I expected to have published the fourth and, hopefully, final installment of the Cell Phones are Radios blog by now. This is where we’ll talk about the convergence of technologies like phones and radios, dirty detectives, and post-military haters. These last weeks, however, I’ve been in the Bay Area tending to my continued survival as a victim of real estate mobbing in northeast Seattle. A critical component of surviving in this unfortunate situation is continuing to work in San Francisco and doing what I have to do to ensure that I have work going forward.
Living in this situation is pretty tough, so some months it’s difficult to write the kind of blog entries that I’d like to write while holding everything together. Nevertheless, with any luck, the final installment of Cell Phones are Radios won’t be long coming, and after that, I’m looking forward to writing about how televisions don’t have to be smart to get hacked. Tonight, however, so people don’t forget this writer, a Seattle woman who is the victim of the human rights crime that is real estate mobbing and all the felony crimes it entails, I’m finishing my day with a short post about a news report on some vulnerabilities that could reach many of us in our own homes.
A few weeks ago I caught a brief spot on some Bay Area news broadcast about the vulnerabilities that Consumer Reports recently found in Samsung televisions, on televisions using the Roku TV “smart-TV” platform, and on the Roku streaming media player. Consumer Reports found that unsophisticated hackers “could change channels, play offensive content, or crank up the volume.” Moreover, this exploit is easily effected over the web and from “thousands of miles away” (Samsung and Roku Smart TVs Vulnerable to Hacking, https://www.consumerreports.org/televisions/samsung-roku-smart-tvs-vulnerable-to-hacking-consumer-reports-finds/).
[The exploits] allowed researchers to pump the volume from a whisper to blaring levels, rapidly cycle through channels, open disturbing YouTube content, or kick the TV off the WiFi network.
The exploits didn’t let us extract information from the sets or monitor what was playing. The process was crude, like someone using a remote control with their eyes closed. But to a television viewer who didn’t know what was happening, it might feel creepy, as though an intruder were lurking nearby or spying on you through the set (emphasis mine).
The source of the vulnerability is the application programming interface (API) that Roku provides to developers who write applications for the Roku platform. According to Eason Goodale, lead engineer at Disconnect, “Roku devices have a totally unsecured remote control API enabled by default. This means that even extremely unsophisticated hackers can take control of Rokus. It’s less of a locked door and more of a see-through curtain next to a neon ‘We’re open!’ sign.” Consumer Reports noted that the unsecured API had been discussed in online programming forums since 2015.
Having learned about Samsung’s release of the application programming interface (API) that allows for the firmware manipulation on many Samsung television models smart and dumb, that reference wasn’t earthshaking. The same APIs that ensure interoperability between software components and operating systems become a platform for the bad acts of black hats and other malicious agents. And even if these APIs weren’t published, many brands of televisions build the firmware that controls their televisions on the same open source operating system: Linux. Some companies avoid open source code bases because of the hacking they invite. As for the Roku, the vulnerabilities of any device—the attack surface—increase with the number of applications and the popularity of the platform with application developers. What is more interesting is how discussion of the vulnerabilities that are intrinsic to IoT (Internet of Things) devices has arrived in the mass media and is creeping into the awareness of us all.
Gary Ellison of Roku responded that the Consumer Reports study was a “mischaracterization of a feature.” Ellison states that the API is not enabled by default and can be disabled by going to Settings>System>Advanced System Settings>External Control>Disabled.” According to Ellison, there is therefore “no security risk.”
Devices are complex, however, and consumers cannot be expected to understand the effects of settings that have no obvious immediate effect, much less to know what an API is and how that affects their safety in their own homes. Roku spokeswoman Tricia Mifsud admitted to NPR that “a consumer could click on something that exposes their computer,” and the remote control app does allow for changing the volume or channel. At the same time, she stresses that this can cause limited damage — “there is no security risk to a customer’s account or to the Roku platform” (‘Consumer Reports’ Says Roku, Samsung Smart TVs Have Security Vulnerabilities, https://www.npr.org/sections/thetwo-way/2018/02/07/584018673/consumer-reports-says-roku-samsung-smart-tvs-have-security-vulnerabilities).
When a hacker controls your devices, it is this unfamiliar phenomenon that creates the uncomfortable feeling that someone is spying on you. Because when someone can manipulate your environment or speak to you in the privacy of your home, the natural assumption is that they must be watching you. One of the aspects of the phenomenon of being mobbed that I’ve remarked on in other posts has been the likelihood that perhaps even most of the time, the mobbers just listen, or that they infect your devices and just talk without listening at all.
This seems to be the case at my home in Seattle these days, and possibly once a digital-era mobbing is underway and the mobbers have already used camfecting, spying, or even an infrared-enabled drone to gather whatever information they need to make good their crime. By now, I’ve covered the cameras in my laptops and keep my PDAs (personal devices) off the WiFi for the most most.
The extent to which mobbers only use sound and not vision to make you feel that you are being watched is something I’ve speculated on in numerous blog entries. Bullying by cell phone is also called “mobbing” and those who would mob someone in the physical world may well have honed their skills bullying their victims by voice alone. Between VoIP, satellite phones, and shortwave radio, the possibilities are myriad: In my own case, it has seemed likely that the mobbers of northeast Seattle also harass remotely by phone, using directional speakers and radio from unseen positions; or that they make the most of the cordless base stations of those who believe that landlines are safer than smart phones. If surveillance drones using infrared track people remotely through their homes, that’s just another way to remotely acquire information to use against the victim. Either way, what a way to make someone crazy, at least make them appear crazy when they report the crime, and to simultaneously minimize liability.
The statements of Ellison and Mifsud minimize the potential for harm by hackers whose target is not the customer account information or the Roku platform. Taking control of devices in the privacy of someone’s home, cranking up the volume, changing the channels or disconnecting their television from the WiFi service does irrevocably harm. The individual who believes that an intruder lurks nearby or might be spying on him through his television is being terrorized. Instead of his social security number or banking information being stolen, he is being robbed of the sense of integrity, of privacy, of well-being and home that is fundamental to his life, to her life, to my life. Criminals who intrude into your devices are breaking into your home. Crimes like this may not stop with taking your personal information. Criminals who do such things may be real estate speculators, wacko neighborhood watches, or hate groups whose goal is to rob you of your home.
It seems like we live in a time that is unprecedented for consumers. The devices we rely upon for communication, entertainment and, indeed, our very livelihoods, make us unsafe. The network services we are provided by monopolistic companies like Comcast share out the routers in our homes as “hot spots” and provision us with services that black hats cut their teeth on. When products have been found to be “defective” in the hands of smaller groups of consumers, the result has been product liability and class action lawsuits. When organized crime see an opportunity and put malware on private computers, you’re lucky if the local police will take a report.
Will we all just be casualties of police ignorance as, one by one, we’re hauled into court for reporting the truth?

Leave a Reply