Live data from Hacker News

Smart TVs sending sensitive user data to Netflix and Facebook

ft.com

381–390 of 524 posts

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#381

Gee who would have seen that coming...

Might as well buy an Alexa, LOL...

At this point, people have to wonder what benefits the IOT fabric provides THEM versus what benefits it provides the vendor or configurator/bundler...

Of far greater concern is the pile of unpatched linuces these crapware bloatware "embedded linux" devices tend to be equipped with. It's an entry vector...

or hardcoded "admin:admin" login credentials...

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#382
post #150

Earlier quoted context omitted.

Oh FFS I just learned this was a thing, I can't even trust my cables anymore.

Be aware that your ethernet cables could also be powering stuff, so that's another cable to watch out for ;)

Watch out for the reverse too, ethernet over powerline is a thing!

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#384
post #206

Earlier quoted context omitted.

Sorry, I was being a bit lazy in my comment. I didn't specify, but I don't really suspect they are sending full frames back if for no other reason than bandwidth. But, honestly fingerprinting is so similar it might as well be the same thing. Though thankfully, yes, the fingerprint calculated for something personal probably is meaningless to them, but possibly could be replaced with a reversible option

One danger is that videos can now "phone home" with the TV they're viewed on. You could torrent through Tor and take all sorts of precautions, then watch on your TV at home and leak your viewing habits. Or worse, get someone else targeted for copyright enforcement if you watch pirated content on their TV.

How would data in the video be used to direct the TV to phone home? As in, what field would be set?

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#385

> Smart TVs sending sensitive user data to Netflix and Facebook No way! Has that ever been news? It is the first thing that comes to mind when some product 'needs' to be connected to the internet. Sending private data is most likely the only reason a internet connection can be made with the device. All the 'great' software around it is only fluff supporting to lure people sending their private data unknowingly. Do th…

The problem is that I want to just use the netflix built-into the TV. Firing up a separate device just to watch something seems like a waste of energy to me, and then I probably need a separate controller for it(like, I can control the PS4 with my TV remote, but I cannot switch it on remotely without using the DS4). >>I have a new x-large smart tv which I would never connect to the internet for these reasons. I use a…

No. It's a linux, and there is no mic or cam connected. I use Netflix too, works like a charm. And I can understand your temptation of using the Netflix button on the remote control, it's one of the lures.

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#386

This is a pretty open secret within the industry. Geographic data can be provided via setup (a lot of TV's ask for a zip code on setup) or usually simply via GeoIP lookup. Dig a bit deeper and you get into service provided by Samba TV and or Inscape and you can find that they're sending back frames of video in a lot of cases to track what you're watching. This data is becoming a huge mechanism for subsidizing TV sale…

How do Doctor's that use TVs like this in meeting rooms get around HIPAA? or other places with PII, etc? With so much stuff being thrown to TVs now, a lot of times they are inheriently monitors, and there are very few people who think taking a screenshot of a monitor is not invasive.

We buy super cheap TVs for our meeting rooms, and then just never connect them to the internet. They have Netflix etc on them, but none of it works. We then just use HDMI or Chromecasts that are provisioned on the company GSuite account.

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#387
post #384
post #206

Earlier quoted context omitted.

One danger is that videos can now "phone home" with the TV they're viewed on. You could torrent through Tor and take all sorts of precautions, then watch on your TV at home and leak your viewing habits. Or worse, get someone else targeted for copyright enforcement if you watch pirated content on their TV.

How would data in the video be used to direct the TV to phone home? As in, what field would be set?

I guess it would be a watermark style change through all the video frames which affects the hashes - e.g. brightness or contrast or sharpness or some combination of that kind of thing - then seed that on torrent sites, and advertisers get to see which TVs watched the torrented film vs the official film.

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#389
Kind of off topic, but I have an older Samsung smart tv. It has an ethernet connection, but it didn't have any option for WiFi. For a few years I had it wired up to ethernet, and after rearranging where my router lived in the house I didn't have a long enough ethernet cable, so I hooked up a USB WiFi dongle. It worked great for a few months until I needed that dongle to connect a Raspberry Pi to WiFi, so I stole it from the TV...and lo and behold the TV still had internet access via WiFi! The only thing that I think could have happened is that the TV had WiFi hardware but was disabled in software, because at the time a WiFi TV was selling at a premium and this was a cheapo one I bought from Wal-Mart. So I guess hooking up the USB dongle somehow unlocked it. It kinda freaked me out that there was hidden WiFi hardware in there.

edit

The tv definitely phones home too, my Pi Hole blocks a few hundred attempts to lookup log-ingestion.samsungacr.com, xpu.samsungelectronics.com and upu.samsungelectronics.com per day.

Re: Smart TVs sending sensitive user data to Netflix and Facebook

#390
post #250

Earlier quoted context omitted.

Encrypted ones do, at least every commercial version these TV’s would be able to use. https://en.m.wikipedia.org/wiki/Wi-Fi_Protected_Setup Is the closest thing to an exception that I know of but still required user action to connect, and it’s been deprecated for a long time. Some enterprise systems don’t require users to enter passwords, but the software still uses them internally when talking to the network. PS: Un…

Nothing’s stopping TVs from hopping on unencrypted networks.

WiFi has limited range, so some people have control over what local networks exist.
Post reply on HN