Live data from Hacker News

GamersNexus and LG: Or why rooting your TV is a bad idea

leaflet.pub

31–40 of 134 posts

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#31
post #18

> Now, what he’s showing can be pretty scary. I wouldn’t want any attacker to be able to record me without knowing. But it’s important to remember the context here: earlier in the video, Wendell rooted the TV. He has full access to everything on it. To run those commands and programs, he had to log into WebOS via SSH and run them on the device. He didn't show remoting calling those commands, nor was this done on an u…

Some attacks shown on the video (like the "silent" voice recording) are initiated by the people in the video manually running those commands via SSH.

This is the major issue with this video: It mixes stuff done by LG (ACR) with stuff done via rooting (audio recording). And now people think LG is 24/7 recording your conversations and uploading them somewhere. This has not been proven.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#32
post #13

Seems incoherent. What exactly is the bad idea and why? Are they rediscovering "don't run stuff needlessly as root"?

The bad idea is that by rooting, you can (of course) turn your device into a 24/7 surveillance device that sends voice and video data everywhere.

That does not mean that LG does all that by default.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#33
post #6
post #4

> If you root or jailbreak your devices, you've, by their very nature, broken their security. > If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view. There are ways to remotely jailbreak LG webOS TVs without user interaction, using the same (or similar) vulnerabilities you use to…

Most of what I’m reading on rootmy.tv says the vulnerability it exploits has been fixed. So, if one were to keep software up to date on their TV, there is an improbably small chance it can actually be remotely jailbroken — am I reading this right?

> So, if one were to keep software up to date on their TV,

I presume LG is like most vendors and stops issuing updates for older models after a while. It's pretty hard to keep software up to date when the vendor stops issuing updates.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#34
post #18

> Now, what he’s showing can be pretty scary. I wouldn’t want any attacker to be able to record me without knowing. But it’s important to remember the context here: earlier in the video, Wendell rooted the TV. He has full access to everything on it. To run those commands and programs, he had to log into WebOS via SSH and run them on the device. He didn't show remoting calling those commands, nor was this done on an u…

Some attacks shown on the video (like the "silent" voice recording) are initiated by the people in the video manually running those commands via SSH. This is the major issue with this video: It mixes stuff done by LG (ACR) with stuff done via rooting (audio recording). And now people think LG is 24/7 recording your conversations and uploading them somewhere. This has not been proven.

Fresh account defending a corporation.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#35
post #24

> If you root or jailbreak your devices, you've, by their very nature, broken their security. Wow. Please stop spreading things like this. Not having root means not owning a device you paid for and have in your home.

I know people here do not want to hear it, but it is a very two-sided sword.

Of course root allows you to tinker with your device and make it run what you want, but:

- Rooted devices make devices unpredictable. As shown in the video: How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?

- Re-selling: How do you know that TV you bought is untampered? How do you know it does not have software with malware installed that steals your credentials?

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#36

I think the author took the wrong message from the video. His arguments are all - yes everyone does this not just lg; :) - yes it can be used to track the user; but unless you literally go into lg ads hq, you can’t say they don’t - they rooted to trigger this; well the os and system apps don’t need root, we need it to observe. If the author is here please consider these as the reasons to why an LG customer would be m…

I agree with the author, the point is that the way the video and the overall research was done, the entire message was diluted too much.

There is substance in what they did. But they should have worked with an actual journalist to frame this properly and create pressure on the overarching topics.

If a TV company (LG or ANY of the others who have Ad-subsidiaries) needs to respond to this video, they can easily reframe the whole topic.

The most blatant example is that they demonstrate in the video that this TV, which has a built-in microphone for voice-control, that can be switched off with a mechanical switch:

1. Will record your voice when you ask it to transcribe your input to a textbox

2. Will process your voice to create this text it shows, as visible on the logs of the rooted OS

3. Will SHOW you that it's transcribing your input on the screen.

This is weakening the whole story.

--

In HN-terms: It's a constant-power, constantly-connected IoT-device with lots of sensors and huge compute-power, located in the center of your home.

There are big topics around this that deserve a huge spotlight, which apply to ALL TV manufacturers:

a. What data is actually being collected about the user, and what is done with this data?

b. How well is security handled on the TV to ensure no malicious usage?

Repeatedly jumping to the conclusion during the video that LG specifically is collecting ALL this local data to spy on you, without clear evidence, this just gives LG an easy way to respond and every other vendor enough room to distance themselves from the whole story.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#37
post #13

Seems incoherent. What exactly is the bad idea and why? Are they rediscovering "don't run stuff needlessly as root"?

The bad idea is that by rooting, you can (of course) turn your device into a 24/7 surveillance device that sends voice and video data everywhere. That does not mean that LG does all that by default.

Because of course it does. You are fighting the wrong side, they should proof they are good, not you defend them.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#38

Earlier quoted context omitted.

Some attacks shown on the video (like the "silent" voice recording) are initiated by the people in the video manually running those commands via SSH. This is the major issue with this video: It mixes stuff done by LG (ACR) with stuff done via rooting (audio recording). And now people think LG is 24/7 recording your conversations and uploading them somewhere. This has not been proven.

Fresh account defending a corporation.

1. Ad hominem. 2. No, LG is not perfect here and their TVs are bloated as fuck and they do questionable things privacy-wise. However, that still does not mean that they listen on every conversation, as shown in the video.

That nuance is important if you value good journalism.

Otherwise if we're just our here throwing random allegations because "corp bad", might as well say LG 's TVs are turning the frickin' frogs gay.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#39

I think the author took the wrong message from the video. His arguments are all - yes everyone does this not just lg; :) - yes it can be used to track the user; but unless you literally go into lg ads hq, you can’t say they don’t - they rooted to trigger this; well the os and system apps don’t need root, we need it to observe. If the author is here please consider these as the reasons to why an LG customer would be m…

I was also a bit disappointed with the video. I don't usually watch the channel, but the previous video on LG with the McAfee thing was good. This one, well it has important points and exposes some very valid concerns. However I mostly agree with the linked article, it does not properly spell out what they actually can prove, and what's just conjecture. The video gets lauded as investigative journalism, I think the technical details are important to get right and make clear to non-tech people. A normal consumer would have no idea how to really judge the danger to their privacy after watching this, they'd come away thinking that for sure someone can listen in on their living room.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#40
post #24

> If you root or jailbreak your devices, you've, by their very nature, broken their security. Wow. Please stop spreading things like this. Not having root means not owning a device you paid for and have in your home.

I know people here do not want to hear it, but it is a very two-sided sword. Of course root allows you to tinker with your device and make it run what you want, but: - Rooted devices make devices unpredictable. As shown in the video: How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)? - Re-sel…

Honestly in a lot of cases people here are too ideologically blinded to see the logic that you’re laying out. It’s the same mental gymnastics that let many here praise something like GrapheneOS yet turn around and screech over it not allowing root which is nearly central to its entire security architecture.

But in this case… I don’t know. The OEM is so actively hostile you might be better off just taking the risk with root if you must purchase it at all (and physically removing the radio/microphone hardware not being an option).

Post reply on HN