Live data from Hacker News

GamersNexus and LG: Or why rooting your TV is a bad idea

leaflet.pub

21–30 of 134 posts

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#21
post #17

Earlier quoted context omitted.

> The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining. But vulnerabilities that can be remotely exploited without user interaction (CVSS grade 9-10)?

Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.

I'm guessing that you're exploiting some sort of exploit (buffer overflow???) on the DVB-T demodulator

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#22
post #17

Earlier quoted context omitted.

> The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining. But vulnerabilities that can be remotely exploited without user interaction (CVSS grade 9-10)?

Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.

> only RF down the TV antenna input

Holy shit. RF to zero-click exploit is a new one. I guess digital-everything wasn't always a good idea, this probably wouldn't ever have been a problem with analogue antennas and CRTs.

What are the people at LG even doing?

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#23
post #17

Earlier quoted context omitted.

> The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining. But vulnerabilities that can be remotely exploited without user interaction (CVSS grade 9-10)?

Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.

> Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.

So no responsible disclosure, I see.

Not knowing any more details, it still sounds like you'd still need the user to tune to the actual frequency on the correct receiver (to cause some buffer overflow?). But then still there's no internet to do anything. So you'd need some very specific f/up exploit to then change local settings on the device I imagine.

Either way, would be a great opportunity to demonstrate this in a video, now that there's attention on the topic, to further amplify the pressure on LG's "terrible security posture" as you say.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#25
post #17

Earlier quoted context omitted.

Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.

> only RF down the TV antenna input Holy shit. RF to zero-click exploit is a new one. I guess digital-everything wasn't always a good idea, this probably wouldn't ever have been a problem with analogue antennas and CRTs. What are the people at LG even doing?

Teletext was available in analogue times. So I could well imagine there to be a possible avenue of exploits with it too. Would take a bit of time, but I see no reason why wouldn't some data result in a incorrect handling.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#26
post #17

Earlier quoted context omitted.

Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.

> Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it. So no responsible disclosure, I see. Not knowing any more details, it still sounds like you'd still need the user to tune to the actual frequency on the correct receiver (to cause some buffer overflow?). But then still there's no internet to do anything…

> So no responsible disclosure, I see.

Huh?

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#27

Thanks for the write-up, it reflects my own impression of the video. The video is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across. They should have decided to set the focus on a specific area and then present every finding around that, i.e.: 1. The Ad data-collecting platform TV-manufacturers are operating, what data they…

Yeah if GN wants to keep my attention on this topic they need to edit out all the stuff about normal Wi-Fi stack behaviors and normal local device discovery behaviors. They didn't need to pad their feature-length video with these non-issues.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#28
post #6
post #4

> If you root or jailbreak your devices, you've, by their very nature, broken their security. > If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view. There are ways to remotely jailbreak LG webOS TVs without user interaction, using the same (or similar) vulnerabilities you use to…

Most of what I’m reading on rootmy.tv says the vulnerability it exploits has been fixed. So, if one were to keep software up to date on their TV, there is an improbably small chance it can actually be remotely jailbroken — am I reading this right?

These vulnerabilities only get fixed because they're used by public rooting tools. If blackhat hackers found them instead, kept quiet about them and used them carefully, they'd never be fixed.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#29

They rooted the TV to study it. They're not saying you're in sudden danger of attackers rooting your TV and running commands over SSH. They're saying there's evidence that certain data is collected when you wouldn't want it to be, and there are any number of potential vulnerabilities that could provide hackers access, on top of LG potentially having access as well which you also probably wouldn't want.

They still run the audio recording manually through SSH and then claim that your TV is spying on your private conversations "silently".

Otherwise, they start a voice command service (clearly displayed on the screen) and then say your TV is recording on your conversation. Like duh, of course my TV starts recording voice when I use voice commands.

And of course you have to trust LG with their TV and (not) having access. That same logic applies to every different company.

Post reply on HN