I know its important to put things down to coincidence whenever possible, but a very expensive Bang OLufsen ( I think they use LG ) TV would turn itself off at "the" most interesting split second moments during gameplay , to the point where I thought "if I am being pranked by a friend, does this TV even stream its contents?".
Much to my surprise I found out that many modern TVs do in fact come with dev mode that allow full remote streaming.
Safe to say I turned off all the "allow metrics and market/dev modes" and have been happier since.
I'm inclined to believe the shutdowns were a bug rather than an extremely patient friend waiting for the perfect gameplay moment. But modern TVs having enough remote-management machinery that the prank theory isn't immediately absurd is not exactly reassuring.
Im not here to feed conspiracy theories and paranoia, its most likely a coincidence, and tied to having "excess metrics and advanced features that indirectly cause a kernel panic that turns the tv off".
But yes, after turning a bunch of unnecessary default options off, my TV never restarted again just as I was making a clutch moment.
So in summary - remember it could just be related to high action moment fps drain, heat, high intensity stuff making the nintendo switch2 compatibility cause a kernel affected restart etc etc etc ( which is documented via the HDMI protocols ) which make it SEEM like something weird is up, but it turns out its a related thing thats not that sus.
In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
That's an easy one to put a compensation figure on but there's probably all sorts of other exploits waiting to happen.
I think the most egregious thing here is that if you don't give the TV a network connection that it will actively search for other ways to get the data back to LG such as open WIFI.
>In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
That's understating the problem. With or without AI, this should be cause enough to shut down a company or at least their specific product division.
>E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
They're going to be fine. A slap on the wrist at best.
The value of this data to the NSA, Mossad etc is probably the only thing keeping it secure.
Never in human history has a government had the means to simultaneously spy on millions of people, to use everyday private conversations to categorise them into various threats to the state, and better yet these tech companies can still sell the commercially valuable side of this to advertisers.
People could return to burning down enterprises that they find unsavory or detrimental to society, such as they did during the industrial revolution, but this is problematic in that it's violent and not something the modern person often considers as viable. A part of why people consider this unviable now is in-part due to the consequences of these surveilance technologies. It's difficult to accomplish a revolution when everyone is being spied on all the time.
> E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
My tinfoil hat believes that they've already accounted for this as the price of doing business. They will have already budgeted for the fines that they might incur, pay them off and continue as normal while people become accustomed to it.
>this is going to be a massive business liability.
No. this is going to go "unnoticed" or at least unactioned. These are surveilance devices - compromising their value as source of surveilance is neither in the interest of industry (who are selling and buying the surveilance) or government (who are buying and acting on it). The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now. These devices bery well may soon be the only lawfully available devices in the consumer market precisely because of their surveilance capabilities. Governments are reluctanty catching up to the capabilities of digital technologies, and they're finding them more useful now than ever before. We will be burning witches again before we ever prosecute tech companies for doing bad things.
>The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now.
I'm thinking less about shame, as corporations are dead to shame, and more about proof the TV stored a record of your bank details it got from text to speech.
If that's stored as text inside the TV and you lost money because it was copied by a hacker then you have a monetary value to show loss and a trail of liability you can use to sue LG.
The average user would not realize LG was the reason, if they do they will loose more money and effort; LG's reputation and public image won't be even damaged enough for them to take a notice. You are an ant for them and ants are only powerful if they work together.
>I'm thinking less about shame, as corporations are dead to shame, and more about if you can prove the TV stored a record of your bank details it got from text to speech.
Then they'll get a joke fine, and continue as before. Maybe cut the price for a while, until they reintroduce it with another pretext a few years down the line.
You would think that would matter, that they’re basically violating all known PII/HIPAA/GDPR/National security standards and god knows what else, but I expect at most some class action down the line.
Makes me glad I bought a Sony TV which has the microphone on the remote - and is compatible with older remotes without a microphone, so the new remote with its microphone and sponsored streaming service buttons gathers dust (without batteries inserted) while I use an old remote.
I've bought an LG Smart TV 5 years ago, read t&c where I was supposed to grant them any data they wanted, decided to disagree and kept all network functions disabled. I was ridiculed by my friends for that. At some point, I thought - maybe I'm really crazy to do so? Who am I, a caveman, a luddite? Oh well, I'm not. Not a bad tv though, many HDMI ports!
My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet.
DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.
All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.
All of your blocking still doesn't change the fact that your LG TV is actively trying to scan your local hardware, gathering IP-addresses of devices, wi-fi names and signal strengths, creating digital finger prints of the audio and video projected on your screen, recording audio through the internal microphone, even when the TV is in standby or without an internet connection, saving the collected data locally and uploading to LG Ad Solutions as soon as the TV is connected to the internet.
But it's never connected to the internet, not even for software updates. If the TV isn't connected to the internet there's no reason to update it, assuming the TV works as expected.
It's a trade off I guess. I use Home Assistant to control TVs, so kinda need the access.
And then your neighbor spins up an unprotected network or something like xfinity which they could have a deal with and it connects there and phones home anyways.
And what exactly would they use that particular access path for ?
I could see a threat if the TV had access to the internet and could establish a TLS tunnel or similar from the mothership, and execute commands on my LAN (or IoT network as it stands), and report back. That could establish a command & control channel that could potentially orchestrate an attack on my infrastructure via the TV.
However, reporting that "network X exists and has these devices" over a different network complicates things a fair bit. In theory they could still use the TV as a command and control platform, but it would have to switch networks between my closed network and the open network in order to execute commands and report results. Not saying it's impossible, just very unlikely.
Besides, the TVs are not alone in being cut off from the internet. I have two IoT networks, one for trusted devices (AppleTVs, Sonos, and the likes), and one for untrusted devices like TVs. They run on different VLANs, and anything on the untrusted IoT network can pretty much only talk to itself (client isolation) and the gateway, and there's no internet and no open ports to any other VLAN.
I use Home Assistant to turn on/off the TV via automations, sensors, etc.
I could possibly do it via HDMI CEC, but I have a couple of Sony Bravia TVs that more often than not completely ignores that, so I prefer having control over assuming it happens.
I could buy a tv in late 2014 and happened to be the last batch of bravia tvs pre android tv. Back then I was kind of bummed out that just a few weeks after that they announced the first tvs with android tv and now i was hooked with a smart-but-not-that-smart tv with a bunch of crappy ads, an unusable web browser and a non-customizable os.
But they stopped updating it years ago, none of its apps work anymore and the only "smart" feature that still works is screen mirroring feature. The tv part itself still works great. Not a 4k oled 120Hz shiny impressive thing but the image quality is still great. What I thought was an unlucky adquisition back then turned out to be a pretty good one.
This sort of blanket data collection needs to be made illegal in every single jurisdiction, and have _very_ robust penalties for anyone found in breach of them.
This is the same behaviour as the german secret police in east germany. The difference now its for ads and by tech.
All collected data are probably ai transcribed from audio to text and is fused via data fusion to serve ads. Add collaborative filtering to find similar interests between users.
Mossad would love to know who to de-bank for criticising Israel, United Health Care would love to know who to deny coverage to based on remarks about their back pain.
You're not wrong, but you could ask your favorite LLM to interact with the LG API's to switch the input for you. At least for my case, it was ~10 minutes of work to develop a small tray app that looks for a specific USB device and switches the TV input if it gets inserted. I don't really even touch the remote anymore
Is all of them, every "smart tv" does it, even after adb, permission restricting or rooting.
Insert a (non infected) usb lamp in your tv and see the lamp turning on when your tv is off. It notifies you about the background activation activity :) Interesting to see when exactly get active (is it keywords or nearby devices or scheduled processes)? Can´t be keywords as that would mean 24/7 active and the lamp says otherwise.
I have a rooted LG C4. Beyond blocking things at the DNS level, not accepting terms, not using AI, I wonder if there’s some existing software solution or a documented step-by-step to remove this bloatware/spyware.
I will remind everyone again that weev was raided by the FBI, arrested, and had all electronics seized, before getting a chance to defend himself in court, all for the crime of publishing emails he found on unsecured URLs he was able to guess.
But we're allowing 1000x worse things, because what, there's a vague line about it buried deep in some EULA, which means laws no longer apply?
Lets treat them the same. Raid LG, seize all of their electronics, at least in the US (other countries are encouraged to do their own raids), arrest the executives, and after they're all in jail, and digital forensics are poring over their products and servers to find what else they did, they can argue in court how actually all these crimes are legal.
the only TV I have connected to the home network (guilty, I admit), Sony OLED 65, ARP floods my network about 12-15 hours after "turning off". On a plus side, it doesn't appear to be streaming anything out: no local DNS hits, not enough outgoing traffic for any meaningful audio stream
The choice between privacy concerns and ineptly coded network stack is tough. But that's the choice we're forced to have
Why don’t you just use it as a display and have a more reputable device (e.g a mini pc or an apple tv) feeding it? I’m not forced to give my tv network access at all, since it doesn’t do anything other than display whatever the apple box outputs…
This is (mostly) the way. Samsung TV without networking configured, XBox for everything - which is problematic in its own ways but it's a known quantity. It doesn't prevent it from "helpfully" hopping on a nearby unsecured network but a) I haven't spotted one of those in a while, and b) it hasn't ever been able to get updates to change its behaviour to make it start doing that if it previously wouldn't.
So I have a tv of LG from the same period. I keep it dumb, not connected to the internet and just use an apple TV, so far it's a clean option. And it's always a good idea to have piHole up to, they usually have the block list updated with LG's and Samsungs urls.
The Gamers Nexus video explained that they will connect to nearby open SSID’s to send the data they have collected. So just not connecting it to your network may not be enough.
Fun fact: some (most?) Samsung TVs of the last ~6 years can't complete OOB setup if they're connected to a PiHoled network with the most vanilla PiHole filters
At this point, best to just keep it disconnected. Just use an apple tv or similar. They sold us a spying device masqueraded as a smart TV.
If internet is really required, I'd personally flood such an LG tv with fake data - add a raspberry pi to provide it with looped audio streams for the microphone, fake bluetooth devices, and so on. But it's still probably a drop in a bucket.
PiHole doesn't block IPs. It blocks DNS. The device have at least three ways to bypass PiHole: use external DNS directly, or pin the phone-home servers' IP addresses, or use some other protocols to carry IP resolution.
I'd just open the TV and yank or desolder the mic out. Or use the TV as a dumb monitor -- don't connect it to WiFi or Ethernet. And use an external Kodi/AppleTV/whatever-rocks-your-viewing-boat
Shares my browsing info with 1745 "partners" with no clear way to opt out (which ought to be opt-in by the way to be compliant with ePrivacy and GDPR).
But I am also practically certain, that, eventually, any pile of data will attract ideas you do not want attracted.
Much to my surprise I found out that many modern TVs do in fact come with dev mode that allow full remote streaming.
Safe to say I turned off all the "allow metrics and market/dev modes" and have been happier since.
But yes, after turning a bunch of unnecessary default options off, my TV never restarted again just as I was making a clutch moment.
So in summary - remember it could just be related to high action moment fps drain, heat, high intensity stuff making the nintendo switch2 compatibility cause a kernel affected restart etc etc etc ( which is documented via the HDMI protocols ) which make it SEEM like something weird is up, but it turns out its a related thing thats not that sus.
Normally they show a warning, but i just got a new tcl, and it’s warning is very short leading to shutdown if you don’t pause quick enough to reset it
E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
That's an easy one to put a compensation figure on but there's probably all sorts of other exploits waiting to happen.
I think the most egregious thing here is that if you don't give the TV a network connection that it will actively search for other ways to get the data back to LG such as open WIFI.
That's understating the problem. With or without AI, this should be cause enough to shut down a company or at least their specific product division.
>E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
They're going to be fine. A slap on the wrist at best.
Never in human history has a government had the means to simultaneously spy on millions of people, to use everyday private conversations to categorise them into various threats to the state, and better yet these tech companies can still sell the commercially valuable side of this to advertisers.
- Larry Ellison (Oracle Corporation)
My tinfoil hat believes that they've already accounted for this as the price of doing business. They will have already budgeted for the fines that they might incur, pay them off and continue as normal while people become accustomed to it.
No. this is going to go "unnoticed" or at least unactioned. These are surveilance devices - compromising their value as source of surveilance is neither in the interest of industry (who are selling and buying the surveilance) or government (who are buying and acting on it). The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now. These devices bery well may soon be the only lawfully available devices in the consumer market precisely because of their surveilance capabilities. Governments are reluctanty catching up to the capabilities of digital technologies, and they're finding them more useful now than ever before. We will be burning witches again before we ever prosecute tech companies for doing bad things.
Spot on.
If that's stored as text inside the TV and you lost money because it was copied by a hacker then you have a monetary value to show loss and a trail of liability you can use to sue LG.
The average user would not realize LG was the reason, if they do they will loose more money and effort; LG's reputation and public image won't be even damaged enough for them to take a notice. You are an ant for them and ants are only powerful if they work together.
Then they'll get a joke fine, and continue as before. Maybe cut the price for a while, until they reintroduce it with another pretext a few years down the line.
It is well known for like 5 years. Smsrt TVs go through your movies library, and upload screenshots and filenames to internet.
Some will start showing ads after firmware upgrade.
"216M Spy TVs – The LG Smart TV Problem [video]" https://news.ycombinator.com/item?id=49592375
"LG TVs aren't the only ones spying on you [video]" https://news.ycombinator.com/item?id=49575176
DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.
All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.
It's a trade off I guess. I use Home Assistant to control TVs, so kinda need the access.
I could see a threat if the TV had access to the internet and could establish a TLS tunnel or similar from the mothership, and execute commands on my LAN (or IoT network as it stands), and report back. That could establish a command & control channel that could potentially orchestrate an attack on my infrastructure via the TV.
However, reporting that "network X exists and has these devices" over a different network complicates things a fair bit. In theory they could still use the TV as a command and control platform, but it would have to switch networks between my closed network and the open network in order to execute commands and report results. Not saying it's impossible, just very unlikely.
Besides, the TVs are not alone in being cut off from the internet. I have two IoT networks, one for trusted devices (AppleTVs, Sonos, and the likes), and one for untrusted devices like TVs. They run on different VLANs, and anything on the untrusted IoT network can pretty much only talk to itself (client isolation) and the gateway, and there's no internet and no open ports to any other VLAN.
I could possibly do it via HDMI CEC, but I have a couple of Sony Bravia TVs that more often than not completely ignores that, so I prefer having control over assuming it happens.
But they stopped updating it years ago, none of its apps work anymore and the only "smart" feature that still works is screen mirroring feature. The tv part itself still works great. Not a 4k oled 120Hz shiny impressive thing but the image quality is still great. What I thought was an unlucky adquisition back then turned out to be a pretty good one.
Mossad would love to know who to de-bank for criticising Israel, United Health Care would love to know who to deny coverage to based on remarks about their back pain.
I hope someone uses their free time to hack the OS and offer a clean and simple interface to make it a “dumb” TV.
But we're allowing 1000x worse things, because what, there's a vague line about it buried deep in some EULA, which means laws no longer apply?
Lets treat them the same. Raid LG, seize all of their electronics, at least in the US (other countries are encouraged to do their own raids), arrest the executives, and after they're all in jail, and digital forensics are poring over their products and servers to find what else they did, they can argue in court how actually all these crimes are legal.
It's only fair.
The choice between privacy concerns and ineptly coded network stack is tough. But that's the choice we're forced to have
If anyone could recommend any dumb TV with good panels in EU, you're more than welcome.
Just don't ever let it connect to the internet.
If internet is really required, I'd personally flood such an LG tv with fake data - add a raspberry pi to provide it with looped audio streams for the microphone, fake bluetooth devices, and so on. But it's still probably a drop in a bucket.
Disclaimer: I haven't tried any of this myself, I've just been looking into it as I am/was considering buying an LG TV.
I'd just open the TV and yank or desolder the mic out. Or use the TV as a dumb monitor -- don't connect it to WiFi or Ethernet. And use an external Kodi/AppleTV/whatever-rocks-your-viewing-boat
This is not sufficient (for some of these devices) - they will automatically connect to an unsecured hotspot.
> We value your privacy
Shares my browsing info with 1745 "partners" with no clear way to opt out (which ought to be opt-in by the way to be compliant with ePrivacy and GDPR).
Vizio TVs were caught taking screen grabs and phoning those home years ago.
Anyway, the EU's reasons seem to be entirely legitimate to me.