I've bought LG Smart TV 5 years ago, read t&c where I was supposed to grant them any data they wanted, desided to disagree and kept all network functions disabled. I was ridiculed by my friends for that. At some point, I thought - maybe I'm really crazy to do so? Who am I, a caveman, a luddite? Oh well, I'm not. Not a bad tv though, many HDMI ports!
I could buy a tv in late 2014 and happened to be the last batch of bravia tvs pre android tv. Back then I was kind of bummed out that just a few weeks after that they announced the first tvs with android tv and now i was hooked with a smart-but-not-that-smart tv with a bunch of crappy ads, an unusable web browser and a non-customizable os.
But they stopped updating it years ago, none of its apps work anymore and the only "smart" feature that still works is screen mirroring feature. The tv part itself still works great. Not a 4k oled 120Hz shiny impressive thing but the image quality is still great. What I thought was an unlucky adquisition back then turned out to be a pretty good one.
I know its important to put things down to coincidence whenever possible, but a very expensive Bang OLufsen ( I think they use LG ) TV would turn itself off at "the" most interesting split second moments during gameplay , to the point where I thought "if I am being pranked by a friend, does this TV even stream its contents?".
Much to my surprise I found out that many modern TVs do in fact come with dev mode that allow full remote streaming.
Safe to say I turned off all the "allow metrics and market/dev modes" and have been happier since.
In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
That's an easy one to put a compensation figure on but there's probably all sorts of other exploits waiting to happen.
I think the most egregious thing here is that if you don't give the TV a network connection that it will actively search for other ways to get the data back to LG such as open WIFI.
>In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
That's understating the problem. With or without AI, this should be cause enough to shut down a company or at least their specific product division.
>E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
They're going to be fine. A slap on the wrist at best.
The value of this data to the NSA, Mossad etc is probably the only thing keeping it secure.
Never in human history has a government had the means to simultaneously spy on millions of people, to use everyday private conversations to categorise them into various threats to the state, and better yet these tech companies can still sell the commercially valuable side of this to advertisers.
People could return to burning down enterprises that they find unsavory or detrimental to society, such as they did during the industrial revolution, but this is problematic in that it's violent and not something the modern person often considers as viable. A part of why people consider this unviable now is in-part due to the consequences of these surveilance technologies. It's difficult to accomplish a revolution when everyone is being spied on all the time.
> E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
My tinfoil hat believes that they've already accounted for this as the price of doing business. They will have already budgeted for the fines that they might incur, pay them off and continue as normal while people become accustomed to it.
You would think that would matter, that they’re basically violating all known PII/HIPAA/GDPR/National security standards and god knows what else, but I expect at most some class action down the line.
>this is going to be a massive business liability.
No. this is going to go "unnoticed" or at least unactioned. These are surveilance devices - compromising their value as source of surveilance is neither in the interest of industry (who are selling and buying the surveilance) or government (who are buying and acting on it). The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now. These devices bery well may soon be the only lawfully available devices in the consumer market precisely because of their surveilance capabilities. Governments are reluctanty catching up to the capabilities of digital technologies, and they're finding them more useful now than ever before. We will be burning witches again before we ever prosecute tech companies for doing bad things.
>The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now.
I'm thinking less about shame, as corporations are dead to shame, and more about proof the TV stored a record of your bank details it got from text to speech.
If that's stored as text inside the TV and you lost money because it was copied by a hacker then you have a monetary value to show loss and a trail of liability you can use to sue LG.
>I'm thinking less about shame, as corporations are dead to shame, and more about if you can prove the TV stored a record of your bank details it got from text to speech.
Then they'll get a joke fine, and continue as before. Maybe cut the price for a while, until they reintroduce it with another pretext a few years down the line.
My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet.
DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.
All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.
All of your blocking still doesn't change the fact that your LG TV is actively trying to scan your local hardware, gathering IP-addresses of devices, wi-fi names and signal strengths, creating digital finger prints of the audio and video projected on your screen, recording audio through the internal microphone, even when the TV is in standby or without an internet connection, saving the collected data locally and uploading to LG Ad Solutions as soon as the TV is connected to the internet.
And then your neighbor spins up an unprotected network or something like xfinity which they could have a deal with and it connects there and phones home anyways.
You're not wrong, but you could ask your favorite LLM to interact with the LG API's to switch the input for you. At least for my case, it was ~10 minutes of work to develop a small tray app that looks for a specific USB device and switches the TV input if it gets inserted. I don't really even touch the remote anymore
I have a rooted LG C4. Beyond blocking things at the DNS level, not accepting terms, not using AI, I wonder if there’s some existing software solution or a documented step-by-step to remove this bloatware/spyware.
Is all of them, every "smart tv" does it, even after adb, permission restricting or rooting.
Insert a (non infected) usb lamp in your tv and see the lamp turning on when your tv is off. It notifies you about the background activation activity :) Interesting to see when exactly get active (is it keywords or nearby devices or scheduled processes)? Can´t be keywords as that would mean 24/7 active and the lamp says otherwise.
This is the same behaviour as the german secret police in east germany. The difference now its for ads and by tech.
All collected data are probably ai transcribed from audio to text and is fused via data fusion to serve ads. Add collaborative filtering to find similar interests between users.
Mossad would love to know who to de-bank for criticising Israel, United Health Care would love to know who to deny coverage to based on remarks about their back pain.
I will remind everyone again that weev was raided by the FBI, arrested, and had all electronics seized, before getting a chance to defend himself in court, all for the crime of publishing emails he found on unsecured URLs he was able to guess.
But we're allowing 1000x worse things, because what, there's a vague line about it buried deep in some EULA, which means laws no longer apply?
Lets treat them the same. Raid LG, seize all of their electronics, at least in the US (other countries are encouraged to do their own raids), arrest the executives, and after they're all in jail, and digital forensics are poring over their products and servers to find what else they did, they can argue in court how actually all these crimes are legal.
the only TV I have connected to the home network (guilty, I admit), Sony OLED 65, ARP floods my network about 12-15 hours after "turning off". On a plus side, it doesn't appear to be streaming anything out: no local DNS hits, not enough outgoing traffic for any meaningful audio stream
The choice between privacy concerns and ineptly coded network stack is tough. But that's the choice we're forced to have
Why don’t you just use it as a display and have a more reputable device (e.g a mini pc or an apple tv) feeding it? I’m not forced to give my tv network access at all, since it doesn’t do anything other than display whatever the apple box outputs…
This is (mostly) the way. Samsung TV without networking configured, XBox for everything - which is problematic in its own ways but it's a known quantity. It doesn't prevent it from "helpfully" hopping on a nearby unsecured network but a) I haven't spotted one of those in a while, and b) it hasn't ever been able to get updates to change its behaviour to make it start doing that if it previously wouldn't.
At this point, best to just keep it disconnected. Just use an apple tv or similar. They sold us a spying device masqueraded as a smart TV.
If internet is really required, I'd personally flood such an LG tv with fake data - add a raspberry pi to provide it with looped audio streams for the microphone, fake bluetooth devices, and so on. But it's still probably a drop in a bucket.
So I have a tv of LG from the same period. I keep it dumb, not connected to the internet and just use an apple TV, so far it's a clean option. And it's always a good idea to have piHole up to, they usually have the block list updated with LG's and Samsungs urls.
The Gamers Nexus video explained that they will connect to nearby open SSID’s to send the data they have collected. So just not connecting it to your network may not be enough.
Fun fact: some (most?) Samsung TVs of the last ~6 years can't complete OOB setup if they're connected to a PiHoled network with the most vanilla PiHole filters
PiHole doesn't block IPs. It blocks DNS. The device have at least three ways to bypass PiHole: use external DNS directly, or pin the phone-home servers' IP addresses, or use some other protocols to carry IP resolution.
I'd just open the TV and yank or desolder the mic out. Or use the TV as a dumb monitor -- don't connect it to WiFi or Ethernet. And use an external Kodi/AppleTV/whatever-rocks-your-viewing-boat
Shares my browsing info with 1745 "partners" with no clear way to opt out (which ought to be opt-in by the way to be compliant with ePrivacy and GDPR).
I've bought LG Smart TV 5 years ago, read t&c where I was supposed to grant them any data they wanted, desided to disagree and kept all network functions disabled. I was ridiculed by my friends for that. At some point, I thought - maybe I'm really crazy to do so? Who am I, a caveman, a luddite? Oh well, I'm not. Not a bad tv though, many HDMI ports!
I could buy a tv in late 2014 and happened to be the last batch of bravia tvs pre android tv. Back then I was kind of bummed out that just a few weeks after that they announced the first tvs with android tv and now i was hooked with a smart-but-not-that-smart tv with a bunch of crappy ads, an unusable web browser and a non-customizable os.
But they stopped updating it years ago, none of its apps work anymore and the only "smart" feature that still works is screen mirroring feature. The tv part itself still works great. Not a 4k oled 120Hz shiny impressive thing but the image quality is still great. What I thought was an unlucky adquisition back then turned out to be a pretty good one.
I know its important to put things down to coincidence whenever possible, but a very expensive Bang OLufsen ( I think they use LG ) TV would turn itself off at "the" most interesting split second moments during gameplay , to the point where I thought "if I am being pranked by a friend, does this TV even stream its contents?".
Much to my surprise I found out that many modern TVs do in fact come with dev mode that allow full remote streaming.
Safe to say I turned off all the "allow metrics and market/dev modes" and have been happier since.
Did it ever turn itself off after you made those settings changes?
This is automatic liability in California and the EU, correct? Does Illinois consider one’s voice pattern to be a biometric? If so, there, too.
In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
That's an easy one to put a compensation figure on but there's probably all sorts of other exploits waiting to happen.
I think the most egregious thing here is that if you don't give the TV a network connection that it will actively search for other ways to get the data back to LG such as open WIFI.
>In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
That's understating the problem. With or without AI, this should be cause enough to shut down a company or at least their specific product division.
>E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
They're going to be fine. A slap on the wrist at best.
The value of this data to the NSA, Mossad etc is probably the only thing keeping it secure.
Never in human history has a government had the means to simultaneously spy on millions of people, to use everyday private conversations to categorise them into various threats to the state, and better yet these tech companies can still sell the commercially valuable side of this to advertisers.
Advertisers are the reason we have this problem. The only way to stop them is legislation.
People could return to burning down enterprises that they find unsavory or detrimental to society, such as they did during the industrial revolution, but this is problematic in that it's violent and not something the modern person often considers as viable. A part of why people consider this unviable now is in-part due to the consequences of these surveilance technologies. It's difficult to accomplish a revolution when everyone is being spied on all the time.
“Citizens will be on their best behavior because we are constantly recording and reporting everything that’s going on”
- Larry Ellison (Oracle Corporation)
As much as the problem is advertising the government allows it because the government buys the data!
Based on historical records, I would say not much will happen to these companies. Interested to see what the EU will do though
> E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
My tinfoil hat believes that they've already accounted for this as the price of doing business. They will have already budgeted for the fines that they might incur, pay them off and continue as normal while people become accustomed to it.
You would think that would matter, that they’re basically violating all known PII/HIPAA/GDPR/National security standards and god knows what else, but I expect at most some class action down the line.
>this is going to be a massive business liability.
No. this is going to go "unnoticed" or at least unactioned. These are surveilance devices - compromising their value as source of surveilance is neither in the interest of industry (who are selling and buying the surveilance) or government (who are buying and acting on it). The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now. These devices bery well may soon be the only lawfully available devices in the consumer market precisely because of their surveilance capabilities. Governments are reluctanty catching up to the capabilities of digital technologies, and they're finding them more useful now than ever before. We will be burning witches again before we ever prosecute tech companies for doing bad things.
>The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now.
Spot on.
I'm thinking less about shame, as corporations are dead to shame, and more about proof the TV stored a record of your bank details it got from text to speech.
If that's stored as text inside the TV and you lost money because it was copied by a hacker then you have a monetary value to show loss and a trail of liability you can use to sue LG.
>I'm thinking less about shame, as corporations are dead to shame, and more about if you can prove the TV stored a record of your bank details it got from text to speech.
Then they'll get a joke fine, and continue as before. Maybe cut the price for a while, until they reintroduce it with another pretext a few years down the line.
Ongoing discussions:
"216M Spy TVs – The LG Smart TV Problem [video]" https://news.ycombinator.com/item?id=49592375
"LG TVs aren't the only ones spying on you [video]" https://news.ycombinator.com/item?id=49575176
My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet.
DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.
All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.
All of your blocking still doesn't change the fact that your LG TV is actively trying to scan your local hardware, gathering IP-addresses of devices, wi-fi names and signal strengths, creating digital finger prints of the audio and video projected on your screen, recording audio through the internal microphone, even when the TV is in standby or without an internet connection, saving the collected data locally and uploading to LG Ad Solutions as soon as the TV is connected to the internet.
Do transparent faraday cages exist?
If you're streaming via AppleTV, why do you need to give the TV itself access to the network?
And then your neighbor spins up an unprotected network or something like xfinity which they could have a deal with and it connects there and phones home anyways.
I absolutely loathe my LG smart TV. Just switching to another input requires 3 button press.
I hope someone uses their free time to hack the OS and offer a clean and simple interface to make it a “dumb” TV.
You're not wrong, but you could ask your favorite LLM to interact with the LG API's to switch the input for you. At least for my case, it was ~10 minutes of work to develop a small tray app that looks for a specific USB device and switches the TV input if it gets inserted. I don't really even touch the remote anymore
I have a rooted LG C4. Beyond blocking things at the DNS level, not accepting terms, not using AI, I wonder if there’s some existing software solution or a documented step-by-step to remove this bloatware/spyware.
Is all of them, every "smart tv" does it, even after adb, permission restricting or rooting. Insert a (non infected) usb lamp in your tv and see the lamp turning on when your tv is off. It notifies you about the background activation activity :) Interesting to see when exactly get active (is it keywords or nearby devices or scheduled processes)? Can´t be keywords as that would mean 24/7 active and the lamp says otherwise.
Wait, do LG Webos TVs have microphones in the TV and/or in the remote? I am aware of the latter only.
This is the same behaviour as the german secret police in east germany. The difference now its for ads and by tech. All collected data are probably ai transcribed from audio to text and is fused via data fusion to serve ads. Add collaborative filtering to find similar interests between users.
how do you know it is for ads? how do you know it will always be only for ads if it now is?
Why not both?
Mossad would love to know who to de-bank for criticising Israel, United Health Care would love to know who to deny coverage to based on remarks about their back pain.
that's the fear, but it would be reasonable to say that ads are what has gotten us to this point
I will remind everyone again that weev was raided by the FBI, arrested, and had all electronics seized, before getting a chance to defend himself in court, all for the crime of publishing emails he found on unsecured URLs he was able to guess.
But we're allowing 1000x worse things, because what, there's a vague line about it buried deep in some EULA, which means laws no longer apply?
Lets treat them the same. Raid LG, seize all of their electronics, at least in the US (other countries are encouraged to do their own raids), arrest the executives, and after they're all in jail, and digital forensics are poring over their products and servers to find what else they did, they can argue in court how actually all these crimes are legal.
It's only fair.
They just won't stop, will they?
They will once they've killed television and they'll get back to the net.
Almost 13 years ago: https://news.ycombinator.com/item?id=6759426
the only TV I have connected to the home network (guilty, I admit), Sony OLED 65, ARP floods my network about 12-15 hours after "turning off". On a plus side, it doesn't appear to be streaming anything out: no local DNS hits, not enough outgoing traffic for any meaningful audio stream
The choice between privacy concerns and ineptly coded network stack is tough. But that's the choice we're forced to have
Why don’t you just use it as a display and have a more reputable device (e.g a mini pc or an apple tv) feeding it? I’m not forced to give my tv network access at all, since it doesn’t do anything other than display whatever the apple box outputs…
This is (mostly) the way. Samsung TV without networking configured, XBox for everything - which is problematic in its own ways but it's a known quantity. It doesn't prevent it from "helpfully" hopping on a nearby unsecured network but a) I haven't spotted one of those in a while, and b) it hasn't ever been able to get updates to change its behaviour to make it start doing that if it previously wouldn't.
Just don't buy a smart TV. Buy a good "dumb" TV (or just get a good large monitor), then hook it up to a set top box (with TV capabilities as needed).
If you want a good panel, you're going to have to buy a smart TV.
Just don't ever let it connect to the internet.
As an owner of a (2020?) LG WebOS TV, to what degree can I fight this? Any point in trying Pihole with targeted blocking of certain IPs?
At this point, best to just keep it disconnected. Just use an apple tv or similar. They sold us a spying device masqueraded as a smart TV.
If internet is really required, I'd personally flood such an LG tv with fake data - add a raspberry pi to provide it with looped audio streams for the microphone, fake bluetooth devices, and so on. But it's still probably a drop in a bucket.
So I have a tv of LG from the same period. I keep it dumb, not connected to the internet and just use an apple TV, so far it's a clean option. And it's always a good idea to have piHole up to, they usually have the block list updated with LG's and Samsungs urls.
The Gamers Nexus video explained that they will connect to nearby open SSID’s to send the data they have collected. So just not connecting it to your network may not be enough.
https://en.wikipedia.org/wiki/Capital_punishment
Okay, that is nasty.
Fun fact: some (most?) Samsung TVs of the last ~6 years can't complete OOB setup if they're connected to a PiHoled network with the most vanilla PiHole filters
You can (hopefully) root your TV: https://e.nya.je/getroot/ and then follow a guide like this to disable all the snooping: https://forum.level1techs.com/t/lg-tv-block-mini-how-to/2551...
Disclaimer: I haven't tried any of this myself, I've just been looking into it as I am/was considering buying an LG TV.
PiHole doesn't block IPs. It blocks DNS. The device have at least three ways to bypass PiHole: use external DNS directly, or pin the phone-home servers' IP addresses, or use some other protocols to carry IP resolution.
I'd just open the TV and yank or desolder the mic out. Or use the TV as a dumb monitor -- don't connect it to WiFi or Ethernet. And use an external Kodi/AppleTV/whatever-rocks-your-viewing-boat
> don't connect it to WiFi or Ethernet
This is not sufficient (for some of these devices) - they will automatically connect to an unsecured hotspot.
well, if that was the case with my TV and/or if I was worried, I've got a soldering iron and I'm not afraid to use it
I bought Apple TV many years ago and haven’t plugged tv into internet since.
I mean, I’m not disagreeing, but it’s a bit rich for a site that logs data to 1,745 “partners” to be complaining too much.
notebookcheck.net:
> We value your privacy
Shares my browsing info with 1745 "partners" with no clear way to opt out (which ought to be opt-in by the way to be compliant with ePrivacy and GDPR).
"We value your privacy" → "Your private data is valuable" (I guess)
Clearly the penalties for this are not high enough, because the scumbags keep doing it.
Vizio TVs were caught taking screen grabs and phoning those home years ago.
GDPR compliance lawsuitssss in 3...
Somehow the EU only appears to target big wealthy service providers. I wonder why.
I really hope they do and slap them with the 4% of their total global annual turnover.