cross-posted from: https://lemmy.world/post/51634640

A new Gamers Nexus investigation found a retail LG TV actively scanning the local network for phones, laptops, smartwatches and other connected devices, while also capturing microphone audio when the screen appeared to be in standby. The investigation found voice data being stored locally even after the TV was disconnected from the network, with the queued data uploaded once connectivity returned. Researchers also uncovered webOS vulnerabilities that could potentially turn the television into a remotely controlled surveillance device. The really unsettling part isn’t just the advertising angle. It’s the fact that a consumer television can sit inside your trusted network, enumerate other devices, access a microphone, store collected data locally and communicate with external infrastructure. Put that same device in a corporate office, hospital, hotel or conference room and the security implications become considerably more serious. I went through the investigation in detail, including the network scanning, microphone behavior, ACR, webOS attack surface, offline data collection and practical mitigations

  • DoctorWhoDMC@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 hours ago

    … Well great, now I have to check whether my television has a goddamn microphone for some reason. I didn’t think to check because it’s a television.

    Never connected it to the Wifi though.

    • Mr_Dr_Oink@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 hours ago

      Could connect the tv to the guest wifi network which would prevent it from accessing your local network. Plug in an android tv box of some variety and connect that to the network and you can cut the tv off f4om internet entirely.

      If you set the pihole as your primary DNS on your router then all network traffic goes that way anyway. Set up google as a secondary in case your pihole goes down. Or configure a second pi hole for resilience and set that as the backup.

      • TassieTosser@aussie.zone
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 hours ago

        The GN investigation discovered that LG makes the TVs mesh with each other as well. So even if you don’t connect your LG to the internet, it can connect with other LG devices in the neighbourhood and exfiltrate data that way.

  • 0x0@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    15 hours ago

    It’s hard to find a dumb TV.
    Monitors and projectors are going the same way. Not connecting them might not be enough.

    Time to learn how to use a soldering iron.

    • Hueristic_Autistic@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      12 hours ago

      modern ones are soldered directly to the board and integrate bluetooth into the same chip and removing that chip form the board could remove the ability to use bluetooth functions and the remote, however!!! most have usb ports!!! lets make new operating systems and fucking delete their file system, load a new os that lacks the abilities these manufactures have.

      The hardware is whatever but if we remove the file systems that its preloaded with it won’t be able to load any of its preinstalled shit. If we mod the operating system we can mod some of the shit the hardware is capable of doing through the software and coding. Kinda like how windows 11 is known for lowering ram speed.

          • rumba@lemmy.zip
            link
            fedilink
            English
            arrow-up
            0
            ·
            10 hours ago

            Thanks, threw me for a loop when they recommended trying to unsolder a chip from the sbc and expecting it to still work as a tv at all.

  • paulcdb@lemmy.radio
    link
    fedilink
    English
    arrow-up
    0
    ·
    15 hours ago

    I don’t care that companies thought they’d get away with this, the problem is have are the people buying this shit! This should’ve been enough to get people to just refuse to buy it but no.

    And the bigger problem isn’t what we know they can do, you have to think about what it ‘could’ do.

    Even if you never connect this stuff to the internet, they could still track all this stuff locally. Once that happens, which no doubt it will if not already, what happens if suddenly you get arrested for something, they confiscate the TV, download all the stuff tracked, and oops, something even more incriminating… maybe you watched an illiegal movie on jellyfin! 😲

    Look at all the “People will never let it happen” that has happened pretty much unchallenged… you’ll have no privacy, and you’ll all be paying for it!

    • nserrano@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 hours ago

      The majority of people do not realize how much information is being recorded and what it’s used for. If there was an easy way to track down how a telemarketer got your information, a lot more people would freak out and demand change.

    • Xabis@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      10 hours ago

      What exactly is the alternative? Every tv manufacturer is doing this. Buying a commercial display isn’t the answer.

      • Talcosis@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        9 hours ago

        Scepter.

        (I dunno if they’re doing it yet or not but I bought a dumb TV and a dumb monitor from them and I really hope they stay dumb)

    • dontfeedthemouse@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      15 hours ago

      The problem is not that people are buying this willingly, it’s because they don’t know. If you present them two rougly similar options, but one of them is a spying machine, people will choose the other one. This stuff should not be legal in the first place.

      • 0x0@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        15 hours ago

        The problem’s that what’s presented is a cheap machine vs an expensive machine. Guess which one spies on you?

        • AbKingPro@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          10 hours ago

          That’s not true at all. The LG OLED (C5, G5) are very expensive. I paid over 1300$ for my C4 last year and just learned that LG is pulling this shit.

        • dontfeedthemouse@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          15 hours ago

          That’s true, but the law should be the first line of defence against practices like this - you can’t expect every person to do thorough research on every appliance they buy.

    • OakTree@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 hours ago

      I was radicalized when a Roku TV told me I needed to be online to change an input name from HDMI1 to Xbox. Motherfucker WHAT.

  • Tikiporch@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    20 hours ago

    Is this anything a VLAN and Pihole can’t fix?

    Edit: looks kind of impossible to prevent, if it can access an open Wi-Fi nearby.

    • gian @lemmy.grys.it
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 hours ago

      Is this anything a VLAN and Pihole can’t fix?

      You can simply put it on a guest WiFi network that cannot see any other networks and just put a password on your main network, it is not that difficult.

    • Johanno@feddit.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      16 hours ago

      For now the only known thing to do that works is for it to never to be connected to any network.

      Also if a smart tv was connected to the WiFi there is a possibility it won’t forget that until factory reset.

    • M0oP0o@mander.xyz
      link
      fedilink
      English
      arrow-up
      0
      ·
      20 hours ago

      Possible that they are piggy backing on other hidden networks. I remember there was a whole thing with Samsung years ago with their stuff doing something like that, and there are a few patents around that propose hidden networks from the “internet of things” days.

      I just don’t want to even truck with this nonsense, where the fuck is the line before we just stop using these things? I know there must not be a line, since we are talking about circumventing our shit spying on us like it is normal.

      • captainlezbian@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        10 hours ago

        All of this needs to be illegal, but piggybacking especially does. Circumventing the will of the end user (aka the person who should be considered the owner) as for what the product in their possession, home, and use does shouldn’t be tolerated

  • johntwinkletits@fedinsfw.app
    link
    fedilink
    English
    arrow-up
    0
    ·
    21 hours ago

    Every device with a CPU, WiFi module, and microphones are vulnerable to this. If you don’t want to be vulnerable, build your own hardware, software, and network. There’s no other option.

    • ayyy@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      18 hours ago

      This is terrible and useless security advice. There is actually a whole lot you can do besides just giving up.

    • bthest@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      19 hours ago

      Or just don’t allow corporations to put microphones and wifi into literally everything so that we CAN have some options. Even a no frills basic TV wouldn’t need a CPU if it just uses analogue connections. Those are still being made for now. So yeah it’s possible to have a TV and not have to live in fear of it spying on you.

  • MehBlah@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    21 hours ago

    If I had a LG the on thing it would spy on would be the other untrusted shit I have on the vlan I let them use.

    • silicon@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      23 hours ago

      Also keep them off wifi/network and you should be good unless they’re smart enough to try to connect to any open network they can find like some sort of malware

      • M0oP0o@mander.xyz
        link
        fedilink
        English
        arrow-up
        0
        ·
        20 hours ago

        unless they’re smart enough to try to connect to any open network they can find like some sort of malware

        Uhhhhhhh, bad news there. Many companies have been found to have their stuff make hidden networks and share info these days. I am sure you could figure out a work around if you are savvy enough, but the normal dood? Fucked and pretending this is normal.

        • frongt@lemmy.zip
          link
          fedilink
          English
          arrow-up
          0
          ·
          11 hours ago

          Many? I heard a rumor about one Samsung TV connecting to an open Wi-Fi network, but I’ve never heard of many companies creating hidden networks.

        • Hueristic_Autistic@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          13 hours ago

          Yeah maybe there’s way to make a file explorer for them. Maybe there’s ways to jailbreak them. We focus on phones a lot, webos was on the hp bought out palm phones back in the 2010’s.

          We find out the operating systems, we jailbreak them and completely remove their programming and then, in-turn we can mess with hardware settings.

          So let’s start making a TV Linux that doesn’t suck or make an Ubuntu TV version or a KDE TV version.

          They can’t force people into using their OSes forever. The only thing I know is it’s like Pandoras battery trying to disable the wifi from the hardware.

  • SaharaMaleikuhm@feddit.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 day ago

    I keep mine offline and fully turn it off via the power switch on the extension cord. My steam deck is my smart TV instead. Yay Linux!

  • cmnybo@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 day ago

    If you are going to have smart devices, put them on their own VLAN. They should not have access to the rest of your network. TVs shouldn’t be connected at all. Use a PC or android box if you want to stream stuff.

    • Humanius@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 day ago

      The issue in this case is that they apparently use text to speech locally, store that information on the device itself, and then if at any point in the future gets connected to the internet for any meaningful length of time (be it by a subsequent owner) it will then be sent on to LG… for safekeeping of course /s

      The deep-dive by GamersNexus is pretty in depth.

      https://www.youtube.com/watch?v=6IFVTcM28KA

      • cmnybo@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        0
        ·
        20 hours ago

        In that case, it should be disposed of like an SSD that contains sensitive information. Find the flash chips and either drill holes through them or smash them into dust with a big hammer.

          • cmnybo@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            0
            ·
            19 hours ago

            That would work if you can open the case without breaking it. Modern TVs are usually clipped together and the bezels are really thin. It’s very easy to crack the panel when trying to get the case apart.