Jumping off a career on YouTube is everyone’s dream, but it takes a ton of work and skill to actually turn it into anything. If you want to start building up your own brand you might be interested in our YouTube Master Class bundle to teach you everything there is to know to create your […]
Samsung has dropped its Android Pie update roadmap addressing all the devices which will receive it – and disappointingly, many of the company’s customers will be waiting a long time for their slice of Pie. Samsung has a long history of long delays when updating their devices to the newest versions of Android, though they […]
Google was warned of a bug in its Chromecast media streaming stick years ago, but did not fix it. Now, hackers are exploiting the bug — and security researchers say things could get even worse.
A hacker, known as Hacker Giraffe, has become the latest person to figure out how to trick Google’s media streamer into playing any YouTube video they want — including videos that are custom-made. This time around, the hacker hijacked thousands of Chromecasts, forcing them to display a pop-up notice that’s viewable on the connected TV, warning the user that their misconfigured router is exposing their Chromecast and smart TV to hackers like himself.
Not one to waste an opportunity, the hacker also asks that you subscribe to PewDiePie, an awful internet person with a popular YouTube following. (He’s the same hacker who tricked thousands of exposed printers into printing support for PewDiePie.)
The bug, dubbed CastHack, exploits a weakness in both Chromecast and the router it connects to. Some home routers have enabled Universal Plug and Play (UPnP), a networking standard that can be exploited in many ways. UPnP forwards ports from the internal network to the internet, making Chromecasts and other devices viewable and accessible from anywhere on the internet.
“We have received reports from users who have had an unauthorized video played on their TVs via a Chromecast device,” a Google spokesperson told TechCrunch. “This is not an issue with Chromecast specifically, but is rather the result of router settings that make smart devices, including Chromecast, publicly reachable,” the spokesperson said.
That’s true on one hand, but it doesn’t address the years-old bug that gives anyone with access to a Chromecast the ability to hijack the media stream and display whatever they want, because Chromecast doesn’t check to see if someone is authorized to change the video stream. (Google did not respond to our follow-up question.)
Hacker Giraffe sent this YouTube video to thousands of exposed Chromecast devices, warning that their streams could be easily hijacked. (Screenshot: TechCrunch)
Bishop Fox, a security consultancy firm, first found the bug in 2014, not long after the Chromecast debuted. The researchers found that they could conduct a “deauth” attack that disconnects the Chromecast from the Wi-Fi network it was connected to, causing it to revert back to its out-of-the-box state, waiting for a device to tell it where to connect and what to stream. That’s when it can be hijacked and forced to stream whatever the hijacker wants. All of this can be done in an instant — as they did — with a touch of a button on a custom-built handheld remote.
Ken Munro, who founded Pen Test Partners, says there’s “no surprise that somebody else stumbled on to it,” given both Bishop Fix found it in 2014 and his company tested it in 2016.
“In fairness, we never thought that the service would be exposed on the public internet, so that is a very valid finding of his, full credit to him for that,” Munro told TechCrunch.
He said the way the attack is conducted is different, but the method of exploitation is the same. CastHack can be exploited over the internet, while Bishop Fox and his “deauth” attacks can be carried out within range of the Wi-Fi network — yet, both attacks let the hacker control what’s displayed on the TV from the Chromecast, he said.
Munro said Google should have fixed its bug in 2014 when it first had the chance.
“Allowing control over a local network without authentication is a really silly idea on [Google’s] part,” he said. “Because users do silly things, like expose their TVs on the internet, and hackers find bugs in services that can be exploited.”
Hacker Giraffe is the latest to resort to “Good Samaritan security,” by warning users of the issues and providing advice on how to fix them before malicious hackers take over, where tech companies and device makers have largely failed.
But Munro said that these kinds of attacks — although obnoxious and intrusive on the face of it — could be exploited to have far more malicious consequences.
In a blog post Wednesday, Munro said it was easy to exploit other smart home devices — like an Amazon Echo — by hijacking a Chromecast and forcing it to play commands that are loud enough to be picked up by its microphone. That’s happened before, when smart assistants get confused when they overhear words on the television or radio, and suddenly and without warning purchase items from Amazon. (You can and should turn on a PIN for ordering through Amazon.)
To name a few, Munro said it’s possible to force a Chromecast into loading a YouTube video created by an attacker to trick an Echo to: “Alexa, order an iPad,” or, “Alexa, turn off the house alarm,” or, “Alexa, set an alarm every day at 3am.”
Google wants to make it easier to donate to your favorite charities and organizations, and they started that process by allowing donations directly from the Play Store last year. Now they’re going a step further and adding quick donation options right into Google Assistant and your local Google Home devices. The process really is […]
Writing a screenplay can be tough, but that’s where programs like WriterDuet Pro come in. Instead of wasting time doing everything manually and by hand, you can let WriterDuet streamline the process, eliminate distractions, and help you craft the best product you’re capable of. The program offers real-time live collaboration, easy drafting and outline support, […]
Nokia has been in the Android game for two years now, after being sold by Microsoft to HMD Global – the latter of which comprises of many former Nokia staff. The resurrected Nokia released a slew of mediocre and overpriced phones in 2017, and some genuinely great phones in 2018, including a supposed […]
It’s on like Donkey Kong! We’ll be seeing you next week on January 9, 2019 at 6:00 PM where we’ll mingle and run a full TC pitchoff with a bunch of great hardware companies. I’ve added 40 extra tickets so hurry!
The event will be held at Work In Progress, 317 South 6th Street. Special thanks to those amazing folks who opened their doors to us during one of the busiest weeks in LV.
I’ve contacted the companies that will be pitching via email. If anyone drops out, I’ll choose some more so there is still a chance to pitch.
Very special thanks go out to Shenzhen Valley Ventures, a hardware-focused venture capital firm for engineers, by engineers. They will be on hand to talk about their firm and would love to hear your pitches… and they are paying for the beer and pizza!