After researching a new TV (where it only needs an Apple TV, no so-called smart features for spying purposes) the three contenders were Samsung, LG and Sony Bravia (the higher end models). Samsung was the least trustworthy, having played games with firmware updates and adding telemetry, LG was medium trustworthy, and Sony seemed the least likely. It looks like that heuristic was correct. For the Bravia, I put it on wifi just once temporarily to upgrade the firmware when I bought it, and I'm leaving it disconnected.
It can't just magically connect to an openwifi and update its firmware to start telemetry. It would need a new firmware to even try that.
Folks, never update a TV firmware unless it's necessary.
I've bought an LG Smart TV 5 years ago, read t&c where I was supposed to grant them any data they wanted, decided to disagree and kept all network functions disabled. I was ridiculed by my friends for that. At some point, I thought - maybe I'm really crazy to do so? Who am I, a caveman, a luddite? Oh well, I'm not. Not a bad tv though, many HDMI ports!
I have a similar reaction from folks when I don't trust services/devices. Most telling moment was when I refused to upload my license to LinkedIn because I lost 2FA (token on phone, phone destroyed). Microsoft assured me they would "delete the license as soon as it was verified". I've written too many software systems for too many companies, and I do not believe them.
That's from 2024, but we just had a larger breach with IDScan this week.
Sorry for the digression, but the common thread is how much to trust these companies, and my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want. Some paranoia is warranted, I think.
My apartment complex came to install keypads and centrally managed smart thermostats and I would not let them.
Thankfully my lease was old enough that I was able to argue against it. I don’t want a 3rd party company tracking my habits, and I don’t want some manager boiling my pets alive while I’m gone because they decided they think our AC is set too low.
Nah, you're not crazy. I'm also someone who actually reads terms documents, because I find that they're often the only thing that will be truthful about a company's intentions.
And keeping it completely disconnected from the internet should be the default, in my opinion.
There is absolutely no reason to read those contracts any more. As Louis Rossman keeps pointing out, most of them now include the ability for them to change terms at any time. That's basically the null contract.
Since the legal system has once again failed to protect users from corporations, it's up to users to use technical means for self defense.
Depends on jurisdiction, just because someone wrote something in a contract doesn’t mean it’s binding.
In Poland/EU we have an (ever growing) list of forbidden clauses that even when written and signed by consumer are null and void. And I think these can be enacted retroactively - when corporations invent new shady clauses, government steps in and tells them these are invalid.
This helps to even out the consumer-corporation field.
Interestingly, in Brazil and I'm sure in some other legislations, those contracts are essentially void because there's a presumption the average person does not have the time, patience, or ability to understand every clause—so they are by definition unable to agree to their terms.
I'd love to have a similar standard applied in the US but I'm not holding my breath.
Which doesnt work. LG tvs will scan for availible networks. Someone setting up a new router within range briefly disables encryption and "your" tv will jump on that network and transmit all the stored data.
I never understood why any of the smartness had to be built into the TV in the first place. Sure, it's useful for the first year, and then the seriously underpowered hardware they installed into it will have trouble with just about anything.
I bought a Philips Ambilight OLED TV probably over 8 years now. Brilliant tv, great quality, I still see no reason to replace it at all. But its built in AndroidTV is garbage.
Because it’s extremely profitable for them to serve ads and sell PI. Kind of like how the airline industry makes more money off credit card shenanigans than actual plane tickets.
> Capitalism cannot survive when products last a lifetime.
This is totally backwards; capitalism would do fine in such an environment (in the same way that evolution does fine in an environment where organisms live more than just a few seconds; the whole reason we have the notion of a "lifetime" is that our germ line comes from a long line of ancestral DNA that made organisms that outlasted their competition.)
Individual companies might have to hustle to innovate or die, but that too is good for capitalism.
Only good until the device starts using a neighbor's LG TV as access point, without telling you, for the sole purpose of upgrading itself and sending this "telemetry".
"Watch this two hour long video" is not a particularly useful reply. If you think the TV can exfiltrate your data without an internet connection then you should be able to explain how it could do that in your own words.
Just because you didn't allow it on your local WiFi doesn't mean it did not connect to the Internet. Your neighbors might have a guest WiFi it can use. Or maybe it has a built-in cell modem. Your data is valuable, there's reason to put effort into getting it.
They can just start a capture, record to RAM / storage, and retrieve it later when it is reconnected to the network.
Otherwise if it's disconnected, it is still hard to exfiltrate the data somewhere.
Maybe they could get creative via Bluetooth, but then you would need a cooperating device in proximity of the device.
> This. Why would you even connect TV to the network?
I happen to have a NAS with family pictures I like to display. I can (and do) firewall that thing, but then you hit other issues like the apps you need to show pictures and movies in the first place not to install/run.
I've yet to hear of a reasonable recipe to isolate and secure such connected TVs. And don't get me started on Chromecast or other Android dongles, I've no reason to expect better treatment from Google. Some open source hacked-together box, then?
I turn on the device, the app in the upper left is selected and showing some content from that.
The device sits idle, I get drone footage of landscapes.
If I accidentally bump the wrong button on the remote and get sent into the Apple TV (streaming service) app, sure it advertises producte, but in general there are no ads.
In comparison, Google TV's homescreen is giant ads for content on services I don't subscribe to, Roku is at least as bad, Amazon is worse, and Samsung and LG......oof.
Obviously, as an advertising company, Google should have your utmost scrutiny. But as far as I know, their TV boxes don't ACR your content. If they were the only two options, sticking with your smart TV software instead of using a Google TV box would be a privacy mistake.
Typically you will get sambatv or such installed, and technicians for whatever reason tend to click accept/approve during installations. Happened to me n my Google TV thing
What technicians? When my TV was delivered they pretty much just unboxed it and set it on the floor, not even being willing to help mount it, let alone plugging it in.
I've just used an old Intel NUC with Debian stable, a remote mini-keyboard and an automounted Samba share on the network forever. It's no more hacked together than any other computer. I do make the mouse pointer and the fonts real big. No apps required. Don't really need the keyboard except for mplayer hotkey presses - just the touchpad on it; if I need to do something that involves typing other than typing a password, I usually ssh in.
I think people are lowkey addicted to having shit sliding in and out and constantly being advertised to. How do you know what to watch unless somebody is constantly bombarding you with options? If it doesn't look like a star trek control panel, is it really TV?
If you like that, you can install Kodi. I haven't tried it since it was XBMC because I found the interfaces annoying and it had trouble dealing with networks, but I'm sure it's better.
> I've yet to hear of a reasonable recipe to isolate and secure such connected TVs
I don't even try. I overpay for dumb tvs in the present, or underpay for 10 year old tvs pre-Applefication. I've never owned a network capable television, or one with apps. I wouldn't.
edit: if your NAS is a separate box that can sit in proximity to your television, you could probably just run all of this stuff directly from the NAS. They spend most of their time doing nothing at all.
Yes tv makers were caught doing HDMI fingerprinting. There was a story some years ago about how basically all smart tv makers were sending data to an ad network based in China.
Samsung were openly bragging about this on their website some years ago (for the benefit of their advertising partners) but have recently muddied the waters when I check their site again, couching it in language mentioning privacy and other evasive language:
It's (mostly) a US thing; basically subsidizing TV prices with ad revenue. It's how the entry-level companies like Vizio operate, though the "big brand" TV makers are certainly just as guilty here. It's much less of a thing in the EU, where data privacy laws are stricter and TVs are hence (comparatively) more expensive.
As far as I know, they don't literally scan your media libraries; they screenshot whatever you're watching through HDMI (most often cable / satellite boxes), as those devices don't provide the telemetry that normal apps do. This info is used for audience measurement (thing Nielsen ratings), as well as showing you ads that are actually likely to match your interests.
"Starting in 2014, Vizio made TVs that automatically tracked what consumers were watching and transmitted that data back to its servers. Vizio even retrofitted older models by installing its tracking software remotely. All of this, the FTC and AG allege, was done without clearly telling consumers or getting their consent.
...
"Vizio collected a selection of pixels on the screen that it matched to a database of TV, movie, and commercial content
Did you know that no one has implemented it? You might as well talk about packet-carrying fairies in your TV. And of course the Apple TV box it’s connected to will be quite happy to share its network connection with arbitrary crap you connect to it.
But I guess like an xkcd comic, someone is obligated to raise the issue every time TVs come up.
Support in cables is nearly universal, because the same pins in the cable are used for the Audio Return Channel feature that allows a TV to pass audio from its internal apps back out to a soundbar or receiver via the same HDMI cable it takes signals in on from other devices. As far as I'm aware no one has made a cable lacking those pins since 1080p was still the high end.
But yes, support for the ethernet mode as far as I'm aware was never actually implemented in any devices that reached retail availability.
Even if it did support it, nobody connects their TV to their local network via HDMI, they connect it to their PC. And, as far as I'm aware, no PCs automatically start sharing networking with whichever networks they are connected to.
That could of course change. Could be even a nice feature for connecting your TV to the network via your multi media center, if the bandwidth is good.
LG was caught abusing (although it's hard to argue that it isn't intended behaviour) Windows automatic installation of hardware-related software to install adware. Doesn't take too many tinfoil wraps around one's head to imagine them doing the same to enable network sharing (assuming hardware support is ubiqtuous enough).
Their solution to that is to either use the cell phone network or services like amazon sidewalk where they connect in through your (or a neighbour's) internet-connected device.
Not at all, because it uses the same pins as ARC, so the two features can't operate at the same time, and a lot of people use ARC to get audio from TV apps back to a soundbar or receiver.
HDMI Ethernet is dead, it's never going to happen in consumer televisions because it has a hard conflict with a feature a lot of people actually use.
Then you make sure to only use HDMI cables that aren't HEC, in conjunction with not connecting the TV to the internet directly, if you want to keep them isolated.
christ we need to start rooting tvs and start up a open and secure tv os. i never give my tv os internet access i rely on the appletv for the "smart tv" but if what another poster says is true about lg devices looking for public wifi to exfiltrate data then lol time to start pulling tvs apart and shielding their network components from getting a signal
That basically exists, but runs on external hardware: https://kodi.tv/
There's no need for the TV to be anything but a dumb screen that has only "power on", "power off", "volume up", "volume down" and "mute" functions. Most are probably too underpowered anyway to be useful.
We replaced our old TV recently with an LG and are really liking it. We do not let it on our network though and keep networking functionality disabled. It's basically a monitor for our Kubuntu Linux laptop sitting behind it. We stream with Chrome and use a mouse and the TV remote for audio. Once in a while we actually watch something on TV itself too. It'd be nice I guess if the built in TV app had DVR but if it does; I couldn't figure out how to make it work. No great loss there.
I'm still nervously holding my breath for the first disclosure that a TV manufacturer is using Amazon's distributed Sidewalk Network (or perhaps mobile vehicles, cell-SIMs, LoRa) to remotely gather all that viewing data they've subsidized into your artificially-low TV purchase price .
I didn’t care much about data collected but I found that with every update it becomes worse and worse objectively. I had to cut it from in internet so doesn’t get completely unusable
Mine is still attached to the network, but I’ve turned off all the ad/customisation &AI stuff. Seems to work fine, no ads etc. though usually I’m using it simply as a screen for the AppleTV.
I do have it isolated from other devices on my network, though.
Worse, if you watch the GN video this article is based on you'll find the TV can figure out how to leverage other non obvious networks (threads, etc) to reach LG servers. Worth a watch to see how bad this is: https://www.youtube.com/watch?v=6IFVTcM28KA
My in-laws were so proud of themselves. I came home one day and they told me they figured out how to connect my TV to the network so that I don’t have to use my Apple TV if I don’t want.
I had to take a few deep breaths to keep from yelling. I am very happy with my TCL tv but I trust it about as far as I can throw my father in law.
At least with LG you can revoke your consent. I came home to found STT audio recording enabled and I promptly disabled it and lectured the household about privacy.
The sad part about the privacy discourse is that people not only don't care, but they would argue for the invading party. And I am not talking about your average teenager looking for their next brainrot fix, but highly educated and extremely intellegent people!
I've long since gave up trying to talk to people about these issues. Which unfortunately means I'll surrender to exposing myself to this plague to some degree, considering how herd immunity principles apply here as well.
LG TVs have the best OLED displays and the most questionable privacy policy. So I picked best of both the worlds and left the TV off the internet. Apple TV is the way to go for me.
Okay. This is insane. First the monitor that uses a windows feature to automatically install a small helper tool with root permissions and then starts showing adds in certain regions. Now a tv that is actually actively snooping around on top of the known fingerprinting. What else is next?
In the previous topic I got ridiculed for not wanting to buy LG anymore because I could use an agent to modify to strip out the offending bits.
But there must be something better than just keeping to buy things that invade our privacy and homes further and further. Which brands aren’t doing this? Sony? They also announced a partnership for the lower end TVs IIRC.
We need to climb two very difficult hills for there to be any change here: 1. We need our governments to actually start charging companies with crimes, when what they are doing would be illegal for an individual to do, and 2. We need the penalties to be something other than fines, which are ultimately treated by companies as routine costs of business.
> We need the penalties to be something other than fines, which are ultimately treated by companies as routine costs of business.
It's true that fines are nothing more than predictable costs, so maybe an option would be fines in percentage of the incoming of the company: this way it could make a real impact. I know in some north Europe countries the speed limit fines are in percentage on the personal net worth.
I would like to send vast amounts of garbage data to the LG servers. They aren’t being respectful of our bandwidth and data, we don’t need to be respectful of theirs.
This also applies incentives in the correct direction. Their database of customer information becomes less valuable if there’s bad information in it. Disconnecting your TV from the internet doesn’t affect LG, feeding them bad data does.
I like this enough to actually considering buying one to get it to identify the endpoints. Maybe better to see first if we can find it in the firmware update downloads.
Well, it’s a smart TV. I would assume with extreme prejudice that every single one of them is doing stuff like this and worse until proven innocent. Based on everything I’ve read about these things it seems the most reasonable stance.
> In the previous topic I got ridiculed for not wanting to buy LG anymore because I could use an agent to modify to strip out the offending bits.
It's insane, but it's not like it's not known, personally, each time we have a party at home with friends, we always unplug the TV for this reason, it's out of doubt but it's normal to doubt as it's proprietary and has a microphone, so it's a bit obvious that it might be recording and processing data somewhere. The same as I would never trust an average phone around if I'm having a private conversation.
Blackbox+Mic = Not private.
To consider something secure software wise, it involves so many layers, and almost none of those are present with a Smart TV, so it IS considered insecure by anyone having privacy standards.
When I was a kid we used vacuum tube radio both as a passive speaker and a microphone... connected to the speakerphone of a telephone as a very poor man walkie-talkie.
Using the speakers as microphone when there is no outgoing sounds is pretty trivial in that regard. I don't know how paranoid a person can be, though.
First of all, your TV is not interested in random gibberish from loud parties. It’s just not economically viable.
During the Soviet era, not everyone could afford to have a landline phone, but the system kept hunting down its dissidents one by one. If you are a person of interest (which I believe doesn’t apply to you), there are way more important signals to adversaries than your microphone.
It's important to choose your threat model. If your plan is to resist surveillance capitalism or just a random Bob and his grandmother snooping on you online, luckily, there are some effective methods. Otherwise, I would say it’s always a question of time, not 'if' or 'how.'
>But there must be something better than just keeping to buy things that invade our privacy and homes further and further. Which brands aren’t doing this? Sony? They also announced a partnership for the lower end TVs IIRC.
Smart people need to band together to advocate their state governments to make commercial mass surveillance for any purpose a criminal offense (not just banning, making it a crime).
As an owner of 2 LG OLEDs, I am not surprised at all. I neutered these things the first day I was past the return policy. Opened the back and unplugged the WiFi/BT chip, bought a cheap dumb universal remote with no mic in it, disagreed to all T&C in the TV, updated the firmware via USB and just use an AppleTV over HDMI for streaming. Kind of silly to have to go through all of this but hey thats where we are in 2026 in the US. And I am fully aware that I am typing this on an iPhone thats probably doing the same things that this article is talking about LG doing ;-(
Why wait until after the return policy? Also what firmware did you update to? Also if you could point to a video where it shows how to do all these things that would be amazing
Probably worried about things like spectrum wifi. I don't know if others do it, but spectrum will sell access to a private WiFi network using their customers Internet as a backend.
Well even if they don't do it now, these are just a forced update away from using WiFi to connect to an open AP to do whatever they want. I also really hated the fact that there was really no way to turn BT off. Anytime the TV was on it showed up as a BT device ready to connect, and I would get random neighbors trying to and having to say no to random pop ups approving connections. Now these things are sans any type of wireless, and when it comes time to sell them, it will take me 5 mins to reconnect the internal ribbon cable.
My Samsung asked for internet access and I just laughed and said nope.
It exists to displays pixels from a Linux box, utterly sick of living in a world where "is my TV manufacturer bugging our house?" Is a thing anyone has to ask.
If you're not using the defining feature of a TV (the OTA tuner), why not buy a monitor instead of a TV?
(Next time I have to replace our house's TV, I'm seriously considering buying a separate SBTVD tuner and a monitor instead of a TV, if ignoring the "smart" features of these TVs by not connecting them to a network starts getting too difficult.)
Modern TVs are designed to work with PCs and consoles, they just also happen to have tuners. "Smart" features are mostly a distraction from actual panel capabilities.
Monitor choices also tend charge a premium for equivalent size and quality while lacking some of the features, or introducing other issues. See LG gaming monitors silently installing adware on connection:
My LG OLED C2 also has a great utility to manage deep service-level configurations. Makes it easy to professionally customize without having to fuss with the menus.
I believe we should push for legislation that prohibits the sale of customer data to third parties. Websites can use the data on their customers but they cannot share it with anyone else. Because aggregators are selling it cross-border after which you lose track and all control over it.
They shouldn't be able to collect it in the first place. The big companies have 10 page agreements that say they "value" your privacy and that they don't sell your data to third parties. They do value it, highly. And they don't sell it--they just hoard it, mine it, and sell increasingly accurate targeting. Why would they give it up? I mean, besides coughing it up with little objection to national security letters.
It also implies that Google,Meta and others can't put trackers on other people's websites. That kills about 99% of all tracking on the internet. Foreign companies would also be banned from placing trackers to close any loopholes.
Look at the outrage from US tech bros when the EU passed a law saying that you only had to tell people you were going to do this. Imagine how preventing it would be received.
The bottom of the line TVs are basically commoditized and are sold at a loss. There's few tv manufacturers and they mostly compete on price, only the top of the line models have pricing power and only for 6-24 months for new models. A supermajority of consumers don't care if they're tracked all the time and a large fraction don't mind ads everywhere either (they're used to it).
The point is: which brands still respect user privacy? If I were to buy a new TV today, which brands-models should I prioritize?
Also, are there brands-models that in which it is possible to sideload a different OS like with mobile phones (LineageOS, GrapheneOS, etc.)
Our Android TV (Sony) has an option to basically make it a dumb TV. Not sure whether that still exists. We use that + simply don't plug a network cable or set up WiFi. As long as they don't add cellular modems, this works.
I suspect because it's hard to differentiate between ones that actually respect the consumer vs ones that only say so, but are actually lying to your face.
That and not respecting the consumer is more profitable in the short term (only!), which means more marketing money, buying out other brands, lobbying to increase the barrier for entry, et cetera.
A consumer respecting brand sells products. A Consumer selling brand sells consumers so they can be profiled, analysed for weaknesses and exploited economically in the name of Surveillance Capitalism
Machiavelli's flexibility: evil has more options to achieve its goals than good, and therefore it always wins. (The invisible hand of the market is a myth - people don't choose things on principles unless they have money to burn).
Which is published on a video streaming website run by one of the biggest tracking and data collection companies, which is used to pay for the creation of the video (in addition to ads embedded in the video itself).
There is a very I-am-very-smart aspect to these predictable sorts of comments. And weirdly they always seem oddly intended to diminish the core concern being addressed.
"Oh your TV is listening to you and mapping your network and exfiltrating your data? Yeah, well, look at that website that has some ads on it! Boom!
Give up. The future is lost. Don't sweat the wiretapping TV."
It is 100% diminishing the concern. If someone were paid by LG to try to manage this revelation, they would post exactly what touwer posted. Like, there isn't a better way to try to normalize and excuse bad behaviour than doing the incredibly boorish tactic seen above. The "everyone is doing it" excuse is a go to.
I mean, LG would probably also pay someone to run around going "it's just funny, is all" in support if anyone noticed this pathetic astroturfing.
No I disagree here. I would argue that a TV doing this 30 years ago would find themselves in court, whereas now they are all skirting the edge of the law and we accept it because that frog has been boiling for decades.
The idea that logging audio is bad, but cars logging your weight, tvs logging your watch history, scales sending your wifi details, android and apple both mapping your access point to create a pseudo-location tracker without GPS, my mobile network sending me location-based adverts based on tower proximity via sms to a dumbphone are all very very bad.
LG have slightly overstepped the line here, legally, but in my opinion they've overstepped what is OK by a long long way. A website reporting on this while sending your details to hundreds of tracking sites are doing the same thing - abusing what is allowed and I assume only printing the report for more engagement and not because they actually care.
LG need to go a lifetime shit list for this behaviour - there should be outrage like there was about Sony's root kit. But websites like this also need to find out that this behaviour is not ok
I have two LG TVs so this freaks me out a lot. I guess I’m fortunate to have kept their network permanently disconnected (we use Apple TV for smart stuff) but who knows if they don’t do things like scan for open hotspots or connect without permission to networks you previously used to update firmware and then deleted from history.
This company needs to be nuked from orbit. Automatic content recognition is one thing, spying on conversations when switched off is a whole other level of violation.
GamerNexus has been so good at their investigation work.
I know people who complain the channel does not talk more about Hardware and Games as much, but we live in a timeline that personal hardware and games will not be ours anymore, just see how prohibitive hardware prices are today.
Probably best to treat the wifi password as compromised and change it after the TV has had access to it. But I suppose there's nothing you can do to prevent it from accessing open wifi networks that happen to be nearby.
Ad Tech is a cancer that is / has destroyed society. It is responsible for almost everything that is awful today. Conflating attention for interest and rewarding sensationalism has created a giant stinking hole in our lives.
It must be eradicated.
Do everything in your power to destroy these companies and their immoral business practices.
Interestingly, there are many laws against launching precision guided missiles, despite the fact that people were throwing snowballs at each other long before missiles were invented.
I actually think our information environment is better today than it was in say, 1930.
A handful of newspapers that controlled 95% of the information was much more of a "precision guided missile", in terms of ability to control information, than social media is today.
(That's not to say it's good today, it's terrifying, but at least it's possible to hear different voices, including voices on the ground)
I strongly believe the worst vices of social media would all persist if there were zero advertising.
You can see that by looking at more minor or fringe social media sites. Public "liking" is literally all it takes for people to degenerate into performativeness, sensationalism, grandstanding, misinformation, etc.
I find it sad that intelligent, educated people can be so blind to the evils building around them. How they confuse the opportunity for a right and how they take and accept awful as normal because they were raised without understanding what they never had...
To associate contextual advertising based on large scale demographics and location with spying, lying, cheating and thieving at an individual level, is a great example of this in real life.
In the old days, the tabloids were obvious. The sensationalism was easy to identify and passive in its voice. They sat on the end caps of grocery stores, far away from the News. TV news was regulated and there was a strict ethics code in place. Today, all news is tabloid as they all chase attention. They have all become the Weekly World News and as a result, we have clowns and ignoramuses running things.
And people fell for it. They actually fell for it...and continue to fall for it.
That is why it's a cancer. Ad tech eats everything in its path and destroys everything good in the process.
When you cannot tell the difference between fact and fiction, you have lost the plot.
> They sat on the end caps of grocery stores, far away from the News. TV news was regulated and there was a strict ethics code in place.
This is our key point of disagreement, not any of the rest
I strongly disagree that the "Real News" of yesterday was "good information" as I define that. It served the biases of the publishers and writers. It was sensationalist. It strongly censored and suppressed politically incorrect viewpoints, to a degree not seen today. The Overton Window was miniscule. The ethics codes were largely self-serving and inert against its major flaws.
My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet.
DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.
All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.
All of your blocking still doesn't change the fact that your LG TV is actively trying to scan your local hardware, gathering IP-addresses of devices, wi-fi names and signal strengths, creating digital finger prints of the audio and video projected on your screen, recording audio through the internal microphone, even when the TV is in standby or without an internet connection, saving the collected data locally and uploading to LG Ad Solutions as soon as the TV is connected to the internet.
But it's never connected to the internet, not even for software updates. If the TV isn't connected to the internet there's no reason to update it, assuming the TV works as expected.
It's a trade off I guess. I use Home Assistant to control TVs, so kinda need the access.
Have you noticed that on many home routers there is now a default open, sometimes password protective network named AT&T or Cox Wi-Fi? That’s the backhaul. The TV will join that automatically without asking you because they have an agreement with the network provider. This is how tons of devices phone home now. You don’t ever need to add a device on your network for it to have internet. If there’s a partner Wi-Fi network anywhere, it’ll push through that.
Joining that network from a new device always presents a captive portal that requires the credentials of my ISP account, so how does that work for you?
Where is a web link indicating partnerships, and compatible hardware lists? My ISP does not sell any TV sets.
Again, what I mean is, even if you're able to block all these things, the company LG is still secretly and actively trying to collect and process user data, without user awareness or consent.
Actually what I wanted from the video was impact of user consent, but it doesn't seme to cover this: what happens if you accept nothing, or the minimal set of consent (so not including audio) of licenses to allow you to run third-party apps? I recall there are four checkboxes to check.
And then your neighbor spins up an unprotected network or something like xfinity which they could have a deal with and it connects there and phones home anyways.
I hear this a lot “TVs will just connect to a nearby unprotected WiFi network!” But I ve never seen any evidence of it. It appears to just be speculation, unless you have an actual source?
If TV manufacturers wanted to be underhanded then they could actually make this much harder to detect by delaying the connection to new unauthenticated networks for e.g. months or only after seeing another device connect and then using that device's MAC when it is not around.
They could (although I’m not sure of the 80Kbps that Amazon sidewalk allows is really sufficient for the purpose of uploading ACR data), but is there any evidence that any TV manufacturer actually is? The reality is, why would they bother? 95% percent of people that buy a “Smart TV” hook it right up to their WiFi as soon as they take it out of the box.
And what exactly would they use that particular access path for ?
I could see a threat if the TV had access to the internet and could establish a TLS tunnel or similar from the mothership, and execute commands on my LAN (or IoT network as it stands), and report back. That could establish a command & control channel that could potentially orchestrate an attack on my infrastructure via the TV.
However, reporting that "network X exists and has these devices" over a different network complicates things a fair bit. In theory they could still use the TV as a command and control platform, but it would have to switch networks between my closed network and the open network in order to execute commands and report results. Not saying it's impossible, just very unlikely.
Besides, the TVs are not alone in being cut off from the internet. I have two IoT networks, one for trusted devices (AppleTVs, Sonos, and the likes), and one for untrusted devices like TVs. They run on different VLANs, and anything on the untrusted IoT network can pretty much only talk to itself (client isolation) and the gateway, and there's no internet and no open ports to any other VLAN.
> And what exactly would they use that particular access path for ?
Uploading the weeks, months, or years of locally-stored activity [0] data? Text compresses really well and local storage used to be very cheap.
[0] ...mic voice transcription, how often you use the thing, for how long, and a best guess (because of lack of time sync) at when, "automated content detection" logs [1], names of files you've fed to the thing, -if equipped with a camera- number of people in the room and interesting information about them, etc, etc, etc...
[1] ...assuming that that can be done with data loaded from the factory, which I kinda doubt...
1) What I called "automated content detection" is apparently called "automated content recognition", abbreviated as "ACR".
2) That weeks, months, or years of locally-stored activity I mentioned can also contain historical ACR records. Given that the audio and video of what's being displayed on the screen is "fingerprinted", those fingerprints can be saved just like everything else picked up by the "TV" and uploaded whenever the thing next has Internet connectivity. The "TV" manufacturer will lose the "what are they doing right now?" aspect of the feature, but the "what have they been doing?" aspect of the feature will work just fine.
Directly related is this section of this Gamers Nexus investigation, but the entire video seems to be worth watching if you're not rather familiar with the topic: <https://youtube.com/watch?v=6IFVTcM28KA&t=26m47s>
> My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet. NS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked),[...]
That's great, good for you that you can do that.
Unfortunately, from LG's surveillance capitalism point of view, the 0.001% of LG owners that can even think about doing that isn't even a drop in the bucket. They don't care about any one individual, and the vast majority of individuals don't care or understand what LG is doing as long as they can watch TV.
It's only a matter of time before another Cambridge Analytica situation pops up, except with better tools and vastly more data. Or maybe something we can't even imagine yet enabled by simply re-purposing ad-tech into something political and malevolent? Some people will be wise to it, of course, but if enough are caught up in it, it won't matter, we all lose as a whole.
That's great that you know how to do that, but LG and others know that also. They don't care that a miniscule amount of ppl can do it, they care about the 99.9999% that don't. Thid should be dealt with legislation and very high fees, sufficient to discourage anyone to do it.
There is sadly no hdmi CEC support on Most GPUs for pcs. So when you want your tv to turn on and off with your pc it is only possible with the tv being reachable from your pc via ip.
I believe LG doesn’t advertise such an api via Bluetooth
HDMI breakout and a esp32 module flashed with esphome is another option. The tv most likely doesn’t care that the port that sent on/off command is not the same port the video signal is coming from..
I use Home Assistant to turn on/off the TV via automations, sensors, etc.
I could possibly do it via HDMI CEC, but I have a couple of Sony Bravia TVs that more often than not completely ignores that, so I prefer having control over assuming it happens.
I have an automation that turns on amplifier only when using certain inputs, not just when the TV is turned on. I can easily imagine people would also configure their amps to use different input depending on TV input.
Yeah CEC is a bit tricky sometimes. How about auto-off from the TV itself and then a timer for a HA controlled outlet to turn off power after that using automation (i.e., when the streaming device is off for a x minutes)
Congratulations but I also dislike this type of comment because that is not a solution, a workaround that doesn't happen for 99% of the population.
Soon you won't be able to IoT network or block these devices as they begin to partner with Amazon and the likes that sell Internet for near-by IoT devices. Then your only option then is physically removing / de soldering radios from the board.
For now, setting up an IoT network is pretty much best practice, and I'd wager the average Hacker News reader both has the necessary equipment and skills to do it. That may not always be the case.
Assuming they install some 5G modem in the device, which is pretty much dirt cheap these days (our local water utility uses 5G for meter readings, and the cost per meter is something like $1/year), there's literally nothing short of a faraday cage you can do.
The can report on what you watch freely, and only consumer laws can stop them. However, without a wifi connection they can't snoop on your local network, and they probably can't connect the data to you, assuming you don't register the TV for those 3 months of added warranty or whatever they try to get you to register.
I tend to avoid devices that are built to snoop on you, so no Amazon Alexa, no Google Home, no Apple HomePod. Everything I have utilizes local control via Home Assistant, and most of it is actively blocked in the firewall from accessing the internet. It's not hard to implement, and doesn't require a master of IT, but it does remove a lot of the convenience, which I guess is the reason people don't do it.
In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
That's an easy one to put a compensation figure on but there's probably all sorts of other exploits waiting to happen.
I think the most egregious thing here is that if you don't give the TV a network connection that it will actively search for other ways to get the data back to LG such as open WIFI.
>In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.
That's understating the problem. With or without AI, this should be cause enough to shut down a company or at least their specific product division.
>E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
They're going to be fine. A slap on the wrist at best.
The value of this data to the NSA, Mossad etc is probably the only thing keeping it secure.
Never in human history has a government had the means to simultaneously spy on millions of people, to use everyday private conversations to categorise them into various threats to the state, and better yet these tech companies can still sell the commercially valuable side of this to advertisers.
People could return to burning down enterprises that they find unsavory or detrimental to society, such as they did during the industrial revolution, but this is problematic in that it's violent and not something the modern person often considers as viable. A part of why people consider this unviable now is in-part due to the consequences of these surveilance technologies. It's difficult to accomplish a revolution when everyone is being spied on all the time.
The shortest path answer is a bit too caveman-esque to survive its application to reality.
That said, I think there is a lot of appeal to go hunting for firms, since it really feels like corporations and their owners are engaging in predatory behavior as opposed to customer centric behavior.
> E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.
My tinfoil hat believes that they've already accounted for this as the price of doing business. They will have already budgeted for the fines that they might incur, pay them off and continue as normal while people become accustomed to it.
Will make surveillance mandatory? I mean we definitely should somehow fight terrorism, protect children, and prevent copyright infringement on trillions of dollars per year.
The EU is actually already quite equipped to counter such behavior, with GDPR and CRA (Cyber Resilience Act) regulation they can not only penalize on consumer privacy protection (GDPR) but also on inadequate security practice (CRA), both allow either an absolute fine or a percentage of the annual company revenue.
I wonder what chances a consumer in US has though. If the past is any indication, consumer privacy is not a highly regarded good when ranked against a corporate strategy...
>this is going to be a massive business liability.
No. this is going to go "unnoticed" or at least unactioned. These are surveilance devices - compromising their value as source of surveilance is neither in the interest of industry (who are selling and buying the surveilance) or government (who are buying and acting on it). The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now. These devices bery well may soon be the only lawfully available devices in the consumer market precisely because of their surveilance capabilities. Governments are reluctanty catching up to the capabilities of digital technologies, and they're finding them more useful now than ever before. We will be burning witches again before we ever prosecute tech companies for doing bad things.
>The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now.
I'm thinking less about shame, as corporations are dead to shame, and more about proof the TV stored a record of your bank details it got from text to speech.
If that's stored as text inside the TV and you lost money because it was copied by a hacker then you have a monetary value to show loss and a trail of liability you can use to sue LG.
The average user would not realize LG was the reason, if they do they will loose more money and effort; LG's reputation and public image won't be even damaged enough for them to take a notice. You are an ant for them and ants are only powerful if they work together.
>I'm thinking less about shame, as corporations are dead to shame, and more about if you can prove the TV stored a record of your bank details it got from text to speech.
Then they'll get a joke fine, and continue as before. Maybe cut the price for a while, until they reintroduce it with another pretext a few years down the line.
And what will anyone actually do when they are bound by an arbitration agreement that prevents class action lawsuits and/or will find against the user because it's an arbitration agreement (with an arbiter that will bend knee and suck cock for the corporations and governments overseeing it - read Five Eyes[0] and Israeli espionage in the US[1])? Or are forced out of court due to the obscene cost of legal action in most nations due to lobbying efforts to protect corporations? Or never get to court due to said obscene costs, or even the simple knowledge of the ofence? Or are simply homeless because all of their money (their most recent paycheck) was stolen, and they are now derelict?
The legal systems that are in place (at least, those in the US) are not sufficient or even designed to act in any amount of favor of individuals. Even leveraging collective action (class action cases), most individuals are left worse off after judgement when they are wronged. Signalling that you are an affected class is effectively an admission of, at minimum, association - and worse guilt, of whatever an inteligence agency may suspect you of. Intelligence is not justice, and does not "protect" individuals under the same standards. If a government wants you to be wronged, they will accomplish it regardless of law, and the information they have regarding you will be leveraged as aggressively as possible. If you are simply wronged, the cost of accomplishing justice is often insurmountable.
In the most innocent case of wrongdoing by one of these surveilance devices, what would you, as an individual, do if your bank details were compromised as a result of a "smart" device exposing your credentials to bad actors? Obviously, you would contact your banking institution and try your best to rememedy the situation. But say, for example, this smart device is on your home network, has your login details, and possibly used your 2fa details because you used it to log in to your banking institution. That is You™. You logged in. You actioned something. It's verifiable because of your IP and your cookies and your 2fa code and the heuristics of your device usage (time of day, and the previous factors, and more). Many smart device applications already include SDKs that act as residential proxies - it's not impossible to believe that malicious ones may act as MITM or such. The possibility of 0Day expoloits or even backdoors can never be ruled out as you do not own these devices.
People should be subject to shame. Every government and every company are composed of people (for now) - these people are what action these possible futures, and who action the exploits of now. They are shameless by trade because that is their value. Much like the adtech industry thrives on the compromise of compensation to overcome the shame of doing wrong, so does intelligence and clandestine commercial exploitation. Money affords people the things that they want and need, which are becoming ever more impossible to acquire without succumbing to the shame of doing Bad Things™ to acquire it. You are never going to be able to sue LG because your bank details were leaked by a public DB or some other endpoint. Nobody will. Because the value of the information that LG provides to governments circumventing established anti-surveilance law (in the US, the 4th Amendment) through sales is worth more than any dollar amount it costs these parties.
Shame on every fucking one of you stains who implements this, if you can feel it, hidden in the walls of your owned property.
You would think that would matter, that they’re basically violating all known PII/HIPAA/GDPR/National security standards and god knows what else, but I expect at most some class action down the line.
At the same time an average citizen can sue and win against these corporations. I never ended up Suing because all companies settled once I showed the evidence. So try it out. Will get expensive for them to use lawyers against ai and still lose.
I commented this only a few days ago on a different LG related thread. What LG are doing is indefensible and we should all vote with our wallets when considering a new TV... but for those who already own an LG TV you really owe it to yourself to jailbreak it and make it "yours", so to speak.
> OpenLGTV[1] is a collective, non-commercial project for legal reverse engineering and research of LG (Smart and non Smart) TVs firmware, which is partially Open Source.
> The main goal of the project is to improve the functionality of the TVs by adding new features, fixing bugs and providing new software.
This is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across.
1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.
2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.
3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.
All the points and scenarios in the video might be valid, but they are not sufficiently grouped into one of the above categories.
Instead, it just mixes them all together to imply that its all the same, weakening the whole investigation.
--
The plain example: Using voice-input for a web-search on the TV [0], make long pauses and observe how it keeps populating the prompt-UI with everything you say.
This is a matter of #3 above, accusing a malicious intent already on such a trivial implementation topic is harming the whole story
I find your "summary" much harder to read and understand, though.
I prefer the original article and the net-benefit of a google-linked video to explain things that already were properly explained, is rather small, at best, in my opinion.
> I find your "summary" much harder to read and understand, though.
Sorry, my grouping of topics isn't supposed to replace the entire research-session.
It's merely my observation after watching the actual "investigation video" that they mixed together lots of stuff they discovered into the larger conspiracy that everything is secretly spying on the user to feed a huge Ad-profiling database.
> I prefer the original article and the net-benefit of a google-linked video to explain things that already were properly explained, is rather small, at best, in my opinion
The article was made FROM the video and takes the wrong conclusions and summaries from it. If you want to form an opinion and are a bit technically savvy, you should watch the video instead.
For example: The video actually shows that all audio that is logged was only processed after voice-input was explicitly started on the device, either via the enabled wake-word or by starting voice-input in the web-search UI. The TV continues to show the text-input UI to the user while its transcribing the voice. This is not malicious, this is the expected behavior from user-perspective.
I managed to watch 14 minutes of the Gamer Nexus video (on my computer) before going into the living room and disconnecting the network cable, OMFG. If there's no legal consequences for LG for this I'll be surprised. I'm in Europe, not counting on the US for this, trust me.
You need to up your irony. The proles were reading Orwell's 1984 and thought "hey, I shouldn't mind being spied on by (smart) TVs!" because this is the statistically average behavior of the consumers.
Watching the actual investigation video the article is based on, it turns out that alot of the statements in the article don't really hold up to closer scrutiny.
I couldn't find any "smoking gun" or discovery of malicious intent.
What's left in the end is the already-known fact in the tech-community: The most-common, most-vulnerable and most-equipped device to spy on you in your home is your Smart-TV.
1. It has all the compute-power and sensors it needs
And it's the only device that "normies" own that has reliable power and reliable internet 24/7. This means you can use it for nefarious purposes, even wastefully so, and it won't show up as suspicious battery drain or prematurely hitting the cell plan's data cap.
For a lot of hacker type stuff (esp. botnets and residential proxies), this is exactly what you want.
I used to believe that piracy couldn't come back in a significant way because people don't want to use computers any more, and phones are a really bad fit for p2p, even if running some hypothetical non-walled-garden OS that wouldn't have issues with that sort of thing. I entirely failed to appreciate the impact of cheap Android TV boxes here.
It's unfortunate LG screens are still the best in image quality, even though competition is getting closer. That said, the best way to use LG TVs is to immediately disconnect them from the internet and use an Apple TV 4K for streaming applications.
"Disconnect" is not enough. They will seek out open WiFi and other available LG TVs as relays. You need to remove the WiFi card or at least the antenna.
My old Vizio TV is probably too old to do much of that, and it doesn't have a microphone, but regardless it's never connected to the internet. In fact, I removed the Wifi module altogether, as the TV would sometimes lock up and make a very loud, annoying screeching sound. Some online searching suggested it was temperature related and removing the WiFi module would help. It's just a standard board like you might find in a laptop. Removing it did help a lot, the lockups still happen very occasionally but are much reduced.
I know its important to put things down to coincidence whenever possible, but a very expensive Bang OLufsen ( I think they use LG ) TV would turn itself off at "the" most interesting split second moments during gameplay , to the point where I thought "if I am being pranked by a friend, does this TV even stream its contents?".
Much to my surprise I found out that many modern TVs do in fact come with dev mode that allow some sort of screen capture.
Safe to say I turned off all the "allow metrics and market/dev modes" and have been happier since.
EDIT> Incase anyone was wondering I did some more research about my model ( im NOT a TV guy ) and came across this regarding what screen content could technically be passed remotely: "Most probable raw grab: ThinQ/SSAP on the LAN after pairing — ~960×540 JPEG.
Live Plus/ACR: most probably sends a fingerprint, not a retrievable raw frame." No idea what it means but thought it might be relevant. Remember Im saying in my case it was a coincidence.
I'm inclined to believe the shutdowns were a bug rather than an extremely patient friend waiting for the perfect gameplay moment. But modern TVs having enough remote-management machinery that the prank theory isn't immediately absurd is not exactly reassuring.
Im not here to feed conspiracy theories and paranoia, its most likely a coincidence, and tied to having "excess metrics and advanced features that indirectly cause a kernel panic that turns the tv off".
But yes, after turning a bunch of unnecessary default options off, my TV never restarted again just as I was making a clutch moment.
So in summary - remember it could just be related to high action moment fps drain, heat, high intensity stuff making the nintendo switch2 compatibility cause a kernel affected restart etc etc etc ( which is documented via the HDMI protocols ) which make it SEEM like something weird is up, but it turns out its a related thing thats not that sus.
Ahhh, i had that with my ps5 and a couple of games were terrible in hiqh quality graphics mode, shutting down the ps5, and then through hdmi, would turn off the tv.
Both games weren’t particularly intensive, the one i remember last was divinity original sin 2, but i think both games ran on unity.
Performance mode mostly fixed it, but blowing out several years of dust from the vents properly sorted it out.
That did happen a few times , but Im telling you bro that TV restarted a couple times just as I was about to clutch, like the same second i was about to press a trigger in an otherwise boring 25 minute round more than once, but yes as I mentioned earlier it could be related to other tech aspects.
This is the same behaviour as the german secret police in east germany. The difference now its for ads and by tech.
All collected data are probably ai transcribed from audio to text and is fused via data fusion to serve ads. Add collaborative filtering to find similar interests between users.
Mossad would love to know who to de-bank for criticising Israel, United Health Care would love to know who to deny coverage to based on remarks about their back pain.
I pretty much assume every smart home device capable of doing this is doing it already.
Nothing gets connected to wifi. If temporary connection is required it gets a random one time use guest network SSID and pass that I remove after. (Yes they can collect and send setup metadata during this temporary access period but sometimes it is a worthwhile tradeoff)
What would the HN crowd recommend for a good linux streaming box + hardware with decent TV UX and remote?
My LG is completely offline and I'm using an nvidia shield to display any content, but I'm thinking maybe I need to go the extra mile, there nothing preventing an android tv box to do the same.
I have a "Homatics Box R 4K Plus" with CoreELEC/Kodi installed. The UX is then determined by your Kodi skin or apps. I wouldn't exactly recommend that box for ease of installation, but it works. It only needed to boot once into Android, annoyingly requiring an internet connection for setup. Since then it only runs CoreELEC. Works via HDMI CEC via the TV remote, which is still a bit annoying, because they had space for a dozen branded streaming provider buttons, but pause/forward etc. are on a mode switch button that overloads the navigation buttons.
Overall I am pretty happy with Kodi on my Android box. 90% of the content is streamed from a local Jellyfin server, so I can't comment on how well it works with DRM media. It occasionally [1] seems to hang, requiring a power reset. The next time it does, I will hook it up to a smart plug to simplify that as well. If you are into tinkering, CoreELEC is based on Linux and you have some basic tools already installed with more available from the addon repos. I have SSHed into LibreELEC to debug network issues with iperf and on a previous iteration to kick over Kodi with systemctl restart.
[1] gonna say less than once a month, I don't remember when it last happened
"This is a concern broadly and future looking" does not in any way mean LG TVs are doing it now; there would be proof of this if they were, it would be easy to catch.
Is anyone else thinking of cracking open the back cover and desoldering any wireless chips found? I have had a firewall rule to deny my LG TV and related domains, but that doesn't look to be enough
This sort of blanket data collection needs to be made illegal in every single jurisdiction, and have _very_ robust penalties for anyone found in breach of them.
And those jurisdictions need to have people not susceptible to bribery or extortion by the corporations making those data collection devices. That's a big ask.
True. But corruption by those in positions of power and influence is a problem as old as the ages, sadly. But at least there _are_ rules and penalties in place for those caught so there's an element of risk. Whereas the blanket data harvesting by corporations currently appears to go utterly unabated.
TFW LG OLED without internet access probably flirting with neighbor's connected LG fridge and LG washer and sharing all my gossip to Chaebols anyway. Just waiting for Chinese OLED to commoditize far enough that you can ship a bare panel with outputs for development. Reality is Korean companies do have enough competition / incentive to value engineer down. There's no reason 5/10 years from you can't just buy a nice OLED panel and a 3D printed shell from ali like eink now. Except more sanctions I guess.Seems like just a matter of time gig work license plate scanners also wardrive around with open access points to harvest info from "unconnected" smart devices, if not already.
Is all of them, every "smart tv" does it, even after adb, permission restricting or rooting.
Insert a (non infected) usb lamp in your tv and see the lamp turning on when your tv is off. It notifies you about the background activation activity :) Interesting to see when exactly get active (is it keywords or nearby devices or scheduled processes)? Can´t be keywords as that would mean 24/7 active and the lamp says otherwise.
Granted, I only watched one hour of the original video, but I get the feeling the way it is presented is a bit dishonest.
A lot of the "silent listening" they show in the video is on a TV they rooted. They start recordings through arecord manually. Or, when they show the transcripts from the recording, the AI voice search is clearly visible on the screen and was manually triggered by something.
Now, does a smart TV need all that hardware? Is a compromised TV a security hazard and smart TVs need to learn more in terms of security from modern smartphones in terms of privacy indicators, attested boot and more?
Sure.
But I do not see enough evidence that the TV is actually voice capturing all this stuff on its own, without any notice.
There is plenty of stuff on the video regarding the network scanning, ACR and more that is definitely concerning. And this is something LG actually does by themselves (when you agree to their ToS / privacy policy).
However, I think that mixing the ACR / network scanning in with "let's root the TV and actively start recording ourselves" mixes the narrative of "what LG actually does" versus "what a compromised TV can actually do", and makes it seem like LG is just recording, transcribing and submitting voice transcript automatically by themselves.
This was not proven here. And I feel that GamersNexus is just risking a lawsuit here by not separating these different concerns clear enough.
I don't share your definition of ill intent. The decision to put a (hidden) recording device in people's homes with the express purpose of exfiltrating data is already ill-intentioned of itself, regardless of whatever they planned to do with the collected data.
Pray tell, what goals do "we" want to achieve? Your position of no ill-intent does not sound like you're on the same side as I am, much less more so than myself.
> Because your position of no ill-intent does not sound like you're on the same side as I am.
If your position is "We do not want these kinds of stuff to exist/happen", then we are.
If your position however is "Witchhunts are fun, and decisions and dialogue should be driven by emotions", then indeed we are misaligned by a few centuries.
> Where in my post did I advocate for any form of action?
Wait what?
You don't? What?!
I want action. I do not want there to be a microphone array in my TV that may or may not sample at random times and forwards that data god knows where.
And to achieve that, I believe that we need to look at the systems that brought us to this outcome.
You change the conversation about televisions to be about judging the person you're having the conversation with for what they think is "ill-intent" and for one-upsmanship, you put words into their mouth, and when they point it out, you ignore them and return to the conversation. You aggressively silence them, then start babbling about yourself.
Are you a bot designed to disrupt conversations or just doing a good imitation of one?
Yes, I am indeed trying to disrupt the classic outrage scripts, as I believe that they are harmful to our goals.
There are many, many places on the web where performative outrage as in-group signalling is cheered, but, ideally, we also have some spaces where we can think and derive solutions.
By splitting the spaces, people can get the emotional validation they crave, while we can also have a workspace to make things better and reduce the need for that validation in the first place.
I agree with your sentiment but unless the person you replied to edited their comment it seems misguided. They mostly just said they didn't agree with you, there was no outrage or one upping, and genuine discussions should be encouraged
If you look at it, it's just "it's ill-intent based on what it is, regardless of intent".
Which is.. a dumb statement, but also just the usual social media outrage one-upping in lingo that passes the letter of the law of HN.
Effectively, the user just said that things are bad in response to an implicit "let us examine why, how, and what to do about it". Which is known, but unhelpful and derailing.
And.. somehow also hinted at that I'd not be aligned enough, because my definition of ill-intent being based on intent is not shared.
I read it more as them disagreeing with at what point it's "intent" - is it bad to give yourself the option to record all customers without consent or does it only become bad once they actually turn it on (remotely) and start shipping it.
Having said that, you might be right given the follow up to you
Yes, unfortunately the investigative video is implying (or explicitly stating) malice on every detail they discovered, which is harming the overall message IMO.
They hacked the TV OS, then used the TV UI to do a web search with voice-input and observed (still on the UI!) that the voice input didn't stop immediately on silence but kept extending the search prompt with everything said [0].
The OS-hack was irrelevant for this, the whole sensationalism that a listening process is running (and therefore the device is listening to everything) is just drama added to the sober fact that someone started voice-input, the input field is still displayed on the bottom of the UI and keeps getting populated with new input.
There is an important message in this about security hardening, privacy, data protection, but this conspiracy theory that everything is made to spy on you is not helping...
| but this conspiracy theory that everything is made to spy on you is not helping...
Have you actually looked at what is being discussed? There is no conspiracy theory, these are simple facts. Just about every electronic device is made to spy on you in 2026. Thinking otherwise is naive, at best.
| but this conspiracy theory that everything is made to spy on you is not helping...
Have you actually looked at what is being discussed? There is no conspiracy theory, these are simple facts. Just about every electronic device is made to spy on you in 2026. Thinking otherwise is naive, at best.
You've accidentally proven my statement: If you're not specific, you're not helping.
Nothing about my previous statement was accidental, and it’s proven nothing to your point as far as I can tell. What exactly are you being specific about here? You started with a baseless claim that anyone who believes we live in a surveillance state is misguided, while I stated that the discussion was surrounding facts. Meanwhile, there are numerous citations throughout the thread, go read them; I’m not going to reproduce them here.
> You started with a baseless claim that anyone who believes we live in a surveillance state is misguided
Oh I made no such claim whatsoever. My complete statement was this, in context of the original research the article is based on:
"There is an important message in this about security hardening, privacy, data protection, but this conspiracy theory that everything is made to spy on you is not helping..."
To translate:
It's important to raise and emphasize matters of security hardening, privacy, data protection, and there's alot to raise here.
But doing so by implying broad malicious intent on even the most trivial use-case observed on the device (like user-initiated voice-transcription, as I also elaborated as an example) is not helping to emphasize the actually important findings of that research.
Meanwhile, you started a broad strawman-argument "that anyone who believes we live in a surveillance state is misguided". You need to find a opposing position to argue that, you won't find that with me...
You don't understand - it's not meant to spy on you, it's only meant to spy on you.
It's only meant to spy on you in the way that won't get really bad viral press right now. If it spies on you in the way that people notice and object, it was clearly a honest mistake.
Question: I recently upgraded my LG OLED and decided to not accept any of the terms and conditions. I just connect it to my Apple TV and it lives on that HDMI port permanently. How safe am I?
PS: I do have the TV connected to wifi for software updates (on a pi.holed network)
I don't think you need any software updates for your TV. I have a LG oled which I haven't connected to Internet for the last 3 years. Just do a factory reset and don't connect TV to Internet.
Everything works without software updates
No doubt the feature that would imply analytics doesn’t function until terms are accepted doesn’t work as intended. It’s not like it’s going to be a priority to test before going to production.
You're not wrong, but you could ask your favorite LLM to interact with the LG API's to switch the input for you. At least for my case, it was ~10 minutes of work to develop a small tray app that looks for a specific USB device and switches the TV input if it gets inserted. I don't really even touch the remote anymore
I'm convinced Google TV firmware does something similar. I have an LED bar connected to the TV via USB and from time to time the bar turns on but the TV is "off". I think it's silently turning on to send some kind of telemetry.
Well that's it. No more LG stuff for me. I bought the C1 OLED TV years ago, great TV, but with this BS, they lost me forever.
And yes I connect the tv the wifi for YouTube and for my local media server. No, I do not want other intermediate devices , I want my TV to not spy on me.
Makes me glad I bought a Sony TV which has the microphone on the remote - and is compatible with older remotes without a microphone, so the new remote with its microphone and sponsored streaming service buttons gathers dust (without batteries inserted) while I use an old remote.
I could buy a tv in late 2014 and happened to be the last batch of bravia tvs pre android tv. Back then I was kind of bummed out that just a few weeks after that they announced the first tvs with android tv and now i was hooked with a smart-but-not-that-smart tv with a bunch of crappy ads, an unusable web browser and a non-customizable os.
But they stopped updating it years ago, none of its apps work anymore and the only "smart" feature that still works is screen mirroring feature. The tv part itself still works great. Not a 4k oled 120Hz shiny impressive thing but the image quality is still great. What I thought was an unlucky adquisition back then turned out to be a pretty good one.
Apps, browsers and "smart" features are disposable software, but a good panel can remain useful for a decade. Makes you wish manufacturers treated the smart layer as optional from the start.
Can somebody attest or falsify that we’d all be better off with a huge gaming monitor plus an Apple TV? Expensive, of course, but privacy is the main consideration here.
Another proof of how much our data is worth. But I think they make a loss on me, I can remember only a handful occasions that I bought something based on an ad I saw, which were more informative than seductive, like a monthly bike rental service.
But I guess they still sell my data. I wish they would flag the data of rational people like me as "worthless", and not sell my data.
That would be lovely. Unfortunately, to the best of my knowledge, nobody sells (for instance) high-quality 65"+ OLED non-"smart" TVs. "dumb TV" options are limited to older display technology.
I bought a Sceptre a few years ago but it died pretty quickly (dead pixel strip on the screen). But the replacement 44" Insignia (Best Buy) that I replaced it with has been an awesome tv.
So yes, you can just walk into the Electronics Store (Best Buy) and purchase a dumb TV.
I don't understand why the best advice in this thread is getting downvoted. Even if you buy a smart TV and then disable the smarts, you're still teaching the TV companies that smart TVs sell.
I have a rooted LG C4. Beyond blocking things at the DNS level, not accepting terms, not using AI, I wonder if there’s some existing software solution or a documented step-by-step to remove this bloatware/spyware.
Isn't observation of LG's operation a violation?
I mean it may fit the category "Intercepting live telemetry packets as they travel from the client machine to the company's servers can violate the Electronic Communications Privacy Act (Wiretap Act)"
I've had several conversations about this over the years, usually about the EU and how they keep harping on Apple (for instance) because it's a highly visible brand while they completely ignore LG (and others) and their massive data collection devices that (by the way) are in every single European institution.
So I have a tv of LG from the same period. I keep it dumb, not connected to the internet and just use an apple TV, so far it's a clean option. And it's always a good idea to have piHole up to, they usually have the block list updated with LG's and Samsungs urls.
The Gamers Nexus video explained that they will connect to nearby open SSID’s to send the data they have collected. So just not connecting it to your network may not be enough.
Fun fact: some (most?) Samsung TVs of the last ~6 years can't complete OOB setup if they're connected to a PiHoled network with the most vanilla PiHole filters
PiHole doesn't block IPs. It blocks DNS. The device have at least three ways to bypass PiHole: use external DNS directly, or pin the phone-home servers' IP addresses, or use some other protocols to carry IP resolution.
I'd just open the TV and yank or desolder the mic out. Or use the TV as a dumb monitor -- don't connect it to WiFi or Ethernet. And use an external Kodi/AppleTV/whatever-rocks-your-viewing-boat
At this point, best to just keep it disconnected. Just use an apple tv or similar. They sold us a spying device masqueraded as a smart TV.
If internet is really required, I'd personally flood such an LG tv with fake data - add a raspberry pi to provide it with looped audio streams for the microphone, fake bluetooth devices, and so on. But it's still probably a drop in a bucket.
These are spy devices. It is sad that the industry has become so addicted to sniffing - the problem I see is that they can no longer stop doing so, as they built an additional network around that yielding money to them.
My LG C5 is in a separate VLAN, with no access to the rest of my home network. I've never accepted the terms and conditions, and I don't need anything from it other than to be a display for my 4k player and PC. I guess now I'm going to remove Internet access from it altogether!
The thing I'd like is if the remote didn't have 4 buttons for crappy streaming services I will never use, but instead had 4 buttons to select the HDMI inputs directly; but no, I have to press a button, wait for the stupid laggy UI to load, navigate or point and click at input I want, then do the same to the preview window. A tedious pain in arse for basically the one main thing I use the remote for. It annoys me no end, and it seems to me that the last thing LG care about is the UX; they've put all their efforts into underhand and user-hostile profiling.
I also have a Roku Ultra for streaming, which I very rarely use. I don't expect they treat their users any better and they use ACR too
the only TV I have connected to the home network (guilty, I admit), Sony OLED 65, ARP floods my network about 12-15 hours after "turning off". On a plus side, it doesn't appear to be streaming anything out: no local DNS hits, not enough outgoing traffic for any meaningful audio stream
The choice between privacy concerns and ineptly coded network stack is tough. But that's the choice we're forced to have
Why don’t you just use it as a display and have a more reputable device (e.g a mini pc or an apple tv) feeding it? I’m not forced to give my tv network access at all, since it doesn’t do anything other than display whatever the apple box outputs…
This is (mostly) the way. Samsung TV without networking configured, XBox for everything - which is problematic in its own ways but it's a known quantity. It doesn't prevent it from "helpfully" hopping on a nearby unsecured network but a) I haven't spotted one of those in a while, and b) it hasn't ever been able to get updates to change its behaviour to make it start doing that if it previously wouldn't.
This is exactly what I do on the other TV, as I suggested in a different message in this thread. But this particular TV is mounted flush to the wall and there's physically no space for the apple TV anywhere near or behind it. Sacrifices we have to make
Is it your wall? We have a fairly modern house and the walls are solid gypsum so i just carved out a small hollow for it, cables are going via a channel with some ducting i then plastered over
There is censorship of illegal streaming sites crippling the internet (Cloudflare). People are being freightened from illegal iptv boxes to watch free sports because it could be part of a botnet or residential proxy network. There are million or billion euro fines for social media and service providers like google. There is enforcement against "fast fashion". Yet there is zero effort for iot privacy, not even labels or certification for good devices.
I don't want to be cynical but face it, the EU really only cares about things that generate money for themselves or big internal market players under the disguise of consumer safety and privacy. Obviously that also comes with some good effects but the perverse incentives are enormous from which we must not be blinded by ideology and warm feelings of our politicians being good and working for the people and the common good.
Shares my browsing info with 1745 "partners" with no clear way to opt out (which ought to be opt-in by the way to be compliant with ePrivacy and GDPR).
I posted two comments on similar threads recently. This is only going to get worse.
> Not long until companies partner with Amazon and others to send traffic automatically through their near-by devices like smart speakers, disconnecting will be impossible.
Not surprised if this is happening already. I don't want to remove radios out my TV..
> Samba, a media intelligence company have several partnerships with manufacturers to take screenshots and collect metadata.
Viewer analytics are valuable to companies like Samba, they aren't the only ones. Laws ASAP, these companies will lobby hard to stop anything of the sort.
Why does anyone trust any device? The surveillance capitalism is just sleepwalking towards disaster, but nobody cares because of the pretty screen and the goddamn brainrot content.
I will remind everyone again that weev was raided by the FBI, arrested, and had all electronics seized, before getting a chance to defend himself in court, all for the crime of publishing emails he found on unsecured URLs he was able to guess.
But we're allowing 1000x worse things, because what, there's a vague line about it buried deep in some EULA, which means laws no longer apply?
Lets treat them the same. Raid LG, seize all of their electronics, at least in the US (other countries are encouraged to do their own raids), arrest the executives, and after they're all in jail, and digital forensics are poring over their products and servers to find what else they did, they can argue in court how actually all these crimes are legal.
It can't just magically connect to an openwifi and update its firmware to start telemetry. It would need a new firmware to even try that.
Folks, never update a TV firmware unless it's necessary.
reply