I know its important to put things down to coincidence whenever possible, but a very expensive Bang OLufsen ( I think they use LG ) TV would turn itself off at "the" most interesting split second moments during gameplay , to the point where I thought "if I am being pranked by a friend, does this TV even stream its contents?".
Much to my surprise I found out that many modern TVs do in fact come with dev mode that allow full remote streaming.
Safe to say I turned off all the "allow metrics and market/dev modes" and have been happier since.
Lio
In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
That's an easy one to put a compensation figure on but there's probably all sorts of other exploits waiting to happen.
I think the most egregious thing here is that if you don't give the TV a network connection that it will actively search for other ways to get the data back to LG such as open WIFI.
My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet.
DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.
All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.
show comments
zerof1l
I have a rooted LG C4. Beyond blocking things at the DNS level, not accepting terms, not using AI, I wonder if there’s some existing software solution or a documented step-by-step to remove this bloatware/spyware.
prmph
Just don't buy a smart TV. Buy a good "dumb" TV (or just get a good large monitor), then hook it up to a set top box (with TV capabilities as needed).
like_any_other
I will remind everyone again that weev was raided by the FBI, arrested, and had all electronics seized, before getting a chance to defend himself in court, all for the crime of publishing emails he found on unsecured URLs he was able to guess.
But we're allowing 1000x worse things, because what, there's a vague line about it buried deep in some EULA, which means laws no longer apply?
Lets treat them the same. Raid LG, seize all of their electronics, at least in the US (other countries are encouraged to do their own raids), arrest the executives, and after they're all in jail, and digital forensics are poring over their electronics to find what else they did, they can argue in court how actually all these crimes are legal.
It's only fair.
monkeydust
Wait, do LG Webos TVs have microphones in the TV and/or in the remote? I am aware of the latter only.
acd
This is the same behaviour as the german secret police in east germany. The difference now its for ads and by tech.
All collected data are probably ai transcribed from audio to text and is fused via data fusion to serve ads. Add collaborative filtering to find similar interests between users.
show comments
trilogic
Is all of them, every "smart tv" does it, even after adb, permission restricting or rooting.
Insert a (non infected) usb lamp in your tv and see the lamp turning on when your tv is off. It notifies you about the background activation activity :) Interesting to see when exactly get active (is it keywords or nearby devices or scheduled processes)? Can´t be keywords as that would mean 24/7 active and the lamp says otherwise.
the only TV I have connected to the home network (guilty, I admit), Sony OLED 65, ARP floods my network about 12-15 hours after "turning off". On a plus side, it doesn't appear to be streaming anything out: no local DNS hits, not enough outgoing traffic for any meaningful audio stream
The choice between privacy concerns and ineptly coded network stack is tough. But that's the choice we're forced to have
show comments
egorfine
They just won't stop, will they?
show comments
gruelsandwich
As an owner of a (2020?) LG WebOS TV, to what degree can I fight this? Any point in trying Pihole with targeted blocking of certain IPs?
show comments
Y-bar
notebookcheck.net:
> We value your privacy
Shares my browsing info with 1745 "partners" with no clear way to opt out (which ought to be opt-in by the way to be compliant with ePrivacy and GDPR).
robin_reala
I mean, I’m not disagreeing, but it’s a bit rich for a site that logs data to 1,745 “partners” to be complaining too much.
VerifiedReports
Clearly the penalties for this are not high enough, because the scumbags keep doing it.
Vizio TVs were caught taking screen grabs and phoning those home years ago.
I know its important to put things down to coincidence whenever possible, but a very expensive Bang OLufsen ( I think they use LG ) TV would turn itself off at "the" most interesting split second moments during gameplay , to the point where I thought "if I am being pranked by a friend, does this TV even stream its contents?".
Much to my surprise I found out that many modern TVs do in fact come with dev mode that allow full remote streaming.
Safe to say I turned off all the "allow metrics and market/dev modes" and have been happier since.
In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
That's an easy one to put a compensation figure on but there's probably all sorts of other exploits waiting to happen.
I think the most egregious thing here is that if you don't give the TV a network connection that it will actively search for other ways to get the data back to LG such as open WIFI.
Ongoing discussions:
"216M Spy TVs – The LG Smart TV Problem [video]" https://news.ycombinator.com/item?id=49592375
"LG TVs aren't the only ones spying on you [video]" https://news.ycombinator.com/item?id=49575176
My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet.
DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.
All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.
I have a rooted LG C4. Beyond blocking things at the DNS level, not accepting terms, not using AI, I wonder if there’s some existing software solution or a documented step-by-step to remove this bloatware/spyware.
Just don't buy a smart TV. Buy a good "dumb" TV (or just get a good large monitor), then hook it up to a set top box (with TV capabilities as needed).
I will remind everyone again that weev was raided by the FBI, arrested, and had all electronics seized, before getting a chance to defend himself in court, all for the crime of publishing emails he found on unsecured URLs he was able to guess.
But we're allowing 1000x worse things, because what, there's a vague line about it buried deep in some EULA, which means laws no longer apply?
Lets treat them the same. Raid LG, seize all of their electronics, at least in the US (other countries are encouraged to do their own raids), arrest the executives, and after they're all in jail, and digital forensics are poring over their electronics to find what else they did, they can argue in court how actually all these crimes are legal.
It's only fair.
Wait, do LG Webos TVs have microphones in the TV and/or in the remote? I am aware of the latter only.
This is the same behaviour as the german secret police in east germany. The difference now its for ads and by tech. All collected data are probably ai transcribed from audio to text and is fused via data fusion to serve ads. Add collaborative filtering to find similar interests between users.
Is all of them, every "smart tv" does it, even after adb, permission restricting or rooting. Insert a (non infected) usb lamp in your tv and see the lamp turning on when your tv is off. It notifies you about the background activation activity :) Interesting to see when exactly get active (is it keywords or nearby devices or scheduled processes)? Can´t be keywords as that would mean 24/7 active and the lamp says otherwise.
Almost 13 years ago: https://news.ycombinator.com/item?id=6759426
the only TV I have connected to the home network (guilty, I admit), Sony OLED 65, ARP floods my network about 12-15 hours after "turning off". On a plus side, it doesn't appear to be streaming anything out: no local DNS hits, not enough outgoing traffic for any meaningful audio stream
The choice between privacy concerns and ineptly coded network stack is tough. But that's the choice we're forced to have
They just won't stop, will they?
As an owner of a (2020?) LG WebOS TV, to what degree can I fight this? Any point in trying Pihole with targeted blocking of certain IPs?
notebookcheck.net:
> We value your privacy
Shares my browsing info with 1745 "partners" with no clear way to opt out (which ought to be opt-in by the way to be compliant with ePrivacy and GDPR).
I mean, I’m not disagreeing, but it’s a bit rich for a site that logs data to 1,745 “partners” to be complaining too much.
Clearly the penalties for this are not high enough, because the scumbags keep doing it.
Vizio TVs were caught taking screen grabs and phoning those home years ago.
GDPR compliance lawsuitssss in 3...