cross-posted from: https://lemmy.world/post/51634640
A new Gamers Nexus investigation found a retail LG TV actively scanning the local network for phones, laptops, smartwatches and other connected devices, while also capturing microphone audio when the screen appeared to be in standby. The investigation found voice data being stored locally even after the TV was disconnected from the network, with the queued data uploaded once connectivity returned. Researchers also uncovered webOS vulnerabilities that could potentially turn the television into a remotely controlled surveillance device. The really unsettling part isn’t just the advertising angle. It’s the fact that a consumer television can sit inside your trusted network, enumerate other devices, access a microphone, store collected data locally and communicate with external infrastructure. Put that same device in a corporate office, hospital, hotel or conference room and the security implications become considerably more serious. I went through the investigation in detail, including the network scanning, microphone behavior, ACR, webOS attack surface, offline data collection and practical mitigations
Fuck LG, this is creepy AF
It’s hard to find a dumb TV.
Monitors and projectors are going the same way. Not connecting them might not be enough.Time to learn how to use a soldering iron.
modern ones are soldered directly to the board and integrate bluetooth into the same chip and removing that chip form the board could remove the ability to use bluetooth functions and the remote, however!!! most have usb ports!!! lets make new operating systems and fucking delete their file system, load a new os that lacks the abilities these manufactures have.
The hardware is whatever but if we remove the file systems that its preloaded with it won’t be able to load any of its preinstalled shit. If we mod the operating system we can mod some of the shit the hardware is capable of doing through the software and coding. Kinda like how windows 11 is known for lowering ram speed.
Why are you concerned with the USB ports?
I think he’s suggesting said OS could be installed using them.
Thanks, threw me for a loop when they recommended trying to unsolder a chip from the sbc and expecting it to still work as a tv at all.
It is like trying to find a new car that doesn’t have one of those fucking screens instead of a real console.
I keep my tv dumb by not connecting it to a network.
deleted by creator
I don’t care that companies thought they’d get away with this, the problem is have are the people buying this shit! This should’ve been enough to get people to just refuse to buy it but no.
And the bigger problem isn’t what we know they can do, you have to think about what it ‘could’ do.
Even if you never connect this stuff to the internet, they could still track all this stuff locally. Once that happens, which no doubt it will if not already, what happens if suddenly you get arrested for something, they confiscate the TV, download all the stuff tracked, and oops, something even more incriminating… maybe you watched an illiegal movie on jellyfin! 😲
Look at all the “People will never let it happen” that has happened pretty much unchallenged… you’ll have no privacy, and you’ll all be paying for it!
The problem is not that people are buying this willingly, it’s because they don’t know. If you present them two rougly similar options, but one of them is a spying machine, people will choose the other one. This stuff should not be legal in the first place.
The problem’s that what’s presented is a cheap machine vs an expensive machine. Guess which one spies on you?
That’s true, but the law should be the first line of defence against practices like this - you can’t expect every person to do thorough research on every appliance they buy.
Yeah, caveat emptor worked in an era where there were a lot of sellers and not that many ways to screw over customers, especially as most people weren’t buying a wide range of products. I should be able to assume that my appliances aren’t working against me, especially when it’s becoming more difficult to purchase ones that don’t
That’s not true at all. The LG OLED (C5, G5) are very expensive. I paid over 1300$ for my C4 last year and just learned that LG is pulling this shit.
The majority of people do not realize how much information is being recorded and what it’s used for. If there was an easy way to track down how a telemarketer got your information, a lot more people would freak out and demand change.
The majority of people do not
realizecare how much information is being recorded and what it’s used for.
What exactly is the alternative? Every tv manufacturer is doing this. Buying a commercial display isn’t the answer.
Scepter.
(I dunno if they’re doing it yet or not but I bought a dumb TV and a dumb monitor from them and I really hope they stay dumb)
… Well great, now I have to check whether my television has a goddamn microphone for some reason. I didn’t think to check because it’s a television.
Never connected it to the Wifi though.
Doesn’t anything with a speaker have an inherent shitty microphone?
Does it have voice command capability?
anybody know when this started? i don’t have my tv connected to the network, and have not updated the firmware in 2 r 3 years.
There’s no “might” here. It’s why high-end TVs are cheap.
Remember: all that is done simply to give LG executives, like, a few dozen bucks over the device’s lifetime.
Customer privacy means nothing at all to them. They sell it for pocket change.
Others do too
I was radicalized when a Roku TV told me I needed to be online to change an input name from HDMI1 to Xbox. Motherfucker WHAT.
Is this anything a VLAN and Pihole can’t fix?
Edit: looks kind of impossible to prevent, if it can access an open Wi-Fi nearby.
Possible that they are piggy backing on other hidden networks. I remember there was a whole thing with Samsung years ago with their stuff doing something like that, and there are a few patents around that propose hidden networks from the “internet of things” days.
I just don’t want to even truck with this nonsense, where the fuck is the line before we just stop using these things? I know there must not be a line, since we are talking about circumventing our shit spying on us like it is normal.
All of this needs to be illegal, but piggybacking especially does. Circumventing the will of the end user (aka the person who should be considered the owner) as for what the product in their possession, home, and use does shouldn’t be tolerated
Is this anything a VLAN and Pihole can’t fix?
You can simply put it on a guest WiFi network that cannot see any other networks and just put a password on your main network, it is not that difficult.
That’s what I do at home with a Ubiquiti setup. Seperate network with client isolation enabled.
For now the only known thing to do that works is for it to never to be connected to any network.
Also if a smart tv was connected to the WiFi there is a possibility it won’t forget that until factory reset.
So get power strips and turn them off when you’re not using the TV.
Also keep them off wifi/network and you should be good unless they’re smart enough to try to connect to any open network they can find like some sort of malware
unless they’re smart enough to try to connect to any open network they can find like some sort of malware
Uhhhhhhh, bad news there. Many companies have been found to have their stuff make hidden networks and share info these days. I am sure you could figure out a work around if you are savvy enough, but the normal dood? Fucked and pretending this is normal.
Which is why I said just get a power strip. Can’t hack a TV that’s not plugged in.
Many? I heard a rumor about one Samsung TV connecting to an open Wi-Fi network, but I’ve never heard of many companies creating hidden networks.
Yeah maybe there’s way to make a file explorer for them. Maybe there’s ways to jailbreak them. We focus on phones a lot, webos was on the hp bought out palm phones back in the 2010’s.
We find out the operating systems, we jailbreak them and completely remove their programming and then, in-turn we can mess with hardware settings.
So let’s start making a TV Linux that doesn’t suck or make an Ubuntu TV version or a KDE TV version.
They can’t force people into using their OSes forever. The only thing I know is it’s like Pandoras battery trying to disable the wifi from the hardware.
Probably safe to assume every other smart TV brand is doing the same, but just no one has gone to the effort to check…
Is there a way to direct all the iffy traffic from the tv to a pi hole?
Could connect the tv to the guest wifi network which would prevent it from accessing your local network. Plug in an android tv box of some variety and connect that to the network and you can cut the tv off f4om internet entirely.
If you set the pihole as your primary DNS on your router then all network traffic goes that way anyway. Set up google as a secondary in case your pihole goes down. Or configure a second pi hole for resilience and set that as the backup.
Fuck that, become ungovernable. If the pihole is down, the tv is down.
Build your own router and
Redirect all port 53 to your pihole
Block port 853 on that vlan
Block these ips on that vlan
https://github.com/dibdot/DoH-IP-blocklistsI had a raspberry pi working as a router but when my provider gave me a zyxel router i didnt need it anymore as its super customisable.
Will i need to go back to my openwrt router to get this working? Since its saying github actions update the list?
In opnsense, fetching an alias list file is native
https://docs.opnsense.org/manual/aliases.htmlZyxel gear is legit as i understand it, but i don’t know their system.
The GN investigation discovered that LG makes the TVs mesh with each other as well. So even if you don’t connect your LG to the internet, it can connect with other LG devices in the neighbourhood and exfiltrate data that way.
Oh! Thats sneaky.
The investors must have their data
FYI guest network doesn’t separate traffic from normal network. You need different vlan for that.
my guest network is in a different vlan by default.
Afaik thats standard for guest networks. They have internet access but not local network access. Otherwise whats the point in them?
Sadly that’s not how they are setup on many consumer routers.
They just act as another ssid that offer easy limits/ controls instead of a full vlan/ isolation
Wow. I might only be a little wise to this stuff but the average consumer is getting screwed.
I wonder if I can disable it if I rooted webOS on my parents’ TV
This is why TVs cost close to nothing these days. If you’re not the customer, you’re the product.
If I had a LG the on thing it would spy on would be the other untrusted shit I have on the vlan I let them use.





