Menu
Suggested Searches
Recent Searches
Suggested Searches
Product Ratings
Resources
Chat With AskCR
Resources
All Products A-ZThe payment for your account couldn't be processed or you've canceled your account with us.
Re-activateMy account
Sign In
My account
Sign In
Media Room
Release date 04/26/2021
The Consumer Reports (CR) Digital Lab recently discovered a security flaw in the TiVo Stream 4K streaming media device that TiVo has now fixed after the company was notified of the issue by the nonprofit consumer research, testing, and advocacy organization.
During recent testing of various privacy and security aspects of streaming media devices, researchers at CR’s Digital Lab found that the TiVo Stream 4K transmitted user data in clear plaintext, which could result in users’ sensitive information being intercepted. The data that was exposed included the SSID of the user’s WiFi network, as well as the city, state, and the latitudinal and longitudinal coordinates of the network's location. This could be used to pinpoint users’ actual street addresses under certain circumstances.
“Streaming players, like many smart devices, collect and transmit sensitive data that you wouldn’t want to fall into the hands of a malicious actor. That’s why this data should be encrypted before it’s transmitted over the network,” said Ben Moskowitz, Director of Consumer Reports’ Digital Lab. “We applaud TiVo for expeditiously fixing this security vulnerability and making its devices safer for consumers.”
CR also tested the TiVo Edge DVR, which has built-in streaming capability, and noticed that it, too, was sending out unencrypted data. However, none of the information being transmitted was sensitive user data, such as IP addresses.
TiVo issued a software patch for the Stream 4K player soon after we notified the company, but CR’s testing showed that it didn't remedy the problem. However, subsequent CR testing confirmed that a second update pushed out in March did correct the issue. The device is no longer sending out unencrypted data. The Stream 4K was the only one of the 18 tested devices in CR’s streaming media player ratings that had this particular vulnerability.
Founded in 1936, CR has a mission to create a fair and just marketplace for all. Widely known for our rigorous research and testing of products and services, we also survey millions of consumers each year, report extensively on marketplace issues, and advocate for consumer rights and protections around safety as well as digital rights, financial fairness, and sustainability. CR is independent and nonprofit.
© 2021 Consumer Reports. The material above is intended for legitimate news entities only; it may not be used for advertising or promotional purposes. Consumer Reports® is an expert, independent, nonprofit organization whose mission is to work side by side with consumers to create a fairer, safer, and healthier world. We accept no advertising and pay for all the products we test. We are not beholden to any commercial interest. Our income is derived from the sale of Consumer Reports® magazine, ConsumerReports.org® and our other publications and information products, services, fees, and noncommercial contributions and grants. Our Ratings and reports are intended solely for the use of our readers. Neither the Ratings nor the reports may be used in advertising or for any other commercial purpose without our prior written permission. Consumer Reports will take all steps open to it to prevent unauthorized commercial use of its content and trademarks.
Founded in 1936, CR has a mission to create a fair and just marketplace for all. Widely known for our rigorous research and testing of products and services, we also survey millions of consumers each year, report extensively on marketplace issues, and advocate for consumer rights and protections around safety as well as digital rights, financial fairness, and sustainability. CR is independent and nonprofit.
© 2021 Consumer Reports. The material above is intended for legitimate news entities only; it may not be used for advertising or promotional purposes. Consumer Reports® is an expert, independent, nonprofit organization whose mission is to work side by side with consumers to create a fairer, safer, and healthier world. We accept no advertising and pay for all the products we test. We are not beholden to any commercial interest. Our income is derived from the sale of Consumer Reports® magazine, ConsumerReports.org® and our other publications and information products, services, fees, and noncommercial contributions and grants. Our Ratings and reports are intended solely for the use of our readers. Neither the Ratings nor the reports may be used in advertising or for any other commercial purpose without our prior written permission. Consumer Reports will take all steps open to it to prevent unauthorized commercial use of its content and trademarks.