So this happened over the weekend: I was making coffee Saturday morning and my Chromecast, completely unprompted, started blaring a warning through the TV speakers. Not a video I cast. Not anything my kid triggered from her tablet. Just... audio, telling me my device was "exposed" and that I should go subscribe to PewDiePie on YouTube while I was at it.
I want to be annoyed about this. I am annoyed about this. But I also have to admit it's kind of a great hack.
For anyone who missed it, this is the CastHack thing that's been going around the last couple days, courtesy of the same guy (or guys, going by "Hacker Giraffe" and "party-corgi" this time) who got tens of thousands of printers worldwide to spit out flyers back around Thanksgiving pushing the same subscribe-to-PewDiePie campaign. He's apparently still going, because the PewDiePie vs T-Series subscriber race hasn't actually resolved and some people online have decided this is a hill worth camping on indefinitely. I don't really care who wins that race. What I do care about is that my home network let a stranger on the internet talk through my television.
Heres the part that actually matters if youve got a Chromecast or a Google Home sitting around: this isnt a Chromecast bug. Google didnt mess up here, not directly anyway. Whats happening is that a lot of home routers ship with UPnP turned on by default, and UPnP is basically a "please forward whatever ports my devices ask for" setting. Your Chromecast asks your router to open up port 8008 (sometimes 8443) so local apps on your network can find and cast to it, which is fine and normal, until the router decides "local network" is a suggestion and forwards it out to the entire internet instead. At that point anyone scanning IP ranges for open Chromecast ports can just send it a cast command directly. No password, no pairing, nothing. Its wide open.
The fix is annoyingly simple once you know to look for it, and thats basically the whole reason Im writing this post, because I bet most people reading this have never once opened their router's admin panel:
- Find your router's IP (usually 192.168.0.1 or 192.168.1.1, check the sticker on the router itself if you don't remember)
- Log in with the admin credentials — and please, if youve never changed these from the default, go do that too while you're in there
- Look for a section called UPnP, sometimes buried under "Advanced" or "NAT" or "Forwarding"
- Turn it off
Thats genuinely it. Your Chromecast will still work fine on your own network, it just wont be reachable from outside it anymore. There are sites floating around right now that let you check if your specific IP is exposed before you even touch the router settings, which is a nice sanity check, though Id honestly just turn UPnP off regardless since half the reason these things get exposed in the first place is routers people bought five years ago and never looked at again.
The bigger annoyance to me isnt even the hack itself, its that this is like the third or fourth time in a year some researcher or troll has demonstrated that consumer routers are a mess of default settings nobody audits. Printers, webcams, now casting devices. Its always the same story: a convenience feature ships on by default, nobody explains the tradeoff to the person setting it up, and eventually somebody with too much free time turns it into a prank or a warning shot. This time it was relatively harmless, a video and some audio. Next time it might not be someone doing it as a public service with a YouTube subscriber count as the motive.
Anyway. I turned UPnP off on my router Saturday morning, checked it twice because I didnt fully trust myself, and havent had any more surprise PSAs from my TV since. If you've got a Chromecast and you havent looked at this yet, it takes about four minutes and it's a better use of your Saturday morning than mine was, since I spent a chunk of it trying to figure out why my television was yelling at me before I even had coffee.
Didnt end up subscribing to PewDiePie either, for the record. Felt like giving in.