Live data from Hacker News

GamersNexus and LG: Or why rooting your TV is a bad idea

leaflet.pub

71–80 of 134 posts

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#71

Earlier quoted context omitted.

I know people here do not want to hear it, but it is a very two-sided sword. Of course root allows you to tinker with your device and make it run what you want, but: - Rooted devices make devices unpredictable. As shown in the video: How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)? - Re-sel…

> How do you know that TV you bought is untampered? Many rooted devices display during boot a warning that they have been rooted. This is a problem that has been solved for more than a decade, but manufacturers pretend not to know the solution, because they are actively hostile to user freedom. > How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually r…

> Many rooted devices display during boot a warning that they have been rooted.

Usually, this happens after a bootloader unlock because then verified boot is disabled. You can still have a rooted device and not break verified, resulting in no warning. See: jailbroken iPhones.

I wouldn't say it's a solved problem. Just have to find an exploit that works with verified / attested boot.

And device manufactures are getting more and more restrictive here, too. Why do you think that is?

> Let's pretend there aren't plenty other ways they could spy on you.

Sure, of course there are other ways to spy on people. But as we see here: If the device itself does it, then we like to blame LG. If they used an exploit to do that, then we blame LG's shitty security.

If a hotel owner installed a microphone inside one or their specific TVs, then we blame the hotel owner at least - not LG.

> If it's bad if a hotel does it, why is it okay if LG does it?

It doesn't seem like it is okay. We are discussing this right here.

> Do you honestly trust LG, and the thousands of "partners" that they sell your data to, and every government whose warrants they have to honor?

Do I trust LG more than a shady hotel / BnB owner or eBay seller? Yes. Do I trust them fully? No. It's not fully binary, I'd say.

> Your argument reduces to "if the warden lets us out of our jail cells, who will make sure we behave?"

I am just trying to say, it's really not that binary. You can extend that to other places whenever attestation is involved.

Do I like Linux and open platforms? Sure! Tampering is fun! Do I hate people using open platforms to scrape my websites and constantly cause load, steal my content and use that for AI training? Also, yes.

But how can I fight that? We run into CAPTCHAs, Cloudflare, Anubis and co. Now that issue is reduced, but the openness is also gone.

And you always see in tech spaces we rather want "dumb" devices rather than smart devices, because we cannot trust them.

Attestation buys you more trust, but at the cost of openness.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#72
post #68
post #67

Earlier quoted context omitted.

It’s a whole computer that runs YouTube, Netflix, Amazon video, etc

I've never used a TV that way, that's the job of whatever is connected to the TV. But if you do use your TV like that, didn't those things work when you got it? Why do you need software updates?

I think you're being deliberately obtuse. You would update software on a TV for all the same reasons you update software on any other device: improved performance, better compatibly, new features, etc

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#73
post #53

Earlier quoted context omitted.

1. Ad hominem. 2. No, LG is not perfect here and their TVs are bloated as fuck and they do questionable things privacy-wise. However, that still does not mean that they listen on every conversation, as shown in the video. That nuance is important if you value good journalism. Otherwise if we're just our here throwing random allegations because "corp bad", might as well say LG 's TVs are turning the frickin' frogs gay…

It’s the era of ai bots and coördinated agitprop from nation states. Spend some time building your reputation before arguing for divisive topics or be ignored. Consider it a mechanical Turk but for social trust.

How do you build reputation if everyone starts tells you to build reputation first?

You have to start somewhere. Better makes sense to start looking at the arguments rather than the author.

It also helps you train your brain. Stop trusting someone solely because of who they are.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#74
post #49

Earlier quoted context omitted.

1. Ad hominem. 2. No, LG is not perfect here and their TVs are bloated as fuck and they do questionable things privacy-wise. However, that still does not mean that they listen on every conversation, as shown in the video. That nuance is important if you value good journalism. Otherwise if we're just our here throwing random allegations because "corp bad", might as well say LG 's TVs are turning the frickin' frogs gay…

It's not just questionable things, its using dark patterns to do things that wouldn't stand up in court because they definitely illegal in places with data protection laws. Sorry but such contrary takes in the face of this sort of evidence are either contrary for the sake of it or paid astroturfing.

I agree on the dark patterns. And I do not claim that ACR and all the privacy violating crap bundled into modern devices is good. No, it is evil.

However, just because your TV does ACR, does not immediately mean they listen 24/7 through your TV through any conversations even if the TV is off.

That is another, also quite different level of claim.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#75
post #61
post #26

Earlier quoted context omitted.

> So no responsible disclosure, I see. Huh?

Not disclosing a vulnerability you found to the manufacturer (while the product can still hopefully be patched) is “not responsible”. I think that’s what the person is trying to say.

It seems that some people do not appreciate the amount of labour that can be required to turn knowledge of a vulnerability into an actionable bug report. (Before someone says "ask an LLM to do it", LG has that option available to them, too)

It is certainly not work that I would do to benefit a many-billion dollar company, for ~free. I may do it to benefit device owners such as myself, instead.

LG is solely responsible for the security of the products that they choose to sell.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#76
post #53

Earlier quoted context omitted.

It’s the era of ai bots and coördinated agitprop from nation states. Spend some time building your reputation before arguing for divisive topics or be ignored. Consider it a mechanical Turk but for social trust.

How do you build reputation if everyone starts tells you to build reputation first? You have to start somewhere. Better makes sense to start looking at the arguments rather than the author. It also helps you train your brain. Stop trusting someone solely because of who they are.

This is hacker news. Not Reddit.

You can comment about anything here and build credibility.

Just don’t start on the most divisive topics.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#77

Earlier quoted context omitted.

You stated that you're "sitting on one that doesn't even require an internet connection [..] I'm waiting for my model to go EOL before I release it" I read this as "Wait until the model is EOL, hoping it won't be disclosed and fixed until then and also not fixed afterwards" Is this not what you meant to say?

This would be one way to interpret it. Another way would be: "If the model is EOL, the potential attack surface gets lower, because you cannot buy it any longer and the amount of devices in use will reduce over time." On a different note: Are you, in any way, affiliated with LG? You read to me as someone who is "unhappy" with the findings.

The attack-surface doesn't get lower, it just doesn't continue to increase UNLESS the same vulnerability is not carried over to other products.

The attack-surface only gets lower when the TV is no longer in use and is disposed. That doesn't happen at EOL, customers don't suddenly throw away their TVs after 2 years.

I'm happy with the findings and hope that it gains momentum, but unhappy with the dilution of the matter with speculation, assumptions and sensationalism, because it allows the vendor to wiggle out of it and wait for attention to wind down.

I would prefer a clear spotlight to be shined on #1 the ad-networks business model of TV-manufacturers and #2 the security of their (very powerful) products.

If the process results in regulation which also requires the TV manufacturer to offer root-access to the consumer to verify and control its operations, I would be overjoyed.

But this is unfortunately not a subject of the current narrative at all, it will actually result in the opposite (more effort to lock-down the OS to prevent future sensationalism reporting)

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#78
post #72
post #68

Earlier quoted context omitted.

I've never used a TV that way, that's the job of whatever is connected to the TV. But if you do use your TV like that, didn't those things work when you got it? Why do you need software updates?

I think you're being deliberately obtuse. You would update software on a TV for all the same reasons you update software on any other device: improved performance, better compatibly, new features, etc

No. My computer is a tool I actively use. The TV is an almost entirely passive consumption device. Was performance not good enough when it was new? If it wasn't, will the new software versions truly buck the trend we've seen in software for the past few decades and improve performance? What new features are necessary? Video playback has been a solved problem for the past few decades.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#79
post #17

Earlier quoted context omitted.

Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.

> Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it. So no responsible disclosure, I see. Not knowing any more details, it still sounds like you'd still need the user to tune to the actual frequency on the correct receiver (to cause some buffer overflow?). But then still there's no internet to do anything…

> So no responsible disclosure, I see.

If the manufacturers responsibly included a responsible way to install custom software/firmware, perhaps people would feel more inclined to help them. Their current attitude buys them very little goodwill.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#80
post #56

Earlier quoted context omitted.

Responsible disclosure makes sense when the user and the manufacturer have the same goal of the product being secure. Jailbreaking is a case where the user and the manufacturer have opposing goals: the user wants to be in charge their hardware, the manufacturer wants to prevent the user from being in charge of their own hardware. Responsible disclosure doesn't make sense, the manufacturer would just patch the vulnera…

To me as a user, responsible disclosure is most-valuable for every vulnerability that could be exploited remotely without me being in control. The video draws exactly that picture, a nefarious actor, remotely taking control over my TV and recording Audio from it

To me as a user, responsible disclosure takes away my right to do what I want with my hardware.
Post reply on HN