Live data from Hacker News

GamersNexus and LG: Or why rooting your TV is a bad idea

leaflet.pub

51–60 of 134 posts

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#51
post #25

Earlier quoted context omitted.

> only RF down the TV antenna input Holy shit. RF to zero-click exploit is a new one. I guess digital-everything wasn't always a good idea, this probably wouldn't ever have been a problem with analogue antennas and CRTs. What are the people at LG even doing?

Teletext was available in analogue times. So I could well imagine there to be a possible avenue of exploits with it too. Would take a bit of time, but I see no reason why wouldn't some data result in a incorrect handling.

Exploiting what? There wasn’t any software hierarchy for Teletext to escape from in analogy TVs. If you found a bug in the Teletext chip you couldn’t then go on to do anything to the TV set aside print different data to the screen. And since you’re already tuned into that radio frequency and controlling the data sent on it, you already have control of what’s sent to the TV screen already anyway so who cares?

As an aside, I once interviewed one of the guys who wrote Teletext processors for analog TVs. He was a very interesting individual.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#52

I think the author took the wrong message from the video. His arguments are all - yes everyone does this not just lg; :) - yes it can be used to track the user; but unless you literally go into lg ads hq, you can’t say they don’t - they rooted to trigger this; well the os and system apps don’t need root, we need it to observe. If the author is here please consider these as the reasons to why an LG customer would be m…

I agree with the author, the point is that the way the video and the overall research was done, the entire message was diluted too much. There is substance in what they did. But they should have worked with an actual journalist to frame this properly and create pressure on the overarching topics. If a TV company (LG or ANY of the others who have Ad-subsidiaries) needs to respond to this video, they can easily reframe…

> What data is actually being collected about the user, and what is done with this data?

This question implies that the answer could be something other than the maximum amount of data collection and monetization of that data they can get away with.

If that statement gives you pause please spend even a short amount of time reading about ad networks, data brokers, and corporate surveillance.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#53

Earlier quoted context omitted.

Fresh account defending a corporation.

1. Ad hominem. 2. No, LG is not perfect here and their TVs are bloated as fuck and they do questionable things privacy-wise. However, that still does not mean that they listen on every conversation, as shown in the video. That nuance is important if you value good journalism. Otherwise if we're just our here throwing random allegations because "corp bad", might as well say LG 's TVs are turning the frickin' frogs gay…

It’s the era of ai bots and coördinated agitprop from nation states.

Spend some time building your reputation before arguing for divisive topics or be ignored.

Consider it a mechanical Turk but for social trust.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#54

I think the author took the wrong message from the video. His arguments are all - yes everyone does this not just lg; :) - yes it can be used to track the user; but unless you literally go into lg ads hq, you can’t say they don’t - they rooted to trigger this; well the os and system apps don’t need root, we need it to observe. If the author is here please consider these as the reasons to why an LG customer would be m…

Yes, as the owner of an LG OLED, I paid a premium for a good quality panel, and expect it to be mine.

Also, I anticipated ads on a smart TV (unfortunately it's inevitable), but (wrongly) assumed that such invasive tracking and "we own the glass" would be a bar too low even for the budget manufacturers.

I'm never buying any LG product ever again.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#55

I think the author took the wrong message from the video. His arguments are all - yes everyone does this not just lg; :) - yes it can be used to track the user; but unless you literally go into lg ads hq, you can’t say they don’t - they rooted to trigger this; well the os and system apps don’t need root, we need it to observe. If the author is here please consider these as the reasons to why an LG customer would be m…

I agree with the author, the point is that the way the video and the overall research was done, the entire message was diluted too much. There is substance in what they did. But they should have worked with an actual journalist to frame this properly and create pressure on the overarching topics. If a TV company (LG or ANY of the others who have Ad-subsidiaries) needs to respond to this video, they can easily reframe…

LG's terms of service essentially state that they will record any voice commands and store them for 6 months. They explicitly say they may store them in Korea. https://us.lgappstv.com/main/terms

Actually I think everything you're suggesting is unclear, LG explicitly say they do these things in their ToS. I skimmed their privacy policy, and I'm pretty sure it essentially says they collect all this information and use it for targeted advertising.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#56
post #26

Earlier quoted context omitted.

> So no responsible disclosure, I see. Huh?

You stated that you're "sitting on one that doesn't even require an internet connection [..] I'm waiting for my model to go EOL before I release it" I read this as "Wait until the model is EOL, hoping it won't be disclosed and fixed until then and also not fixed afterwards" Is this not what you meant to say?

Responsible disclosure makes sense when the user and the manufacturer have the same goal of the product being secure. Jailbreaking is a case where the user and the manufacturer have opposing goals: the user wants to be in charge their hardware, the manufacturer wants to prevent the user from being in charge of their own hardware. Responsible disclosure doesn't make sense, the manufacturer would just patch the vulnerability before users could use it.

If manufacturers had a sanctioned way for the user to get root access to their own hardware, responsible disclosure would've made sense, but as it is, vulnerabilities are a useful tool for the owner of the device.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#57
post #6
post #4

> If you root or jailbreak your devices, you've, by their very nature, broken their security. > If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view. There are ways to remotely jailbreak LG webOS TVs without user interaction, using the same (or similar) vulnerabilities you use to…

Most of what I’m reading on rootmy.tv says the vulnerability it exploits has been fixed. So, if one were to keep software up to date on their TV, there is an improbably small chance it can actually be remotely jailbroken — am I reading this right?

why would I want to keep the software on my TV updated, it's a screen

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#58
post #24

> If you root or jailbreak your devices, you've, by their very nature, broken their security. Wow. Please stop spreading things like this. Not having root means not owning a device you paid for and have in your home.

True, but rooting the device de-facto means breaking the trust-chain of the OS. The inevitable outcome of this video is that TV vendors are pushed to harden the security and preserve the trust-chain, because part of the (valid) claim is that nefarious actors may break the security to use the device for spying on you. With support from an actual journalist, it could be reframed to also emphasize the importance of cont…

[deleted]

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#59
post #26

Earlier quoted context omitted.

> So no responsible disclosure, I see. Huh?

You stated that you're "sitting on one that doesn't even require an internet connection [..] I'm waiting for my model to go EOL before I release it" I read this as "Wait until the model is EOL, hoping it won't be disclosed and fixed until then and also not fixed afterwards" Is this not what you meant to say?

This would be one way to interpret it. Another way would be: "If the model is EOL, the potential attack surface gets lower, because you cannot buy it any longer and the amount of devices in use will reduce over time."

On a different note: Are you, in any way, affiliated with LG? You read to me as someone who is "unhappy" with the findings.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#60
post #40

Earlier quoted context omitted.

I know people here do not want to hear it, but it is a very two-sided sword. Of course root allows you to tinker with your device and make it run what you want, but: - Rooted devices make devices unpredictable. As shown in the video: How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)? - Re-sel…

Honestly in a lot of cases people here are too ideologically blinded to see the logic that you’re laying out. It’s the same mental gymnastics that let many here praise something like GrapheneOS yet turn around and screech over it not allowing root which is nearly central to its entire security architecture. But in this case… I don’t know. The OEM is so actively hostile you might be better off just taking the risk wit…

Wait who are these people who praise GrapheneOS but complain about it not allowing root? It sounds like you're conflating two groups of people
Post reply on HN