Gandalf_The_Grey
Level 84
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
- Apr 24, 2016
- 7,595
Read the full story here at Sick.Codes:The following piece is the culmination of a three-month long investigation into Smart TVs running Android. Having lived through this research experience, I can wholeheartedly say that there were multiple moments that I, and another security researcher that I met along the way, couldn’t believe what was happening. On multiple occasions I found myself feeling as though, “you couldn’t even make this up…”
I’m a security researcher, a freelance developer, and a hacker.
Please follow me on Twitter @sickcodes here: https://twitter.com/sickcodes
The second researcher in this story is John Jackson: https://twitter.com/johnjhacking, an Application Security Engineer with Shutterstock, and a hacker.
We met about half way through this, and I have included his experience too.
Initial Research
Near the end of September, while conducting research into low-end Android boxes, I came across a number of serious flaws in the way in which these devices were being designed.
Without delving into the nuances of each device, all of the Smart TV products are Android based.
There are four types of TV products in the TV market:
All of them are ARM based single board computers (SBCs). Most of the dies are 32bit, some are 64bit, but all of them are like a little Raspberry Pi competitor, focusing on GPU performance through the small, but powerful, Mali GPUs.
- TV Sticks
- TV Boxes
- Smart TVs
- Android TVs
Some of the products that I investigated were “factory-flawed” and deliberately insecure.
![sick.codes](https://sick.codes/wp-content/uploads/2020/11/TCL-Android-TV-Vulnerability-L.png)
Extraordinary Vulnerabilities Discovered in TCL Android TVs, Now World’s 3rd Largest TV Manufacturer. - Sick Codes - Security Research, Hardware & Software Hacking, Consulting, Linux, IoT, Cloud, Embedded, Arch, Tweaks & Tips!
The following piece is the culmination of a three-month long investigation into Smart TVs running Android. Having lived through this research experience, I can wholeheartedly say that there were multiple moments that I, and another security researcher that I met along the way, couldn’t believe...
![sick.codes](https://sick.codes/wp-content/uploads/2016/12/cropped-ExcerptThumnail-32x32.png)