Content protection dossier

A closed, certified operator platform

fibwiTV delivers TV and premium content over the operator's own device, with hardware DRM protection (Widevine L1) and secure boot, validated by an independent security audit.

Device · ZTE fibwiStick B866W12MWidevine L1 · TEEVerified Boot: greenAudited by LALIGA · 2026

Summary

What it is and why it's secure

The service is delivered through a device managed by the operator —the ZTE fibwiStick B866W12M— configured as a closed environment: signed firmware, verified boot, and no standard way to install external software or access the system. Protected content playback runs through Widevine L1, with decryption and decoding inside the Trusted Execution Environment (TEE), isolated from the operating system. The device's security level was assessed by LALIGA's anti-piracy department, which confirmed a highly restricted environment resistant to tampering.

Chain of trust

From boot to decryption, verified at every stage

Secure boot
Secure Boot active · bootloader locked
Verified boot
vb_state: green · hvb_state: green
Hardware DRM
Widevine L1 · decryption in the TEE

Platform pillars

Six controls that reinforce protection

Hardware DRM — Widevine L1

The highest Widevine level: protected content is decrypted and decoded inside the TEE, isolated from the system. Enables premium HD and 4K playback.

security_level: L1

Google-certified device

GMS certification and a Widevine certificate signed by Google. Passes Play Integrity and only runs approved applications.

GMS · Play Integrity

Secure and verified boot

Secure Boot and Verified Boot in a valid (green) state; bootloader locked and cryptographically verified. Only firmware signed by the operator runs.

bootloader: locked

Closed environment

No ADB, no developer options, no installation from unknown sources. Doesn't allow external software or system console access.

no sideload · no ADB

Operator firmware and controlled OTA

End-to-end managed device: the operator controls the firmware and updates (OTA), without relying on third-party stores for its lifecycle.

managed · OTA

LALIGA security audit

Technical security assessment carried out by LALIGA's anti-piracy department (2026): highly restricted environment, tampering vectors blocked by design.

LALIGA · report v1.0 · 2026

LALIGA audit

What the audit confirmed

Technical device assessment

LALIGA's anti-piracy department · ZTE fibwiStick B866W12M device · 2026

  • Widevine L1 active, with decryption inside the TEE — also verified with the DRM-Info app on the device itself.
  • Bootloader locked; Verified Boot and Hardware Verified Boot in a valid (green) state.
  • Secure Boot active: the device only boots firmware signed and authorized by the operator.
  • ADB disabled, Developer options blocked by firmware, and sideloading removed.
  • No remote vectors to install unauthorized software or access system partitions.
Device cryptographic status — excerpt
security_level   : "L1"      # Widevine · TEE
bootloader_state : "locked"
vb_state         : "green"   # Verified Boot
hvb_state        : "green"   # Hardware Verified Boot
secure_boot      : active

Source: technical security assessment carried out by LALIGA's anti-piracy department. The full report is confidential; this document only includes high-level conclusions, without exposing details that could compromise device security.

For rights holders

What this means for your content

Hardware protectionYour content plays back under Widevine L1, not software: decryption isolated in the TEE.

Tamper-proof deviceCannot be rooted, flashed, or have external apps installed through standard means; audited closed environment.

Managed output policyOutput protection is applied according to the Widevine license policy for each session.

LALIGA validationThe platform's robustness has been assessed by LALIGA's anti-piracy department.

Content protection architecture

End-to-end model over Widevine

01
Encryption at source
Content is packaged encrypted (Common Encryption, CENC).
02
License server
Issues the Widevine license per session and device.
03
Playback in the TEE
The device (L1) processes the license and decrypts inside the TEE.
04
Protected output
Secure playback according to the license policy.

The device is already ready for Widevine L1 (audited). The content encryption layer —CENC packaging and license server— completes end-to-end protection and is being rolled out across fibwi's distribution chain.

Technical specs

Device identity

ManufacturerZTE
ModelFIBWI B866W12M · "fibwiStick"
SoCAmlogic (S905 series)
SystemAndroid 14 · Android TV (GMS / Google Cast)
DRMWidevine L1 — decryption in TEE
BootSecure Boot + Verified Boot (green) · bootloader locked
DistributionOperator firmware · controlled OTA update
CertificationEvaluated and audited by LALIGA (anti-piracy dept.) — technical security report, 2026
EcosystemCertified for premium OTT services (e.g. Netflix, Prime Video) in HD/4K