Turning a TV set-top box into a Linux computer (2022)
zeus.ugent.be
zeus.ugent.be
It's optimized for mainline Linux and since u-boot supports UEFI booting, you can just throw a downloaded Fedora arm64 image on it and it will boot.
I know what you meant, but I have known and loathed hardware for which this would occur quite literally
I eventually just bought an intel NUC which I saw as a big defeat but also a remarkably practical solution.
I guess it requires them to be on wired network, but if they're in a closet, that's probably the case anyway.
Pony up a bit more cash for "high endurance" grade (mostly MLC), or even industrial SLC cards at a much higher price point. My current roster for my small pi4 cluster is a mix of Samsung Pro Endurance, SanDisk High Endurance and Kioxia High Endurance. So far they've been working pretty great for me. Last time I checked they're about $15-25 a pop, which isn't cheap but not that bad either. I've been meaning to checkout SanDisk's max endurance which supposedly has much better write cycles, which I'll probably do after the card in my dashcam dies.
*On SBCs you could do something *like* trim, but it's not as straight forward, and support depends on the controller of the card wildly.
Their display controller driver was fun to figure out. https://github.com/torvalds/linux/tree/master/drivers/gpu/dr...
Great article!
[1] related to security of user private data
These boxes are most of the times locked, whereas they could be repurposed for many interesting uses (linux machines, android boxes, educational devices...), now they will be thrown away, remain in closets/garages or at the best be recycled.
Tried to unlock my Vodafone TV box (Sagemcom DIW387 if I'm not mistaken), but with no luck since there is no community to "hack" it.
And that isn't really addressing the fact that many companies don't have the funding or the will to secure these devices.
I don't know for sure but I do strongly suspect it.
If it wouldn’t, they have zero incentive to do it.
Plus, if the parts of the underlying software that are not going to be reused without modification in future products were open sourced, then for most semi-successful products there is the possibility of the code base growing, new tools and utilities being created, and information being generated that would improve their future products.
The only potential downside is that if the newer products that are released are retrogressive or are deemed to not be enough of an improvement then their own older systems with better software might crowd out their market share.
This would be a dramatic blow to sales of products like iPhones which have not had any MAJOR hardware upgrades in a few years, but for SBCs, a new processor, additional cores, faster memory, stronger graphics cards, USB-C, there's dozens of small improvements each generation that make a newer version worthwhile to customers.
In cases I am familiar with, you would need the sign off of 4 separate companies. I’m 99% certain one of them would outright refuse. I’m also 99% certain the others would be ambivalent and it would fall to the bottom of a bottomless queue.
Don't try to pass off lockdown nonsense as "security". If your "security" depends on a locked down end user device it's a broken design from the start.
I'd be willing to bet that the restrictions actually enforce the execution of insecure components, almost every locked down device ends up that way because the chain of vendors involved in approving updates doesn't really care about anything that doesn't affect their profit margins.
Just admit it's all about the margins, don't lie about security.
I think it's holding the industry back somewhat. Having a bit more power might make these boxes a home hub, a video calling device, a gaming device, or at least a bit future-proof.
One thing I like to do with Android TV devices is install tailscale on them. At least I can ADB to them from anywhere, and I can also setup the exit node. They use hardly any power, so it's a nice solution to have access to your home network or home internet connection.
> In theory, we might be asked to give this device back. In practice, these devices are written off as soon as they’re sent to customers.
In my country, there are various ISPs with the same OEM boxes from SDMCtech. They went to the trouble of asking manufacturer to put a custom SDIO encryption chip onboard. If someone dares to touch the firmware and/or included apps (not system, but phone-home ones) the device automatically bricks forever. Not even a NAND change fixes this, as the SoC/cryptochip/NAND trio is somehow "mated" at factory. This derived in a literal invasion of these at flea markets, charity stores etc. Almost none of them work, and if they do they are thoroughly locked.
Some people like me had limited success tweaking things through ADB. This box seems to accept a launcher change as long as the original isn't erased. That works until the box updates itself and bitches again about "pirating/unauthorized use", which is quite frequent.
Our ISPs are well aware of said e-waste, and still won't budge their up-the-ass attitude.
I spent a few years dealing with some of these STBs and yeah, they make great little computers. Such a waste. Just like smartphones,
Had a pogoplug that I was able to repurpose as a linux server for some odd cron jobs and occasional backups.
Assuming there are no such constraints to revert, what other general purpose consumer devices are hack friendly and can be turned into low powered linux boxes ?
The main difficultly is usually unlocking the bootloader.
I have one, it worked fine and is of course highly recommended since the combination of a cheap way to get signals into the computer and Sigrok's protocol analyzers makes things really neat.
[1]: https://www.infineon.com/cms/en/product/universal-serial-bus...
I would love to repurpose them. Where do I start with ?
(Edit: or google the PCB board markings, maybe somebody already did this)
Here's one of these boards, just search for "ahd dvr board".
https://www.alibaba.com/countrysearch/CN/dvr-motherboard.htm...
Here are a few pages I found that could turn out interesting:
https://securitycamcenter.com/firmware-chinese-dvr-nvr-secur...
And as widely reported, they're quite vulnerable.
https://github.com/tothi/pwn-hisilicon-dvr
https://www.exploit-db.com/exploits/44004
I wonder if those vulnerabilities could be used to gain root access to the hardware in order to either patch it and make decent security devices, or repurpose them completely, as the hardware is interesting and dirt cheap.
These may have an ARM Cortex A7 dual-core at 1.3Ghz according to this datasheet for the HiSilicon hi3520dv400 (the 4 channel version):
http://wangxunic.com/wp-content/uploads/2019/05/Hi3520DV400....
Not bad at all. And with DDR3.
Ultimately I decided to work on something else as I have plenty of more interesting hardware hacking projects to work on, but it was fun practice to overcome the watchdog.
How did you determine what addresses to read things into? (the chainloaded bootloader, then its initrd/ FDT / etc.).
I'm a hobbyist that's been tinkering with uboot now and again for years and can never figure out the right addresses for stuff, or where / how to learn this.
I assume this memory is subsequently released for the OS? Or does the OS just work around it?
Are you hobbling your runtime experience in some way if you load to the wrong address?
I think (not entirely sure) that the kernel gets relocated to a more or less fixed address in memory anyway, this won't affect your runtime experience.
The only decent cpu atm that will eventually show up in TV boxes is the Rockchip Rk3588, but they aren't as cheap as some old s905x chips, and software support is very early days, so it will be a while before we see them in any android tv boxes.
The key does seem to be you need at least a quad-core of high-efficiency cores. The Nvidia Tegra X1 found in the Nvidia Shield and Switch runs fine even though it has even older A57 cores(predecessor to the A72). Compare this to rockchip's last-gen Rk3399, which only has 2x A72 cores (and 4x A53 cores) and is pretty slow compared to a Rpi 4 (but that could also be because of crap software support on the Rockchip side)
This seems similar, if not identical, to the free streaming box I told Xfinity they could keep. Might go revisit that decision now.
However with so many being available on Ebay et al and the HD-less (DN360T) forcing people onto streaming services, I think its only right to reprovision these to work in a hive networked manner with external storage so people can store as much broadcast footage as they have storage for, and stream from any device.
Being an early adopter of Media Portal over a decade ago, but finding it impossible to secure windows even back then despite only using it for satellite transmissions, I think Linux should receive more attention now.
a) the box was useless and
b) would never be asked for again and
c) (as I've said) would just be charged a certain amount for non-return...
I hardly see how it's an ethical activity. If the owner was one person that was needing this device -- fine. But this is just a company doing business...
The "wildly popular" part came when people realized BRCM was dumping these boards cheaper than any existing Linux SBC at the time. The educational angle is long gone.
I would agree that most of the Pis sold are not used for education, but that doesn't diminish their importance in that area.
https://forum.armbian.com/topic/12656-csc-armbian-for-rk322x...
People immediately MitM'd these devices to get unlimited free bonus stuff, and the forum was copyright struck to hell.
These devices are programmed so badly that once you give any user any modicum of control over them, you can bypass almost every restriction your TV provider can think of. Modify one or two files and you've got an excellent piracy box.
Personally, I think this whole situation is terrible and I think that it's up to providers to fix their shitty DRM, but legally speaking these boxes don't become your property.