12 comments

  • adithyassekhar 49 minutes ago
    I think the author took the wrong message from the video.

    His arguments are all

    - yes everyone does this not just lg; :)

    - yes it can be used to track the user; but unless you literally go into lg ads hq, you can’t say they don’t

    - they rooted to trigger this; well the os and system apps don’t need root, we need it to observe.

    If the author is here please consider these as the reasons to why an LG customer would be mad.

    - They did not knew LG has an ads subsidiary, whose CEOs and executives constantly go on investor meetings claiming “they own the glass”, “they own the living room”, “they own the network and devices” in the “lg household”

    - if the above was said by lg tv division it would have still stung less. This was said by an ad company they didn’t knew existed nor did they agree to be associated with when they bought a home appliance.

    Stop focusing on the technical details, look at the larger picture.

    • shellfishgene 3 minutes ago
      I was also a bit disappointed with the video. I don't usually watch the channel, but the previous video on LG with the McAfee thing was good. This one, well it has important points and exposes some very valid concerns. However I mostly agree with the linked article, it does not properly spell out what they actually can prove, and what's just conjecture. The video gets lauded as investigative journalism, I think the technical details are important to get right and make clear to non-tech people. A normal consumer would have no idea how to really judge the danger to their privacy after watching this, they'd come away thinking that for sure someone can listen in on their living room.
    • rickdeckard 10 minutes ago
      I agree with the author, the point is that the way the video and the overall research was done, the entire message was diluted too much.

      There is substance in what they did. But they should have worked with an actual journalist to frame this properly and create pressure on the overarching topics.

      If a TV company (LG or ANY of the others who have Ad-subsidiaries) needs to respond to this video, they can easily reframe the whole topic.

      The most blatant example is that they demonstrate in the video that this TV, which has a built-in microphone for voice-control, that can be switched off with a mechanical switch:

      1. Will record your voice when you ask it to transcribe your input to a textbox

      2. Will process your voice to create this text it shows, as visible on the logs of the rooted OS

      3. Will SHOW you that it's transcribing your input on the screen.

      This is weakening the whole story.

      --

      In HN-terms: It's a constant-power, constantly-connected IoT-device with lots of sensors and huge compute-power, located in the center of your home.

      There are big topics around this that deserve a huge spotlight, which apply to ALL TV manufacturers:

      a. What data is actually being collected about the user, and what is done with this data?

      b. How well is security handled on the TV to ensure no malicious usage?

      Repeatedly jumping to the conclusion during the video that LG specifically is collecting ALL this local data to spy on you, without clear evidence, this just gives LG an easy way to respond and every other vendor enough room to distance themselves from the whole story.

  • Retr0id 1 hour ago
    > If you root or jailbreak your devices, you've, by their very nature, broken their security.

    > If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.

    There are ways to remotely jailbreak LG webOS TVs without user interaction, using the same (or similar) vulnerabilities you use to root your own TV voluntarily.

    The main reason tools like https://rootmy.tv are prefixed with disclaimers and require user interaction is because we're being courteous, not because they're technically necessary. (source: I own the rootmy.tv domain)

    • froddd 1 hour ago
      Most of what I’m reading on rootmy.tv says the vulnerability it exploits has been fixed. So, if one were to keep software up to date on their TV, there is an improbably small chance it can actually be remotely jailbroken — am I reading this right?
      • toast0 18 minutes ago
        > So, if one were to keep software up to date on their TV,

        I presume LG is like most vendors and stops issuing updates for older models after a while. It's pretty hard to keep software up to date when the vendor stops issuing updates.

      • Retr0id 1 hour ago
        The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining. There are also more up-to-date rooting tools beyond rootmy.tv.

        The security posture of webOS is absolutely terrible, at least, it is in the way LG deploys it.

        • rickdeckard 56 minutes ago
          > The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining.

          But vulnerabilities that can be remotely exploited without user interaction (CVSS grade 9-10)?

          • Retr0id 54 minutes ago
            Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.
            • minetest2048 46 minutes ago
              I'm guessing that you're exploiting some sort of exploit (buffer overflow???) on the DVB-T demodulator
            • rickdeckard 42 minutes ago
              > Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.

              So no responsible disclosure, I see.

              Not knowing any more details, it still sounds like you'd still need the user to tune to the actual frequency on the correct receiver (to cause some buffer overflow?). But then still there's no internet to do anything. So you'd need some very specific f/up exploit to then change local settings on the device I imagine.

              Either way, would be a great opportunity to demonstrate this in a video, now that there's attention on the topic, to further amplify the pressure on LG's "terrible security posture" as you say.

              • Retr0id 35 minutes ago
                > So no responsible disclosure, I see.

                Huh?

            • delta_p_delta_x 45 minutes ago
              > only RF down the TV antenna input

              Holy shit. RF to zero-click exploit is a new one. I guess digital-everything wasn't always a good idea, this probably wouldn't ever have been a problem with analogue antennas and CRTs.

              What are the people at LG even doing?

              • Ekaros 40 minutes ago
                Teletext was available in analogue times. So I could well imagine there to be a possible avenue of exploits with it too. Would take a bit of time, but I see no reason why wouldn't some data result in a incorrect handling.
      • franga2000 32 minutes ago
        These vulnerabilities only get fixed because they're used by public rooting tools. If blackhat hackers found them instead, kept quiet about them and used them carefully, they'd never be fixed.
      • LoganDark 1 hour ago
        I read the documentation and it appears that the only reason it doesn't still work is because development was "postponed for a few months" back in 2021. Presumably there is still the possibility of exploits on the latest versions, it's just nobody's bothered yet.
  • rickdeckard 59 minutes ago
    Thanks for the write-up, it reflects my own impression of the video.

    The video is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across.

    They should have decided to set the focus on a specific area and then present every finding around that, i.e.:

    1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.

    2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.

    3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.

    All the points and scenarios in the video might be valid, but they jump between those scopes and imply that its all the same, weakening the whole investigation.

    If I'm LG and forced to respond to this, I can easily focus on dissecting the voice-input topic as a mere demonstration of the feature and how rooting the TV beforehand just showed the local process of handling it, steering the narrative away from the (IMO) much more important topics...

    • jeffbee 33 minutes ago
      Yeah if GN wants to keep my attention on this topic they need to edit out all the stuff about normal Wi-Fi stack behaviors and normal local device discovery behaviors. They didn't need to pad their feature-length video with these non-issues.
  • taylorfinley 50 minutes ago
    This reads like a PR crisis management firm planted article. it probably isn't, but it reads like one. It muddies the waters with vague implications and suggests we cannot infer anything from encrypted packets. If your screen is showing content sourced over HDMI and the packets are heading to the ACR endpoint, I think it's safe to infer HDMI is being ACR'd.
  • pmlnr 41 minutes ago
    > If you root or jailbreak your devices, you've, by their very nature, broken their security.

    Wow. Please stop spreading things like this.

    Not having root means not owning a device you paid for and have in your home.

    • p0lychromatic 11 minutes ago
      I know people here do not want to hear it, but it is a very two-sided sword.

      Of course root allows you to tinker with your device and make it run what you want, but:

      - Rooted devices make devices unpredictable. As shown in the video: How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?

      - Re-selling: How do you know that TV you bought is untampered? How do you know it does not have software with malware installed that steals your credentials?

  • badsectoracula 1 hour ago
    > If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.

    Do you actually want a channel with 2.66 million subscribers to show how to get remote access to TVs used by millions of people? :-P

    • Krutonium 1 hour ago
      I'm pretty sure they DID mention that they can remotely flip settings. So that's a thing for sure.
    • jaimex2 1 hour ago
      That would be against Youtubes terms, the video would get pulled.
    • Arcuru 1 hour ago
      demonstrate != explain?
    • supriyo-biswas 56 minutes ago
      They do show using https://github.com/raws0kil/jsbro-autoroot to get root access. For anyone interested, that pointer is enough, I guess.
  • bob1029 1 hour ago
    > What am I meant to take away from this? If you look at other IoT devices, they’re going to show the same thing. But here it’s presented as bad. Why?

    The influencer economy is a bit soaked these days. You need to crank up the stakes to keep the viewer's attention.

  • fulafel 58 minutes ago
    Seems incoherent. What exactly is the bad idea and why? Are they rediscovering "don't run stuff needlessly as root"?
    • p0lychromatic 25 minutes ago
      The bad idea is that by rooting, you can (of course) turn your device into a 24/7 surveillance device that sends voice and video data everywhere.

      That does not mean that LG does all that by default.

      • nokeya 10 minutes ago
        Because of course it does. You are fighting the wrong side, they should proof they are good, not you defend them.
  • LoganDark 58 minutes ago
    They rooted the TV to study it. They're not saying you're in sudden danger of attackers rooting your TV and running commands over SSH. They're saying there's evidence that certain data is collected when you wouldn't want it to be, and there are any number of potential vulnerabilities that could provide hackers access, on top of LG potentially having access as well which you also probably wouldn't want.
    • p0lychromatic 28 minutes ago
      They still run the audio recording manually through SSH and then claim that your TV is spying on your private conversations "silently".

      Otherwise, they start a voice command service (clearly displayed on the screen) and then say your TV is recording on your conversation. Like duh, of course my TV starts recording voice when I use voice commands.

      And of course you have to trust LG with their TV and (not) having access. That same logic applies to every different company.

  • rbanffy 28 minutes ago
    Now I want to build a cluster of rooted WebOS TVs.

    I always say any serious computer needs blinkenlights and a smart TV has literally millions of them.

  • ChrisArchitect 54 minutes ago
    Related:

    216M Spy TVs – The LG Smart TV Problem [video]

    https://news.ycombinator.com/item?id=49592375

  • lovich 54 minutes ago
    > Now, what he’s showing can be pretty scary. I wouldn’t want any attacker to be able to record me without knowing. But it’s important to remember the context here: earlier in the video, Wendell rooted the TV. He has full access to everything on it. To run those commands and programs, he had to log into WebOS via SSH and run them on the device. He didn't show remoting calling those commands, nor was this done on an unmodified device.

    > If you root or jailbreak your devices, you've, by their very nature, broken their security. If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.

    What is this authors point?

    LG doesn’t need a root exploit to get this info because they made the fucking thing.

    I read the article and then grepped for “Texas” to see if I missed it. The author never mentions the fact that this data collection was only found out initially because of a Texas government lawsuit that LG settled on by agreeing to give “informed consent” to users about data collection and then the warnings started popping up in unexpected places.

    Is the author arguing that jailbreaking your device to find out what the manufacturer can do to gather data on you is dangerous because I don’t know, questioning your corporate overlords is bad or something?

    • p0lychromatic 26 minutes ago
      Some attacks shown on the video (like the "silent" voice recording) are initiated by the people in the video manually running those commands via SSH.

      This is the major issue with this video: It mixes stuff done by LG (ACR) with stuff done via rooting (audio recording). And now people think LG is 24/7 recording your conversations and uploading them somewhere. This has not been proven.

      • newsclues 13 minutes ago
        Fresh account defending a corporation.
        • p0lychromatic 6 minutes ago
          1. Ad hominem. 2. No, LG is not perfect here and their TVs are bloated as fuck and they do questionable things privacy-wise. However, that still does not mean that they listen on every conversation, as shown in the video.

          That nuance is important if you value good journalism.

          Otherwise if we're just our here throwing random allegations because "corp bad", might as well say LG 's TVs are turning the frickin' frogs gay.