Live data from Hacker News

216M Spy TVs – The LG Smart TV Problem [video]

youtube.com

741–750 of 1001 posts

Re: 216M Spy TVs – The LG Smart TV Problem [video]

#741
post #364

Earlier quoted context omitted.

Have you noticed that on many home routers there is now a default open, sometimes password protective network named AT&T or Cox Wi-Fi? That’s the backhaul. The TV will join that automatically without asking you because they have an agreement with the network provider. This is how tons of devices phone home now. You don’t ever need to add a device on your network for it to have internet. If there’s a partner Wi-Fi net…

The TV will join that automatically without asking you because they have an agreement with the network provider. This seems far fetched to me. Have you seen evidence or reliable reporting of this?

This is alarmingly realistic to me.

The part about ISP routers broadcasting an alternate "hotspot" SSID is documented [1] and can be easily observed. Walk around any city, open your phone's wifi settings and see networks like "xfinitywifi" or "optimumwifi". As an end user, if you connect to one of these networks from your device, you'll get a captive portal web page that makes you sign in to your ISP account. Once signed in, you get internet access courtesy of the router sitting in whatever home or business you happen to be near to.

In addition to ISPs allowing their own subscribers access, there are examples of corporations cutting deals with ISPs for hotspot network access. For example, Google's MVNO Google Fi has a deal with unnamed partners that allows subscribers' phones to connect to hotspot wifi networks for extra coverage, branded "Wi-Fi Auto Connect+" [2].

From the user's perspective (and personal experience), this connection is handled seamlessly and outside of the OS' normal wifi UI flow. If your phone sees no saved wifi networks but does see xfinitywifi (et al), it auto-connects in the background. Authentication with the captive portal happens automatically and non-interactively, presumably with some keys provisioned to your device. Your traffic is VPNed back to Google, so the router and ISP don't see anything. The only indication that any of this happened is that the "5G" icon changes to "W+"; the normal WiFi icon never shows up.

In the case of Google Fi, this is actually a pretty great deal for users. You get better coverage (especially indoors in cities, where cell service can be spotty) with no real downsides to you – your traffic isn't meaningfully exposed to another third party, it doesn't cost you extra, and you don't have to bother the staff for a wifi password.

But given all that, it's not a huge leap to believe that ISPs are also more than willing to quietly take LG's money in exchange for an all-access pass to their hotspot network.

It's easy to imagine that an evil company could ship their TV with a key that allows it on an ISP's hotspot network. No extra suspicious hardware like a 5G modem needed, and no MAC address spoofing required. The TV software could easily connect to the hotspot network with zero indication in the UI, and then use the surreptitious connection only to transmit your kompromat back to HQ.

If done intelligently, you'd never notice. By only transmitting spy reports (and not downloading new ads), even a keen observer wouldn't notice any behavior on the TV that would trigger "how tf did this thing get a network connection?" Even more insidious, you couldn't really see what traffic was happening, since IP packet captures on your network are useless in this scenario. You'd need special hardware to capture what the TV is actually doing on the air.

If truly evil, the software could do this hotspot dance even if you've configured your own WiFi network on the TV. If the software finds it can't reach ad HQ because you've firewalled it off, then despite your best efforts to contain the disease, it still can spy effectively thanks to your neighbor's router with its default-enabled ISP hotspot. Just do a daily upload while you're sleeping and otherwise sit innocuously on your locked-down VLAN.

Everyone evil wins: ISP collects that sweet bonus revenue at zero marginal cost, TV manufacturer doesn't have to foot the hardware bill for millions of 5G modems or (relatively) expensive cellular agreements, and advertisers get to be that much more creepy targeting you. I'm sure the wanna-be despots of the world don't mind the spy apparatus being built for them either, conveniently under the control of easily-compelled corporations.

--

Now to be clear, I have no proof that any TV manufacturer is surreptitiously connecting to an ISP's hotspot network in order to exfiltrate your data. But all of the building blocks to make that happen provably do exist, and I seriously doubt that capitalism will allow them to go unused.

It's anything but far-fetched.

[1] eg https://www.xfinity.com/support/articles/xfinity-wifi-hotspo... and https://www.spectrum.net/support/internet/spectrum-mobile-wi... and https://www.optimum.net/pages/internet/hotspots/faq.html

[2] https://fi.google.com/about/wi-fi-auto-connect-plus and https://support.google.com/fi/answer/10091529?hl=en

Re: 216M Spy TVs – The LG Smart TV Problem [video]

#742

Most TV sets should not normally need microphones, and if they have that in some models (as long as there are models without), then there should be a hardware switch to disable them. However, "continuously sweep home networks, map secondary devices, and log microphone audio while appearing to be turned off" is also stealing and wasting your power.

Every speaker is also a microphone

Speakers can act as part of a useful microphone circuit but you're missing all the amplifiers and ADCs and other stuff to use it as one in any sane speaker driver circuit. They'd have to intentionally add all that, which maybe they would, but it'd be easier to just stick a tiny $0.05 all in one microphone chip on there.

Re: 216M Spy TVs – The LG Smart TV Problem [video]

#745

Why would you ever connect a TV to the internet in the first place?

The average person's house has a gateway/router/wifi thing from their ISP, a smart tv connected to the internet with microphones, and one of those iptv piracy boxes that's actually the source of all the residential proxy ips.

Convenience over all else is what 99% of people are doing.

Re: 216M Spy TVs – The LG Smart TV Problem [video]

#746

Why would you ever connect a TV to the internet in the first place?

Because it is a 'smart Tv', and it asks to get connected to the internet during setup?

That being said, I have an old LG Tv (pre-android, forget what they call the os), and I never connected it, opting instead to hook up a firetv stick .... (who knows what bad crap they might be up to btw).

But the point is, we are a minority, most people go the path of least resistance.

Re: 216M Spy TVs – The LG Smart TV Problem [video]

#747
post #559

Earlier quoted context omitted.

> my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want Honestly, it's not even that extreme in most cases. I think it's usually not malice, it's incompetence. That's why I don't trust big companies with my data. Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are a…

> I think it's usually not malice, it's incompetence. Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.

why not both?

Re: 216M Spy TVs – The LG Smart TV Problem [video]

#748

Why would you ever connect a TV to the internet in the first place?

The average person's house has a gateway/router/wifi thing from their ISP, a smart tv connected to the internet with microphones, and one of those iptv piracy boxes that's actually the source of all the residential proxy ips. Convenience over all else is what 99% of people are doing.

Residential proxying seems a good trade for piracy to me. However, there's a chance it will attract attention of some authority, who (although proxying itself is legal) will see your piracy box and arrest you for piracy. However, this doesn't seem to happen in practice, perhaps because residential proxying is so common.

Re: 216M Spy TVs – The LG Smart TV Problem [video]

#749

Here are LG's contract terms for appliances.[1] They are awful. Not only can they listen in. You have a contractual requirement to tell everyone in range of an appliance that they may be eavesdropped upon. CONSENT REQUIREMENT: You acknowledge and agree that it is your sole responsibility to obtain all necessary consents from any third parties whose voices may be captured by the Product and to notify household members…

tempted to go into my nearest big box electronics store and then sue them when they don't tell me the LG tv's they have on display are eavesdropping on me.

Do it

Re: 216M Spy TVs – The LG Smart TV Problem [video]

#750
post #387
post #326

Earlier quoted context omitted.

I never understood why any of the smartness had to be built into the TV in the first place. Sure, it's useful for the first year, and then the seriously underpowered hardware they installed into it will have trouble with just about anything. I bought a Philips Ambilight OLED TV probably over 8 years now. Brilliant tv, great quality, I still see no reason to replace it at all. But its built in AndroidTV is garbage.

Because it’s extremely profitable for them to serve ads and sell PI. Kind of like how the airline industry makes more money off credit card shenanigans than actual plane tickets.

Not relevant to the discussion but to your comment, Freakonomics Radio claimed "airline industry makes more money off credit card shenanigans" was not true

https://freakonomics.com/podcast/is-your-plane-ticket-too-ex...

WSJ and Wendover claim it is true.

Post reply on HN