Rendered at 13:50:35 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
korzinka 3 hours ago [-]
I've bought an LG Smart TV 5 years ago, read t&c where I was supposed to grant them any data they wanted, decided to disagree and kept all network functions disabled. I was ridiculed by my friends for that. At some point, I thought - maybe I'm really crazy to do so? Who am I, a caveman, a luddite? Oh well, I'm not. Not a bad tv though, many HDMI ports!
soleveloper 1 hours ago [-]
Is there a list of all LG tracking services and external DNS endpoints?
I'd just block them - and keep local streaming and remote control working
edit: just found out WebOS doesn't support DoH/DoT so nextdns won't work.
I wonder if one of the public dns providers got LG blocklisted natively with specific IP
altairprime 2 minutes ago [-]
[delayed]
wavesplash 1 hours ago [-]
Worse, if you watch the GN video this article is based on you'll find the TV can figure out how to leverage other non obvious networks (threads, etc) to reach LG servers. Worth a watch to see how bad this is: https://www.youtube.com/watch?v=6IFVTcM28KA
rcarmo 1 hours ago [-]
Oh, by the way, these things spoof MAC addresses too, so you can't rely on DHCP.
deadbunny 17 minutes ago [-]
[citation needed]
Sophira 3 hours ago [-]
Nah, you're not crazy. I'm also someone who actually reads terms documents, because I find that they're often the only thing that will be truthful about a company's intentions.
And keeping it completely disconnected from the internet should be the default, in my opinion.
imglorp 1 hours ago [-]
There is absolutely no reason to read those contracts any more. As Louis Rossman keeps pointing out, most of them now include the ability for them to change terms at any time. That's basically the null contract.
Since the legal system has once again failed to protect users from corporations, it's up to users to use technical means for self defense.
DaSHacka 55 minutes ago [-]
At the very least, you can be sure they'll never change the terms of the agreement to be more beneficial for you, though.
So just treat it as a best case scenario, knowing that it can get even worse.
pnt12 45 minutes ago [-]
Just assume the worse then, save yourself some time.
airstrike 1 hours ago [-]
Interestingly, in Brazil and I'm sure in some other legislations, those contracts are essentially void because there's a presumption the average person does not have the time, patience, or ability to understand every clause—so they are by definition unable to agree to their terms.
I'd love to have a similar standard applied in the US but I'm not holding my breath.
skerit 15 minutes ago [-]
I never understood why any of the smartness had to be built into the TV in the first place. Sure, it's useful for the first year, and then the seriously underpowered hardware they installed into it will have trouble with just about anything.
I bought a Philips Ambilight OLED TV probably over 8 years now. Brilliant tv, great quality, I still see no reason to replace it at all. But its built in AndroidTV is garbage.
snvzz 2 hours ago [-]
Only good until the device starts using a neighbor's LG TV as access point, without telling you, for the sole purpose of upgrading itself and sending this "telemetry".
They can just start a capture, record to RAM / storage, and retrieve it later when it is reconnected to the network.
Otherwise if it's disconnected, it is still hard to exfiltrate the data somewhere.
Maybe they could get creative via Bluetooth, but then you would need a cooperating device in proximity of the device.
ezst 3 hours ago [-]
> This. Why would you even connect TV to the network?
I happen to have a NAS with family pictures I like to display. I can (and do) firewall that thing, but then you hit other issues like the apps you need to show pictures and movies in the first place not to install/run.
I've yet to hear of a reasonable recipe to isolate and secure such connected TVs. And don't get me started on Chromecast or other Android dongles, I've no reason to expect better treatment from Google. Some open source hacked-together box, then?
theshrike79 23 minutes ago [-]
Apple TV is the best one.
No ads, full OS updates for a long time.
rossy 1 hours ago [-]
Obviously, as an advertising company, Google should have your utmost scrutiny. But as far as I know, their TV boxes don't ACR your content. If they were the only two options, sticking with your smart TV software instead of using a Google TV box would be a privacy mistake.
givinguflac 2 hours ago [-]
No idea what NAS you’re using, but I would recommend the Apple TV box.
jojobas 2 hours ago [-]
Any SBC like Radxa Rock (cheap) to Orange Pi (powerful). 4k output, a linux you control, play retro games or stream torrent movies.
pessimizer 1 hours ago [-]
> Some open source hacked-together box, then?
I've just used an old Intel NUC with Debian stable, a remote mini-keyboard and an automounted Samba share on the network forever. It's no more hacked together than any other computer. I do make the mouse pointer and the fonts real big. No apps required. Don't really need the keyboard except for mplayer hotkey presses - just the touchpad on it; if I need to do something that involves typing other than typing a password, I usually ssh in.
I think people are lowkey addicted to having shit sliding in and out and constantly being advertised to. How do you know what to watch unless somebody is constantly bombarding you with options? If it doesn't look like a star trek control panel, is it really TV?
If you like that, you can install Kodi. I haven't tried it since it was XBMC because I found the interfaces annoying and it had trouble dealing with networks, but I'm sure it's better.
> I've yet to hear of a reasonable recipe to isolate and secure such connected TVs
I don't even try. I overpay for dumb tvs in the present, or underpay for 10 year old tvs pre-Applefication. I've never owned a network capable television, or one with apps. I wouldn't.
edit: if your NAS is a separate box that can sit in proximity to your television, you could probably just run all of this stuff directly from the NAS. They spend most of their time doing nothing at all.
jangxx 2 hours ago [-]
I use the built-in AirPlay receiver on my Sony TV quite a bit and that requires network access
Dan_- 58 minutes ago [-]
LG’s AirPlay requires internet access.
trueno 34 minutes ago [-]
christ we need to start rooting tvs and start up a open and secure tv os. i never give my tv os internet access i rely on the appletv for the "smart tv" but if what another poster says is true about lg devices looking for public wifi to exfiltrate data then lol time to start pulling tvs apart and shielding their network components from getting a signal
amelius 3 hours ago [-]
Did you know that ethernet can run over HDMI? It's called HDMI Ethernet Channel (HEC).
emsixteen 20 minutes ago [-]
Surely it still needs to be connected to something that has a network connection, though? Doesn't really mean much here.
bzzzt 2 hours ago [-]
Yes, but support in devices and cables is very limited.
wolrah 1 hours ago [-]
Support in cables is nearly universal, because the same pins in the cable are used for the Audio Return Channel feature that allows a TV to pass audio from its internal apps back out to a soundbar or receiver via the same HDMI cable it takes signals in on from other devices. As far as I'm aware no one has made a cable lacking those pins since 1080p was still the high end.
But yes, support for the ethernet mode as far as I'm aware was never actually implemented in any devices that reached retail availability.
iamtedd 2 hours ago [-]
How much would support increase when manufacturers realise how few of their TVs don't get connected to the network?
bookofjoe 12 minutes ago [-]
Proportion of HN users whose TVs don't connect to the internet? Significant
Proportion of non-HN users whose TVs don't connect to the internet? Negligible
_flux 2 hours ago [-]
Even if it did support it, nobody connects their TV to their local network via HDMI, they connect it to their PC. And, as far as I'm aware, no PCs automatically start sharing networking with whichever networks they are connected to.
That could of course change. Could be even a nice feature for connecting your TV to the network via your multi media center, if the bandwidth is good.
rcxdude 2 hours ago [-]
Their solution to that is to either use the cell phone network or services like amazon sidewalk where they connect in through your (or a neighbour's) internet-connected device.
Dan_- 56 minutes ago [-]
I think it’s also possible to piggyback on other devices signed with the same certificate to exfiltrate using BLE. Maybe I’m wrong though.
wolrah 1 hours ago [-]
Not at all, because it uses the same pins as ARC, so the two features can't operate at the same time, and a lot of people use ARC to get audio from TV apps back to a soundbar or receiver.
HDMI Ethernet is dead, it's never going to happen in consumer televisions because it has a hard conflict with a feature a lot of people actually use.
jayknight 1 hours ago [-]
If people really start not connecting them. TV makers will just start including a cellular modem.
eks391 2 hours ago [-]
Then you make sure to only use HDMI cables that aren't HEC, in conjunction with not connecting the TV to the internet directly, if you want to keep them isolated.
unixhero 3 hours ago [-]
They do screenshot? Do you have a source so I can read more?
patrickk 3 hours ago [-]
Yes tv makers were caught doing HDMI fingerprinting. There was a story some years ago about how basically all smart tv makers were sending data to an ad network based in China.
Samsung were openly bragging about this on their website some years ago (for the benefit of their advertising partners) but have recently muddied the waters when I check their site again, couching it in language mentioning privacy and other evasive language:
It's (mostly) a US thing; basically subsidizing TV prices with ad revenue. It's how the entry-level companies like Vizio operate, though the "big brand" TV makers are certainly just as guilty here. It's much less of a thing in the EU, where data privacy laws are stricter and TVs are hence (comparatively) more expensive.
As far as I know, they don't literally scan your media libraries; they screenshot whatever you're watching through HDMI (most often cable / satellite boxes), as those devices don't provide the telemetry that normal apps do. This info is used for audience measurement (thing Nielsen ratings), as well as showing you ads that are actually likely to match your interests.
"Starting in 2014, Vizio made TVs that automatically tracked what consumers were watching and transmitted that data back to its servers. Vizio even retrofitted older models by installing its tracking software remotely. All of this, the FTC and AG allege, was done without clearly telling consumers or getting their consent.
...
"Vizio collected a selection of pixels on the screen that it matched to a database of TV, movie, and commercial content
Mine is still attached to the network, but I’ve turned off all the ad/customisation &AI stuff. Seems to work fine, no ads etc. though usually I’m using it simply as a screen for the AppleTV.
I do have it isolated from other devices on my network, though.
alex_duf 54 minutes ago [-]
Similar, I was only using it as a screen for my shield so I factory-reset it and never re-connected it to wifi.
It's actually a lot faster now (it's an 8 year old TV, their OS can get a little heavy on older models)
shakna 1 hours ago [-]
A few models/firmware combinations have found to look for public hotspots when you don't agree to give them network.
anonreplier 59 minutes ago [-]
have they? what ones?
jgrahamc 40 minutes ago [-]
Yeah. I own an LG TV also of about the same vintage. It doesn't get to talk to the Internet.
chrisBob 3 hours ago [-]
My in-laws were so proud of themselves. I came home one day and they told me they figured out how to connect my TV to the network so that I don’t have to use my Apple TV if I don’t want.
I had to take a few deep breaths to keep from yelling. I am very happy with my TCL tv but I trust it about as far as I can throw my father in law.
grepfru_it 1 hours ago [-]
At least with LG you can revoke your consent. I came home to found STT audio recording enabled and I promptly disabled it and lectured the household about privacy.
AdamN 3 hours ago [-]
Only give the permissions you want the device/agent/human to use - no more.
Same for anything whether you trust it or not (or somewhere in between).
NooneAtAll3 2 hours ago [-]
> Not a bad tv though, many HDMI ports!
that's not a plus, tho
spockz 3 hours ago [-]
Okay. This is insane. First the monitor that uses a windows feature to automatically install a small helper tool with root permissions and then starts showing adds in certain regions. Now a tv that is actually actively snooping around on top of the known fingerprinting. What else is next?
In the previous topic I got ridiculed for not wanting to buy LG anymore because I could use an agent to modify to strip out the offending bits.
But there must be something better than just keeping to buy things that invade our privacy and homes further and further. Which brands aren’t doing this? Sony? They also announced a partnership for the lower end TVs IIRC.
afarah1 36 minutes ago [-]
I think the insane part is that this is not criminal and the executives are not jailed for it.
Sharlin 1 hours ago [-]
Well, it’s a smart TV. I would assume with extreme prejudice that every single one of them is doing stuff like this and worse until proven innocent. Based on everything I’ve read about these things it seems the most reasonable stance.
> In the previous topic I got ridiculed for not wanting to buy LG anymore because I could use an agent to modify to strip out the offending bits.
Jesus fucking Christ.
colechristensen 18 minutes ago [-]
>But there must be something better than just keeping to buy things that invade our privacy and homes further and further. Which brands aren’t doing this? Sony? They also announced a partnership for the lower end TVs IIRC.
Smart people need to band together to advocate their state governments to make commercial mass surveillance for any purpose a criminal offense (not just banning, making it a crime).
gizzlon 48 minutes ago [-]
Yeah, just keep buying the poisonous breakfast serial. It's easy to pick out the brown bits of rat poison /s
ctippett 12 minutes ago [-]
I commented this only a few days ago on a different LG related thread. What LG are doing is indefensible and we should all vote with our wallets when considering a new TV... but for those who already own an LG TV you really owe it to yourself to jailbreak it and make it "yours", so to speak.
> OpenLGTV[1] is a collective, non-commercial project for legal reverse engineering and research of LG (Smart and non Smart) TVs firmware, which is partially Open Source.
> The main goal of the project is to improve the functionality of the TVs by adding new features, fixing bugs and providing new software.
Funny, published on a site with 1745 'partners' who fully respect our privacy of course
hn_submit 44 minutes ago [-]
I believe we should push for legislation that prohibits the sale of customer data to third parties. Websites can use the data on their customers but they cannot share it with anyone else. Because aggregators are selling it cross-border after which you lose track and all control over it.
titzer 22 minutes ago [-]
They shouldn't be able to collect it in the first place. The big companies have 10 page agreements that say they "value" your privacy and that they don't sell your data to third parties. They do value it, highly. And they don't sell it--they just hoard it, mine it, and sell increasingly accurate targeting. Why would they give it up? I mean, besides coughing it up with little objection to national security letters.
iso1631 23 minutes ago [-]
Look at the outrage from US tech bros when the EU passed a law saying that you had to tell people you were going to do this.
Anoian 3 hours ago [-]
Respect for the consumer has long been gone generally except for a few brands.
I am still wondering why consumer respecting brands are not emerging more and thriving.
recurseP 2 hours ago [-]
The point is: which brands still respect user privacy? If I were to buy a new TV today, which brands-models should I prioritize?
Also, are there brands-models that in which it is possible to sideload a different OS like with mobile phones (LineageOS, GrapheneOS, etc.)
dwedge 2 hours ago [-]
I bought a projector in part because they are behind on this and only seem to have basic software
msandford 2 hours ago [-]
That's a great idea, thanks for sharing!
exe34 57 minutes ago [-]
Machiavelli's flexibility: evil has more options to achieve its goals than good, and therefore it always wins. (The invisible hand of the market is a myth - people don't choose things on principles unless they have money to burn).
usern20260720 3 hours ago [-]
A consumer respecting brand sells products. A Consumer selling brand sells consumers so they can be profiled, analysed for weaknesses and exploited economically in the name of Surveillance Capitalism
DarkUranium 3 hours ago [-]
I suspect because it's hard to differentiate between ones that actually respect the consumer vs ones that only say so, but are actually lying to your face.
That and not respecting the consumer is more profitable in the short term (only!), which means more marketing money, buying out other brands, lobbying to increase the barrier for entry, et cetera.
ngcazz 3 hours ago [-]
Because there's no incentive to do it. The consequences of being tracked are outta sight outta mind.
fithisux 3 hours ago [-]
That is why politicians get rich.
But also, people do not generally hesitate in front of an all-you-can-eat bouffe
There is a very I-am-very-smart aspect to these predictable sorts of comments. And weirdly they always seem oddly intended to diminish the core concern being addressed.
"Oh your TV is listening to you and mapping your network and exfiltrating your data? Yeah, well, look at that website that has some ads on it! Boom!
Give up. The future is lost. Don't sweat the wiretapping TV."
hk__2 2 hours ago [-]
> And weirdly they always seem oddly intended to diminish the core concern being addressed.
No they don’t. OP says it’s funny, that’s all.
llm_nerd 2 hours ago [-]
It is 100% diminishing the concern. If someone were paid by LG to try to manage this revelation, they would post exactly what touwer posted. Like, there isn't a better way to try to normalize and excuse bad behaviour than doing the incredibly boorish tactic seen above. The "everyone is doing it" excuse is a go to.
I mean, LG would probably also pay someone to run around going "it's just funny, is all" in support if anyone noticed this pathetic astroturfing.
dwedge 2 hours ago [-]
No I disagree here. I would argue that a TV doing this 30 years ago would find themselves in court, whereas now they are all skirting the edge of the law and we accept it because that frog has been boiling for decades.
The idea that logging audio is bad, but cars logging your weight, tvs logging your watch history, scales sending your wifi details, android and apple both mapping your access point to create a pseudo-location tracker without GPS, my mobile network sending me location-based adverts based on tower proximity via sms to a dumbphone are all very very bad.
LG have slightly overstepped the line here, legally, but in my opinion they've overstepped what is OK by a long long way. A website reporting on this while sending your details to hundreds of tracking sites are doing the same thing - abusing what is allowed and I assume only printing the report for more engagement and not because they actually care.
LG need to go a lifetime shit list for this behaviour - there should be outrage like there was about Sony's root kit. But websites like this also need to find out that this behaviour is not ok
8fingerlouie 4 hours ago [-]
My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet.
DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.
All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.
blahblaher 9 minutes ago [-]
That's great that you know how to do that, but LG and others know that also. They don't care that a miniscule amount of ppl can do it, they care about the 99.9999% that don't. Thid should be dealt with legislation and very high fees, sufficient to discourage anyone to do it.
HelloUsername 4 hours ago [-]
All of your blocking still doesn't change the fact that your LG TV is actively trying to scan your local hardware, gathering IP-addresses of devices, wi-fi names and signal strengths, creating digital finger prints of the audio and video projected on your screen, recording audio through the internal microphone, even when the TV is in standby or without an internet connection, saving the collected data locally and uploading to LG Ad Solutions as soon as the TV is connected to the internet.
shaan7 3 hours ago [-]
Yeah which is why its imperative that you _never_ connect to the Internet.
ihsw 2 hours ago [-]
[dead]
8fingerlouie 3 hours ago [-]
But it's never connected to the internet, not even for software updates. If the TV isn't connected to the internet there's no reason to update it, assuming the TV works as expected.
It's a trade off I guess. I use Home Assistant to control TVs, so kinda need the access.
HelloUsername 3 hours ago [-]
Again, what I mean is, even if you're able to block all these things, the company LG is still secretly and actively trying to collect and process user data, without user awareness or consent.
_flux 2 hours ago [-]
Actually what I wanted from the video was impact of user consent, but it doesn't seme to cover this: what happens if you accept nothing, or the minimal set of consent (so not including audio) of licenses to allow you to run third-party apps? I recall there are four checkboxes to check.
My guess is: not much.
kungp 1 hours ago [-]
What if you sell the TV? Can you clear the data with a factory reset so it's not just uploaded when a new user connects it?
tjpnz 4 hours ago [-]
Do transparent faraday cages exist?
c16 2 hours ago [-]
WiFi / 5G faraday cages exist, but they have been downrated for affecting the signal quality somewhat...
4 hours ago [-]
Eji1700 4 hours ago [-]
And then your neighbor spins up an unprotected network or something like xfinity which they could have a deal with and it connects there and phones home anyways.
sgerenser 2 hours ago [-]
I hear this a lot “TVs will just connect to a nearby unprotected WiFi network!” But I ve never seen any evidence of it. It appears to just be speculation, unless you have an actual source?
deadbunny 12 minutes ago [-]
Its always speculation that would be trivial to actually test.
1. Do not connect to network
2. Create unauthenticated WiFi network
3. Monitor WiFi network
Strange no one has ever done this simple af test to backup their claims
lxgr 18 minutes ago [-]
They could also use something like Amazon Sidewalk or ATSC 3.0's dedicated return channel.
8fingerlouie 3 hours ago [-]
And what exactly would they use that particular access path for ?
I could see a threat if the TV had access to the internet and could establish a TLS tunnel or similar from the mothership, and execute commands on my LAN (or IoT network as it stands), and report back. That could establish a command & control channel that could potentially orchestrate an attack on my infrastructure via the TV.
However, reporting that "network X exists and has these devices" over a different network complicates things a fair bit. In theory they could still use the TV as a command and control platform, but it would have to switch networks between my closed network and the open network in order to execute commands and report results. Not saying it's impossible, just very unlikely.
Besides, the TVs are not alone in being cut off from the internet. I have two IoT networks, one for trusted devices (AppleTVs, Sonos, and the likes), and one for untrusted devices like TVs. They run on different VLANs, and anything on the untrusted IoT network can pretty much only talk to itself (client isolation) and the gateway, and there's no internet and no open ports to any other VLAN.
simoncion 3 hours ago [-]
> And what exactly would they use that particular access path for ?
Uploading the weeks, months, or years of locally-stored activity [0] data? Text compresses really well and local storage used to be very cheap.
[0] ...mic voice transcription, how often you use the thing, for how long, and a best guess (because of lack of time sync) at when, "automated content detection" logs [1], names of files you've fed to the thing, -if equipped with a camera- number of people in the room and interesting information about them, etc, etc, etc...
[1] ...assuming that that can be done with data loaded from the factory, which I kinda doubt...
harha 4 hours ago [-]
If you're streaming via AppleTV, why do you need to give the TV itself access to the network?
8fingerlouie 3 hours ago [-]
I use Home Assistant to turn on/off the TV via automations, sensors, etc.
I could possibly do it via HDMI CEC, but I have a couple of Sony Bravia TVs that more often than not completely ignores that, so I prefer having control over assuming it happens.
harha 2 hours ago [-]
Yeah CEC is a bit tricky sometimes. How about auto-off from the TV itself and then a timer for a HA controlled outlet to turn off power after that using automation (i.e., when the streaming device is off for a x minutes)
05 2 hours ago [-]
You can do on/off using an IR blaster (broadlink integration with discrete on/off codes). It’s when you want to read volume etc things get trickier
_flux 2 hours ago [-]
I have an automation that turns on amplifier only when using certain inputs, not just when the TV is turned on. I can easily imagine people would also configure their amps to use different input depending on TV input.
Asmod4n 3 hours ago [-]
There is sadly no hdmi CEC support on Most GPUs for pcs. So when you want your tv to turn on and off with your pc it is only possible with the tv being reachable from your pc via ip.
I believe LG doesn’t advertise such an api via Bluetooth
fanatic2pope 1 hours ago [-]
You can get USB controlled CEC injectors for HDMI.
HDMI breakout and a esp32 module flashed with esphome is another option. The tv most likely doesn’t care that the port that sent on/off command is not the same port the video signal is coming from..
CommanderData 3 hours ago [-]
Congratulations but I also dislike this type of comment because that is not a solution, a workaround that doesn't happen for 99% of the population.
Soon you won't be able to IoT network or block these devices as they begin to partner with Amazon and the likes that sell Internet for near-by IoT devices. Then your only option then is physically removing / de soldering radios from the board.
Laws needed, like yesterday.
8fingerlouie 1 hours ago [-]
For now, setting up an IoT network is pretty much best practice, and I'd wager the average Hacker News reader both has the necessary equipment and skills to do it. That may not always be the case.
Assuming they install some 5G modem in the device, which is pretty much dirt cheap these days (our local water utility uses 5G for meter readings, and the cost per meter is something like $1/year), there's literally nothing short of a faraday cage you can do.
The can report on what you watch freely, and only consumer laws can stop them. However, without a wifi connection they can't snoop on your local network, and they probably can't connect the data to you, assuming you don't register the TV for those 3 months of added warranty or whatever they try to get you to register.
I tend to avoid devices that are built to snoop on you, so no Amazon Alexa, no Google Home, no Apple HomePod. Everything I have utilizes local control via Home Assistant, and most of it is actively blocked in the firewall from accessing the internet. It's not hard to implement, and doesn't require a master of IT, but it does remove a lot of the convenience, which I guess is the reason people don't do it.
Lio 5 hours ago [-]
In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
That's an easy one to put a compensation figure on but there's probably all sorts of other exploits waiting to happen.
I think the most egregious thing here is that if you don't give the TV a network connection that it will actively search for other ways to get the data back to LG such as open WIFI.
coldtea 4 hours ago [-]
>In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
That's understating the problem. With or without AI, this should be cause enough to shut down a company or at least their specific product division.
>E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
They're going to be fine. A slap on the wrist at best.
jiaosdjf 4 hours ago [-]
The value of this data to the NSA, Mossad etc is probably the only thing keeping it secure.
Never in human history has a government had the means to simultaneously spy on millions of people, to use everyday private conversations to categorise them into various threats to the state, and better yet these tech companies can still sell the commercially valuable side of this to advertisers.
nannal 4 hours ago [-]
Advertisers are the reason we have this problem. The only way to stop them is legislation.
vintermann 2 hours ago [-]
Advertisers may be the reason we got this problem, but the security state is the reason we can't fix this problem and it only gets worse.
shit_game 4 hours ago [-]
People could return to burning down enterprises that they find unsavory or detrimental to society, such as they did during the industrial revolution, but this is problematic in that it's violent and not something the modern person often considers as viable. A part of why people consider this unviable now is in-part due to the consequences of these surveilance technologies. It's difficult to accomplish a revolution when everyone is being spied on all the time.
type0 4 hours ago [-]
“Citizens will be on their best behavior because we are constantly recording and reporting everything that’s going on”
- Larry Ellison (Oracle Corporation)
intended 2 hours ago [-]
The shortest path answer is a bit too caveman-esque to survive its application to reality.
That said, I think there is a lot of appeal to go hunting for firms, since it really feels like corporations and their owners are engaging in predatory behavior as opposed to customer centric behavior.
newsclues 4 hours ago [-]
As much as the problem is advertising the government allows it because the government buys the data!
jjgreen 2 hours ago [-]
Well, not the only way: widespread slaughter would probably work too.
bilekas 4 hours ago [-]
> E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
My tinfoil hat believes that they've already accounted for this as the price of doing business. They will have already budgeted for the fines that they might incur, pay them off and continue as normal while people become accustomed to it.
dgellow 4 hours ago [-]
Based on historical records, I would say not much will happen to these companies. Interested to see what the EU will do though
MentalM 1 hours ago [-]
> Interested to see what the EU will do though
Will make surveillance mandatory? I mean we definitely should somehow fight terrorism, protect children, and prevent copyright infringement on trillions of dollars per year.
rickdeckard 2 hours ago [-]
The EU is actually already quite equipped to counter such behavior, with GDPR and CRA (Cyber Resilience Act) regulation they can not only penalize on consumer privacy protection (GDPR) but also on inadequate security practice (CRA), both allow either an absolute fine or a percentage of the annual company revenue.
I wonder what chances a consumer in US has though. If the past is any indication, consumer privacy is not a highly regarded good when ranked against a corporate strategy...
shit_game 4 hours ago [-]
>this is going to be a massive business liability.
No. this is going to go "unnoticed" or at least unactioned. These are surveilance devices - compromising their value as source of surveilance is neither in the interest of industry (who are selling and buying the surveilance) or government (who are buying and acting on it). The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now. These devices bery well may soon be the only lawfully available devices in the consumer market precisely because of their surveilance capabilities. Governments are reluctanty catching up to the capabilities of digital technologies, and they're finding them more useful now than ever before. We will be burning witches again before we ever prosecute tech companies for doing bad things.
coldtea 4 hours ago [-]
>The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now.
Spot on.
Lio 4 hours ago [-]
I'm thinking less about shame, as corporations are dead to shame, and more about proof the TV stored a record of your bank details it got from text to speech.
If that's stored as text inside the TV and you lost money because it was copied by a hacker then you have a monetary value to show loss and a trail of liability you can use to sue LG.
type0 3 hours ago [-]
> a trail of liability you can use to sue LG.
The average user would not realize LG was the reason, if they do they will loose more money and effort; LG's reputation and public image won't be even damaged enough for them to take a notice. You are an ant for them and ants are only powerful if they work together.
coldtea 4 hours ago [-]
>I'm thinking less about shame, as corporations are dead to shame, and more about if you can prove the TV stored a record of your bank details it got from text to speech.
Then they'll get a joke fine, and continue as before. Maybe cut the price for a while, until they reintroduce it with another pretext a few years down the line.
shit_game 23 minutes ago [-]
And what will anyone actually do when they are bound by an arbitration agreement that prevents class action lawsuits and/or will find against the user because it's an arbitration agreement (with an arbiter that will bend knee and suck cock for the corporations and governments overseeing it - read Five Eyes[0] and Israeli espionage in the US[1])? Or are forced out of court due to the obscene cost of legal action in most nations due to lobbying efforts to protect corporations? Or never get to court due to said obscene costs, or even the simple knowledge of the ofence? Or are simply homeless because all of their money (their most recent paycheck) was stolen, and they are now derelict?
The legal systems that are in place (at least, those in the US) are not sufficient or even designed to act in any amount of favor of individuals. Even leveraging collective action (class action cases), most individuals are left worse off after judgement when they are wronged. Signalling that you are an affected class is effectively an admission of, at minimum, association - and worse guilt, of whatever an inteligence agency may suspect you of. Intelligence is not justice, and does not "protect" individuals under the same standards. If a government wants you to be wronged, they will accomplish it regardless of law, and the information they have regarding you will be leveraged as aggressively as possible. If you are simply wronged, the cost of accomplishing justice is often insurmountable.
In the most innocent case of wrongdoing by one of these surveilance devices, what would you, as an individual, do if your bank details were compromised as a result of a "smart" device exposing your credentials to bad actors? Obviously, you would contact your banking institution and try your best to rememedy the situation. But say, for example, this smart device is on your home network, has your login details, and possibly used your 2fa details because you used it to log in to your banking institution. That is You™. You logged in. You actioned something. It's verifiable because of your IP and your cookies and your 2fa code and the heuristics of your device usage (time of day, and the previous factors, and more). Many smart device applications already include SDKs that act as residential proxies - it's not impossible to believe that malicious ones may act as MITM or such. The possibility of 0Day expoloits or even backdoors can never be ruled out as you do not own these devices.
People should be subject to shame. Every government and every company are composed of people (for now) - these people are what action these possible futures, and who action the exploits of now. They are shameless by trade because that is their value. Much like the adtech industry thrives on the compromise of compensation to overcome the shame of doing wrong, so does intelligence and clandestine commercial exploitation. Money affords people the things that they want and need, which are becoming ever more impossible to acquire without succumbing to the shame of doing Bad Things™ to acquire it. You are never going to be able to sue LG because your bank details were leaked by a public DB or some other endpoint. Nobody will. Because the value of the information that LG provides to governments circumventing established anti-surveilance law (in the US, the 4th Amendment) through sales is worth more than any dollar amount it costs these parties.
Shame on every fucking one of you stains who implements this, if you can feel it, hidden in the walls of your owned property.
At that point network isolation stops looking like a privacy preference and starts looking like an adversarial relationship with a product you own
pferde 3 hours ago [-]
... product you ownꭞ
ꭞ Terms and conditions apply
Eji1700 4 hours ago [-]
You would think that would matter, that they’re basically violating all known PII/HIPAA/GDPR/National security standards and god knows what else, but I expect at most some class action down the line.
skeptic_ai 3 hours ago [-]
At the same time an average citizen can sue and win against these corporations. I never ended up Suing because all companies settled once I showed the evidence. So try it out. Will get expensive for them to use lawyers against ai and still lose.
ninjagoo 3 hours ago [-]
Telescreens [1] are here!
War is peace. Freedom is slavery. Ignorance is strength. [1]
The thought police will be after you now for mocking them!
megous 3 hours ago [-]
Yep. LG was reading Orwell and were like. Wow, great idea! Let's do it.
PinkSheep 43 minutes ago [-]
You need to up your irony. The proles were reading Orwell's 1984 and thought "hey, I shouldn't mind being spied on by (smart) TVs!" because this is the statistically average behavior of the consumers.
alex_duf 50 minutes ago [-]
What would the HN crowd recommend for a good linux streaming box + hardware with decent TV UX and remote?
My LG is completely offline and I'm using an nvidia shield to display any content, but I'm thinking maybe I need to go the extra mile, there nothing preventing an android tv box to do the same.
holowoodman 7 minutes ago [-]
> My LG is completely offline
Are you sure? They will seek out open WiFi and other neighboring LG TVs as relays.
blahblaher 13 minutes ago [-]
Well that's it. No more LG stuff for me. I bought the C1 OLED TV years ago, great TV, but with this BS, they lost me forever.
And yes I connect the tv the wifi for YouTube and for my local media server. No, I do not want other intermediate devices , I want my TV to not spy on me.
dwayne_dibley 49 minutes ago [-]
My 20+ year old dumb samsung TV needs replacing, and has done for a while. But it's stuff like this that makes me shy away from upgrading.
rickdeckard 2 hours ago [-]
Watching the actual investigation video the article is based on, it turns out that alot of the statements in the article don't really hold up to closer scrutiny.
I couldn't find any "smoking gun" or discovery of malicious intent.
What's left in the end is the already-known fact in the tech-community: The most-common, most-vulnerable and most-equipped device to spy on you in your home is your Smart-TV.
1. It has all the compute-power and sensors it needs
2. It already does some spying for ad-profiling
3. If a hacker exploits it, it's a problem
miki123211 1 hours ago [-]
And it's the only device that "normies" own that has reliable power and reliable internet 24/7. This means you can use it for nefarious purposes, even wastefully so, and it won't show up as suspicious battery drain or prematurely hitting the cell plan's data cap.
For a lot of hacker type stuff (esp. botnets and residential proxies), this is exactly what you want.
I used to believe that piracy couldn't come back in a significant way because people don't want to use computers any more, and phones are a really bad fit for p2p, even if running some hypothetical non-walled-garden OS that wouldn't have issues with that sort of thing. I entirely failed to appreciate the impact of cheap Android TV boxes here.
sebstefan 2 hours ago [-]
But also
4. Every single fucked up thing it did was indeed listed in their customer agreement and privacy policy
ihsw 2 hours ago [-]
[dead]
vachina 2 hours ago [-]
Reads like a smear campaign in my opinion. Watch for new American product launches in the next few days.
It's unfortunate LG screens are still the best in image quality, even though competition is getting closer. That said, the best way to use LG TVs is to immediately disconnect them from the internet and use an Apple TV 4K for streaming applications.
holowoodman 8 minutes ago [-]
"Disconnect" is not enough. They will seek out open WiFi and other available LG TVs as relays. You need to remove the WiFi card or at least the antenna.
left-struck 5 minutes ago [-]
Why trust apple?
Sent from iPhone (for now)
rickdeckard 3 hours ago [-]
This is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across.
1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.
2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.
3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.
All the points and scenarios in the video might be valid, but they are not sufficiently grouped into one of the above categories.
Instead, it just mixes them all together to imply that its all the same, weakening the whole investigation.
--
The plain example: Using voice-input for a web-search on the TV [0], make long pauses and observe how it keeps populating the prompt-UI with everything you say.
This is a matter of #3 above, accusing a malicious intent already on such a trivial implementation topic is harming the whole story
You posted a Youtube link with a share ID tracker in it: ?si=oVqX6NtkxPmqh6R-
shevy-java 3 hours ago [-]
I find your "summary" much harder to read and understand, though.
I prefer the original article and the net-benefit of a google-linked video to explain things that already were properly explained, is rather small, at best, in my opinion.
rickdeckard 3 hours ago [-]
> I find your "summary" much harder to read and understand, though.
Sorry, my grouping of topics isn't supposed to replace the entire research-session.
It's merely my observation after watching the actual "investigation video" that they mixed together lots of stuff they discovered into the larger conspiracy that everything is secretly spying on the user to feed a huge Ad-profiling database.
> I prefer the original article and the net-benefit of a google-linked video to explain things that already were properly explained, is rather small, at best, in my opinion
The article was made FROM the video and takes the wrong conclusions and summaries from it. If you want to form an opinion and are a bit technically savvy, you should watch the video instead.
For example: The video actually shows that all audio that is logged was only processed after voice-input was explicitly started on the device, either via the enabled wake-word or by starting voice-input in the web-search UI. The TV continues to show the text-input UI to the user while its transcribing the voice. This is not malicious, this is the expected behavior from user-perspective.
gchamonlive 6 minutes ago [-]
Pihole blacklist, would it be enough to mitigate this?
ionwake 4 hours ago [-]
I know its important to put things down to coincidence whenever possible, but a very expensive Bang OLufsen ( I think they use LG ) TV would turn itself off at "the" most interesting split second moments during gameplay , to the point where I thought "if I am being pranked by a friend, does this TV even stream its contents?".
Much to my surprise I found out that many modern TVs do in fact come with dev mode that allow some sort of screen capture.
Safe to say I turned off all the "allow metrics and market/dev modes" and have been happier since.
EDIT> Incase anyone was wondering I did some more research about my model ( im NOT a TV guy ) and came across this regarding what screen content could technically be passed remotely: "Most probable raw grab: ThinQ/SSAP on the LAN after pairing — ~960×540 JPEG.
Live Plus/ACR: most probably sends a fingerprint, not a retrievable raw frame." No idea what it means but thought it might be relevant. Remember Im saying in my case it was a coincidence.
ErigmolCt 3 hours ago [-]
I'm inclined to believe the shutdowns were a bug rather than an extremely patient friend waiting for the perfect gameplay moment. But modern TVs having enough remote-management machinery that the prank theory isn't immediately absurd is not exactly reassuring.
Nition 4 hours ago [-]
Did it ever turn itself off after you made those settings changes?
ionwake 3 hours ago [-]
Im not here to feed conspiracy theories and paranoia, its most likely a coincidence, and tied to having "excess metrics and advanced features that indirectly cause a kernel panic that turns the tv off".
But yes, after turning a bunch of unnecessary default options off, my TV never restarted again just as I was making a clutch moment.
So in summary - remember it could just be related to high action moment fps drain, heat, high intensity stuff making the nintendo switch2 compatibility cause a kernel affected restart etc etc etc ( which is documented via the HDMI protocols ) which make it SEEM like something weird is up, but it turns out its a related thing thats not that sus.
secretsatan 2 hours ago [-]
Ahhh, i had that with my ps5 and a couple of games were terrible in hiqh quality graphics mode, shutting down the ps5, and then through hdmi, would turn off the tv.
Both games weren’t particularly intensive, the one i remember last was divinity original sin 2, but i think both games ran on unity.
Performance mode mostly fixed it, but blowing out several years of dust from the vents properly sorted it out.
secretsatan 3 hours ago [-]
Most tvs now come with auto off kou have to cancel with a button press, prob just that.
Normally they show a warning, but i just got a new tcl, and it’s warning is very short leading to shutdown if you don’t pause quick enough to reset it
ionwake 3 hours ago [-]
That did happen a few times , but Im telling you bro that TV restarted a couple times just as I was about to clutch, like the same second i was about to press a trigger in an otherwise boring 25 minute round more than once, but yes as I mentioned earlier it could be related to other tech aspects.
This is the same behaviour as the german secret police in east germany. The difference now its for ads and by tech.
All collected data are probably ai transcribed from audio to text and is fused via data fusion to serve ads. Add collaborative filtering to find similar interests between users.
polotics 4 hours ago [-]
how do you know it is for ads? how do you know it will always be only for ads if it now is?
sixeyes 4 hours ago [-]
that's the fear, but it would be reasonable to say that ads are what has gotten us to this point
jiaosdjf 4 hours ago [-]
Why not both?
Mossad would love to know who to de-bank for criticising Israel, United Health Care would love to know who to deny coverage to based on remarks about their back pain.
xyzelement 3 hours ago [-]
// Mossad would love to know who to de-bank for criticising Israel
"Criticizing Israel" has moved from edgy subversive to lamely pedestrian in the last few years.
There's no great secret that Mossad needs to unearth by spying on you watching tv.
maxglute 2 hours ago [-]
TFW LG OLED without internet access probably flirting with neighbor's connected LG fridge and LG washer and sharing all my gossip to Chaebols anyway. Just waiting for Chinese OLED to commoditize far enough that you can ship a bare panel with outputs for development. Reality is Korean companies do have enough competition / incentive to value engineer down. There's no reason 5/10 years from you can't just buy a nice OLED panel and a 3D printed shell from ali like eink now. Except more sanctions I guess.Seems like just a matter of time gig work license plate scanners also wardrive around with open access points to harvest info from "unconnected" smart devices, if not already.
c16 2 hours ago [-]
It's been fun to see people re-writing and flashing their own smartwatch software with LLMs. Looking forward to the first TV OS rewrite video.
INTPenis 33 minutes ago [-]
I've been using a big monitor as a TV for 8 years now. That's all it takes, a big monitor.
I just didn't want to buy any TV that was available 8 years ago because they all seemed invasive to me.
trilogic 4 hours ago [-]
Is all of them, every "smart tv" does it, even after adb, permission restricting or rooting.
Insert a (non infected) usb lamp in your tv and see the lamp turning on when your tv is off. It notifies you about the background activation activity :) Interesting to see when exactly get active (is it keywords or nearby devices or scheduled processes)? Can´t be keywords as that would mean 24/7 active and the lamp says otherwise.
medwards666 3 hours ago [-]
This sort of blanket data collection needs to be made illegal in every single jurisdiction, and have _very_ robust penalties for anyone found in breach of them.
afarah1 24 minutes ago [-]
Legislators in every jurisdiction seem to have more to gain with the data collection than without.
pferde 3 hours ago [-]
And those jurisdictions need to have people not susceptible to bribery or extortion by the corporations making those data collection devices. That's a big ask.
medwards666 3 hours ago [-]
True. But corruption by those in positions of power and influence is a problem as old as the ages, sadly. But at least there _are_ rules and penalties in place for those caught so there's an element of risk. Whereas the blanket data harvesting by corporations currently appears to go utterly unabated.
hypfer 3 hours ago [-]
I'm practically certain that there was no ill-intent by LG when conceiving this feature. It was most likely just a convenience thing.
But I am also practically certain, that, eventually, any pile of data will attract ideas you do not want attracted.
tremon 3 hours ago [-]
I don't share your definition of ill intent. The decision to put a (hidden) recording device in people's homes with the express purpose of exfiltrating data is already ill-intentioned of itself, regardless of whatever they planned to do with the collected data.
hypfer 3 hours ago [-]
Look, I am probably more on your side than you are yourself, but this constant one-up-ing out of outrage in comment sections is so incredibly useless and harmful. Can you please stop.
I more than most people deeply understand the rage there, but I've tried to have a conversation here that leads somewhere, and you're dragging it back down to baseline outrage.
This is not how we actually achieve the goals we want to achieve.
tremon 2 hours ago [-]
Pray tell, what goals do "we" want to achieve? Your position of no ill-intent does not sound like you're on the same side as I am, much less more so than myself.
hypfer 2 hours ago [-]
> Because your position of no ill-intent does not sound like you're on the same side as I am.
If your position is "We do not want these kinds of stuff to exist/happen", then we are.
If your position however is "Witchhunts are fun, and decisions and dialogue should be driven by emotions", then indeed we are misaligned by a few centuries.
tremon 2 hours ago [-]
Do not put words in my mouth. Where in my post did I advocate for any form of action?
hypfer 2 hours ago [-]
> Where in my post did I advocate for any form of action?
Wait what?
You don't? What?!
I want action. I do not want there to be a microphone array in my TV that may or may not sample at random times and forwards that data god knows where.
And to achieve that, I believe that we need to look at the systems that brought us to this outcome.
pessimizer 48 minutes ago [-]
You change the conversation about televisions to be about judging the person you're having the conversation with for what they think is "ill-intent" and for one-upsmanship, you put words into their mouth, and when they point it out, you ignore them and return to the conversation. You aggressively silence them, then start babbling about yourself.
Are you a bot designed to disrupt conversations or just doing a good imitation of one?
hypfer 36 minutes ago [-]
Yes, I am indeed trying to disrupt the classic outrage scripts, as I believe that they are harmful to our goals.
There are many, many places on the web where performative outrage as in-group signalling is cheered, but, ideally, we also have some spaces where we can think and derive solutions.
By splitting the spaces, people can get the emotional validation they crave, while we can also have a workspace to make things better and reduce the need for that validation in the first place.
dwedge 2 hours ago [-]
I agree with your sentiment but unless the person you replied to edited their comment it seems misguided. They mostly just said they didn't agree with you, there was no outrage or one upping, and genuine discussions should be encouraged
hypfer 2 hours ago [-]
If you look at it, it's just "it's ill-intent based on what it is, regardless of intent".
Which is.. a dumb statement, but also just the usual social media outrage one-upping in lingo that passes the letter of the law of HN.
Effectively, the user just said that things are bad in response to an implicit "let us examine why, how, and what to do about it". Which is known, but unhelpful and derailing.
And.. somehow also hinted at that I'd not be aligned enough, because my definition of ill-intent being based on intent is not shared.
Anyway.
dwedge 2 hours ago [-]
I read it more as them disagreeing with at what point it's "intent" - is it bad to give yourself the option to record all customers without consent or does it only become bad once they actually turn it on (remotely) and start shipping it.
Having said that, you might be right given the follow up to you
rickdeckard 3 hours ago [-]
Yes, unfortunately the investigative video is implying (or explicitly stating) malice on every detail they discovered, which is harming the overall message IMO.
They hacked the TV OS, then used the TV UI to do a web search with voice-input and observed (still on the UI!) that the voice input didn't stop immediately on silence but kept extending the search prompt with everything said [0].
The OS-hack was irrelevant for this, the whole sensationalism that a listening process is running (and therefore the device is listening to everything) is just drama added to the sober fact that someone started voice-input, the input field is still displayed on the bottom of the UI and keeps getting populated with new input.
There is an important message in this about security hardening, privacy, data protection, but this conspiracy theory that everything is made to spy on you is not helping...
I really wish Steve would not have befriended Louis to the degree he has, but.. well.
Or rather I wish Louis would limit the "bulldozing" persona to the context in which it is necessary instead of all contexts ever at any time.
No issue with people being friends. Just issue in standards deteriorating.
___
Is this how Twitter felt like for journalists back in the day?
You see a story, and you think "ah yes, that guy's signature"?
End me.
givinguflac 2 hours ago [-]
| but this conspiracy theory that everything is made to spy on you is not helping...
Have you actually looked at what is being discussed? There is no conspiracy theory, these are simple facts. Just about every electronic device is made to spy on you in 2026. Thinking otherwise is naive, at best.
rickdeckard 2 hours ago [-]
| but this conspiracy theory that everything is made to spy on you is not helping...
Have you actually looked at what is being discussed? There is no conspiracy theory, these are simple facts. Just about every electronic device is made to spy on you in 2026. Thinking otherwise is naive, at best.
You've accidentally proven my statement: If you're not specific, you're not helping.
pessimizer 43 minutes ago [-]
You don't understand - it's not meant to spy on you, it's only meant to spy on you.
It's only meant to spy on you in the way that won't get really bad viral press right now. If it spies on you in the way that people notice and object, it was clearly a honest mistake.
p0lychromatic 2 hours ago [-]
Granted, I only watched one hour of the original video, but I get the feeling the way it is presented is a bit dishonest.
A lot of the "silent listening" they show in the video is on a TV they rooted. They start recordings through arecord manually. Or, when they show the transcripts from the recording, the AI voice search is clearly visible on the screen and was manually triggered by something.
Now, does a smart TV need all that hardware? Is a compromised TV a security hazard and smart TVs need to learn more in terms of security from modern smartphones in terms of privacy indicators, attested boot and more?
Sure.
But I do not see enough evidence that the TV is actually voice capturing all this stuff on its own, without any notice.
There is plenty of stuff on the video regarding the network scanning, ACR and more that is definitely concerning. And this is something LG actually does by themselves (when you agree to their ToS / privacy policy).
However, I think that mixing the ACR / network scanning in with "let's root the TV and actively start recording ourselves" mixes the narrative of "what LG actually does" versus "what a compromised TV can actually do", and makes it seem like LG is just recording, transcribing and submitting voice transcript automatically by themselves.
This was not proven here. And I feel that GamersNexus is just risking a lawsuit here by not separating these different concerns clear enough.
mohsen1 4 hours ago [-]
I absolutely loathe my LG smart TV. Just switching to another input requires 3 button press.
I hope someone uses their free time to hack the OS and offer a clean and simple interface to make it a “dumb” TV.
givinguflac 2 hours ago [-]
I’m unaware of any projects trying to make a dumb tv, but I like the idea. You can start with rootmy.tv and research from there.
appcustodian2 4 hours ago [-]
You're not wrong, but you could ask your favorite LLM to interact with the LG API's to switch the input for you. At least for my case, it was ~10 minutes of work to develop a small tray app that looks for a specific USB device and switches the TV input if it gets inserted. I don't really even touch the remote anymore
JumpCrisscross 4 hours ago [-]
This is automatic liability in California and the EU, correct? Does Illinois consider one’s voice pattern to be a biometric? If so, there, too.
ranger_danger 9 minutes ago [-]
This is a known feature that is not hidden which is not automatically turned on by default.
You must set your TV to a different standby mode and enable LG voice control.
When you do this, it very plainly tells you that it can listen with the screen off so you can control the TV with voice.
Failure of User Awareness, not some nefarious spyware.
edf13 1 hours ago [-]
Be interesting to know the true cost of smart TVs without the subsidized benefit of tracking that the "smart" element has.
A comparison of a dumb 4k panel vs the equivalent "smart" tv for example>
jdalgetty 25 minutes ago [-]
Is there a list of which LG tvs do this?
1 hours ago [-]
rob74 3 hours ago [-]
Makes me glad I bought a Sony TV which has the microphone on the remote - and is compatible with older remotes without a microphone, so the new remote with its microphone and sponsored streaming service buttons gathers dust (without batteries inserted) while I use an old remote.
They will once they've killed television and they'll get back to the net.
gonzalohm 2 hours ago [-]
I'm convinced Google TV firmware does something similar. I have an LED bar connected to the TV via USB and from time to time the bar turns on but the TV is "off". I think it's silently turning on to send some kind of telemetry.
1970-01-01 49 minutes ago [-]
The only appliance that should come from the factory with a microphone is the telephone.
monkeydust 4 hours ago [-]
Wait, do LG Webos TVs have microphones in the TV and/or in the remote? I am aware of the latter only.
Gualdrapo 4 hours ago [-]
I could buy a tv in late 2014 and happened to be the last batch of bravia tvs pre android tv. Back then I was kind of bummed out that just a few weeks after that they announced the first tvs with android tv and now i was hooked with a smart-but-not-that-smart tv with a bunch of crappy ads, an unusable web browser and a non-customizable os.
But they stopped updating it years ago, none of its apps work anymore and the only "smart" feature that still works is screen mirroring feature. The tv part itself still works great. Not a 4k oled 120Hz shiny impressive thing but the image quality is still great. What I thought was an unlucky adquisition back then turned out to be a pretty good one.
ErigmolCt 3 hours ago [-]
Apps, browsers and "smart" features are disposable software, but a good panel can remain useful for a decade. Makes you wish manufacturers treated the smart layer as optional from the start.
alsetmusic 1 hours ago [-]
The thing that everyone thinks their smart phones do is true of their televisions and they probably won't discuss it.
testaccount121 34 minutes ago [-]
has anyone tried to pwn an lg smart tv using a coding agent? would love to turn mine into a dumb tv.
prmph 4 hours ago [-]
Just don't buy a smart TV. Buy a good "dumb" TV (or just get a good large monitor), then hook it up to a set top box (with TV capabilities as needed).
nnevatie 26 minutes ago [-]
> Buy a good "dumb" TV
Unfortunately, you can't have one without the other. The best, image quality -wise, TVs are all "smart".
JoshTriplett 2 hours ago [-]
That would be lovely. Unfortunately, to the best of my knowledge, nobody sells (for instance) high-quality 65"+ OLED non-"smart" TVs. "dumb TV" options are limited to older display technology.
I bought a Sceptre a few years ago but it died pretty quickly (dead pixel strip on the screen). But the replacement 44" Insignia (Best Buy) that I replaced it with has been an awesome tv.
So yes, you can just walk into the Electronics Store (Best Buy) and purchase a dumb TV.
drcongo 2 hours ago [-]
I don't understand why the best advice in this thread is getting downvoted. Even if you buy a smart TV and then disable the smarts, you're still teaching the TV companies that smart TVs sell.
kklisura 2 hours ago [-]
Is there a difference between a LG TV in EU and in USA?
rcarmo 1 hours ago [-]
The EU ones do reach out to endpoints, but mine is currently off and I am not testing that :)
rcarmo 1 hours ago [-]
I've had several conversations about this over the years, usually about the EU and how they keep harping on Apple (for instance) because it's a highly visible brand while they completely ignore LG (and others) and their massive data collection devices that (by the way) are in every single European institution.
And many government officials' households, too.
Just saying.
xuhu 3 hours ago [-]
When the first TV ships with a battery to keep running while unplugged, I'm dusting off my soldering iron and my digital circuits handbook.
My LG C5 is in a separate VLAN, with no access to the rest of my home network. I've never accepted the terms and conditions, and I don't need anything from it other than to be a display for my 4k player and PC. I guess now I'm going to remove Internet access from it altogether!
The thing I'd like is if the remote didn't have 4 buttons for crappy streaming services I will never use, but instead had 4 buttons to select the HDMI inputs directly; but no, I have to press a button, wait for the stupid laggy UI to load, navigate or point and click at input I want, then do the same to the preview window. A tedious pain in arse for basically the one main thing I use the remote for. It annoys me no end, and it seems to me that the last thing LG care about is the UX; they've put all their efforts into underhand and user-hostile profiling.
I also have a Roku Ultra for streaming, which I very rarely use. I don't expect they treat their users any better and they use ACR too
zerof1l 2 hours ago [-]
You can root your LG and install an app that allow remapping any button to do anything, including selecting specific HDMI input.
tombardier 29 minutes ago [-]
Oh wow; I'm definitely doing to look into this, thanks!
in_vestor 1 hours ago [-]
Why are people so infuriated by Flock cameras but just completely shrug at this (much worse) TV thing?
Nothing is going to change until people are that enraged by it.
datakan 1 hours ago [-]
Can't watch football on a flock camera
in_vestor 1 hours ago [-]
Is it really that simple? Is society really that dumb?
datakan 59 minutes ago [-]
Unfortunately yes.
gruelsandwich 4 hours ago [-]
As an owner of a (2020?) LG WebOS TV, to what degree can I fight this? Any point in trying Pihole with targeted blocking of certain IPs?
bilekas 4 hours ago [-]
So I have a tv of LG from the same period. I keep it dumb, not connected to the internet and just use an apple TV, so far it's a clean option. And it's always a good idea to have piHole up to, they usually have the block list updated with LG's and Samsungs urls.
realityloop 4 hours ago [-]
The Gamers Nexus video explained that they will connect to nearby open SSID’s to send the data they have collected. So just not connecting it to your network may not be enough.
stephen_g 2 hours ago [-]
I hear this a lot as a rumour but has it actually ever been demonstrated in the wild?
Fun fact: some (most?) Samsung TVs of the last ~6 years can't complete OOB setup if they're connected to a PiHoled network with the most vanilla PiHole filters
Disclaimer: I haven't tried any of this myself, I've just been looking into it as I am/was considering buying an LG TV.
datakan 1 hours ago [-]
The broken, terrible English on that website does not inspire confidence of any kind.
chimpontherun 4 hours ago [-]
PiHole doesn't block IPs. It blocks DNS. The device have at least three ways to bypass PiHole: use external DNS directly, or pin the phone-home servers' IP addresses, or use some other protocols to carry IP resolution.
I'd just open the TV and yank or desolder the mic out. Or use the TV as a dumb monitor -- don't connect it to WiFi or Ethernet. And use an external Kodi/AppleTV/whatever-rocks-your-viewing-boat
noinsight 4 hours ago [-]
> don't connect it to WiFi or Ethernet
This is not sufficient (for some of these devices) - they will automatically connect to an unsecured hotspot.
chimpontherun 4 hours ago [-]
well, if that was the case with my TV and/or if I was worried, I've got a soldering iron and I'm not afraid to use it
lodovic 4 hours ago [-]
At this point, best to just keep it disconnected. Just use an apple tv or similar. They sold us a spying device masqueraded as a smart TV.
If internet is really required, I'd personally flood such an LG tv with fake data - add a raspberry pi to provide it with looped audio streams for the microphone, fake bluetooth devices, and so on. But it's still probably a drop in a bucket.
tremon 3 hours ago [-]
Vote for politicians that vocally campaign against advertising surveillance.
nicce 4 hours ago [-]
I bought Apple TV many years ago and haven’t plugged tv into internet since.
shevy-java 3 hours ago [-]
These are spy devices. It is sad that the industry has become so addicted to sniffing - the problem I see is that they can no longer stop doing so, as they built an additional network around that yielding money to them.
noisy_boy 3 hours ago [-]
All devices in my home sit behind adguard. The TV can try all it wants.
rcarmo 60 minutes ago [-]
They are more creative than that.
9991 50 minutes ago [-]
Adguard only intercepts DNS, right? I would be worried that IP addresses to phone home are hardcoded. Doesn't seem like a resilient solution.
balazspapp 2 hours ago [-]
Isn't observation of LG's operation a violation?
I mean it may fit the category "Intercepting live telemetry packets as they travel from the client machine to the company's servers can violate the Electronic Communications Privacy Act (Wiretap Act)"
zerof1l 4 hours ago [-]
I have a rooted LG C4. Beyond blocking things at the DNS level, not accepting terms, not using AI, I wonder if there’s some existing software solution or a documented step-by-step to remove this bloatware/spyware.
morissette 2 hours ago [-]
Why I don’t have a tv
brador 3 hours ago [-]
SKorean intelligence on China (and Japan). This will not be easily regulated. The intelligence value is huge.
polotics 5 hours ago [-]
GDPR compliance lawsuitssss in 3...
marcyb5st 4 hours ago [-]
I really hope they do and slap them with the 4% of their total global annual turnover.
jck86 4 hours ago [-]
Somehow the EU only appears to target big wealthy service providers. I wonder why.
gpvos 3 hours ago [-]
Please bring your actual argument instead of insinuating stuff.
Anyway, the EU's reasons seem to be entirely legitimate to me.
jck86 3 hours ago [-]
There is censorship of illegal streaming sites crippling the internet (Cloudflare). People are being freightened from illegal iptv boxes to watch free sports because it could be part of a botnet or residential proxy network. There are million or billion euro fines for social media and service providers like google. There is enforcement against "fast fashion". Yet there is zero effort for iot privacy, not even labels or certification for good devices.
I don't want to be cynical but face it, the EU really only cares about things that generate money for themselves or big internal market players under the disguise of consumer safety and privacy. Obviously that also comes with some good effects but the perverse incentives are enormous from which we must not be blinded by ideology and warm feelings of our politicians being good and working for the people and the common good.
kklisura 2 hours ago [-]
Wasn't there concern that they would target small companies and thus stifle the innovation? Seems like a win-win to me.
AnssiH 3 hours ago [-]
CMS has a public tracker of GDPR fines (https://www.enforcementtracker.com/) listing over 3000 cases, most are companies HN readers have not heard of.
titzer 25 minutes ago [-]
Why does anyone trust any device? The surveillance capitalism is just sleepwalking towards disaster, but nobody cares because of the pretty screen and the goddamn brainrot content.
chimpontherun 4 hours ago [-]
the only TV I have connected to the home network (guilty, I admit), Sony OLED 65, ARP floods my network about 12-15 hours after "turning off". On a plus side, it doesn't appear to be streaming anything out: no local DNS hits, not enough outgoing traffic for any meaningful audio stream
The choice between privacy concerns and ineptly coded network stack is tough. But that's the choice we're forced to have
cyberpunk 4 hours ago [-]
Why don’t you just use it as a display and have a more reputable device (e.g a mini pc or an apple tv) feeding it? I’m not forced to give my tv network access at all, since it doesn’t do anything other than display whatever the apple box outputs…
chimpontherun 2 hours ago [-]
This is exactly what I do on the other TV, as I suggested in a different message in this thread. But this particular TV is mounted flush to the wall and there's physically no space for the apple TV anywhere near or behind it. Sacrifices we have to make
cyberpunk 44 minutes ago [-]
Is it your wall? We have a fairly modern house and the walls are solid gypsum so i just carved out a small hollow for it, cables are going via a channel with some ducting i then plastered over
regularfry 4 hours ago [-]
This is (mostly) the way. Samsung TV without networking configured, XBox for everything - which is problematic in its own ways but it's a known quantity. It doesn't prevent it from "helpfully" hopping on a nearby unsecured network but a) I haven't spotted one of those in a while, and b) it hasn't ever been able to get updates to change its behaviour to make it start doing that if it previously wouldn't.
like_any_other 4 hours ago [-]
I will remind everyone again that weev was raided by the FBI, arrested, and had all electronics seized, before getting a chance to defend himself in court, all for the crime of publishing emails he found on unsecured URLs he was able to guess.
But we're allowing 1000x worse things, because what, there's a vague line about it buried deep in some EULA, which means laws no longer apply?
Lets treat them the same. Raid LG, seize all of their electronics, at least in the US (other countries are encouraged to do their own raids), arrest the executives, and after they're all in jail, and digital forensics are poring over their products and servers to find what else they did, they can argue in court how actually all these crimes are legal.
It's only fair.
cindyllm 4 hours ago [-]
[dead]
VerifiedReports 4 hours ago [-]
Clearly the penalties for this are not high enough, because the scumbags keep doing it.
Vizio TVs were caught taking screen grabs and phoning those home years ago.
CommanderData 3 hours ago [-]
I posted two comments on similar threads recently. This is only going to get worse.
> Not long until companies partner with Amazon and others to send traffic automatically through their near-by devices like smart speakers, disconnecting will be impossible.
Not surprised if this is happening already. I don't want to remove radios out my TV..
> Samba, a media intelligence company have several partnerships with manufacturers to take screenshots and collect metadata.
Viewer analytics are valuable to companies like Samba, they aren't the only ones. Laws ASAP, these companies will lobby hard to stop anything of the sort.
Y-bar 4 hours ago [-]
notebookcheck.net:
> We value your privacy
Shares my browsing info with 1745 "partners" with no clear way to opt out (which ought to be opt-in by the way to be compliant with ePrivacy and GDPR).
blaze33 4 hours ago [-]
"We value your privacy" → "Your private data is valuable" (I guess)
robin_reala 5 hours ago [-]
I mean, I’m not disagreeing, but it’s a bit rich for a site that logs data to 1,745 “partners” to be complaining too much.
I'd just block them - and keep local streaming and remote control working
edit: just found out WebOS doesn't support DoH/DoT so nextdns won't work.
I wonder if one of the public dns providers got LG blocklisted natively with specific IP
And keeping it completely disconnected from the internet should be the default, in my opinion.
Since the legal system has once again failed to protect users from corporations, it's up to users to use technical means for self defense.
So just treat it as a best case scenario, knowing that it can get even worse.
I'd love to have a similar standard applied in the US but I'm not holding my breath.
I bought a Philips Ambilight OLED TV probably over 8 years now. Brilliant tv, great quality, I still see no reason to replace it at all. But its built in AndroidTV is garbage.
Any iphone/ipad/mac nearby will act as a router for them[1]
Given that we have already established that LG is a shady company, I wouldn't put it beyond them to try to use the same trick.
[1]https://lifehacker.com/tech/how-apple-airtags-actually-work
AirTags broadcast an encrypted ID. Phones build lists of ID’s they’ve seen and send the list to Apple.
There is no routing, no ability to send arbitrary data, no active communication of any sort. It’s not a mesh network.
The link you posted makes that pretty clear.
It is well known for like 5 years. Smsrt TVs go through your movies library, and upload screenshots and filenames to internet.
Some will start showing ads after firmware upgrade.
They can just start a capture, record to RAM / storage, and retrieve it later when it is reconnected to the network.
Otherwise if it's disconnected, it is still hard to exfiltrate the data somewhere. Maybe they could get creative via Bluetooth, but then you would need a cooperating device in proximity of the device.
I happen to have a NAS with family pictures I like to display. I can (and do) firewall that thing, but then you hit other issues like the apps you need to show pictures and movies in the first place not to install/run.
I've yet to hear of a reasonable recipe to isolate and secure such connected TVs. And don't get me started on Chromecast or other Android dongles, I've no reason to expect better treatment from Google. Some open source hacked-together box, then?
I've just used an old Intel NUC with Debian stable, a remote mini-keyboard and an automounted Samba share on the network forever. It's no more hacked together than any other computer. I do make the mouse pointer and the fonts real big. No apps required. Don't really need the keyboard except for mplayer hotkey presses - just the touchpad on it; if I need to do something that involves typing other than typing a password, I usually ssh in.
I think people are lowkey addicted to having shit sliding in and out and constantly being advertised to. How do you know what to watch unless somebody is constantly bombarding you with options? If it doesn't look like a star trek control panel, is it really TV?
If you like that, you can install Kodi. I haven't tried it since it was XBMC because I found the interfaces annoying and it had trouble dealing with networks, but I'm sure it's better.
> I've yet to hear of a reasonable recipe to isolate and secure such connected TVs
I don't even try. I overpay for dumb tvs in the present, or underpay for 10 year old tvs pre-Applefication. I've never owned a network capable television, or one with apps. I wouldn't.
edit: if your NAS is a separate box that can sit in proximity to your television, you could probably just run all of this stuff directly from the NAS. They spend most of their time doing nothing at all.
But yes, support for the ethernet mode as far as I'm aware was never actually implemented in any devices that reached retail availability.
Proportion of non-HN users whose TVs don't connect to the internet? Negligible
That could of course change. Could be even a nice feature for connecting your TV to the network via your multi media center, if the bandwidth is good.
HDMI Ethernet is dead, it's never going to happen in consumer televisions because it has a hard conflict with a feature a lot of people actually use.
Samsung were openly bragging about this on their website some years ago (for the benefit of their advertising partners) but have recently muddied the waters when I check their site again, couching it in language mentioning privacy and other evasive language:
https://www.samsung.com/us/support/answer/ANS10010616/
As far as I know, they don't literally scan your media libraries; they screenshot whatever you're watching through HDMI (most often cable / satellite boxes), as those devices don't provide the telemetry that normal apps do. This info is used for audience measurement (thing Nielsen ratings), as well as showing you ads that are actually likely to match your interests.
"Starting in 2014, Vizio made TVs that automatically tracked what consumers were watching and transmitted that data back to its servers. Vizio even retrofitted older models by installing its tracking software remotely. All of this, the FTC and AG allege, was done without clearly telling consumers or getting their consent.
...
"Vizio collected a selection of pixels on the screen that it matched to a database of TV, movie, and commercial content
https://arxiv.org/pdf/2409.06203 shows LG and Samsung doing something similar
I do have it isolated from other devices on my network, though.
It's actually a lot faster now (it's an 8 year old TV, their OS can get a little heavy on older models)
Same for anything whether you trust it or not (or somewhere in between).
that's not a plus, tho
In the previous topic I got ridiculed for not wanting to buy LG anymore because I could use an agent to modify to strip out the offending bits.
But there must be something better than just keeping to buy things that invade our privacy and homes further and further. Which brands aren’t doing this? Sony? They also announced a partnership for the lower end TVs IIRC.
> In the previous topic I got ridiculed for not wanting to buy LG anymore because I could use an agent to modify to strip out the offending bits.
Jesus fucking Christ.
Smart people need to band together to advocate their state governments to make commercial mass surveillance for any purpose a criminal offense (not just banning, making it a crime).
I am still wondering why consumer respecting brands are not emerging more and thriving.
That and not respecting the consumer is more profitable in the short term (only!), which means more marketing money, buying out other brands, lobbying to increase the barrier for entry, et cetera.
But also, people do not generally hesitate in front of an all-you-can-eat bouffe
There is a very I-am-very-smart aspect to these predictable sorts of comments. And weirdly they always seem oddly intended to diminish the core concern being addressed.
"Oh your TV is listening to you and mapping your network and exfiltrating your data? Yeah, well, look at that website that has some ads on it! Boom!
Give up. The future is lost. Don't sweat the wiretapping TV."
No they don’t. OP says it’s funny, that’s all.
I mean, LG would probably also pay someone to run around going "it's just funny, is all" in support if anyone noticed this pathetic astroturfing.
The idea that logging audio is bad, but cars logging your weight, tvs logging your watch history, scales sending your wifi details, android and apple both mapping your access point to create a pseudo-location tracker without GPS, my mobile network sending me location-based adverts based on tower proximity via sms to a dumbphone are all very very bad.
LG have slightly overstepped the line here, legally, but in my opinion they've overstepped what is OK by a long long way. A website reporting on this while sending your details to hundreds of tracking sites are doing the same thing - abusing what is allowed and I assume only printing the report for more engagement and not because they actually care.
LG need to go a lifetime shit list for this behaviour - there should be outrage like there was about Sony's root kit. But websites like this also need to find out that this behaviour is not ok
DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.
All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.
It's a trade off I guess. I use Home Assistant to control TVs, so kinda need the access.
My guess is: not much.
1. Do not connect to network 2. Create unauthenticated WiFi network 3. Monitor WiFi network
Strange no one has ever done this simple af test to backup their claims
I could see a threat if the TV had access to the internet and could establish a TLS tunnel or similar from the mothership, and execute commands on my LAN (or IoT network as it stands), and report back. That could establish a command & control channel that could potentially orchestrate an attack on my infrastructure via the TV.
However, reporting that "network X exists and has these devices" over a different network complicates things a fair bit. In theory they could still use the TV as a command and control platform, but it would have to switch networks between my closed network and the open network in order to execute commands and report results. Not saying it's impossible, just very unlikely.
Besides, the TVs are not alone in being cut off from the internet. I have two IoT networks, one for trusted devices (AppleTVs, Sonos, and the likes), and one for untrusted devices like TVs. They run on different VLANs, and anything on the untrusted IoT network can pretty much only talk to itself (client isolation) and the gateway, and there's no internet and no open ports to any other VLAN.
Uploading the weeks, months, or years of locally-stored activity [0] data? Text compresses really well and local storage used to be very cheap.
[0] ...mic voice transcription, how often you use the thing, for how long, and a best guess (because of lack of time sync) at when, "automated content detection" logs [1], names of files you've fed to the thing, -if equipped with a camera- number of people in the room and interesting information about them, etc, etc, etc...
[1] ...assuming that that can be done with data loaded from the factory, which I kinda doubt...
I could possibly do it via HDMI CEC, but I have a couple of Sony Bravia TVs that more often than not completely ignores that, so I prefer having control over assuming it happens.
I believe LG doesn’t advertise such an api via Bluetooth
https://www.pulse-eight.com/p/104/usb-hdmi-cec-adapter
Soon you won't be able to IoT network or block these devices as they begin to partner with Amazon and the likes that sell Internet for near-by IoT devices. Then your only option then is physically removing / de soldering radios from the board.
Laws needed, like yesterday.
Assuming they install some 5G modem in the device, which is pretty much dirt cheap these days (our local water utility uses 5G for meter readings, and the cost per meter is something like $1/year), there's literally nothing short of a faraday cage you can do.
The can report on what you watch freely, and only consumer laws can stop them. However, without a wifi connection they can't snoop on your local network, and they probably can't connect the data to you, assuming you don't register the TV for those 3 months of added warranty or whatever they try to get you to register.
I tend to avoid devices that are built to snoop on you, so no Amazon Alexa, no Google Home, no Apple HomePod. Everything I have utilizes local control via Home Assistant, and most of it is actively blocked in the firewall from accessing the internet. It's not hard to implement, and doesn't require a master of IT, but it does remove a lot of the convenience, which I guess is the reason people don't do it.
E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
That's an easy one to put a compensation figure on but there's probably all sorts of other exploits waiting to happen.
I think the most egregious thing here is that if you don't give the TV a network connection that it will actively search for other ways to get the data back to LG such as open WIFI.
That's understating the problem. With or without AI, this should be cause enough to shut down a company or at least their specific product division.
>E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
They're going to be fine. A slap on the wrist at best.
Never in human history has a government had the means to simultaneously spy on millions of people, to use everyday private conversations to categorise them into various threats to the state, and better yet these tech companies can still sell the commercially valuable side of this to advertisers.
- Larry Ellison (Oracle Corporation)
That said, I think there is a lot of appeal to go hunting for firms, since it really feels like corporations and their owners are engaging in predatory behavior as opposed to customer centric behavior.
My tinfoil hat believes that they've already accounted for this as the price of doing business. They will have already budgeted for the fines that they might incur, pay them off and continue as normal while people become accustomed to it.
Will make surveillance mandatory? I mean we definitely should somehow fight terrorism, protect children, and prevent copyright infringement on trillions of dollars per year.
I wonder what chances a consumer in US has though. If the past is any indication, consumer privacy is not a highly regarded good when ranked against a corporate strategy...
No. this is going to go "unnoticed" or at least unactioned. These are surveilance devices - compromising their value as source of surveilance is neither in the interest of industry (who are selling and buying the surveilance) or government (who are buying and acting on it). The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now. These devices bery well may soon be the only lawfully available devices in the consumer market precisely because of their surveilance capabilities. Governments are reluctanty catching up to the capabilities of digital technologies, and they're finding them more useful now than ever before. We will be burning witches again before we ever prosecute tech companies for doing bad things.
Spot on.
If that's stored as text inside the TV and you lost money because it was copied by a hacker then you have a monetary value to show loss and a trail of liability you can use to sue LG.
The average user would not realize LG was the reason, if they do they will loose more money and effort; LG's reputation and public image won't be even damaged enough for them to take a notice. You are an ant for them and ants are only powerful if they work together.
Then they'll get a joke fine, and continue as before. Maybe cut the price for a while, until they reintroduce it with another pretext a few years down the line.
The legal systems that are in place (at least, those in the US) are not sufficient or even designed to act in any amount of favor of individuals. Even leveraging collective action (class action cases), most individuals are left worse off after judgement when they are wronged. Signalling that you are an affected class is effectively an admission of, at minimum, association - and worse guilt, of whatever an inteligence agency may suspect you of. Intelligence is not justice, and does not "protect" individuals under the same standards. If a government wants you to be wronged, they will accomplish it regardless of law, and the information they have regarding you will be leveraged as aggressively as possible. If you are simply wronged, the cost of accomplishing justice is often insurmountable.
In the most innocent case of wrongdoing by one of these surveilance devices, what would you, as an individual, do if your bank details were compromised as a result of a "smart" device exposing your credentials to bad actors? Obviously, you would contact your banking institution and try your best to rememedy the situation. But say, for example, this smart device is on your home network, has your login details, and possibly used your 2fa details because you used it to log in to your banking institution. That is You™. You logged in. You actioned something. It's verifiable because of your IP and your cookies and your 2fa code and the heuristics of your device usage (time of day, and the previous factors, and more). Many smart device applications already include SDKs that act as residential proxies - it's not impossible to believe that malicious ones may act as MITM or such. The possibility of 0Day expoloits or even backdoors can never be ruled out as you do not own these devices.
People should be subject to shame. Every government and every company are composed of people (for now) - these people are what action these possible futures, and who action the exploits of now. They are shameless by trade because that is their value. Much like the adtech industry thrives on the compromise of compensation to overcome the shame of doing wrong, so does intelligence and clandestine commercial exploitation. Money affords people the things that they want and need, which are becoming ever more impossible to acquire without succumbing to the shame of doing Bad Things™ to acquire it. You are never going to be able to sue LG because your bank details were leaked by a public DB or some other endpoint. Nobody will. Because the value of the information that LG provides to governments circumventing established anti-surveilance law (in the US, the 4th Amendment) through sales is worth more than any dollar amount it costs these parties.
Shame on every fucking one of you stains who implements this, if you can feel it, hidden in the walls of your owned property.
0: https://en.wikipedia.org/wiki/Five_Eyes 1: https://en.wikipedia.org/wiki/Israeli_espionage_in_the_Unite...
ꭞ Terms and conditions apply
War is peace. Freedom is slavery. Ignorance is strength. [1]
Would you like to know more?
[1] https://en.wikipedia.org/wiki/Telescreen
My LG is completely offline and I'm using an nvidia shield to display any content, but I'm thinking maybe I need to go the extra mile, there nothing preventing an android tv box to do the same.
Are you sure? They will seek out open WiFi and other neighboring LG TVs as relays.
I couldn't find any "smoking gun" or discovery of malicious intent.
What's left in the end is the already-known fact in the tech-community: The most-common, most-vulnerable and most-equipped device to spy on you in your home is your Smart-TV.
1. It has all the compute-power and sensors it needs
2. It already does some spying for ad-profiling
3. If a hacker exploits it, it's a problem
For a lot of hacker type stuff (esp. botnets and residential proxies), this is exactly what you want.
I used to believe that piracy couldn't come back in a significant way because people don't want to use computers any more, and phones are a really bad fit for p2p, even if running some hypothetical non-walled-garden OS that wouldn't have issues with that sort of thing. I entirely failed to appreciate the impact of cheap Android TV boxes here.
4. Every single fucked up thing it did was indeed listed in their customer agreement and privacy policy
"216M Spy TVs – The LG Smart TV Problem [video]" https://news.ycombinator.com/item?id=49592375
"LG TVs aren't the only ones spying on you [video]" https://news.ycombinator.com/item?id=49575176
Sent from iPhone (for now)
1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.
2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.
3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.
All the points and scenarios in the video might be valid, but they are not sufficiently grouped into one of the above categories.
Instead, it just mixes them all together to imply that its all the same, weakening the whole investigation.
--
The plain example: Using voice-input for a web-search on the TV [0], make long pauses and observe how it keeps populating the prompt-UI with everything you say. This is a matter of #3 above, accusing a malicious intent already on such a trivial implementation topic is harming the whole story
[0] https://youtu.be/6IFVTcM28KA?si=oVqX6NtkxPmqh6R-&t=2951
I prefer the original article and the net-benefit of a google-linked video to explain things that already were properly explained, is rather small, at best, in my opinion.
Sorry, my grouping of topics isn't supposed to replace the entire research-session.
It's merely my observation after watching the actual "investigation video" that they mixed together lots of stuff they discovered into the larger conspiracy that everything is secretly spying on the user to feed a huge Ad-profiling database.
> I prefer the original article and the net-benefit of a google-linked video to explain things that already were properly explained, is rather small, at best, in my opinion
The article was made FROM the video and takes the wrong conclusions and summaries from it. If you want to form an opinion and are a bit technically savvy, you should watch the video instead.
For example: The video actually shows that all audio that is logged was only processed after voice-input was explicitly started on the device, either via the enabled wake-word or by starting voice-input in the web-search UI. The TV continues to show the text-input UI to the user while its transcribing the voice. This is not malicious, this is the expected behavior from user-perspective.
Much to my surprise I found out that many modern TVs do in fact come with dev mode that allow some sort of screen capture.
Safe to say I turned off all the "allow metrics and market/dev modes" and have been happier since.
EDIT> Incase anyone was wondering I did some more research about my model ( im NOT a TV guy ) and came across this regarding what screen content could technically be passed remotely: "Most probable raw grab: ThinQ/SSAP on the LAN after pairing — ~960×540 JPEG. Live Plus/ACR: most probably sends a fingerprint, not a retrievable raw frame." No idea what it means but thought it might be relevant. Remember Im saying in my case it was a coincidence.
But yes, after turning a bunch of unnecessary default options off, my TV never restarted again just as I was making a clutch moment.
So in summary - remember it could just be related to high action moment fps drain, heat, high intensity stuff making the nintendo switch2 compatibility cause a kernel affected restart etc etc etc ( which is documented via the HDMI protocols ) which make it SEEM like something weird is up, but it turns out its a related thing thats not that sus.
Both games weren’t particularly intensive, the one i remember last was divinity original sin 2, but i think both games ran on unity.
Performance mode mostly fixed it, but blowing out several years of dust from the vents properly sorted it out.
Normally they show a warning, but i just got a new tcl, and it’s warning is very short leading to shutdown if you don’t pause quick enough to reset it
Mossad would love to know who to de-bank for criticising Israel, United Health Care would love to know who to deny coverage to based on remarks about their back pain.
"Criticizing Israel" has moved from edgy subversive to lamely pedestrian in the last few years.
There's no great secret that Mossad needs to unearth by spying on you watching tv.
I just didn't want to buy any TV that was available 8 years ago because they all seemed invasive to me.
But I am also practically certain, that, eventually, any pile of data will attract ideas you do not want attracted.
I more than most people deeply understand the rage there, but I've tried to have a conversation here that leads somewhere, and you're dragging it back down to baseline outrage.
This is not how we actually achieve the goals we want to achieve.
If your position is "We do not want these kinds of stuff to exist/happen", then we are.
If your position however is "Witchhunts are fun, and decisions and dialogue should be driven by emotions", then indeed we are misaligned by a few centuries.
Wait what?
You don't? What?!
I want action. I do not want there to be a microphone array in my TV that may or may not sample at random times and forwards that data god knows where.
And to achieve that, I believe that we need to look at the systems that brought us to this outcome.
Are you a bot designed to disrupt conversations or just doing a good imitation of one?
There are many, many places on the web where performative outrage as in-group signalling is cheered, but, ideally, we also have some spaces where we can think and derive solutions.
By splitting the spaces, people can get the emotional validation they crave, while we can also have a workspace to make things better and reduce the need for that validation in the first place.
Which is.. a dumb statement, but also just the usual social media outrage one-upping in lingo that passes the letter of the law of HN.
Effectively, the user just said that things are bad in response to an implicit "let us examine why, how, and what to do about it". Which is known, but unhelpful and derailing.
And.. somehow also hinted at that I'd not be aligned enough, because my definition of ill-intent being based on intent is not shared.
Anyway.
Having said that, you might be right given the follow up to you
They hacked the TV OS, then used the TV UI to do a web search with voice-input and observed (still on the UI!) that the voice input didn't stop immediately on silence but kept extending the search prompt with everything said [0].
The OS-hack was irrelevant for this, the whole sensationalism that a listening process is running (and therefore the device is listening to everything) is just drama added to the sober fact that someone started voice-input, the input field is still displayed on the bottom of the UI and keeps getting populated with new input.
There is an important message in this about security hardening, privacy, data protection, but this conspiracy theory that everything is made to spy on you is not helping...
[0] https://youtu.be/6IFVTcM28KA?si=OCmfai2KXSaQt1Bk&t=2958
Or rather I wish Louis would limit the "bulldozing" persona to the context in which it is necessary instead of all contexts ever at any time.
No issue with people being friends. Just issue in standards deteriorating.
___
Is this how Twitter felt like for journalists back in the day? You see a story, and you think "ah yes, that guy's signature"?
End me.
Have you actually looked at what is being discussed? There is no conspiracy theory, these are simple facts. Just about every electronic device is made to spy on you in 2026. Thinking otherwise is naive, at best.
You've accidentally proven my statement: If you're not specific, you're not helping.
It's only meant to spy on you in the way that won't get really bad viral press right now. If it spies on you in the way that people notice and object, it was clearly a honest mistake.
A lot of the "silent listening" they show in the video is on a TV they rooted. They start recordings through arecord manually. Or, when they show the transcripts from the recording, the AI voice search is clearly visible on the screen and was manually triggered by something.
Now, does a smart TV need all that hardware? Is a compromised TV a security hazard and smart TVs need to learn more in terms of security from modern smartphones in terms of privacy indicators, attested boot and more?
Sure.
But I do not see enough evidence that the TV is actually voice capturing all this stuff on its own, without any notice.
There is plenty of stuff on the video regarding the network scanning, ACR and more that is definitely concerning. And this is something LG actually does by themselves (when you agree to their ToS / privacy policy).
However, I think that mixing the ACR / network scanning in with "let's root the TV and actively start recording ourselves" mixes the narrative of "what LG actually does" versus "what a compromised TV can actually do", and makes it seem like LG is just recording, transcribing and submitting voice transcript automatically by themselves.
This was not proven here. And I feel that GamersNexus is just risking a lawsuit here by not separating these different concerns clear enough.
I hope someone uses their free time to hack the OS and offer a clean and simple interface to make it a “dumb” TV.
You must set your TV to a different standby mode and enable LG voice control.
When you do this, it very plainly tells you that it can listen with the screen off so you can control the TV with voice.
Failure of User Awareness, not some nefarious spyware.
A comparison of a dumb 4k panel vs the equivalent "smart" tv for example>
But they stopped updating it years ago, none of its apps work anymore and the only "smart" feature that still works is screen mirroring feature. The tv part itself still works great. Not a 4k oled 120Hz shiny impressive thing but the image quality is still great. What I thought was an unlucky adquisition back then turned out to be a pretty good one.
Unfortunately, you can't have one without the other. The best, image quality -wise, TVs are all "smart".
If anyone could recommend any dumb TV with good panels in EU, you're more than welcome.
- Samsung 40 inch Odyssey G7 (G75F) Series WUHD Curved Gaming Monitor (https://www.amazon.com/Samsung-Odyssey-Curved-Gaming-Monitor...) -- $699.99
- Acer Nitro 49 inch DQHD 5120x1440 Curved 120Hz Office Monitor (https://www.amazon.com/Acer-Nitro-Gaming-Monitor-UltraWide/d...) -- $549.99
- Acer DM431K A 43 inch Class 4K UHD LED Monitor - 16:9 (https://www.amazon.com/acer-DM431K-Class-UHD-Monitor/dp/B0F3...)-- $334.20
- LG 37G800A-B 37 inch Ultragear 4K UHD (3840 x 2160) Curved Gaming Monitor, 165Hz, 1ms (https://www.amazon.com/gp/product/B0FS3LV3WG) -- $598
- INNOCN 40C1R Ultrawide Monitor 40 inch WQHD 3440 x 1440p 144Hz (https://www.amazon.com/INNOCN-Ultrawide-Monitor-FreeSync-Pre...) -- $479.99
Just don't ever let it connect to the internet.
[0] https://andybeaumont.com/post/dumb-tv/
So yes, you can just walk into the Electronics Store (Best Buy) and purchase a dumb TV.
And many government officials' households, too.
Just saying.
The thing I'd like is if the remote didn't have 4 buttons for crappy streaming services I will never use, but instead had 4 buttons to select the HDMI inputs directly; but no, I have to press a button, wait for the stupid laggy UI to load, navigate or point and click at input I want, then do the same to the preview window. A tedious pain in arse for basically the one main thing I use the remote for. It annoys me no end, and it seems to me that the last thing LG care about is the UX; they've put all their efforts into underhand and user-hostile profiling.
I also have a Roku Ultra for streaming, which I very rarely use. I don't expect they treat their users any better and they use ACR too
Nothing is going to change until people are that enraged by it.
Disclaimer: I haven't tried any of this myself, I've just been looking into it as I am/was considering buying an LG TV.
I'd just open the TV and yank or desolder the mic out. Or use the TV as a dumb monitor -- don't connect it to WiFi or Ethernet. And use an external Kodi/AppleTV/whatever-rocks-your-viewing-boat
This is not sufficient (for some of these devices) - they will automatically connect to an unsecured hotspot.
If internet is really required, I'd personally flood such an LG tv with fake data - add a raspberry pi to provide it with looped audio streams for the microphone, fake bluetooth devices, and so on. But it's still probably a drop in a bucket.
Anyway, the EU's reasons seem to be entirely legitimate to me.
I don't want to be cynical but face it, the EU really only cares about things that generate money for themselves or big internal market players under the disguise of consumer safety and privacy. Obviously that also comes with some good effects but the perverse incentives are enormous from which we must not be blinded by ideology and warm feelings of our politicians being good and working for the people and the common good.
The choice between privacy concerns and ineptly coded network stack is tough. But that's the choice we're forced to have
But we're allowing 1000x worse things, because what, there's a vague line about it buried deep in some EULA, which means laws no longer apply?
Lets treat them the same. Raid LG, seize all of their electronics, at least in the US (other countries are encouraged to do their own raids), arrest the executives, and after they're all in jail, and digital forensics are poring over their products and servers to find what else they did, they can argue in court how actually all these crimes are legal.
It's only fair.
Vizio TVs were caught taking screen grabs and phoning those home years ago.
> Not long until companies partner with Amazon and others to send traffic automatically through their near-by devices like smart speakers, disconnecting will be impossible.
Not surprised if this is happening already. I don't want to remove radios out my TV..
> Samba, a media intelligence company have several partnerships with manufacturers to take screenshots and collect metadata.
Viewer analytics are valuable to companies like Samba, they aren't the only ones. Laws ASAP, these companies will lobby hard to stop anything of the sort.
> We value your privacy
Shares my browsing info with 1745 "partners" with no clear way to opt out (which ought to be opt-in by the way to be compliant with ePrivacy and GDPR).