Live data from Hacker News

LG to ban residential proxies from smart TV apps

krebsonsecurity.com

231–240 of 549 posts

Re: LG to ban residential proxies from smart TV apps

#232

Earlier quoted context omitted.

Never once had a problem with an LG because I've never given it internet access. A trustworthy set top box handles everything instead. Concerned that might not be an option in the future.

That is my problem. What can you trust anymore? Is there an appliance out there that can do the basics and not be a malware gateway?

You could give it a vpn to a public cloud provider so that even if they run residential proxies they still get a dirty vps IP.

Admittedly this doesn't stop the presumed screenshotting and microphone use and worse

Re: LG to ban residential proxies from smart TV apps

#233
post #220
post #209

Earlier quoted context omitted.

If you don't ever give your network credentials to the Smart TV you've closed off 99% of the attack surface.

From previous discussions there are apparently TVs which will connect to any open network nearby, if it can find one. I got myself a normal, non-smart Philips 49" TV some ten years ago, it's good, but I don't expect to be able to find something similar anymore.

Your smart TV would make you risk going to prison for theft? Just because its open does not mean permission to use.

Re: LG to ban residential proxies from smart TV apps

#234

Earlier quoted context omitted.

> It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs This is also a misrepresentation. Microsoft has provided LG with a certificate to sign its driver packages with, and allows LG to upload packages to Windows Update, which includes a feature to install sidecar applications. Now, the spirit of this feature is that any application is meant to provide genuine configuration functionality…

The commercial software landscape more and more reminds me of a civil war torn town. Everyone shooting at everyone, a dark forest through and through

It’s more a tragedy of the commons, we are the commons.

Re: LG to ban residential proxies from smart TV apps

#235

Earlier quoted context omitted.

Grey market residential proxy service providers are one of the most common methods of implementing bot spam, social media manipulation and plenty of straight-out fraud. There's all kinds of things that malicious actors want to do where they value coming from an ordinary (comcast, charter, centurylink, shaw cable, whatever) residential IP.

I mean, some of us have legitimate business needs to get past cloudflares frankly somewhat bs gatekeeping business model, however

Do you really need residential ip for this? for my news scraping i have choose static datacenter proxy first, rotating only as fallback, direct as last. flaresolverr covered cloudflare js challenge, but it wedge on memory time to time, so i add healthcheck for it. on my own site aws waf meet datacenter ua with captcha, so i understand other side too. residential never was necessary for me, but maybe my targets are just easier, what do you scrape?

Re: LG to ban residential proxies from smart TV apps

#236

42% of the apps on LG's platform have these quasi-malware SDKs in them? Seems kinda bad, whether it's due to negligence or just pure incompetence? You'd think there might be legal consequences for a corporation that lets their app store turn into a malware delivery system?

It's all above board though, as you, the user, agreed to the terms & conditions for installing said app.

This won't change unless governments create and enforce laws.

Re: LG to ban residential proxies from smart TV apps

#237

Earlier quoted context omitted.

The monitors aren't installing anything. That headline was a lie. It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs. That's why the problem affected older monitors too - it's the update side that suddenly started to ship malware.

> It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs This is also a misrepresentation. Microsoft has provided LG with a certificate to sign its driver packages with, and allows LG to upload packages to Windows Update, which includes a feature to install sidecar applications. Now, the spirit of this feature is that any application is meant to provide genuine configuration functionality…

> One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.

Maybe not, but LG has violated this trust and should therefore be either fined or severely restricted by Microsoft. Banning will likely cause more problems than solutions, but they shouldn't get away with this.

Adware was a huge problem during the Windows XP era, can't believe it's coming back now through Microsoft's official channels.

Also I doubt there's actually millions of hardware vendors. But that aside, Microsoft has a duty to vet everything that they offer through their channels. If it's too expensive for them to do, do like Apple did and have those that want to make use of their distribution network (and trust) pay them.

Re: LG to ban residential proxies from smart TV apps

#238

Earlier quoted context omitted.

The monitors aren't installing anything. That headline was a lie. It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs. That's why the problem affected older monitors too - it's the update side that suddenly started to ship malware.

> It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs This is also a misrepresentation. Microsoft has provided LG with a certificate to sign its driver packages with, and allows LG to upload packages to Windows Update, which includes a feature to install sidecar applications. Now, the spirit of this feature is that any application is meant to provide genuine configuration functionality…

My point is not to shift the blame to Microsoft; it's primarily LG that's at fault here.

My point here is simply that it's not the monitor that is installing this. Neither the malware nor the URLs to malware exist on the device - they get fetched as part of normal OS-side auto-provisioning, which is the part that was compromised.

Re: LG to ban residential proxies from smart TV apps

#239

Earlier quoted context omitted.

Wait, you're saying a monitor can just advertise a URL over the video connection for its driver and then Windows will blindly install it, without user confirmation? I thought that LG had submitted these "drivers" (adware) to Microsoft and they approved it.

I believe you register your device with Microsoft so Windows can automatically obtain and install drivers for them when they are plugged in. What LG sent in for installation is not a simple .inf or .sys/.dll file. They sent in a whole bag of software which does all the nasty things, and Microsoft doesn't vet or care about the software installed as the "driver" of the hardware.

This is actually a feature of the .inf by design, an AddSoftware directive. It can even link to apps from the store instead of bundling them with the driver. This is designed to install settings panels like the ones for GPUs.

https://learn.microsoft.com/en-us/windows-hardware/drivers/i...

I guess that from Microsoft's perspective, the driver itself wasn't suspicious, but it installs a questionable sidecar app they would have never vetted anyway.

Re: LG to ban residential proxies from smart TV apps

#240
post #220

Earlier quoted context omitted.

From previous discussions there are apparently TVs which will connect to any open network nearby, if it can find one. I got myself a normal, non-smart Philips 49" TV some ten years ago, it's good, but I don't expect to be able to find something similar anymore.

Who runs open WiFi networks in 2026?

Japan is full of them
Post reply on HN