Watching You Watch

The Princeton University and the University of Chicago published a study of The Tracking Ecosystem of Over-the-Top TV Streaming Devices.

Their findings are that most channels have trackers implemented (for advertising and analytics) and also Identifier and Information leakage.

For network engineers it’s interesting that those devices use unencrypted traffic and for encrypted traffic those devices failed to verify the server certificate or weak cipher suits are used.

Also the API used on those devices makes it possible to exfiltrate unique device identifiers (MAC address, serial number), WiFi SSID and Geolocation data.

Link: Watching You Watch: The Tracking Ecosystem of Over-the-TopTV Streaming Devices