Live data from Hacker News

LG to ban residential proxies from smart TV apps

krebsonsecurity.com

21–30 of 549 posts

Re: LG to ban residential proxies from smart TV apps

#21
post #18

My TV doesn't know my router's wi-fi password.

I've said it before on HN a long time ago but I'll repeat myself, I have about a thousand times more confidence that Sony and/or Microsoft will keep their PS5 and Xbox operating systems secure and not crapped up with stuff like this, than I do that random TV manufacturers will not result in a cybersecurity or privacy disaster.

Yeah, the PS and Xbox OSes show you ads, and they have telemetry. But both companies also have an extremely important core functional need of keeping them secure, because possible fuckery with the OS could result in game piracy/DRM bypasses and a direct threat to their revenue models.

Re: LG to ban residential proxies from smart TV apps

#22

Sharing a slice of your internet in a privacy preserving way in exchange for something of value, seems fair, no?

Grey market residential proxy service providers are one of the most common methods of implementing bot spam, social media manipulation and plenty of straight-out fraud. There's all kinds of things that malicious actors want to do where they value coming from an ordinary (comcast, charter, centurylink, shaw cable, whatever) residential IP.

I mean, some of us have legitimate business needs to get past cloudflares frankly somewhat bs gatekeeping business model, however

Re: LG to ban residential proxies from smart TV apps

#23

Earlier quoted context omitted.

Add to that list respecting the TOS of the user's ISP so that the user does not get banned, and providing some sort of remuneration if illicit activity through the proxy causes problems for the primary user, and then _maybe_ you could call this all not shady as fuck.

If only ISPs would actually crack down on (usually unwitting) users whose systems are participating in a malicious botnet or otherwise have their networks compromised. They could offer temporary disconnection + anti-malware support to get the user cleaned up, if they actually gave a shit.

No residential last mile broadband ISP at the scale of hundreds of thousands or millions of customers is presently willing to spend the salary/benefits/fully loaded employee cost on the massive teams of (somewhat technically clued in, not low wage) people it would take to effectively implement this.

Re: LG to ban residential proxies from smart TV apps

#24

Earlier quoted context omitted.

Grey market residential proxy service providers are one of the most common methods of implementing bot spam, social media manipulation and plenty of straight-out fraud. There's all kinds of things that malicious actors want to do where they value coming from an ordinary (comcast, charter, centurylink, shaw cable, whatever) residential IP.

I mean, some of us have legitimate business needs to get past cloudflares frankly somewhat bs gatekeeping business model, however

Sure, I do as well, I have my own VPN into my home office that lets me run traffic outbound through its default gateway while I'm somewhere else. But letting random third parties I don't know run traffic through my house is another thing entirely.

Re: LG to ban residential proxies from smart TV apps

#28
post #3

is this some kind of tactical distraction from the other LG headlines this week? I thought residential proxies are already banned from SmartTV apps by virtue of practically every APK under the sun being subject to the Google Play terms of service.

That only applies to the subset of TVs that use Google TV/Android TV.

Not so much for the rest of them that have operating systems with names like Roku TV OS, Tizen, WebOS, and Fire TV OS. They do their own things.

Re: LG to ban residential proxies from smart TV apps

#29

Earlier quoted context omitted.

No need of (2) and (3) - the user can choose to not install/use the app. (1) is the right fair boundary.

Those apps just shouldn't exist. I don't know how "join your users to a botnet" became some kind of legitimized monetization scheme. Ads are bad enough. What's next? "Participate in a DDOS in order to use our app?"

"train our machine to identify traffic lights" or something
Post reply on HN