Live data from Hacker News

GamersNexus and LG: Or why rooting your TV is a bad idea

leaflet.pub

111–120 of 134 posts

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#111
post #13

Seems incoherent. What exactly is the bad idea and why? Are they rediscovering "don't run stuff needlessly as root"?

The bad idea is that by rooting, you can (of course) turn your device into a 24/7 surveillance device that sends voice and video data everywhere. That does not mean that LG does all that by default.

You're just jumping around a single point about rooting, whereas the video shows it's logging all the devices, with their ip, name, even detecting someone being in a Teams call. And you are as with the article, trying to sidetrack all of it by focusing on rooting.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#112
post #105

Earlier quoted context omitted.

Your broken waking machine drawer is an orthogonal problem, and perhaps not specific to one corp. Plastic parts break but, OTOH, overbuilding consumes resources with diminishing utility. A deep spare parts market is a cost. May i suggest basic home repair? Two techniques that work in many cases are: - "welding" with a soldering iron, using cable tie as a filler rod. You'll want good ventilation and a sacrificial tip…

I used to think this too, but e.g. Bosch and IKEA have great replacement parts websites accessible to the consumer. IKEA’s parts are mostly free, too! With modern logistics (automated warehouses, cheap shipping, ordering online) it is actually a solvable problem, if the company gives a damn about it.

I'll take that as a recommendation, thank you! Fwiw, i have found spares for many brands by searching model numbers and wading through spate parts aggregators. The market exists. It's often uneconomic :-(

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#113
post #7

Earlier quoted context omitted.

The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining. There are also more up-to-date rooting tools beyond rootmy.tv. The security posture of webOS is absolutely terrible, at least, it is in the way LG deploys it.

> The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining. But vulnerabilities that can be remotely exploited without user interaction (CVSS grade 9-10)?

Why do you even ask? Why do you even think this is at all unlikely?

It doesn't even matter what exploits are publicly known and closed at any given moment. What we know is that at every given moment, no matter what security hole was just found and closed right now in some device, always later it turns out there were others not yet known by you but known and used by someone. This has been everything with an OS for 40 years. So yes, of course, right now, on every tv, and everything else, from any manufacturer, there are "grade 9-10" exploits just sitting there. It's the default state not some exception.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#114
post #78
post #72

Earlier quoted context omitted.

I think you're being deliberately obtuse. You would update software on a TV for all the same reasons you update software on any other device: improved performance, better compatibly, new features, etc

No. My computer is a tool I actively use. The TV is an almost entirely passive consumption device. Was performance not good enough when it was new? If it wasn't, will the new software versions truly buck the trend we've seen in software for the past few decades and improve performance? What new features are necessary? Video playback has been a solved problem for the past few decades.

All of the software on a tv is a client to some service, and the service changes constantly, and so must also the client whether anyone likes it or not, and you already knew all of this perfectly well.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#115
post #86

I’m convinced the only thing saving us from hardware manufacturers security incompetence is NAT

I am still somewhat new to networking concepts (currently reading Computer Networking: A Top Down Approach by Kurose & Ross), and as far as I understood, most IPv6 networks don't have a NAT, or did I misunderstand? If that is the case, that means homes using IPv6 have globally routable IP addresses for their connected devices, right? Would the router's firewall protect it if it denies incoming connections?

Yeah you just need to remember to login to your totally-not-corrupt ISP's definitely-easy-to-use firewall manager app and setup your firewall rules to prevent hostile governments from using your microwave as a passive listening device, which they sell back to your own government for probable cause, to arrest you for cooking the wrong brand of popcorn.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#116
post #85

Earlier quoted context omitted.

Yeah, it is insane a fully open source firmware with reproducible builds is not a minimum standard for something as sensitive as a modern smart TV.

It is not the minimum standard for computers. Why should it be for TVs?

It should be the minimum standard everywhere.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#117

They rooted the TV to study it. They're not saying you're in sudden danger of attackers rooting your TV and running commands over SSH. They're saying there's evidence that certain data is collected when you wouldn't want it to be, and there are any number of potential vulnerabilities that could provide hackers access, on top of LG potentially having access as well which you also probably wouldn't want.

They still run the audio recording manually through SSH and then claim that your TV is spying on your private conversations "silently". Otherwise, they start a voice command service (clearly displayed on the screen) and then say your TV is recording on your conversation. Like duh, of course my TV starts recording voice when I use voice commands. And of course you have to trust LG with their TV and (not) having access…

I don't think you paid very close attention. They clearly showed it transcribing audio when the TV was "switched off". And they weren't "running audio recording through SSH", SSH was just incidental to watch the audio recording and transcription that was happening.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#118
> If you root or jailbreak your devices, you've, by their very nature, broken their security.

Yeah no this is just incorrect. There's many cases where jailbreaking actually fixes issues when a vendor abandons the platform. It also enables usefulness for a product long after it's been EOL'd.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#119
post #27

Thanks for the write-up, it reflects my own impression of the video. The video is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across. They should have decided to set the focus on a specific area and then present every finding around that, i.e.: 1. The Ad data-collecting platform TV-manufacturers are operating, what data they…

Yeah if GN wants to keep my attention on this topic they need to edit out all the stuff about normal Wi-Fi stack behaviors and normal local device discovery behaviors. They didn't need to pad their feature-length video with these non-issues.

> normal Wi-Fi stack behaviors and normal local device discovery behaviors

Sending to LG a JSON with a list of all the devices in the current broadcast domain is NOT "normal local device discovery behaviors" and everyone should be irate about it. Stop normalizing capitalism surveillance.

Re: GamersNexus and LG: Or why rooting your TV is a bad idea

#120
post #75
post #61

Earlier quoted context omitted.

Not disclosing a vulnerability you found to the manufacturer (while the product can still hopefully be patched) is “not responsible”. I think that’s what the person is trying to say.

It seems that some people do not appreciate the amount of labour that can be required to turn knowledge of a vulnerability into an actionable bug report. (Before someone says "ask an LLM to do it", LG has that option available to them, too) It is certainly not work that I would do to benefit a many-billion dollar company, for ~free. I may do it to benefit device owners such as myself, instead. LG is solely responsibl…

Looking forward to your writeup/talk/whatever. Root via analog(?) RF signal sounds amazing.
Post reply on HN