logoalt Hacker News

sphars • today at 4:26 PM • 1 reply • view on HN

Friends don't let friends use those shady streaming boxes

https://krebsonsecurity.com/2025/11/is-your-android-tv-strea...


Replies

ssl-3 • today at 5:37 PM

The pre-stuffed, pre-configured, plug-n-play, extra-spooky-box method described in the article is just one of many methods.

Someone I know buys cheap "IPTV" service by the year. Access is paid for by buying potted plants or something else that looks random on some web store and is delivered in the form of a .m3u playlist that hides behind a username/password pair.

The usual way they use it is with slimey-feeling closed-source sideloaded apps on mass-market streaming devices from such unknown companies as Amazon and Google, or directly on a smart TV itself. Wherein: Despite the dingy back-alley ambience of the subscription and installation processes, the UI is snappy and responsive in use.

And the slimey software is also avoidable. Since it's all based around a playlist that is hiding behind basic http auth, it also works with open-source projects like Dispatcharr, which in turn can emulate an HDHomeRun network-connected OTA TV tuner. This combination can then present new possibilities, like live streaming TV for Plex users.

(It'd all be very interesting to me if I had any motivation to sit down and absorb live television like a slug, but I didn't do much of that even when I worked for a cable company and got the uber-premium package for free as a perk.)