583 comments

[ 0.23 ms ] story [ 11.3 ms ] thread
They just won't stop, will they?
They will once they've killed television and they'll get back to the net.
In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.

E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.

That's an easy one to put a compensation value on but there's probably all sorts of other exploits waiting to happen.

> E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.

My tinfoil hat believes that they've already accounted for this as the price of doing business. They will have already budgeted for the fines that they might incur, pay them off and continue as normal while people become accustomed to it.

The value of this data to the NSA, Mossad etc is probably the only thing keeping it secure.

Never in human history has a government had the means to simultaneously spy on millions of people, to use everyday private conversations to categorise them into various threats to the state, and better yet these tech companies can still sell the commercially valuable side of this to advertisers.

Based on historical records, I would say not much will happen to these companies. Interested to see what the EU will do though
The EU is actually already quite equipped to counter such behavior, with GDPR and CRA (Cyber Resilience Act) regulation they can not only penalize on consumer privacy protection (GDPR) but also on inadequate security practice (CRA), both allow either an absolute fine or a percentage of the annual company revenue.

I wonder what chances a consumer in US has though. If the past is any indication, consumer privacy is not a highly regarded good when ranked against a corporate strategy...

> Interested to see what the EU will do though

Will make surveillance mandatory? I mean we definitely should somehow fight terrorism, protect children, and prevent copyright infringement on trillions of dollars per year.

>this is going to be a massive business liability.

No. this is going to go "unnoticed" or at least unactioned. These are surveilance devices - compromising their value as source of surveilance is neither in the interest of industry (who are selling and buying the surveilance) or government (who are buying and acting on it). The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now. These devices bery well may soon be the only lawfully available devices in the consumer market precisely because of their surveilance capabilities. Governments are reluctanty catching up to the capabilities of digital technologies, and they're finding them more useful now than ever before. We will be burning witches again before we ever prosecute tech companies for doing bad things.

>The age of shame is over. Current world goernments have flourished under the premise of being terrible, horrible, awful, evil enterprises that do bad for the sake of either being bad or enriching the bad - a consumer device with a ToS that says it will spy on you spying on people is nothing now. Laws be damned, because laws mean nothing now.

Spot on.

We must inculcate into our children and youth a supreme distrust of and skeptical eye for both government and corporations. They are both systems of resource acquisition and control, whose interests often come into conflict with the interests of the people. It is unfortunate that modern technology is being used in this manner, as it very well may lead to a destructive sort of neoludditism. Technology should be embraced, in the sense of teaching children how its composed, how it works, information security, privacy, etc. A child should not leave elementary school not knowing at all how to use an OpenPGP client or how to do very basic Linux system administration from the command line. Ignorance of technology's workings combined with the excitement for technology's consumer applications are the recipé for the normies' complacancy today. Maybe throw a few Steinbeck books out of the school curriculum to make room for this education?
>In an age where AI can search vast amounts of data having something in your home or workplace turning what it hears into text looks like a problem waiting to happen.

That's understating the problem. With or without AI, this should be cause enough to shut down a company or at least their specific product division.

>E.g. As soon as someone proves LG, Samsung, etc. recorded and stored credit card details and knowingly have weak security this is going to be a massive business liability.

They're going to be fine. A slap on the wrist at best.

You would think that would matter, that they’re basically violating all known PII/HIPAA/GDPR/National security standards and god knows what else, but I expect at most some class action down the line.
> HIPAA

They're not directly or a business associate of an entity involved in providing you healthcare so not this.

At that point network isolation stops looking like a privacy preference and starts looking like an adversarial relationship with a product you own
... product you ownꭞ

ꭞ Terms and conditions apply

At the same time an average citizen can sue and win against these corporations. I never ended up Suing because all companies settled once I showed the evidence. So try it out. Will get expensive for them to use lawyers against ai and still lose.
GDPR compliance lawsuitssss in 3...
I really hope they do and slap them with the 4% of their total global annual turnover.
Somehow the EU only appears to target big wealthy service providers. I wonder why.
Wasn't there concern that they would target small companies and thus stifle the innovation? Seems like a win-win to me.
I mean, I’m not disagreeing, but it’s a bit rich for a site that logs data to 1,745 “partners” to be complaining too much.
As an owner of a (2020?) LG WebOS TV, to what degree can I fight this? Any point in trying Pihole with targeted blocking of certain IPs?
At this point, best to just keep it disconnected. Just use an apple tv or similar. They sold us a spying device masqueraded as a smart TV.

If internet is really required, I'd personally flood such an LG tv with fake data - add a raspberry pi to provide it with looped audio streams for the microphone, fake bluetooth devices, and so on. But it's still probably a drop in a bucket.

Vote for politicians that vocally campaign against advertising surveillance.
the only TV I have connected to the home network (guilty, I admit), Sony OLED 65, ARP floods my network about 12-15 hours after "turning off". On a plus side, it doesn't appear to be streaming anything out: no local DNS hits, not enough outgoing traffic for any meaningful audio stream

The choice between privacy concerns and ineptly coded network stack is tough. But that's the choice we're forced to have

Why don’t you just use it as a display and have a more reputable device (e.g a mini pc or an apple tv) feeding it? I’m not forced to give my tv network access at all, since it doesn’t do anything other than display whatever the apple box outputs…
This is (mostly) the way. Samsung TV without networking configured, XBox for everything - which is problematic in its own ways but it's a known quantity. It doesn't prevent it from "helpfully" hopping on a nearby unsecured network but a) I haven't spotted one of those in a while, and b) it hasn't ever been able to get updates to change its behaviour to make it start doing that if it previously wouldn't.
This is exactly what I do on the other TV, as I suggested in a different message in this thread. But this particular TV is mounted flush to the wall and there's physically no space for the apple TV anywhere near or behind it. Sacrifices we have to make
Is it your wall? We have a fairly modern house and the walls are solid gypsum so i just carved out a small hollow for it, cables are going via a channel with some ducting i then plastered over
My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet.

DNS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked), and DoH is blocked as best effort though it's hard to block HTTP DNS traffic, which again is why the devices are blocked in the firewall.

All streaming is done via AppleTV, which is a platform I trust infinitely more than LG/Samsung/whatever.

All of your blocking still doesn't change the fact that your LG TV is actively trying to scan your local hardware, gathering IP-addresses of devices, wi-fi names and signal strengths, creating digital finger prints of the audio and video projected on your screen, recording audio through the internal microphone, even when the TV is in standby or without an internet connection, saving the collected data locally and uploading to LG Ad Solutions as soon as the TV is connected to the internet.
Do transparent faraday cages exist?
WiFi / 5G faraday cages exist, but they have been downrated for affecting the signal quality somewhat...
Yeah which is why its imperative that you _never_ connect to the Internet.
[dead]
More imperative is that you _never_ buy one.
But it's never connected to the internet, not even for software updates. If the TV isn't connected to the internet there's no reason to update it, assuming the TV works as expected.

It's a trade off I guess. I use Home Assistant to control TVs, so kinda need the access.

Again, what I mean is, even if you're able to block all these things, the company LG is still secretly and actively trying to collect and process user data, without user awareness or consent.
Actually what I wanted from the video was impact of user consent, but it doesn't seme to cover this: what happens if you accept nothing, or the minimal set of consent (so not including audio) of licenses to allow you to run third-party apps? I recall there are four checkboxes to check.

My guess is: not much.

What if you sell the TV? Can you clear the data with a factory reset so it's not just uploaded when a new user connects it?
Have you noticed that on many home routers there is now a default open, sometimes password protective network named AT&T or Cox Wi-Fi? That’s the backhaul. The TV will join that automatically without asking you because they have an agreement with the network provider. This is how tons of devices phone home now. You don’t ever need to add a device on your network for it to have internet. If there’s a partner Wi-Fi network anywhere, it’ll push through that.
Joining that network from a new device always presents a captive portal that requires the credentials of my ISP account, so how does that work for you?

Where is a web link indicating partnerships, and compatible hardware lists? My ISP does not sell any TV sets.

The TV will join that automatically without asking you because they have an agreement with the network provider.

This seems far fetched to me. Have you seen evidence or reliable reporting of this?

Why is this more far fetched than LG smart TVs recording audio while pretending to be off and caching the results waiting for an opportunity to exfiltrate the precious data? We're in a "if they can they will" world with this stuff.

Comcast sets up a secondary wifi network on their routers in your home that they use as the backhaul for smartphones. Why wouldn't they make a deal with LG or whoever to use that data? We've already established they'll do about a half-a-Stuxnet to get at this data, you're telling me they won't do a couple bulk deals with common ISPs?

Okay, even if you don’t agree with me that it’s far fetched, claims of ‘X is doing Y’ usually require some evidence that X is doing Y to be considered credible.
Why go through all that trouble of spoofing MAC addresses or assuming it will always be able to connect to an open WiFi network.

5G connectivity is cheap. You can put a 5G modem in pretty much any device for $10 or less, and pay roughly $2/year in subscription fees. My local water utility with ~900 subscribers pays $2/year for 5G connectivity for water meters, and I have no doubt you can get it much cheaper at scale.

They don't even have to tell you about the 5G modem. It could exclusively be used for exfiltrating data about your viewing habits. It's virtually undetectable and more or less impossible to block. The TV could behave nice on the Wifi, you can block all the DNS servers you like, it would still be able to phone home.

because using open wifi is infinity cheaper.

You are asking for $20 increase in BOM, which means they somehow has to extract $20 from your private data, which is hard.

Or simply increase the selling price by $20, would you even notice ?

And if they're not expecting to make $20 over 10 years selling your data, it hardly seems worth risking your reputation over.

It’s just the BOM price. When your product has Cellular module, there is set of certification that is painful to pass. It’s better to use included wifi module since it’s already there and certified
How about this? LG builds many other home appliances like washers and driers. Some have apps and wifi.

Why wouldn’t LG allow their devices to talk to each other locally, without needing to join a network? With private SSID or something like that? Only one appliance would need internet access.

This shit already exists. Like Amazon Sidewalk: https://ring.com/amazon-sidewalk

Now, I’m not saying LG is doing it, but this is not a far fetched technical concept. The only reason they’re potentially not going that far is because most people probably just connect it to the internet so why bother about the few who don’t.

The devices are already scanning the network for any devices and software they can find, and mapping your phone to your TV viewing habits for example. The LG execs are on record bragging about it. So I don’t see why it’s absurd

after everything we’ve seen factually that companies do, why would this, of all things, seem far-fetched to you?

i think it would be significantly more far-fetched that cable companies don’t sell them access. i would be shocked if they didn’t.

This is alarmingly realistic to me.

The part about ISP routers broadcasting an alternate "hotspot" SSID is documented [1] and can be easily observed. Walk around any city, open your phone's wifi settings and see networks like "xfinitywifi" or "optimumwifi". As an end user, if you connect to one of these networks from your device, you'll get a captive portal web page that makes you sign in to your ISP account. Once signed in, you get internet access courtesy of the router sitting in whatever home or business you happen to be near to.

In addition to ISPs allowing their own subscribers access, there are examples of corporations cutting deals with ISPs for hotspot network access. For example, Google's MVNO Google Fi has a deal with unnamed partners that allows subscribers' phones to connect to hotspot wifi networks for extra coverage, branded "Wi-Fi Auto Connect+" [2].

From the user's perspective (and personal experience), this connection is handled seamlessly and outside of the OS' normal wifi UI flow. If your phone sees no saved wifi networks but does see xfinitywifi (et al), it auto-connects in the background. Authentication with the captive portal happens automatically and non-interactively, presumably with some keys provisioned to your device. Your traffic is VPNed back to Google, so the router and ISP don't see anything. The only indication that any of this happened is that the "5G" icon changes to "W+"; the normal WiFi icon never shows up.

In the case of Google Fi, this is actually a pretty great deal for users. You get better coverage (especially indoors in cities, where cell service can be spotty) with no real downsides to you – your traffic isn't meaningfully exposed to another third party, it doesn't cost you extra, and you don't have to bother the staff for a wifi password.

But given all that, it's not a huge leap to believe that ISPs are also more than willing to quietly take LG's money in exchange for an all-access pass to their hotspot network.

It's easy to imagine that an evil company could ship their TV with a key that allows it on an ISP's hotspot network. No extra suspicious hardware like a 5G modem needed, and no MAC address spoofing required. The TV software could easily connect to the hotspot network with zero indication in the UI, and then use the surreptitious connection only to transmit your kompromat back to HQ.

If done intelligently, you'd never notice. By only transmitting spy reports (and not downloading new ads), even a keen observer wouldn't notice any behavior on the TV that would trigger "how tf did this thing get a network connection?" Even more insidious, you couldn't really see what traffic was happening, since IP packet captures on your network are useless in this scenario. You'd need special hardware to capture what the TV is actually doing on the air.

If truly evil, the software could do this hotspot dance even if you've configured your own WiFi network on the TV. If the software finds it can't reach ad HQ because you've firewalled it off, then despite your best efforts to contain the disease, it still can spy effectively thanks to your neighbor's router with its default-enabled ISP hotspot. Just do a daily upload while you're sleeping and otherwise sit innocuously on your locked-down VLAN.

Everyone evil wins: ISP collects that sweet bonus revenue at zero marginal cost, TV manufacturer doesn't have to foot the hardware bill for millions of 5G modems or (relatively) expensive cellular agreements, and advertisers get to be that much more creepy targeting you. I'm sure the wanna-be despots of the world don't mind the spy apparatus being built for them either, conveniently under the control of easily-compelled corporations.

--

Now to be clear, I have no proof that any TV manufacturer is surreptitiously connecting to an ISP's hotspot network in or...

They tried that in Denmark a decade ago (or more). Enabled a "public wifi" on all home routers to provide wifi coverage for that company's customers everywhere.

They gave every assurance that it would be secure, completely separate from the users own network, and the bandwidth consumed would be added on top of whatever the user had a contract for.

It took a couple of days after launch before somebody managed to gain access to someone's private network from the public network and they shut it down again and never opened it again.

Anyway, I may be spoiled from living in Denmark, but I'm using my own router, which is an option when ordering, so I'm fairly certain nobody is sharing additional wifi hotspots.

And it's not just me. The majority of people I know use some kind of 3rd party router with their ISP. Granted, some of them just use whatever the ISP sends them, but even then I haven't ever seen any additional wifi networks, and the ISP prints the router admin password on the box itself, so you can poke around if you like (though the ISP has a backdoor, which is also why 3rd party routers are a thing).

LG has a cereal port on most of their televisions and monitors. There are quirks and bugs in some models but the general packet structure is simple and it's pretty straightforward to get an ESP32 with ESP home talking to the monitor.
And then your neighbor spins up an unprotected network or something like xfinity which they could have a deal with and it connects there and phones home anyways.
And what exactly would they use that particular access path for ?

I could see a threat if the TV had access to the internet and could establish a TLS tunnel or similar from the mothership, and execute commands on my LAN (or IoT network as it stands), and report back. That could establish a command & control channel that could potentially orchestrate an attack on my infrastructure via the TV.

However, reporting that "network X exists and has these devices" over a different network complicates things a fair bit. In theory they could still use the TV as a command and control platform, but it would have to switch networks between my closed network and the open network in order to execute commands and report results. Not saying it's impossible, just very unlikely.

Besides, the TVs are not alone in being cut off from the internet. I have two IoT networks, one for trusted devices (AppleTVs, Sonos, and the likes), and one for untrusted devices like TVs. They run on different VLANs, and anything on the untrusted IoT network can pretty much only talk to itself (client isolation) and the gateway, and there's no internet and no open ports to any other VLAN.

> And what exactly would they use that particular access path for ?

Uploading the weeks, months, or years of locally-stored activity [0] data? Text compresses really well and local storage used to be very cheap.

[0] ...mic voice transcription, how often you use the thing, for how long, and a best guess (because of lack of time sync) at when, "automated content detection" logs [1], names of files you've fed to the thing, -if equipped with a camera- number of people in the room and interesting information about them, etc, etc, etc...

[1] ...assuming that that can be done with data loaded from the factory, which I kinda doubt...

Two things:

1) What I called "automated content detection" is apparently called "automated content recognition", abbreviated as "ACR".

2) That weeks, months, or years of locally-stored activity I mentioned can also contain historical ACR records. Given that the audio and video of what's being displayed on the screen is "fingerprinted", those fingerprints can be saved just like everything else picked up by the "TV" and uploaded whenever the thing next has Internet connectivity. The "TV" manufacturer will lose the "what are they doing right now?" aspect of the feature, but the "what have they been doing?" aspect of the feature will work just fine.

Directly related is this section of this Gamers Nexus investigation, but the entire video seems to be worth watching if you're not rather familiar with the topic: <https://youtube.com/watch?v=6IFVTcM28KA&t=26m47s>

I hear this a lot “TVs will just connect to a nearby unprotected WiFi network!” But I ve never seen any evidence of it. It appears to just be speculation, unless you have an actual source?
They could also use something like Amazon Sidewalk or ATSC 3.0's dedicated return channel.
They could (although I’m not sure of the 80Kbps that Amazon sidewalk allows is really sufficient for the purpose of uploading ACR data), but is there any evidence that any TV manufacturer actually is? The reality is, why would they bother? 95% percent of people that buy a “Smart TV” hook it right up to their WiFi as soon as they take it out of the box.
ACR isn't generally a lossless 4K snap shot but indexed 32x32 pixel blocks from arbitrary locations on screen. In some cases it's even a fuzzy hash of the content source, and while 80Kbps isn't a lot, you can still push out data in a timely manner.
80Kbps is enough, after all they don't want to accidentally ddos their server.
Its always speculation that would be trivial to actually test.

1. Do not connect to network 2. Create unauthenticated WiFi network 3. Monitor WiFi network

Strange no one has ever done this simple af test to backup their claims

If TV manufacturers wanted to be underhanded then they could actually make this much harder to detect by delaying the connection to new unauthenticated networks for e.g. months or only after seeing another device connect and then using that device's MAC when it is not around.
Still super easily detectable even if they clone a MAC.
I have an unprotected guest network with a captive portal and an LG C1. I have never seen the LG pop up in the logs for the guest network.
Seeing how things have recently been developing, I'd bet on it already being the case or at least in active development.
If you think its already the case, how come nobody can provide any evidence of it? As stated above, it’s trivial to test. Surely if Brand X was doing this, there’d already be blog posts, youtube videos, HN posts, etc. about it?
Because they don't. It's too much guesswork, and honestly pretty complicated. From the user perspective the TV would appear to go offline every now and then, so also somewhat easily detected.

It's much easier to just throw a $10 5G modem in there, pay the $2/year subscription fee for service, and extract data that way. Assuming a 5-10 year relevant lifespan of the TV, they'd throw $20-$30 on top of the sales price for the modem and 10 years of service.

The 5G modem could run completely independent of the wifi network, be a completely different circuit, and you'd never know it was there.

Except they don’t do that either. I’m not aware of any TV bundles a 5G modem. Are you?
almost all new cars have cellular modems reporting all kinds of shit, something like over 90% of new cars. what makes you think tv companies aren’t?

even the ones that aren’t yet, we’d be incredibly incredibly naive to think it’s not on their radar.

Cars having 5G connectivity is something that consumers actually want, it’s well documented on the spec sheets and marketing material, and obviously in a car WiFi is not going to work in most places. None of those things apply to TVs.
If you're streaming via AppleTV, why do you need to give the TV itself access to the network?
I use Home Assistant to turn on/off the TV via automations, sensors, etc.

I could possibly do it via HDMI CEC, but I have a couple of Sony Bravia TVs that more often than not completely ignores that, so I prefer having control over assuming it happens.

You can do on/off using an IR blaster (broadlink integration with discrete on/off codes). It’s when you want to read volume etc things get trickier
I have an automation that turns on amplifier only when using certain inputs, not just when the TV is turned on. I can easily imagine people would also configure their amps to use different input depending on TV input.
Yeah CEC is a bit tricky sometimes. How about auto-off from the TV itself and then a timer for a HA controlled outlet to turn off power after that using automation (i.e., when the streaming device is off for a x minutes)
There is sadly no hdmi CEC support on Most GPUs for pcs. So when you want your tv to turn on and off with your pc it is only possible with the tv being reachable from your pc via ip.

I believe LG doesn’t advertise such an api via Bluetooth

HDMI breakout and a esp32 module flashed with esphome is another option.
The tv does care which port it came from, since it automatically switches to the one which made the request.

One could build a IR emitter but you need soldering skills for that or buy a usb one which cost north of 30€ + shipping.

You can get USB controlled CEC injectors for HDMI.

https://www.pulse-eight.com/p/104/usb-hdmi-cec-adapter

For a 4K120Hz TV I'd be worried about this adding signal integrity issues - "all versions of HDMI®, including HDMI® 2.0a" doesn't inspire confidence.
My understanding is that CEC can be received on any alive interface, not just the active.
Yes but you will lose 120 FPS/VRR. So for high end TVs not really ideal.
Congratulations but I also dislike this type of comment because that is not a solution, a workaround that doesn't happen for 99% of the population.

Soon you won't be able to IoT network or block these devices as they begin to partner with Amazon and the likes that sell Internet for near-by IoT devices. Then your only option then is physically removing / de soldering radios from the board.

Laws needed, like yesterday.

For now, setting up an IoT network is pretty much best practice, and I'd wager the average Hacker News reader both has the necessary equipment and skills to do it. That may not always be the case.

Assuming they install some 5G modem in the device, which is pretty much dirt cheap these days (our local water utility uses 5G for meter readings, and the cost per meter is something like $1/year), there's literally nothing short of a faraday cage you can do.

The can report on what you watch freely, and only consumer laws can stop them. However, without a wifi connection they can't snoop on your local network, and they probably can't connect the data to you, assuming you don't register the TV for those 3 months of added warranty or whatever they try to get you to register.

I tend to avoid devices that are built to snoop on you, so no Amazon Alexa, no Google Home, no Apple HomePod. Everything I have utilizes local control via Home Assistant, and most of it is actively blocked in the firewall from accessing the internet. It's not hard to implement, and doesn't require a master of IT, but it does remove a lot of the convenience, which I guess is the reason people don't do it.

That's great that you know how to do that, but LG and others know that also. They don't care that a miniscule amount of ppl can do it, they care about the 99.9999% that don't. Thid should be dealt with legislation and very high fees, sufficient to discourage anyone to do it.

   > My TVs are on the IoT network so that I can control them from Home Assistant, but they're blocked from accessing the internet. NS lookups are redirected or blocked (53 redirected to my local DNS resolver, 853 blocked),[...]
That's great, good for you that you can do that.

Unfortunately, from LG's surveillance capitalism point of view, the 0.001% of LG owners that can even think about doing that isn't even a drop in the bucket. They don't care about any one individual, and the vast majority of individuals don't care or understand what LG is doing as long as they can watch TV.

It's only a matter of time before another Cambridge Analytica situation pops up, except with better tools and vastly more data. Or maybe something we can't even imagine yet enabled by simply re-purposing ad-tech into something political and malevolent? Some people will be wise to it, of course, but if enough are caught up in it, it won't matter, we all lose as a whole.

Blocking DNS doesn't do much if the device isn't resolving hostnames and just pushes data to a bunch of preconfigured IPs tho...
Is all of them, every "smart tv" does it, even after adb, permission restricting or rooting. Insert a (non infected) usb lamp in your tv and see the lamp turning on when your tv is off. It notifies you about the background activation activity :) Interesting to see when exactly get active (is it keywords or nearby devices or scheduled processes)? Can´t be keywords as that would mean 24/7 active and the lamp says otherwise.
This is the same behaviour as the german secret police in east germany. The difference now its for ads and by tech. All collected data are probably ai transcribed from audio to text and is fused via data fusion to serve ads. Add collaborative filtering to find similar interests between users.
Clearly the penalties for this are not high enough, because the scumbags keep doing it.

Vizio TVs were caught taking screen grabs and phoning those home years ago.

notebookcheck.net:

> We value your privacy

Shares my browsing info with 1745 "partners" with no clear way to opt out (which ought to be opt-in by the way to be compliant with ePrivacy and GDPR).

"We value your privacy" → "Your private data is valuable" (I guess)
I have a rooted LG C4. Beyond blocking things at the DNS level, not accepting terms, not using AI, I wonder if there’s some existing software solution or a documented step-by-step to remove this bloatware/spyware.
It'll be difficult. It's webos of which there's very little custom development.

You'd be better off with an android tv which you can poke at using adb and disable services. Maybe even root it. And install alternative software like smarttubenext.

Unfortunately there very few Android based TVs left. Phillips recently switched to Titanos, Samsung has tizen, Amazon has a new OS. I think it's just Sony that's left on android now.

Surely the Astras and Fables of this world would make light work of setting up a WebOS build environment and be able to create practically any changes you can think of, especially if there is a way for them to iterate the development.
Wait, do LG Webos TVs have microphones in the TV and/or in the remote? I am aware of the latter only.
Just don't buy a smart TV. Buy a good "dumb" TV (or just get a good large monitor), then hook it up to a set top box (with TV capabilities as needed).
If you want a good panel, you're going to have to buy a smart TV.

Just don't ever let it connect to the internet.

"Just a good large monitor" costs a fortune.

If anyone could recommend any dumb TV with good panels in EU, you're more than welcome.

If you don't need something much larger than 43 inches, and you are cool with wide monitors, there are a couple one that seem good:

- Samsung 40 inch Odyssey G7 (G75F) Series WUHD Curved Gaming Monitor (https://www.amazon.com/Samsung-Odyssey-Curved-Gaming-Monitor...) -- $699.99

- Acer Nitro 49 inch DQHD 5120x1440 Curved 120Hz Office Monitor (https://www.amazon.com/Acer-Nitro-Gaming-Monitor-UltraWide/d...) -- $549.99

- Acer DM431K A 43 inch Class 4K UHD LED Monitor - 16:9 (https://www.amazon.com/acer-DM431K-Class-UHD-Monitor/dp/B0F3...)-- $334.20

- LG 37G800A-B 37 inch Ultragear 4K UHD (3840 x 2160) Curved Gaming Monitor, 165Hz, 1ms (https://www.amazon.com/gp/product/B0FS3LV3WG) -- $598

- INNOCN 40C1R Ultrawide Monitor 40 inch WQHD 3440 x 1440p 144Hz (https://www.amazon.com/INNOCN-Ultrawide-Monitor-FreeSync-Pre...) -- $479.99

I have a 50" Philips screen with no smarts. It's great.
I have a 43" Philips Ambilight (43PUS8510, 4K QLED). It's not a dumb TV per se, but you don't have to use any of the smart features, and - most important - you don't have to connect it to a network.
... and that's the trick, isn't it. Have you ever tried going into an electrical store and buying a dumb TV any time recently?
I bought a Sceptre a few years ago but it died pretty quickly (dead pixel strip on the screen). But the replacement 44" Insignia (Best Buy) that I replaced it with has been an awesome tv.

So yes, you can just walk into the Electronics Store (Best Buy) and purchase a dumb TV.

Best Buy no longer produces dumb Insignia TVs.
(comment deleted)
That would be lovely. Unfortunately, to the best of my knowledge, nobody sells (for instance) high-quality 65"+ OLED non-"smart" TVs. "dumb TV" options are limited to older display technology.
Projectors are probably the only remaining exception here, and obviously don't work in all use cases.
Try https://www.aorus.com/monitors/AORUS-FO48U/Key-Features - yes, it's a bit too small for you.
Literally my current computer monitor, but no, does not work as a living room TV. (Also, would not recommend as a monitor; aggressive ABL and persistent messages about turning off for maintenance.)

When I said 55+ I was talking about the whole size category larger than that, including 65, 77, etc.

I don't understand why the best advice in this thread is getting downvoted. Even if you buy a smart TV and then disable the smarts, you're still teaching the TV companies that smart TVs sell.
> Buy a good "dumb" TV

Unfortunately, you can't have one without the other. The best, image quality -wise, TVs are all "smart".

I know its important to put things down to coincidence whenever possible, but a very expensive Bang OLufsen ( I think they use LG ) TV would turn itself off at "the" most interesting split second moments during gameplay , to the point where I thought "if I am being pranked by a friend, does this TV even stream its contents?".

Much to my surprise I found out that many modern TVs do in fact come with dev mode that allow full remote streaming.

Safe to say I turned off all the "allow metrics and market/dev modes" and have been happier since.

Did it ever turn itself off after you made those settings changes?
Most tvs now come with auto off kou have to cancel with a button press, prob just that.

Normally they show a warning, but i just got a new tcl, and it’s warning is very short leading to shutdown if you don’t pause quick enough to reset it

That did happen a few times , but Im telling you bro that TV restarted a couple times just as I was about to clutch, like the same second i was about to press a trigger in an otherwise boring 25 minute round more than once, but yes as I mentioned earlier it could be related to other tech aspects.
I'm inclined to believe the shutdowns were a bug rather than an extremely patient friend waiting for the perfect gameplay moment. But modern TVs having enough remote-management machinery that the prank theory isn't immediately absurd is not exactly reassuring.
I will remind everyone again that weev was raided by the FBI, arrested, and had all electronics seized, before getting a chance to defend himself in court, all for the crime of publishing emails he found on unsecured URLs he was able to guess.

But we're allowing 1000x worse things, because what, there's a vague line about it buried deep in some EULA, which means laws no longer apply?

Lets treat them the same. Raid LG, seize all of their electronics, at least in the US (other countries are encouraged to do their own raids), arrest the executives, and after they're all in jail, and digital forensics are poring over their electronics to find what else they did, they can argue in court how actually all these crimes are legal.

It's only fair.

I absolutely loathe my LG smart TV. Just switching to another input requires 3 button press.

I hope someone uses their free time to hack the OS and offer a clean and simple interface to make it a “dumb” TV.

I’m unaware of any projects trying to make a dumb tv, but I like the idea. You can start with rootmy.tv and research from there.
This is automatic liability in California and the EU, correct? Does Illinois consider one’s voice pattern to be a biometric? If so, there, too.
If its not automatic it's incredibly shaky ground in the EU. I'm sure Apple, Amazon and Google got more than a slap on the wrist just for storing a few seconds after the wake word before.
I could buy a tv in late 2014 and happened to be the last batch of bravia tvs pre android tv. Back then I was kind of bummed out that just a few weeks after that they announced the first tvs with android tv and now i was hooked with a smart-but-not-that-smart tv with a bunch of crappy ads, an unusable web browser and a non-customizable os.

But they stopped updating it years ago, none of its apps work anymore and the only "smart" feature that still works is screen mirroring feature. The tv part itself still works great. Not a 4k oled 120Hz shiny impressive thing but the image quality is still great. What I thought was an unlucky adquisition back then turned out to be a pretty good one.

Apps, browsers and "smart" features are disposable software, but a good panel can remain useful for a decade. Makes you wish manufacturers treated the smart layer as optional from the start.
I've bought an LG Smart TV 5 years ago, read t&c where I was supposed to grant them any data they wanted, decided to disagree and kept all network functions disabled. I was ridiculed by my friends for that. At some point, I thought - maybe I'm really crazy to do so? Who am I, a caveman, a luddite? Oh well, I'm not. Not a bad tv though, many HDMI ports!
This. Why would you even connect TV to the network?

It is well known for like 5 years. Smsrt TVs go through your movies library, and upload screenshots and filenames to internet.

Some will start showing ads after firmware upgrade.

Did you know that ethernet can run over HDMI? It's called HDMI Ethernet Channel (HEC).
Yes, but support in devices and cables is very limited.
Support in cables is nearly universal, because the same pins in the cable are used for the Audio Return Channel feature that allows a TV to pass audio from its internal apps back out to a soundbar or receiver via the same HDMI cable it takes signals in on from other devices. As far as I'm aware no one has made a cable lacking those pins since 1080p was still the high end.

But yes, support for the ethernet mode as far as I'm aware was never actually implemented in any devices that reached retail availability.

Surely it still needs to be connected to something that has a network connection, though? Doesn't really mean much here.
I'm saying that "it is connected only via a HDMI cable" does not imply "it is not connected to the Internet".
Did you know that no one has implemented it? You might as well talk about packet-carrying fairies in your TV. And of course the Apple TV box it’s connected to will be quite happy to share its network connection with arbitrary crap you connect to it.

But I guess like an xkcd comic, someone is obligated to raise the issue every time TVs come up.

> This. Why would you even connect TV to the network?

I happen to have a NAS with family pictures I like to display. I can (and do) firewall that thing, but then you hit other issues like the apps you need to show pictures and movies in the first place not to install/run.

I've yet to hear of a reasonable recipe to isolate and secure such connected TVs. And don't get me started on Chromecast or other Android dongles, I've no reason to expect better treatment from Google. Some open source hacked-together box, then?

No idea what NAS you’re using, but I would recommend the Apple TV box.
Any SBC like Radxa Rock (cheap) to Orange Pi (powerful). 4k output, a linux you control, play retro games or stream torrent movies.
Not well.

If you only care about file playback, bit still care about things like HDR and quality audio I would recommend something like the OSMC Vero V instead.

It's still relatively cheap, and open source, but also let's you playback something like a blu-ray rip without loss of quality.

It has the other bonus of not requiring any real setup or maintenance.

GBM/DRM Kodi supports HDR video on the Orange Pi 5 family. You can grab whatever audio from HDMI or plug whatever in the usb port, the only advantage of this Vero is the optical out.
The orange pi doesn't do HDR properly. Linux in general doesn't support it natively, and the hardware doesn't provide for it.

On most devices Dolby Vision, etc get downgraded or support only the streaming profiles (profile 5) . If you want full Atmos, Dolby Vision, etc you have to buy one of only a handful of devices. The Vero V is one of them. There are only a few others.

https://osmc.tv/wiki/vero-v/dolby-vision-support/

(comment deleted)
Or just buy an old x86 mini pc from ebay, vastly more powerful and less headache.

Mine comes with i5 8500t, 16gb ram and 256gb ssd, and it was like $150.

Obviously, as an advertising company, Google should have your utmost scrutiny. But as far as I know, their TV boxes don't ACR your content. If they were the only two options, sticking with your smart TV software instead of using a Google TV box would be a privacy mistake.
Typically you will get sambatv or such installed, and technicians for whatever reason tend to click accept/approve during installations. Happened to me n my Google TV thing
What technicians? When my TV was delivered they pretty much just unboxed it and set it on the floor, not even being willing to help mount it, let alone plugging it in.
Tbf I was talking about first-party Google TV boxes (Google TV Streamer and Chromecast with Google TV.) Likely not perfect for privacy, but not pure evil like built-in smart TV firmware, they support sideloading without time limits, alternative app stores (Flicky/F-Droid) and they're friends/family/roommate/partner friendly with support for DRM-ed streaming apps, Chromecast and pairing with the official YouTube app.

I chose one over the Apple TV because I knew I wouldn't able to stand any limitations on sideloading. For a while I was running a custom build of Wholphin with patched libmpv/libplacebo to work around a bug before the fix was upstreamed. A device without the freedom to do that sort of thing would drive me nuts.

> Some open source hacked-together box, then?

I've just used an old Intel NUC with Debian stable, a remote mini-keyboard and an automounted Samba share on the network forever. It's no more hacked together than any other computer. I do make the mouse pointer and the fonts real big. No apps required. Don't really need the keyboard except for mplayer hotkey presses - just the touchpad on it; if I need to do something that involves typing other than typing a password, I usually ssh in.

I think people are lowkey addicted to having shit sliding in and out and constantly being advertised to. How do you know what to watch unless somebody is constantly bombarding you with options? If it doesn't look like a star trek control panel, is it really TV?

If you like that, you can install Kodi. I haven't tried it since it was XBMC because I found the interfaces annoying and it had trouble dealing with networks, but I'm sure it's better.

> I've yet to hear of a reasonable recipe to isolate and secure such connected TVs

I don't even try. I overpay for dumb tvs in the present, or underpay for 10 year old tvs pre-Applefication. I've never owned a network capable television, or one with apps. I wouldn't.

edit: if your NAS is a separate box that can sit in proximity to your television, you could probably just run all of this stuff directly from the NAS. They spend most of their time doing nothing at all.

Apple TV is the best one. No ads, full OS updates for a long time.
There are ads for ATV content.
No, there really aren't.

I turn on the device, the app in the upper left is selected and showing some content from that.

The device sits idle, I get drone footage of landscapes.

If I accidentally bump the wrong button on the remote and get sent into the Apple TV (streaming service) app, sure it advertises producte, but in general there are no ads.

In comparison, Google TV's homescreen is giant ads for content on services I don't subscribe to, Roku is at least as bad, Amazon is worse, and Samsung and LG......oof.

And the Nvidia Shield is also hot garbage in this regard.

I suppose my next device is an Apple TV or some kind of home brew Linux box.

The shield was great until Google forced ads into it, switched to Apple TV back then and no complaints since.
The shield is vastly superior to the Apple TV. You aren't trapped in Apples wall garden and can install any apps on it. Android TV comes with an awful launcher, but that is easily replaced. There's no sponsor block on Apple TV and there never will be.
No, it's not. Let's start with the disclaimer that I work for Google, not the Android TV team, all words my own, etc.

The Shield at launch was an amazing product - premium UX and hardware, premium price point. Google changed the experience to an ad-loaded mess without providing an opt out for those who had spent hundreds of dollars on the Shield.

I was dogfooder, a huge advocate of the product, and someone who had convinced others to buy the Shield and Android TV devices. That UX revamp and how the team treated their customers (internal and external) turned me off the product for life. I tried the various competitors (XBox, Roku, Amazon) before landing on Apple TV. I now own two Apple TV devices - both of which are still getting updates many years after I bought them - and will continue using them for as long as the product line is maintained.

People in this thread have talked about Apple's clean beautiful ad-free UX, but the apps themselves are far better. Apple sets customer-friendly App Store requirements *and enforces them*. That means:

* The back button always works. It will bring you back to the home page of the app and then to the system launcher. It will not get stuck in an endless loop of "are you sure you want to quit?" and just dismissing that dialog like multiple Android apps do

* No loud obtrusive sounds on app startup (YouTube, Netflix)

* The apps are first-class priorities for developers. Circa 2019, the Paramount+ app was an inconsistent mess where subtitles were broken on some platforms. The Plex app wouldn't transcode certain formats on the XBox, and so on. None of these issues are a problem on Apple TV. Not every app is perfect (Dropout, I love your content, but your app is awful), but none of them are worse than on any competing platform.

Apple TV is a truly incredible product and ecosystem and one that feels like a joy to use. That's not the case for Android TV (now Google TV, I think?) even with a custom launcher.

Perplexity Launcher is free and takes <2 minutes to install on the Shield or other Google TV devices and has zero ads. Being able to sideload apps that will never be allowed on the Apple TV is a major benefit for anything piracy adjacent.
I (and most users) don't care about that. Having a great app for YouTube and other services I use is far more important than being able to stream pirated content.
Sponsorblock is the great app for YouTube
>In comparison, Google TV's homescreen is giant ads for content on services I don't subscribe to

I enable app-only mode on my chromecast and does not see any ads.

But on the Apple TV you don't need to enable or disable anything. There are no ads, there has been no ads and I'm pretty sure there will be no ads.
The better Roku hardware I would say is a second best - you can block the as servers fairly easily and then you do have to disable all the crap on the homescreen.
You can always just connect your laptop (or some spare laptop) to the TV via HDMI. Not sure why you’d need to “hack together” something. A dedicated HTPC is nicer if you want to use IR remotes and the like.
Yeah, perhaps "hack together" is unnecessarily dismissive, but the experience to match is that of a single peripheral to control everything. The other area I have no interest expanding my knowledge into is the minefield of codecs, HDMI cables, GPU and drivers combos to have something outputting HDR and whatever Dolby's flavour of the month proprietary invention I inevitably come across.
I use the built-in AirPlay receiver on my Sony TV quite a bit and that requires network access
LG’s AirPlay requires internet access.
christ we need to start rooting tvs and start up a open and secure tv os. i never give my tv os internet access i rely on the appletv for the "smart tv" but if what another poster says is true about lg devices looking for public wifi to exfiltrate data then lol time to start pulling tvs apart and shielding their network components from getting a signal
That basically exists, but runs on external hardware: https://kodi.tv/

There's no need for the TV to be anything but a dumb screen that has only "power on", "power off", "volume up", "volume down" and "mute" functions.

Watch the video the article is based on - not connecting to the internet doesn't keep you safe in many cases: https://www.youtube.com/watch?v=6IFVTcM28KA
"Watch this two hour long video" is not a particularly useful reply. If you think the TV can exfiltrate your data without an internet connection then you should be able to explain how it could do that in your own words.
Just because you didn't allow it on your local WiFi doesn't mean it did not connect to the Internet. Your neighbors might have a guest WiFi it can use. Or maybe it has a built-in cell modem. Your data is valuable, there's reason to put effort into getting it.
Wouldn't using a neighbor's Wi-Fi without anyone's permission or instruction violate CFAA or some other law?

Also, wouldn't this be trivial to test by just setting up your own network and seeing if the TV connects?

They have permission from the provider, why they are able to log in.
Xfinity (aka Comcast) routers broadcast a separate network for Comcast subscribers do use from their phone. I don't think it's unreasonable to think that Comcast and TV manufacturer's could have an agreement that would allow TVs to connect.
Laws aren't enforced against large companies.
Using internet access doesn't seem to be illegal. If there's no password you can't even argue it was protected. Residential proxies are legal too (as they should be - fuck cloudflare).
That's what the Ask button is for with the summarize option, to not have to watch unnecessarily-long videos. Apparently it does connect to public hotspots, often run by major providers.
The alternative is inconvenient and more expensive. And most people simply don't care.
We don't really have alternatives, period. LG is the one in the news today, but pretty much any TV this decade has been doing similar things. Computer monitors max out at 32 inches and the idea of a modern dumb TV is non-existent.
I meant alternatives to connecting your TV directly to the internet. As in "why would you ever connect your TV to the internet?" is a stupid question - "because I want to watch things on the internet." And it's not like a roku, firetv, or chrome cast dongle is much different (and Apple TV is $200, normal people don't add 20-50% the cost of their TV to do something built in).

> the idea of a modern dumb TV is non-existent.

They're sold as commercial display panels/digital signage and because they're a business product that isn't subsidized by advertising/spyware they cost a good bit more. But the panels and controls are basically identical to high end TVs.

A cheap 4k generic android media box is less than $70 on Amazon. There are dozens of them. I use one because half the apps on my old smart TV don't work anymore. The android ones are always up to date and the UX is better.

Is there any TV on the market that flat out wont work if it can't see the internet?

I was going to suggest updating firmware initially right after your purchase, but that could also update a list of Wi-Fi credentials so it can continue to connect to the Internet using other nearby access points.
Only give the permissions you want the device/agent/human to use - no more.

Same for anything whether you trust it or not (or somewhere in between).

My in-laws were so proud of themselves. I came home one day and they told me they figured out how to connect my TV to the network so that I don’t have to use my Apple TV if I don’t want. I had to take a few deep breaths to keep from yelling. I am very happy with my TCL tv but I trust it about as far as I can throw my father in law.
At least with LG you can revoke your consent. I came home to found STT audio recording enabled and I promptly disabled it and lectured the household about privacy.
Nah, you're not crazy. I'm also someone who actually reads terms documents, because I find that they're often the only thing that will be truthful about a company's intentions.

And keeping it completely disconnected from the internet should be the default, in my opinion.

Only good until the device starts using a neighbor's LG TV as access point, without telling you, for the sole purpose of upgrading itself and sending this "telemetry".
There is absolutely no reason to read those contracts any more. As Louis Rossman keeps pointing out, most of them now include the ability for them to change terms at any time. That's basically the null contract.

Since the legal system has once again failed to protect users from corporations, it's up to users to use technical means for self defense.

At the very least, you can be sure they'll never change the terms of the agreement to be more beneficial for you, though.

So just treat it as a best case scenario, knowing that it can get even worse.

Just assume the worse then, save yourself some time.
Well yeah, that's kinda the idea, but sometimes it's nice to know what 'the worst' will entail
At this point every EULA or TOS change should begin with the heading:

We Are Altering The Deal. Pray We Don't Alter It Any Further

PS, my technical means are keeping my TV off the internet.
Which doesnt work. LG tvs will scan for availible networks. Someone setting up a new router within range briefly disables encryption and "your" tv will jump on that network and transmit all the stored data.

It is tinfoil hats time, at least for LG tvs.

Give it a network, but don't allow that network to access the internet.
If it can't phone home, it's not connected.

A technical solution would presumably spoof the spaff but with E2EE and DoH is it possible? So then what, flashing firmware? I guess then TVs get a hard lifespan limit.

I guess you could remove the wifi antenna, or otherwise brick the wifi reception ability (faraday cage, lead block, etc). Or - just boycott LG. I'll never buy any of that corporate espionage nonsense, ever.

Also: the US intelligence agencies used Echelon ages ago to monitor what vast swaths of innocent people were up to. I think it's sensible to presume they've got their hooks into these devices too.

Depends on jurisdiction, just because someone wrote something in a contract doesn’t mean it’s binding.

In Poland/EU we have an (ever growing) list of forbidden clauses that even when written and signed by consumer are null and void. And I think these can be enacted retroactively - when corporations invent new shady clauses, government steps in and tells them these are invalid.

This helps to even out the consumer-corporation field.

That’s great! Because then you’re left with the simple task of raising it up with the government.
There are governments with working institutions believe or not.

Also, I just read up and in our legal system a nonindividual agreement is nonbinding if “it is drastically against the consumer’s interests or against ‘good manners’”, with free legal help for consumers affected.

E.g. last year PayPal was forbidden from giving out bans and suspensions of user accounts based on vague and overly broad rationales. They were also charged $25M for that, but that’s peanuts.

If you think about, a good government has institutions where there are people whose full time job is to look at hands of corporations and listen to citizens. I know this may sound like sci-fi if you don’t live in a country like that.

> we have an (ever growing) list of forbidden clauses that even when written and signed by consumer are null and void

I'm pretty sure that's true almost everywhere. Law beats contract. The real question is how strong the laws are. In the US not so much because of small government and stuff, especially in red states.

The law matters very little when enforcing it in court often means a multiyear lawsuit against an opponent which employs an army of attorneys, has effectively unlimited amounts of money, will likely cost you ruinious sums of money, and for an outcome that's far from guaranteed.
>The law matters very little when enforcing it in court often means a multiyear lawsuit against an opponent which employs an army of attorneys, has effectively unlimited amounts of money, will likely cost you ruinious sums of money, and for an outcome that's far from guaranteed.

Or when you can't even enforce anything in court as you've already given up your right to spend all your money suing, as binding arbitration is the required and only mechanism to "resolve disputes." To make it extra fair, the corporation pays the arbitration firm for their "objective" decisions and not you.

What could go wrong?

Has it actually happened that someone went to court and the court told them no, you have to do binding arbitration? Or is it just something they put in the contract to scare you? Has anyone argued they didn't actually agree to what the country thinks they agreed to?

In the Gamer's Nexus video, he gets drunk before accepting the terms so that it isn't legal consent. A drunk person can't enter a contract.

>Has it actually happened that someone went to court and the court told them no, you have to do binding arbitration? Or is it just something they put in the contract to scare you? Has anyone argued they didn't actually agree to what the country thinks they agreed to? You could start by just saying no, you didn't agree to that, and the company will have to prove you did.

Yes[0]. For over 100 years.

Next question?

[0] https://en.wikipedia.org/wiki/Arbitration_case_law_in_the_Un...

You can do that too. You can show up, represent yourself and pay a few hundred dollar court fee, while the big company has to waste hundreds of thousands of dollars to defend themselves from you. You'll probably lose the case if you don't have a lawyer, but in a place like the US, you don't have to pay the other side's legal fees unless the case is frivolous (which it won't be).
The US is not small government at all. It’s one of the largest governments in the world. It just exists almost exclusively to serve billionaires.

It’s “small government” when it comes to protecting your individual rights, and full flock powered ai surveillance state when someone has an abortion.

I obviously didn't invent that term. And in large part you're right that it means deregulation so companies can do whatever
Funny how the type system works in a legislative framework: null AND void

I'm never going to interpret that one with a straight face.

>There is absolutely no reason to read those contracts any more

For another perspective, check out the comment you're replying to.

I never understood why any of the smartness had to be built into the TV in the first place. Sure, it's useful for the first year, and then the seriously underpowered hardware they installed into it will have trouble with just about anything.

I bought a Philips Ambilight OLED TV probably over 8 years now. Brilliant tv, great quality, I still see no reason to replace it at all. But its built in AndroidTV is garbage.

It's so you buy a new one every few years instead of keeping the same TV for a decade or two. Capitalism cannot survive when products last a lifetime.
> Capitalism cannot survive when products last a lifetime.

This is totally backwards; capitalism would do fine in such an environment (in the same way that evolution does fine in an environment where organisms live more than just a few seconds; the whole reason we have the notion of a "lifetime" is that our germ line comes from a long line of ancestral DNA that made organisms that outlasted their competition.)

Individual companies might have to hustle to innovate or die, but that too is good for capitalism.

Whoa!

I think maybe I stepped on somebody's agenda?

Both capitalism and evolution depend on the fact that over time, on average, less fit organisms/organizations are displaced by better alternatives. You may not like that, but down-voting anyone who points it out doesn't make it any less true.

[delayed]
It did. We are currently on the fourth or more reinvention of capitalism. It's like ethernet - every time networking technology changes, the new one is called the same thing as the old one. Same for capitalism.
Because it’s extremely profitable for them to serve ads and sell PI. Kind of like how the airline industry makes more money off credit card shenanigans than actual plane tickets.
Similar boat - Panasonic glass fronted TV. Circa 2013. None of the smart works anymore.

1080p, but the picture far outstrips most other TVs I've owned to this day.

I have zero plans to change it, and it's usefulness has outlasted the Chromecast that's connected to it.

Yes, I put the first ads on Smart TVs. Apologies.

I hear you. This is exactly the reason why I have a digital signage display rather than a Smart TV.
Because having the TV play from streaming apps out of the box is pretty useful.

The problem is we've not enforced any strong regulation against ads, downgrade rights or hack ability.

I don't need "better performance" from the system built into my TV I just need it to run Kodi.

> I never understood why any of the smartness had to be built into the TV in the first place.

Because technology got ever more complex. A TV of yore? That thing operated on (relatively) simple physics alone, at the cost of requiring an absurd amount of broadcast infrastructure to make sure a TV signal could be received across the country.

Modern TVs however... digital modulation schemes with a lot of signal processing wizardry allow TV reception with far less broadcast towers and far better quality. You got satellites and with these a myriad of control schemes (DiSEqC, Unicable, ...). You got Pay-TV that requires decryption. You got HDMI CEC to allow your TV to remote control your DVD player.

And all of that complexity requires firmware which means it can have bugs which means you need a firmware update capability and when you're at that point you can just go and slap something Linux on it and get all the apps for streaming services.

> I find that they're often the only thing that will be truthful about a company's intentions.

Really? Many years ago, I had to physically sign a license with Microsoft to obtain some software. The license was not consistent with the license included with the software. Both licenses effectively said they were the real license and that any other agreement you made with Microsoft was not valid.

I don't think there was any nefarious intent. It was likely to avoid a situation where Microsoft employees offered terms that were not approved of by the company. Still, it goes to show that it can be awfully difficult to judge the intent of a company.

I guess neither is valid then, you got the software for free.
Is there a list of all LG tracking services and external DNS endpoints?

I'd just block them - and keep local streaming and remote control working

Oh, by the way, these things spoof MAC addresses too, so you can't rely on DHCP.
[citation needed]
If you have one, can't you just look at the router to the MAC being reported?
I'm not the one claiming TVs actively spoof their MAC address. Its on the person making claims to provide evidence.
You can spoof MACs all you want, but your MAC is tied to the address I give out. What happens if you spoof addresses? FAFO...
Worse, if you watch the GN video this article is based on you'll find the TV can figure out how to leverage other non obvious networks (threads, etc) to reach LG servers. Worth a watch to see how bad this is: https://www.youtube.com/watch?v=6IFVTcM28KA
Its a 2+ hour video. Do you have a timestamp for this?
There’s a list of them in the Intercepting section of the source video.
A few models/firmware combinations have found to look for public hotspots when you don't agree to give them network.
Mine is still attached to the network, but I’ve turned off all the ad/customisation &AI stuff. Seems to work fine, no ads etc. though usually I’m using it simply as a screen for the AppleTV.

I do have it isolated from other devices on my network, though.

If you're only using it as a screen for the AppleTV, why connect it to the network at all?
So I can turn it on/off using Home Assistant and my phone.
What a useless feature. Reinventing a worse remote.
It is precisely so I _don't_ have to touch the actual TV remote ever.
Why not use cheap $10 IR blaster for that? it will connect to home assistant in same manner.
Because it's one more thing that I have to own and maintain; versus a built-in feature?
You might want to watch the video. LG tvs have the ability to record when they're not connected, and if you or your neighbors have an open wifi connection (like the ones that Comcast routers enable by default), it will silently use that route to phone home to communicate ACR data.
Yeah. I own an LG TV also of about the same vintage. It doesn't get to talk to the Internet.
We replaced our old TV recently with an LG and are really liking it. We do not let it on our network though and keep networking functionality disabled. It's basically a monitor for our Kubuntu Linux laptop sitting behind it. We stream with Chrome and use a mouse and the TV remote for audio. Once in a while we actually watch something on TV itself too. It'd be nice I guess if the built in TV app had DVR but if it does; I couldn't figure out how to make it work. No great loss there.
I'm still nervously holding my breath for the first disclosure that a TV manufacturer is using Amazon's distributed Sidewalk Network (or perhaps mobile vehicles, cell-SIMs, LoRa) to remotely gather all that viewing data they've subsidized into your artificially-low TV purchase price .

But they've been calling "crazy?" for decades.

This exactly. Surely some sort of IoT mesh networking will allow exfiltration of data even without having configured your own device.

I'm hopeful that there will be sufficient distrust that "jailbreaking" or "rooting" TV controller boards will be turnkey enough to move to something like OpenWrt or GrapheneOS but for TVs.

>IoT mesh networking

I'll bet there is already a manufacturer whose TVs can all communicate intratelevisually (non-standard proprietary frequencies) – and then, if even one of them is online... they're all relaying within their private intra-TV spyware meshnets to their various relays.

----

In unrelated news, my 2012 Sony Bravia is still fantastic, even if not for (4K) high-refresh games (the image quality remains fantastic for casual usage).

Why not do it yourself?
That is a reasonable push back. The simple answer is a lack of present day need given my TV is a very old Samsung without any need.

I suppose I also assume someone with Android ROM development experience is better positioned to take up organizing such a project as an overall smaller effort, there by being faster and more efficient. Other real life constraints also seem to suggest not pursuing this type of thing in lieu of other things I should be pursuing and already procrastinate. But, here there be dragons, or at the very least a can of worms.

I didn’t care much about data collected but I found that with every update it becomes worse and worse objectively. I had to cut it from in internet so doesn’t get completely unusable
I have a similar reaction from folks when I don't trust services/devices. Most telling moment was when I refused to upload my license to LinkedIn because I lost 2FA (token on phone, phone destroyed). Microsoft assured me they would "delete the license as soon as it was verified". I've written too many software systems for too many companies, and I do not believe them.

Of course, they'd outsourced to AU10TIX, which did retain the licenses, and got hacked: https://www.404media.co/id-verification-service-for-tiktok-u...

That's from 2024, but we just had a larger breach with IDScan this week.

Sorry for the digression, but the common thread is how much to trust these companies, and my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want. Some paranoia is warranted, I think.

Replit was asking for my license to change email address. Jeez
Same here when they find out I’ve never had an FB/IG/X etc account. As though having that crap in your life is somehow mandatory.

People who make poor choices love to pretend that they had no choice at all.

1. Interaction with Meta is virtually mandatory in many places in the world. Try opting out of Meta when your kid's daycare or your building's group chat is on whatsapp.

2. It doesn't really matter if you opt out, because _other people around you don't_: they take pictures in which you show, they tag you, they talk about you, they send you links, etc. Which means they (Meta) build a shadow profile of you anyway.

The "personal responsibility angle" is pure fiction.

You’re assuming that my primary concern is my privacy rather than my sanity. I don’t understand how anyone can seek out a non-stop feed of the sort of people who routinely post on FB. I’ve seen exactly what the doom scroll does to people without them realizing it.

So yeah if a business requires me to have an account I’ll find a different business to patronize. Frankly if you’re expecting someone other than you to take responsibility for the media you consume, that’s a problem.

My building’s group is on FB. I’ve managed without access for over a decade.

I live a somewhat normal adult life and manage without having anything to do with Meta ¯\_(ツ)_/¯ I probably miss some things, but I don’t notice.

All my friends just contact me through other sources.

If you have kids, it’s more difficult - I can acknowledge that.

You don’t NEED to participate in those group chats.
outside of the US, whatsapp has a huge chunk of the "private" messaging market. Everything that we usually use SMS or iMessage for, happens via whatsapp in much of Europe and South America.
When are the victims going to start getting significantly compensated for these breaches?

They will keep happening as long as the consequences are just the cost of doing business.

It will be when enough people elect enough politicians who take action against this weaponized incompetence and strip-mining of the peoples' assets.

Or, if that does not happen, when enough people rise up in revolution and take the compensation for themselves.

Or, never.

If enough people vote enough or revolt enough, they cannot be stopped. But the incentives for too few people rising up are too costly. They work hard to keep the equilibrium in that balance.

It becomes tricky fast.

There is obviously a fine that could bankrupt the company: this would be a clear signal "do not do this".

There are also many cases where people have been doing everything they should have been, and still got hacked (zero days, for instance).

Now, I do not think people should only be slapped on the wrist in that case: it still needs to be significant so companies carefully decide to store only the data they really do need!

I want this data to be treated like HIPAA data. Any company that collects personal data must have a compliance officer, and any breaches should lead to people going to jail. If you collect personal data, you are personally responsible for it.
> my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want

Honestly, it's not even that extreme in most cases. I think it's usually not malice, it's incompetence.

That's why I don't trust big companies with my data. Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.

> Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.

The CEO is responsible for what their company does. If a major breach can occur through the oversight or "incompetence" of one worker, the CEO has already failed, whether through negligence or malice.

Will the CEO suffer consequences? It seems the worst they face is being fired with a golden parachute.
In China, CEOs go to prison or are executed. Not all the time, but enough. In the US, they are given a golden parachute and make more money at their next posting. There is mostly only failing upwards.
Pardon my French but bull-fucking-shit! A CEO _should_ take responsibility for what their subordinates do. It's preposterous to simple throw up our arms and say "oh well, some employees were sloppy so we lost some 100 million user IDs and other sensitive information that we promised not to store but we lied. Oopsie, silly me, pardon my wee incompetence tee-hee". No no no NO NO!

At some level, and certainly at the level where you get paychecks of 10 million a year for the "huge responsibility you are bearing", then incompetence IS malice!

Everything you say should be true on any level playing field. Not in the British public sector where shambolic incompetence is the norm.
Uhh. I think you misread my comment pretty badly here. I am not making excuses for anyone.

I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.

Both are inexcusable, but one is more common/likely than the other.

You can certainly link them together and yes leaders should be held responsible no matter what, but from my perspective as the user who had his data leaked, it doesn't really matter how/why it happened, does it?

> I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.

Not being held accountable for negligence or incompetence is the evil machination.

> I think it's usually not malice, it's incompetence.

Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.

Careful not to cut yourself on all that edge bro
> Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.

I disagree with this as stated. Maybe in the right context you could make a case for it, but in general? Heck no. Intent matters a great deal, and there is no justice in treating someone incompetent (or negligent) the same as someone who is actually malicious. Both things are bad, but the latter is worse than the former even if they lead to the same outcome.

If you make your negligence my problem, you are my enemy.
In the context of a company doing something like this, intent does not matter in the slightest.
One could say that simply incentives are wrong so people turn negligent and/or are out of their breadth on a topic.

But is there someone accountable for it being so? Are they malicious? Who is ultimately to blame?

> Intent matters a great deal,

The road to hell is paved with good intentions.

It's probably both, vis a vis negligence. I just wish it was treated as criminal negligence. This will continue as long as CEO's face no real punishment for mishandling PII.
100% agreed. I'm definitely not making excuses for malice here (as I said in another thread, I think I wasn't clear enough in my original post)..

I think there should be much harsher punishments for PII mishandling, no matter why it happened.

It's malice. Compliance tends to not "maximize the shareholder value". Why pay millions/year to maintain a compliance team when you can get away with paying a small fine from time to time?
> I was ridiculed by my friends for that.

The sad part about the privacy discourse is that people not only don't care, but they would argue for the invading party. And I am not talking about your average teenager looking for their next brainrot fix, but highly educated and extremely intellegent people!

I've long since gave up trying to talk to people about these issues. Which unfortunately means I'll surrender to exposing myself to this plague to some degree, considering how herd immunity principles apply here as well.

It’s okay to be a luddite. Not everything needs to have an interface.

Got into a spat with a manager at my apartment complex because I refused to install their app just to deal with a maintenance issue.

He was like, “I don’t see the problem, you have to use the Latch app to open your apartment door.”

To which I replied, “No, I have the door keypad code memorized.”

Just like I don’t need an app to make a log of exit/entry history in a backend database just to enter my apartment via a Bluetooth lock…

…I should not have to install their app to make my apartment livable.

Indeed, my argument was convincing enough to have a resolution which didn’t include installing their app.

> you have to use the Latch app to open your apartment door

So what happens if you arrive home with a dead phone?

And possibly worse, they have a log of when you come and go?

You have a unique code, don't they already have a log of your coming and goings?

But I would absolutely not install an app for that.

They do. But the apartment complex gets a nice little kickback, especially since an app for unlocking your front door is one that has at least a plausible argument for having your location, which means a whole bunch of location data that can be mined/sold/both.
Usually smart lock does not have network connection(due to using battery).

But the app on your phone does not have that limitation.

> And possibly worse, they have a log of when you come and go?

Most apartment buildings in the US already use face-tracking cameras to get this log

I am a student and where I live most student housing has an app to open the door instead of a normal key. My current place used Bluetooth, the previous one was even more inconvenient because it used NFC. It sucks, and if you accidentally forget your phone at home you're fucked, but the landlords do it because it lets them block old tenants from entering without having to switch the locks.
My apartment complex came to install keypads and centrally managed smart thermostats and I would not let them.

Thankfully my lease was old enough that I was able to argue against it. I don’t want a 3rd party company tracking my habits, and I don’t want some manager boiling my pets alive while I’m gone because they decided they think our AC is set too low.

You got lucky. If you've got an apartment in, say, a healthcare facility, they'll install those thermostats and whatnot. Usually the neighbours are clueless about technology so complaining doesn't get very far at all.

It's even worse if some staff wrote paranoid in your file, 'cause they'll argue it's good for "exposure".

(comment deleted)
You mean if you are permanently resident in a mental institute they don't let you control the temperature? That's hardly surprising...
I read it more as a senior living facility.

Those folks pay out the effing nose, they ought to be allowed to control the temp in their apartment.

Some day, that could be you.
It's not about being a luddite. In many respects I consider it the opposite. It's engaging with technology in a way that demands standards of behaviour and performance.

I don't want the new thing because it is the new thing. I want new things that are better.

People accept abusive technology because they consider that's just the way it is with this new thing. It's a failure to understand what should be considered unacceptable.

Does this app work on GrapheneOS? LineageOS? Android betas? Who will troubleshoot issues if it doesn't?
Also, those "smart" TVs aren't really smart, besides that data grabbing, and are really slow. So connecting some mini PC is the way to go.
We need a HIPAA for consumer devices.
I had a similar experience regarding Facebook. People would always remark that they thought someone who knew about tech would surely have an account.

People don't say that so much anymore.

It's worth remembering that for all the animosity they face, they did what they told you they were going to do when they asked for your permission to do it.

Just thinking, if this is an issue, how you can dare to buy a modern car with embedded SIM card and GPS? :)
I yanked the OCU (telematics) out of my VW Mk7, and coded out the expectation of its existence from about four other devices with Ross-Tech's VCDS! I also coded out the Bluetooth on my infotainment unit, for good measure. :^)
I have an LG C5 OLED and do not give it internet access. It does not nag, every non-internet feature works fine, the interface is clean, and my Apple TV works just fine.
Same, disabled internet access on my LG years ago using the router config. It’s good that it at least doesn’t stop working without internet
Doesn't HDMI have built in Ethernet these days? So any HDMI cable of a certain specification is also a network cable.

I remember these things being discussed a while ago on here, how TVs use their own hard coded DNS ("for safety") rather than any network provided DNS (to avoid filtered DNS ala PiHole), how there's Ethernet in a HDMI cable, how other wireless networks are tried, and how eventually they'll go the car route and just embed a wireless modem in the device.

I am not aware of any smart TV that actively solicits a DHCP lease and default route outbound from anything it's plugged into by the 100M ethernet built into a current gen HDMI link. At least not yet. And since I think the default behavior for things like xboxes, playstations and apple TV is not to be a dhcp server and provide routing/NAT, I don't think a lot of things you can plug a TV into (also yet), would provide such function even if the TV tried.

I'm sure somebody at LG is hard at work on fixing this problem.

HDMI Ethernet was included in the spec 15 years ago and not a single consumer device (that I am aware of) ever implemented it.

Idk why this is so often citied in Smart TV boogeyman arguments.

Because it's there and available should they ever want to use it, and most people would not know that the HDMI cable is potentially another network cable.
I keep my off-brand smart TV offline as well, partly just because the next update could brick it. I just use it as a monitor. External Google TV box is the way to go if you want smart functionality.
I think the worst part is that most devices give you no option to disagree.

I bought a DJI action camera, I had watched a bunch of reviews and read the store page. Yet only after buying and turning it on did I discover the device only allows you to use it 5 times before connecting it to the internet and signing up for an account.

There aren’t even any features that require this, it simply bricks itself after the 5th use until you sign up and agree to the terms.

I usually go for Samsung TVs, but same, I never give it network access. I use a Fire Stick that gets its power from the TV's USB port. Best as I can tell, turning off the TV turns off power to the Fire Stick.
Same. And one of my requirements was that i can use HDMI ports without agreeing to TOS. Most android TVs do not allow this at all, LG did.
Makes me glad I bought a Sony TV which has the microphone on the remote - and is compatible with older remotes without a microphone, so the new remote with its microphone and sponsored streaming service buttons gathers dust (without batteries inserted) while I use an old remote.