Live data from Hacker News

LG to ban residential proxies from smart TV apps

krebsonsecurity.com

321–330 of 549 posts

Re: LG to ban residential proxies from smart TV apps

#322
post #279

Earlier quoted context omitted.

3 out of 4 OLED screens in my household suffer from burned pixels. It's the early 90s all over again with OLED.

How old are these and how often / how long are they turned on? My OLED TV is over two years old now without any issues even though it gets frequent usage.

I don't buy a TV every 2 years, that's absurd. If I buy a TV, it better work for > 10 years.

Re: LG to ban residential proxies from smart TV apps

#325
post #30

Stop hooking up your LG tv to any network

Want to stream Netflix? Disney+? Hulu? You need to hook something up to a network, and another device would have similar risks. Setting up a sandboxed VPC or auditing traffic is beyond the means of the average TV owner.

The problem is that the LG company went full-spyware. It's not a mere risk, they turned hostile on their customers.

Re: LG to ban residential proxies from smart TV apps

#326

Earlier quoted context omitted.

Japan is full of them

interesting. any idea why?

they say that Japan is simultaneously living 20 years in the past and 20 years in the future. lots of legacy devices are still being used for all manner of quirky convenience contraptions. they also live in an extremely high trust society where networks don't necessarily need to be secured

If you want a very specific example, the original nintendo DS can only connect to WEP connections, which meant that when I was there I was able to play parts of DS games that wouldn't have been accessible in the west

Re: LG to ban residential proxies from smart TV apps

#327

Earlier quoted context omitted.

sudo dkpg -i FileYouDownloadedFromAnywhere.deb

Let's be real, in most cases it is: curl -s script.random-guy.net | sh It is such glaring security hole that there was an old submission about filling such install script with `sleep` commands and detecting it on server side, to send different versions for downloading (and reviewing) and for actual direct execution.

    wget https://raw.githubusercontent.com/timofurrer/russian-roulette/master/russian-roulette -O - | sudo bash

Re: LG to ban residential proxies from smart TV apps

#328

Earlier quoted context omitted.

> It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs This is also a misrepresentation. Microsoft has provided LG with a certificate to sign its driver packages with, and allows LG to upload packages to Windows Update, which includes a feature to install sidecar applications. Now, the spirit of this feature is that any application is meant to provide genuine configuration functionality…

My point is not to shift the blame to Microsoft; it's primarily LG that's at fault here. My point here is simply that it's not the monitor that is installing this . Neither the malware nor the URLs to malware exist on the device - they get fetched as part of normal OS-side auto-provisioning, which is the part that was compromised.

This is a primary LG fault, however I would say that Microsoft also has a fair bit of blame here.

They are downloading and installing something without the users consent.

It's nice to have drivers work without any intervention, same with "helper software" but along side the ease of use they also took on the responsibility.

If I download some random .exe from the net; I have to confirm that I want to run it, sometimes I even have to right click and unblock it to allow it to run, because it is "untrusted".

Their signature key, their auto-run system, everything done for ease of use means they own this.

Otherwise what does "trusted" mean?

Re: LG to ban residential proxies from smart TV apps

#329

Earlier quoted context omitted.

On the trackpads - I only ever use my MacBook as a single screen device, so the experience may be different. A long time ago I used it with an external monitor and the experience was very poor compared to windows. > Ugh, this is annoying. Hardware vendors need to be banned from writing lousy, inefficient, unsafe software. Yeah, I commented on the McAfee LG thread but the stuff that comes bundled with hardware is emba…

What part of Afterburner caused issues? I have it installed to undervolt an old GPU but not actively running.

One of the big ones is people just over clocking way past what’s sensible. Another is stuff like https://www.reddit.com/r/pathofexile/comments/z3xf5r/msi_aft... or https://www.reddit.com/r/pcmasterrace/comments/ob5jam/msi_af...

Other overlay apps like discord https://www.reddit.com/r/discordapp/comments/1jncrlc/new_ove... have similar issues - the way they work is by drive hooks and drawing over the application; depending on how close you are to the limit and how the game loop is coded this can very easily (and often does) cause micro stuttering, and in cases like discord causes massive performance problems regularly.

Re: LG to ban residential proxies from smart TV apps

#330

Earlier quoted context omitted.

Only reason LG doesn't have adverts is by forcing it to use a pihole, but even that needs updating -- recently they've managed to push things through and I need to do another investigation to see what needs blocking. Trouble is I only see them when I'm not in the mood to be working, and then forget about them

They hardcode DNS servers into the TV. You need a firewall in front of the pihole intercepting that traffic, I use OpenWrt.

Given how cheap screens are, I'm puzzled as to why keeping a smart-ass TV is worth this effort?
Post reply on HN