Live data from Hacker News

LG to ban residential proxies from smart TV apps

krebsonsecurity.com

421–430 of 549 posts

Re: LG to ban residential proxies from smart TV apps

#421

42% of the apps on LG's platform have these quasi-malware SDKs in them? Seems kinda bad, whether it's due to negligence or just pure incompetence? You'd think there might be legal consequences for a corporation that lets their app store turn into a malware delivery system?

It's not "quasi-malware," it is malware.

My understanding is that these apps' TOS explains that by using the app you consent to having third party traffic routed through your device. For example [1] the Hola VPN's free users agree to let third party traffic get routed through their networks. Now, how closely users actually read the TOS is a different story, but it's arguably not malware on the grounds that users are, at least on paper, informed and agree to this behavior.

1. https://en.wikipedia.org/wiki/Hola_(VPN)

Re: LG to ban residential proxies from smart TV apps

#422

Earlier quoted context omitted.

most of my machines use unnatended-upgrades Increasingly software is distributed by "curl dodgysite.com/get.sh|sudo bash -", no different to running "install.exe" on windows Surely Windows Update is a vetted repo as much as arch or debian

> Increasingly software is distributed by "curl dodgysite.com/get.sh|sudo bash -" I don't think this is the norm at all. I have seen curl/bash install scripts for tools like Claude Code, but they don't use sudo, and the expectation is that you deploy them in isolated user accounts or containers.

> the expectation is that you deploy them in isolated user accounts or containers.

Why are you lying right now? This is a norm across the dev tools world for businesses to distribute dodgy curl piped to bash scripts that users install without question, popular examples: homebrew, docker, nvm, bun, deno, k3s. There is zero "expectation" given by any of these install scripts that they are isolated. Can you even find a single source online that suggests doing what you said for you to think its a commonly held expectation?

Re: LG to ban residential proxies from smart TV apps

#423
post #255

Earlier quoted context omitted.

Airgapped is harder than you might think. If your TV finds an open network (neigbours?) it will use that one. And it is only a matter of time before they have cellular capabilities too.

Maybe 10 years ago. Very few homes have an open network today, ISPs all ship their routers with random passwords and/or force the customer to create a WiFi password during setup.

[deleted]

Re: LG to ban residential proxies from smart TV apps

#424

Earlier quoted context omitted.

My LG DualUp monitors (with no internet access) recently triggered some LG Adware Bullshit to install on my Windows laptop. So I'd say stop using LG anything (or Windows anything since they're voluntarily in on the scam too lol). If you want the 2560x2880, maybe buy the knock-off INNOCN vertical monitors. https://old.reddit.com/r/pcmasterrace/comments/1v1pkbs/lg_sp... ← examples of others who ran into the same shit

I would probably have a DualUp by now if I could find one available anywhere: it's a very appealing form factor. I looked at the INNOCN site, but only see normal-looking monitors there; do you have a model name or any pointers I could search for?

I will say I have two DualUp monitors and they are my favorite monitors I ever had so I'm sad I can no longer recommend them. 2560x2880 is perfect for programming, researching, writing documents, graphics work, and so on.

The INNOCN knockoff is the INNOCN 28C1Q. Likely the same panel.

https://www.amazon.com/dp/B0BWDMYK83?peakEvent=4&dealEvent=1...

https://www.newegg.com/p/3D4-007R-00003

Out of stock on Amazon and Newegg

Re: LG to ban residential proxies from smart TV apps

#425

Earlier quoted context omitted.

There's no spying required. The NSA and ISPs can find open proxies through infiltration and report them to (e.g. abuse@comcast.com), then Comcast simply has to act on it robustly. ISPs already deal with abuse reports like this, the system just isn't being operated comptently.

What is Comcast going to do about it? Shut off a paying customer? Not likely.

Voluntarily, maybe not, but we can make it a legal requirement.

Re: LG to ban residential proxies from smart TV apps

#426

Earlier quoted context omitted.

> These are not open proxies. Okay, I was being imprecise. These residential proxies aren't "open proxies" in the traditional sense, but they're usually "open" to anyone willing to pay a small amount of money to use them. > Most ISP abuse reports are routinely ignored. They might as well be a dead letter box. This is where regulation might play a role, or at least a change in attitude. Companies shouldn't be allowed…

Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one? Unless you are doing GFW China-level traffic analysis against a blacklist, which again how do you prove?

[deleted]

Re: LG to ban residential proxies from smart TV apps

#427

Earlier quoted context omitted.

> These are not open proxies. Okay, I was being imprecise. These residential proxies aren't "open proxies" in the traditional sense, but they're usually "open" to anyone willing to pay a small amount of money to use them. > Most ISP abuse reports are routinely ignored. They might as well be a dead letter box. This is where regulation might play a role, or at least a change in attitude. Companies shouldn't be allowed…

Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one? Unless you are doing GFW China-level traffic analysis against a blacklist, which again how do you prove?

> Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one?

Why do you think that? These are proxies, so they're making huge numbers of outbound connections to websites on behalf of the people operating them. They are the "exit nodes" in this setup.

You could probably just count the number of unique destination IPs they connect to each day. If the average residential user connects to 5,000, an infected machine is probably connecting to 50,000+.

But the simplest approach is to buy access to these illicit proxy services and use them to make requests to web servers you control. If you see your own unique request arrive from a residential IP, you've proven that connection is being used as a proxy.

Re: LG to ban residential proxies from smart TV apps

#428
post #38
post #30

Stop hooking up your LG tv to any network

Stop hooking up your LG: https://www.theverge.com/tech/967983/lg-monitors-mcafee-adwa...

https://youtu.be/Q9uefFYe6bM

A tech YouTuber showing this off and all the anti consumer behavior. I’m assuming this threads article is for an LG PR piece trying to redirect anger at the app developers to hide the fact that they are engaged in the same behavior themselves.

Re: LG to ban residential proxies from smart TV apps

#429

Earlier quoted context omitted.

I had an LG TV for work because my team developed some of the software on it. Similar experience - it got progressively worse (including the software my team developed, which in true Google fashion was deprioritized, discontinued, team laid off, and left to rot without anyone bothering to tell LG that it was no longer being maintained) until by the time I left that team it was nearly unusable as a "smart" TV and all…

> but for a TV, I just want a dumb screen that I can hook an HDMI cable to and run off a computer. Look into Digital Signage displays. You pay a brickload more money but get (much) higher quality in return.

I haven't found digital signage displays with the same brightness for HDR content, or variable refresh rate support.

Re: LG to ban residential proxies from smart TV apps

#430

US residential proxies are the bane of the internet. They're the major source of social media manipulation and spam. Services can dramatically reduce abuse by blocking entire IP ranges based on country of origin, organization, or type (hosting providers). But a company can't block US residential IPs if it would also cut off many of their real customers. The US government (probably the NSA) should be cracking down har…

And it is source of major scam. NSA can simply sign up residential proxy and start banning each hop. But, I guess they aren't interested.
Post reply on HN