LG smart TVs caught logging audio with screen off and snooping on local devices
An investigation by Gamers Nexus found LG smart TVs sweep local networks to map phones and nearby devices. Tests also showed the sets can capture microphone audio with the screen off — they then upload data once reconnected to the internet.
I don’t know if any TVs are actually using it, but Amazon Sidewalk is a form of LoRa, low power, low bandwidth, long distance communication. It’s designed to let non-internet connected devices phone back home. I hear it is very popular with shipping trackers because you can put a small device in a pallet and have it send it’s GPS back for free. I’m not sure it would support the GBs of data TVs are phoning home with each month, but it could certainly send some data home.
You could try to host your DNS, change the router DNS to that and then spend a while to see to which addresses the TV talk to and block them, it’s probably time consuming but if you have that time, it can work
Yeah, I know. I have a blocklist for LG and other common brands compiled by someone else on my router DNS adblocker. But considering how sneaky they are with collecting information they should stay the fuck away from, I bet they have mechanisms to get around their common ad domains for the data that matters.
Yeah you are right, you are better of staying away from LG but if you already have one, you could make a subnet for the TV (and/or other IoT devices) with a DNS whitelist to block every domain except Youtube or whatever else is used
I have a separate and isolated net for all my IoT and smart home devices but things like the telly, amp, media player etc need to have some network access. Makes me tired that this kind of fiddling is necessary.
Oh right that might be a problem, but in that case we can make a subnet (as i suggested on another reply) and block any connection that isn’t on specific addresses or IPs with a firewall
It’s not the politicians job to know everything but to make decisions and legislate based on information from the expertise. It is the people in the know that need to make the proposals for the politicians to bring it up. It’s us, the tech literate, that need to write proposals that are informative with arguments derived from trusted sources to make the politicians aware that these are concerns that need to be addressed.
Let’s all lie belly up and do nothing and accept that nothing will ever change for the better because nobody else is doing it for us and it is impossible for us to change the world all alone. This is exactly the defeatist mindset that the economic elites want people to have.
You could do something small, like find out your representatives and write a personal mail to them, informing them from your point of view. With enough people doing small things and some doing big things the chances for things like this gaining traction are magnitudes bigger than giving up in advance. It takes a few hours to a few days depending on your dedication and whatever cost coffee is in your area of residence.
I can’t tell if this comment thread is filled with doomer basement dweller defeatists that use their worldview as excuse to not even try or foreign bot farms pushing said agenda.
Yeah sorry, it’s not just time and money,but also skill. I’m not the person you choose to convince people to do something. That’s why we choose representatives. That’s why we vote.
After proposals come in, yes. If the only proposals coming in are from lobbyists of various corporations and interest groups, guess which matters are going to be on the table?
The fucked up part is that “expertise” is assumed to be exclusively found in the industry being regulated. Bill Gates is a respected industry expert, but RMS is just some dumbfuck nobody because he’s not “in the industry”.
Maybe read what you write? No reason to make yourself look so dumb (and just to state the obvious, I’m not disagreeing at all, just pointing out what should be obvious but apparently isn’t).
In the later years the EU regulations have been massively disappointing. Only favouring big EU companies and destroying little businesses and the european consumers.
Some disappointing eu regulations:
The cookiesgate. Your data is still going around everywhere. You just have a pop up everywhere that means nothing.
¿Replaceable batteries on smartphones? No, only for cheap chinese phones if so. The big players can pay for some european certification on the quality of their batteries and doesn’t need to be replaceable.
¿Stop killing games? Hahahaha don’t ever think about it.
You are buying too much, we need you poorer. So we put up a 3€ tariffs per category product on chinese stores so you are forced to buy the exact same product to an european retailer at twice the price.
We heard you like the environment, what about a new complicated tax on packaging so all small business cannot function and only big business are allowed to send products within the european union.
I think the days of the EU legislation saving the day are far off.
Liberalism will always be corrupted by capitalism at the end of the the day. Maybe some systems last a decade or two longer, but it’s all bound to fall.
IMHO Liberalism was manufactured by Capitalism as a left-sounding form of politics to allow mainstream parties which were genuinelly leftwing to move Right in Economic, Quality Of Life and even broad Equality whislt still appearing to be left-wing due to their pro-liberty posture on Moral and Social subjects.
I say this because I have yet to see any form of Liberalism in mainstream politics, ever, anywhere, which sought to maximize people’s freedom to access limitied or constrained resources which are required merelly to live, such as Land (which Land Ownership goes against), so I don’t think that at least in Politics there was ever any genuine Liberalism for Capitalism to corrupt.
That charge is not just on Chinese stores. I manufacture my own product in the usa through a factory i own and get hit with those fucking charges.
Then I’ve got to pay for all this cardboard and plastic but OH LOOK there’s a minimum fee so I’m subsidizing larger businesses or Europeans in general. AND I need to pay for a European contact to do it! Fuck yourselves for that one.
Eu regulation is hostile to small business and they will be left with nothing but major shitty international corps at this rate.
I mean the whole point of this is to subsidize small business in the EU at the expense of businesses outside the EU. The fact it is more difficult and costly for you is exactly the point. They want to support businesses and workers in the EU, because that’s where their people actually are, that’s where their taxes are, that’s where they support infrastructure and social programs.
It is true that it favors larger international corporations, because they have near monopolies and csn manage all of this at a smaller relative cost. The solution of course is to make tariffs and other import duties scale with the size of the company.
So the EU regulations are not perfect, they do hurt international small businesses while protecting in part local small businesses. They need, like everyone, to deal with the problem of international monopoly companies and restore more and more of their manufacturing and product development into more and more local small businesses.
Secretly recording conversations in peoples homes sounds like it should be against the law in a number of countries.
Imagine someone working for the government, security services, or a defence contractor. I suspect LG may be in trouble with a number of National Security agencies.
It is illegal. Unfortunately crime is legal for corporations. They just pay the crime fee and can continue undisturbed. Shareholders must be held responsible individually, otherwise it will only get worse.
Shareholders must be held responsible individually
So, are you personally on the hook here because the company managing your pension fund is holding stocks in LG? Because that technically makes you a shareholder as it was bought with your money, right?
Edit: not sure why I get downvoted, this is a legitimate concern/nuance to the debate. The managing company doesn’t own these stocks so they’re not the shareholders, that’s the people whose money they are managing, but these people are not directly in control of the funds. Who is the liable party in this?
The fact that a pension fund can hold shareholds is crazy by itself, also, is the pension found a company or managed by your state? It shouldn’t really be a thing in first place
is the pension fund a company or managed by your state?
Both in my case, as there are both the government pension fund that is mandatory and the one used by my employer which uses one of the large primary pension institutions in my country.
Is it a bit weird that I don’t just manage all my pensions myself? Yes, a bit. But it’s how its done in my country and it has some tax benefits compared to getting the money in hand and investing myself.
See the thing is if your pension also funds a murder company does outsourcing who manages it not make you at least a little culpable? I think it does and i think the only way to stop this madness is for a little justice to come your way.
does outsourcing who manages it not make you at least a little culpable
What if i have no control over who manages it? I have two, one is government managed and mandatory, the other is part of my salary (and mandatory) and who manages my company paid pension is decided by my employer. I have no control of either aside from general risk profile and high level market groups on my company paid pension (e.g. “tech” or “renewable energy”).
Also, which shareholders? Shareholders have no say in the business decisions outside of the annual voting for board members and whatever broad issues are brought up for a vote. If someone holds stock and then sells it before a vote, are they responsible for the business decisions? If a swing trader bought and then sold in one day/week/month (even at a loss), how much is their liability? If someone sells their shares just before a vote, then buys them again after, are they liable?
If I don’t get executive say in what happens at the company, I am not included in liability. I am not allowed to sit on the damn board with my pension fund.
Executives and controlling board members get held personally liable. It really is as simple as that. If you are in the meetings, and you get a vote, you are liable. There is absolutely no slippery slope fallacy here.
Any bullshit “uhm actually you technically are a shareholder” is just trying to ward off people having to take responsibility for their decisions. (also, in many pension schemas you aren’t actually the shareholders, the investment fund technically is and you are just given the license to decide how they invest those funds and get a portion of the payout, but it is different than manually retail investing for example)
Not shareholders. Decision makers. Upper management.
Shareholders should pay in share value (the financial penalty to the corporations should be high enough to affect that), bu the personal an criminal responsibility belongs to managers, CEO in particular.
There should at least be something resembling an attempt of investigating, who, where, and when signed an order to implement this shit into their products. That way they will at least think twice if they want to risk the chance of being held personally responsible.
Recording without consent is very much a crime in any two-party state, but my guess is that the TOS that people click past to use the TV gives them permission to record you. If it didn’t, they would be in big legal hot water.
Making that consent required to use the TV or its features and it being buried within lengthy, opaque terms of service in a country with a low level of literacy should be illegal, but it stands in the US because it’s a consumer hostile country.
A TOS presented after an electronic device has been sold is not valid in most of the World since it’s considered an attempt to, after the sale, force a change of the terms of the implicit contract which is the sale.
A company can shove whatever they want in front of the customer as contract conditions they have to accept for a sale before the sale - by which point the potential customer can refuse and not buy or accept and buy - not after.
Of course, they don’t do that because they would lose most sales, so instead there’s a TOS or EULA which the owners of the devices are forced to agree to after the sale to fully enjoy that which they bought, but these are really just legal fictions in most countries.
Mind you, this does not apply to a subscription to an ongoing service, though even then at least in Europe, there are conditions they much obbey to have the customer accept a TOS or a TOS change after subscribing, such as it being possible for the customer to cancel the service at no cost rather than accept the new TOS.
“In any two-party state” what? That’s such a weird thing to say. Two-party systems are a worse version of applied democracy, that should be incredibly obvious. I just seriously don’t understand why you would even think about saying that it’s a crime in two-party states only, it’s so odd. If anything two-party states are more akin to not having strong laws against that because of the very fact of it. Look at the US, which I’m guessing is a big part of your mind in this. Do yourself a favor and search for countries two-party systems and their laws on this compared to actual democracies with more parties.
Call recording laws in some U.S. states require only one party to be aware of the recording, while other states generally require both parties to be aware. Several states require that all parties consent when one party wants to record a telephone conversation.
I have basically every URL our TV automatically pings blocked at this point. It phones home every 10-30 seconds whether they’re off or on. I think when we get a new TV we’re looking for a dumb TV
To be clear this was Windows, detecting you had an LG display device plugged in, and Windows Update opting to automatically download the latest drivers/software for that LG display.
I have a led backlight connected my TV’s usb port and I’ve noticed it comes on randomly when the TV is turned off, then turns off. This happens couple of times throughout the night, when the TV is clearly doing something
And that’s why I have a VLAN without outbound connections allowed. Still allows me to cast to the device from a separate vlan but the TV has no internet at all.
Seriously, this is the way. I did this too in about 15 mins. Also setup a simple rule to allow the vlan to reach my homeserver in a separate vlan specifically on Plex and Jellyfin ports. That's it. They cant phone home. You still enjoy your own media.
I’ve recently tried setting up VLANs on my network, but I’m very new to this type of networking. I’ve got a bunch of guides and videos bookmarked, but I haven’t successfully got things working yet. Would you happen to have any good resources for a beginner? I THINK I have all the hardware I’ll need—a Pi5 8GB with OpenWRT installed, a managed gigabit switch, and a router flashed with OpenWRT to act as an access point. And a ton of Ethernet cables. I’ve also got some Lenovo Tinys I could use with… Opnsense? once I’ve got more knowledge and skillz and stuff.
Did this a few month back. Then my Sony TV decided to hide all apps when it has no internet for a few weeks. I guess when the internal disk is filling up and it needs to phone home again. What a shit show!
Clarification: Most Android users don’t use custom firmware (“ROM”). OEM means the company that makes your phone. All the major ones use Google Play Services. Nothing and OnePlus might be exceptions as those are known for using custom firmware that is more private. Also, Pixel phones running GrapheneOS ostensibly do not include Google Play Services. But Pixel phones don’t ship with GrapheneOS. You have to add that yourself by unlocking the bootloader (available deep in the settings, wipes the phone), and manually flashing the custom firmware (CFW or “ROM”) to the phone.
That said, the whole reason Android exists today is because Google was getting a lot of personal data from Gmail, but when they saw Andy Rubin’s invention, they realised they could get a lot more personal data with a phone, so they bought Android from him.
Android collects a lot of data (as that is its primary purpose for Google), but it doesn’t upload everything you say. It — or, more accurately, Google Play Services (and possibly other services) do other underhanded things to exfiltrate your data from the device back to Google. Like if you try to use an ad blocker, it will use DNS filtering to tunnel around the ad blocker for its own uses.
The wildest thing is, Google successfully ran an ad campaign convincing people their way was the right way and that Apple’s way of doing things was wrong. That’s a big part of why Apple is trying to be more like Google. They’re certainly not hurting for money, but they see people willingly accepting this sort of thing, so they’re realising more and more how much money they’re leaving on the table. Imagine if it had gone the other way, if more people rejected Google and its data collecting practices. We’d probably be paying more for some things since we’re not (also) the product, but more companies would be putting privacy first. Because that’s what the consumers would be demanding. But no, we have people out there, a metric fuck ton of them, saying privacy is negotiable. So, companies are negotiating with privacy — mostly against it.
I think I will opt to not belive they are not collecting.
Google been caught time and time again doing shady stuff and enabling evil features by default with some obscure optout mechanism either added later or only after been caught.
I assume any device with such a capability is doing so until proven otherwise. And some internet poster saying no and relying on conjectures isn’t proof. i.e. Throwing around technological illiteracy implications.
The modus operandi of tech companies is to do it. Deny doing it. If they get caught, say it wasn’t that bad. If it was, it a mistake and they didn’t mean it. And maybe you asked for it by using the device in the first place.
I assume any device with such a capability is doing so until proven otherwise.
I tend to agree.
Google been caught time and time again adding anti consume features and enabling by default with some obscure optout mechanism either added later or only after been caught.
Great, I wonder what my fridge is up to. It’s LG and has wifi for some reason. I never connected it to my network, but I wouldn’t be surprised if they take advantage of open networks anyway
My LG fridge also beeps, as any other fridge would. I guess the added benefit is that it can send a notification to your phone, maybe useful in some scenarios, all it costs is your privacy…
My LG TV runs WebOS, which is a linux distro. I have been wondering how hard it is to root and replace with a distro of my own choosing. I had thought because my TV is pretty old that I was safe from the more sophisticated spying, but last week it interrupted what I was watching and would not let me continue using it without agreeing to new terms of use. This revived my interest in rooting it.
I didn’t know LG webOS rooting was a thing, that’s interesting to know.
There is an open source version of webOS, although I don’t know how it compares to the stock LG version. Maybe there will eventually be something like a LineageOS equivalent.
cani.rootmy.tv - I just recently bought an LG for the first time, with eyes wide open, and used this site to get root on it, as well as VLANing it with a strict block list, but also an allow list only based policy, and strict no external DNS requests policies.
Also worth knowing that when accepting their policies many of them are optional and are just data slurping consent , think it was the top 2 compulsory in my region out of about 5.
Waiting for the “No idea how this happened, we’re sorry and promise to make this better in future versions” moment - instead of admitting that this is just part of their business model.
Hoping for prosecution from the EU and at least one other country.
The EU is not a country, yet it does stuff that otherwise countries do, like legislating and judicating privacy laws. The correct term would have been “other political entity” but what is the point of that word picking again?
Like any political entity the EU can do many things at once, the good, the bad, and the ugly. Different institutions also have different interests. The Commission isn’t the primary driver behind chat control, a number of member states are. At the same time EU courts tend to be staunchly opposed to mass surveillance and in the European Parliament it depends on the party.
Me too with my TV. But reading more detailed comments here, it’s more complicated and nuanced than just “if it has a direct Internet connection it will get up to shenanigans”. Sounds like this device is using HDMI to manipulate Windows (install drivers etc) and piggyback off the Windows machine’s Internet connection. But I’m assuming if it’s not plugged into a Windows PC directly it might not be a problem.
Why fabric and aluminium foil? Pretty sure removing microphones/cameras/bt/wifi modules is enough :p
Also, the foil wont do too much if you dont ground it!
There’s a lot of misinformation in the comments here.
LG have been caught using the Internet connection of connected devices (like windows computers) to snoop on your network.
Because of that, it has access to your network even if you remove the wifi module or do not connect the TV directly to your network.
Lobotomizing the TV will not necessarily fix this issue, but I still think it’s a good start. It may be beneficial to switch to a different operating system or just ban the TV from accessing certain parts of the Eco system on your computer.
Removing Bluetooth, wifi, and microphone modules will be beneficial in the long run because this will not be the last time a company tries this and it’s not limited to LG. If you are technically inclined or can follow a YouTube video, go for it.
I think you’re misunderstanding what’s happening. The LG TV isn’t directly using the Windows internet connection. It’s taking advantage of Windows Update to have Windows itself install malware as a driver update for the screen.
Which I think is actually worse, because it shows that Microsoft is complicit in this nonsense.
This all happens the moment you plug that HDMI (or DisplayPort for people who purchased an LG computer monitor) right into an internet-enabled laptop through a protocol called EDID, also known as “Extended Display Identification Data,” which by itself is totally harmless!
It simply tells your operating system what kind of monitor is connected, what its capabilities are, it’s serial number. That’s it!
Inside Windows, when you go to Device Manager, it might not seem like much. Just a generic PnP device attached as a monitor.
Dive a little more into Device Manager, and we see where EDID does its magic; we found that this particular Microsoft Box is hooked up to some kind of Samsung monitor. Now, Samsung might have some kind of driver that would help take advantage of my monitor. But this Samsung is so old they simply do not care.
Yeah, it’s installing drivers on WINDOWS.
So, caveat two is don’t connect these things to an internet-connected WINDOWS machine.
Good point.
But, as others have said, if you do successfully air gap one of these things, it might stop working because a hard drive is full, or more directly because it can’t phone home and is designed to lock you out in that case.
On Gamer’s Nexus’s video on the subject at 1:20 you’ll hear how they talk about how LG accesses your network data through windows.
I think it’s important to note that I didn’t say in my original comment anything about it using your windows Internet connection to send and receive that data that it collects via microphone or that it may have accessed through your Wi-Fi network if you happened to connect it to that.
I think people assumed (it’s early for me, my bad) that I meant it was transmitting this data that it collected over your windows computer’s Internet connection but that wasn’t what I was intending to claim. When you connect an LG device (Television or Monitor) you agree to allow that device access to your network and they literally say they have full access to your device both in the TOS and in device settings . They gather all the information of every single device connected to your TV. Their apps can “use all system resources” and “access your Internet connection”.
Stuff like this is why I'm still holding on to my old TV for dear life. It's seen better days but it's at least easily repairable.
The amp went bad which causes the internal speakers to give up after a couple of minutes, so I just run it with a soundbar. Then one of the cats broke the optical port for it, so now it's taped on lol. The panel still works great, so I think I'll just replace the main board on it to keep it going for a few more years.
Once something on it finally goes where repairing it becomes unviable, then I've no idea where to go from there. I guess I'll just keep buying used TVs and fix them up.
I do tv repair. They are dead east to repair. Its basically a large laptop. You have a system board, power board, and depending the brand a few other smaller boards that are easy to swap. Getting the parts is not incredibly difficult, but it depend how new, how old, Eric. EBay is key. But, like any tv, of its the screen, it’s trash. Typically costs more to replace that then buy new.
It’s still listening and recording. The recent Gamers Nexus video shows that the just store everything locally until they find a way to send it. They’re always scanning the radio for other access points too.
My Visio TV developed a thing where the OSD menus freeze up and the controls unresponsive frequently - it’s not connected to WiFi. Its my opinion that some internal drive is filled up with my watch data that a factory reset cannot fix, and I suspect the lack of disk space is why it’s freezing. I can’t* prove this, but I suspect it to be.
*I might possibly have the skills to, but my time is devoted to other tasks, and I don’t want to deprive my household of the living room TV just because I want to tear it apart.
High risk low reward. the eFlash would almost certainly be wiped in a reset. If you did get to it, it’s not removable. If you unsoldered it, the new one could need a base load on it for it to work. You could probably buy a used board from another TV, but it could well already have issues. Getting the screen off and back on in one piece isn’t trivial.
A friend of mine recapped his 75" Took most of a day, it did fix the tv, but he complained that it was definitely not worth it.
You’ll also have to make sure to properly destroy it afterwards. If you re-sell it, the next owner might connect it to the internet and all the stored data will get uploaded.
Also there’s tech like Amazon Sidewalk that allows devices to talk to other devices nearby in a mesh, bypassing your router entirely.
My “big” TV is a 55", 14-year-old Toshiba dumb display. It still works as well as it ever has, but it’s not OLED and it’s not 100", so sometimes I think maybe…
But, then I read articles like this, and decide against it.
Could you please share what resources you used? I connected my TV to the internet before all of this came out, and I’d like to completely wipe it and start fresh
That’s why my TV doesn’t get wifi access, and I use a third-party device like an Amazon Fire to do all my streaming, so at least it’s Amazon who gets my data, not LG.
Back in the 90’s we had designated computer desks, where the big ass CRT and big ass desktop PC lived. Most people would use a surge protector power strip with a master power switch, and they would use that one switch to turn on and off the CRT monitor, PC, printer, desk lamp, etc…
I still do that and never did it any differently. Mainly to conserve energy, since my parental household was poor and we actually could not afford to leave appliances running when not in use. This became a habit and now I’ve been incidentally preventing data harvesting for years. I do need to get an old 90s alarm clock though, since I cannot always turn off my phone at night when I have plans in the morning. Also GrapheneOS.
I have a Samsung TV that I suspect does this. Once upon a time (back when I was less knowledgeable about this practice) I connected my TV to the internet. I have since been totally I able to forget my network from the TV, even a factory reset didn’t wipe the network settings from it. I’ve had to block it from the network at a router level.
I only discovered it was still doing this when I got a new router, and I had a popup on my TV saying “software update downloaded and complete” and I was wondering how tf it did that even though I’d gone through the process of forgetting the network, and seemingly the settings showed it had been “done”.
I’m very glad that my “unsubstantiated fearmongering” regarding smart TVs doesn’t look that unsubstantiated anymore. I’ve Bad my girldfriends Samsung smartTV Lockes down once she moved in with that thing and I saw what kind of connections that thing made.
Not that simple for her, she likes some of the features it offers. For example, using the youtube app on your phone to control videos on the TV. I’ve blocked most unrelated domains tho, including the update domains so I’m not being surprised by a random update that bypasses everything I’ve set up.
Once I got a bit of time, I play on building a pi box that works similarly to what she’s expecting.
No. I would never use a TV that isn’t connected to a computer. It would be great if that computer was built-in with good peripherals, but only on the condition that the user owns it.
If it’s like a lot of other devices, it will realize that it can’t get to “The Internet” through that network, and might disconnect. It’s possible it will then look for another option, and might see an open network and use it.
I think the point is they can’t upload anything if they’re not connected. Unfortunately, they’re some of the best OLED TVs right now in terms of the display
I do understand that but I don’t think it’s something we should accept. Next thing these fuckers have their own 5G antenna and connect to mobile with zero config, then what, rip out the antenna or literally wrap it in tinfoil?
LGs will find nearby wifi that will let them on to phone home. It doesn’t matter if your own network is locked down. And if they’re doing it, it’s likely others are as well.
Are they monitoring those running for office, those they find “of interest”, certain key words and phrases, and so on?
CERTAINLY.
AI helps them to sort through the noise; this is the Patriot Act manifest. Companies are eager to comply.
Decades ago, they would have to “wire” your house to monitor you, tapping your phone and the like.
Today, they simply have to notice you, and they can get all of the data they want at will.
If your goal is political and unpopular with the powers that be, using the internet or phone will never be even vaguely secure. The TV is watching you… and the fridge and the washing machine and so on.
If you think your device is secure; that very same device is guaranteed to be insecure. They are supremely interested in those who want “secret” communications.
“No way every domestic telephone call is being recorded and transcribed!”
Next moment:
“Woah! Gnarly dude! A.I. that’s been trained on ludicrously large datasets! It can mimic your mom’s voice, dude! Here, check it out! It can also write e-mails like a human!”
All the leaked intel points to: this is a very real and possible situation. Better not think about it and stick your head deeper into the sands.
On a technical level Google knows where 80% of Americans are, because they’re using Google’s Android. It could report back what cell-tower their mobile-computer is using, or it could be using the mobile-computer’s GPS, or it could take the SSID of any nearby WiFi or Bluetooth device and compare it to a map that’s diligently updated daily by every Google Android user. To say Google knows where every Google Android user is is very technically possible. It’s also technically possible to infer other things with a satisfactory probability, like where the other 20% are.
The NSA, CIA and FBI were the data harvesters. The solutions to their needs were financed by them and we got… for instance, Google. They had vasts amounts of data and needed a way to search through it. Likewise the intelligence-agencies wanted ways to impersonate others digitally and… oh look, we have live ‘deep-fakes’. I won’t bother espousing how the economy serves the state’s needs first and any consumer commodities are second- or third-order artifacts, but really? You don’t think the very thing advertisers are doing now–in no way secretly either–are not technically feasible for the rapacious, infinite-money pits of the secret-police?
Right–I forgot! Only communists have secret-police!
Yeah, I went with LG because I wanted to try an OLED, and the price was right. Never buying anything from them again, and whatever tv I do buy next I’ll disable all the shit from the get-go.
I’ve always been privacy minded, but things have gotten so bad, and I’ve gotten complacent. Hell, I just bought a connected smoke alarm system because my wife and kids needed something they can mute remotely. Should have just bought a stick instead.
I need to replace my WiFi, about time I get one with real VLAN support, so I can build an isolated guest/IoT network.
What the fuck? I would have simply bought a wall powered smoke alarm, opened it up, and wired an auxiliary button to the snooze button’s pads and put that button lower down as one of those wall switch buttons.
You really just need to complete the circuit to make it shut up.
Because they are short and my ceilings are tall. We also cook a lot and with kids, smoke happens. So, the requirement from the wife was being able to silence remotely.
Yeah, I’m glad I took the time to set up a separate VLAN for this. It wasn’t easy on my MikroTik router (nothing ever is with those), but it’s worth the effort.
there was a time… long past I suppose …when this would have been an outrage and politicians would be holding press conferences where they took crowbar swings to such devices. Things sure have changed.
Is this even possible or reasonable? Smart tvs are pretty dumb if you never connect them to the internet, so no issues until they decide to add 5g chips to them
Or… If your neighbor has an open network… Or the TV has a secret networking protocol that allows it to talk to other LG smart devices that are on a network. Or it looks for phones that have the LG app installed… You get the idea. Once you put wireless capabilities in it, there is any number of ways it can leak your data out.
Proving it is the hard and expensive part. I don’t really have the time, skillset, or money to buy a bunch of LG or other branded IoT devices, put them in an isolated test chamber and then try to decode all the RF noise come off them.
That being said, all the technical requirements to do the things I suggested in my previous comment currently exist in those smart TVs. All that was preventing LG from doing that was consumer trust, and they’ve clearly thrown that in the garbage. At this point, based on previous behavior, it should be assumed that they will go as far as possible to exfil customer data without their consent or knowledge, until proven otherwise.
I didn’t read the article and I’ve only watched the “trailer” for Gamers Nexus’ series on this so far, but I bet they actually do check this at some point.
My solution here (this is my solution; i recognize 99.5% of people would never do this) is to open up the tv and physically remove any wifi adapters or cards. Obviously not stopping them from hiding them, but being under the plastic shell is enough to stop most people
Non-smart TVs are still available, they just cost a bit more. As for the connectivity issue, China has been caught hiding 5g chips in electrical control systems and city buses, and selling “free streaming” boxes with malware that scans networks and attacks targets deemed worth while. And all these TVs are being manufactured in China so why take the risk when you aren’t going to use the connectivity anyway?
I mean that works too, I’m just not a fan of watching things on computer monitors. Sometimes I just want to sit in a recliner and watch a movie on a larger screen.
Yeah that’s fair. Personally, I live in a really small space so steam deck and phone are my only devices. Don’t think I’d feel comfortable with a TV that reported back on me - but TBF I do have a phone which I’m sure is doing that anyway!
My TVs don’t get connected to the network because TV companies have started showing ads, and that was bad enough. Then came the fact that a lot of TV apps were making your TV into a residential proxy, making your TV into part of a botnet. And now, on top of all that, they’re spying on you.
The ads were bad enough.
In any reasonable world you would have control over devices in your house that contained computers and would be able to remove bad software and install your own stuff. But, these devices are all covered by section 1201 of the DMCA which makes it a crime to bypass any access control software. This is how Apple is able to block alternate app stores. It’s why printer ink is the most expensive liquid on the planet. It’s why John Deere is able to remotely brick a tractor anywhere in the world, and prevent farmers from fixing their own farm equipment.
What’s especially galling about this is that, the US forced the rest of the world to adopt this bullshit as a part of trade treaties, threatening that any country that didn’t do it might lose tariff-free access to the US economy. And now what happened? Trump just ripped up those treaties anyhow and imposed the tariffs anyhow.
I just wish there was a country brave enough to rip up the IP agreements the US forced on them and allow us to actually own our own stuff again.
not necessarily, MAC is a layer 2 protocol, and your router (NAT or no NAT) operates on layer 3. Routers are supposed to overwrite the MAC address with their own when they forward a packet.
It’s always possible for the unit to put its own identfying info in the payload. But you didn’t do anything silly like register the TV, did you?
Yea I could see them using Amazon sidewalk or xfinity open access points to get around the no connection thing. But that should be easily discovered if they do.
The logging was shown using shell commands running on a rooted OS. I don’t doubt the companies can or are doing this, but it’s akin to showing that installing malware exfiltrates your crypto wallet info.
Anything with a CPU, WiFi module, and microphones is capable of this.
Right. When the fuck did a TV start needing a microphone?
I’m old enough that I remember our first remote control TV. The remote was on a cable. It’s incredible and wonderful to me how far and how fast tech has come - but some stuff is just going too far. You don’t need to talk to your TV. Same with smart fridges - WTF? I dunno, maybe I’m just showing my age. But this unnecessary complexity adds insecurity and more stuff to go wrong.
But the video showed him connecting a pc to the TV to do the hacking. So it means a physical connection is required to run the shell command. Soo It means I can’t get hacked right ?
I’m not surprised. Almost everything that you would assume does something in only one direction also does it in the other direction. LEDs generate a small amount of current when you shine a light on them, solar panels emit a small amount of infrared when you apply power to them, etc.
To clarify, are you looking for where to get a pihole or where to get the LG rules?
Pihole is essentially a dns server that routes junk you dont want to nothing so that ads or trackers cant phone home. You can run it on any computer, but then need to make sure your router or devices are using it as a dns server.
The rules for blocking can be found in lots of places, everyone has their own lists. Im not familiar with lg specific rules but there are probably hardware telemetry lists out there if you search pihole lg block list
That raspberrypi would work but to be clear, while pihole started on Raspberry Pi hardware you can run pihole on virtually anything now. It’s lightweight so old hardware is fine. I’m setting it up for my daughters house on an old refurb Chromebook - reformatted to run Linux Mint.
Pihole runs a dns service for your network, translating server names to ip addresses. The block lists keep certain ads, malware and other unwanted behavior from functioning, but only those that can be blocked this way. Not all ads and malware can be. For instance it can’t block YouTube ads so browser extensions like UBlock Origin are still useful but it certainly blocks a lot of stuff.
Yes, it will do that. I wouldn’t call it an extension. Pihole is a DNS server. It’s the “phonebook” that your devices will use to look up IP addresses that correspond with the requested domains. If a domain is requested and it happens to be on the block list, it will deny the lookup.
Adguard offers a similar service that isn’t self hosted (Which I use as backup) and they have a pretty good explanation here: adguard-dns.io/en/welcome.html#workStages
Bring on the TV firmware. Jailbreak your consoles. Use Linux or steal windows and use tools to completely rip its spyware out of it (e.g. revi.cc).
Custom firmware anywhere and everywhere a device that someone supports with custom firmware is a feature worth researching.
The fucks are only going to jeep doing it. Protect yourself. Push for GDPR like laws in the US. California’s privacy laws are headed in the right direction.