GamersNexus and LG: Or why rooting your TV is a bad idea
Posted by drasticactions 10 hours ago
Comments
Comment by adithyassekhar 8 hours ago
His arguments are all
- yes everyone does this not just lg; :)
- yes it can be used to track the user; but unless you literally go into lg ads hq, you can’t say they don’t
- they rooted to trigger this; well the os and system apps don’t need root, we need it to observe.
If the author is here please consider these as the reasons to why an LG customer would be mad.
- They did not knew LG has an ads subsidiary, whose CEOs and executives constantly go on investor meetings claiming “they own the glass”, “they own the living room”, “they own the network and devices” in the “lg household”
- if the above was said by lg tv division it would have still stung less. This was said by an ad company they didn’t knew existed nor did they agree to be associated with when they bought a home appliance.
Stop focusing on the technical details, look at the larger picture.
Comment by drbscl 7 hours ago
Also, I anticipated ads on a smart TV (unfortunately it's inevitable), but (wrongly) assumed that such invasive tracking and "we own the glass" would be a bar too low even for the budget manufacturers.
I'm never buying any LG product ever again.
Comment by cassianoleal 5 hours ago
I also had an LG washing machine. The dispenser plastic drawer broke after a year of use. After over a week of multiple emails and calls with the shop, LG themselves and third-party spares shops trying to get a replacement, I bought a Bosch.
I am also never buying anything from LG again.
Comment by psd1 4 hours ago
May i suggest basic home repair? Two techniques that work in many cases are:
- "welding" with a soldering iron, using cable tie as a filler rod. You'll want good ventilation and a sacrificial tip - epoxy repair putty
Superglue (cyanoacrylate) tends to give disappointing results on its own, but can be a good first step before putty. Putty can be reinforced with some kind of fibre. Never use cyanoacrylate with the welding technique (cyanide).
I don't love the model profusion that makes spare parts markets inefficient, but free markets are inefficient all over the place. Price in the externalities.
Comment by stdbrouw 4 hours ago
Comment by psd1 4 hours ago
Comment by croon 5 hours ago
Better yet would be never needing an update, but alas.
Comment by rickdeckard 7 hours ago
There is substance in what they did. But they should have worked with an actual journalist to frame this properly and create pressure on the overarching topics.
If a TV company (LG or ANY of the others who have Ad-subsidiaries) needs to respond to this video, they can easily reframe the whole topic.
The most blatant example is that they demonstrate in the video that this TV, which has a built-in microphone for voice-control, that can be switched off with a mechanical switch:
1. Will record your voice when you ask it to transcribe your input to a textbox
2. Will process your voice to create this text it shows, as visible on the logs of the rooted OS
3. Will SHOW you that it's transcribing your input on the screen.
This is weakening the whole story.
--
In HN-terms: It's a constant-power, constantly-connected IoT-device with lots of sensors and huge compute-power, located in the center of your home.
There are big topics around this that deserve a huge spotlight, which apply to ALL TV manufacturers:
a. What data is actually being collected about the user, and what is done with this data?
b. How well is security handled on the TV to ensure no malicious usage?
Repeatedly jumping to the conclusion during the video that LG specifically is collecting ALL this local data to spy on you, without clear evidence, this just gives LG an easy way to respond and every other vendor enough room to distance themselves from the whole story.
Comment by taurath 7 hours ago
This question implies that the answer could be something other than the maximum amount of data collection and monetization of that data they can get away with.
If that statement gives you pause please spend even a short amount of time reading about ad networks, data brokers, and corporate surveillance.
Comment by rickdeckard 6 hours ago
So even IF that would be a sufficient answer in a court of US, it would not be sufficient in a court of an EU country.
--> Hence my point on how the overall message was diluted too much.
See, you may look at all this as "nothing can be done anyway, so let's bunch it all together and rant about it as emotionally as possible". But I look at it as "this is all potential evidence that a law was either already broken or needs to have a loophole closed"
But you won't get any of this done by spraying all over how normal this is and how everyone does it anyway. You get this done with a precise shot at ONE of them, concise enough to pin them down while aiming at the next one.
Comment by lukeschlather 7 hours ago
Actually I think everything you're suggesting is unclear, LG explicitly say they do these things in their ToS. I skimmed their privacy policy, and I'm pretty sure it essentially says they collect all this information and use it for targeted advertising.
Comment by rickdeckard 6 hours ago
So there's the angle that US is lacking the proper regulation, and the angle that LG may have violated its ToS in the EU.
But neither of this is going to get pinned down if everything is bunched together without focus and clear evidence...
Comment by psd1 4 hours ago
Comment by stuaxo 7 hours ago
It's either a deliberately contrary or the author has other motives (which may sound ridiculous, but we know that bad actors have been paying people for bad takes for years - Malcolm Gladwell for instance being paid by oil and gas).
Comment by shellfishgene 7 hours ago
Comment by expedition32 4 hours ago
Uhm every tech bro does this it is what makes the tech industry a fucking Bond villain lol.
Comment by Retr0id 9 hours ago
> If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.
There are ways to remotely jailbreak LG webOS TVs without user interaction, using the same (or similar) vulnerabilities you use to root your own TV voluntarily.
The main reason tools like https://rootmy.tv are prefixed with disclaimers and require user interaction is because we're being courteous, not because they're technically necessary. (source: I own the rootmy.tv domain)
Comment by froddd 8 hours ago
Comment by Retr0id 8 hours ago
The security posture of webOS is absolutely terrible, at least, it is in the way LG deploys it.
Comment by rickdeckard 8 hours ago
But vulnerabilities that can be remotely exploited without user interaction (CVSS grade 9-10)?
Comment by Retr0id 8 hours ago
Comment by minetest2048 8 hours ago
Comment by delta_p_delta_x 8 hours ago
Holy shit. RF to zero-click exploit is a new one. I guess digital-everything wasn't always a good idea, this probably wouldn't ever have been a problem with analogue antennas and CRTs.
What are the people at LG even doing?
Comment by Ekaros 8 hours ago
Comment by hnlmorg 7 hours ago
As an aside, I once interviewed one of the guys who wrote Teletext processors for analog TVs. He was a very interesting individual.
Comment by rickdeckard 8 hours ago
So no responsible disclosure, I see.
Not knowing any more details, it still sounds like you'd still need the user to tune to the actual frequency on the correct receiver (to cause some buffer overflow?). But then still there's no internet to do anything. So you'd need some very specific f/up exploit to then change local settings on the device I imagine.
Either way, would be a great opportunity to demonstrate this in a video, now that there's attention on the topic, to further amplify the pressure on LG's "terrible security posture" as you say.
Comment by michaelt 6 hours ago
If I, a corporation, declare that I only accept security reports carved on clay tablets in ancient greek and hand-delivered to my office in Timbuktu during a total solar eclipse - does that stop responsible security researchers from disclosing their findings publicly?
Of course not.
If the guy sends a clear message to the best public contact address he can find with 15 minutes of searching; and gives them 30 days to patch before publicly disclosing the bug; then he's performed responsible disclosure.
The vendor's corporate policies and release cycles and contact addresses and triage procedures are their problem.
Comment by RobotToaster 5 hours ago
If the manufacturers responsibly included a responsible way to install custom software/firmware, perhaps people would feel more inclined to help them. Their current attitude buys them very little goodwill.
Comment by Retr0id 8 hours ago
Huh?
Comment by rickdeckard 7 hours ago
I read this as "Wait until the model is EOL, hoping it won't be disclosed and fixed until then and also not fixed afterwards"
Is this not what you meant to say?
Comment by mort96 7 hours ago
If manufacturers had a sanctioned way for the user to get root access to their own hardware, responsible disclosure would've made sense, but as it is, vulnerabilities are a useful tool for the owner of the device.
Comment by rcxdude 6 hours ago
Comment by p0lychromatic 5 hours ago
While some stuff are legit issues such as ADR, people now think they are wire-tapping. Because somebody used a rooted device to show-case recording silently through their device.
Can you blame corporations having this control-freak nature when shit like this happens?
It's stuff like this that likely pushes corporations now to invest more into device security, and locking down their stuff more.
Good for security and the corporation.
Maybe mid-term good for you consumer, because they might get more cautious with tracking stuff.
But long-term bad for you consumer, too, because they will make sure to lock down their devices better.
Comment by mort96 5 hours ago
But that's not going to happen.
Comment by rcxdude 5 hours ago
(And yeah, as pointed out by another comment, if you officially allow users full control of their devices, you are less likely to have people sitting on undisclosed exploits so that they can get it without your help, and as a bonus you have an easier argument for why you are not liable for what someone does with that control)
Comment by croon 5 hours ago
> Can you blame corporations having this control-freak nature when shit like this happens?
Is "shit like this" referring to the corporation spying on the user, or the user discovering it? Because one happened before the other, and so impossibly could have caused the former.
> It's stuff like this that likely pushes corporations now to invest more into device security, and locking down their stuff more.
Or they could just sell the device users want, and not sell their users.
Comment by rickdeckard 6 hours ago
The video draws exactly that picture, a nefarious actor, remotely taking control over my TV and recording Audio from it
Comment by mort96 5 hours ago
Comment by MrGilbert 7 hours ago
On a different note: Are you, in any way, affiliated with LG? You read to me as someone who is "unhappy" with the findings.
Comment by rickdeckard 5 hours ago
The attack-surface only gets lower when the TV is no longer in use and is disposed. That doesn't happen at EOL, customers don't suddenly throw away their TVs after 2 years.
I'm happy with the findings and hope that it gains momentum, but unhappy with the dilution of the matter with speculation, assumptions and sensationalism, because it allows the vendor to wiggle out of it and wait for attention to wind down.
I would prefer a clear spotlight to be shined on #1 the ad-networks business model of TV-manufacturers and #2 the security of their (very powerful) products.
If the process results in regulation which also requires the TV manufacturer to offer root-access to the consumer to verify and control its operations, I would be overjoyed.
But this is unfortunately not a subject of the current narrative at all, it will actually result in the opposite (more effort to lock-down the OS to prevent future sensationalism reporting)
Comment by Diti 6 hours ago
Comment by Retr0id 5 hours ago
It is certainly not work that I would do to benefit a many-billion dollar company, for ~free. I may do it to benefit device owners such as myself, instead.
LG is solely responsible for the security of the products that they choose to sell.
Comment by hypfer 1 hour ago
Comment by Brian_K_White 3 hours ago
It doesn't even matter what exploits are publicly known and closed at any given moment. What we know is that at every given moment, no matter what security hole was just found and closed right now in some device, always later it turns out there were others not yet known by you but known and used by someone. This has been everything with an OS for 40 years. So yes, of course, right now, on every tv, and everything else, from any manufacturer, there are "grade 9-10" exploits just sitting there. It's the default state not some exception.
Comment by mort96 7 hours ago
Comment by dgellow 6 hours ago
Comment by mort96 6 hours ago
Comment by bcraven 5 hours ago
Comment by mort96 5 hours ago
Comment by sersi 5 hours ago
Comment by mort96 5 hours ago
Comment by Brian_K_White 3 hours ago
Comment by franga2000 8 hours ago
Comment by toast0 8 hours ago
I presume LG is like most vendors and stops issuing updates for older models after a while. It's pretty hard to keep software up to date when the vendor stops issuing updates.
Comment by LoganDark 8 hours ago
Comment by rickdeckard 8 hours ago
The video is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across.
They should have decided to set the focus on a specific area and then present every finding around that, i.e.:
1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.
2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.
3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.
All the points and scenarios in the video might be valid, but they jump between those scopes and imply that its all the same, weakening the whole investigation.
If I'm LG and forced to respond to this, I can easily focus on dissecting the voice-input topic as a mere demonstration of the feature and how rooting the TV beforehand just showed the local process of handling it, steering the narrative away from the (IMO) much more important topics...
Comment by jeffbee 8 hours ago
Comment by rickdeckard 7 hours ago
Comment by rcxdude 6 hours ago
Comment by bakugo 6 hours ago
It's unfortunate, because they're one of the few voices speaking out about issues like this.
Comment by expedition32 4 hours ago
Comment by thefz 1 hour ago
Sending to LG a JSON with a list of all the devices in the current broadcast domain is NOT "normal local device discovery behaviors" and everyone should be irate about it. Stop normalizing capitalism surveillance.
Comment by taylorfinley 8 hours ago
Comment by pmlnr 8 hours ago
Wow. Please stop spreading things like this.
Not having root means not owning a device you paid for and have in your home.
Comment by p0lychromatic 7 hours ago
Of course root allows you to tinker with your device and make it run what you want, but:
- Rooted devices make devices unpredictable. As shown in the video: How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?
- Re-selling: How do you know that TV you bought is untampered? How do you know it does not have software with malware installed that steals your credentials?
Comment by cryptonym 7 hours ago
Comment by pmlnr 5 hours ago
you/we/me not having root while, for example, Google Play Services does on invalidates everything you said.
Comment by p0lychromatic 5 hours ago
Compared to, say, random Magisk modules or some random crap the OEM developed?
Comment by sdcfgy 5 hours ago
If it’s a problem, unplug it.
If it’s a problem, don’t buy it.
Works for everything!
Comment by like_any_other 7 hours ago
Many rooted devices display during boot a warning that they have been rooted. This is a problem that has been solved for more than a decade, but manufacturers pretend not to know the solution, because they are actively hostile to user freedom.
> How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?
Let's pretend there aren't plenty other ways they could spy on you. If it's bad if a hotel does it, why is it okay if LG does it? Do you honestly trust LG, and the thousands of "partners" that they sell your data to, and every government whose warrants they have to honor?
Your argument reduces to "if the warden lets us out of our jail cells, who will make sure we behave?"
Comment by p0lychromatic 6 hours ago
Usually, this happens after a bootloader unlock because then verified boot is disabled. You can still have a rooted device and not break verified, resulting in no warning. See: jailbroken iPhones.
I wouldn't say it's a solved problem. Just have to find an exploit that works with verified / attested boot.
And device manufactures are getting more and more restrictive here, too. Why do you think that is?
> Let's pretend there aren't plenty other ways they could spy on you.
Sure, of course there are other ways to spy on people. But as we see here: If the device itself does it, then we like to blame LG. If they used an exploit to do that, then we blame LG's shitty security.
If a hotel owner installed a microphone inside one or their specific TVs, then we blame the hotel owner at least - not LG.
> If it's bad if a hotel does it, why is it okay if LG does it?
It doesn't seem like it is okay. We are discussing this right here.
> Do you honestly trust LG, and the thousands of "partners" that they sell your data to, and every government whose warrants they have to honor?
Do I trust LG more than a shady hotel / BnB owner or eBay seller? Yes. Do I trust them fully? No. It's not fully binary, I'd say.
> Your argument reduces to "if the warden lets us out of our jail cells, who will make sure we behave?"
I am just trying to say, it's really not that binary. You can extend that to other places whenever attestation is involved.
Do I like Linux and open platforms? Sure! Tampering is fun! Do I hate people using open platforms to scrape my websites and constantly cause load, steal my content and use that for AI training? Also, yes.
But how can I fight that? We run into CAPTCHAs, Cloudflare, Anubis and co. Now that issue is reduced, but the openness is also gone.
And you always see in tech spaces we rather want "dumb" devices rather than smart devices, because we cannot trust them.
Attestation buys you more trust, but at the cost of openness.
Comment by sersi 5 hours ago
In general though on devices that are rootable, white-hat hackers are more inclined to responsibly disclose vulnerabilities instead of releasing them as a way to root said device. So having a rootable phone does increase security.
What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.
Comment by p0lychromatic 5 hours ago
> What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.
I'll ask naively: Why not? I can come up with a bunch of arguments why it does help the bank and why it might reduce the risk of certain attacks.
Comment by armadyl 7 hours ago
But in this case… I don’t know. The OEM is so actively hostile you might be better off just taking the risk with root if you must purchase it at all (and physically removing the radio/microphone hardware not being an option).
Comment by mort96 7 hours ago
Comment by dugite-code 46 minutes ago
If you don't have root rights, you don't really own it. All other arguments are talking past this key point.
Comment by rickdeckard 7 hours ago
The inevitable outcome of this video is that TV vendors are pushed to harden the security and preserve the trust-chain, because part of the (valid) claim is that nefarious actors may break the security to use the device for spying on you.
With support from an actual journalist, it could be reframed to also emphasize the importance of controlled root-access to monitor and control the devices behavior.
But none of this was done unfortunately, and if I'm LG I don't want to see another video where someone reframes user-initiated voice-input for a web-search as spying initiative by showing some device-logs of the transcription process in parallel...
Comment by m4rtink 5 hours ago
Comment by pmlnr 5 hours ago
Like every single Microsoft laptop out there does so? Think a bit harder before sentences like this, please.
Comment by badsectoracula 9 hours ago
Do you actually want a channel with 2.66 million subscribers to show how to get remote access to TVs used by millions of people? :-P
Comment by Krutonium 9 hours ago
Comment by m4rtink 5 hours ago
Comment by jaimex2 8 hours ago
Comment by Arcuru 8 hours ago
Comment by supriyo-biswas 8 hours ago
Comment by VCFundedGenYer 1 hour ago
Yeah no this is just incorrect. There's many cases where jailbreaking actually fixes issues when a vendor abandons the platform. It also enables usefulness for a product long after it's been EOL'd.
Comment by bob1029 9 hours ago
The influencer economy is a bit soaked these days. You need to crank up the stakes to keep the viewer's attention.
Comment by fulafel 8 hours ago
Comment by p0lychromatic 8 hours ago
That does not mean that LG does all that by default.
Comment by t_mahmood 4 hours ago
Comment by nokeya 7 hours ago
Comment by m4rtink 5 hours ago
Comment by p0lychromatic 5 hours ago
Comment by m4rtink 2 hours ago
Comment by Havoc 5 hours ago
Comment by pid0x17 4 hours ago
Would the router's firewall protect it if it denies incoming connections?
Comment by liveoneggs 2 hours ago
Comment by LoganDark 8 hours ago
Comment by p0lychromatic 8 hours ago
Otherwise, they start a voice command service (clearly displayed on the screen) and then say your TV is recording on your conversation. Like duh, of course my TV starts recording voice when I use voice commands.
And of course you have to trust LG with their TV and (not) having access. That same logic applies to every different company.
Comment by headsman771 2 hours ago
Comment by wewewedxfgdf 7 hours ago
GamersNexus did an investigation which may overstate the privacy threat posed by LG smart TVs.
Comment by laylower 4 hours ago
They literally write "Now, I’m not going to claim to be a network expert. I may be totally off-base, but what? Reverse DNS? I don't know what this means."
The findings are a smoking gun already.
The bar shouldn't be a video of an NSA agent or someone from LG listening your everyday life. I don't doubt this happens but we shouldn't expect gamernexus to be able to prove it.
Jesus some people with their whataboutism and nihilism.
Comment by delduca 5 hours ago
Comment by hypfer 7 hours ago
Maintaining enemy lists like the one of Drew linked there has been illegal in Germany since 2021 as part of the government's (very necessary!) efforts against hate crimes and right-wing extremism.
Or at least that's my understanding of the law there. Maybe it's exempt based on technicalities.
In any case, I can in many cases emotionally relate to why he is doing that, but.. oof.
Comment by cassianoleal 5 hours ago
Comment by ChrisArchitect 8 hours ago
216M Spy TVs – The LG Smart TV Problem [video]
Comment by rbanffy 8 hours ago
I always say any serious computer needs blinkenlights and a smart TV has literally millions of them.
Comment by lovich 8 hours ago
> If you root or jailbreak your devices, you've, by their very nature, broken their security. If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.
What is this authors point?
LG doesn’t need a root exploit to get this info because they made the fucking thing.
I read the article and then grepped for “Texas” to see if I missed it. The author never mentions the fact that this data collection was only found out initially because of a Texas government lawsuit that LG settled on by agreeing to give “informed consent” to users about data collection and then the warnings started popping up in unexpected places.
Is the author arguing that jailbreaking your device to find out what the manufacturer can do to gather data on you is dangerous because I don’t know, questioning your corporate overlords is bad or something?
Comment by p0lychromatic 8 hours ago
This is the major issue with this video: It mixes stuff done by LG (ACR) with stuff done via rooting (audio recording). And now people think LG is 24/7 recording your conversations and uploading them somewhere. This has not been proven.
Comment by newsclues 8 hours ago
Comment by p0lychromatic 7 hours ago
That nuance is important if you value good journalism.
Otherwise if we're just our here throwing random allegations because "corp bad", might as well say LG 's TVs are turning the frickin' frogs gay.
Comment by stuaxo 7 hours ago
Sorry but such contrary takes in the face of this sort of evidence are either contrary for the sake of it or paid astroturfing.
Comment by p0lychromatic 5 hours ago
However, just because your TV does ACR, does not immediately mean they listen 24/7 through your TV through any conversations even if the TV is off.
That is another, also quite different level of claim.
Comment by lovich 7 hours ago
Spend some time building your reputation before arguing for divisive topics or be ignored.
Consider it a mechanical Turk but for social trust.
Comment by p0lychromatic 5 hours ago
You have to start somewhere. Better makes sense to start looking at the arguments rather than the author.
It also helps you train your brain. Stop trusting someone solely because of who they are.
Comment by lovich 5 hours ago
You can comment about anything here and build credibility.
Just don’t start on the most divisive topics.
Comment by handoflixue 5 hours ago
* When disagreeing, please reply to the argument instead of calling names.
* Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith.
* Please don't post shallow dismissals
* Please don't post insinuations about astroturfing, shilling, brigading, foreign agents, and the like. It degrades discussion and is usually mistaken.
And yet not once does it mention "don't start commenting on divisive topics"
Comment by sersi 5 hours ago
And to be clear, I'm not defending LG here. Their terms and conditions are terrible, 'We know who's in the LG household… we own the glass' is not something that should be said by any appliance company and shows a clear lack of ethics. But if someone is going to make a video explaining what's happening it's better to stick to what LG is actually doing instead of listing potential issues without making it clear.
A rooted tv by definition has less security, if you show that you can record because you have full control over the device that only shows that there's no hardware block for the mic (which most devices in existence don't have, apple, Framework, pinephones are the exception there). It's not in anyway different from most phones and devices that people use in daily life.
Comment by nalekberov 7 hours ago