a stripped down Linux+Kodi setup
reply
If it's something like a Firestick (or the knock-off featured in the article), you're really just connecting to Content Provider servers to handle auth and content streaming, right? They're just OSes designed to run Netflix and Hulu. Would be hard to spoof I think
reply
Indeed. Owning the streaming box lets you loose on whatever network it's on, but it doesn't actually get you inside the content gardens; those are separately managed by teams of people much more motivated to protect their IP.
reply
I wonder to what degree malice can be engineered to look like incompetence?
reply
Try examining the old entries from the https://en.wikipedia.org/wiki/Underhanded_C_Contest.
reply