LG to ban residential proxies from smart TV apps
248 points
6 hours ago
| 31 comments
| krebsonsecurity.com
| HN
12_throw_away
4 hours ago
[-]
42% of the apps on LG's platform have these quasi-malware SDKs in them? Seems kinda bad, whether it's due to negligence or just pure incompetence? You'd think there might be legal consequences for a corporation that lets their app store turn into a malware delivery system?
reply
drnick1
2 hours ago
[-]
It's not "quasi-malware," it is malware.
reply
JumpCrisscross
1 hour ago
[-]
> You'd think there might be legal consequences

I own an airgapped LG TV. Does anyone actually want to go class action/mass arb?

reply
nikanj
1 hour ago
[-]
They've seen the ruckus that follows from controlling / curating the app store experience. For example, see the comments at https://news.ycombinator.com/item?id=45017028
reply
coldtea
33 minutes ago
[-]
That's for a general purpose computing platform that a smartphone is.

This is for a fucking TV.

reply
iso1631
1 hour ago
[-]
LG's own code is quasi-malware
reply
xacky
4 minutes ago
[-]
They should be banned from all app stores and added to anti virus definitions. Many smaller sites have already shutdown due to being DDOSed. Even Wikipedia gets attacked by them.
reply
s1ncere
4 hours ago
[-]
Stop hooking up your LG tv to any network
reply
5kg
4 hours ago
[-]
reply
ahartmetz
3 hours ago
[-]
Fine with Linux though :)

LG's behavior isn't fine, but their monitors don't install crapware on Linux.

reply
TeMPOraL
2 hours ago
[-]
The monitors aren't installing anything. That headline was a lie.

It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs. That's why the problem affected older monitors too - it's the update side that suddenly started to ship malware.

reply
delta_p_delta_x
1 hour ago
[-]
> It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs

This is also a misrepresentation. Microsoft has provided LG with a certificate to sign its driver packages with, and allows LG to upload packages to Windows Update, which includes a feature to install sidecar applications. Now, the spirit of this feature is that any application is meant to provide genuine configuration functionality or some graphical front end to the driver's configuration knobs.

LG then abused that feature to provide adware. Now, there are millions of hardware vendors. One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.

Sometimes one actually wants the app that comes with the device, like AMD's and NVIDIA's configuration trays.

Even so, I fully expect that after this debacle MS will disable this stuff. There is precedent for this. Synaptics/ELAN/Alps touchpad tray applications largely disappeared after MS implemented precision touchpads somewhere in 2015, and suddenly Windows touchpads became as precise as those on Macs. Likewise with RGB peripherals. Even GPU driver applications have increasingly become less useful as the most important features—power control, adaptive sync, HDR, etc have moved into native Windows settings.

reply
Aaargh20318
3 minutes ago
[-]
> One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.

If you're going to allow 3rd parties to install software on potentially billions of computers with far reaching privileges then you better have something in place other than 'just trust me bro'.

reply
maccard
1 hour ago
[-]
I agree with you on the precedent

> after MS implemented precision touchpads somewhere in 2015, and suddenly Windows touchpads became as precise as those on Macs.

There’s still a world of difference between a MacBook touchpad and a windows one. My work laptop (18 month old dell XPS) can’t hold a candle to my 6 year old MacBook’s trackpad.

> Likewise with RGB peripherals. Even GPU driver applications have increasingly become less useful as the most important features—power control, adaptive sync, HDR, etc have moved into native Windows settings.

The peripherals still need the addons though; I have ASUS armory crate, Corsair iCue and MSI center for my Motherboard, cooler and GPU respectively. They all suck.

reply
doikor
1 hour ago
[-]
> There’s still a world of difference between a MacBook touchpad and a windows one. My work laptop (18 month old dell XPS) can’t hold a candle to my 6 year old MacBook’s trackpad.

The latest Dell trackpads are quite bad. Price or the product being premium or not unfortunately does not tell you if it will have a good trackpad or not. And it changes over time (Dell XPS used to have really good trackpads)

Basically you have to go to a store and try or find reviews that actually pay attention to this.

reply
delta_p_delta_x
1 hour ago
[-]
> There’s still a world of difference between a MacBook touchpad and a windows one

Oddly I've found otherwise (Dell Precision notebook from 2021, and Surface Laptop). It might be macOS's animations and smoothing interfering here, but I've found that my Windows touchpads are much more responsive, especially when swiping between desktops.

> The peripherals still need the addons though

Ugh, this is annoying. Hardware vendors need to be banned from writing lousy, inefficient, unsafe software.

reply
maccard
41 minutes ago
[-]
On the trackpads - I only ever use my MacBook as a single screen device, so the experience may be different. A long time ago I used it with an external monitor and the experience was very poor compared to windows.

> Ugh, this is annoying. Hardware vendors need to be banned from writing lousy, inefficient, unsafe software.

Yeah, I commented on the McAfee LG thread but the stuff that comes bundled with hardware is embarassing. I don’t know how Razer, Logitech, nvidia, MSI, asus, etc get away with it. The stuff is awful, even their “good” software. I work in games and a few years ago the biggest correlation we had between unexplained crashes/performance problems in the wild was users having MSI Afterburner installed. Users thought it did great things and fixed a bunch of games but it absolutely thrashed everything we worked very hard to do and caused no end of issues doing so.

reply
chronogram
24 minutes ago
[-]
What part of Afterburner caused issues? I have it installed to undervolt an old GPU but not actively running.
reply
21asdffdsa12
1 hour ago
[-]
The commercial software landscape more and more reminds me of a civil war torn town. Everyone shooting at everyone, a dark forest through and through
reply
denkmoon
1 hour ago
[-]
I can only imagine the meetings at microsoft HQ where they all sat around a table and crossed their fingers and hoped that vendors would act in the spirit of their design.
reply
petesergeant
1 hour ago
[-]
> One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.

Apple seem to do a pretty decent job of just that

reply
delta_p_delta_x
1 hour ago
[-]
The situation is very different on Macs. Apple control almost the entire hardware stack of the machines that macOS runs on. They make it an absolute pain in the neck to run any application not blessed by attestation. This attestation server is also frequently offline. They've also made it very difficult to write things like filesystem drivers, having completely pulled that functionality from more recent versions of macOS. In fact, if I recall correctly one cannot ship a third-party kext on more recent Macs, especially ARM ones. As such, hackintoshing has basically vanished as a hobby.

At least on Windows, the most you get is a scare screen saying 'this app is from an unidentified developer'. I know what I'd rather have.

reply
petesergeant
39 minutes ago
[-]
> At least on Windows, the most you get is a scare screen

Well that and side-loaded LG adware

reply
felooboolooomba
1 hour ago
[-]
> That headline was a lie.

Kinda agree but let's call it "misinformed" or something, instead of a lie.

reply
fauigerzigerk
34 minutes ago
[-]
I would say it's neither a lie nor misinformed. It 's a punchier headline that can be justified by what the user experiences. The user connects a monitor which causes ads to appear. The rest of this Rube Goldberg contraption is a mere detail.
reply
drnick1
2 hours ago
[-]
Another win for the Linux security model (software installed and updated manually from vetted repos only).
reply
gblargg
2 hours ago
[-]
Wait, you're saying a monitor can just advertise a URL over the video connection for its driver and then Windows will blindly install it, without user confirmation? I thought that LG had submitted these "drivers" (adware) to Microsoft and they approved it.
reply
Sophira
36 minutes ago
[-]
As far as I'm aware, the monitor does not transmit a URL. Windows is looking at the hardware's vendor and device IDs and using those to look up and download the "drivers" that LG has stated are for that device.
reply
stkdump
1 hour ago
[-]
I think the point is that:

1. Yes Windows must have "approved" the drivers

2. Windows Update runs automatically and not (usually) manually

3. Automatic update can't even be disabled, only manually postponed a bit

At least 2 and 3 are different on virtually every Linux distro. Also, I find it very unlikely that they would accept such behavior.

To give MS the benefit of the doubt here, now that this happened and has been reported on they might decide to enforce stricter rules on manufacturers in the future. But as a Windows user you don't have a choice in case you don't like how they decide and how their decisions might change again later.

reply
dmos62
1 hour ago
[-]
https://github.com/raphire/win11debloat

This has an option to disable downloading of auxiliary apps when a device is connected. Yes, it's a Windows Update thing.

> Prevent Windows from auto-installing device companion apps, like LG Monitor App, Alienware Command Center and more.

reply
bayindirh
2 hours ago
[-]
I believe you register your device with Microsoft so Windows can automatically obtain and install drivers for them when they are plugged in.

What LG sent in for installation is not a simple .inf or .sys/.dll file. They sent in a whole bag of software which does all the nasty things, and Microsoft doesn't vet or care about the software installed as the "driver" of the hardware.

reply
ssl-3
2 hours ago
[-]
Eh? No.

It's just a device attached to a computer.

But in a Plug-and-Play world, its addition is noticed by the operating system -- as has been normal for decades.

Microsoft's Windows operating system sees this new hardware ID and then goes forth to install whatever-the-fuck software it associates with that identification, presumably as a service to the user. (Did Microsoft approve it? Dunno. I'm just over hear eating popcorn.)

reply
voidUpdate
1 hour ago
[-]
sudo dkpg -i FileYouDownloadedFromAnywhere.deb
reply
iso1631
1 hour ago
[-]
most of my machines use unnatended-upgrades

Increasingly software is distributed by "curl dodgysite.com/get.sh|sudo bash -", no different to running "install.exe" on windows

Surely Windows Update is a vetted repo as much as arch or debian

reply
krige
2 hours ago
[-]
Surely you mean Linux security model (not relevant enough to be targeted by big tech)?
reply
dns_snek
2 hours ago
[-]
It's not a weakness that they targeted and exploited, it's a feature that was purposefully implemented by Microsoft.
reply
delta_p_delta_x
1 hour ago
[-]
> Another win for the Linux security model

I swear, OSs have become sports teams.

Linux's 'security model’ has plenty of holes. The very fact the kernel and much of its user-mode is written in C almost guarantees that its security model is worthless. The Linux ecosystem operates on trust and respect that can and has been easily abused by bad actors to provide supply-chain pwnage.

There have been so many zero-click local privilege escalation CVEs I've lost track.

Arch Linux AUR malware: https://lists.archlinux.org/archives/list/aur-general@lists....

reply
silver_silver
1 hour ago
[-]
AUR is an effectively unmoderated user repo. It’s not Arch Linux’s core repository, nor is it enabled by default or indeed even possible to use without manual downloads from outside the package manager.
reply
opan
1 hour ago
[-]
I think you can probably find a better example, even if less recent. The AUR is unofficial and not properly vetted in the same way as the actual Arch repos, Debian repos, etc.
reply
meta-level
2 hours ago
[-]
yet?

I guess with more and more consumer devices running Linux based OSes (SteamOS, Android, Bazzite, Silverblue, ..) that becomes more and more interesting.

And unfortunately the "I'm safe on my non-windows-system" argument doesn't count for long, as the 99% muggle crowd justifies a shift to a world where our non-certified (=> 'insecure') systems are not supported by big companies anymore, as it's currently happening on Android.

reply
Gigachad
2 hours ago
[-]
The LG scandal specifically relies on the fact windows will auto install OEM crapware as soon as you plug it in. No other OS does that.
reply
rconti
2 hours ago
[-]
Huh? What does WebOS have to do with windows?
reply
smackeyacky
1 hour ago
[-]
LG monitors not TVs
reply
ahartmetz
2 hours ago
[-]
"Fortunately", agent Poettering is on the case, implementing remote attestation for Linux so we can all be secure. Barf.
reply
manarth
1 hour ago
[-]
Want to stream Netflix? Disney+? Hulu?

You need to hook something up to a network, and another device would have similar risks.

Setting up a sandboxed VPC or auditing traffic is beyond the means of the average TV owner.

reply
coldtea
31 minutes ago
[-]
>You need to hook something up to a network, and another device would have similar risks.

Another device might not give the free reign for all shitty malware like they do. Apple TV for one wouldn't.

reply
timc3
53 minutes ago
[-]
Apple TV is the usual recommendation.
reply
qq66
39 minutes ago
[-]
> and another device would have similar risks

Do you think an Apple TV and a Walmart special TV have same risks? I don't. I give the Apple device my network credentials and the TV never sees them.

reply
michaelchisari
3 hours ago
[-]
Never once had a problem with an LG because I've never given it internet access. A trustworthy set top box handles everything instead. Concerned that might not be an option in the future.
reply
jmward01
2 hours ago
[-]
That is my problem. What can you trust anymore? Is there an appliance out there that can do the basics and not be a malware gateway?
reply
mapt
2 hours ago
[-]
Smart TVs replaced dumb TVs not out of consumer demand, but out of subsidy from commercial databrokers and streaming services. Despite adding $100 of hardware they were priced $100 cheaper.
reply
modo_mario
1 hour ago
[-]
Is there still any specific brand known for dumb tv's that features the quality and 'non smart' options of the smart variants?
reply
lodovic
2 hours ago
[-]
I'm always wondering how hard it would be to just remove the hardware for spying. Just keep enough hardware to make it a dumb panel, remove the webos logic boards, wifi antenna, etc.
reply
iso1631
55 minutes ago
[-]
Consumers will happily sell their data for a $100 discount. Hell they'll waste 20 minutes watching adverts to save $1.
reply
gblargg
2 hours ago
[-]
LG now installs adware when you merely connect one of their monitors to a Windows PC.
reply
userbinator
2 hours ago
[-]
reply
mikepurvis
3 hours ago
[-]
I'm mostly very happy with my LG C4 as a home theatre centerpiece, and I did have it online so that I could use the apps for YouTube and Jellyfin. However, the lack of support for modern 4k rips (HEVC+DTS) ended up being a dealbreaker and I finally ditched the built in software for a fire stick instead.

No transcoding, no weird codec issues, just the raw files direct streamed from the underpowered Unraid box, into the back of the AVR where the audio is handled correctly and the video is sent to the screen.

reply
otikik
51 minutes ago
[-]
Stop buying LG
reply
MiddleEndian
4 hours ago
[-]
My LG DualUp monitors (with no internet access) recently triggered some LG Adware Bullshit to install on my Windows laptop. So I'd say stop using LG anything (or Windows anything since they're voluntarily in on the scam too lol). If you want the 2560x2880, maybe buy the knock-off INNOCN vertical monitors.

https://old.reddit.com/r/pcmasterrace/comments/1v1pkbs/lg_sp... ← examples of others who ran into the same shit

reply
marssaxman
2 hours ago
[-]
I would probably have a DualUp by now if I could find one available anywhere: it's a very appealing form factor. I looked at the INNOCN site, but only see normal-looking monitors there; do you have a model name or any pointers I could search for?
reply
CivBase
4 hours ago
[-]
Stop buying LG TVs.
reply
smcleod
4 hours ago
[-]
Unfortunately they make arguably the best OLEDs and webOS is pretty decent to use (especially compared to the terrible OS that Samsung and Sony run). I think the best thing people can do is update their firmware then disconnect it from the internet. Using an AppleTV or similar provides a better experience than any TVs built in apps anyway.
reply
Yizahi
2 minutes ago
[-]
I thought webOS was pretty decent initially. But LG never provided even a single major update to my TV in a decade, so that just about cancels any possible benefits from the faster code. I'm using Chromecast for several years now, bypassing and ignoring webOS completely. But the initial idea was nice, all those years ago.
reply
cosmic_cheese
3 hours ago
[-]
I don’t ever use their “smart” functionality (that’s what my Apple TV is for) but I’ve never had any issues with the Google TV (Android) build that Sony ships. It doesn’t nag me about being kept offline, is reasonably fast, and doesn’t even show its home screen unless I specifically summon it, so it checks my boxes.
reply
mey
4 hours ago
[-]
How important is "the best" OLED vs the second best or 100th best OLED? I am personally ok not buying the bleeding edge to not get malware onto my OS.
reply
smcleod
1 hour ago
[-]
If you care about home cinema it's important. There's a pretty big jump down. You can look up the specs and reviews of the C and G series from LG. Anecdotally quite a few times when people see my 7 year old LG C9 I've had them ask if it was some new expensive TV as they are so impressed with the picture.
reply
notatoad
4 hours ago
[-]
reasonably important, if you're never connecting your lg tv to any network, and just connecting it to an AppleTV or something and letting HDMI-CEC control it so you never even see their OS.
reply
StumpChunkman
3 hours ago
[-]
Exactly this. And with an Apple TV 4K Ethernet, you've got a bonus Thread border router for smart home devices. I actually didn't even realize that initially, but was very pleased when I found IKEAs latest round of Matter over Thread devices paired nicely with it and my existing Home Assistant + Hue setup.
reply
drnick1
2 hours ago
[-]
I would suggest a mini-PC running Linux and Plasma Bigscreen instead of an AppleTV if you want something 100% private and user-controlled.
reply
przmk
1 hour ago
[-]
Unless you're using streaming services like Netflix, in which case you're stuck with 720p because of widevine.
reply
N19PEDL2
2 hours ago
[-]
Do you recommend any specific distro for this?
reply
theplumber
4 hours ago
[-]
If you care about malware you do not plug it into the internet. I think windows computers are pretty mallwareish as well or at least spyware. People who buy Oled buy them because they care about PQ.
reply
altairprime
2 hours ago
[-]
2nd best, not. 100th, better to get a great LCD than a junk OLED?
reply
globular-toast
3 hours ago
[-]
Exactly. If you get the best today it'll be the second best tomorrow anyway. Absolute position is undetectable, you can only perceive change. Use that to your advantage and stay off the treadmill.
reply
smcleod
1 hour ago
[-]
7 years into my C9 and it never fails to impress.
reply
jedberg
4 hours ago
[-]
I haven’t looked recently but last I checked Samsung made the best panels. Has that changed recently?
reply
nvme0n1p1
3 hours ago
[-]
Samsung scored highest on https://www.rtings.com/ for my criteria, and I'm happy with the purchase. I didn't connect it to the network, of course. (I had to stop my handyman from connecting it and he seemed to think I was crazy for insisting.)
reply
lostlogin
2 hours ago
[-]
I installed a Pihole and set an edge router to direct any port 53 traffic that wasn’t from the Pihole, to the Pihole.

That made a Samsung behave a little better. But giving it no network access is better.

reply
ahartmetz
3 hours ago
[-]
"I work in software. I have seen things you people wouldn't believe. Attack ships on fire off the shoulder of Orion. I watched C-beams glitter in the dark near the Tannhäuser Gate..."
reply
dodslaser
3 hours ago
[-]
Samsung is good, except:

- No Dolby Vision support, only HDR10+ - Issues with judder/micro stutter - History of nerfing TVs via OTA updates - HDMI ports randomly failing - Bad HDMI-CEC implementation - Selling completely different panel generations under the exact same model names.

reply
smcleod
4 hours ago
[-]
Their panels are often over-saturated with that fake HDR like look, similar to their phones.
reply
ahartmetz
3 hours ago
[-]
Most screens come with "showroom settings" out of the box. You need to configure them to something more neutral once and then it's fine.
reply
smcleod
3 hours ago
[-]
I'm aware of that setting, but this is the Samsung baseline. The panels they export for OEMs / other manufacturers don't seem to have the same hyper saturation. Even just standing next to someone using a Samsung phone or tablet you can often spot it straight away we know you what to look for.
reply
ahartmetz
2 hours ago
[-]
Even phones have screen settings these days (much less detailed than monitors). On my Motorola phone w/ OLED screen, I turned off "vibrant colors" or something like that. Maybe the people you saw didn't bother or liked it. Maybe there is something that can't be turned off, who knows. I only have semi-regular experience with an older (and non OLED) Samsung tablet which seems fine.
reply
TeMPOraL
1 hour ago
[-]
Over saturated HDR is a good default in times when all TV shows only use various shades of pitch black.
reply
PowerElectronix
2 hours ago
[-]
That goes away if you set them in filmaker mode.
reply
PowerElectronix
2 hours ago
[-]
No, qd-oled is still best, LG is closing the gap with tandem oled but is still the second best panel tech.
reply
pjmlp
3 hours ago
[-]
Have to agree, WebOS is much better than Android TV OS, with ads on the dashboard.
reply
Gigachad
2 hours ago
[-]
As long as you keep it off the internet. Otherwise it’s absolute loaded with adverts everywhere.
reply
pjmlp
1 hour ago
[-]
Not the 2020 version I have, it has a suggested shows row from the apps I have already installed, which makes sense.

Android TV even has ads for Disney and Apple, which I never installed.

reply
Leonard_of_Q
2 hours ago
[-]
You can replace the Android TV launcher with an alternative like Projectivy [1] to get rid of whatever nonsense the stock launcher tries to push. Add Flicky [2] to address F-Droid and you've got a nuisance-free Android TV.

[1] https://github.com/spocky/miproja1

[2] https://github.com/mlm-games/flicky

reply
pjmlp
1 hour ago
[-]
Thanks, however is kind of the problem, it shouldn't be a thing in first place.
reply
matheusmoreira
4 hours ago
[-]
Aren't they the only TVs that can be jailbroken?
reply
bcraven
3 hours ago
[-]
I decided there wasn't much to do if I did:

https://www.webosbrew.org/rooting/

reply
kaelwd
3 hours ago
[-]
And buy what? Smasnug? Sony? They're all uniquely shit.
reply
mastazi
1 hour ago
[-]
I am afraid that my dumb TV, which I've been holding onto for many years, might be on its last leg.

I remember seeing privacy guides for smart TVs over the years, does anyone know a place with up to date info?

Most 55inch monitors are now "smart" sadly, so are most "digital signage" products. So there is no longer a way to get a true dumb panel at least over 50 inch

EDIT I am in Australia, there might be products that are available elsewhere but cannot be bought/shipped here

reply
kyriakos
3 minutes ago
[-]
Don't connect your TV to the network. Use an external device for smart features like firestick, Apple tv, Google streamer etc (there are open source options too if you look around and don't mind missing some polish).

I have yet to receive a software update on any of my smart TVs that brought in any positive feature.

reply
qq66
40 minutes ago
[-]
If you don't ever give your network credentials to the Smart TV you've closed off 99% of the attack surface.
reply
Tor3
22 minutes ago
[-]
From previous discussions there are apparently TVs which will connect to any open network nearby, if it can find one.

I got myself a normal, non-smart Philips 49" TV some ten years ago, it's good, but I don't expect to be able to find something similar anymore.

reply
kyriakos
2 minutes ago
[-]
Who runs open WiFi networks in 2026?
reply
m132
1 minute ago
[-]
Hopefully nobody, but still—it takes just one
reply
cynicalsecurity
36 minutes ago
[-]
You can easily turn dumb mode on any smart TV.
reply
tikkabhuna
52 minutes ago
[-]
I share your disappointment. I just want a screen with a tuner. If I want any “apps”, I’ll pair it with another device which will probably be an Apple TV.

I’m starting to wonder if a monitor and a soundbar with an external tuner is possible.

reply
crote
45 minutes ago
[-]
I don't even care about the tuner part. If I ever get the desire to watch linear TV again, I'll just get an IPTV subscription.

A decent-ish TV-sized panel with at least a single HDMI input really is all I need.

reply
awllau
1 hour ago
[-]
What happens to the copies already installed?

Spur says these SDKs can keep running after the app is closed and only stop when the user deletes the app or opts out. LG says developers must remove them or have their apps suspended, but the article doesn’t say whether that disables existing installs. If it doesn’t, LG needs to tell affected users which apps to remove.

Does webOS have any way to kill an installed app remotely?

reply
Utilera
12 minutes ago
[-]
I can imagine someone choosing "no ads" without realizing they just agreed to let strangers route traffic through their home IP indefinitely
reply
ifh-hn
1 hour ago
[-]
My question is how would a user know their TV is being used like this?

Also this is the reason you down download random crap onto your devices.

I have an LG that is connected on its own network with bare minimal apps (netflix, prime, etc) because it's too convenient for my family. I actually bought it because it didn't display ads on the home screen like the other smart TVs I'd researched. Thought LG was the lesser evil, turns out they're all a bad as each other.

reply
iso1631
1 hour ago
[-]
Only reason LG doesn't have adverts is by forcing it to use a pihole, but even that needs updating -- recently they've managed to push things through and I need to do another investigation to see what needs blocking. Trouble is I only see them when I'm not in the mood to be working, and then forget about them
reply
yodon
4 hours ago
[-]
If other non-Android-based TV manufacturers follow, this will have a much bigger impact on the spread (and cost) of scraping than either Anubis or Cloudflare.
reply
akersten
5 hours ago
[-]
is this some kind of tactical distraction from the other LG headlines this week?

I thought residential proxies are already banned from SmartTV apps by virtue of practically every APK under the sun being subject to the Google Play terms of service.

reply
Marsymars
5 hours ago
[-]
> I thought residential proxies are already banned from SmartTV apps by virtue of practically every APK under the sun being subject to the Google Play terms of service.

The platforms in question here are webOS and Tizen, neither of which are Android or use the Google Play Store.

reply
ssl-3
5 hours ago
[-]
That only applies to the subset of TVs that use Google TV/Android TV.

Not so much for the rest of them that have operating systems with names like Roku TV OS, Tizen, WebOS, and Fire TV OS. They do their own things.

reply
ranger_danger
5 hours ago
[-]
LG webOS is not Android though, it's from the old Palm/HP devices of the early 2010s. And I'm pretty sure there are still tons of play store apps with these proxy SDKs in them, advertised/consented or not.
reply
glimshe
5 hours ago
[-]
My TV doesn't know my router's wi-fi password.
reply
declan_roberts
4 hours ago
[-]
My TV thinks it's January 1st 1970.
reply
kazinator
3 hours ago
[-]
And so it thinks it is fairly new, then, and doesn't require any tubes replaced. Should that change, it will let you know.
reply
charles_f
3 hours ago
[-]
My TV isn't even connected to power
reply
mc3301
4 hours ago
[-]
Every time anything asks for a DOB or anything like that, I enter the earliest date their system allows. Been doing it for decades.

I guess that might make me more trackable?

reply
ahartmetz
3 hours ago
[-]
At least you could get some interesting ads. Do you want to participate in a longevity study?
reply
laughing_man
1 hour ago
[-]
Heh. Steam thinks I'm 126.
reply
walrus01
5 hours ago
[-]
I've said it before on HN a long time ago but I'll repeat myself, I have about a thousand times more confidence that Sony and/or Microsoft will keep their PS5 and Xbox operating systems secure and not crapped up with stuff like this, than I do that random TV manufacturers will not result in a cybersecurity or privacy disaster.

Yeah, the PS and Xbox OSes show you ads, and they have telemetry. But both companies also have an extremely important core functional need of keeping them secure, because possible fuckery with the OS could result in game piracy/DRM bypasses and a direct threat to their revenue models.

reply
thewebguyd
3 hours ago
[-]
The gaming consoles aren't subsidized via the data collection like smart TVs are via content recognition (selling everything on your screen to advertisers).

Consoles are sometimes sold at a loss, but the revenue model is different. Playstation plus/game pass, a cut of game sales and microtransactions, exclusives, and accessories.

No one should ever connect their TV to the internet. There just isn't any reason to, get access to your streaming apps another way.

reply
amazingman
5 hours ago
[-]
Hope you don't have any open WiFi networks nearby. IMO it's better to put it on one of your networks and isolate it from the internet and other devices.
reply
tyre
4 hours ago
[-]
Yes. I bought a Samsung TV and there isn’t a way to set up Art Mode without the internet. So first you have to get a raspberry pi, install pi hole, then switch your router’s DNS.

What a wild experience 2026 is. But I do feel like a wizard.

reply
walrus01
4 hours ago
[-]
You don't need an actual physical raspberry pi to temporarily run pihole on your LAN, you can, for instance, install a barebones debian VM inside any common hypervisor on your laptop like virtualbox or qemu, then install pihole on that basic debian x86-64 system.
reply
entropie
4 hours ago
[-]
They might hardcode DNS. It's not certain that this will work.
reply
slau
4 hours ago
[-]
This is why I’m a bit conflicted about DoH and ODoH. Firefox and Chrome have defaulted to DoH for years if I’m not mistaken (although I’m in Europe so I believe my FF still uses regular DNS instead of DoH by default).

This also means that DoH effectively sends all your queries to CloudFlare on FF. Chrome is slightly smarter and tries to map your DNS provider to a DoH implementation if known.

reply
TeMPOraL
1 hour ago
[-]
That's why I'm not a fan of DoH or certificate pinning. Those are tools of control.
reply
tkel
4 hours ago
[-]
I have my router set with iptables rules to block/redirect all port 53 and you can also add known DoH to a blocklist to try and force LAN devices to use your router DNS.
reply
lodovic
2 hours ago
[-]
I have a separate lan for untrusted devices, I only use whitelisting. No public DNS for these devices.
reply
Jnr
1 hour ago
[-]
I block known DoH servers on my lan and forward all dns requests to my dns server.
reply
CyberDildonics
4 hours ago
[-]
You can intercept normal DNS with iptables rules.

The best way to deal with a TV you don't trust is what no one wants to hear.

Open up the back and disconnect the wifi antenna. It is easy to open them up and everything is pretty simple and obvious once you do.

reply
drnick1
2 hours ago
[-]
> Open up the back and disconnect the wifi antenna.

Upvoted. This is precisely the kind of thing I expect to read on HN.

reply
drnick1
2 hours ago
[-]
> So first you have to get a raspberry pi, install pi hole, then switch your router’s DNS.

This does not provide any meaningful protection against data exfiltration. The TV is very possibly using public DNS or outright phoning home through stable IPs.

reply
MrDrMcCoy
4 hours ago
[-]
If it connects to another network, it's somebody else's problem. Unless of course, it has a built in webcam or microphone.
reply
stvltvs
4 hours ago
[-]
It does, at least for any media played through the device. Read up on automatic content recognition.

https://www.howtogeek.com/its-not-just-streaming-content-you...

reply
RiverCrochet
4 hours ago
[-]
I haven't seen any open WiFi networks around me in years. I don't think it's a thing anymore; it's definitely not something a TV company can rely on.
reply
baby_souffle
4 hours ago
[-]
They're not unheard of in cities. Hotels and shopping malls have them. Some residential ISPs will also broadcast a public access point using a slice of each customer's bandwidth allocation...
reply
drnick1
2 hours ago
[-]
Another reason not to use ISP hardware. That's on top of a well-known backdoor (https://en.wikipedia.org/wiki/TR-069).
reply
dhosek
4 hours ago
[-]
When I had Comcast internet, I could get on those, but it required a network profile to actually connect to the internet. That said, I wouldn’t put it past TV makers and Comcast to collude on using this to allow backdoor network exfiltration.
reply
prmoustache
2 hours ago
[-]
They all have captive portal for regulatory reasons though.
reply
Symbiote
1 hour ago
[-]
Depends on the country.

The cafe I live above in Denmark just has an open network.

reply
Hamuko
3 hours ago
[-]
I have an open guest network with a captive portal, and not once have I seen my LG TV try to connect to it.
reply
gboss
5 hours ago
[-]
Pretty sure they can get internet through the HDMI cord from Roku or similar device
reply
MrDrMcCoy
4 hours ago
[-]
Source? HDMI includes Ethernet in the spec, but I've never heard of any devices actually implementing it.
reply
RiverCrochet
4 hours ago
[-]
That would require the Roku to specifically be set up to act as a router. You can't just connect to a random device that's not specifically a router/AP and use its internet connection.

Since Roku like other smart TV companies makes money off of user data captur, it's not incentivized to enable those conditions for a downstream device, especially if not specifically advertised as a feature.

reply
toast0
2 hours ago
[-]
If this was a feature they wanted to provide, it would simplest to set the Roku up as a bridge. No dhcp, no nat, just a virtual switch. Roku devices run on Linux, if their HDMI chip supports Ethernet and that's plumbed to a Linux supported MAC (probably not), it might take an hour to build and test the feature. Longer if the wifi interface doesn't like being bridged (I've seen that on some openwrt devices).

There's esp-idf examples from espressif for doing bridging on an esp32 if you have one with a MAC and a PHY and/or spi mac+phy.

Or for wired ethernet, they could include a three port switch IC.

reply
mikestew
4 hours ago
[-]
This again? Yes, it’s in the spec. No, no one has been shown to have actually implemented it. No streaming box is going to allow random devices to use their connection.
reply
toast0
2 hours ago
[-]
E-Arc uses the wires intended for Ethernet. Hook your Roku up to an earc port if you're seriously concerned about it.
reply
walrus01
4 hours ago
[-]
does a roku provide a dhcp server, issue a dhcp lease, do NAT and routing to things that are plugged into it over the 100M ethernet built into a current gen HDMI link?
reply
aussieguy1234
5 hours ago
[-]
This is the best approach
reply
miki123211
50 minutes ago
[-]
> researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.

Eh, so even sources as reliable as Krebs on Security sometimes engage in bad statistics.

This is a statistic that feels significant, but actually tells you nothing. For all we know, "42% of all apps" can mean a single spray-and-pray campaign with a few hundred downloads in total, with the vast majority of users only downloading apps from the top10, which are all unaffected. Or maybe the problem is widespread across the entire distribution of app downloads, with the majority of users having at least one infected app. We don't know either way, because "42% of apps" is a completely meaningless statistic.

reply
ram_rattle
4 hours ago
[-]
Apparently all these vendors did nothing to prevent this, a nice article from spur intelligence

https://www.cbsnews.com/newyork/video/how-smart-tvs-may-be-s...

reply
signalbright
27 minutes ago
[-]
It's absolutely crazy that they were accepted in the first place
reply
0xblinq
4 hours ago
[-]
I'm very worried with all this bullshit around TVs.

I've been running the same Samsung UE40C6530 since 2010. It's 16 f'ng years and the thing works flawlessly like the first day. No other electronic device in my life worked so well, during so long.

But I'm about to move to a new home, and it feels like it's about time to get something more modern, at least a 4k TV.

But I'm honestly totally lost at what to buy. I do not want a "Smart" tv that's slow to start, bloated with crap, installing updates every day, and maybe even spying on me.

I want a plain, old, normal TV. If possible without Android or any advanced operating system. Just a TV. I'll plug external content myself, either via a Chromecast device, or something similar. I don't want my TV to be a full fledged computer.

Is there such a thing? What would you buy nowadays? It seems you're forced to get yet another computer to maintain and be worried about whatever you buy.

reply
dataengineer56
34 minutes ago
[-]
The new Chromecasts and Apple TVs are really pretty good. I connect my LG TV to the wifi every few months to run updates, then disconnect it after. I control my TV through the Chromecast remote, so I never see any LG dashboards/apps.
reply
geor9e
2 hours ago
[-]
If you hook an Apple TV (or similar) up to any 4k TV, and turn CEC on (to let the Apple TV control it), and never set it up otherwise, it becomes a dumb monitor.
reply
dzhiurgis
50 minutes ago
[-]
My parents got new telco IPTV boxes and they are excellent. Even voice search in our niche language works flawlessly.

Apple TV I got them few years ago just sits there unused.

reply
orly01
3 hours ago
[-]
I've heard you are not forced to connect to wifi, and on most of them you can connect make it default certain HDMI input. Latency to turn on/off might be less good than the 2010 one, but other than that this might be a very good way to do it.
reply
Fantosism
3 hours ago
[-]
You buy a commercial panel used for advertising/signage that's 3x the price of the "Smart" consumer panels.
reply
kaelwd
2 hours ago
[-]
Are there even any OLED commercial panels with HDR and VRR?
reply
thewebguyd
3 hours ago
[-]
the smart consumer panels would also be more expensive if they weren't subsidized via the spyware.
reply
unethical_ban
1 hour ago
[-]
My Sony tv has never connected to my network and it works great. I use an external device as the source.
reply
jdmarble
3 hours ago
[-]
If you’re fine with “okay” picture quality, try a Sceptre. You can get them on Amazon. I’ve had good success with them. I heard you can still disable some smart features on Sony TVs.
reply
iugtmkbdfil834
2 hours ago
[-]
Heh. tinfoil hat on I always suspected that the AI gods would manifest themselves through TV. Hat stays on from this point on. It is not like LG suddenly found it in their heart to stop the money flow from the offending apps. Not when combined with recent security incident at frontier labs and current admin freaking out over open models.
reply
jmward01
2 hours ago
[-]
Honestly I have nothing but anger for all parties involved here. We need to treat any appliance as hostile. Vote for people that will stop this stuff. Don't buy it. This is digital assault and should be treated as such.

If any of the HN crowd reading this are tech reviewers, make privacy and security a first class feature of the things you review. If it has a network connection then ask hard questions of the manufacturer about how they are managing that massive responsibility and what promises they have about how they will, and won't, use it. Ask what qualifies a 'trusted partner' and get a list of them so you can dig into them and report on how much those partners can or can't be trusted.

I really don't care how bright the screen is if this type of stuff happens. I'd rather watch nothing.

reply
kh2engab
3 hours ago
[-]
Is there a (technical) difference between a residential proxy and bot network node?
reply
markasoftware
2 hours ago
[-]
Residential proxies operated by "legitimate" providers can only open TCP connections, which more or less rules out DDoS attacks, which seem to be the most common use of botnets. (And all tcp connections typically have to go through the proxy providers datacenter first to get through NAT, which effectively limits the total amount of traffic/connections you can make)
reply
charcircuit
1 hour ago
[-]
As they are both distributed systems there will be some inherit underlying similarities, but a botnet has things like antidebug, stealth, privilege escalation, etc. They typically include attack payloads or spying features like taking screenshots, keyloggers and stealing account information. Additionally they may include further ways of spreading to other computers such as messaging people on Discord or using other vulnerabilities. They might also try and take exclusive control of the device by patching security vulnerabilities and uninstalling other malware. Well unless they sell dropper capabilities letting other people deploy malware to the machine.
reply
Nursie
3 hours ago
[-]
A figleaf of "We gave ourselves permission on page 247, paragraph 3 of your user agreement"
reply
gblargg
2 hours ago
[-]
So does this mean that using a proxy will cause all of the "smart" features to stop working? Win-win.
reply
jbverschoor
2 hours ago
[-]
Thanks for the heads up, LG.

Those cheap/discount tv brands make soo much sense these days

reply
xena
5 hours ago
[-]
This is the best news I've heard all week. Finally good news for once!
reply
atoav
1 hour ago
[-]
LG is on my blacklist. That means I won't buy LG products and in my job actively fight against buying products from them. And they put themselves onto that lost with their behavior.
reply
BrenBarn
3 hours ago
[-]
The messed up thing is that we need to rely on LG to stop allowing it rather than just making it illegal.
reply
BetterThanSober
2 hours ago
[-]
Stop buying "smart" TV
reply
JoshTriplett
1 hour ago
[-]
I'd love to. Last I checked, nobody makes large-format high-quality tandem OLEDs that aren't smart TVs.
reply
spudlyo
4 hours ago
[-]
One day there will be a decent TV that can be relatively easily hacked to run on open source firmware. My wife and I are moving soon, and I'm happy we've decided not to have a TV in the new place. Neither of our current LG TV's have ever been connected to the network, but it will feel good when I sell or give the cursed things away.
reply
4rt
4 hours ago
[-]
lg's had a good run of being a monitor, their software was a bit shit but the hardware supported e-arc etc.

i've got 2 expensive lg tvs and i bought them because you don't need to use their remote, it just turns on and shows the picture.

reply
jchw
4 hours ago
[-]
None of my TVs are connected to the Internet. That said, I could really do with a better open source fullscreen UI, especially since I mainly just want a web browser that works good. I'm just using KDE Plasma with a custom daemon to control the TV power state over an HDMI CEC adapter plus an old K830 keyboard.

I'm, frankly, a bit annoyed by this whole thing; I'd rather have USB adapter RF wireless because it is simpler to deal with vs Bluetooth, but actually I can't even find other Bluetooth keyboards that are as compelling as this K830 and worse yet, they don't even make the K830 anymore. I don't really mind KDE Plasma with just some minor customizations but I don't really like any of the options like Kodi. Maybe Plasma BigScreen will eventually be what I want for that. And finally, HDMI CEC is a pain in the ass. For reasons, I actually use an adapter to get CEC support on a normal PC platform, because most PC HDMI ports can't do it. And also, it's just a bizarre and overly complicated thing. I have it working reliably, but it took some time to iron out all the kinks, particularly because my TV responds quite differently depending on how recently it was powered off.

I really just want a big monitor and to basically just use DPMS... Like a computer does, but large computer monitors tend to be expensive and don't always have remote controls, which admittedly are handy.

reply
saint_yossarian
4 hours ago
[-]
K400+ user here, you might be interested in the upcoming Framework Wireless Touchpad Keyboard.
reply
JoshTriplett
1 hour ago
[-]
> integrated touchpad that you don’t hate.

> no mouse buttons

Failed at the first sentence.

reply
charcircuit
3 hours ago
[-]
>“The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”

Note that the same applies for the other privacy invasive webos features. But since that doesn't harm big tech's monopoly they will conveniently avoid mentioning it.

reply
symfoniq
4 hours ago
[-]
This is madness.

Only LG themselves should be able to have this kind of invasive control over your television.

reply
pixl97
5 hours ago
[-]
I mean, why didn't they do that from the start?
reply
steele
5 hours ago
[-]
Honeypot for more logos
reply
cognitiveinline
5 hours ago
[-]
Sharing a slice of your internet in a privacy preserving way in exchange for something of value, seems fair, no?
reply
walrus01
5 hours ago
[-]
Grey market residential proxy service providers are one of the most common methods of implementing bot spam, social media manipulation and plenty of straight-out fraud.

There's all kinds of things that malicious actors want to do where they value coming from an ordinary (comcast, charter, centurylink, shaw cable, whatever) residential IP.

reply
cognitiveinline
3 hours ago
[-]
You make a good point. I've reassessed and agree this is shady, and not a good pattern. And should be disabled/abolished.
reply
hokumguru
5 hours ago
[-]
I mean, some of us have legitimate business needs to get past cloudflares frankly somewhat bs gatekeeping business model, however
reply
walrus01
5 hours ago
[-]
Sure, I do as well, I have my own VPN into my home office that lets me run traffic outbound through its default gateway while I'm somewhere else. But letting random third parties I don't know run traffic through my house is another thing entirely.
reply
nikanj
1 hour ago
[-]
To be clear, bot spam and social media manipulation are legitimate business needs for the business selling said services.
reply
JoshTriplett
1 hour ago
[-]
You can't have legitimate business needs if you're not a legitimate business in the first place. Ban them all.
reply
charcircuit
4 hours ago
[-]
Just because others abuse privacy doesn't mean that we should remove privacy from everyone else. They also let you get around geoblocking.
reply
nvme0n1p1
3 hours ago
[-]
You're free to let strangers download illegal images from a proxy running on your IP, but I sure as hell won't.
reply
charcircuit
3 hours ago
[-]
If you don't want to share your internet with others, that is your choice, but please don't make seem like you are only sharing the internet with criminals. That is a harmful belief to spread.
reply
ryandrake
5 hours ago
[-]
Only if the app provides 1. prominently-displayed, informed consent, 2. an option to opt-out without losing app functionality, or 3. joining the botnet provides some kind of actual benefit to the user, besides just money to the developer.
reply
mirashii
5 hours ago
[-]
Add to that list respecting the TOS of the user's ISP so that the user does not get banned, and providing some sort of remuneration if illicit activity through the proxy causes problems for the primary user, and then _maybe_ you could call this all not shady as fuck.
reply
ryandrake
5 hours ago
[-]
If only ISPs would actually crack down on (usually unwitting) users whose systems are participating in a malicious botnet or otherwise have their networks compromised. They could offer temporary disconnection + anti-malware support to get the user cleaned up, if they actually gave a shit.
reply
walrus01
5 hours ago
[-]
No residential last mile broadband ISP at the scale of hundreds of thousands or millions of customers is presently willing to spend the salary/benefits/fully loaded employee cost on the massive teams of (somewhat technically clued in, not low wage) people it would take to effectively implement this.
reply
krackers
5 hours ago
[-]
Apparently at least one of the apps mentioned does that. From the article

>A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node.

reply
ryandrake
5 hours ago
[-]
I wonder how informed the end user actually is, and if it's disclosed to them what kind of content might pass through their network as a result of agreeing.
reply
charcircuit
4 hours ago
[-]
Most traffic is normal scraping like checking amazon prices.
reply
cognitiveinline
5 hours ago
[-]
No need of (2) and (3) - the user can choose to not install/use the app. (1) is the right fair boundary.
reply
ryandrake
5 hours ago
[-]
Those apps just shouldn't exist.

I don't know how "join your users to a botnet" became some kind of legitimized monetization scheme. Ads are bad enough. What's next? "Participate in a DDOS in order to use our app?"

reply
Dylan16807
4 hours ago
[-]
Sometimes it's botnet, sometimes it's just accessing netflix without hitting big IP range bans.

If there are proxy apps that only do the latter sort of work than I'm actually in favor of them existing and being widespread.

reply
NopIdoN
4 hours ago
[-]
"train our machine to identify traffic lights" or something
reply
LoganDark
5 hours ago
[-]
Some residential proxy providers offer a few cents for the use of your network.
reply
oasisbob
4 hours ago
[-]
No.

I'm surprised Comcast or some other ISP doesn't step in with a claim of tortious interference. Reselling or granting access to the ISPs services like this is almost always against the ISPs terms of service.

The consumer is in no place to consent to this exchange.

reply
Dylan16807
4 hours ago
[-]
On the other hand if you want to resell 2% of your bandwidth the ISP shouldn't have any say in that.
reply
ButlerianJihad
3 hours ago
[-]
Oh yes they can. If I'm a consumer, I pay for my connection that is sold to me and held in my name. I have no right to "resell" or "sublet" part of that. It is usually spelled out in the Terms of Service or Acceptable Use Policy.

At the very least, consumer connections explicitly disallow "Commercial Use". That means that you can't use them to run a business. You can't use them to turn a profit. You can't use them to generate revenue. That means no running servers, and that means no "reselling 2% of your bandwidth" for a few pennies because some Euro-Trash-Stranger wants to borrow it!

reply
Dylan16807
2 hours ago
[-]
> At the very least, consumer connections explicitly disallow "Commercial Use".

And that's really bad! Far more than reselling, you should very much be able to run a website from home!

reply
ButlerianJihad
2 hours ago
[-]
> And that's really bad!

No, it’s fair, and probably federally regulated.

You wanna run a business? Then get a business license, pay your business taxes, and sign up for a business Internet connection. That’s what they’re made for. Then run your servers to your heart’s content.

reply
TeMPOraL
1 hour ago
[-]
What if I don't want to run a business? I just want to run a website!
reply
boredatoms
4 hours ago
[-]
Tell your relatives, buy an apple tv
reply
amlib
3 hours ago
[-]
I don't think apple makes actual tvs
reply
boredatoms
3 hours ago
[-]
Whats your point exactly? Are you purposely being obtuse?

Plenty of uninformed people let their tv on the network, they shouldn’t. A separate box should instead. Tell me I'm wrong?

reply