#iot_
What's actually inside a £30 Android projector
I put a cheap 'smart' Android projector on my network before trusting it on the TV, and spent a weekend pulling it apart. Inside: an unauthenticated root register console listening on the LAN, SELinux switched to Permissive, two shipped root backdoors, an app store that installs unsigned APKs over plain HTTP with a hardcoded signing key, and cleartext telemetry home. The one thing they got right was firmware signing, and everything around it leaks.