Remix.run Logo
Phemist 7 hours ago

Also debunked in the Gamer Nexus video. The TV will scan for public wifis and connect. Watching the video, it also seemed like a "missed opportunity" for LG to not create a mesh network of LG devices that would help eachother connect to the internet. So the LG device on your neighbours wifi might help your not connected TV to some tasty internet access. Or at least to unload its cache of A(V)CR fingerprints.

LG is truly an adversial party in all of this.

ZoneZealot 7 hours ago | parent | next [-]

They didn't actually say it does that. They said it could do that. It doesn't (yet).

hdgvhicv 7 hours ago | parent | prev [-]

There are so many misunderstandings about that video. Which ain’t surprising as it was longer than a movie and mainly nonsense about what it can do rather than what it does do.

semiquaver 6 hours ago | parent [-]

Agreed. I’ve come to believe that the video’s benefit from bringing awareness to the issue is outweighed by how misleading it is. Massive amounts of the video were “we hacked the TV and made it do [bad thing]” and was reported as “LG TVs do [bad thing]!”

okamiueru 3 hours ago | parent | next [-]

Did we watch a different video? The point of hacking the TV, and making it do bad thing. Was to explain the privacy issues inherent with the hardware capabilites for video and audio recording, which combined with multiple known exploits to gain access.

It's a long video, and they cover more than one issue. Please explain what, in particular, you found was misleading.

hdgvhicv an hour ago | parent [-]

So a Linux computer with a microphone and network access can send that mocrohpine to the Internet or record it. That’s obvious. That it can scan for WiFi networks is implied by the fact it had WiFi chip, and even exposes that functionality via the front end is also obvious. That it participates in MdNS is known for the fact it’s an mdns target.

What would be worthwhile is what is actually sent. The breathless reporting on it suggests it scans your network, I’ve never seen anything in my router logs to show any kind of port scan or even arp scan.

The only thing that’s seem to be a problem is the ages old adtech which the tech industry tends to be quite happy with as it pts so much of the bills for so many companies

ulyssys 5 hours ago | parent | prev [-]

Disclaimer: I haven’t yet watched the video, but on the point of security: yes, when data is collected without my clear approval and full understanding, and is not done in a secure way, it matters all the more.

It’s of little concern to me that the threat is theoretical when it’s only a matter of time before a script kiddy or some bored guy with a YouTube tutorial and $20 of AI credits sets it up himself, let alone well-funded groups or motivated actors.

Unmanaged IOT devices in general are not to be trusted. LG isn’t leading with transparency nor are they big enough like Microsoft or Apple to put out bug bounties and audits with hundreds of thousands of eyeballs on them. They make the device that sits in the corner of your living room and is forgotten about. They’re being cagey about the data they collect and how they collect it, and I’m asked to take the risk on “trust me bro” and “you’re required to tell anyone within earshot of the TV’s mic that they’re being recorded”? Fuck that.

Never mind that data being exposed even if encrypted is a risk all its own: the collection can start now, and whenever it’s detected and blocked it’s too late. It can be cracked later whenever they have the tech and the time.