Remix.run Logo
Retr0id 3 hours ago

> So no responsible disclosure, I see.

Huh?

rickdeckard 2 hours ago | parent | next [-]

You stated that you're "sitting on one that doesn't even require an internet connection [..] I'm waiting for my model to go EOL before I release it"

I read this as "Wait until the model is EOL, hoping it won't be disclosed and fixed until then and also not fixed afterwards"

Is this not what you meant to say?

mort96 2 hours ago | parent | next [-]

Responsible disclosure makes sense when the user and the manufacturer have the same goal of the product being secure. Jailbreaking is a case where the user and the manufacturer have opposing goals: the user wants to be in charge their hardware, the manufacturer wants to prevent the user from being in charge of their own hardware. Responsible disclosure doesn't make sense, the manufacturer would just patch the vulnerability before users could use it.

If manufacturers had a sanctioned way for the user to get root access to their own hardware, responsible disclosure would've made sense, but as it is, vulnerabilities are a useful tool for the owner of the device.

rickdeckard 42 minutes ago | parent | next [-]

To me as a user, responsible disclosure is most-valuable for every vulnerability that could be exploited remotely without me being in control.

The video draws exactly that picture, a nefarious actor, remotely taking control over my TV and recording Audio from it

mort96 31 minutes ago | parent [-]

To me as a user, responsible disclosure takes away my right to do what I want with my hardware.

rcxdude an hour ago | parent | prev [-]

Exactly. This control-freak nature of manufacturers is sadly what makes me cheer for the security holes much of the time.

p0lychromatic 27 minutes ago | parent [-]

Yet here we are, in this thread, discussing why LG is spying on us.

While some stuff are legit issues such as ADR, people now think they are wire-tapping. Because somebody used a rooted device to show-case recording silently through their device.

Can you blame corporations having this control-freak nature when shit like this happens?

It's stuff like this that likely pushes corporations now to invest more into device security, and locking down their stuff more.

Good for security and the corporation.

Maybe mid-term good for you consumer, because they might get more cautious with tracking stuff.

But long-term bad for you consumer, too, because they will make sure to lock down their devices better.

mort96 25 minutes ago | parent [-]

The best solution is obviously sanctioned rooting so that vulnerabilities can be freely shared with manufacturers and fixed.

But that's not going to happen.

MrGilbert 2 hours ago | parent | prev [-]

This would be one way to interpret it. Another way would be: "If the model is EOL, the potential attack surface gets lower, because you cannot buy it any longer and the amount of devices in use will reduce over time."

On a different note: Are you, in any way, affiliated with LG? You read to me as someone who is "unhappy" with the findings.

rickdeckard 33 minutes ago | parent [-]

The attack-surface doesn't get lower, it just doesn't continue to increase UNLESS the same vulnerability is not carried over to other products.

The attack-surface only gets lower when the TV is no longer in use and is disposed. That doesn't happen at EOL, customers don't suddenly throw away their TVs after 2 years.

I'm happy with the findings and hope that it gains momentum, but unhappy with the dilution of the matter with speculation, assumptions and sensationalism, because it allows the vendor to wiggle out of it and wait for attention to wind down.

I would prefer a clear spotlight to be shined on #1 the ad-networks business model of TV-manufacturers and #2 the security of their (very powerful) products.

If the process results in regulation which also requires the TV manufacturer to offer root-access to the consumer to verify and control its operations, I would be overjoyed.

But this is unfortunately not a subject of the current narrative at all, it will actually result in the opposite (more effort to lock-down the OS to prevent future sensationalism reporting)

Diti 2 hours ago | parent | prev [-]

Not disclosing a vulnerability you found to the manufacturer (while the product can still hopefully be patched) is “not responsible”. I think that’s what the person is trying to say.

Retr0id 34 minutes ago | parent [-]

It seems that some people do not appreciate the amount of labour that can be required to turn knowledge of a vulnerability into an actionable bug report. (Before someone says "ask an LLM to do it", LG has that option available to them, too)

It is certainly not work that I would do to benefit a many-billion dollar company, for ~free. I may do it to benefit device owners such as myself, instead.

LG is solely responsible for the security of the products that they choose to sell.