cross-posted from: https://lemmy.world/post/51634640
A new Gamers Nexus investigation found a retail LG TV actively scanning the local network for phones, laptops, smartwatches and other connected devices, while also capturing microphone audio when the screen appeared to be in standby. The investigation found voice data being stored locally even after the TV was disconnected from the network, with the queued data uploaded once connectivity returned. Researchers also uncovered webOS vulnerabilities that could potentially turn the television into a remotely controlled surveillance device. The really unsettling part isn’t just the advertising angle. It’s the fact that a consumer television can sit inside your trusted network, enumerate other devices, access a microphone, store collected data locally and communicate with external infrastructure. Put that same device in a corporate office, hospital, hotel or conference room and the security implications become considerably more serious. I went through the investigation in detail, including the network scanning, microphone behavior, ACR, webOS attack surface, offline data collection and practical mitigations
Is this anything a VLAN and Pihole can’t fix?
Edit: looks kind of impossible to prevent, if it can access an open Wi-Fi nearby.
For now the only known thing to do that works is for it to never to be connected to any network.
Also if a smart tv was connected to the WiFi there is a possibility it won’t forget that until factory reset.
Is this anything a VLAN and Pihole can’t fix?
You can simply put it on a guest WiFi network that cannot see any other networks and just put a password on your main network, it is not that difficult.
Possible that they are piggy backing on other hidden networks. I remember there was a whole thing with Samsung years ago with their stuff doing something like that, and there are a few patents around that propose hidden networks from the “internet of things” days.
I just don’t want to even truck with this nonsense, where the fuck is the line before we just stop using these things? I know there must not be a line, since we are talking about circumventing our shit spying on us like it is normal.
All of this needs to be illegal, but piggybacking especially does. Circumventing the will of the end user (aka the person who should be considered the owner) as for what the product in their possession, home, and use does shouldn’t be tolerated
I want to care… I really do… But untill ceos and those who decided this was OK are killed, it will continue. Money means nothing to these evil people.
If I had a LG the on thing it would spy on would be the other untrusted shit I have on the vlan I let them use.
Fuck LG, this is creepy AF
I wonder if I can disable it if I rooted webOS on my parents’ TV
So get power strips and turn them off when you’re not using the TV.
Also keep them off wifi/network and you should be good unless they’re smart enough to try to connect to any open network they can find like some sort of malware
unless they’re smart enough to try to connect to any open network they can find like some sort of malware
Uhhhhhhh, bad news there. Many companies have been found to have their stuff make hidden networks and share info these days. I am sure you could figure out a work around if you are savvy enough, but the normal dood? Fucked and pretending this is normal.
Yeah maybe there’s way to make a file explorer for them. Maybe there’s ways to jailbreak them. We focus on phones a lot, webos was on the hp bought out palm phones back in the 2010’s.
We find out the operating systems, we jailbreak them and completely remove their programming and then, in-turn we can mess with hardware settings.
So let’s start making a TV Linux that doesn’t suck or make an Ubuntu TV version or a KDE TV version.
They can’t force people into using their OSes forever. The only thing I know is it’s like Pandoras battery trying to disable the wifi from the hardware.
Many? I heard a rumor about one Samsung TV connecting to an open Wi-Fi network, but I’ve never heard of many companies creating hidden networks.
Which is why I said just get a power strip. Can’t hack a TV that’s not plugged in.
I keep mine offline and fully turn it off via the power switch on the extension cord. My steam deck is my smart TV instead. Yay Linux!
What do you use for YouTube?
VacuumTube
Nothing
Probably safe to assume every other smart TV brand is doing the same, but just no one has gone to the effort to check…
“We own the glass, we own the TV, we own the living room. We know who is in an LG home.” –LG President of Ads
These are the Gamers Nexus videos these articles are referencing btw. Support them and their work. Get some cool shirts and physical media while you’re at it.
I’m watching the main one right now (your second link). Holy shit.
Remember: all that is done simply to give LG executives, like, a few dozen bucks over the device’s lifetime.
Customer privacy means nothing at all to them. They sell it for pocket change.
Don’t connect TVs to your network.
I wonder if any of such devices use nbiot or alike…
And according to the article the data collection runs even if it’s disconnected. So, don’t ever connect it to the network. As soon as you do everything gets uploaded.
Could I burn a hole through a WiFi chip with a soldering iron?
Only one way to find out.
Oops I meant to reply to the person saying Gamer’s Nexus found LG televisions connect without permission to any insecure Wi-Fi networks within range in your neighbourhood. Otherwise it’d seem a bit extreme to burn a hole through it :p
My TV is too old for this to matter yet but I’d research a way to physically disable network hardware before buying any specific model next time.
how is it collecting and sending data if not connected to a network?
read the article, it still needs a connection
It’s not sending them, just collecting them. Then it sends them the moment you connect. They even transcribe speech to text via mic, according to GN they send about 4GB/month… IN TEXT FILES!
How much storage could it possibly have?
You know how some people rent their wifi routers?
That’s the backbone
if it’s connecting without your explicit permission each time how us that not a worm
Because it is done by a wealthy corporation. See also: rootkits from Sony.
that shit should have been a jail term
but i stopped buying sony over it
The person you are replying to said that the smart TV collects spy data onto a hard drive even when it’s not connected.
Then once the TV acquires a connection, it dumps the entire drive worth of spy data to the mothership.
The danger here is obvious, I think.
i just misread their post originally
reread the comment you replied to
lol i missed the entire second part
and i meant i read the article
not you read the article
Read and read and reed and reed. Love english
You edited your comment but rereading did not clear up what yaroto is saying, which is that it will build up a collection of recordings, not send any when not connected. Upon connection, recordings will then be sent.
i should just let other ppl be wrong on the internet
yea because
read
read
read the same, i was trying to be clear
i’m saying you are right, relax, i must have skipped over your second sentence on
Deleted by author
This would’ve worked just a few years back but due to shitty “age verification” laws, even TV manufacturers willl force users to create an account the very least for the TV to even start up. They may also implement an always-online model and they’ll justify that it’s necessary to monitor users for “age verification purposes”. ATP better to get a good monitor and use it as TV cuz cable or satellite boxes are either way gonna be provided by the network companies so that’s there
This would’ve worked just a few years back but due to shitty “age verification” laws, even TV manufacturers willl force users to create an account the very least for the TV to even start up.
Surely only for “smart” features but without enabling any of that shit, you shouldn’t get any age verification prompt.
I could see them doing it anyway as OTA broadcasts include rating data.
That said, if it’s a family TV, you’re never going to put everyone on it, just the oldest one anyway.
Impossible - no one would buy them, and that idea would die.
[citation needed]
A citation… of a would be scenario? My what a confusing comment.
I think their point is that by and large consumers are stupid and willing to put up with almost any garbage like that. What makes you think otherwise?
Where is the original citation showing you cannot use a tv disconnected, without setting up an account?
This whole thread is nonsense.
What emb said. When in the history of the universe did consumers reject a product like that? You do realize Alexa and Google speakers are still very popular and tons of people wear watches with GPS, sleep tracking, heart rate tracking and always turn on BT?
So I should connect it to someone elses network?
Although usb stick firmware updating is super annoying
The TV should just act as a TV with input ports. Why update the firmware?
Works for now, but my fear is when that may not broadly be the case.
This is the only correct answer. Discussion over.
Imagine when it’s turned on…
This is why I don’t let my TV watch porn.
If you are going to have smart devices, put them on their own VLAN. They should not have access to the rest of your network. TVs shouldn’t be connected at all. Use a PC or android box if you want to stream stuff.
The issue in this case is that they apparently use text to speech locally, store that information on the device itself, and then if at any point in the future gets connected to the internet for any meaningful length of time (be it by a subsequent owner) it will then be sent on to LG… for safekeeping of course /s
The deep-dive by GamersNexus is pretty in depth.
In that case, it should be disposed of like an SSD that contains sensitive information. Find the flash chips and either drill holes through them or smash them into dust with a big hammer.
Just desolder the mic
That would work if you can open the case without breaking it. Modern TVs are usually clipped together and the bezels are really thin. It’s very easy to crack the panel when trying to get the case apart.
I don’t care that companies thought they’d get away with this, the problem is have are the people buying this shit! This should’ve been enough to get people to just refuse to buy it but no.
And the bigger problem isn’t what we know they can do, you have to think about what it ‘could’ do.
Even if you never connect this stuff to the internet, they could still track all this stuff locally. Once that happens, which no doubt it will if not already, what happens if suddenly you get arrested for something, they confiscate the TV, download all the stuff tracked, and oops, something even more incriminating… maybe you watched an illiegal movie on jellyfin! 😲
Look at all the “People will never let it happen” that has happened pretty much unchallenged… you’ll have no privacy, and you’ll all be paying for it!
The majority of people do not realize how much information is being recorded and what it’s used for. If there was an easy way to track down how a telemarketer got your information, a lot more people would freak out and demand change.
What exactly is the alternative? Every tv manufacturer is doing this. Buying a commercial display isn’t the answer.
Scepter.
(I dunno if they’re doing it yet or not but I bought a dumb TV and a dumb monitor from them and I really hope they stay dumb)
The problem is not that people are buying this willingly, it’s because they don’t know. If you present them two rougly similar options, but one of them is a spying machine, people will choose the other one. This stuff should not be legal in the first place.
The problem’s that what’s presented is a cheap machine vs an expensive machine. Guess which one spies on you?
That’s true, but the law should be the first line of defence against practices like this - you can’t expect every person to do thorough research on every appliance they buy.
That’s not true at all. The LG OLED (C5, G5) are very expensive. I paid over 1300$ for my C4 last year and just learned that LG is pulling this shit.
Really makes one wonder…How many fucking data points do these assholes need telling them we’re too fucking broke for their game and want their heads on pikes?
Enough that they can tell with a decent amount of certainty whose social credit score should be lowered, once that gets inevitably introduced /s
(I don’t think that conspiratorially… It’s probably just data harvesting and extreme greed.)
That social credit works only as long as you want to buy shit. If you’re like me and don’t even own a credit card, these assholes have zero power over any aspect of my life because anything they own/control, I wouldn’t want to use anyhow. They are only professional capitalists because the public are amateur consumers.
Unless it gets to the point where it’s impacting where you can live or work
The issue is that they don’t care, they sell the data to others and they get to spin it while doing it. Its not selling data (that you are broke) to an advertiser, its the idea of that advertiser falling behind if they don’t buy your data (that you are broke).
At least 13k












