Another possibility, I suppose, is that the STB might be hacked. I would have no way of knowing. Even with external packet capture and analysis, since I don't know what normal traffic looks like, I wouldn't be able to recognise abnormal behaviour.
-----------------------
Anyway, after talking it through in this thread (thanks, guys), I have concluded that I will:
(1) downgrade the STB to 'severely untrusted' and cease using the Youtube app.
(2) build a new Home Theatre PC and do more on that, where I can have control over the software and filter content (like I do on my desktop PC).
(3) relegate the STB to using only the least troublesome/least risky apps and maybe retire it altogether.
I think the lessons for everyone else are: don't trust IoT devices, especially ones with apps, because, without control over the software, you can't know what they're really doing; and, beware what Youtube recommends.
|