{"id":181,"date":"2023-11-23T13:32:05","date_gmt":"2023-11-23T13:32:05","guid":{"rendered":"http:\/\/localhost\/wordpress-again\/?p=13"},"modified":"2023-11-23T13:32:05","modified_gmt":"2023-11-23T13:32:05","slug":"electronic-frontier-foundation-calls-for-ftc-action-on-poisoned-set-top-boxes","status":"publish","type":"post","link":"https:\/\/dekpo.cciformationlyon.fr\/wordpress\/2023\/11\/23\/electronic-frontier-foundation-calls-for-ftc-action-on-poisoned-set-top-boxes\/","title":{"rendered":"Electronic Frontier Foundation Calls for FTC Action on Poisoned Set-Top Boxes"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">TV set-top boxes infected with malware are being sold online at Amazon and other resellers, and the&nbsp;<a target=\"_blank\" href=\"https:\/\/www.eff.org\/\" rel=\"noreferrer noopener\">Electronic Frontier Foundation<\/a>&nbsp;wants the Federal Trade Commission to put a stop to it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cRecent reports have revealed various models of Android TV set-top boxes and mobile devices that are being sold by resellers Amazon, AliExpress, and other smaller vendors to include malware before the point of sale,\u201d the EFF wrote Tuesday in a letter to the FTC.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThese include malware included in devices by Chinese manufacturers AllWinner and RockChip,\u201d the letter continued. \u201cWe call on the FTC to use its power\u2026to sanction resellers of devices widely known to include harmful malware.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The EFF revealed in May that several set-top box models \u2014 AllWinner T95, AllWinner T95Max, RockChip X12-Plus, and RockChip X88-Pro-10 \u2014 were infected out of the box with malware from the BrianLian family. \u201cThese devices were widely reported to contain malware, and Amazon and others still made them available,\u201d said EFF Senior Staff Technologist Bill Budington.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWe wanted to see the resellers take the devices down and make sure their customers are protected,\u201d he told TechNewsWorld. \u201cUnfortunately, that\u2019s not what we saw, and we thought it was time to bring this up to regulatory parties.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">FTC spokesperson Julianna Gruenwald Henderson said the agency had no comment on the letter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cSecurity is of the utmost importance to Amazon,\u201d spokesperson Adam Montgomery told TechNewsWorld. \u201cWe are working to learn more about these findings and will take appropriate action if needed.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Malware-Infected Boxes: Gateway to Click-Fraud<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In its letter, the EFF explained that the devices, when first powered on and connected to the internet, will immediately begin communicating with botnet command and control servers. From there, the devices connect to a vast click-fraud network. All this happens in the background of the device, without the buyer\u2019s knowledge.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWe believe the resellers of these devices bear some responsibility for the broad scope of this attack and for failing to create a reliable pathway for researchers to notify them of these issues,\u201d the EFF wrote.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It noted that security researcher Daniel Milisic, who deeply researched and published his findings on the malware infecting the devices, mentioned finding it difficult \u2014 if not impossible \u2014 to reach out to Amazon and report the issue.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It added that EFF also reached out to Amazon, yet the products are still available.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWhile it would be impractical for resellers to run comprehensive security audits on every device they make available,\u201d the letter said, \u201cthey should pull these devices from the market once they are revealed and confirmed to include harmful malware.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Legal Exposure for Consumers Unaware of Malware<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The EFF warned that consumers with the infected devices could face legal perils.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThese devices put buyers at risk not only by the click-fraud they routinely take part in, but also the fact that they facilitate using the buyers\u2019 internet connections as proxies for the malware manufacturers or those they sell access to,\u201d the letter explained.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThis means that any nefarious deeds done using this proxy will look as though they were originating from the buyers\u2019 internet connection, possibly exposing them to significant legal risk,\u201d it continued. \u201cThis can result in real harm to buyers of these devices, presenting an unacceptable risk which must be addressed.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The EFF called on the FTC to sanction sellers of the devices because they present \u201ca clear instance of deceptive conduct: the devices are advertised without disclosure of the harms they present.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It also urged the FTC to use its regulatory power to make it easier for customers to report compromised devices either directly to the device vendors or to the commission itself, which can then inform the vendor and ensure it takes remedial action.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>TV set-top boxes infected with malware are being sold online at Amazon and other resellers, and the&nbsp;Electronic Frontier Foundation&nbsp;wants the Federal Trade Commission to put a stop to it. \u201cRecent reports have revealed various models of Android TV set-top boxes and mobile devices that are being sold by resellers Amazon, AliExpress, and other smaller vendors [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":41,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,7],"tags":[19],"class_list":["post-181","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-internet","category-toutes","tag-tv"],"_links":{"self":[{"href":"https:\/\/dekpo.cciformationlyon.fr\/wordpress\/wp-json\/wp\/v2\/posts\/181","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dekpo.cciformationlyon.fr\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dekpo.cciformationlyon.fr\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dekpo.cciformationlyon.fr\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dekpo.cciformationlyon.fr\/wordpress\/wp-json\/wp\/v2\/comments?post=181"}],"version-history":[{"count":0,"href":"https:\/\/dekpo.cciformationlyon.fr\/wordpress\/wp-json\/wp\/v2\/posts\/181\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dekpo.cciformationlyon.fr\/wordpress\/wp-json\/wp\/v2\/media\/41"}],"wp:attachment":[{"href":"https:\/\/dekpo.cciformationlyon.fr\/wordpress\/wp-json\/wp\/v2\/media?parent=181"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dekpo.cciformationlyon.fr\/wordpress\/wp-json\/wp\/v2\/categories?post=181"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dekpo.cciformationlyon.fr\/wordpress\/wp-json\/wp\/v2\/tags?post=181"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}