Content protection dossier
A closed, certified operator platform
fibwiTV delivers TV and premium content over the operator's own device, with hardware DRM protection (Widevine L1) and secure boot, validated by an independent security audit.
Summary
What it is and why it's secure
The service is delivered through a device managed by the operator —the ZTE fibwiStick B866W12M— configured as a closed environment: signed firmware, verified boot, and no standard way to install external software or access the system. Protected content playback runs through Widevine L1, with decryption and decoding inside the Trusted Execution Environment (TEE), isolated from the operating system. The device's security level was assessed by LALIGA's anti-piracy department, which confirmed a highly restricted environment resistant to tampering.
Chain of trust
From boot to decryption, verified at every stage
Platform pillars
Six controls that reinforce protection
Hardware DRM — Widevine L1
The highest Widevine level: protected content is decrypted and decoded inside the TEE, isolated from the system. Enables premium HD and 4K playback.
security_level: L1Google-certified device
GMS certification and a Widevine certificate signed by Google. Passes Play Integrity and only runs approved applications.
GMS · Play IntegritySecure and verified boot
Secure Boot and Verified Boot in a valid (green) state; bootloader locked and cryptographically verified. Only firmware signed by the operator runs.
bootloader: lockedClosed environment
No ADB, no developer options, no installation from unknown sources. Doesn't allow external software or system console access.
no sideload · no ADBOperator firmware and controlled OTA
End-to-end managed device: the operator controls the firmware and updates (OTA), without relying on third-party stores for its lifecycle.
managed · OTALALIGA security audit
Technical security assessment carried out by LALIGA's anti-piracy department (2026): highly restricted environment, tampering vectors blocked by design.
LALIGA · report v1.0 · 2026LALIGA audit
What the audit confirmed
Technical device assessment
LALIGA's anti-piracy department · ZTE fibwiStick B866W12M device · 2026
- Widevine L1 active, with decryption inside the TEE — also verified with the DRM-Info app on the device itself.
- Bootloader locked; Verified Boot and Hardware Verified Boot in a valid (green) state.
- Secure Boot active: the device only boots firmware signed and authorized by the operator.
- ADB disabled, Developer options blocked by firmware, and sideloading removed.
- No remote vectors to install unauthorized software or access system partitions.
security_level : "L1" # Widevine · TEE
bootloader_state : "locked"
vb_state : "green" # Verified Boot
hvb_state : "green" # Hardware Verified Boot
secure_boot : activeSource: technical security assessment carried out by LALIGA's anti-piracy department. The full report is confidential; this document only includes high-level conclusions, without exposing details that could compromise device security.
For rights holders
What this means for your content
Hardware protectionYour content plays back under Widevine L1, not software: decryption isolated in the TEE.
Tamper-proof deviceCannot be rooted, flashed, or have external apps installed through standard means; audited closed environment.
Managed output policyOutput protection is applied according to the Widevine license policy for each session.
LALIGA validationThe platform's robustness has been assessed by LALIGA's anti-piracy department.
Content protection architecture
End-to-end model over Widevine
The device is already ready for Widevine L1 (audited). The content encryption layer —CENC packaging and license server— completes end-to-end protection and is being rolled out across fibwi's distribution chain.
Technical specs
Device identity
| Manufacturer | ZTE |
|---|---|
| Model | FIBWI B866W12M · "fibwiStick" |
| SoC | Amlogic (S905 series) |
| System | Android 14 · Android TV (GMS / Google Cast) |
| DRM | Widevine L1 — decryption in TEE |
| Boot | Secure Boot + Verified Boot (green) · bootloader locked |
| Distribution | Operator firmware · controlled OTA update |
| Certification | Evaluated and audited by LALIGA (anti-piracy dept.) — technical security report, 2026 |
| Ecosystem | Certified for premium OTT services (e.g. Netflix, Prime Video) in HD/4K |