Live data from Hacker News

Smart TVs sending sensitive user data to Netflix and Facebook

ft.com

281–290 of 524 posts

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#281

Earlier quoted context omitted.

Are you sure about this? If the TV really is phoning home with whatever is on the screen, including anything personal the owner might happen to be displaying, that's a vast set of lawsuits waiting to happen. The GDPR fines alone could be staggering. I could easily imagine spyware logging whatever TV shows you're streaming and the like, but it's hard to imagine any business in this industry having lawyers dumb enough…

Sorry, I was being a bit lazy in my comment. I didn't specify, but I don't really suspect they are sending full frames back if for no other reason than bandwidth. But, honestly fingerprinting is so similar it might as well be the same thing. Though thankfully, yes, the fingerprint calculated for something personal probably is meaningless to them, but possibly could be replaced with a reversible option

I don't think fingerprints are the same at all. While still having privacy implications, fingerprints to match against broadcast content aren't uploading your family photo or caps from your home movie if that's what you're showing on screen.

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#282

Earlier quoted context omitted.

I worked on that. It sends audio and/or video fingerprints (not frames, for privacy and bandwidth reasons), which are matched against a fingerprint database. Whatever people see on TV is usually 10 to 60 seconds behind the real live stream at the broadcaster (which is where the reference fingerprinting happens). GeoIP data can be used to roughly deduce where the TV is located, in order to better filter out false posi…

Any way to turn it off? Or perhaps block a specific domain via pihole?

It is not enabled by default. For the first time when you use a TV input, it asks you whether you want to enable it. If you have enabled it, you can opt out from settings later on.

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#283

This is a pretty open secret within the industry. Geographic data can be provided via setup (a lot of TV's ask for a zip code on setup) or usually simply via GeoIP lookup. Dig a bit deeper and you get into service provided by Samba TV and or Inscape and you can find that they're sending back frames of video in a lot of cases to track what you're watching. This data is becoming a huge mechanism for subsidizing TV sale…

Roku enabled TVs very clearly send back frames of what you are watching. I've been watching YouTube casted via chromecast plugged into HDMI (NOT the built in chromecast, I have verified multiple times) and the Roku will give me a full width toast saying to press `*` to watch the full movie or some similar contextual option I was pretty put off the first time this happened. That said, I don't even know if I looked thr…

It is off by default and is enabled only if you opt in. They call it "More ways to watch". If you have enabled it, you can disable it later on from the settings.

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#284
post #264

My TV (Vizio P55-C1) doesn't have a "disconnect" option. I either need to do a factory reset, or change passwords three times (WiFi AP to temporary, TV to temporary, WiFi AP back to normal.) I suppose I could just never connect it to WiFi, but then it wouldn't get firmware updates.

TVs should be dumb enough to never need firmware updates. I realize many do, but I consider that a design flaw.

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#285
post #250

Earlier quoted context omitted.

Encrypted ones do, at least every commercial version these TV’s would be able to use. https://en.m.wikipedia.org/wiki/Wi-Fi_Protected_Setup Is the closest thing to an exception that I know of but still required user action to connect, and it’s been deprecated for a long time. Some enterprise systems don’t require users to enter passwords, but the software still uses them internally when talking to the network. PS: Un…

Nothing’s stopping TVs from hopping on unencrypted networks.

Or even from silently bruteforcing passwords.

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#287
post #119

Earlier quoted context omitted.

Five years from now, 5G will be widely deployed, with a connection density of 1M/sqkm, 1000 times larger than 4G. The TV will connect directly to the 5G network without asking for permission. For your convenience [TM].

At which point I hope there will be websites describing how to take the TV apart and disable the 5G modem. Or somebody will invent a small short-range backhaul-less 5G spoof microcell you can put next to the TV that will confuse the TV's modem into connecting to nothing. Or just wrap the TV in a Faraday cage. But keeping the screen visible might make that tricky.

1% of us will take the troubles to protect themselves. We'll even marginally succeed, as long as we don't go out in public or visit a friend's house. Too expensive to circumvent protections if the other 99% have no [time to develop an] understanding of what they are exposed to.

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#289
Does anyone publish a set of firewall rules (pfSense would be ideal) that allows Netflix, Hulu, etc to work with a Roku or Smart TV while blocking things like facebook?

I understand that Netflix is going to track me when I'm a Netflix subscriber, but why should Facebook do it?

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#290

What if the communication is benign? What if the TV is simply refreshing a list of recommendations? Everybody - including this forum - is so primed to read nefarious motives into basically anything a computer can do now. Soon we're not going to be able to write a single "hello world" app w/o having to fill out a ream of EU paperwork and get licensed and bonded in advance.

Also, what if the TV communicated with its OEM's backends instead, which communicated with malicious third parties behind the scenes?
Post reply on HN