Here are LG's contract terms for appliances.[1] They are awful.
Not only can they listen in. You have a contractual requirement to tell everyone in range of an appliance that they may be eavesdropped upon.
CONSENT REQUIREMENT: You acknowledge and agree that it is your sole responsibility to obtain all necessary consents from any third parties whose voices may be captured by the Product and to notify household members and guests that their voices may be captured and processed, in compliance with applicable wiretapping, eavesdropping, and privacy laws. If anyone does not consent, you should disable the microphone or voice features in the settings. LGE disclaims any liability for your failure to obtain such consent or provide such notification.
What's absurd is that this doesn't void the terms by default. There should be limits to what companies can put in their ToS beyond which those terms aren't enforceable.
Is that actually for smart tvs? The first paragraph includes "the products you may access or otherwise connect to via the ThinQ mobile application (not including Smart TVs)" and "These Terms of Use do not apply to any other LG products or services, including Smart Media Products."
[EDIT] Smart Media products terms appear to be at https://us.lgappstv.com/main/terms (for comparison here's UK: https://gb.lgappstv.com/main/terms, there are some other EU versions available for e.g. Germany but I imagine UK terms should be quite close and more accessible for most of readers)
> 8. I understand that LGE will retain the collected Voice Information for 6 months to fulfil the purposes for which we collected it, and after this period, it will be deleted or anonymized, depending on the case.
> 9. I understand that this Smart Media Product is a household device. If this Smart Media Product will be used by more than one person, I represent that, in addition to agreeing to this Agreement, that I have obtained consent from all other members of my household whose information may be collected through this Smart Media Product and am providing consent on their behalf.
These (and other TOS agreements) fall under the category of "adhesion contracts".
Because the buyer has no real ability to negotiate, any ambiguity is resolved in their favor. A judge can also strike provisions that a reasonable buyer would not expect, or that are unconscionable. So it's up to the judge's judgment.
tempted to go into my nearest big box electronics store and then sue them when they don't tell me the LG tv's they have on display are eavesdropping on me.
Can you actually even turn and keep the microphone off or does it toggle itself back on like Apple's Wifi and Bluetooth one-touch toggle off for now buttons?
> The law has been unable to keep up with tech changes.
Nah, for the most part the law has been unable to keep up with (or choose to oppose) corporate power, and new ways it's being used. Usually there's no magic quantum doohickey which demands fundamentally new legal theory.
I've bought an LG Smart TV 5 years ago, read t&c where I was supposed to grant them any data they wanted, decided to disagree and kept all network functions disabled. I was ridiculed by my friends for that. At some point, I thought - maybe I'm really crazy to do so? Who am I, a caveman, a luddite? Oh well, I'm not. Not a bad tv though, many HDMI ports!
I have a similar reaction from folks when I don't trust services/devices. Most telling moment was when I refused to upload my license to LinkedIn because I lost 2FA (token on phone, phone destroyed). Microsoft assured me they would "delete the license as soon as it was verified". I've written too many software systems for too many companies, and I do not believe them.
That's from 2024, but we just had a larger breach with IDScan this week.
Sorry for the digression, but the common thread is how much to trust these companies, and my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want. Some paranoia is warranted, I think.
> my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want
Honestly, it's not even that extreme in most cases. I think it's usually not malice, it's incompetence.
That's why I don't trust big companies with my data. Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.
> Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.
The CEO is responsible for what their company does. If a major breach can occur through the oversight or "incompetence" of one worker, the CEO has already failed, whether through negligence or malice.
Pardon my French but bull-fucking-shit! A CEO _should_ take responsibility for what their subordinates do. It's preposterous to simple throw up our arms and say "oh well, some employees were sloppy so we lost some 100 million user IDs and other sensitive information that we promised not to store but we lied. Oopsie, silly me, pardon my wee incompetence tee-hee". No no no NO NO!
At some level, and certainly at the level where you get paychecks of 10 million a year for the "huge responsibility you are bearing", then incompetence IS malice!
Uhh. I think you misread my comment pretty badly here. I am not making excuses for anyone.
I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.
Both are inexcusable, but one is more common/likely than the other.
You can certainly link them together and yes leaders should be held responsible no matter what, but from my perspective as the user who had his data leaked, it doesn't really matter how/why it happened, does it?
1. Interaction with Meta is virtually mandatory in many places in the world. Try opting out of Meta when your kid's daycare or your building's group chat is on whatsapp.
2. It doesn't really matter if you opt out, because _other people around you don't_: they take pictures in which you show, they tag you, they talk about you, they send you links, etc. Which means they (Meta) build a shadow profile of you anyway.
The "personal responsibility angle" is pure fiction.
My building’s group is on FB. I’ve managed without access for over a decade.
I live a somewhat normal adult life and manage without having anything to do with Meta ¯\_(ツ)_/¯ I probably miss out on some things, but I don’t notice.
All my friends just contact me through other sources.
If you have kids, it’s more difficult - I can acknowledge that.
You’re assuming that my primary concern is my privacy rather than my sanity. I don’t understand how anyone can seek out a non-stop feed of the sort of people who routinely post on FB. I’ve seen exactly what the doom scroll does to people without them realizing it.
So yeah if a business requires me to have an account I’ll find a different business to patronize. Frankly if you’re expecting someone other than you to take responsibility for the media you consume, that’s a problem.
It will be when enough people elect enough politicians who take action against this weaponized incompetence and strip-mining of the peoples' assets.
Or, if that does not happen, when enough people rise up in revolution and take the compensation for themselves.
Or, never.
If enough people vote enough or revolt enough, they cannot be stopped. But the incentives for too few people rising up are too costly. They work hard to keep the equilibrium in that balance.
It's not about being a luddite. In many respects I consider it the opposite. It's engaging with technology in a way that demands standards of behaviour and performance.
I don't want the new thing because it is the new thing. I want new things that are better.
People accept abusive technology because they consider that's just the way it is with this new thing. It's a failure to understand what should be considered unacceptable.
They do. But the apartment complex gets a nice little kickback, especially since an app for unlocking your front door is one that has at least a plausible argument for having your location, which means a whole bunch of location data that can be mined/sold/both.
My apartment complex came to install keypads and centrally managed smart thermostats and I would not let them.
Thankfully my lease was old enough that I was able to argue against it. I don’t want a 3rd party company tracking my habits, and I don’t want some manager boiling my pets alive while I’m gone because they decided they think our AC is set too low.
You got lucky. If you've got an apartment in, say, a healthcare facility, they'll install those thermostats and whatnot. Usually the neighbours are clueless about technology so complaining doesn't get very far at all.
It's even worse if some staff wrote paranoid in your file, 'cause they'll argue it's good for "exposure".
Nah, you're not crazy. I'm also someone who actually reads terms documents, because I find that they're often the only thing that will be truthful about a company's intentions.
And keeping it completely disconnected from the internet should be the default, in my opinion.
There is absolutely no reason to read those contracts any more. As Louis Rossman keeps pointing out, most of them now include the ability for them to change terms at any time. That's basically the null contract.
Since the legal system has once again failed to protect users from corporations, it's up to users to use technical means for self defense.
Depends on jurisdiction, just because someone wrote something in a contract doesn’t mean it’s binding.
In Poland/EU we have an (ever growing) list of forbidden clauses that even when written and signed by consumer are null and void. And I think these can be enacted retroactively - when corporations invent new shady clauses, government steps in and tells them these are invalid.
This helps to even out the consumer-corporation field.
> we have an (ever growing) list of forbidden clauses that even when written and signed by consumer are null and void
I'm pretty sure that's true almost everywhere. Law beats contract. The real question is how strong the laws are. In the US not so much because of small government and stuff, especially in red states.
The law matters very little when enforcing it in court often means a multiyear lawsuit against an opponent which employs an army of attorneys, has effectively unlimited amounts of money, will likely cost you ruinious sums of money, and for an outcome that's far from guaranteed.
You can do that too. You can show up, represent yourself and pay a few hundred dollar court fee, while the big company has to waste hundreds of thousands of dollars to defend themselves from you. You'll probably lose the case if you don't have a lawyer, but in a place like the US, you don't have to pay the other side's legal fees unless the case is frivolous (which it won't be).
>The law matters very little when enforcing it in court often means a multiyear lawsuit against an opponent which employs an army of attorneys, has effectively unlimited amounts of money, will likely cost you ruinious sums of money, and for an outcome that's far from guaranteed.
Or when you can't even enforce anything in court as you've already given up your right to spend all your money suing, as binding arbitration is the required and only mechanism to "resolve disputes." To make it extra fair, the corporation pays the arbitration firm for their "objective" decisions and not you.
Has it actually happened that someone went to court and the court told them no, you have to do binding arbitration? Or is it just something they put in the contract to scare you? Has anyone argued they didn't actually agree to what the country thinks they agreed to?
In the Gamer's Nexus video, he gets drunk before accepting the terms so that it isn't legal consent. A drunk person can't enter a contract.
The judiciary is a branch of government. But more crucially, some countries have better consumer protection agencies, eliminating the need for people to go through costly court battles for common sense stuff.
Interestingly, in Brazil and I'm sure in some other legislations, those contracts are essentially void because there's a presumption the average person does not have the time, patience, or ability to understand every clause—so they are by definition unable to agree to their terms.
I'd love to have a similar standard applied in the US but I'm not holding my breath.
Which doesnt work. LG tvs will scan for availible networks. Someone setting up a new router within range briefly disables encryption and "your" tv will jump on that network and transmit all the stored data.
I guess you could remove the wifi antenna, or otherwise brick the wifi reception ability (faraday cage, lead block, etc). Or - just boycott LG. I'll never buy any of that corporate espionage nonsense, ever.
Also: the US intelligence agencies used Echelon ages ago to monitor what vast swaths of innocent people were up to. I think it's sensible to presume they've got their hooks into these devices too.
A technical solution would presumably spoof the spaff but with E2EE and DoH is it possible? So then what, hacking firmware? I guess then TVs get a hard lifespan limit.
I never understood why any of the smartness had to be built into the TV in the first place. Sure, it's useful for the first year, and then the seriously underpowered hardware they installed into it will have trouble with just about anything.
I bought a Philips Ambilight OLED TV probably over 8 years now. Brilliant tv, great quality, I still see no reason to replace it at all. But its built in AndroidTV is garbage.
Because it’s extremely profitable for them to serve ads and sell PI. Kind of like how the airline industry makes more money off credit card shenanigans than actual plane tickets.
It did. We are currently on the fourth or more reinvention of capitalism. It's like ethernet - every time networking technology changes, the new one is called the same thing as the old one. The current fiber-optic switched Ethernet has absolutely nothing in common with the original vampire-tapped coax with media attachment units clamped onto the cable and a serial-port-looking AUI interface running down from the ceiling to the computer. Same for capitalism.
> Capitalism cannot survive when products last a lifetime.
This is totally backwards; capitalism would do fine in such an environment (in the same way that evolution does fine in an environment where organisms live more than just a few seconds; the whole reason we have the notion of a "lifetime" is that our germ line comes from a long line of ancestral DNA that made organisms that outlasted their competition.)
Individual companies might have to hustle to innovate or die, but that too is good for capitalism.
Both capitalism and evolution depend on the fact that over time, on average, less fit organisms/organizations are displaced by better alternatives. You may not like that, but down-voting anyone who points it out doesn't make it any less true.
> I find that they're often the only thing that will be truthful about a company's intentions.
Really? Many years ago, I had to physically sign a license with Microsoft to obtain some software. The license was not consistent with the license included with the software. Both licenses effectively said they were the real license and that any other agreement you made with Microsoft was not valid.
I don't think there was any nefarious intent. It was likely to avoid a situation where Microsoft employees offered terms that were not approved of by the company. Still, it goes to show that it can be awfully difficult to judge the intent of a company.
Only good until the device starts using a neighbor's LG TV as access point, without telling you, for the sole purpose of upgrading itself and sending this "telemetry".
An Apple airtag probably doesn't but it is apparently possible to send some data at a very low rate (the article in [1] says a few bits per hour) over the find my network [2]
Yeah and my worry is, TVs like this can use sidewalk to connect to when they are not provided with internet access by the user (either but plugging into ethernet or connecting WiFi). Leaving the TV with an always-available exfiltration channel for it's espionage of the user's viewing habits.
This is a really bad thing for those of us who until now have just not connected our 'smart' shit to the internet.
Where I live in the EU they don't do sidewalk otherwise I'd have to look at ways to fight it (disassociate connections or DDoS the devices providing sidewalk routing)
We replaced our old TV recently with an LG and are really liking it. We do not let it on our network though and keep networking functionality disabled. It's basically a monitor for our Kubuntu Linux laptop sitting behind it. We stream with Chrome and use a mouse and the TV remote for audio. Once in a while we actually watch something on TV itself too. It'd be nice I guess if the built in TV app had DVR but if it does; I couldn't figure out how to make it work. No great loss there.
I'm still nervously holding my breath for the first disclosure that a TV manufacturer is using Amazon's distributed Sidewalk Network (or perhaps mobile vehicles, cell-SIMs, LoRa) to remotely gather all that viewing data they've subsidized into your artificially-low TV purchase price .
This exactly. Surely some sort of IoT mesh networking will allow exfiltration of data even without having configured your own device.
I'm hopeful that there will be sufficient distrust that "jailbreaking" or "rooting" TV controller boards will be turnkey enough to move to something like OpenWrt or GrapheneOS but for TVs.
I'll bet there is already a manufacturer whose TVs can all communicate intratelevisually (non-standard proprietary frequencies) – and then, if even one of them is online... they're all relaying within their private intra-TV spyware meshnets to their various relays.
----
In unrelated news, my 2012 Sony Bravia is still fantastic, even if not for (4K) high-refresh games (the image quality remains fantastic for casual usage).
"Watch this two hour long video" is not a particularly useful reply. If you think the TV can exfiltrate your data without an internet connection then you should be able to explain how it could do that in your own words.
Just because you didn't allow it on your local WiFi doesn't mean it did not connect to the Internet. Your neighbors might have a guest WiFi it can use. Or maybe it has a built-in cell modem. Your data is valuable, there's reason to put effort into getting it.
Using internet access doesn't seem to be illegal. If there's no password you can't even argue it was protected. Residential proxies are legal too (as they should be - fuck cloudflare).
Xfinity (aka Comcast) routers broadcast a separate network for Comcast subscribers do use from their phone. I don't think it's unreasonable to think that Comcast and TV manufacturer's could have an agreement that would allow TVs to connect.
They can just start a capture, record to RAM / storage, and retrieve it later when it is reconnected to the network.
Otherwise if it's disconnected, it is still hard to exfiltrate the data somewhere.
Maybe they could get creative via Bluetooth, but then you would need a cooperating device in proximity of the device.
> This. Why would you even connect TV to the network?
I happen to have a NAS with family pictures I like to display. I can (and do) firewall that thing, but then you hit other issues like the apps you need to show pictures and movies in the first place not to install/run.
I've yet to hear of a reasonable recipe to isolate and secure such connected TVs. And don't get me started on Chromecast or other Android dongles, I've no reason to expect better treatment from Google. Some open source hacked-together box, then?
The better Roku hardware I would say is a second best - you can block the as servers fairly easily and then you do have to disable all the crap on the homescreen.
I turn on the device, the app in the upper left is selected and showing some content from that.
The device sits idle, I get drone footage of landscapes.
If I accidentally bump the wrong button on the remote and get sent into the Apple TV (streaming service) app, sure it advertises producte, but in general there are no ads.
In comparison, Google TV's homescreen is giant ads for content on services I don't subscribe to, Roku is at least as bad, Amazon is worse, and Samsung and LG......oof.
The shield is vastly superior to the Apple TV. You aren't trapped in Apples wall garden and can install any apps on it. Android TV comes with an awful launcher, but that is easily replaced. There's no sponsor block on Apple TV and there never will be.
No, it's not. Let's start with the disclaimer that I work for Google, not the Android TV team, all words my own, etc.
The Shield at launch was an amazing product - premium UX and hardware, premium price point. Google changed the experience to an ad-loaded mess without providing an opt out for those who had spent hundreds of dollars on the Shield.
I was dogfooder, a huge advocate of the product, and someone who had convinced others to buy the Shield and Android TV devices. That UX revamp and how the team treated their customers (internal and external) turned me off the product for life. I tried the various competitors (XBox, Roku, Amazon) before landing on Apple TV. I now own two Apple TV devices - both of which are still getting updates many years after I bought them - and will continue using them for as long as the product line is maintained.
People in this thread have talked about Apple's clean beautiful ad-free UX, but the apps themselves are far better. Apple sets customer-friendly App Store requirements *and enforces them*. That means:
* The back button always works. It will bring you back to the home page of the app and then to the system launcher. It will not get stuck in an endless loop of "are you sure you want to quit?" and just dismissing that dialog like multiple Android apps do
* No loud obtrusive sounds on app startup (YouTube, Netflix)
* The apps are first-class priorities for developers. Circa 2019, the Paramount+ app was an inconsistent mess where subtitles were broken on some platforms. The Plex app wouldn't transcode certain formats on the XBox, and so on. None of these issues are a problem on Apple TV. Not every app is perfect (Dropout, I love your content, but your app is awful), but none of them are worse than on any competing platform.
Apple TV is a truly incredible product and ecosystem and one that feels like a joy to use. That's not the case for Android TV (now Google TV, I think?) even with a custom launcher.
You can also use the VLC app on an Apple TV to have a free and slightly janky media server. Just drag and drop files through any browser on a computer.
You can always just connect your laptop (or some spare laptop) to the TV via HDMI. Not sure why you’d need to “hack together” something. A dedicated HTPC is nicer if you want to use IR remotes and the like.
Yeah, perhaps "hack together" is unnecessarily dismissive, but the experience to match is that of a single peripheral to control everything. The other area I have no interest expanding my knowledge into is the minefield of codecs, HDMI cables, GPU and drivers combos to have something outputting HDR and whatever Dolby's flavour of the month proprietary invention I inevitably come across.
Obviously, as an advertising company, Google should have your utmost scrutiny. But as far as I know, their TV boxes don't ACR your content. If they were the only two options, sticking with your smart TV software instead of using a Google TV box would be a privacy mistake.
Typically you will get sambatv or such installed, and technicians for whatever reason tend to click accept/approve during installations. Happened to me n my Google TV thing
What technicians? When my TV was delivered they pretty much just unboxed it and set it on the floor, not even being willing to help mount it, let alone plugging it in.
GBM/DRM Kodi supports HDR video on the Orange Pi 5 family. You can grab whatever audio from HDMI or plug whatever in the usb port, the only advantage of this Vero is the optical out.
I've just used an old Intel NUC with Debian stable, a remote mini-keyboard and an automounted Samba share on the network forever. It's no more hacked together than any other computer. I do make the mouse pointer and the fonts real big. No apps required. Don't really need the keyboard except for mplayer hotkey presses - just the touchpad on it; if I need to do something that involves typing other than typing a password, I usually ssh in.
I think people are lowkey addicted to having shit sliding in and out and constantly being advertised to. How do you know what to watch unless somebody is constantly bombarding you with options? If it doesn't look like a star trek control panel, is it really TV?
If you like that, you can install Kodi. I haven't tried it since it was XBMC because I found the interfaces annoying and it had trouble dealing with networks, but I'm sure it's better.
> I've yet to hear of a reasonable recipe to isolate and secure such connected TVs
I don't even try. I overpay for dumb tvs in the present, or underpay for 10 year old tvs pre-Applefication. I've never owned a network capable television, or one with apps. I wouldn't.
edit: if your NAS is a separate box that can sit in proximity to your television, you could probably just run all of this stuff directly from the NAS. They spend most of their time doing nothing at all.
Support in cables is nearly universal, because the same pins in the cable are used for the Audio Return Channel feature that allows a TV to pass audio from its internal apps back out to a soundbar or receiver via the same HDMI cable it takes signals in on from other devices. As far as I'm aware no one has made a cable lacking those pins since 1080p was still the high end.
But yes, support for the ethernet mode as far as I'm aware was never actually implemented in any devices that reached retail availability.
Even if it did support it, nobody connects their TV to their local network via HDMI, they connect it to their PC. And, as far as I'm aware, no PCs automatically start sharing networking with whichever networks they are connected to.
That could of course change. Could be even a nice feature for connecting your TV to the network via your multi media center, if the bandwidth is good.
LG was caught abusing (although it's hard to argue that it isn't intended behaviour) Windows automatic installation of hardware-related software to install adware. Doesn't take too many tinfoil wraps around one's head to imagine them doing the same to enable network sharing (assuming hardware support is ubiqtuous enough).
Their solution to that is to either use the cell phone network or services like amazon sidewalk where they connect in through your (or a neighbour's) internet-connected device.
Not at all, because it uses the same pins as ARC, so the two features can't operate at the same time, and a lot of people use ARC to get audio from TV apps back to a soundbar or receiver.
HDMI Ethernet is dead, it's never going to happen in consumer televisions because it has a hard conflict with a feature a lot of people actually use.
Then you make sure to only use HDMI cables that aren't HEC, in conjunction with not connecting the TV to the internet directly, if you want to keep them isolated.
Did you know that no one has implemented it? You might as well talk about packet-carrying fairies in your TV. And of course the Apple TV box it’s connected to will be quite happy to share its network connection with arbitrary crap you connect to it.
But I guess like an xkcd comic, someone is obligated to raise the issue every time TVs come up.
christ we need to start rooting tvs and start up a open and secure tv os. i never give my tv os internet access i rely on the appletv for the "smart tv" but if what another poster says is true about lg devices looking for public wifi to exfiltrate data then lol time to start pulling tvs apart and shielding their network components from getting a signal
That basically exists, but runs on external hardware: https://kodi.tv/
There's no need for the TV to be anything but a dumb screen that has only "power on", "power off", "volume up", "volume down" and "mute" functions. Most are probably too underpowered anyway to be useful.
Yes tv makers were caught doing HDMI fingerprinting. There was a story some years ago about how basically all smart tv makers were sending data to an ad network based in China.
Samsung were openly bragging about this on their website some years ago (for the benefit of their advertising partners) but have recently muddied the waters when I check their site again, couching it in language mentioning privacy and other evasive language:
It's (mostly) a US thing; basically subsidizing TV prices with ad revenue. It's how the entry-level companies like Vizio operate, though the "big brand" TV makers are certainly just as guilty here. It's much less of a thing in the EU, where data privacy laws are stricter and TVs are hence (comparatively) more expensive.
As far as I know, they don't literally scan your media libraries; they screenshot whatever you're watching through HDMI (most often cable / satellite boxes), as those devices don't provide the telemetry that normal apps do. This info is used for audience measurement (thing Nielsen ratings), as well as showing you ads that are actually likely to match your interests.
"Starting in 2014, Vizio made TVs that automatically tracked what consumers were watching and transmitted that data back to its servers. Vizio even retrofitted older models by installing its tracking software remotely. All of this, the FTC and AG allege, was done without clearly telling consumers or getting their consent.
...
"Vizio collected a selection of pixels on the screen that it matched to a database of TV, movie, and commercial content
We don't really have alternatives, period. LG is the one in the news today, but pretty much any TV this decade has been doing similar things. Computer monitors max out at 32 inches and the idea of a modern dumb TV is non-existent.
I had a similar experience regarding Facebook. People would always remark that they thought someone who knew about tech would surely have an account.
People don't say that so much anymore.
It's worth remembering that for all the animosity they face, they did what they told you they were going to do when they asked for your permission to do it.
Doesn't HDMI have built in Ethernet these days? So any HDMI cable of a certain specification is also a network cable.
I remember these things being discussed a while ago on here, how TVs use their own hard coded DNS ("for safety") rather than any network provided DNS (to avoid filtered DNS ala PiHole), how there's Ethernet in a HDMI cable, how other wireless networks are tried, and how eventually they'll go the car route and just embed a wireless modem in the device.
I am not aware of any smart TV that actively solicits a DHCP lease and default route outbound from anything it's plugged into by the 100M ethernet built into a current gen HDMI link. At least not yet. And since I think the default behavior for things like xboxes, playstations and apple TV is not to be a dhcp server and provide routing/NAT, I don't think a lot of things you can plug a TV into (also yet), would provide such function even if the TV tried.
I'm sure somebody at LG is hard at work on fixing this problem.
Worse, if you watch the GN video this article is based on you'll find the TV can figure out how to leverage other non obvious networks (threads, etc) to reach LG servers. Worth a watch to see how bad this is: https://www.youtube.com/watch?v=6IFVTcM28KA
My in-laws were so proud of themselves. I came home one day and they told me they figured out how to connect my TV to the network so that I don’t have to use my Apple TV if I don’t want.
I had to take a few deep breaths to keep from yelling. I am very happy with my TCL tv but I trust it about as far as I can throw my father in law.
At least with LG you can revoke your consent. I came home to found STT audio recording enabled and I promptly disabled it and lectured the household about privacy.
I didn’t care much about data collected but I found that with every update it becomes worse and worse objectively. I had to cut it from in internet so doesn’t get completely unusable
Mine is still attached to the network, but I’ve turned off all the ad/customisation &AI stuff. Seems to work fine, no ads etc. though usually I’m using it simply as a screen for the AppleTV.
I do have it isolated from other devices on my network, though.
>If you're only using it as a screen for the AppleTV, why connect it to the network at all?
Not GP, but I do so to make sure my TV doesn't try to connect to a different network. I provide specific IP addresses to the ethernet-connected interface and then block those IP addresses.
I suppose I could also move the TV to an isolated VLAN, but I spent months (the device was purchased nearly, or perhaps even more than, a decade ago) monitoring network traffic to determine to where (via DNS queries and packet captures) my TV was trying to phone home and blocked all egress for the TV and ingress from the sites/IP addresses to which the TV tried to connect.
I suppose that newer TVs might be sneakier (with the kind of WiFi surfing mentioned in TFA and/or installing cellular modems) in their attempts to bypass user control and when I need a new TV, I'll burn that bridge when I come to it.
But for now, my TV can't phone home. Or I'd have thrown it away years ago.
I have an LG C5 OLED and do not give it internet access. It does not nag, every non-internet feature works fine, the interface is clean, and my Apple TV works just fine.
I yanked the OCU (telematics) out of my VW Mk7, and coded out the expectation of its existence from about four other devices with Ross-Tech's VCDS! I also coded out the Bluetooth on my infotainment unit, for good measure. :^)
The sad part about the privacy discourse is that people not only don't care, but they would argue for the invading party. And I am not talking about your average teenager looking for their next brainrot fix, but highly educated and extremely intellegent people!
I've long since gave up trying to talk to people about these issues. Which unfortunately means I'll surrender to exposing myself to this plague to some degree, considering how herd immunity principles apply here as well.
Okay. This is insane. First the monitor that uses a windows feature to automatically install a small helper tool with root permissions and then starts showing adds in certain regions. Now a tv that is actually actively snooping around on top of the known fingerprinting. What else is next?
In the previous topic I got ridiculed for not wanting to buy LG anymore because I could use an agent to modify to strip out the offending bits.
But there must be something better than just keeping to buy things that invade our privacy and homes further and further. Which brands aren’t doing this? Sony? They also announced a partnership for the lower end TVs IIRC.
We need to climb two very difficult hills for there to be any change here: 1. We need our governments to actually start charging companies with crimes, when what they are doing would be illegal for an individual to do, and 2. We need the penalties to be something other than fines, which are ultimately treated by companies as routine costs of business.
> We need the penalties to be something other than fines, which are ultimately treated by companies as routine costs of business.
It's true that fines are nothing more than predictable costs, so maybe an option would be fines in percentage of the incoming of the company: this way it could make a real impact. I know in some north Europe countries the speed limit fines are in percentage on the personal net worth.
Income is too small, how about in terms of the highest market capitalization between deciding to do the bad thing and being convicted of the bad thing? Maybe some of these penalties should result in bankruptcies for the most egregious big players, and when I say bankruptcies I don't mean restructuring but actual corporate financial death: firesale auction the assets, debt holders lose much of their value, equity holders get squat, and all employees are out on their asses having been let go. Do it to a Microsoft or Google sized company, scare the piss out of the rest! Then implement protection policies to make it impossible to move headquarters out of the country without having product prices end up 2-4x higher, so domestic competition (which could be let to run tax free) can come up and fill the void. Also tax the hectomillionaires+ more heavily on assets, income, and capital gains!
So step one is a constitutional amendment to ban corporate money in politics, which is going to be suuuper hard to accomplish.
But yeah similar to how humans are put in jail and it can easily ruin their life, the punishment for a severe crime needs to ruin a company’s life. It’s an absurd double standard.
Simplest thing to say is: find all the people responsible for this, from the bottom to the top, and charge them with the same crime as an individual would be. I would include everyone in the chain from the programmers that implemented it, to the VP that authorised it, and finally to the CEO because all responsibility ends with them (that's why they get paid the big bucks right?).
I'd like to say look at Volkswagen for an example but I don't know if all the necessary people were charged.
I don't blame VW because EPA's requirements were killing diesel cars in the US. There haven't been any new model diesel passenger cars in about ten years now.
Similar policy is why American trucks and SUVs are ridiculusly massive transformer-looking behemoths and there're really no 'small' trucks anymore. The Ford Ranger of today is of similar size to the Ford F-150 of 25 years ago.
Seriously. This was my first thought too, the audacity to implement a system like this and the deterioration of a society that seems to give any fucks about privacy where this will be a minor news story that gets some buzz then disappears fairly quickly... I don't know what the fuck has happened. At the very least something like this should result in devastating class action lawsuits towards LG.
I would like to send vast amounts of garbage data to the LG servers. They aren’t being respectful of our bandwidth and data, we don’t need to be respectful of theirs.
This also applies incentives in the correct direction. Their database of customer information becomes less valuable if there’s bad information in it. Disconnecting your TV from the internet doesn’t affect LG, feeding them bad data does.
I have just launched http://weowntheglass.com, it features an oled-safe screensaver steady stream of public domain images of violent uprisings against an oppressive class. The ACR should enjoy that!
I like this enough to actually considering buying one to get it to identify the endpoints. Maybe better to see first if we can find it in the firmware update downloads.
Well, it’s a smart TV. I would assume with extreme prejudice that every single one of them is doing stuff like this and worse until proven innocent. Based on everything I’ve read about these things it seems the most reasonable stance.
> In the previous topic I got ridiculed for not wanting to buy LG anymore because I could use an agent to modify to strip out the offending bits.
>But there must be something better than just keeping to buy things that invade our privacy and homes further and further. Which brands aren’t doing this? Sony? They also announced a partnership for the lower end TVs IIRC.
Smart people need to band together to advocate their state governments to make commercial mass surveillance for any purpose a criminal offense (not just banning, making it a crime).
It's insane, but it's not like it's not known, personally, each time we have a party at home with friends, we always unplug the TV for this reason, it's out of doubt but it's normal to doubt as it's proprietary and has a microphone, so it's a bit obvious that it might be recording and processing data somewhere. The same as I would never trust an average phone around if I'm having a private conversation.
Blackbox+Mic = Not private.
To consider something secure software wise, it involves so many layers, and almost none of those are present with a Smart TV, so it IS considered insecure by anyone having privacy standards.
It's not known. Ask the average person that owns a smart TV if they think they're being listened in on. Or even what kinds of data they think their smart TV collects. I could bet you anything that for nearly all people, their answers would be "I never thought about that", "I didn't know they collected data" or "I thought it was only what I watched".
It's highly insidious - our society was reshaped to normalize data collection like this by adtech. At the same time, these invasive technologies were quietly integrated into existing devices people assumed they knew. TVs look like the same black rectangles they were 15 years ago. Cars today are similar to cars from the early 2010s. The average person doesn't understand how adding internet connectivity to some device exposes them to this until it's explained to them. To them, the notion that they record everything sounds as cospiratorial as "your microwave is secretly recording you on camera". If technological limitations required TVs with mics to have a huge studio microphone protrude on top of it with a flashing red light, a lot more people would suddenly care.
When I was a kid we used vacuum tube radio both as a passive speaker and a microphone... connected to the speakerphone of a telephone as a very poor man walkie-talkie.
Using the speakers as microphone when there is no outgoing sounds is pretty trivial in that regard. I don't know how paranoid a person can be, though.
First of all, your TV is not interested in random gibberish from loud parties. It’s just not economically viable.
During the Soviet era, not everyone could afford to have a landline phone, but the system kept hunting down its dissidents one by one. If you are a person of interest (which I believe doesn’t apply to you), there are way more important signals to adversaries than your microphone.
It's important to choose your threat model. If your plan is to resist surveillance capitalism or just a random Bob and his grandmother snooping on you online, luckily, there are some effective methods. Otherwise, I would say it’s always a question of time, not 'if' or 'how.'
But as the video shows, the TV is doing text to speech and associating audio with a person. That text data is relatively very cheap to hang onto forever.
The problem is really that this tracking is at an absurd scale. So while an individual attacker isn’t targeting you and buying your profile from LG, the data is out there, and once it’s out there, it’s probably easy to get on the dark web if someone did want to do something nefarious. So it’s not just the surveillance capitalism.
I'm surprised this hasn't run afoul of all-party wiretap laws. Even if you could waive your own rights via ToS other people in the house may not have agreed.
Theoretically I could see LG or even the TV's owner being culpable.
I'd love to see that case hit the media. Average citizen jailed over wiretap violations because they let their TV record a guest.
On top of that, the first few minutes of the video suggests it captures your neighbors' device and IP information.
I'm sure the ToS has some BS about you being required to inform any guests, but what if your TV is just recording your neighbors because they are close enough?
Just wait, I'm sure the "solution" will be that TVs start displaying reminders that you're being recorded...
Is our inability to innovate in technology really so bad that we have to just chase more and more spying? Consumers don't want these things. Why can't we innovate on things that consumers actually want? Remember, there was a time where we could build good technology, tech that people wanted, and make buckets of money doing it. That should be our goal, not some cyberpunk dystopia. Honestly it feels like anytime we try to innovate now some manager says "don't make things complicated" or some other dumb excuse, but maybe worse is that peers (other engineers) say "but what's the value" (they always stress that they mean monetary, not utility)? Feels like monkeys attacking each other for trying to get the banana...
Re. The last paragraph, that's what confuses me the most about all of this. LG has virtually held a monopoly of the entire OLED TV market for the past ~15 years, selling (arguably) one of the TVs on the market and being the only thing I've recommended people buy in about as long. They could have done literally nothing but update the hardware every other year with a newer SoC, HDMI version, etc. and done just fine. Now, I don't think I could see myself buying or even recommending any LG products going forward.
There *has* to be some complex math involved. It's insane that there's more profit in duping your users to spy on them and sell their data/information, than there is just making and selling a great product.
My partner, who has a doctorate in economics, and I end up talking about this a lot because I agree that doing nothing, as a monopoly, is the winning move for consumers. Related I ask why we have an economy set up where you're rewarded for climbing to the top but are punished for being at the top [0].
Their explanations are typically around markets being myopic and that low competition fucks things up even more. But we do make small decisions and they add up. I think many of the problems in the world today come from the accumulation of many small decisions, which is why they're hard to address. Obviously some people have more power than others, and more frequently have high power, but we should still look for our opportunities and not abdicate when and where we do have power. It is important for us to push back when we can. The top always wants to convince us that we have no power and we try to convince ourselves that's true because we believe that if we have power that makes us culpable, but I don't think that's true.
[0] my goto example is AWS. It's easy to find articles about how Azure or GCloud are "doing better" but AWS still has more total customers. But AWS is being "punished" for being at the top because it is just harder to grow percentage wise when you have a larger base amount (note, it isn't a zero sum game)
> It's insane that there's more profit in duping your users to spy on them and sell their data/information, than there is just making and selling a great product.
Seems pretty logical, no?
How do we sell more TVs? Be a cheaper and or better choice. If we're already doing well technically, sell customer data to discount the TV and appear more attractive.
If this is ethical / how much disclosure you'd need to give to customers so they can make this informed choice is a whole other discussion...
Not really, it's incredibly myopic. Would you really risk your brand, that took decades to build, by acting hostile to your customers? It only "makes sense" to do when you no longer care about your brand or you are only interested in the short term
You seem to be making the assumption that this is all a zero sum game.
I have to point out the irony that this is a technology based site, focused on software. You know, a sector that isn't nearly as tied to physical resources as other sectors. It's the whole reason our industry exploded, because you can make software and ship it an infinite number of times, allowing you to scale like no other sector can.
But my point is that the economy is a positive sum game. There's always more money to be made through more innovation.
When you treat things as zero sum you make all these bad decisions and focus on the wrong type of growth. It makes you focus on capturing the existing market rather than push to create markets that previously never existed. (Of course there's a bad way to do the latter too. You can make markets against people's will, as we also see today...)
Of what? This can only be evaluated in the context of wherever you live. In most of America recording sounds "in public" is a broadly protected activity because that's what "in public" means. You can only get in trouble for this if you violate another person's reasonable expectation of privacy.
The TV's license agreement attempts to shift the burden onto the TV's owner. Taken at face value, it's the owner who is guilty of recording people without their consent.
Really good question. For instance, TX is a one-party consent state. If the TV is recording what's happening in the living room with nobody's knowledge, that seems like a very clear violation of "one party in the conversation needs to know it's being recorded." IANAL
As an owner of 2 LG OLEDs, I am not surprised at all. I neutered these things the first day I was past the return policy. Opened the back and unplugged the WiFi/BT chip, bought a cheap dumb universal remote with no mic in it, disagreed to all T&C in the TV, updated the firmware via USB and just use an AppleTV over HDMI for streaming. Kind of silly to have to go through all of this but hey thats where we are in 2026 in the US. And I am fully aware that I am typing this on an iPhone thats probably doing the same things that this article is talking about LG doing ;-(
Idk, I have a strong feeling Apple is not doing ACR or covert recording themselves, and the OS provides some strong guarantees that you know when the mic is active.
My Samsung asked for internet access and I just laughed and said nope.
It exists to displays pixels from a Linux box, utterly sick of living in a world where "is my TV manufacturer bugging our house?" Is a thing anyone has to ask.
Have you heard of Amazon Sidewalk (https://sidewalk.amazon/)? All those Rings and Alexas in your neighborhood are able to serve as network proxies for random IoT devices.
LG very likely has your neighbor's WiFi password, so even if you don't connect it to your own network, they could theoretically just try and connect to any known network nearby. No 5g modem needed.
Idk if they do that, but it doesn't seem complicated to implement, and it doesn't seem to fall outside of the company's ethical boundaries.
I think enough customers freely connect their devices to the internet that they don't need to invest in the engineering required to include those kinds of things. I agree they won't have ethical qualms about it. It would also be pretty easy to spot; I feel confident saying they'd be too greedy to be sufficiently sneaky to keep it hidden.
For now, it remains easy and sufficient to not give them your wifi credentials.
Smarter people than me are usually pretty good at guessing what PCB components do just by looking at the shape of them. I guess that's not proof but it's enough for me.
If you're not using the defining feature of a TV (the OTA tuner), why not buy a monitor instead of a TV?
(Next time I have to replace our house's TV, I'm seriously considering buying a separate SBTVD tuner and a monitor instead of a TV, if ignoring the "smart" features of these TVs by not connecting them to a network starts getting too difficult.)
Modern TVs are designed to work with PCs and consoles, they just also happen to have tuners. "Smart" features are mostly a distraction from actual panel capabilities.
Monitor choices also tend charge a premium for equivalent size and quality while lacking some of the features, or introducing other issues. See LG gaming monitors silently installing adware on connection:
My LG OLED C2 also has a great utility to manage deep service-level configurations. Makes it easy to professionally customize without having to fuss with the menus.
If you don't care much for display quality (or are willing to pay significantly more than what you'd be paying for a TV) that's doable.
I've tried finding a monitor big enough and with a decent panel for anywhere near the price of a TV... it's nearly impossible.
Then I tried finding 'dumb TVs' with at least somewhat decent panels... also almost impossible.
In the end I just bought a decent Philips TV with a good panel and 'Android TV' and chose to never connect it to WiFi and activate that (run it in dumb mode.)
It had enough HDMI ports to hook up everything I want and was the best option available. Would I have preferred a 'dumb screen' with a bunch of HDMI ports and no TV tuner at all? Yes.
You're a bit late on that, monitors without all the same features are going the way of the dodo. Smart features are even starting to crop up in the commercial display market. Your last vestige will be buying a panel without a controller board and turning it into a display yourself.
But we just don’t want creepy executives spying on us for bigger bonuses. Hope “secure facilities” keep buying displays that promise not to do gross things so we have something safe for our homes.
I was strongly considering something like that, but the actual screen technology in them is not that great. The new OLED panels look stunning in comparison, because generally those commercial sets are older LCD technology.
I could probably handle 1080p all day (maybe not at such a large size, not sure) so I’d probably be okay with it…
until I hung out on your couch and went back home and turned something on, going “oh no it’s a blur now!” :)
Maybe they’ll eventually have exquisite WiFi/BT-free displays! That even newer tech has trouble of obsoleting (except they could still release a super low power consumption display or something).
Now imagining something very silly: an honor-system subscription from a manufacturer who sells spyware-free displays at a fair price but still wants to satisfy investors (heh), not that I’d chomp at that bit.
Probably worried about things like spectrum wifi. I don't know if others do it, but spectrum will sell access to a private WiFi network using their customers Internet as a backend.
Well even if they don't do it now, these are just a forced update away from using WiFi to connect to an open AP to do whatever they want. I also really hated the fact that there was really no way to turn BT off. Anytime the TV was on it showed up as a BT device ready to connect, and I would get random neighbors trying to and having to say no to random pop ups approving connections. Now these things are sans any type of wireless, and when it comes time to sell them, it will take me 5 mins to reconnect the internal ribbon cable.
I've been tinkering with electronics for the better part of 40 years so I am fairly comfortable cracking stuff open to at least take a look. The TV's I have (B5) were fairly easy to get into. I unplugged the TV and left it unplugged for a little bit to let all the capacitors drain, then I put it face down on a towel on the floor, took 6 or so screws off the bottom, 1 off the back, then the back panel just pops off because it's held on with some clips. The WiFi/BT module was easy to identify, it has some shielded chips with a shielded ribbon cord going to it. It's on the bottom right hand side if you're looking at the back. I unplugged both ends of the ribbon cord by pushing the clip holding it in back/up. Obviously try all of this at your own risk if you're going to. If you're used to opening up and messing with electronics, it was not that hard or time consuming.
edit: one thing I will add is that I was extremely careful moving the screen or pushing on it while working on it. I have heard the super-thin OLED panels are easy to crack from just a little bit too much force.
Why wait until after the return policy? Also what firmware did you update to? Also if you could point to a video where it shows how to do all these things that would be amazing
I believe we should push for legislation that prohibits the sale of customer data to third parties. Websites can use the data on their customers but they cannot share it with anyone else. Because aggregators are selling it cross-border after which you lose track and all control over it.
They shouldn't be able to collect it in the first place. The big companies have 10 page agreements that say they "value" your privacy and that they don't sell your data to third parties. They do value it, highly. And they don't sell it--they just hoard it, mine it, and sell increasingly accurate targeting. Why would they give it up? I mean, besides coughing it up with little objection to national security letters.
The problem is that this includes literally everything on a cloud service. My emails and documents on Gmail/Google Drive is my personal data. My email on Fastmail is my personal data, even if they’re privacy friendly. So that service would be illegal.
Even having an account at all, and being able to see that I have a subscription, or that I previously watched that video, is personal data they collected.
So the Privacy Policy is what you “agree” to let the company do with that data. How do you even begin to differentiate the superfluous stuff they track just for ads, on a technical level without workarounds?
And then think about banning “transferring personal data to a 3rd party.” Does that mean I can’t host account data on AWS, or use a hosted database, be causing I’m transferring data to a different company which can presumably also access it? That’s what the privacy policy has to allow, and why sites have so many “partner services”
It also implies that Google,Meta and others can't put trackers on other people's websites. That kills about 99% of all tracking on the internet. Foreign companies would also be banned from placing trackers to close any loopholes.
Oh they can. They can offer profiling local servers/software for most important websites which, after profiling will request from google the specific ad category
100% agree. There are a million reasons people come up with for why this will never happen, but pardon me if I want to see us try first and then fix the mistakes we made after. Right now we're living in one big dystopian mistake that needs immediate pushback.
Look at the outrage from US tech bros when the EU passed a law saying that you only had to tell people you were going to do this. Imagine how preventing it would be received.
Which is published on a video streaming website run by one of the biggest tracking and data collection companies, which is used to pay for the creation of the video (in addition to ads embedded in the video itself).
Not a valid critique when dealing with an oligopoly (YT, Tik Tok, Insta, etc.). You use the platform or you get ignored. Using the platform to criticize the platform or other platforms like it is possibly the best use of the platform.
The point is: which brands still respect user privacy? If I were to buy a new TV today, which brands-models should I prioritize?
Also, are there brands-models that in which it is possible to sideload a different OS like with mobile phones (LineageOS, GrapheneOS, etc.)
An Apple TV would be the best for privacy you can easily use but not perfect. Don't use streaming services. Torrenting with a VPN would share the least data but Nuvio/Stremio wouldn't share much with adtech. Can't use those on an Apple TV without sideloading :(
Our Android TV (Sony) has an option to basically make it a dumb TV. Not sure whether that still exists. We use that + simply don't plug a network cable or set up WiFi. As long as they don't add cellular modems, this works.
The bottom of the line TVs are basically commoditized and are sold at a loss. There's few tv manufacturers and they mostly compete on price, only the top of the line models have pricing power and only for 6-24 months for new models. A supermajority of consumers don't care if they're tracked all the time and a large fraction don't mind ads everywhere either (they're used to it).
To be fair, most TVs on the market are buying panels from the same few manufacturers. For example, Hisense sources panels from part of LG. I think Samsung is another manufacturer.
So a new company could theoretically access these panels to make a privacy friendly TV without as much capital.
But like you say, it wouldn’t be able to compete on price, because the ad tech lets other companies sell at a loss.
Well you can say this about dozens of products. People basically only care about price and perceived status for some products. Repairability, privacy, sustainability ... are not important for 90% of people, when government tries to they get pissed annoyed having to pay more.
A consumer respecting brand sells products. A Consumer selling brand sells consumers so they can be profiled, analysed for weaknesses and exploited economically in the name of Surveillance Capitalism
I suspect because it's hard to differentiate between ones that actually respect the consumer vs ones that only say so, but are actually lying to your face.
That and not respecting the consumer is more profitable in the short term (only!), which means more marketing money, buying out other brands, lobbying to increase the barrier for entry, et cetera.
We're in a recession, in all but official numbers (which are decreasingly credible by the day). Big companies weather a recession and use it to ransack countries, becsuse smaller/mid-size companies are struggling to do the bare minimum, outright shut down, or cannot start up to begin with.
There's a lot of moving parts that makes it really hard for ethical newcomers to disrupt in these current times. And that's just one angle.
Machiavelli's flexibility: evil has more options to achieve its goals than good, and therefore it always wins. (The invisible hand of the market is a myth - people don't choose things on principles unless they have money to burn).
There is a very I-am-very-smart aspect to these predictable sorts of comments. And weirdly they always seem oddly intended to diminish the core concern being addressed.
"Oh your TV is listening to you and mapping your network and exfiltrating your data? Yeah, well, look at that website that has some ads on it! Boom!
Give up. The future is lost. Don't sweat the wiretapping TV."
It is 100% diminishing the concern. If someone were paid by LG to try to manage this revelation, they would post exactly what touwer posted. Like, there isn't a better way to try to normalize and excuse bad behaviour than doing the incredibly boorish tactic seen above. The "everyone is doing it" excuse is a go to.
I mean, LG would probably also pay someone to run around going "it's just funny, is all" in support if anyone noticed this pathetic astroturfing.
No I disagree here. I would argue that a TV doing this 30 years ago would find themselves in court, whereas now they are all skirting the edge of the law and we accept it because that frog has been boiling for decades.
The idea that logging audio is bad, but cars logging your weight, tvs logging your watch history, scales sending your wifi details, android and apple both mapping your access point to create a pseudo-location tracker without GPS, my mobile network sending me location-based adverts based on tower proximity via sms to a dumbphone are all very very bad.
LG have slightly overstepped the line here, legally, but in my opinion they've overstepped what is OK by a long long way. A website reporting on this while sending your details to hundreds of tracking sites are doing the same thing - abusing what is allowed and I assume only printing the report for more engagement and not because they actually care.
LG need to go a lifetime shit list for this behaviour - there should be outrage like there was about Sony's root kit. But websites like this also need to find out that this behaviour is not ok
I have two LG TVs so this freaks me out a lot. I guess I’m fortunate to have kept their network permanently disconnected (we use Apple TV for smart stuff) but who knows if they don’t do things like scan for open hotspots or connect without permission to networks you previously used to update firmware and then deleted from history.
This company needs to be nuked from orbit. Automatic content recognition is one thing, spying on conversations when switched off is a whole other level of violation.
GamerNexus has been so good at their investigation work.
I know people who complain the channel does not talk more about Hardware and Games as much, but we live in a timeline that personal hardware and games will not be ours anymore, just see how prohibitive hardware prices are today.
I just discovered this channel since I own an lg tv and I also realized something peculiar: after I mention something I see an ad about it very shortly after
the video explains so much and its obvious now and this makes me quite angry
Probably best to treat the wifi password as compromised and change it after the TV has had access to it. But I suppose there's nothing you can do to prevent it from accessing open wifi networks that happen to be nearby.
I see the same thing with advertising. The cost of a banner ad in real life is always decreasing. Now every road intersection, shop aisle, plane seat etc has a huge super bright billboard blasting ads at people who can't realistically avoid it.
After researching a new TV (where it only needs an Apple TV, no so-called smart features for spying purposes) the three contenders were Samsung, LG and Sony Bravia (the higher end models). Samsung was the least trustworthy, having played games with firmware updates and adding telemetry, LG was medium trustworthy, and Sony seemed the least likely. It looks like that heuristic was correct. For the Bravia, I put it on wifi just once temporarily to upgrade the firmware when I bought it, and I'm leaving it disconnected.
It can't just magically connect to an openwifi and update its firmware to start telemetry. It would need a new firmware to even try that.
Folks, never update a TV firmware unless it's necessary.
> Folks, never update a TV firmware unless it's necessary.
Why would a TV ever need a firmware update? Either it works out of the box or it doesn't and I return it. I never updated the firmware of my PC monitor either.
There really is a lot of processing between the signal and final display. It's pretty common for TVs to ship and then get a firmware update that does actually affect core display functionality.
I'd rather they just shipped finished firmware, but yanno. I got bit on a monitor that has actual firmware bugs but no firmware upgrade path that doesn't involve trying to ship it to a service center.
To Ardon's point, my Dell AW3423DWF shipped with an incorrect EOTF for its HDR Peak 1000 mode which was fixed in a firmware update. It's still just a plain monitor though without any "Smart" features though.
... I said something about not sneaking crap in but then I remembered that Dell liked to try and push the Alienware app via Windows Update. I don't have it but I don't remember what I did to block it or if they just stopped pushing it.
There is a feature that you can enable in windows update, which was off by default once upon a time, that allows windows update to lookup and install apps by usb/peripheral id: plug and play something. https://learn.microsoft.com/en-us/answers/questions/2450930/...
Now you're trusting Apple to not enshittify your TV with a firmware update. Even modern set-top boxes are so awful that I understand why everyone moved on to phones/computers.
Anything that you use to show stuff on your tv is gonna have this problem. Apple is a little higher on the trust spectrum than, say, Roku. You’re paying Apple in part for the convenience of not doing a homebrew setup, and in part for the trust.
Not anything - you can use XBMC or Jellyfin and have a certain degree of control over your frontend.
Apple's big problem is that whatever they say, goes. If they decide to partner with Hulu for advertisements, you have no escape hatch to install a respectful UX.
What makes you think the Apple TV isn't also spying on you? It almost certainly is collecting telemetry too. Whether that's more or less than LG I don't know, but my preference is a Linux box with Plasma Bigscreen.
My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet.
DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.
All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.
All of your blocking still doesn't change the fact that your LG TV is actively trying to scan your local hardware, gathering IP-addresses of devices, wi-fi names and signal strengths, creating digital finger prints of the audio and video projected on your screen, recording audio through the internal microphone, even when the TV is in standby or without an internet connection, saving the collected data locally and uploading to LG Ad Solutions as soon as the TV is connected to the internet.
But it's never connected to the internet, not even for software updates. If the TV isn't connected to the internet there's no reason to update it, assuming the TV works as expected.
It's a trade off I guess. I use Home Assistant to control TVs, so kinda need the access.
Have you noticed that on many home routers there is now a default open, sometimes password protective network named AT&T or Cox Wi-Fi? That’s the backhaul. The TV will join that automatically without asking you because they have an agreement with the network provider. This is how tons of devices phone home now. You don’t ever need to add a device on your network for it to have internet. If there’s a partner Wi-Fi network anywhere, it’ll push through that.
They tried that in Denmark a decade ago (or more). Enabled a "public wifi" on all home routers to provide wifi coverage for that company's customers everywhere.
They gave every assurance that it would be secure, completely separate from the users own network, and the bandwidth consumed would be added on top of whatever the user had a contract for.
It took a couple of days after launch before somebody managed to gain access to someone's private network from the public network and they shut it down again and never opened it again.
Anyway, I may be spoiled from living in Denmark, but I'm using my own router, which is an option when ordering, so I'm fairly certain nobody is sharing additional wifi hotspots.
And it's not just me. The majority of people I know use some kind of 3rd party router with their ISP. Granted, some of them just use whatever the ISP sends them, but even then I haven't ever seen any additional wifi networks, and the ISP prints the router admin password on the box itself, so you can poke around if you like (though the ISP has a backdoor, which is also why 3rd party routers are a thing).
Why is this more far fetched than LG smart TVs recording audio while pretending to be off and caching the results waiting for an opportunity to exfiltrate the precious data? We're in a "if they can they will" world with this stuff.
Comcast sets up a secondary wifi network on their routers in your home that they use as the backhaul for smartphones. Why wouldn't they make a deal with LG or whoever to use that data? We've already established they'll do about a half-a-Stuxnet to get at this data, you're telling me they won't do a couple bulk deals with common ISPs?
Why go through all that trouble of spoofing MAC addresses or assuming it will always be able to connect to an open WiFi network.
5G connectivity is cheap. You can put a 5G modem in pretty much any device for $10 or less, and pay roughly $2/year in subscription fees. My local water utility with ~900 subscribers pays $2/year for 5G connectivity for water meters, and I have no doubt you can get it much cheaper at scale.
They don't even have to tell you about the 5G modem. It could exclusively be used for exfiltrating data about your viewing habits. It's virtually undetectable and more or less impossible to block. The TV could behave nice on the Wifi, you can block all the DNS servers you like, it would still be able to phone home.
Okay, even if you don’t agree with me that it’s far fetched, claims of ‘X is doing Y’ usually require some evidence that X is doing Y to be considered credible.
How about this? LG builds many other home appliances like washers and driers. Some have apps and wifi.
Why wouldn’t LG allow their devices to talk to each other locally, without needing to join a network? With private SSID or something like that? Only one appliance would need internet access.
Now, I’m not saying LG is doing it, but this is not a far fetched technical concept. The only reason they’re potentially not going that far is because most people probably just connect it to the internet so why bother about the few who don’t.
The devices are already scanning the network for any devices and software they can find, and mapping your phone to your TV viewing habits for example. The LG execs are on record bragging about it. So I don’t see why it’s absurd
Joining that network from a new device always presents a captive portal that requires the credentials of my ISP account, so how does that work for you?
Where is a web link indicating partnerships, and compatible hardware lists? My ISP does not sell any TV sets.
LG has a cereal port on most of their televisions and monitors. There are quirks and bugs in some models but the general packet structure is simple and it's pretty straightforward to get an ESP32 with ESP home talking to the monitor.
Again, what I mean is, even if you're able to block all these things, the company LG is still secretly and actively trying to collect and process user data, without user awareness or consent.
Actually what I wanted from the video was impact of user consent, but it doesn't seme to cover this: what happens if you accept nothing, or the minimal set of consent (so not including audio) of licenses to allow you to run third-party apps? I recall there are four checkboxes to check.
And then your neighbor spins up an unprotected network or something like xfinity which they could have a deal with and it connects there and phones home anyways.
I hear this a lot “TVs will just connect to a nearby unprotected WiFi network!” But I ve never seen any evidence of it. It appears to just be speculation, unless you have an actual source?
If TV manufacturers wanted to be underhanded then they could actually make this much harder to detect by delaying the connection to new unauthenticated networks for e.g. months or only after seeing another device connect and then using that device's MAC when it is not around.
Because they don't. It's too much guesswork, and honestly pretty complicated. From the user perspective the TV would appear to go offline every now and then, so also somewhat easily detected.
It's much easier to just throw a $10 5G modem in there, pay the $2/year subscription fee for service, and extract data that way. Assuming a 5-10 year relevant lifespan of the TV, they'd throw $20-$30 on top of the sales price for the modem and 10 years of service.
The 5G modem could run completely independent of the wifi network, be a completely different circuit, and you'd never know it was there.
They could (although I’m not sure of the 80Kbps that Amazon sidewalk allows is really sufficient for the purpose of uploading ACR data), but is there any evidence that any TV manufacturer actually is? The reality is, why would they bother? 95% percent of people that buy a “Smart TV” hook it right up to their WiFi as soon as they take it out of the box.
ACR isn't generally a lossless 4K snap shot but indexed 32x32 pixel blocks from arbitrary locations on screen. In some cases it's even a fuzzy hash of the content source, and while 80Kbps isn't a lot, you can still push out data in a timely manner.
If you think its already the case, how come nobody can provide any evidence of it? As stated above, it’s trivial to test. Surely if Brand X was doing this, there’d already be blog posts, youtube videos, HN posts, etc. about it?
And what exactly would they use that particular access path for ?
I could see a threat if the TV had access to the internet and could establish a TLS tunnel or similar from the mothership, and execute commands on my LAN (or IoT network as it stands), and report back. That could establish a command & control channel that could potentially orchestrate an attack on my infrastructure via the TV.
However, reporting that "network X exists and has these devices" over a different network complicates things a fair bit. In theory they could still use the TV as a command and control platform, but it would have to switch networks between my closed network and the open network in order to execute commands and report results. Not saying it's impossible, just very unlikely.
Besides, the TVs are not alone in being cut off from the internet. I have two IoT networks, one for trusted devices (AppleTVs, Sonos, and the likes), and one for untrusted devices like TVs. They run on different VLANs, and anything on the untrusted IoT network can pretty much only talk to itself (client isolation) and the gateway, and there's no internet and no open ports to any other VLAN.
> And what exactly would they use that particular access path for ?
Uploading the weeks, months, or years of locally-stored activity [0] data? Text compresses really well and local storage used to be very cheap.
[0] ...mic voice transcription, how often you use the thing, for how long, and a best guess (because of lack of time sync) at when, "automated content detection" logs [1], names of files you've fed to the thing, -if equipped with a camera- number of people in the room and interesting information about them, etc, etc, etc...
[1] ...assuming that that can be done with data loaded from the factory, which I kinda doubt...
1) What I called "automated content detection" is apparently called "automated content recognition", abbreviated as "ACR".
2) That weeks, months, or years of locally-stored activity I mentioned can also contain historical ACR records. Given that the audio and video of what's being displayed on the screen is "fingerprinted", those fingerprints can be saved just like everything else picked up by the "TV" and uploaded whenever the thing next has Internet connectivity. The "TV" manufacturer will lose the "what are they doing right now?" aspect of the feature, but the "what have they been doing?" aspect of the feature will work just fine.
Directly related is this section of this Gamers Nexus investigation, but the entire video seems to be worth watching if you're not rather familiar with the topic: <https://youtube.com/watch?v=6IFVTcM28KA&t=26m47s>
That's great that you know how to do that, but LG and others know that also. They don't care that a miniscule amount of ppl can do it, they care about the 99.9999% that don't. Thid should be dealt with legislation and very high fees, sufficient to discourage anyone to do it.
Congratulations but I also dislike this type of comment because that is not a solution, a workaround that doesn't happen for 99% of the population.
Soon you won't be able to IoT network or block these devices as they begin to partner with Amazon and the likes that sell Internet for near-by IoT devices. Then your only option then is physically removing / de soldering radios from the board.
For now, setting up an IoT network is pretty much best practice, and I'd wager the average Hacker News reader both has the necessary equipment and skills to do it. That may not always be the case.
Assuming they install some 5G modem in the device, which is pretty much dirt cheap these days (our local water utility uses 5G for meter readings, and the cost per meter is something like $1/year), there's literally nothing short of a faraday cage you can do.
The can report on what you watch freely, and only consumer laws can stop them. However, without a wifi connection they can't snoop on your local network, and they probably can't connect the data to you, assuming you don't register the TV for those 3 months of added warranty or whatever they try to get you to register.
I tend to avoid devices that are built to snoop on you, so no Amazon Alexa, no Google Home, no Apple HomePod. Everything I have utilizes local control via Home Assistant, and most of it is actively blocked in the firewall from accessing the internet. It's not hard to implement, and doesn't require a master of IT, but it does remove a lot of the convenience, which I guess is the reason people don't do it.
> My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet. NS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked),[...]
That's great, good for you that you can do that.
Unfortunately, from LG's surveillance capitalism point of view, the 0.001% of LG owners that can even think about doing that isn't even a drop in the bucket. They don't care about any one individual, and the vast majority of individuals don't care or understand what LG is doing as long as they can watch TV.
It's only a matter of time before another Cambridge Analytica situation pops up, except with better tools and vastly more data. Or maybe something we can't even imagine yet enabled by simply re-purposing ad-tech into something political and malevolent? Some people will be wise to it, of course, but if enough are caught up in it, it won't matter, we all lose as a whole.
I use Home Assistant to turn on/off the TV via automations, sensors, etc.
I could possibly do it via HDMI CEC, but I have a couple of Sony Bravia TVs that more often than not completely ignores that, so I prefer having control over assuming it happens.
Put the tv on a zigbee/matter plug and connect that for the power. (Just be mindful that some TVs need to condition their screens and they will do that when turned “off”, typically during the night. So it you do a hard power off you will need to perform it manually. LG calls it OLED Care iirc.)
I have an automation that turns on amplifier only when using certain inputs, not just when the TV is turned on. I can easily imagine people would also configure their amps to use different input depending on TV input.
Yeah CEC is a bit tricky sometimes. How about auto-off from the TV itself and then a timer for a HA controlled outlet to turn off power after that using automation (i.e., when the streaming device is off for a x minutes)
There is sadly no hdmi CEC support on Most GPUs for pcs. So when you want your tv to turn on and off with your pc it is only possible with the tv being reachable from your pc via ip.
I believe LG doesn’t advertise such an api via Bluetooth
HDMI breakout and a esp32 module flashed with esphome is another option. The tv most likely doesn’t care that the port that sent on/off command is not the same port the video signal is coming from..
The TV has multiple mics that can't be disabled, they constantly record everything and upload transcripts in plain text.
It gathers data and metadata of all devices on the network, including IP addresses. And even analyzes network data to understand which applications are being run.
This should be grounds for a class-action lawsuit. It’s lying, it’s scummy, it’s an abuse of consumer trust, and it’s written off LG as a company to do business with. I’m surprised we aren’t already seeing DPAs in the EU take on LG.
Did the video actually say this? I scrubbed through and found it interesting, but from what I gathered, microphones were only activated when AI voice input was used. Granted, there was no investigation on how trigger happy the beginning of recording might actually be. Did I misinterpret?
Not only that. If shows that it does capture lots of ambiance conversations and switching microphone recording to be easily.
Also there is a scare bit that they show an almost silent stream of audio actually contains audible conversation. Why was it even recording?
The "own the glass" thing is the most consumer disrespect I have heard in a while. They claim they own the TV and YOUR LIVING ROOM.
They know they are invading your privacy, they know the make it fricking hard for you to be able to disable it.
They are pyschos.
I'm ditching buying LG forever
But weren't most recordings manually started in the video? Either through the UI, or via the root access they have?
I might be missing something here, but I did not see the TV automatically recording stuff by itself (or them showing it is transmitted somewhere) without a visible UI element showing that the microphone is active.
It seems that they turned the TV into a wiretap via root. That is a concern and might give some lessons for LG that they need to invest more into security of their devices (privacy indicators, attested boot, anti-root / anti-persistence measures, hard-shutting off the microphone without privacy indicators)...
But you can pull of similar attacks with a compromised laptop / computer or smartphone.
Of course, it's a TV, why does it need that stuff?
Still though, I think the video itself is a bit misleading that it claims (or many people think) it automatically records and transmits all this stuff, while this was not shown here (unless I miss something).
My takeaway was just that the root access gave them the ability to find out what was being recorded, and they were able to play back recordings that it made.
It didn't appear to me that they were initiating anything.
Not only the telescreens, but my impression of the world in 1984 is that the surveillance depended on an army of watchers at the opposite end. Today we have models of all kinds: classification models, speech to text models, large language models, etc. Surveillance with our devices is automated, no human army of watchers needed!
You need to up your irony. The proles were reading Orwell's 1984 and thought "hey, I shouldn't mind being spied on by (smart) TVs!" because this is the statistically average behavior of the consumers.
In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
That's an easy one to put a compensation figure on but there's probably all sorts of other exploits waiting to happen.
I think the most egregious thing here is that if you don't give the TV a network connection that it will actively search for other ways to get the data back to LG such as open WIFI.
>In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
That's understating the problem. With or without AI, this should be cause enough to shut down a company or at least their specific product division.
>E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
They're going to be fine. A slap on the wrist at best.
The value of this data to the NSA, Mossad etc is probably the only thing keeping it secure.
Never in human history has a government had the means to simultaneously spy on millions of people, to use everyday private conversations to categorise them into various threats to the state, and better yet these tech companies can still sell the commercially valuable side of this to advertisers.
People could return to burning down enterprises that they find unsavory or detrimental to society, such as they did during the industrial revolution, but this is problematic in that it's violent and not something the modern person often considers as viable. A part of why people consider this unviable now is in-part due to the consequences of these surveilance technologies. It's difficult to accomplish a revolution when everyone is being spied on all the time.
The shortest path answer is a bit too caveman-esque to survive its application to reality.
That said, I think there is a lot of appeal to go hunting for firms, since it really feels like corporations and their owners are engaging in predatory behavior as opposed to customer centric behavior.
> E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
My tinfoil hat believes that they've already accounted for this as the price of doing business. They will have already budgeted for the fines that they might incur, pay them off and continue as normal while people become accustomed to it.
Will make surveillance mandatory? I mean we definitely should somehow fight terrorism, protect children, and prevent copyright infringement on trillions of dollars per year.
The EU is actually already quite equipped to counter such behavior, with GDPR and CRA (Cyber Resilience Act) regulation they can not only penalize on consumer privacy protection (GDPR) but also on inadequate security practice (CRA), both allow either an absolute fine or a percentage of the annual company revenue.
I wonder what chances a consumer in US has though. If the past is any indication, consumer privacy is not a highly regarded good when ranked against a corporate strategy...
>this is going to be a massive business liability.
No. this is going to go "unnoticed" or at least unactioned. These are surveilance devices - compromising their value as source of surveilance is neither in the interest of industry (who are selling and buying the surveilance) or government (who are buying and acting on it). The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now. These devices bery well may soon be the only lawfully available devices in the consumer market precisely because of their surveilance capabilities. Governments are reluctanty catching up to the capabilities of digital technologies, and they're finding them more useful now than ever before. We will be burning witches again before we ever prosecute tech companies for doing bad things.
We must inculcate into our children and youth a supreme distrust of and skeptical eye for both government and corporations. They are both systems of resource acquisition and control, whose interests often come into conflict with the interests of the people. It is unfortunate that modern technology is being used in this manner, as it very well may lead to a destructive sort of neoludditism. Technology should be embraced, in the sense of teaching children how its composed, how it works, information security, privacy, etc. A child should not leave elementary school not knowing at all how to use an OpenPGP client or how to do very basic Linux system administration from the command line. Ignorance of technology's workings combined with the excitement for technology's consumer applications are the recipé for the normies' complacancy today. Maybe throw a few Steinbeck books out of the school curriculum to make room for this education?
>The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now.
I'm thinking less about shame, as corporations are dead to shame, and more about proof the TV stored a record of your bank details it got from text to speech.
If that's stored as text inside the TV and you lost money because it was copied by a hacker then you have a monetary value to show loss and a trail of liability you can use to sue LG.
The average user would not realize LG was the reason, if they do they will loose more money and effort; LG's reputation and public image won't be even damaged enough for them to take a notice. You are an ant for them and ants are only powerful if they work together.
>I'm thinking less about shame, as corporations are dead to shame, and more about if you can prove the TV stored a record of your bank details it got from text to speech.
Then they'll get a joke fine, and continue as before. Maybe cut the price for a while, until they reintroduce it with another pretext a few years down the line.
And what will anyone actually do when they are bound by an arbitration agreement that prevents class action lawsuits and/or will find against the user because it's an arbitration agreement (with an arbiter that will bend knee and suck cock for the corporations and governments overseeing it - read Five Eyes[0] and Israeli espionage in the US[1])? Or are forced out of court due to the obscene cost of legal action in most nations due to lobbying efforts to protect corporations? Or never get to court due to said obscene costs, or even the simple knowledge of the ofence? Or are simply homeless because all of their money (their most recent paycheck) was stolen, and they are now derelict?
The legal systems that are in place (at least, those in the US) are not sufficient or even designed to act in any amount of favor of individuals. Even leveraging collective action (class action cases), most individuals are left worse off after judgement when they are wronged. Signalling that you are an affected class is effectively an admission of, at minimum, association - and worse guilt, of whatever an inteligence agency may suspect you of. Intelligence is not justice, and does not "protect" individuals under the same standards. If a government wants you to be wronged, they will accomplish it regardless of law, and the information they have regarding you will be leveraged as aggressively as possible. If you are simply wronged, the cost of accomplishing justice is often insurmountable.
In the most innocent case of wrongdoing by one of these surveilance devices, what would you, as an individual, do if your bank details were compromised as a result of a "smart" device exposing your credentials to bad actors? Obviously, you would contact your banking institution and try your best to rememedy the situation. But say, for example, this smart device is on your home network, has your login details, and possibly used your 2fa details because you used it to log in to your banking institution. That is You™. You logged in. You actioned something. It's verifiable because of your IP and your cookies and your 2fa code and the heuristics of your device usage (time of day, and the previous factors, and more). Many smart device applications already include SDKs that act as residential proxies - it's not impossible to believe that malicious ones may act as MITM or such. The possibility of 0Day expoloits or even backdoors can never be ruled out as you do not own these devices.
People should be subject to shame. Every government and every company are composed of people (for now) - these people are what action these possible futures, and who action the exploits of now. They are shameless by trade because that is their value. Much like the adtech industry thrives on the compromise of compensation to overcome the shame of doing wrong, so does intelligence and clandestine commercial exploitation. Money affords people the things that they want and need, which are becoming ever more impossible to acquire without succumbing to the shame of doing Bad Things™ to acquire it. You are never going to be able to sue LG because your bank details were leaked by a public DB or some other endpoint. Nobody will. Because the value of the information that LG provides to governments circumventing established anti-surveilance law (in the US, the 4th Amendment) through sales is worth more than any dollar amount it costs these parties.
Shame on every fucking one of you stains who implements this, if you can feel it, hidden in the walls of your owned property.
You would think that would matter, that they’re basically violating all known PII/HIPAA/GDPR/National security standards and god knows what else, but I expect at most some class action down the line.
At the same time an average citizen can sue and win against these corporations. I never ended up Suing because all companies settled once I showed the evidence. So try it out. Will get expensive for them to use lawyers against ai and still lose.
This is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across.
1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.
2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.
3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.
All the points and scenarios in the video might be valid, but they are not sufficiently grouped into one of the above categories.
Instead, it just mixes them all together to imply that its all the same, weakening the whole investigation.
--
The plain example: Using voice-input for a web-search on the TV [0], make long pauses and observe how it keeps populating the prompt-UI with everything you say.
This is a matter of #3 above, accusing a malicious intent already on such a trivial implementation topic is harming the whole story
I find your "summary" much harder to read and understand, though.
I prefer the original article and the net-benefit of a google-linked video to explain things that already were properly explained, is rather small, at best, in my opinion.
> I find your "summary" much harder to read and understand, though.
Sorry, my grouping of topics isn't supposed to replace the entire research-session.
It's merely my observation after watching the actual "investigation video" that they mixed together lots of stuff they discovered into the larger conspiracy that everything is secretly spying on the user to feed a huge Ad-profiling database.
> I prefer the original article and the net-benefit of a google-linked video to explain things that already were properly explained, is rather small, at best, in my opinion
The article was made FROM the video and takes the wrong conclusions and summaries from it. If you want to form an opinion and are a bit technically savvy, you should watch the video instead.
For example: The video actually shows that all audio that is logged was only processed after voice-input was explicitly started on the device, either via the enabled wake-word or by starting voice-input in the web-search UI. The TV continues to show the text-input UI to the user while its transcribing the voice. This is not malicious, this is the expected behavior from user-perspective.
I commented this only a few days ago on a different LG related thread. What LG are doing is indefensible and we should all vote with our wallets when considering a new TV... but for those who already own an LG TV you really owe it to yourself to jailbreak it and make it "yours", so to speak.
> OpenLGTV[1] is a collective, non-commercial project for legal reverse engineering and research of LG (Smart and non Smart) TVs firmware, which is partially Open Source.
> The main goal of the project is to improve the functionality of the TVs by adding new features, fixing bugs and providing new software.
Watching the actual investigation video the article is based on, it turns out that alot of the statements in the article don't really hold up to closer scrutiny.
I couldn't find any "smoking gun" or discovery of malicious intent.
What's left in the end is the already-known fact in the tech-community: The most-common, most-vulnerable and most-equipped device to spy on you in your home is your Smart-TV.
1. It has all the compute-power and sensors it needs
And it's the only device that "normies" own that has reliable power and reliable internet 24/7. This means you can use it for nefarious purposes, even wastefully so, and it won't show up as suspicious battery drain or prematurely hitting the cell plan's data cap.
For a lot of hacker type stuff (esp. botnets and residential proxies), this is exactly what you want.
I used to believe that piracy couldn't come back in a significant way because people don't want to use computers any more, and phones are a really bad fit for p2p, even if running some hypothetical non-walled-garden OS that wouldn't have issues with that sort of thing. I entirely failed to appreciate the impact of cheap Android TV boxes here.
Tbf, maybe I wouldn't call it a smear campaign, but every NexusGamer video felt like an angry rant for a while now. It was amusing the first 20 times, now I'm kinda fed up with it.
This is the same behaviour as the german secret police in east germany. The difference now its for ads and by tech.
All collected data are probably ai transcribed from audio to text and is fused via data fusion to serve ads. Add collaborative filtering to find similar interests between users.
Mossad would love to know who to de-bank for criticising Israel, United Health Care would love to know who to deny coverage to based on remarks about their back pain.
I managed to watch 14 minutes of the Gamer Nexus video (on my computer) before going into the living room and disconnecting the network cable, OMFG. If there's no legal consequences for LG for this I'll be surprised. I'm in Europe, not counting on the US for this, trust me.
I know its important to put things down to coincidence whenever possible, but a very expensive Bang OLufsen ( I think they use LG ) TV would turn itself off at "the" most interesting split second moments during gameplay , to the point where I thought "if I am being pranked by a friend, does this TV even stream its contents?".
Much to my surprise I found out that many modern TVs do in fact come with dev mode that allow some sort of screen capture.
Safe to say I turned off all the "allow metrics and market/dev modes" and have been happier since.
EDIT> Incase anyone was wondering I did some more research about my model ( im NOT a TV guy ) and came across this regarding what screen content could technically be passed remotely: "Most probable raw grab: ThinQ/SSAP on the LAN after pairing — ~960×540 JPEG.
Live Plus/ACR: most probably sends a fingerprint, not a retrievable raw frame." No idea what it means but thought it might be relevant. Remember Im saying in my case it was a coincidence.
I'm inclined to believe the shutdowns were a bug rather than an extremely patient friend waiting for the perfect gameplay moment. But modern TVs having enough remote-management machinery that the prank theory isn't immediately absurd is not exactly reassuring.
Im not here to feed conspiracy theories and paranoia, its most likely a coincidence, and tied to having "excess metrics and advanced features that indirectly cause a kernel panic that turns the tv off".
But yes, after turning a bunch of unnecessary default options off, my TV never restarted again just as I was making a clutch moment.
So in summary - remember it could just be related to high action moment fps drain, heat, high intensity stuff making the nintendo switch2 compatibility cause a kernel affected restart etc etc etc ( which is documented via the HDMI protocols ) which make it SEEM like something weird is up, but it turns out its a related thing thats not that sus.
Ahhh, i had that with my ps5 and a couple of games were terrible in hiqh quality graphics mode, shutting down the ps5, and then through hdmi, would turn off the tv.
Both games weren’t particularly intensive, the one i remember last was divinity original sin 2, but i think both games ran on unity.
Performance mode mostly fixed it, but blowing out several years of dust from the vents properly sorted it out.
That did happen a few times , but Im telling you bro that TV restarted a couple times just as I was about to clutch, like the same second i was about to press a trigger in an otherwise boring 25 minute round more than once, but yes as I mentioned earlier it could be related to other tech aspects.
I wonder whether it's better to connect it to a network that is then firewalled off from the internet. That may prevent it from looking for alternatives.
> Only a matter of time before they ship with cell modems
I do wonder about the hackability of this. Will it be a purely telemetry connection or will it be able to stream video via that connection as well? (not that data costs as much these days as it used to). Can we piggy back the rest of our internet data on this connection? LG TV as modem/router?
Will they include GPS, so they can also connect your home address to the profile they're creating on you? Location-specific advertising value would make that answer: yes!
They would probably use a low cost IoT plan, which (without volume discount) is something like $1/mo and a few cents per MB. So they may be able to send content ID info or conversation transcripts, but video would be too expensive unless the user pays.
GPS is probably unnecessary since mobile phones are constantly mapping out WLANs. You can get a decent approximation of GPS with just a wireless scan in most places.
I saw a previous conversation here where someone said they were able to “repurpose” a similar IoT modem to get some free data, but the modern chips are soldered on and tightly integrated, so it would be harder to reuse unless you get root on the device. I think they use eSIMs stored in a secure element in the CPU.
I've thought for a while on this and with 5G RedCap I really see a day where they include a fully ad-supported 720p streaming TV service over the 5G link and some kind of "premium" offering to pay more for higher streaming quality (but still be screwed over by ad city to cover the 5G link).
Consumers will buy it if they're told they "never have to worry about an over the air TV antenna again" because it has a magic 5G antenna in it!
Hard to get a gps fix indoors. My guess is to infer it from OTA tv channel IDs and relative signal strengths. Wouldn’t need a big database and the transmitters don’t move much.
See “datacasting” for data side. Would be 1-way so hard to know how many eye/ear balls get the noise; I mean; ad.
Couldn't you still get a reliable GPS fix by observing over longer time periods? But it requires a relatively expensive hardware component so geolocating via nearby wifi APs would definitely be cheaper. Google offers a convenient API for that and there's a semi-public database over at WiGLE.
Seriously. My fucking CPAP machine ships with a 5g modem so my info can be easily available to my physician. Can’t turn it off, no clue if I’m even paying for it given how obtuse the billing situation is with how the company charges health insurance
I do the same thing. My concern is that if somebody makes the decision to spin up an open wireless network it’ll just try to connect to that and upload all of the telemetry it’s been holding onto.
I’m considering opening mine and taking a desoldering braid to both the RJ45 and wireless antenna solder joints. This might break the TV, but at this point if it does I’m ready to just throw it in the trash and find a commercial display.
I bought a television. I didn’t buy an invitation to be watched in the name of surveillance capitalism and until America gets its shit together with data privacy and consumer protection laws this is just going to continue happening.
I haven’t had a chance to watch this yet, but I did watch the preview and all of Steve’s latest work has been great so
I’m sure it’ll be great.
Now do a analysis on everything else, including the smart fridge in the kitchen.
Or what I am trying to say: Everybody has devices which have the potential to spy on you.
Unless your first name is Richard, only travel with open source hardware and software, and you have to ask someone to lend you a phone if you want to call someone even when you are at home.
How does that make this right? And that a device has the potential to spy with an update doesn’t mean it does or will.
Of course, the AVR will be able to snoop and send what is available. Any smart fridges, ovens, appliances, whatever can. Doesn’t mean that they or should. Also doesn’t mean we should just lie down and give up.
If we aren't there already we're well on our way to a bizarre dystopia where our own internet subscriptions somehow cost more than our devices, which somehow generate enough money for their makers to justify embedding wireless modems for constant surveillance. If you buys a device at loss, for them spend a monthly fee to give it access to spy on you, because the data is so valuable, what on earth are they using it for? Or is everyone losing money?
This sort of blanket data collection needs to be made illegal in every single jurisdiction, and have _very_ robust penalties for anyone found in breach of them.
And those jurisdictions need to have people not susceptible to bribery or extortion by the corporations making those data collection devices. That's a big ask.
True. But corruption by those in positions of power and influence is a problem as old as the ages, sadly. But at least there _are_ rules and penalties in place for those caught so there's an element of risk. Whereas the blanket data harvesting by corporations currently appears to go utterly unabated.
What would the HN crowd recommend for a good linux streaming box + hardware with decent TV UX and remote?
My LG is completely offline and I'm using an nvidia shield to display any content, but I'm thinking maybe I need to go the extra mile, there nothing preventing an android tv box to do the same.
Raspberry Pi + LibreElec. It supports CEC, so you can control it with your TV's remote. Or you could download Kore from F-droid to control it over Wifi.
I have a "Homatics Box R 4K Plus" with CoreELEC/Kodi installed. The UX is then determined by your Kodi skin or apps. I wouldn't exactly recommend that box for ease of installation, but it works. It only needed to boot once into Android, annoyingly requiring an internet connection for setup. Since then it only runs CoreELEC. Works via HDMI CEC via the TV remote, which is still a bit annoying, because they had space for a dozen branded streaming provider buttons, but pause/forward etc. are on a mode switch button that overloads the navigation buttons.
Overall I am pretty happy with Kodi on my Android box. 90% of the content is streamed from a local Jellyfin server, so I can't comment on how well it works with DRM media. It occasionally [1] seems to hang, requiring a power reset. The next time it does, I will hook it up to a smart plug to simplify that as well. If you are into tinkering, CoreELEC is based on Linux and you have some basic tools already installed with more available from the addon repos. I have SSHed into LibreELEC to debug network issues with iperf and on a previous iteration to kick over Kodi with systemctl restart.
[1] gonna say less than once a month, I don't remember when it last happened
"This is a concern broadly and future looking" does not in any way mean LG TVs are doing it now; there would be proof of this if they were, it would be easy to catch.
Is all of them, every "smart tv" does it, even after adb, permission restricting or rooting.
Insert a (non infected) usb lamp in your tv and see the lamp turning on when your tv is off. It notifies you about the background activation activity :) Interesting to see when exactly get active (is it keywords or nearby devices or scheduled processes)? Can´t be keywords as that would mean 24/7 active and the lamp says otherwise.
If its not automatic it's incredibly shaky ground in the EU. I'm sure Apple, Amazon and Google got more than a slap on the wrist just for storing a few seconds after the wake word before.
It's unfortunate LG screens are still the best in image quality, even though competition is getting closer. That said, the best way to use LG TVs is to immediately disconnect them from the internet and use an Apple TV 4K for streaming applications.
"Disconnect" is not enough. They will seek out open WiFi and other available LG TVs as relays. You need to remove the WiFi card or at least the antenna.
TFW LG OLED without internet access probably flirting with neighbor's connected LG fridge and LG washer and sharing all my gossip to Chaebols anyway. Just waiting for Chinese OLED to commoditize far enough that you can ship a bare panel with outputs for development. Reality is Korean companies do have enough competition / incentive to value engineer down. There's no reason 5/10 years from you can't just buy a nice OLED panel and a 3D printed shell from ali like eink now. Except more sanctions I guess.Seems like just a matter of time gig work license plate scanners also wardrive around with open access points to harvest info from "unconnected" smart devices, if not already.
I know I'm just paranoid, but when I see LG and these big advertising companies taking bad press from Gamers Nexus, I can't help but think the reporters need to be concerned about their safety.
I'm not sure about that. Although this reporting is aimed at the everyman, the problem they describe is far more impactful for elites and corporations. This is pervasive violation of their personal, corporate and legally privileged privacy, and is a vector for systematic corporate espionage. So I suspect US Senators will soon get phone calls from donors really upset about this.
I don't share your definition of ill intent. The decision to put a (hidden) recording device in people's homes with the express purpose of exfiltrating data is already ill-intentioned of itself, regardless of whatever they planned to do with the collected data.
Pray tell, what goals do "we" want to achieve? Your position of no ill-intent does not sound like you're on the same side as I am, much less more so than myself.
> Because your position of no ill-intent does not sound like you're on the same side as I am.
If your position is "We do not want these kinds of stuff to exist/happen", then we are.
If your position however is "Witchhunts are fun, and decisions and dialogue should be driven by emotions", then indeed we are misaligned by a few centuries.
> Where in my post did I advocate for any form of action?
Wait what?
You don't? What?!
I want action. I do not want there to be a microphone array in my TV that may or may not sample at random times and forwards that data god knows where.
And to achieve that, I believe that we need to look at the systems that brought us to this outcome.
You change the conversation about televisions to be about judging the person you're having the conversation with for what they think is "ill-intent" and for one-upsmanship, you put words into their mouth, and when they point it out, you ignore them and return to the conversation. You aggressively silence them, then start babbling about yourself.
Are you a bot designed to disrupt conversations or just doing a good imitation of one?
Yes, I am indeed trying to disrupt the classic outrage scripts, as I believe that they are harmful to our goals.
There are many, many places on the web where performative outrage as in-group signalling is cheered, but, ideally, we also have some spaces where we can think and derive solutions.
By splitting the spaces, people can get the emotional validation they crave, while we can also have a workspace to make things better and reduce the need for that validation in the first place.
I agree with your sentiment but unless the person you replied to edited their comment it seems misguided. They mostly just said they didn't agree with you, there was no outrage or one upping, and genuine discussions should be encouraged
If you look at it, it's just "it's ill-intent based on what it is, regardless of intent".
Which is.. a dumb statement, but also just the usual social media outrage one-upping in lingo that passes the letter of the law of HN.
Effectively, the user just said that things are bad in response to an implicit "let us examine why, how, and what to do about it". Which is known, but unhelpful and derailing.
And.. somehow also hinted at that I'd not be aligned enough, because my definition of ill-intent being based on intent is not shared.
I read it more as them disagreeing with at what point it's "intent" - is it bad to give yourself the option to record all customers without consent or does it only become bad once they actually turn it on (remotely) and start shipping it.
Having said that, you might be right given the follow up to you
There are multiple recordings of LG executives saying "we own the glass (the TV)", referring to the "LG household", and how they can serve targeted ads by recognizing every device on the network. Just watch the video...
The head of LG ads was banned from serving in a public company for 10 years by the SEC for fraud...
Yes, unfortunately the investigative video is implying (or explicitly stating) malice on every detail they discovered, which is harming the overall message IMO.
They hacked the TV OS, then used the TV UI to do a web search with voice-input and observed (still on the UI!) that the voice input didn't stop immediately on silence but kept extending the search prompt with everything said [0].
The OS-hack was irrelevant for this, the whole sensationalism that a listening process is running (and therefore the device is listening to everything) is just drama added to the sober fact that someone started voice-input, the input field is still displayed on the bottom of the UI and keeps getting populated with new input.
There is an important message in this about security hardening, privacy, data protection, but this conspiracy theory that everything is made to spy on you is not helping...
| but this conspiracy theory that everything is made to spy on you is not helping...
Have you actually looked at what is being discussed? There is no conspiracy theory, these are simple facts. Just about every electronic device is made to spy on you in 2026. Thinking otherwise is naive, at best.
| but this conspiracy theory that everything is made to spy on you is not helping...
Have you actually looked at what is being discussed? There is no conspiracy theory, these are simple facts. Just about every electronic device is made to spy on you in 2026. Thinking otherwise is naive, at best.
You've accidentally proven my statement: If you're not specific, you're not helping.
Nothing about my previous statement was accidental, and it’s proven nothing to your point as far as I can tell. What exactly are you being specific about here? You started with a baseless claim that anyone who believes we live in a surveillance state is misguided, while I stated that the discussion was surrounding facts. Meanwhile, there are numerous citations throughout the thread, go read them; I’m not going to reproduce them here.
> You started with a baseless claim that anyone who believes we live in a surveillance state is misguided
Oh I made no such claim whatsoever. My complete statement was this, in context of the original research the article is based on:
"There is an important message in this about security hardening, privacy, data protection, but this conspiracy theory that everything is made to spy on you is not helping..."
To translate:
It's important to raise and emphasize matters of security hardening, privacy, data protection, and there's alot to raise here.
But doing so by implying broad malicious intent on even the most trivial use-case observed on the device (like user-initiated voice-transcription, as I also elaborated as an example) is not helping to emphasize the actually important findings of that research.
Meanwhile, you started a broad strawman-argument "that anyone who believes we live in a surveillance state is misguided". You need to find a opposing position to argue that, you won't find that with me...
You don't understand - it's not meant to spy on you, it's only meant to spy on you.
It's only meant to spy on you in the way that won't get really bad viral press right now. If it spies on you in the way that people notice and object, it was clearly a honest mistake.
I wonder if in the EU, if you refuse everything, you're protected or screwed. Juridically, you should be okay, but is it rational to trust them to respect the law when breaking it is probably more profitable?
The tradeoff is picture quality. Those panels are dumb and also bad. That's one of the main problems with the marketplace. The best displays are tied to some shady practices like the one in the OP.
You're not wrong, but you could ask your favorite LLM to interact with the LG API's to switch the input for you. At least for my case, it was ~10 minutes of work to develop a small tray app that looks for a specific USB device and switches the TV input if it gets inserted. I don't really even touch the remote anymore
This seems to be the worst case scenario, put into practice by a highly popular device manufacturer. Are they doing this with all of their other devices as well? Monitors, washing machines, fridges? If they can fit this into a TV, they can fit it into everything else.
There's also a fair bit of arrogance from LG: "We own the glass..." leading to this great piece of marketing:
"within an LG TV household we can help extend the ad campaign footprint to the other devices in the household" (at ~14:11)
Advertising is a mind virus. These people are fucking gross. And this seems to be what all technology companies are turning into. Advertising is the Paperclip Maximiser of the real world.
I recently divided much of my home network into VLANs (with "Entertainment" devices separated for this very reason), and this makes me happy to have done so, but now makes me want to do the same to my in-laws network, since they have an LG TV and I regularly connect various of my devices through their network...
Tangential point: I recall on a previous article someone commenting on their surprise at how good Gamers Nexus investigative reporting was. This seems to be another example. You go Gamers Nexus. Might have to buy a supporter pack.
> There's also a fair bit of arrogance from LG: "We own the glass..."
The execs shown in those clips used some pretty revealing language. I also had to do a double-take when they described a customer's (compromised) house as an "LG household," where they "know who's in [it], we know which devices are there... we know how to extend that reach into mobile" and tell advertisers they can "own the living room."
The sense of entitlement is so over-the-top that it's difficult to distinguish from satire.
I shared this thought with a friend of mine recently, primarily in regards to the use of residential proxies:
They don't care about any effect on the individual people.
They view their thing in a vacuum with some kind of religious fervor. It's a form of psychosis, and it seems increasingly prevalent in tech company leadership and so spreads into those who aspire to be tech company leadership types.
Fairly strong disagree. Plenty of damage could be caused to the individual, whether they made the decision to run a residential proxy or not.
Essentially little difference from running a tor exit node.
My position is that I assume that most people running a residential proxy are not aware that they're running a residential proxy. I understand why people use them and how they're useful, but I just don't think there's informed consent. I think they essentially grew out of botnets, or botnets just rebranded into 'residential proxies'.
Having said that, I'm not trying to convince you to change your position. Feel free to continue to disagree with me.
I don’t have a deep understanding of residential proxies. But if you had an internet plan with a data cap, it would surely count against both download and upload, yeah? That alone is a huge violation.
These companies need to be fined into the dirt. We need a corporate death penalty, to be honest.
It's like AI model collapse, where they're surrounded by feedback they're doing everything right, no matter what, for a long time, the feedback loop just drifts away from baseline reality.
My old Vizio TV is probably too old to do much of that, and it doesn't have a microphone, but regardless it's never connected to the internet. In fact, I removed the Wifi module altogether, as the TV would sometimes lock up and make a very loud, annoying screeching sound. Some online searching suggested it was temperature related and removing the WiFi module would help. It's just a standard board like you might find in a laptop. Removing it did help a lot, the lockups still happen very occasionally but are much reduced.
Technical solutions are insufficient for such disregard, the company needs to be sued out of existence, and laws made to prohibit and punish such behavior
Unfortunately, "AI" speech to text loggers can run a long time before it ever runs out of memory. Every time you have to update the TV software, a few MiB of your data is sent.
The issue is a lot of the TV traffic is encrypted, and given the other issues reported it likely gets a lot worse for privacy advocates. Air-gaps don't necessarily guarantee anything either. =3
Is anyone else thinking of cracking open the back cover and desoldering any wireless chips found? I have had a firewall rule to deny my LG TV and related domains, but that doesn't look to be enough
IIRC, most wifi enabled televisions have internal antennae. Remove that (or otherwise disable it) and you significantly improve your security posture by ensuring the radio can't hold a connection beyond the TV bezels.
I don't think the title (edit: of the thread merged into this one!) is accurate.
Starting at 16:04, they say that they merely claim that the TV has the capability to be used as a listening device. In the first 34 minutes, they don't seem to show that LG are actually recording audio from the surroundings (only from the content playing) and after that they start investigating whether you could record audio if you take control of the device (obviously yes).
So the video doesn't seem to support the claim in the article (edit: linked in the merged submission!) that "LG smart TVs continuously [...] log microphone audio while appearing to be turned off".
Of course, all the stuff LG are actually shown to be doing is bad nevertheless, particularly the "Automated Content Recognition".
EDIT: Just to be clear, the parent's post was originally made in relation to an article/thread called: "LG smart TVs caught logging audio with screen off and snooping on local devices". My response was written at the same time.
> So the video doesn't seem to support the claim in the article that "LG smart TVs continuously [...] log microphone audio while appearing to be turned off".
While it is a bit unclear as to whether the logging and transmitting of audio is happening[1], without hacking the device, they were also quite clear that they made it extremely difficult (if not impossible) to MITM certain encrypted communications on their consumer devices. Combining that with claims they make about advertising makes LG's actions highly suspect.
While the video is quite clear that they are not saying LG is doing this (for legal reasons), the set out to prove the capabilities are there and the privacy related configuration options are very weak. For example: the microphone switch only controls one of the onboard microphones. Even if it physically cut off all of the microphones, there are other vectors that could only be software controlled (such as voice enabled remote controls).
Either way, whether it is LG or a third party, the capability to log and transmit audio can certainly be exploited.
Perhaps it is time we start considering whether we should do something just because it can be done. That is to say: do we really need to control a television by voice, or have other features that require a microphone, just because adding a microphone is cheap and there is enough compute to process the data?
[1] I got the impression they were claiming that the audio was recorded and stored on device. They simply could not prove it was sent to LG.
As far as I can tell, all the recording, storing and transmitting of audio from the microphone happens after 34 minutes in, after the point where they start hacking the TV and telling it themselves to do these things.
LG's advertising features appear (from what they discover before 34 minutes in and from the clips of the LG execs boasting about their ad platform) to be concerned only with what's played on the TV (and networks, devices, ..., but not microphone audio).
If I'm wrong about this, I would appreciate a timestamp for where in the video they show LG actually storing and transmitting audio recorded from the microphone.
It's a shame that the only critical evaluation of the OP is buried this far down the page, under all the "this is basically the Stasi" fluff. I wish there was something richer than up/down voting to indicate posts that contribute to the debate.
I think this video is completely misleading about what LG does, versus what the TV is capable of doing. I tried watching this yesterday and was pretty offended by the lack of clarity and closed it.
I'm fairly concerned that at some point in the future is will be almost zero-cost to include eSIM with devices and we'll have virtually no way to prevent devices from working as discovery for advert targeting.
I'm convinced Google TV firmware does something similar. I have an LED bar connected to the TV via USB and from time to time the bar turns on but the TV is "off". I think it's silently turning on to send some kind of telemetry.
What is needed is accountability and transparency. Accountability is criminal charges. Transparency is warning labels on products similar to cigarette warnings. This is digital assault and needs to be treated that way.
Makes me glad I bought a Sony TV which has the microphone on the remote - and is compatible with older remotes without a microphone, so the new remote with its microphone and sponsored streaming service buttons gathers dust (without batteries inserted) while I use an old remote.
I pretty much assume every smart home device capable of doing this is doing it already.
Nothing gets connected to wifi. If temporary connection is required it gets a random one time use guest network SSID and pass that I remove after. (Yes they can collect and send setup metadata during this temporary access period but sometimes it is a worthwhile tradeoff)
I could buy a tv in late 2014 and happened to be the last batch of bravia tvs pre android tv. Back then I was kind of bummed out that just a few weeks after that they announced the first tvs with android tv and now i was hooked with a smart-but-not-that-smart tv with a bunch of crappy ads, an unusable web browser and a non-customizable os.
But they stopped updating it years ago, none of its apps work anymore and the only "smart" feature that still works is screen mirroring feature. The tv part itself still works great. Not a 4k oled 120Hz shiny impressive thing but the image quality is still great. What I thought was an unlucky adquisition back then turned out to be a pretty good one.
Apps, browsers and "smart" features are disposable software, but a good panel can remain useful for a decade. Makes you wish manufacturers treated the smart layer as optional from the start.
Granted, I only watched one hour of the original video, but I get the feeling the way it is presented is a bit dishonest.
A lot of the "silent listening" they show in the video is on a TV they rooted. They start recordings through arecord manually. Or, when they show the transcripts from the recording, the AI voice search is clearly visible on the screen and was manually triggered by something.
Now, does a smart TV need all that hardware? Is a compromised TV a security hazard and smart TVs need to learn more in terms of security from modern smartphones in terms of privacy indicators, attested boot and more?
Sure.
But I do not see enough evidence that the TV is actually voice capturing all this stuff on its own, without any notice.
There is plenty of stuff on the video regarding the network scanning, ACR and more that is definitely concerning. And this is something LG actually does by themselves (when you agree to their ToS / privacy policy).
However, I think that mixing the ACR / network scanning in with "let's root the TV and actively start recording ourselves" mixes the narrative of "what LG actually does" versus "what a compromised TV can actually do", and makes it seem like LG is just recording, transcribing and submitting voice transcript automatically by themselves.
This was not proven here. And I feel that GamersNexus is just risking a lawsuit here by not separating these different concerns clear enough.
Question: I recently upgraded my LG OLED and decided to not accept any of the terms and conditions. I just connect it to my Apple TV and it lives on that HDMI port permanently. How safe am I?
PS: I do have the TV connected to wifi for software updates (on a pi.holed network)
I don't think you need any software updates for your TV. I have a LG oled which I haven't connected to Internet for the last 3 years. Just do a factory reset and don't connect TV to Internet.
Everything works without software updates
No doubt the feature that would imply analytics doesn’t function until terms are accepted doesn’t work as intended. It’s not like it’s going to be a priority to test before going to production.
How disrespectful one can be towards its customers.
I am honestly disgusted by such behaviour.
I know the cheeky confidence biz talk, but is that really what you want your customers to hear? And what about the guys making such disgusting business possible. Is that what you want to build?
LG TVs have the best OLED displays and the most questionable privacy policy. So I picked best of both the worlds and left the TV off the internet. Apple TV is the way to go for me.
Well that's it. No more LG stuff for me. I bought the C1 OLED TV years ago, great TV, but with this BS, they lost me forever.
And yes I connect the tv the wifi for YouTube and for my local media server. No, I do not want other intermediate devices , I want my TV to not spy on me.
That would be lovely. Unfortunately, to the best of my knowledge, nobody sells (for instance) high-quality 65"+ OLED non-"smart" TVs. "dumb TV" options are limited to older display technology.
Literally my current computer monitor, but no, does not work as a living room TV. (Also, would not recommend as a monitor; aggressive ABL and persistent messages about turning off for maintenance.)
When I said 55+ I was talking about the whole size category larger than that, including 65, 77, etc.
I have a 43" Philips Ambilight (43PUS8510, 4K QLED). It's not a dumb TV per se, but you don't have to use any of the smart features, and - most important - you don't have to connect it to a network.
I bought a Sceptre a few years ago but it died pretty quickly (dead pixel strip on the screen). But the replacement 44" Insignia (Best Buy) that I replaced it with has been an awesome tv.
So yes, you can just walk into the Electronics Store (Best Buy) and purchase a dumb TV.
I don't understand why the best advice in this thread is getting downvoted. Even if you buy a smart TV and then disable the smarts, you're still teaching the TV companies that smart TVs sell.
We bought a new tv two years ago and I spent probably a week researching to find the least-smart set I could.
The best option is display only units made for businesses, like what they use for restaurant menus, but those are usually twice the price of normal tvs because they're not app subsidized like smart tvs are.
What I ended up going with was Hisense. They ship with Google TV, but it's disabled by default. On first power up, it asks if you want to activate the Google TV features, and you can just say no. The thing then runs like a basic display.
I have stopped using TV sets more than a decade ago.
Instead of a TV set, I use a very big monitor, which is connected to a mini-PC (an old Intel NUC with Linux), which also has a TV tuner and an infrared remote control receiver. Besides just showing a TV channel, a mini-PC can also record it and it can play any other kind of movie or music files, or it can stream some video from the Internet.
I have an older TCL TV that I've never connected to the internet. Of course, that doesn't prevent it from finding open wifi access points and exfiltrating data without my consent. Based on this (really marvelous) reporting from Gamers Nexus, I probably need to double-check what is actually happening.
BTW corporate meeting rooms with smart TVs...shouldn't have them.
But this response is like when there were meat safety issues in the US and some people said "then buy another brand". People didn't buy that argument (for what I hope are obvious reasons), and so regulation was enacted to protect the public.
It's clear that this problem must be handled with regulation, too. I'm all for markets solving problems, but I'm also for recognizing when it can't. I haven't seen the whole video yet, but I have a sneaking suspicion that it's NOT just LG.
If I am ever well off enough to consider a home theater, it seems I will need to make it a faraday cage and open up the TV to snip all of the microphones and disconnect the Wi-Fi antennae (or maybe even drill any modem chips on the circuitry if we want to go bonkers) as well as any webcams.
Do they make audiophile grade aluminum foil yet? Seems like a neat business opportunity for customers like me
Can somebody attest or falsify that we’d all be better off with a huge gaming monitor plus an Apple TV? Expensive, of course, but privacy is the main consideration here.
I have a rooted LG C4. Beyond blocking things at the DNS level, not accepting terms, not using AI, I wonder if there’s some existing software solution or a documented step-by-step to remove this bloatware/spyware.
It'll be difficult. It's webos of which there's very little custom development.
You'd be better off with an android tv which you can poke at using adb and disable services. Maybe even root it. And install alternative software like smarttubenext.
Unfortunately there very few Android based TVs left. Phillips recently switched to Titanos, Samsung has tizen, Amazon has a new OS. I think it's just Sony that's left on android now.
Can we please agree on calling devices with a cpu and os that spy on the owner smart? I personally think that closed operating systems with spyware is quite dumb for user privacy.
Isn't observation of LG's operation a violation?
I mean it may fit the category "Intercepting live telemetry packets as they travel from the client machine to the company's servers can violate the Electronic Communications Privacy Act (Wiretap Act)"
So I have a tv of LG from the same period. I keep it dumb, not connected to the internet and just use an apple TV, so far it's a clean option. And it's always a good idea to have piHole up to, they usually have the block list updated with LG's and Samsungs urls.
The Gamers Nexus video explained that they will connect to nearby open SSID’s to send the data they have collected. So just not connecting it to your network may not be enough.
Fun fact: some (most?) Samsung TVs of the last ~6 years can't complete OOB setup if they're connected to a PiHoled network with the most vanilla PiHole filters
PiHole doesn't block IPs. It blocks DNS. The device have at least three ways to bypass PiHole: use external DNS directly, or pin the phone-home servers' IP addresses, or use some other protocols to carry IP resolution.
I'd just open the TV and yank or desolder the mic out. Or use the TV as a dumb monitor -- don't connect it to WiFi or Ethernet. And use an external Kodi/AppleTV/whatever-rocks-your-viewing-boat
At this point, best to just keep it disconnected. Just use an apple tv or similar. They sold us a spying device masqueraded as a smart TV.
If internet is really required, I'd personally flood such an LG tv with fake data - add a raspberry pi to provide it with looped audio streams for the microphone, fake bluetooth devices, and so on. But it's still probably a drop in a bucket.
The problem is they really are the best TVs. I have one sitting next to me that thankfully hasn't been connected to the internet in 5 years. Take the subsidies they give you for being able to spy on you then don't let them spy on you is the better move.
I've had several conversations about this over the years, usually about the EU and how they keep harping on Apple (for instance) because it's a highly visible brand while they completely ignore LG (and others) and their massive data collection devices that (by the way) are in every single European institution.
My LG C5 is in a separate VLAN, with no access to the rest of my home network. I've never accepted the terms and conditions, and I don't need anything from it other than to be a display for my 4k player and PC. I guess now I'm going to remove Internet access from it altogether!
The thing I'd like is if the remote didn't have 4 buttons for crappy streaming services I will never use, but instead had 4 buttons to select the HDMI inputs directly; but no, I have to press a button, wait for the stupid laggy UI to load, navigate or point and click at input I want, then do the same to the preview window. A tedious pain in arse for basically the one main thing I use the remote for. It annoys me no end, and it seems to me that the last thing LG care about is the UX; they've put all their efforts into underhand and user-hostile profiling.
I also have a Roku Ultra for streaming, which I very rarely use. I don't expect they treat their users any better and they use ACR too
Another proof of how much our data is worth. But I think they make a loss on me, I can remember only a handful occasions that I bought something based on an ad I saw, which were more informative than seductive, like a monthly bike rental service.
But I guess they still sell my data. I wish they would flag the data of rational people like me as "worthless", and not sell my data.
the only TV I have connected to the home network (guilty, I admit), Sony OLED 65, ARP floods my network about 12-15 hours after "turning off". On a plus side, it doesn't appear to be streaming anything out: no local DNS hits, not enough outgoing traffic for any meaningful audio stream
The choice between privacy concerns and ineptly coded network stack is tough. But that's the choice we're forced to have
Why don’t you just use it as a display and have a more reputable device (e.g a mini pc or an apple tv) feeding it? I’m not forced to give my tv network access at all, since it doesn’t do anything other than display whatever the apple box outputs…
This is exactly what I do on the other TV, as I suggested in a different message in this thread. But this particular TV is mounted flush to the wall and there's physically no space for the apple TV anywhere near or behind it. Sacrifices we have to make
Is it your wall? We have a fairly modern house and the walls are solid gypsum so i just carved out a small hollow for it, cables are going via a channel with some ducting i then plastered over
This is (mostly) the way. Samsung TV without networking configured, XBox for everything - which is problematic in its own ways but it's a known quantity. It doesn't prevent it from "helpfully" hopping on a nearby unsecured network but a) I haven't spotted one of those in a while, and b) it hasn't ever been able to get updates to change its behaviour to make it start doing that if it previously wouldn't.
Shares my browsing info with 1745 "partners" with no clear way to opt out (which ought to be opt-in by the way to be compliant with ePrivacy and GDPR).
There is censorship of illegal streaming sites crippling the internet (Cloudflare). People are being freightened from illegal iptv boxes to watch free sports because it could be part of a botnet or residential proxy network. There are million or billion euro fines for social media and service providers like google. There is enforcement against "fast fashion". Yet there is zero effort for iot privacy, not even labels or certification for good devices.
I don't want to be cynical but face it, the EU really only cares about things that generate money for themselves or big internal market players under the disguise of consumer safety and privacy. Obviously that also comes with some good effects but the perverse incentives are enormous from which we must not be blinded by ideology and warm feelings of our politicians being good and working for the people and the common good.
I have lots of criticisms of the EU and the censorship is lamentable, but this sounds like whataboutism to me. The EU does more for certification than other governments, but even they can't do everything. Is the US going against any of these things? It is only reasonable that they go for the large players first and foremost. Yes, they should do even more, but even the EU has its limits. And I'm quite in favour of going after fast fashion.
"Samba unites TV, digital, and behavioral data through AI to power faster, more accurate media decisions. We help the world’s leading brands and agencies reach the right audiences, measure real outcomes, and access signals no one else has."
These are spy devices. It is sad that the industry has become so addicted to sniffing - the problem I see is that they can no longer stop doing so, as they built an additional network around that yielding money to them.
This is also why I won't buy any watch with a microphone
Even if the manufacturer doesn't do something evil, they may have an exploit or allow 3rd party apps that do whatever
Garmin literally keeps the microphone on 24/7 listening for "OKAY GARMIN"
There should be a consumer law that any device with a microphone must have an LED physically in series so that if the mic has power, the LED is lit, not software control of the LED which can be disabled. Europe might do that someday but unless California does it too it will never happen in USA
I posted two comments on similar threads recently. This is only going to get worse.
> Not long until companies partner with Amazon and others to send traffic automatically through their near-by devices like smart speakers, disconnecting will be impossible.
Not surprised if this is happening already. I don't want to remove radios out my TV..
> Samba, a media intelligence company have several partnerships with manufacturers to take screenshots and collect metadata.
Viewer analytics are valuable to companies like Samba, they aren't the only ones. Laws ASAP, these companies will lobby hard to stop anything of the sort.
That was a long two hours. 15 minutes longer than two hours actually. It was well spent overall since Gamers Nexus covered the privacy intrusions that LG has built into the OS for their smart TV line and likely all of their other smart home devices. "We own the glass" and "we own the living room" don't tell the whole story.
The enshittification of TV ownership and usage through smart TVs and the apps and other software that runs without user knowledge is a huge problem wherever these devices are sold. The TVs track and log every device on owner networks - smart watches, thermostats, smart phones, etc, anything that uses wireless or that accesses the internet from inside the home.
I am so glad that I have avoided "upgrading" our TV, almost montly, for years now by simply sending all the Best Buy texts to spam or deleting them. The best way is to opt out of Best Buy communications and after watching that video I will do that.
Our TV is a Panasonic plasma TV from 2012. I need to exit the last streaming service that we subscribe with and that will get it set to an OTA device used when weather int he area is bad enough that having that real-time local weather channel adds value.
From the video - RCE vulnerabilities could allow anyone to drop code on your TV that enables them to use it as a surveillance device. Lots of microphones in the device and no way for the user to disable them. The TV is listening all the time and, using the very sensitive microphones, can detect and record voices in conversations happening in other rooms more than 60' distant. They are effectively whole-house listening devices probably using MEMS microphones due to excellent sensitivity of the devices. Users are fingerprinted and everyone in the house can be identified, even children and those who are frequent enough guests to have been ID'd. Everything that happens triggers the recording.
I suspect Amazon's and Google's devices were the same with their voice triggers. LG does not allow the user to disable that functionality even after the user has disabled it (apparently) through the deeply buried menu option.
LG pushes updates to TVs that improve the tracking ability for LG and their "partners", which includes Microsoft through MS's ownership of Nuance. LG tried to separate their data collection/advert business to circumvent restrictions on ...
Man there is so much there. Fortunately the only LG product I own is a dumb monitor. I will be contacting relatives to offer advice about what to do with their smart devices, LG or others, so I know this starts another round of investigation for me.
No Samsung or LG at my house. Almost done canceling subscription-based "services" like TV content and gaming (XBox) stuff. I don't have software subscriptions so that's great. And, I should be finished with MS OSes pretty soon and flipped to Linux on new devices.
A lot of the shit and shit infrastructure that some of you build is destructive. One day, you will get your just desserts after shafting people with Binding Arbitration agreements, huge TOS and Privacy Policies, and other types of enshittifying end results.
Ad executives in early 2010s took note of the public response to whistleblowing of the NSA PRISM program and Edward Snowden leaks.
10+ years later, this is their response. They have learned a large majority of people just don't give a shit. We are sheep. A majority of people just want "cheap" shit, no matter the cost.
This world is cooked man. Need an asteroid to wipe this planet clean, bro.
I will remind everyone again that weev was raided by the FBI, arrested, and had all electronics seized, before getting a chance to defend himself in court, all for the crime of publishing emails he found on unsecured URLs he was able to guess.
But we're allowing 1000x worse things, because what, there's a vague line about it buried deep in some EULA, which means laws no longer apply?
Lets treat them the same. Raid LG, seize all of their electronics, at least in the US (other countries are encouraged to do their own raids), arrest the executives, and after they're all in jail, and digital forensics are poring over their products and servers to find what else they did, they can argue in court how actually all these crimes are legal.
Why does anyone trust any device? The surveillance capitalism is just sleepwalking towards disaster, but nobody cares because of the pretty screen and the goddamn brainrot content.
The only thing I hate more than “smart” quotes are “smart” TVs. I groan whenever my LG interrupts. Now I have to spend Labor day wading through a “smart” UI I avoid like the plague to disconnect the internet.
> During bench tests, they found the TV could capture clean microphone audio while the screen was (or at least looked to be) powered down in standby mode. When the team disconnected the TV from Ethernet, the set continued saving voice input locally and uploaded the stored files once network access was restored.
Lawyers: If it is true that the company is secretly recording voices when the device appears to be off, and then uploading the recordings, does that sound like a felony in many US states?
(And a felony that is bumping into different laws than the "unauthorized computer access" ones that tech industry has been getting leeway with?)
Ad Tech is a cancer that is / has destroyed society. It is responsible for almost everything that is awful today. Conflating attention for interest and rewarding sensationalism has created a giant stinking hole in our lives.
It must be eradicated.
Do everything in your power to destroy these companies and their immoral business practices.
Interestingly, there are many laws against launching precision guided missiles, despite the fact that people were throwing snowballs at each other long before missiles were invented.
I actually think our information environment is better today than it was in say, 1930.
A handful of newspapers that controlled 95% of the information was much more of a "precision guided missile", in terms of ability to control information, than social media is today.
(That's not to say it's good today, it's terrifying, but at least it's possible to hear different voices, including voices on the ground)
I strongly believe the worst vices of social media would all persist if there were zero advertising.
You can see that by looking at more minor or fringe social media sites. Public "liking" is literally all it takes for people to degenerate into performativeness, sensationalism, grandstanding, misinformation, etc.
I find it sad that intelligent, educated people can be so blind to the evils building around them. How they confuse the opportunity for a right and how they take and accept awful as normal because they were raised without understanding what they never had...
To associate contextual advertising based on large scale demographics and location with spying, lying, cheating and thieving at an individual level, is a great example of this in real life.
In the old days, the tabloids were obvious. The sensationalism was easy to identify and passive in its voice. They sat on the end caps of grocery stores, far away from the News. TV news was regulated and there was a strict ethics code in place. Today, all news is tabloid as they all chase attention. They have all become the Weekly World News and as a result, we have clowns and ignoramuses running things.
And people fell for it. They actually fell for it...and continue to fall for it.
That is why it's a cancer. Ad tech eats everything in its path and destroys everything good in the process.
When you cannot tell the difference between fact and fiction, you have lost the plot.
> They sat on the end caps of grocery stores, far away from the News. TV news was regulated and there was a strict ethics code in place.
This is our key point of disagreement, not any of the rest
I strongly disagree that the "Real News" of yesterday was "good information" as I define that. It served the biases of the publishers and writers. It was sensationalist. It strongly censored and suppressed politically incorrect viewpoints, to a degree not seen today. The Overton Window was miniscule. The ethics codes were largely self-serving and inert against its major flaws.
Not only can they listen in. You have a contractual requirement to tell everyone in range of an appliance that they may be eavesdropped upon.
CONSENT REQUIREMENT: You acknowledge and agree that it is your sole responsibility to obtain all necessary consents from any third parties whose voices may be captured by the Product and to notify household members and guests that their voices may be captured and processed, in compliance with applicable wiretapping, eavesdropping, and privacy laws. If anyone does not consent, you should disable the microphone or voice features in the settings. LGE disclaims any liability for your failure to obtain such consent or provide such notification.
[1] https://www.lg.com/us/terms
[EDIT] Smart Media products terms appear to be at https://us.lgappstv.com/main/terms (for comparison here's UK: https://gb.lgappstv.com/main/terms, there are some other EU versions available for e.g. Germany but I imagine UK terms should be quite close and more accessible for most of readers)
> 8. I understand that LGE will retain the collected Voice Information for 6 months to fulfil the purposes for which we collected it, and after this period, it will be deleted or anonymized, depending on the case.
> 9. I understand that this Smart Media Product is a household device. If this Smart Media Product will be used by more than one person, I represent that, in addition to agreeing to this Agreement, that I have obtained consent from all other members of my household whose information may be collected through this Smart Media Product and am providing consent on their behalf.
Because the buyer has no real ability to negotiate, any ambiguity is resolved in their favor. A judge can also strike provisions that a reasonable buyer would not expect, or that are unconscionable. So it's up to the judge's judgment.
https://www.investopedia.com/terms/a/adhesion-contract.asp
you ask if they're enforceable but that's the wrong question, the real question is will anyone do anything to stop them?
This is the kind of thing that states need to make explicitly illegal.
This comparison rubs me off the wrong way every time I see, because.
1. The notifications clearly tell the behavior (doing $THING until tomorrow).
2. There's a way to turn them "really off".
What LG does is completely different. IIRC from the teaser of this video, the microphone is never "completely" off or apps can re-enable them somehow.
Nah, for the most part the law has been unable to keep up with (or choose to oppose) corporate power, and new ways it's being used. Usually there's no magic quantum doohickey which demands fundamentally new legal theory.
Of course, they'd outsourced to AU10TIX, which did retain the licenses, and got hacked: https://www.404media.co/id-verification-service-for-tiktok-u...
That's from 2024, but we just had a larger breach with IDScan this week.
Sorry for the digression, but the common thread is how much to trust these companies, and my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want. Some paranoia is warranted, I think.
Honestly, it's not even that extreme in most cases. I think it's usually not malice, it's incompetence.
That's why I don't trust big companies with my data. Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.
Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.
The CEO is responsible for what their company does. If a major breach can occur through the oversight or "incompetence" of one worker, the CEO has already failed, whether through negligence or malice.
At some level, and certainly at the level where you get paychecks of 10 million a year for the "huge responsibility you are bearing", then incompetence IS malice!
I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.
Both are inexcusable, but one is more common/likely than the other.
You can certainly link them together and yes leaders should be held responsible no matter what, but from my perspective as the user who had his data leaked, it doesn't really matter how/why it happened, does it?
People who make poor choices love to pretend that they had no choice at all.
2. It doesn't really matter if you opt out, because _other people around you don't_: they take pictures in which you show, they tag you, they talk about you, they send you links, etc. Which means they (Meta) build a shadow profile of you anyway.
The "personal responsibility angle" is pure fiction.
I live a somewhat normal adult life and manage without having anything to do with Meta ¯\_(ツ)_/¯ I probably miss out on some things, but I don’t notice.
All my friends just contact me through other sources.
If you have kids, it’s more difficult - I can acknowledge that.
So yeah if a business requires me to have an account I’ll find a different business to patronize. Frankly if you’re expecting someone other than you to take responsibility for the media you consume, that’s a problem.
They will keep happening as long as the consequences are just the cost of doing business.
Or, if that does not happen, when enough people rise up in revolution and take the compensation for themselves.
Or, never.
If enough people vote enough or revolt enough, they cannot be stopped. But the incentives for too few people rising up are too costly. They work hard to keep the equilibrium in that balance.
Got into a spat with a manager at my apartment complex because I refused to install their app just to deal with a maintenance issue.
He was like, “I don’t see the problem, you have to use the Latch app to open your apartment door.”
To which I replied, “No, I have the door keypad code memorized.”
Just like I don’t need an app to make a log of exit/entry history in a backend database just to enter my apartment via a Bluetooth lock…
…I should not have to install their app to make my apartment livable.
Indeed, my argument was convincing enough to have a resolution which didn’t include installing their app.
I don't want the new thing because it is the new thing. I want new things that are better.
People accept abusive technology because they consider that's just the way it is with this new thing. It's a failure to understand what should be considered unacceptable.
So what happens if you arrive home with a dead phone?
And possibly worse, they have a log of when you come and go?
Most apartment buildings in the US already use face-tracking cameras to get this log
But I would absolutely not install an app for that.
Thankfully my lease was old enough that I was able to argue against it. I don’t want a 3rd party company tracking my habits, and I don’t want some manager boiling my pets alive while I’m gone because they decided they think our AC is set too low.
It's even worse if some staff wrote paranoid in your file, 'cause they'll argue it's good for "exposure".
And keeping it completely disconnected from the internet should be the default, in my opinion.
Since the legal system has once again failed to protect users from corporations, it's up to users to use technical means for self defense.
In Poland/EU we have an (ever growing) list of forbidden clauses that even when written and signed by consumer are null and void. And I think these can be enacted retroactively - when corporations invent new shady clauses, government steps in and tells them these are invalid.
This helps to even out the consumer-corporation field.
I'm pretty sure that's true almost everywhere. Law beats contract. The real question is how strong the laws are. In the US not so much because of small government and stuff, especially in red states.
Or when you can't even enforce anything in court as you've already given up your right to spend all your money suing, as binding arbitration is the required and only mechanism to "resolve disputes." To make it extra fair, the corporation pays the arbitration firm for their "objective" decisions and not you.
What could go wrong?
In the Gamer's Nexus video, he gets drunk before accepting the terms so that it isn't legal consent. A drunk person can't enter a contract.
I'd love to have a similar standard applied in the US but I'm not holding my breath.
For another perspective, check out the comment you're replying to.
So just treat it as a best case scenario, knowing that it can get even worse.
We Are Altering The Deal. Pray We Don't Alter It Any Further
It is tinfoil hats time, at least for LG tvs.
Also: the US intelligence agencies used Echelon ages ago to monitor what vast swaths of innocent people were up to. I think it's sensible to presume they've got their hooks into these devices too.
A technical solution would presumably spoof the spaff but with E2EE and DoH is it possible? So then what, hacking firmware? I guess then TVs get a hard lifespan limit.
I bought a Philips Ambilight OLED TV probably over 8 years now. Brilliant tv, great quality, I still see no reason to replace it at all. But its built in AndroidTV is garbage.
1080p, but the picture far outstrips most other TVs I've owned to this day.
I have zero plans to change it, and it's usefulness has outlasted the Chromecast that's connected to it.
Yes, I put the first ads on Smart TVs. Apologies.
This is totally backwards; capitalism would do fine in such an environment (in the same way that evolution does fine in an environment where organisms live more than just a few seconds; the whole reason we have the notion of a "lifetime" is that our germ line comes from a long line of ancestral DNA that made organisms that outlasted their competition.)
Individual companies might have to hustle to innovate or die, but that too is good for capitalism.
I think maybe I stepped on somebody's agenda?
Both capitalism and evolution depend on the fact that over time, on average, less fit organisms/organizations are displaced by better alternatives. You may not like that, but down-voting anyone who points it out doesn't make it any less true.
The problem is we've not enforced any strong regulation against ads, downgrade rights or hack ability.
I don't need "better performance" from the system built into my TV I just need it to run Kodi.
Really? Many years ago, I had to physically sign a license with Microsoft to obtain some software. The license was not consistent with the license included with the software. Both licenses effectively said they were the real license and that any other agreement you made with Microsoft was not valid.
I don't think there was any nefarious intent. It was likely to avoid a situation where Microsoft employees offered terms that were not approved of by the company. Still, it goes to show that it can be awfully difficult to judge the intent of a company.
Any iphone/ipad/mac nearby will act as a router for them[1]
Given that we have already established that LG is a shady company, I wouldn't put it beyond them to try to use the same trick.
[1]https://lifehacker.com/tech/how-apple-airtags-actually-work
AirTags broadcast an encrypted ID. Phones build lists of ID’s they’ve seen and send the list to Apple.
There is no routing, no ability to send arbitrary data, no active communication of any sort. It’s not a mesh network.
The link you posted makes that pretty clear.
[1] https://positive.security/blog/send-my
[2] https://github.com/positive-security/send-my
it means you can’t block the tracking by doing anything yourself - you’d also need to block everyone else’s devices too.
This is a really bad thing for those of us who until now have just not connected our 'smart' shit to the internet.
Where I live in the EU they don't do sidewalk otherwise I'd have to look at ways to fight it (disassociate connections or DDoS the devices providing sidewalk routing)
But they've been calling "crazy?" for decades.
I'm hopeful that there will be sufficient distrust that "jailbreaking" or "rooting" TV controller boards will be turnkey enough to move to something like OpenWrt or GrapheneOS but for TVs.
I'll bet there is already a manufacturer whose TVs can all communicate intratelevisually (non-standard proprietary frequencies) – and then, if even one of them is online... they're all relaying within their private intra-TV spyware meshnets to their various relays.
----
In unrelated news, my 2012 Sony Bravia is still fantastic, even if not for (4K) high-refresh games (the image quality remains fantastic for casual usage).
It is well known for like 5 years. Smsrt TVs go through your movies library, and upload screenshots and filenames to internet.
Some will start showing ads after firmware upgrade.
Also, wouldn't this be trivial to test by just setting up your own network and seeing if the TV connects?
They can just start a capture, record to RAM / storage, and retrieve it later when it is reconnected to the network.
Otherwise if it's disconnected, it is still hard to exfiltrate the data somewhere. Maybe they could get creative via Bluetooth, but then you would need a cooperating device in proximity of the device.
I happen to have a NAS with family pictures I like to display. I can (and do) firewall that thing, but then you hit other issues like the apps you need to show pictures and movies in the first place not to install/run.
I've yet to hear of a reasonable recipe to isolate and secure such connected TVs. And don't get me started on Chromecast or other Android dongles, I've no reason to expect better treatment from Google. Some open source hacked-together box, then?
I turn on the device, the app in the upper left is selected and showing some content from that.
The device sits idle, I get drone footage of landscapes.
If I accidentally bump the wrong button on the remote and get sent into the Apple TV (streaming service) app, sure it advertises producte, but in general there are no ads.
In comparison, Google TV's homescreen is giant ads for content on services I don't subscribe to, Roku is at least as bad, Amazon is worse, and Samsung and LG......oof.
I suppose my next device is an Apple TV or some kind of home brew Linux box.
The Shield at launch was an amazing product - premium UX and hardware, premium price point. Google changed the experience to an ad-loaded mess without providing an opt out for those who had spent hundreds of dollars on the Shield.
I was dogfooder, a huge advocate of the product, and someone who had convinced others to buy the Shield and Android TV devices. That UX revamp and how the team treated their customers (internal and external) turned me off the product for life. I tried the various competitors (XBox, Roku, Amazon) before landing on Apple TV. I now own two Apple TV devices - both of which are still getting updates many years after I bought them - and will continue using them for as long as the product line is maintained.
People in this thread have talked about Apple's clean beautiful ad-free UX, but the apps themselves are far better. Apple sets customer-friendly App Store requirements *and enforces them*. That means:
* The back button always works. It will bring you back to the home page of the app and then to the system launcher. It will not get stuck in an endless loop of "are you sure you want to quit?" and just dismissing that dialog like multiple Android apps do
* No loud obtrusive sounds on app startup (YouTube, Netflix)
* The apps are first-class priorities for developers. Circa 2019, the Paramount+ app was an inconsistent mess where subtitles were broken on some platforms. The Plex app wouldn't transcode certain formats on the XBox, and so on. None of these issues are a problem on Apple TV. Not every app is perfect (Dropout, I love your content, but your app is awful), but none of them are worse than on any competing platform.
Apple TV is a truly incredible product and ecosystem and one that feels like a joy to use. That's not the case for Android TV (now Google TV, I think?) even with a custom launcher.
If you only care about file playback, bit still care about things like HDR and quality audio I would recommend something like the OSMC Vero V instead.
It's still relatively cheap, and open source, but also let's you playback something like a blu-ray rip without loss of quality.
It has the other bonus of not requiring any real setup or maintenance.
I've just used an old Intel NUC with Debian stable, a remote mini-keyboard and an automounted Samba share on the network forever. It's no more hacked together than any other computer. I do make the mouse pointer and the fonts real big. No apps required. Don't really need the keyboard except for mplayer hotkey presses - just the touchpad on it; if I need to do something that involves typing other than typing a password, I usually ssh in.
I think people are lowkey addicted to having shit sliding in and out and constantly being advertised to. How do you know what to watch unless somebody is constantly bombarding you with options? If it doesn't look like a star trek control panel, is it really TV?
If you like that, you can install Kodi. I haven't tried it since it was XBMC because I found the interfaces annoying and it had trouble dealing with networks, but I'm sure it's better.
> I've yet to hear of a reasonable recipe to isolate and secure such connected TVs
I don't even try. I overpay for dumb tvs in the present, or underpay for 10 year old tvs pre-Applefication. I've never owned a network capable television, or one with apps. I wouldn't.
edit: if your NAS is a separate box that can sit in proximity to your television, you could probably just run all of this stuff directly from the NAS. They spend most of their time doing nothing at all.
But yes, support for the ethernet mode as far as I'm aware was never actually implemented in any devices that reached retail availability.
That could of course change. Could be even a nice feature for connecting your TV to the network via your multi media center, if the bandwidth is good.
https://www.techspot.com/news/113031-lg-alienware-monitors-c...
Proportion of non-HN users whose TVs don't connect to the internet? Negligible
HDMI Ethernet is dead, it's never going to happen in consumer televisions because it has a hard conflict with a feature a lot of people actually use.
But I guess like an xkcd comic, someone is obligated to raise the issue every time TVs come up.
There's no need for the TV to be anything but a dumb screen that has only "power on", "power off", "volume up", "volume down" and "mute" functions. Most are probably too underpowered anyway to be useful.
Samsung were openly bragging about this on their website some years ago (for the benefit of their advertising partners) but have recently muddied the waters when I check their site again, couching it in language mentioning privacy and other evasive language:
https://www.samsung.com/us/support/answer/ANS10010616/
As far as I know, they don't literally scan your media libraries; they screenshot whatever you're watching through HDMI (most often cable / satellite boxes), as those devices don't provide the telemetry that normal apps do. This info is used for audience measurement (thing Nielsen ratings), as well as showing you ads that are actually likely to match your interests.
"Starting in 2014, Vizio made TVs that automatically tracked what consumers were watching and transmitted that data back to its servers. Vizio even retrofitted older models by installing its tracking software remotely. All of this, the FTC and AG allege, was done without clearly telling consumers or getting their consent.
...
"Vizio collected a selection of pixels on the screen that it matched to a database of TV, movie, and commercial content
https://arxiv.org/pdf/2409.06203 shows LG and Samsung doing something similar
People don't say that so much anymore.
It's worth remembering that for all the animosity they face, they did what they told you they were going to do when they asked for your permission to do it.
I remember these things being discussed a while ago on here, how TVs use their own hard coded DNS ("for safety") rather than any network provided DNS (to avoid filtered DNS ala PiHole), how there's Ethernet in a HDMI cable, how other wireless networks are tried, and how eventually they'll go the car route and just embed a wireless modem in the device.
I'm sure somebody at LG is hard at work on fixing this problem.
I'd just block them - and keep local streaming and remote control working
edit: just found out WebOS doesn't support DoH/DoT so nextdns won't work.
I wonder if one of the public dns providers got LG blocklisted natively with specific IP
I do have it isolated from other devices on my network, though.
Not GP, but I do so to make sure my TV doesn't try to connect to a different network. I provide specific IP addresses to the ethernet-connected interface and then block those IP addresses.
I suppose I could also move the TV to an isolated VLAN, but I spent months (the device was purchased nearly, or perhaps even more than, a decade ago) monitoring network traffic to determine to where (via DNS queries and packet captures) my TV was trying to phone home and blocked all egress for the TV and ingress from the sites/IP addresses to which the TV tried to connect.
I suppose that newer TVs might be sneakier (with the kind of WiFi surfing mentioned in TFA and/or installing cellular modems) in their attempts to bypass user control and when I need a new TV, I'll burn that bridge when I come to it.
But for now, my TV can't phone home. Or I'd have thrown it away years ago.
It's actually a lot faster now (it's an 8 year old TV, their OS can get a little heavy on older models)
Same for anything whether you trust it or not (or somewhere in between).
The sad part about the privacy discourse is that people not only don't care, but they would argue for the invading party. And I am not talking about your average teenager looking for their next brainrot fix, but highly educated and extremely intellegent people!
I've long since gave up trying to talk to people about these issues. Which unfortunately means I'll surrender to exposing myself to this plague to some degree, considering how herd immunity principles apply here as well.
that's not a plus, tho
In the previous topic I got ridiculed for not wanting to buy LG anymore because I could use an agent to modify to strip out the offending bits.
But there must be something better than just keeping to buy things that invade our privacy and homes further and further. Which brands aren’t doing this? Sony? They also announced a partnership for the lower end TVs IIRC.
It's true that fines are nothing more than predictable costs, so maybe an option would be fines in percentage of the incoming of the company: this way it could make a real impact. I know in some north Europe countries the speed limit fines are in percentage on the personal net worth.
But yeah similar to how humans are put in jail and it can easily ruin their life, the punishment for a severe crime needs to ruin a company’s life. It’s an absurd double standard.
I'd like to say look at Volkswagen for an example but I don't know if all the necessary people were charged.
Similar policy is why American trucks and SUVs are ridiculusly massive transformer-looking behemoths and there're really no 'small' trucks anymore. The Ford Ranger of today is of similar size to the Ford F-150 of 25 years ago.
This also applies incentives in the correct direction. Their database of customer information becomes less valuable if there’s bad information in it. Disconnecting your TV from the internet doesn’t affect LG, feeding them bad data does.
> In the previous topic I got ridiculed for not wanting to buy LG anymore because I could use an agent to modify to strip out the offending bits.
Jesus fucking Christ.
Smart people need to band together to advocate their state governments to make commercial mass surveillance for any purpose a criminal offense (not just banning, making it a crime).
Blackbox+Mic = Not private.
To consider something secure software wise, it involves so many layers, and almost none of those are present with a Smart TV, so it IS considered insecure by anyone having privacy standards.
It's not known. Ask the average person that owns a smart TV if they think they're being listened in on. Or even what kinds of data they think their smart TV collects. I could bet you anything that for nearly all people, their answers would be "I never thought about that", "I didn't know they collected data" or "I thought it was only what I watched".
It's highly insidious - our society was reshaped to normalize data collection like this by adtech. At the same time, these invasive technologies were quietly integrated into existing devices people assumed they knew. TVs look like the same black rectangles they were 15 years ago. Cars today are similar to cars from the early 2010s. The average person doesn't understand how adding internet connectivity to some device exposes them to this until it's explained to them. To them, the notion that they record everything sounds as cospiratorial as "your microwave is secretly recording you on camera". If technological limitations required TVs with mics to have a huge studio microphone protrude on top of it with a flashing red light, a lot more people would suddenly care.
When I was a kid we used vacuum tube radio both as a passive speaker and a microphone... connected to the speakerphone of a telephone as a very poor man walkie-talkie.
Using the speakers as microphone when there is no outgoing sounds is pretty trivial in that regard. I don't know how paranoid a person can be, though.
During the Soviet era, not everyone could afford to have a landline phone, but the system kept hunting down its dissidents one by one. If you are a person of interest (which I believe doesn’t apply to you), there are way more important signals to adversaries than your microphone.
It's important to choose your threat model. If your plan is to resist surveillance capitalism or just a random Bob and his grandmother snooping on you online, luckily, there are some effective methods. Otherwise, I would say it’s always a question of time, not 'if' or 'how.'
The problem is really that this tracking is at an absurd scale. So while an individual attacker isn’t targeting you and buying your profile from LG, the data is out there, and once it’s out there, it’s probably easy to get on the dark web if someone did want to do something nefarious. So it’s not just the surveillance capitalism.
Theoretically I could see LG or even the TV's owner being culpable.
I'd love to see that case hit the media. Average citizen jailed over wiretap violations because they let their TV record a guest.
I'm sure the ToS has some BS about you being required to inform any guests, but what if your TV is just recording your neighbors because they are close enough?
Just wait, I'm sure the "solution" will be that TVs start displaying reminders that you're being recorded...
Is our inability to innovate in technology really so bad that we have to just chase more and more spying? Consumers don't want these things. Why can't we innovate on things that consumers actually want? Remember, there was a time where we could build good technology, tech that people wanted, and make buckets of money doing it. That should be our goal, not some cyberpunk dystopia. Honestly it feels like anytime we try to innovate now some manager says "don't make things complicated" or some other dumb excuse, but maybe worse is that peers (other engineers) say "but what's the value" (they always stress that they mean monetary, not utility)? Feels like monkeys attacking each other for trying to get the banana...
There *has* to be some complex math involved. It's insane that there's more profit in duping your users to spy on them and sell their data/information, than there is just making and selling a great product.
Their explanations are typically around markets being myopic and that low competition fucks things up even more. But we do make small decisions and they add up. I think many of the problems in the world today come from the accumulation of many small decisions, which is why they're hard to address. Obviously some people have more power than others, and more frequently have high power, but we should still look for our opportunities and not abdicate when and where we do have power. It is important for us to push back when we can. The top always wants to convince us that we have no power and we try to convince ourselves that's true because we believe that if we have power that makes us culpable, but I don't think that's true.
[0] my goto example is AWS. It's easy to find articles about how Azure or GCloud are "doing better" but AWS still has more total customers. But AWS is being "punished" for being at the top because it is just harder to grow percentage wise when you have a larger base amount (note, it isn't a zero sum game)
Seems pretty logical, no?
How do we sell more TVs? Be a cheaper and or better choice. If we're already doing well technically, sell customer data to discount the TV and appear more attractive.
If this is ethical / how much disclosure you'd need to give to customers so they can make this informed choice is a whole other discussion...
Yeah, welcome to every executive suite since the 80s. How was it under that rock for the last 40 years?
I have to point out the irony that this is a technology based site, focused on software. You know, a sector that isn't nearly as tied to physical resources as other sectors. It's the whole reason our industry exploded, because you can make software and ship it an infinite number of times, allowing you to scale like no other sector can.
But my point is that the economy is a positive sum game. There's always more money to be made through more innovation.
When you treat things as zero sum you make all these bad decisions and focus on the wrong type of growth. It makes you focus on capturing the existing market rather than push to create markets that previously never existed. (Of course there's a bad way to do the latter too. You can make markets against people's will, as we also see today...)
Pure naked greed, something to be celebrated in our Ferengi style capitalist system.
I'm pretty sure Attorney Generals will also join the fray in due time.
This crap needs to be shut down hard.
My Samsung asked for internet access and I just laughed and said nope.
It exists to displays pixels from a Linux box, utterly sick of living in a world where "is my TV manufacturer bugging our house?" Is a thing anyone has to ask.
Okay, but it does work until then. "Things could change in the future" is definitionally true.
Never connect the TV in the first place, and you don't need to physically alter the hardware, firmware, or TOS agreements.
LG very likely has your neighbor's WiFi password, so even if you don't connect it to your own network, they could theoretically just try and connect to any known network nearby. No 5g modem needed.
Idk if they do that, but it doesn't seem complicated to implement, and it doesn't seem to fall outside of the company's ethical boundaries.
For now, it remains easy and sufficient to not give them your wifi credentials.
If you're not using the defining feature of a TV (the OTA tuner), why not buy a monitor instead of a TV?
(Next time I have to replace our house's TV, I'm seriously considering buying a separate SBTVD tuner and a monitor instead of a TV, if ignoring the "smart" features of these TVs by not connecting them to a network starts getting too difficult.)
Monitor choices also tend charge a premium for equivalent size and quality while lacking some of the features, or introducing other issues. See LG gaming monitors silently installing adware on connection:
https://news.ycombinator.com/item?id=48956688
My LG OLED C2 also has a great utility to manage deep service-level configurations. Makes it easy to professionally customize without having to fuss with the menus.
I've tried finding a monitor big enough and with a decent panel for anywhere near the price of a TV... it's nearly impossible.
Then I tried finding 'dumb TVs' with at least somewhat decent panels... also almost impossible.
In the end I just bought a decent Philips TV with a good panel and 'Android TV' and chose to never connect it to WiFi and activate that (run it in dumb mode.)
It had enough HDMI ports to hook up everything I want and was the best option available. Would I have preferred a 'dumb screen' with a bunch of HDMI ports and no TV tuner at all? Yes.
https://www.bhphotovideo.com/c/product/1828914-REG/samsung_q...
Looks like $400 for a 55” 4K TV, $500 for a commercial one, and $1000 to get a commercial one without WiFi. Selling point includes:
TAA: they made it in Mexico (not China, Russia, etc.) to comply with some Trade Agreements Act. Their marketing brochure shows military usage:https://partnerzon.specialelektronik.se/storage/files/produc...
But we just don’t want creepy executives spying on us for bigger bonuses. Hope “secure facilities” keep buying displays that promise not to do gross things so we have something safe for our homes.
until I hung out on your couch and went back home and turned something on, going “oh no it’s a blur now!” :)
Maybe they’ll eventually have exquisite WiFi/BT-free displays! That even newer tech has trouble of obsoleting (except they could still release a super low power consumption display or something).
Now imagining something very silly: an honor-system subscription from a manufacturer who sells spyware-free displays at a fair price but still wants to satisfy investors (heh), not that I’d chomp at that bit.
LG could be using that sort of network.
edit: one thing I will add is that I was extremely careful moving the screen or pushing on it while working on it. I have heard the super-thin OLED panels are easy to crack from just a little bit too much force.
Even having an account at all, and being able to see that I have a subscription, or that I previously watched that video, is personal data they collected.
So the Privacy Policy is what you “agree” to let the company do with that data. How do you even begin to differentiate the superfluous stuff they track just for ads, on a technical level without workarounds?
And then think about banning “transferring personal data to a 3rd party.” Does that mean I can’t host account data on AWS, or use a hosted database, be causing I’m transferring data to a different company which can presumably also access it? That’s what the privacy policy has to allow, and why sites have so many “partner services”
I worked for a major adtech company that bought zero third party data.
There's enough in the bidrequests.
And we had nothing on Meta or Google's ecosystems.
I am still wondering why consumer respecting brands are not emerging more and thriving.
A new display plant costs multiple billions.
To be fair, most TVs on the market are buying panels from the same few manufacturers. For example, Hisense sources panels from part of LG. I think Samsung is another manufacturer.
So a new company could theoretically access these panels to make a privacy friendly TV without as much capital.
But like you say, it wouldn’t be able to compete on price, because the ad tech lets other companies sell at a loss.
And they still do it anyway because why wouldn't they? My $4K+ TV still wants all sorts of "personalized viewing experience" access.
That and not respecting the consumer is more profitable in the short term (only!), which means more marketing money, buying out other brands, lobbying to increase the barrier for entry, et cetera.
There's a lot of moving parts that makes it really hard for ethical newcomers to disrupt in these current times. And that's just one angle.
But also, people do not generally hesitate in front of an all-you-can-eat bouffe
There is a very I-am-very-smart aspect to these predictable sorts of comments. And weirdly they always seem oddly intended to diminish the core concern being addressed.
"Oh your TV is listening to you and mapping your network and exfiltrating your data? Yeah, well, look at that website that has some ads on it! Boom!
Give up. The future is lost. Don't sweat the wiretapping TV."
No they don’t. OP says it’s funny, that’s all.
I mean, LG would probably also pay someone to run around going "it's just funny, is all" in support if anyone noticed this pathetic astroturfing.
The idea that logging audio is bad, but cars logging your weight, tvs logging your watch history, scales sending your wifi details, android and apple both mapping your access point to create a pseudo-location tracker without GPS, my mobile network sending me location-based adverts based on tower proximity via sms to a dumbphone are all very very bad.
LG have slightly overstepped the line here, legally, but in my opinion they've overstepped what is OK by a long long way. A website reporting on this while sending your details to hundreds of tracking sites are doing the same thing - abusing what is allowed and I assume only printing the report for more engagement and not because they actually care.
LG need to go a lifetime shit list for this behaviour - there should be outrage like there was about Sony's root kit. But websites like this also need to find out that this behaviour is not ok
I have two LG TVs so this freaks me out a lot. I guess I’m fortunate to have kept their network permanently disconnected (we use Apple TV for smart stuff) but who knows if they don’t do things like scan for open hotspots or connect without permission to networks you previously used to update firmware and then deleted from history.
This company needs to be nuked from orbit. Automatic content recognition is one thing, spying on conversations when switched off is a whole other level of violation.
I know people who complain the channel does not talk more about Hardware and Games as much, but we live in a timeline that personal hardware and games will not be ours anymore, just see how prohibitive hardware prices are today.
the video explains so much and its obvious now and this makes me quite angry
LG should be banned
Just imagine having to jam the devices in your own home just to stop them from profiling you.
Better pray to your deer god that modem + data contract is gonna stay more expensive that the expected value from selling more data...
We really need regulation to stop this.
It can't just magically connect to an openwifi and update its firmware to start telemetry. It would need a new firmware to even try that.
Folks, never update a TV firmware unless it's necessary.
Why would a TV ever need a firmware update? Either it works out of the box or it doesn't and I return it. I never updated the firmware of my PC monitor either.
I'd rather they just shipped finished firmware, but yanno. I got bit on a monitor that has actual firmware bugs but no firmware upgrade path that doesn't involve trying to ship it to a service center.
... I said something about not sneaking crap in but then I remembered that Dell liked to try and push the Alienware app via Windows Update. I don't have it but I don't remember what I did to block it or if they just stopped pushing it.
Apple's big problem is that whatever they say, goes. If they decide to partner with Hulu for advertisements, you have no escape hatch to install a respectful UX.
DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.
All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.
It's a trade off I guess. I use Home Assistant to control TVs, so kinda need the access.
They gave every assurance that it would be secure, completely separate from the users own network, and the bandwidth consumed would be added on top of whatever the user had a contract for.
It took a couple of days after launch before somebody managed to gain access to someone's private network from the public network and they shut it down again and never opened it again.
Anyway, I may be spoiled from living in Denmark, but I'm using my own router, which is an option when ordering, so I'm fairly certain nobody is sharing additional wifi hotspots.
And it's not just me. The majority of people I know use some kind of 3rd party router with their ISP. Granted, some of them just use whatever the ISP sends them, but even then I haven't ever seen any additional wifi networks, and the ISP prints the router admin password on the box itself, so you can poke around if you like (though the ISP has a backdoor, which is also why 3rd party routers are a thing).
This seems far fetched to me. Have you seen evidence or reliable reporting of this?
Comcast sets up a secondary wifi network on their routers in your home that they use as the backhaul for smartphones. Why wouldn't they make a deal with LG or whoever to use that data? We've already established they'll do about a half-a-Stuxnet to get at this data, you're telling me they won't do a couple bulk deals with common ISPs?
5G connectivity is cheap. You can put a 5G modem in pretty much any device for $10 or less, and pay roughly $2/year in subscription fees. My local water utility with ~900 subscribers pays $2/year for 5G connectivity for water meters, and I have no doubt you can get it much cheaper at scale.
They don't even have to tell you about the 5G modem. It could exclusively be used for exfiltrating data about your viewing habits. It's virtually undetectable and more or less impossible to block. The TV could behave nice on the Wifi, you can block all the DNS servers you like, it would still be able to phone home.
Why wouldn’t LG allow their devices to talk to each other locally, without needing to join a network? With private SSID or something like that? Only one appliance would need internet access.
This shit already exists. Like Amazon Sidewalk: https://ring.com/amazon-sidewalk
Now, I’m not saying LG is doing it, but this is not a far fetched technical concept. The only reason they’re potentially not going that far is because most people probably just connect it to the internet so why bother about the few who don’t.
The devices are already scanning the network for any devices and software they can find, and mapping your phone to your TV viewing habits for example. The LG execs are on record bragging about it. So I don’t see why it’s absurd
Where is a web link indicating partnerships, and compatible hardware lists? My ISP does not sell any TV sets.
My guess is: not much.
1. Do not connect to network 2. Create unauthenticated WiFi network 3. Monitor WiFi network
Strange no one has ever done this simple af test to backup their claims
It's much easier to just throw a $10 5G modem in there, pay the $2/year subscription fee for service, and extract data that way. Assuming a 5-10 year relevant lifespan of the TV, they'd throw $20-$30 on top of the sales price for the modem and 10 years of service.
The 5G modem could run completely independent of the wifi network, be a completely different circuit, and you'd never know it was there.
I could see a threat if the TV had access to the internet and could establish a TLS tunnel or similar from the mothership, and execute commands on my LAN (or IoT network as it stands), and report back. That could establish a command & control channel that could potentially orchestrate an attack on my infrastructure via the TV.
However, reporting that "network X exists and has these devices" over a different network complicates things a fair bit. In theory they could still use the TV as a command and control platform, but it would have to switch networks between my closed network and the open network in order to execute commands and report results. Not saying it's impossible, just very unlikely.
Besides, the TVs are not alone in being cut off from the internet. I have two IoT networks, one for trusted devices (AppleTVs, Sonos, and the likes), and one for untrusted devices like TVs. They run on different VLANs, and anything on the untrusted IoT network can pretty much only talk to itself (client isolation) and the gateway, and there's no internet and no open ports to any other VLAN.
Uploading the weeks, months, or years of locally-stored activity [0] data? Text compresses really well and local storage used to be very cheap.
[0] ...mic voice transcription, how often you use the thing, for how long, and a best guess (because of lack of time sync) at when, "automated content detection" logs [1], names of files you've fed to the thing, -if equipped with a camera- number of people in the room and interesting information about them, etc, etc, etc...
[1] ...assuming that that can be done with data loaded from the factory, which I kinda doubt...
1) What I called "automated content detection" is apparently called "automated content recognition", abbreviated as "ACR".
2) That weeks, months, or years of locally-stored activity I mentioned can also contain historical ACR records. Given that the audio and video of what's being displayed on the screen is "fingerprinted", those fingerprints can be saved just like everything else picked up by the "TV" and uploaded whenever the thing next has Internet connectivity. The "TV" manufacturer will lose the "what are they doing right now?" aspect of the feature, but the "what have they been doing?" aspect of the feature will work just fine.
Directly related is this section of this Gamers Nexus investigation, but the entire video seems to be worth watching if you're not rather familiar with the topic: <https://youtube.com/watch?v=6IFVTcM28KA&t=26m47s>
Soon you won't be able to IoT network or block these devices as they begin to partner with Amazon and the likes that sell Internet for near-by IoT devices. Then your only option then is physically removing / de soldering radios from the board.
Laws needed, like yesterday.
Assuming they install some 5G modem in the device, which is pretty much dirt cheap these days (our local water utility uses 5G for meter readings, and the cost per meter is something like $1/year), there's literally nothing short of a faraday cage you can do.
The can report on what you watch freely, and only consumer laws can stop them. However, without a wifi connection they can't snoop on your local network, and they probably can't connect the data to you, assuming you don't register the TV for those 3 months of added warranty or whatever they try to get you to register.
I tend to avoid devices that are built to snoop on you, so no Amazon Alexa, no Google Home, no Apple HomePod. Everything I have utilizes local control via Home Assistant, and most of it is actively blocked in the firewall from accessing the internet. It's not hard to implement, and doesn't require a master of IT, but it does remove a lot of the convenience, which I guess is the reason people don't do it.
Unfortunately, from LG's surveillance capitalism point of view, the 0.001% of LG owners that can even think about doing that isn't even a drop in the bucket. They don't care about any one individual, and the vast majority of individuals don't care or understand what LG is doing as long as they can watch TV.
It's only a matter of time before another Cambridge Analytica situation pops up, except with better tools and vastly more data. Or maybe something we can't even imagine yet enabled by simply re-purposing ad-tech into something political and malevolent? Some people will be wise to it, of course, but if enough are caught up in it, it won't matter, we all lose as a whole.
I could possibly do it via HDMI CEC, but I have a couple of Sony Bravia TVs that more often than not completely ignores that, so I prefer having control over assuming it happens.
I believe LG doesn’t advertise such an api via Bluetooth
https://www.pulse-eight.com/p/104/usb-hdmi-cec-adapter
One could build a IR emitter but you need soldering skills for that or buy a usb one which cost north of 30€ + shipping.
The TV has multiple mics that can't be disabled, they constantly record everything and upload transcripts in plain text.
It gathers data and metadata of all devices on the network, including IP addresses. And even analyzes network data to understand which applications are being run.
The "own the glass" thing is the most consumer disrespect I have heard in a while. They claim they own the TV and YOUR LIVING ROOM.
They know they are invading your privacy, they know the make it fricking hard for you to be able to disable it. They are pyschos. I'm ditching buying LG forever
I might be missing something here, but I did not see the TV automatically recording stuff by itself (or them showing it is transmitted somewhere) without a visible UI element showing that the microphone is active.
It seems that they turned the TV into a wiretap via root. That is a concern and might give some lessons for LG that they need to invest more into security of their devices (privacy indicators, attested boot, anti-root / anti-persistence measures, hard-shutting off the microphone without privacy indicators)...
But you can pull of similar attacks with a compromised laptop / computer or smartphone.
Of course, it's a TV, why does it need that stuff? Still though, I think the video itself is a bit misleading that it claims (or many people think) it automatically records and transmits all this stuff, while this was not shown here (unless I miss something).
It didn't appear to me that they were initiating anything.
Totally and absolutely, and seemingly proud of it. Just gross.
War is peace. Freedom is slavery. Ignorance is strength. [1]
Would you like to know more?
[1] https://en.wikipedia.org/wiki/Telescreen
E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
That's an easy one to put a compensation figure on but there's probably all sorts of other exploits waiting to happen.
I think the most egregious thing here is that if you don't give the TV a network connection that it will actively search for other ways to get the data back to LG such as open WIFI.
That's understating the problem. With or without AI, this should be cause enough to shut down a company or at least their specific product division.
>E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
They're going to be fine. A slap on the wrist at best.
Never in human history has a government had the means to simultaneously spy on millions of people, to use everyday private conversations to categorise them into various threats to the state, and better yet these tech companies can still sell the commercially valuable side of this to advertisers.
- Larry Ellison (Oracle Corporation)
That said, I think there is a lot of appeal to go hunting for firms, since it really feels like corporations and their owners are engaging in predatory behavior as opposed to customer centric behavior.
My tinfoil hat believes that they've already accounted for this as the price of doing business. They will have already budgeted for the fines that they might incur, pay them off and continue as normal while people become accustomed to it.
Will make surveillance mandatory? I mean we definitely should somehow fight terrorism, protect children, and prevent copyright infringement on trillions of dollars per year.
I wonder what chances a consumer in US has though. If the past is any indication, consumer privacy is not a highly regarded good when ranked against a corporate strategy...
No. this is going to go "unnoticed" or at least unactioned. These are surveilance devices - compromising their value as source of surveilance is neither in the interest of industry (who are selling and buying the surveilance) or government (who are buying and acting on it). The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now. These devices bery well may soon be the only lawfully available devices in the consumer market precisely because of their surveilance capabilities. Governments are reluctanty catching up to the capabilities of digital technologies, and they're finding them more useful now than ever before. We will be burning witches again before we ever prosecute tech companies for doing bad things.
Spot on.
If that's stored as text inside the TV and you lost money because it was copied by a hacker then you have a monetary value to show loss and a trail of liability you can use to sue LG.
The average user would not realize LG was the reason, if they do they will loose more money and effort; LG's reputation and public image won't be even damaged enough for them to take a notice. You are an ant for them and ants are only powerful if they work together.
Then they'll get a joke fine, and continue as before. Maybe cut the price for a while, until they reintroduce it with another pretext a few years down the line.
The legal systems that are in place (at least, those in the US) are not sufficient or even designed to act in any amount of favor of individuals. Even leveraging collective action (class action cases), most individuals are left worse off after judgement when they are wronged. Signalling that you are an affected class is effectively an admission of, at minimum, association - and worse guilt, of whatever an inteligence agency may suspect you of. Intelligence is not justice, and does not "protect" individuals under the same standards. If a government wants you to be wronged, they will accomplish it regardless of law, and the information they have regarding you will be leveraged as aggressively as possible. If you are simply wronged, the cost of accomplishing justice is often insurmountable.
In the most innocent case of wrongdoing by one of these surveilance devices, what would you, as an individual, do if your bank details were compromised as a result of a "smart" device exposing your credentials to bad actors? Obviously, you would contact your banking institution and try your best to rememedy the situation. But say, for example, this smart device is on your home network, has your login details, and possibly used your 2fa details because you used it to log in to your banking institution. That is You™. You logged in. You actioned something. It's verifiable because of your IP and your cookies and your 2fa code and the heuristics of your device usage (time of day, and the previous factors, and more). Many smart device applications already include SDKs that act as residential proxies - it's not impossible to believe that malicious ones may act as MITM or such. The possibility of 0Day expoloits or even backdoors can never be ruled out as you do not own these devices.
People should be subject to shame. Every government and every company are composed of people (for now) - these people are what action these possible futures, and who action the exploits of now. They are shameless by trade because that is their value. Much like the adtech industry thrives on the compromise of compensation to overcome the shame of doing wrong, so does intelligence and clandestine commercial exploitation. Money affords people the things that they want and need, which are becoming ever more impossible to acquire without succumbing to the shame of doing Bad Things™ to acquire it. You are never going to be able to sue LG because your bank details were leaked by a public DB or some other endpoint. Nobody will. Because the value of the information that LG provides to governments circumventing established anti-surveilance law (in the US, the 4th Amendment) through sales is worth more than any dollar amount it costs these parties.
Shame on every fucking one of you stains who implements this, if you can feel it, hidden in the walls of your owned property.
0: https://en.wikipedia.org/wiki/Five_Eyes 1: https://en.wikipedia.org/wiki/Israeli_espionage_in_the_Unite...
ꭞ Terms and conditions apply
1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.
2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.
3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.
All the points and scenarios in the video might be valid, but they are not sufficiently grouped into one of the above categories.
Instead, it just mixes them all together to imply that its all the same, weakening the whole investigation.
--
The plain example: Using voice-input for a web-search on the TV [0], make long pauses and observe how it keeps populating the prompt-UI with everything you say. This is a matter of #3 above, accusing a malicious intent already on such a trivial implementation topic is harming the whole story
[0] https://youtu.be/6IFVTcM28KA?si=oVqX6NtkxPmqh6R-&t=2951
I prefer the original article and the net-benefit of a google-linked video to explain things that already were properly explained, is rather small, at best, in my opinion.
Sorry, my grouping of topics isn't supposed to replace the entire research-session.
It's merely my observation after watching the actual "investigation video" that they mixed together lots of stuff they discovered into the larger conspiracy that everything is secretly spying on the user to feed a huge Ad-profiling database.
> I prefer the original article and the net-benefit of a google-linked video to explain things that already were properly explained, is rather small, at best, in my opinion
The article was made FROM the video and takes the wrong conclusions and summaries from it. If you want to form an opinion and are a bit technically savvy, you should watch the video instead.
For example: The video actually shows that all audio that is logged was only processed after voice-input was explicitly started on the device, either via the enabled wake-word or by starting voice-input in the web-search UI. The TV continues to show the text-input UI to the user while its transcribing the voice. This is not malicious, this is the expected behavior from user-perspective.
I couldn't find any "smoking gun" or discovery of malicious intent.
What's left in the end is the already-known fact in the tech-community: The most-common, most-vulnerable and most-equipped device to spy on you in your home is your Smart-TV.
1. It has all the compute-power and sensors it needs
2. It already does some spying for ad-profiling
3. If a hacker exploits it, it's a problem
For a lot of hacker type stuff (esp. botnets and residential proxies), this is exactly what you want.
I used to believe that piracy couldn't come back in a significant way because people don't want to use computers any more, and phones are a really bad fit for p2p, even if running some hypothetical non-walled-garden OS that wouldn't have issues with that sort of thing. I entirely failed to appreciate the impact of cheap Android TV boxes here.
4. Every single fucked up thing it did was indeed listed in their customer agreement and privacy policy
https://www.eff.org/deeplinks/2026/03/targeted-advertising-g...
https://www.npr.org/2026/03/25/nx-s1-5752369/ice-surveillanc...
Mossad would love to know who to de-bank for criticising Israel, United Health Care would love to know who to deny coverage to based on remarks about their back pain.
"Criticizing Israel" has moved from edgy subversive to lamely pedestrian in the last few years.
There's no great secret that Mossad needs to unearth by spying on you watching tv.
https://en.wikipedia.org/wiki/Telescreen
Much to my surprise I found out that many modern TVs do in fact come with dev mode that allow some sort of screen capture.
Safe to say I turned off all the "allow metrics and market/dev modes" and have been happier since.
EDIT> Incase anyone was wondering I did some more research about my model ( im NOT a TV guy ) and came across this regarding what screen content could technically be passed remotely: "Most probable raw grab: ThinQ/SSAP on the LAN after pairing — ~960×540 JPEG. Live Plus/ACR: most probably sends a fingerprint, not a retrievable raw frame." No idea what it means but thought it might be relevant. Remember Im saying in my case it was a coincidence.
But yes, after turning a bunch of unnecessary default options off, my TV never restarted again just as I was making a clutch moment.
So in summary - remember it could just be related to high action moment fps drain, heat, high intensity stuff making the nintendo switch2 compatibility cause a kernel affected restart etc etc etc ( which is documented via the HDMI protocols ) which make it SEEM like something weird is up, but it turns out its a related thing thats not that sus.
Both games weren’t particularly intensive, the one i remember last was divinity original sin 2, but i think both games ran on unity.
Performance mode mostly fixed it, but blowing out several years of dust from the vents properly sorted it out.
Normally they show a warning, but i just got a new tcl, and it’s warning is very short leading to shutdown if you don’t pause quick enough to reset it
My LG tv post-update is never allowed on a network and it will never be updated again. Hopefully it never breaks…
Details?
> Only a matter of time before they ship with cell modems
I do wonder about the hackability of this. Will it be a purely telemetry connection or will it be able to stream video via that connection as well? (not that data costs as much these days as it used to). Can we piggy back the rest of our internet data on this connection? LG TV as modem/router?
Will they include GPS, so they can also connect your home address to the profile they're creating on you? Location-specific advertising value would make that answer: yes!
GPS is probably unnecessary since mobile phones are constantly mapping out WLANs. You can get a decent approximation of GPS with just a wireless scan in most places.
I saw a previous conversation here where someone said they were able to “repurpose” a similar IoT modem to get some free data, but the modern chips are soldered on and tightly integrated, so it would be harder to reuse unless you get root on the device. I think they use eSIMs stored in a secure element in the CPU.
Consumers will buy it if they're told they "never have to worry about an over the air TV antenna again" because it has a magic 5G antenna in it!
See “datacasting” for data side. Would be 1-way so hard to know how many eye/ear balls get the noise; I mean; ad.
https://developers.google.com/maps/documentation/geolocation...
https://wigle.net/
I’m considering opening mine and taking a desoldering braid to both the RJ45 and wireless antenna solder joints. This might break the TV, but at this point if it does I’m ready to just throw it in the trash and find a commercial display.
I bought a television. I didn’t buy an invitation to be watched in the name of surveillance capitalism and until America gets its shit together with data privacy and consumer protection laws this is just going to continue happening.
I haven’t had a chance to watch this yet, but I did watch the preview and all of Steve’s latest work has been great so I’m sure it’ll be great.
Or what I am trying to say: Everybody has devices which have the potential to spy on you.
Unless your first name is Richard, only travel with open source hardware and software, and you have to ask someone to lend you a phone if you want to call someone even when you are at home.
Of course, the AVR will be able to snoop and send what is available. Any smart fridges, ovens, appliances, whatever can. Doesn’t mean that they or should. Also doesn’t mean we should just lie down and give up.
examine your network when you plug a roku in. then read their privacy policy if you want to see someone give LG a run for their money.
then there's our pocket PCs...
and don't forget about the biggest customers of this "advertising" data.
https://www.npr.org/2026/03/25/nx-s1-5752369/ice-surveillanc...
https://www.eff.org/deeplinks/2026/03/targeted-advertising-g...
My LG is completely offline and I'm using an nvidia shield to display any content, but I'm thinking maybe I need to go the extra mile, there nothing preventing an android tv box to do the same.
For far too many options, see this massive sheet for Kodi support, including newer formats like Dolby Vision and HDR variants: https://docs.google.com/spreadsheets/d/1Uyuw_1dADsRw7u1LGW6q...
Overall I am pretty happy with Kodi on my Android box. 90% of the content is streamed from a local Jellyfin server, so I can't comment on how well it works with DRM media. It occasionally [1] seems to hang, requiring a power reset. The next time it does, I will hook it up to a smart plug to simplify that as well. If you are into tinkering, CoreELEC is based on Linux and you have some basic tools already installed with more available from the addon repos. I have SSHed into LibreELEC to debug network issues with iperf and on a previous iteration to kick over Kodi with systemctl restart.
[1] gonna say less than once a month, I don't remember when it last happened
Are you sure? They will seek out open WiFi and other neighboring LG TVs as relays.
But better watch the whole video. Then get snarky again ;)
Sent from iPhone (for now)
I just didn't want to buy any TV that was available 8 years ago because they all seemed invasive to me.
I don’t really watch tv, but my wife would want something somewhat modern.
I'm not sure about that. Although this reporting is aimed at the everyman, the problem they describe is far more impactful for elites and corporations. This is pervasive violation of their personal, corporate and legally privileged privacy, and is a vector for systematic corporate espionage. So I suspect US Senators will soon get phone calls from donors really upset about this.
:pray emoji:
Definitely need to find a powerful-adjacent group that could be damaged by the kinds of leaks these TVs represent.
But I am also practically certain, that, eventually, any pile of data will attract ideas you do not want attracted.
If your position is "We do not want these kinds of stuff to exist/happen", then we are.
If your position however is "Witchhunts are fun, and decisions and dialogue should be driven by emotions", then indeed we are misaligned by a few centuries.
Wait what?
You don't? What?!
I want action. I do not want there to be a microphone array in my TV that may or may not sample at random times and forwards that data god knows where.
And to achieve that, I believe that we need to look at the systems that brought us to this outcome.
Are you a bot designed to disrupt conversations or just doing a good imitation of one?
There are many, many places on the web where performative outrage as in-group signalling is cheered, but, ideally, we also have some spaces where we can think and derive solutions.
By splitting the spaces, people can get the emotional validation they crave, while we can also have a workspace to make things better and reduce the need for that validation in the first place.
Which is.. a dumb statement, but also just the usual social media outrage one-upping in lingo that passes the letter of the law of HN.
Effectively, the user just said that things are bad in response to an implicit "let us examine why, how, and what to do about it". Which is known, but unhelpful and derailing.
And.. somehow also hinted at that I'd not be aligned enough, because my definition of ill-intent being based on intent is not shared.
Anyway.
Having said that, you might be right given the follow up to you
The head of LG ads was banned from serving in a public company for 10 years by the SEC for fraud...
They hacked the TV OS, then used the TV UI to do a web search with voice-input and observed (still on the UI!) that the voice input didn't stop immediately on silence but kept extending the search prompt with everything said [0].
The OS-hack was irrelevant for this, the whole sensationalism that a listening process is running (and therefore the device is listening to everything) is just drama added to the sober fact that someone started voice-input, the input field is still displayed on the bottom of the UI and keeps getting populated with new input.
There is an important message in this about security hardening, privacy, data protection, but this conspiracy theory that everything is made to spy on you is not helping...
[0] https://youtu.be/6IFVTcM28KA?si=OCmfai2KXSaQt1Bk&t=2958
Or rather I wish Louis would limit the "bulldozing" persona to the context in which it is necessary instead of all contexts ever at any time.
No issue with people being friends. Just issue in standards deteriorating.
___
Is this how Twitter felt like for journalists back in the day? You see a story, and you think "ah yes, that guy's signature"?
End me.
Have you actually looked at what is being discussed? There is no conspiracy theory, these are simple facts. Just about every electronic device is made to spy on you in 2026. Thinking otherwise is naive, at best.
You've accidentally proven my statement: If you're not specific, you're not helping.
Oh I made no such claim whatsoever. My complete statement was this, in context of the original research the article is based on:
"There is an important message in this about security hardening, privacy, data protection, but this conspiracy theory that everything is made to spy on you is not helping..."
To translate:
It's important to raise and emphasize matters of security hardening, privacy, data protection, and there's alot to raise here.
But doing so by implying broad malicious intent on even the most trivial use-case observed on the device (like user-initiated voice-transcription, as I also elaborated as an example) is not helping to emphasize the actually important findings of that research.
Meanwhile, you started a broad strawman-argument "that anyone who believes we live in a surveillance state is misguided". You need to find a opposing position to argue that, you won't find that with me...
It's only meant to spy on you in the way that won't get really bad viral press right now. If it spies on you in the way that people notice and object, it was clearly a honest mistake.
https://www.sceptre.com/TV/4K-UHD-TV-category1category73.htm...
With no real influx of 8K tvs one of these will last quite a while until you need to upgrade.
I hope someone uses their free time to hack the OS and offer a clean and simple interface to make it a “dumb” TV.
There's also a fair bit of arrogance from LG: "We own the glass..." leading to this great piece of marketing:
"within an LG TV household we can help extend the ad campaign footprint to the other devices in the household" (at ~14:11)
Advertising is a mind virus. These people are fucking gross. And this seems to be what all technology companies are turning into. Advertising is the Paperclip Maximiser of the real world.
I recently divided much of my home network into VLANs (with "Entertainment" devices separated for this very reason), and this makes me happy to have done so, but now makes me want to do the same to my in-laws network, since they have an LG TV and I regularly connect various of my devices through their network...
Tangential point: I recall on a previous article someone commenting on their surprise at how good Gamers Nexus investigative reporting was. This seems to be another example. You go Gamers Nexus. Might have to buy a supporter pack.
The execs shown in those clips used some pretty revealing language. I also had to do a double-take when they described a customer's (compromised) house as an "LG household," where they "know who's in [it], we know which devices are there... we know how to extend that reach into mobile" and tell advertisers they can "own the living room."
The sense of entitlement is so over-the-top that it's difficult to distinguish from satire.
They don't care about any effect on the individual people.
They view their thing in a vacuum with some kind of religious fervor. It's a form of psychosis, and it seems increasingly prevalent in tech company leadership and so spreads into those who aspire to be tech company leadership types.
Essentially little difference from running a tor exit node.
My position is that I assume that most people running a residential proxy are not aware that they're running a residential proxy. I understand why people use them and how they're useful, but I just don't think there's informed consent. I think they essentially grew out of botnets, or botnets just rebranded into 'residential proxies'.
Having said that, I'm not trying to convince you to change your position. Feel free to continue to disagree with me.
These companies need to be fined into the dirt. We need a corporate death penalty, to be honest.
LG monitors silently install software through Windows Update without consent | https://news.ycombinator.com/item?id=48956688
LG monitors installing adware on Windows PCs | https://news.ycombinator.com/item?id=48953226
No network connection, apparently the BBC thinks I should use the LG app to watch UHD TV, perhaps they’re in league with LG
Is there a DNS setting in LG? Could it be as simple as switching to a local DNS server on your network running nextdns.io?
The issue is a lot of the TV traffic is encrypted, and given the other issues reported it likely gets a lot worse for privacy advocates. Air-gaps don't necessarily guarantee anything either. =3
Starting at 16:04, they say that they merely claim that the TV has the capability to be used as a listening device. In the first 34 minutes, they don't seem to show that LG are actually recording audio from the surroundings (only from the content playing) and after that they start investigating whether you could record audio if you take control of the device (obviously yes).
So the video doesn't seem to support the claim in the article (edit: linked in the merged submission!) that "LG smart TVs continuously [...] log microphone audio while appearing to be turned off".
Of course, all the stuff LG are actually shown to be doing is bad nevertheless, particularly the "Automated Content Recognition".
> So the video doesn't seem to support the claim in the article that "LG smart TVs continuously [...] log microphone audio while appearing to be turned off".
While it is a bit unclear as to whether the logging and transmitting of audio is happening[1], without hacking the device, they were also quite clear that they made it extremely difficult (if not impossible) to MITM certain encrypted communications on their consumer devices. Combining that with claims they make about advertising makes LG's actions highly suspect.
While the video is quite clear that they are not saying LG is doing this (for legal reasons), the set out to prove the capabilities are there and the privacy related configuration options are very weak. For example: the microphone switch only controls one of the onboard microphones. Even if it physically cut off all of the microphones, there are other vectors that could only be software controlled (such as voice enabled remote controls).
Either way, whether it is LG or a third party, the capability to log and transmit audio can certainly be exploited.
Perhaps it is time we start considering whether we should do something just because it can be done. That is to say: do we really need to control a television by voice, or have other features that require a microphone, just because adding a microphone is cheap and there is enough compute to process the data?
[1] I got the impression they were claiming that the audio was recorded and stored on device. They simply could not prove it was sent to LG.
LG's advertising features appear (from what they discover before 34 minutes in and from the clips of the LG execs boasting about their ad platform) to be concerned only with what's played on the TV (and networks, devices, ..., but not microphone audio).
If I'm wrong about this, I would appreciate a timestamp for where in the video they show LG actually storing and transmitting audio recorded from the microphone.
Nothing gets connected to wifi. If temporary connection is required it gets a random one time use guest network SSID and pass that I remove after. (Yes they can collect and send setup metadata during this temporary access period but sometimes it is a worthwhile tradeoff)
But they stopped updating it years ago, none of its apps work anymore and the only "smart" feature that still works is screen mirroring feature. The tv part itself still works great. Not a 4k oled 120Hz shiny impressive thing but the image quality is still great. What I thought was an unlucky adquisition back then turned out to be a pretty good one.
It frequently happens when opening ChatGPT on web.
A lot of the "silent listening" they show in the video is on a TV they rooted. They start recordings through arecord manually. Or, when they show the transcripts from the recording, the AI voice search is clearly visible on the screen and was manually triggered by something.
Now, does a smart TV need all that hardware? Is a compromised TV a security hazard and smart TVs need to learn more in terms of security from modern smartphones in terms of privacy indicators, attested boot and more?
Sure.
But I do not see enough evidence that the TV is actually voice capturing all this stuff on its own, without any notice.
There is plenty of stuff on the video regarding the network scanning, ACR and more that is definitely concerning. And this is something LG actually does by themselves (when you agree to their ToS / privacy policy).
However, I think that mixing the ACR / network scanning in with "let's root the TV and actively start recording ourselves" mixes the narrative of "what LG actually does" versus "what a compromised TV can actually do", and makes it seem like LG is just recording, transcribing and submitting voice transcript automatically by themselves.
This was not proven here. And I feel that GamersNexus is just risking a lawsuit here by not separating these different concerns clear enough.
PS: I do have the TV connected to wifi for software updates (on a pi.holed network)
How disrespectful one can be towards its customers. I am honestly disgusted by such behaviour. I know the cheeky confidence biz talk, but is that really what you want your customers to hear? And what about the guys making such disgusting business possible. Is that what you want to build?
We have sugar-free, lactose free I want Smart free devices!!!
TV with smart features: $999. TV without smart features: $1,200
should we all report this illegal behaviour and contract terms?
When I said 55+ I was talking about the whole size category larger than that, including 65, 77, etc.
If anyone could recommend any dumb TV with good panels in EU, you're more than welcome.
- Samsung 40 inch Odyssey G7 (G75F) Series WUHD Curved Gaming Monitor (https://www.amazon.com/Samsung-Odyssey-Curved-Gaming-Monitor...) -- $699.99
- Acer Nitro 49 inch DQHD 5120x1440 Curved 120Hz Office Monitor (https://www.amazon.com/Acer-Nitro-Gaming-Monitor-UltraWide/d...) -- $549.99
- Acer DM431K A 43 inch Class 4K UHD LED Monitor - 16:9 (https://www.amazon.com/acer-DM431K-Class-UHD-Monitor/dp/B0F3...)-- $334.20
- LG 37G800A-B 37 inch Ultragear 4K UHD (3840 x 2160) Curved Gaming Monitor, 165Hz, 1ms (https://www.amazon.com/gp/product/B0FS3LV3WG) -- $598
- INNOCN 40C1R Ultrawide Monitor 40 inch WQHD 3440 x 1440p 144Hz (https://www.amazon.com/INNOCN-Ultrawide-Monitor-FreeSync-Pre...) -- $479.99
Just don't ever let it connect to the internet.
Unfortunately, you can't have one without the other. The best, image quality -wise, TVs are all "smart".
So yes, you can just walk into the Electronics Store (Best Buy) and purchase a dumb TV.
[0] https://andybeaumont.com/post/dumb-tv/
I know I’m not the only one so I’m sure LG are experiencing the results of consumer democracy.
Can anyone recommend a non-spying TV brand or a model? (Modern)
The best option is display only units made for businesses, like what they use for restaurant menus, but those are usually twice the price of normal tvs because they're not app subsidized like smart tvs are.
What I ended up going with was Hisense. They ship with Google TV, but it's disabled by default. On first power up, it asks if you want to activate the Google TV features, and you can just say no. The thing then runs like a basic display.
Instead of a TV set, I use a very big monitor, which is connected to a mini-PC (an old Intel NUC with Linux), which also has a TV tuner and an infrared remote control receiver. Besides just showing a TV channel, a mini-PC can also record it and it can play any other kind of movie or music files, or it can stream some video from the Internet.
BTW corporate meeting rooms with smart TVs...shouldn't have them.
But this response is like when there were meat safety issues in the US and some people said "then buy another brand". People didn't buy that argument (for what I hope are obvious reasons), and so regulation was enacted to protect the public.
It's clear that this problem must be handled with regulation, too. I'm all for markets solving problems, but I'm also for recognizing when it can't. I haven't seen the whole video yet, but I have a sneaking suspicion that it's NOT just LG.
Do they make audiophile grade aluminum foil yet? Seems like a neat business opportunity for customers like me
A comparison of a dumb 4k panel vs the equivalent "smart" tv for example>
https://www.youtube.com/watch?v=8duCxY-gnZ0&t=5s
You'd be better off with an android tv which you can poke at using adb and disable services. Maybe even root it. And install alternative software like smarttubenext.
Unfortunately there very few Android based TVs left. Phillips recently switched to Titanos, Samsung has tizen, Amazon has a new OS. I think it's just Sony that's left on android now.
Just don't by anything from LG. It's easy.
Disclaimer: I haven't tried any of this myself, I've just been looking into it as I am/was considering buying an LG TV.
I'd just open the TV and yank or desolder the mic out. Or use the TV as a dumb monitor -- don't connect it to WiFi or Ethernet. And use an external Kodi/AppleTV/whatever-rocks-your-viewing-boat
This is not sufficient (for some of these devices) - they will automatically connect to an unsecured hotspot.
If internet is really required, I'd personally flood such an LG tv with fake data - add a raspberry pi to provide it with looped audio streams for the microphone, fake bluetooth devices, and so on. But it's still probably a drop in a bucket.
LG TVs aren't the only ones spying on you [video]
https://news.ycombinator.com/item?id=49575176
And many government officials' households, too.
Just saying.
The thing I'd like is if the remote didn't have 4 buttons for crappy streaming services I will never use, but instead had 4 buttons to select the HDMI inputs directly; but no, I have to press a button, wait for the stupid laggy UI to load, navigate or point and click at input I want, then do the same to the preview window. A tedious pain in arse for basically the one main thing I use the remote for. It annoys me no end, and it seems to me that the last thing LG care about is the UX; they've put all their efforts into underhand and user-hostile profiling.
I also have a Roku Ultra for streaming, which I very rarely use. I don't expect they treat their users any better and they use ACR too
But I guess they still sell my data. I wish they would flag the data of rational people like me as "worthless", and not sell my data.
The choice between privacy concerns and ineptly coded network stack is tough. But that's the choice we're forced to have
> We value your privacy
Shares my browsing info with 1745 "partners" with no clear way to opt out (which ought to be opt-in by the way to be compliant with ePrivacy and GDPR).
Anyway, the EU's reasons seem to be entirely legitimate to me.
I don't want to be cynical but face it, the EU really only cares about things that generate money for themselves or big internal market players under the disguise of consumer safety and privacy. Obviously that also comes with some good effects but the perverse incentives are enormous from which we must not be blinded by ideology and warm feelings of our politicians being good and working for the people and the common good.
https://samba.com/
Such a pity the name is associated with freeing proprietary software.
The _real_ samba: https://www.samba.org/
Even if the manufacturer doesn't do something evil, they may have an exploit or allow 3rd party apps that do whatever
Garmin literally keeps the microphone on 24/7 listening for "OKAY GARMIN"
There should be a consumer law that any device with a microphone must have an LED physically in series so that if the mic has power, the LED is lit, not software control of the LED which can be disabled. Europe might do that someday but unless California does it too it will never happen in USA
Vizio TVs were caught taking screen grabs and phoning those home years ago.
I want the public to get upset about this.
Also, can anyone articulate exactly what data the TV is scraping about your other network devices? IP, name, what else?
You must set your TV to a different standby mode and enable LG voice control.
When you do this, it very plainly tells you that it can listen with the screen off so you can control the TV with voice.
Failure of User Awareness, not some nefarious spyware.
Nothing is going to change until people are that enraged by it.
> Not long until companies partner with Amazon and others to send traffic automatically through their near-by devices like smart speakers, disconnecting will be impossible.
Not surprised if this is happening already. I don't want to remove radios out my TV..
> Samba, a media intelligence company have several partnerships with manufacturers to take screenshots and collect metadata.
Viewer analytics are valuable to companies like Samba, they aren't the only ones. Laws ASAP, these companies will lobby hard to stop anything of the sort.
The enshittification of TV ownership and usage through smart TVs and the apps and other software that runs without user knowledge is a huge problem wherever these devices are sold. The TVs track and log every device on owner networks - smart watches, thermostats, smart phones, etc, anything that uses wireless or that accesses the internet from inside the home.
I am so glad that I have avoided "upgrading" our TV, almost montly, for years now by simply sending all the Best Buy texts to spam or deleting them. The best way is to opt out of Best Buy communications and after watching that video I will do that.
Our TV is a Panasonic plasma TV from 2012. I need to exit the last streaming service that we subscribe with and that will get it set to an OTA device used when weather int he area is bad enough that having that real-time local weather channel adds value.
From the video - RCE vulnerabilities could allow anyone to drop code on your TV that enables them to use it as a surveillance device. Lots of microphones in the device and no way for the user to disable them. The TV is listening all the time and, using the very sensitive microphones, can detect and record voices in conversations happening in other rooms more than 60' distant. They are effectively whole-house listening devices probably using MEMS microphones due to excellent sensitivity of the devices. Users are fingerprinted and everyone in the house can be identified, even children and those who are frequent enough guests to have been ID'd. Everything that happens triggers the recording.
I suspect Amazon's and Google's devices were the same with their voice triggers. LG does not allow the user to disable that functionality even after the user has disabled it (apparently) through the deeply buried menu option.
LG pushes updates to TVs that improve the tracking ability for LG and their "partners", which includes Microsoft through MS's ownership of Nuance. LG tried to separate their data collection/advert business to circumvent restrictions on ...
Man there is so much there. Fortunately the only LG product I own is a dumb monitor. I will be contacting relatives to offer advice about what to do with their smart devices, LG or others, so I know this starts another round of investigation for me.
No Samsung or LG at my house. Almost done canceling subscription-based "services" like TV content and gaming (XBox) stuff. I don't have software subscriptions so that's great. And, I should be finished with MS OSes pretty soon and flipped to Linux on new devices.
A lot of the shit and shit infrastructure that some of you build is destructive. One day, you will get your just desserts after shafting people with Binding Arbitration agreements, huge TOS and Privacy Policies, and other types of enshittifying end results.
10+ years later, this is their response. They have learned a large majority of people just don't give a shit. We are sheep. A majority of people just want "cheap" shit, no matter the cost.
This world is cooked man. Need an asteroid to wipe this planet clean, bro.
But we're allowing 1000x worse things, because what, there's a vague line about it buried deep in some EULA, which means laws no longer apply?
Lets treat them the same. Raid LG, seize all of their electronics, at least in the US (other countries are encouraged to do their own raids), arrest the executives, and after they're all in jail, and digital forensics are poring over their products and servers to find what else they did, they can argue in court how actually all these crimes are legal.
It's only fair.
Lawyers: If it is true that the company is secretly recording voices when the device appears to be off, and then uploading the recordings, does that sound like a felony in many US states?
(And a felony that is bumping into different laws than the "unauthorized computer access" ones that tech industry has been getting leeway with?)
It must be eradicated.
Do everything in your power to destroy these companies and their immoral business practices.
Newspapers were leveraging sensationalism and attempting to capture attention by any means long long before targeted ads were a driver of revenue.
I'd guess there are plenty of pre-newspaper examples as well.
A handful of newspapers that controlled 95% of the information was much more of a "precision guided missile", in terms of ability to control information, than social media is today.
(That's not to say it's good today, it's terrifying, but at least it's possible to hear different voices, including voices on the ground)
people massively underestimate how insidious having millions of data points about a person is, these companies are literally modeling your behavior
You can see that by looking at more minor or fringe social media sites. Public "liking" is literally all it takes for people to degenerate into performativeness, sensationalism, grandstanding, misinformation, etc.
To associate contextual advertising based on large scale demographics and location with spying, lying, cheating and thieving at an individual level, is a great example of this in real life.
In the old days, the tabloids were obvious. The sensationalism was easy to identify and passive in its voice. They sat on the end caps of grocery stores, far away from the News. TV news was regulated and there was a strict ethics code in place. Today, all news is tabloid as they all chase attention. They have all become the Weekly World News and as a result, we have clowns and ignoramuses running things.
And people fell for it. They actually fell for it...and continue to fall for it.
That is why it's a cancer. Ad tech eats everything in its path and destroys everything good in the process.
When you cannot tell the difference between fact and fiction, you have lost the plot.
This is our key point of disagreement, not any of the rest
I strongly disagree that the "Real News" of yesterday was "good information" as I define that. It served the biases of the publishers and writers. It was sensationalist. It strongly censored and suppressed politically incorrect viewpoints, to a degree not seen today. The Overton Window was miniscule. The ethics codes were largely self-serving and inert against its major flaws.
It seems that you may be conflating journalism with news. They are not the same thing.
Curious wow old you are and where you grew up? When did you and where were you when you experienced this singular market bias.