86 comments

[ 0.27 ms ] story [ 7.1 ms ] thread
> If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.

Do you actually want a channel with 2.66 million subscribers to show how to get remote access to TVs used by millions of people? :-P

I'm pretty sure they DID mention that they can remotely flip settings. So that's a thing for sure.
That would be against Youtubes terms, the video would get pulled.
demonstrate != explain?
Yeah, why not ? LG should make their stuff secure (by not shipping bloat and spyware), so it is on them.
> What am I meant to take away from this? If you look at other IoT devices, they’re going to show the same thing. But here it’s presented as bad. Why?

The influencer economy is a bit soaked these days. You need to crank up the stakes to keep the viewer's attention.

> If you root or jailbreak your devices, you've, by their very nature, broken their security.

> If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.

There are ways to remotely jailbreak LG webOS TVs without user interaction, using the same (or similar) vulnerabilities you use to root your own TV voluntarily.

The main reason tools like https://rootmy.tv are prefixed with disclaimers and require user interaction is because we're being courteous, not because they're technically necessary. (source: I own the rootmy.tv domain)

Thanks for the write-up, it reflects my own impression of the video.

The video is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across.

They should have decided to set the focus on a specific area and then present every finding around that, i.e.:

1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.

2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.

3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.

All the points and scenarios in the video might be valid, but they jump between those scopes and imply that its all the same, weakening the whole investigation.

If I'm LG and forced to respond to this, I can easily focus on dissecting the voice-input topic as a mere demonstration of the feature and how rooting the TV beforehand just showed the local process of handling it, steering the narrative away from the (IMO) much more important topics...

Yeah if GN wants to keep my attention on this topic they need to edit out all the stuff about normal Wi-Fi stack behaviors and normal local device discovery behaviors. They didn't need to pad their feature-length video with these non-issues.
And how they asked the device for voice-input for a websearch via the UI, and the device proceeded to perform voice transcription, filling the searchbox with everything that was said...
They are pretty infamously overly verbose.
GN has sadly been trending towards overly long, rambly clickbait videos in recent years, in line with the rest of Youtube. Most of their videos could easily convey the same information with a third of the length.

It's unfortunate, because they're one of the few voices speaking out about issues like this.

Apparently 40 percent of Dutch fifteen year olds can't read. So YouTube is unfortunately the future.
> normal Wi-Fi stack behaviors and normal local device discovery behaviors

Sending to LG a JSON with a list of all the devices in the current broadcast domain is NOT "normal local device discovery behaviors" and everyone should be irate about it. Stop normalizing capitalism surveillance.

They rooted the TV to study it. They're not saying you're in sudden danger of attackers rooting your TV and running commands over SSH. They're saying there's evidence that certain data is collected when you wouldn't want it to be, and there are any number of potential vulnerabilities that could provide hackers access, on top of LG potentially having access as well which you also probably wouldn't want.
They still run the audio recording manually through SSH and then claim that your TV is spying on your private conversations "silently".

Otherwise, they start a voice command service (clearly displayed on the screen) and then say your TV is recording on your conversation. Like duh, of course my TV starts recording voice when I use voice commands.

And of course you have to trust LG with their TV and (not) having access. That same logic applies to every different company.

I don't think you paid very close attention. They clearly showed it transcribing audio when the TV was "switched off". And they weren't "running audio recording through SSH", SSH was just incidental to watch the audio recording and transcription that was happening.
Seems incoherent. What exactly is the bad idea and why? Are they rediscovering "don't run stuff needlessly as root"?
The bad idea is that by rooting, you can (of course) turn your device into a 24/7 surveillance device that sends voice and video data everywhere.

That does not mean that LG does all that by default.

Because of course it does. You are fighting the wrong side, they should proof they are good, not you defend them.
Yeah, it is insane a fully open source firmware with reproducible builds is not a minimum standard for something as sensitive as a modern smart TV.
It is not the minimum standard for computers. Why should it be for TVs?
It should be the minimum standard everywhere.
You're just jumping around a single point about rooting, whereas the video shows it's logging all the devices, with their ip, name, even detecting someone being in a Teams call. And you are as with the article, trying to sidetrack all of it by focusing on rooting.
> Now, what he’s showing can be pretty scary. I wouldn’t want any attacker to be able to record me without knowing. But it’s important to remember the context here: earlier in the video, Wendell rooted the TV. He has full access to everything on it. To run those commands and programs, he had to log into WebOS via SSH and run them on the device. He didn't show remoting calling those commands, nor was this done on an unmodified device.

> If you root or jailbreak your devices, you've, by their very nature, broken their security. If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.

What is this authors point?

LG doesn’t need a root exploit to get this info because they made the fucking thing.

I read the article and then grepped for “Texas” to see if I missed it. The author never mentions the fact that this data collection was only found out initially because of a Texas government lawsuit that LG settled on by agreeing to give “informed consent” to users about data collection and then the warnings started popping up in unexpected places.

Is the author arguing that jailbreaking your device to find out what the manufacturer can do to gather data on you is dangerous because I don’t know, questioning your corporate overlords is bad or something?

Some attacks shown on the video (like the "silent" voice recording) are initiated by the people in the video manually running those commands via SSH.

This is the major issue with this video: It mixes stuff done by LG (ACR) with stuff done via rooting (audio recording). And now people think LG is 24/7 recording your conversations and uploading them somewhere. This has not been proven.

Fresh account defending a corporation.
It's not a question of defending a corporation, it's that publishing a video that mixes true facts with facts that are not quite right weakens your argument and makes it easier for the corporation to control the narrative by pointing anything that's disingenuous.
If they had used the public attention on real problems that would be something of note.

Intercept what a normal tv does, show it uploading your voice recordings, your local network device names, etc.

Don’t bury it under conspiracy theory. Had this contained what actually went on I suspect it would be treated far more seriously. But then the video would be shorter and fewer ad views for the “influencer”.

Completely agree. If anything is suspect Lg paid for this video to confuse people between their legitimate actions (mdns), legitimate crimes (acr) and the theoretical possibilities (unrequested audio) to make anyone complaining about smart TVs sound like a conspiracy nut.
This reads like a PR crisis management firm planted article. it probably isn't, but it reads like one. It muddies the waters with vague implications and suggests we cannot infer anything from encrypted packets. If your screen is showing content sourced over HDMI and the packets are heading to the ACR endpoint, I think it's safe to infer HDMI is being ACR'd.
I think the author took the wrong message from the video.

His arguments are all - yes everyone does this not just lg - yes it can be used to track the user, but unless you literally go inti lg ads hq, you can’t say they don’t - they rooted to trigger this, well the os and system apps don’t need root, we need it to observe.

If the author is here please consider these as the reasons to why an LG customer would be mad.

- They did not knew LG has an ads subsidiary, whose CEOs and executives constantly go on investor meetings claiming “they own the glass”, “they own the living room”, “they own the network and devices” in the “lg household” - if the above was said by lg tv division it would have still stung less. This was said by an ad company they didn’t knew existed nor did they agree to be associated with when they bought a home appliance.

Stop focusing on the technical details, look at the larger picture.

I agree with the author, the point is that the way the video and the overall research was done, the entire message was diluted too much.

There is substance in what they did. But they should have worked with an actual journalist to frame this properly and create pressure on the overarching topics.

If a TV company (LG or ANY of the others who have Ad-subsidiaries) needs to respond to this video, they can easily reframe the whole topic.

The most blatant example is that they demonstrate in the video that this TV, which has a built-in microphone for voice-control, that can be switched off with a mechanical switch:

1. Will record your voice when you ask it to transcribe your input to a textbox

2. Will process your voice to create this text it shows, as visible on the logs of the rooted OS

3. Will SHOW you that it's transcribing your input on the screen.

This is weakening the whole story.

--

In HN-terms: It's a constant-power, constantly-connected IoT-device with lots of sensors and huge compute-power, located in the center of your home.

There are big topics around this that deserve a huge spotlight, which apply to ALL TV manufacturers:

a. What data is actually being collected about the user, and what is done with this data?

b. How well is security handled on the TV to ensure no malicious usage?

Repeatedly jumping to the conclusion during the video that LG specifically is collecting ALL this local data to spy on you, without clear evidence, this just gives LG an easy way to respond and every other vendor enough room to distance themselves from the whole story.

> What data is actually being collected about the user, and what is done with this data?

This question implies that the answer could be something other than the maximum amount of data collection and monetization of that data they can get away with.

If that statement gives you pause please spend even a short amount of time reading about ad networks, data brokers, and corporate surveillance.

Yeah, I wouldn't vouch for a US court, but lucky me I'm in the EU, where the answer "the maximum amount of data collection and monetization of that data they can get away with" is not compliant to the requirements of GDPR.

So even IF that would be a sufficient answer in a court of US, it would not be sufficient in a court of an EU country.

--> Hence my point on how the overall message was diluted too much.

See, you may look at all this as "nothing can be done anyway, so let's bunch it all together and rant about it as emotionally as possible". But I look at it as "this is all potential evidence that a law was either already broken or needs to have a loophole closed"

But you won't get any of this done by spraying all over how normal this is and how everyone does it anyway. You get this done with a precise shot at ONE of them, concise enough to pin them down while aiming at the next one.

LG's terms of service essentially state that they will record any voice commands and store them for 6 months. They explicitly say they may store them in Korea. https://us.lgappstv.com/main/terms

Actually I think everything you're suggesting is unclear, LG explicitly say they do these things in their ToS. I skimmed their privacy policy, and I'm pretty sure it essentially says they collect all this information and use it for targeted advertising.

Yeah, and here's the part that's interesting to me as a EU-consumer: This wording doesn't exist in the European ToS: https://gb.lgappstv.com/main/terms#tabContentTerms6

So there's the angle that US is lacking the proper regulation, and the angle that LG may have violated its ToS in the EU.

But neither of this is going to get pinned down if everything is bunched together without focus and clear evidence...

The numerical majority of developed counties have some kind of privacy law. Murrica is an outlier, because of course it is.
I was also a bit disappointed with the video. I don't usually watch the channel, but the previous video on LG with the McAfee thing was good. This one, well it has important points and exposes some very valid concerns. However I mostly agree with the linked article, it does not properly spell out what they actually can prove, and what's just conjecture. The video gets lauded as investigative journalism, I think the technical details are important to get right and make clear to non-tech people. A normal consumer would have no idea how to really judge the danger to their privacy after watching this, they'd come away thinking that for sure someone can listen in on their living room.
It's such a bad take.

It's either a deliberately contrary or the author has other motives (which may sound ridiculous, but we know that bad actors have been paying people for bad takes for years - Malcolm Gladwell for instance being paid by oil and gas).

Yes, as the owner of an LG OLED, I paid a premium for a good quality panel, and expect it to be mine.

Also, I anticipated ads on a smart TV (unfortunately it's inevitable), but (wrongly) assumed that such invasive tracking and "we own the glass" would be a bar too low even for the budget manufacturers.

I'm never buying any LG product ever again.

I have an LG OLED as well. When I bought it, it was the previous year's flagship. I am also mad at this.

I also had an LG washing machine. The dispenser plastic drawer broke after a year of use. After over a week of multiple emails and calls with the shop, LG themselves and third-party spares shops trying to get a replacement, I bought a Bosch.

I am also never buying anything from LG again.

Your broken waking machine drawer is an orthogonal problem, and perhaps not specific to one corp. Plastic parts break but, OTOH, overbuilding consumes resources with diminishing utility. A deep spare parts market is a cost.

May i suggest basic home repair? Two techniques that work in many cases are:

- "welding" with a soldering iron, using cable tie as a filler rod. You'll want good ventilation and a sacrificial tip - epoxy repair putty

Superglue (cyanoacrylate) tends to give disappointing results on its own, but can be a good first step before putty. Putty can be reinforced with some kind of fibre. Never use cyanoacrylate with the welding technique (cyanide).

I don't love the model profusion that makes spare parts markets inefficient, but free markets are inefficient all over the place. Price in the externalities.

I used to think this too, but e.g. Bosch and IKEA have great replacement parts websites accessible to the consumer. IKEA’s parts are mostly free, too! With modern logistics (automated warehouses, cheap shipping, ordering online) it is actually a solvable problem, if the company gives a damn about it.
I'll take that as a recommendation, thank you! Fwiw, i have found spares for many brands by searching model numbers and wading through spate parts aggregators. The market exists. It's often uneconomic :-(
> Your broken waking machine drawer is an orthogonal problem

Perhaps, but LG has proven problematic to deal with.

To give you an idea, I tried directly with them at first. They gave me an official website to search for the part. It wasn't available. They then game me 2 or 3 third-parties to search. None of them had the part available. I emailed and called. They would at best say "not available".

Eventually I got LG to escalate to a manager, who called me back the next day. The manager was very nice. Told me to go to that official website again. I couldn't find the part. She then instructed me how to navigate to a form on that same website where I could send a message requesting the part. Remember, this is an official LG website.

I sent the form. The next day I got a reply from a third party, telling me they didn't have the part and I should contact the manufacturer directly. Now this is with dirty laundry already accumulating and us risking running out of pants. There's no laundromat near me and I don't have a car, nor I have the time for this crap.

Eventually I found what _could_ be the right part. Only there was no way to be sure it was, and it had a 3-week wait.

At that point I sat down and calculated how much I paid for the machine, its expected lifetime, deducted the time I had it for to get an estimate "remaining value", and it was less than the time I was wasting with this ordeal, plus everything else if I had to arrange alternative washes for the time being and the price of the replacement part (assuming it was the right one), so it made sense to just buy a new machine and send that one for recycling, so I did that.

> May i suggest basic home repair?

Sure you can, but I don't have that machine any longer, would probably not get it to a good state, and would waste even more of my time.

It wasn't a simple plastic crack. The drawer was comprised of 3 bins (on the same part), 2 of them covered by rubbery lids. The rubber needs to seal the bin below, otherwise detergent and softener leak and make a mess (which was happening at this point). One of the bin walls somehow got completely deformed. The rubbery lid wouldn't seal, and to make it worse, it eventually split at the seal because of the pressure from the bin wall. It would have been a nightmare to repair to an acceptable state.

Also note that the bin lid is something that needs to be opened and closed frequently for top-ups and cleaning. No home repair would survive for long.

Yep, that sounds over-engineered for questionable benefit. Ty for the exposition. Sounds like something i would junk, too. I'm angry on your behalf.
I own an LG TV as well, and while I assume the Mi TV Box 4K tracks me instead, at least it's unpowered while the TV is off, and the TV itself is not connected to my network. I have updated TVs/soundbars/etc, but only through USB. When they remove that option is the day I stop being a customer, moving to one that still does.

Better yet would be never needing an update, but alas.

I have an LG OLED as well, and to be honest I don't care. It is pretty obvious that every TV manufacturer does it by the fact that they all have to make their TVs "smart", perhaps save for the tiny/unknown ones that don't have an ad department or a contract with an ad company. Five minutes of using any smart TV interface should be able to dispel the notion that it somehow exists for the benefit of the user, and not for other reasons. My TV simply never goes on the network, which makes this a non-issue
LG has an ads subsidiary, whose CEOs and executives constantly go on investor meetings claiming “they own the glass”, “they own the living room”, “they own the network and devices” in the “lg household”

Uhm every tech bro does this it is what makes the tech industry a fucking Bond villain lol.

> If you root or jailbreak your devices, you've, by their very nature, broken their security.

Wow. Please stop spreading things like this.

Not having root means not owning a device you paid for and have in your home.

I know people here do not want to hear it, but it is a very two-sided sword.

Of course root allows you to tinker with your device and make it run what you want, but:

- Rooted devices make devices unpredictable. As shown in the video: How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?

- Re-selling: How do you know that TV you bought is untampered? How do you know it does not have software with malware installed that steals your credentials?

Honestly in a lot of cases people here are too ideologically blinded to see the logic that you’re laying out. It’s the same mental gymnastics that let many here praise something like GrapheneOS yet turn around and screech over it not allowing root which is nearly central to its entire security architecture.

But in this case… I don’t know. The OEM is so actively hostile you might be better off just taking the risk with root if you must purchase it at all (and physically removing the radio/microphone hardware not being an option).

Wait who are these people who praise GrapheneOS but complain about it not allowing root? It sounds like you're conflating two groups of people
No, go to any large GrapheneOS post on here and you’ll inevitably see comments asking why they can’t have root and why it needs to be so strict, why can’t they have everything with the feature set of GOS + root. I’m sure in my comment history I’ve argued with people here over this.
I would also have been annoyed with that if I had to use GrapheneOS, security is a terrible argument to deny people access to their own hardware. But then I'm not a GrapheneOS user, just like I wouldn't have been a Fedora user on my desktop if Fedora made it impossible to gain root.
> How do you know that TV you bought is untampered?

Many rooted devices display during boot a warning that they have been rooted. This is a problem that has been solved for more than a decade, but manufacturers pretend not to know the solution, because they are actively hostile to user freedom.

> How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?

Let's pretend there aren't plenty other ways they could spy on you. If it's bad if a hotel does it, why is it okay if LG does it? Do you honestly trust LG, and the thousands of "partners" that they sell your data to, and every government whose warrants they have to honor?

Your argument reduces to "if the warden lets us out of our jail cells, who will make sure we behave?"

> Many rooted devices display during boot a warning that they have been rooted.

Usually, this happens after a bootloader unlock because then verified boot is disabled. You can still have a rooted device and not break verified, resulting in no warning. See: jailbroken iPhones.

I wouldn't say it's a solved problem. Just have to find an exploit that works with verified / attested boot.

And device manufactures are getting more and more restrictive here, too. Why do you think that is?

> Let's pretend there aren't plenty other ways they could spy on you.

Sure, of course there are other ways to spy on people. But as we see here: If the device itself does it, then we like to blame LG. If they used an exploit to do that, then we blame LG's shitty security.

If a hotel owner installed a microphone inside one or their specific TVs, then we blame the hotel owner at least - not LG.

> If it's bad if a hotel does it, why is it okay if LG does it?

It doesn't seem like it is okay. We are discussing this right here.

> Do you honestly trust LG, and the thousands of "partners" that they sell your data to, and every government whose warrants they have to honor?

Do I trust LG more than a shady hotel / BnB owner or eBay seller? Yes. Do I trust them fully? No. It's not fully binary, I'd say.

> Your argument reduces to "if the warden lets us out of our jail cells, who will make sure we behave?"

I am just trying to say, it's really not that binary. You can extend that to other places whenever attestation is involved.

Do I like Linux and open platforms? Sure! Tampering is fun! Do I hate people using open platforms to scrape my websites and constantly cause load, steal my content and use that for AI training? Also, yes.

But how can I fight that? We run into CAPTCHAs, Cloudflare, Anubis and co. Now that issue is reduced, but the openness is also gone.

And you always see in tech spaces we rather want "dumb" devices rather than smart devices, because we cannot trust them.

Attestation buys you more trust, but at the cost of openness.

> I wouldn't say it's a solved problem. Just have to find an exploit that works with verified / attested boot

In general though on devices that are rootable, white-hat hackers are more inclined to responsibly disclose vulnerabilities instead of releasing them as a way to root said device. So having a rootable phone does increase security.

What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.

The thing is, the whole topic is not fully binary. I agree with you that having a rootable phone does increase security in certain ways.

> What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.

I'll ask naively: Why not? I can come up with a bunch of arguments why it does help the bank and why it might reduce the risk of certain attacks.

Because a lot of people will install whatever closed source magisk module or lsposed extension they can find to go around the bank jailbreak detection and end up actually weakening their security posture. Those modules are a prime target for trojan attacks.
With an on premise device, the game is already lost. They may plant a separate mic device inside the TV, or elsewhere. Rooted TV doesn't really impact BnB security model.
All of those things are: you don’t.

If it’s a problem, unplug it.

If it’s a problem, don’t buy it.

Works for everything!

> Rooted devices make devices unpredictable.

you/we/me not having root while, for example, Google Play Services does on invalidates everything you said.

True, but rooting the device de-facto means breaking the trust-chain of the OS.

The inevitable outcome of this video is that TV vendors are pushed to harden the security and preserve the trust-chain, because part of the (valid) claim is that nefarious actors may break the security to use the device for spying on you.

With support from an actual journalist, it could be reframed to also emphasize the importance of controlled root-access to monitor and control the devices behavior.

But none of this was done unfortunately, and if I'm LG I don't want to see another video where someone reframes user-initiated voice-input for a web-search as spying initiative by showing some device-logs of the transcription process in parallel...

It's not necessary to break the trust chain for the device to spy on you, turns out they do that regardless
The trust chain is long broken since the TV is spying on you a the manufacturer is bragging about them "owning the glass and the living room".
> True, but rooting the device de-facto means breaking the trust-chain of the OS.

Like every single Microsoft laptop out there does so? Think a bit harder before sentences like this, please.

I'm thinking very hard, yet still don't know what you're trying to say. You want a consumer TV to be like a Microsoft laptop, is that the benchmark?

Did you read and comprehend the rest of my statement?

I'm trying one more time. I'm not arguing against you, maybe read this again in a few hours:

I believe you want to have full control over the device you own (like I do btw).

For this you need to acknowledge that right now it is not in the interest of any party to provide that, because it requires additional effort, carries additional risks and doesn't create an economical benefit.

You have to MAKE it the interest of ANY party in the chain (the manufacturer, the seller, the consumer, the lawmaker,...).

Being an angry consumer is not getting you there, asking people to "vote with your wallet" is not getting you there.

--> Why? Because you won't reach a critical-mass of consumers to move the needle for the manufacturer to notice and take action.

Creating noise on security issues and potential hacking won't get you there.

--> Why? Because IF it creates ANY reaction, the public reaction will be to hold device-manufacturers responsible, which (if it works!) will cause them to just spend more effort to lock down their products even more, secure the trust-chain in the OS and simply stop operation when it is broken at any point.

Trying a mix of topics by mangling everything together, to create as much noise as possible? It will not get you there.

--> Why? Because even if that noise is creating a critical-mass, if it's not based on a sober solid foundation with a clear demand, it is not actionable and will die down. Everyone knows that this will happen and affected parties will count on that.

So. What GETS you there is "artificially" making it the interest of the involved parties, STEERING the manufacturer into the desired direction.

How do you steer things if the sheer economics don't do it?

(I don't know your experience, so YMMV from here)

From my experience, the only sustainable way to achieve this is that you literally regulate it, by demanding a LEGAL requirement.

e.g. Pushing for regulation to provide the user full control over the product if he wants it, acknowledging that the process reduces the responsibilities of the manufacturer for that device.

You do that by finding as many reasons, as much evidence as possible that this is a solid direction: Security concerns, environmental concerns/waste elimination, "ensuring a free market",...

--

So how do I know that?

Because I LIVED through it already (with many other active people in the scene), trying to make bootloader-unlock and community OS a default thing on Android Smartphones.

We amplified the topic when the industry was still new and growing, created more noise than there actually was, riled up journalists to act like this is a crucial buying decision for the market, lobbied the whole industry, to a point that they actually made it a competitive feature.

Doing all that against a juggernaut of interests AGAINST it (in US e.g. Verizon, which never bulged, vendors with concerns about unjustified warranty-claims, journalists/users stating that this is weakening security, etc.)

And what happened? It all died down because we didn't use the momentum to get it into a regulation when there was the chance. Some fruit-company demonstrated over years time and again that this doesn't matter, then even turned it into a marketing-feature to NOT give full control to the user.

Meanwhile the momentum and interest in the market died down, and for the past years we started to lose bootloader-unlock again in many brands, without any notable impact on their sales.

So if we have to do it again, in a matured market (like TV is), how do we do it now?

Again, YMMV, but for me, having lived through that already, the only viable way is regulation.

Regulation which demands a solid trust-chain in control of the vendor, AND the possib...

Agreed the modern push against root access is a prime example of attempted enshitification lock-in.

If you don't have root rights, you don't really own it. All other arguments are talking past this key point.

Now I want to build a cluster of rooted WebOS TVs.

I always say any serious computer needs blinkenlights and a smart TV has literally millions of them.

Anyone who uses GenAI for content creation, isn't worth my time. My rationale is simple: If I wanted to, I could have asked "AI" to generate that content for me, when I am spending my time consuming your content, I expect to get something unique.
Semi-OT, possibly interesting:

Maintaining enemy lists like the one of Drew linked there has been illegal in Germany since 2021 as part of the government's efforts against hate crimes and right-wing extremism.

Or at least that's my understanding of the law there. Maybe it's exempt based on technicalities.

In any case, I can in many cases emotionally relate to why he is doing that, but.. oof.

I'll save you the time and effort trying to work out the point being made:

GamersNexus did an investigation which may overstate the privacy threat posed by LG smart TVs.

Well as I do like saving time I’m certainly it going to watch an hours long video about someone installing their own software on a computer and doing things with it.

If they had shown what a normal LG collects that would be fine.

If they rooted it to install a new root certificate so they can MITM traffic and see what’s actually been sent that would be interesting.

From what I read it’s “you can use a Turing complete computer with network and microphone access to do things”. I mean sure.

What I want to know is what does it actually do

I would love smart TVs to have a “no smart functions” option, and I know that they don’t because that’s part of the ad tech economy so beloved by HN.

What I want to see is what does it actually do and perhaps how can it be blocked technically.

Maybe it’s in the video, but videos are terrible ways to communicate this, and it seems to be mainly breathless nonsense and possibilities.

I’m convinced the only thing saving us from hardware manufacturers security incompetence is NAT
I am still somewhat new to networking concepts (currently reading Computer Networking: A Top Down Approach by Kurose & Ross), and as far as I understood, most IPv6 networks don't have a NAT, or did I misunderstand? If that is the case, that means homes using IPv6 have globally routable IP addresses for their connected devices, right?
Yeah you just need to remember to login to your totally-not-corrupt ISP's definitely-easy-to-use firewall manager app and setup your firewall rules to prevent hostile governments from using your microwave as a passive listening device, which they sell back to your own government for probable cause, to arrest you for cooking the wrong brand of popcorn.
Reading this, I do not have a LG TV, but I have 3 LG AC connected to WiFi… Ouch
Why is this a post even? What is it that the author is trying to say or take a view on?

They literally write "Now, I’m not going to claim to be a network expert. I may be totally off-base, but what? Reverse DNS? I don't know what this means."

The findings are a smoking gun already.

The bar shouldn't be a video of an NSA agent or someone from LG listening your everyday life. I don't doubt this happens but we shouldn't expect gamernexus to be able to prove it.

Jesus some people with their whataboutism and nihilism.

> If you root or jailbreak your devices, you've, by their very nature, broken their security.

Yeah no this is just incorrect. There's many cases where jailbreaking actually fixes issues when a vendor abandons the platform. It also enables usefulness for a product long after it's been EOL'd.

In the current season of LLM driven security research, this is even more important. There are a LOT of EOL devices sitting there unpatched, vulnerable to the growing number of vulnerabilities. We can either stick our heads in the sand, we can demand the ability to update the vulnerable software on the hardware we bought, or we can exploit the CVE ourselves (collectively, as a community) and introduce CFW for the vulnerable devices.

The main thing I'm taking away from this LG thing is that I'm going to root my TV as quickly as I can with whatever CFW will get rid of this surveillance capitalism atrocity attached to the wall in my family room.