You might want to listen this https://darknetdiaries.com/episode/172/
This wasn't nearly as interesting as the headline made it sound.
It's a physical box you purchase to effectively break the law, so some of the architecture is going to be shady because it has to be.
- it polls multiple domain servers to get around blocks (and probably updates that list regularly)
- it obfuscates the endpoints it hits because they're trying to secure a box they're handing to someone else from tinkering that would allow people to access their (pirate) services without buying a box.
- it obfuscates its user agent when connecting to a weather service to avoid being blocked.
There's nothing special or nefarious here. Indeed I've worked on projects that had to take the same considerations into account.
The "someone else's Hulu account" claim sounds like bullshit to me because it doesn't make sense from a business perspective. They'd want to control the accounts in question and rotate the passwords regularly, again to avoid freeloaders. More likely they've paid for 25ish Hulu subscriptions in every region (hence the initial call for IP geolocation) and are then relaying credentials to a box based on this info.
The only really sketchy thing in this whole video was the disabling of TLS checking, which was likely done to get around sketchy pirate websites with bad or nonexistent certs. It wasn't clear though which part of the OS this applied to. If it's only doing this for the pirate streaming, that's sort of a bullet you have to take if you want the service. So long as the only data being sourced unencrypted/unverified is some audio and video, you're fine (assuming you've already accounted for streaming such data in your jurisdiction, ie. you've got a VPN). If you're pulling down software updates though, you're gonna have a bad time.
That's pretty wild man. Reminds me of a while ago, a lot of people got busted locally for selling loaded Kodi boxes at the flea market. I bought one out of mild curiosity from a greasy individual who I could tell wasn't the front man of the operation. Anyway, I booted it an ran wireguard against it. I don't have the skill this guy does in the video, but what I did see were a lot....a lot..of sketchy Chinese ip addresses. So, i shut it down and it resides in the junk bin.
I found this interesting: https://safereddit.com/r/vSeeBox/comments/1hhibu0/vseebox_for_real/
Particularly this comment:
u/Fun-Device-9702
Apr 14 '25
I got a couple strange emails that were definably spam after hooking one up, so I wonder if there some kind of back door program working on these.
Grabbing the stream from a legit iptv provider and sharing it via P2P... love it. chef's kiss
There are much better resources about these things. The YouTube comments are talking about very basic mistakes like not knowing what a shared library is. This is a similar device: https://www.youtube.com/watch?v=lrV0pbx7U7E
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
