206 comments

[ 0.20 ms ] story [ 4.2 ms ] thread
GDPR is forcing them to detail which private data they collect.
they detail, but no one reads that anyways
And if anyone didn’t watch GN’s video on it, it’s thousands of pages of text requiring a button press to scroll each. It’s designed for no one to read.

We should have laws that limit this kinda of “agreements”

They should flat out be banned for consumer electronics and goods.

It's insane that something you purchase can force a post purchase EULA before it can do anything.

Imagine buying a shirt but there's a 10 page EULA that says you agree to arbitration as soon as you break the seal. Or a blender, or an oven, or a refrigerator.

A lot of the "smart" electronics are in fact just that, they are sneaking in EULAs to use an app to connect to the device which robs you of your rights and protections as a consumer "Oh, the law says we have to give a 10 year warranty, but unfortunately you installed our app to work with your device which says you agree to forgo the warranty and pay us for the right to sue".

The GDPR does. Consent to data processing must be unambiguous, accessible, informed in plain language with no legal or technical jargon, and not have any preselected boxes.

https://gdpr.eu/gdpr-consent-requirements/

The problem is the capacity to litigate is far surpassed by the world's speed and volume of doing bad.

This is a case where companies' actions should be treated like parking tickets: a fine is issued summarily, with option to appeal, not a slow process of litigation having to happen before a fine is issued.

The US agreement says it too. They make you agree to them collecting it. It says they listen to everything that's said in the vicinity and you agree to inform any guests to your house that they're being recorded at all times. But nobody reads that.
I find deeply stupid to buy a tv that can potentially spy you but I am pretty sure they do it with phones also...

Every day I want to keep tech more fenced and far from me and only use it for what I need.

The only reason TV’s are getting cheaper is the business model changed. Now your viewing data (and perhaps conversations) are part of their product offering.
Bold from the verge, as clicking the link to go to the official statement took me through 3 redirect trackers as picked up by my browser/extensions (I think ubo to be specific)
[delayed]
Huh. I didn't know you could change the URL. It used to point to https://www.theverge.com/tech/994333/lg-responds-to-tv-spyin...
You can't. The admins can.
It now looks directly to the press release. Wish I could delete or edit my comment because people keep downvoting me for looking like a lunatic I guess. But overall this is what I wanted. Just the primary source. Not like it was in Korean
The real issue here is they’ve been dishonest and less than candid with their customers.

Trust broken, words out, and their statement doesn’t really do anything to mending that.

LG's statement:

> ACR uses audio fingerprinting technology using the TV’s internal audio processor (not a speaker) to identify content and does not collect screenshots, screen recordings, video recordings, voice recordings, or other audio recordings from the TV.

So they are claiming that ACR is done entirely through audio processing, and no visual data from the screen itself is used? That...doesn't seem plausible.

This paper from 2024 investigated both Samsung and LG and found that they both capture screen images for ACR, and send the resulting hash (not the raw content) back to the manufacturer for identification.

https://arxiv.org/html/2409.06203v1

After doing some investigation into my Bang Olufsen after some tech not working right apparently Dev mode on it allows "Most probable raw grab: ThinQ/SSAP on the LAN after pairing — ~960×540 JPEG. Live Plus/ACR: most probably sends a fingerprint, not a retrievable raw frame."

As per HN thread last week

> So they are claiming that ACR is done entirely through audio processing, and no visual data from the screen itself is used? That...doesn't seem plausible.

It's probably easier to do and every bit as accurate as just using a screenshot.

And it's still exactly what I don't want them doing. There's literally zero reason for LG to be building an advertising profile on me because I was foolish enough to buy one of their TVs. This isn't something that makes their products better, it's spying.

It’s a lot less data to process as well.
wouldn't taking screenshots in fact not always be possible depending on the content you are watching? For example netflix with their hardware level drm? (Although its their TV they possibly have ways around that with some custom hardware)
LG sits at exactly the location where screenshots are possible.

Eventually, a digital signal needs to be converted into pixels on a screen. Once that happens, it's trivial to also pipe those pixels into a screenshot.

It's the reason DRM for digital media is pretty dumb IMO. The most sophisticated DRM still has to be decoded at some point for the end user to enjoy it. It can always be broken with a camcorder (though quality suffers). However, there exists devices which decode the HDMI signal so doing a pure digital signals.

I can assure you while out sailing the high seas I have watched many Netflix titles. So their DRM is literally only there to make the experience shittier for the honest customers.
As much as I detest ACR this seems more plausible than screenshots but I wouldn't trust LG regardless.

Audio is much easier to fingerprint and match against content.

To me, it's not even about why they're doing it (building an advertising profile). I don't want them doing it at all, for any reason.

When I buy something from the store, my relationship is between me and the store, for the 30 seconds it takes for me to pay for it. I don't want an ongoing relationship with the device manufacturer. I don't want to be tethered in any way to the manufacturer. I don't want to have an account with the manufacturer. I don't want the device sending anything to the manufacturer, advertising related, telemetry, or even a single bit "user has used your product." Do you get it, manufacturers?? I don't want any kind of relationship with you! I want to purchase my product and use it by myself not with you.

Then what about all the cloud enabled spyware? How would that work? (/sarcasm)

Truly though, smart-home stuff runs the whole gamut of privacy and device manufacturer relationships. eg: I have used three different smart/room AC units:

- one requires its own cloud-enabled app for any remote connectivity, no HomeKit integration - one integrates with HomeKit but then leaves an upgrade hint that can only be done through an app with a login - one integrates with HomeKit and pretty much just works

HomeKit then allows me to remotely control via HomePod/AppleTV acting as a router ... of course this is just a different cloud connectivity but with on-premises devices controlling other on-premises devices.

For each manufacturer of smart devices, there is potentially a separate cloud where data is being funneled through. Some devices support multiple upstreams.

I get that Matter should be a way to fix it but the reality feels more like https://xkcd.com/927/

Part of me just wants dumb devices back. Get rid of buttons on a microwave (just give me a knob for time and maybe another knob for power setting.) Remove touchscreens from cars (mine glares at me with certain sun-angles.) Bring back the desktop/computer hutch and phones that don't live in your pocket. However, having the ability to start cooling my bedroom 45 minutes before I arrive home is ... pretty compelling too.

> I don't want an ongoing relationship with the device manufacturer.

I think it depends on the device. If I buy an iPhone, I have the expectation of installing apps on it after purchase, and that necessarily involves a relationship with the app store provider (ie. Apple), not the store I bought the phone from.

With a TV, I suppose it depends on whether I want to install media apps like Prime Video or Netflix on it. I understand that there will be people who don't want that, in which case I agree with you. But others want to be able to run this stuff somehow, whether it's directly on the TV or via some HDMI device like a Chromecast or a Fire Stick. At that point, they _do_ want a relationship with some manufacturer so that the third party app can run on it.

> If I buy an iPhone, I have the expectation of installing apps on it after purchase, and that necessarily involves a relationship with the app store provider (ie. Apple)

This is only true because Apple dictates it to be so. The manufacturer of the device should not have a say in what I choose to do with a device I bought. I should be able to install software on a device without asking the manufacturer for permission. Why do they think they should have an opinion? After I purchase the device, it's mine, not theirs. I can throw it off a cliff if I want without asking for Apple's permission, why can't I install software on it?

> At that point, they _do_ want a relationship with some hardware manufacturer so that the third party app can be delivered to run on the hardware.

The device manufacturer should not need to be involved with a user's decision to install software. There should not be this requirement to have a relationship with them. We should never have allowed this idea to be normalized that the device manufacturer needs to be somehow have a say, let alone be the sole path to using the device.

Device manufacturers should sell devices and then get out of the way of what the user is doing with those devices.

I mostly agree, although if the manufacturer has a catalog of software (which they have managed to check for quality, classification, etc) that you can optionally use for installing software (which others can also choose to do, e.g. in the case of Android there is also F-Droid), but that you can also install anything that you want to do by yourself (including software that you wrote by yourself) without needing to be able (or willing) to contact (or have anything further to do with) the manufacturer (for any reason), then it can be helpful.

Also, if someone provides a service (e.g. Netflix) that some might want to use and some might not, then you have the option to use that service might be helpful but even that should not require any relationship with the manufacturer unless they are also providing the service. If the manufacturer is separate then they should not have anything to do with it (e.g. they should not add a button on the remote control specific for Netflix; if they have user programmable buttons that you can add your own labels, then it would be possible to use such a thing like that if the end user decides to install Netflix). (There are other problems with Netflix too but I am ignoring them for now because that would be a separate discussion.)

"If I buy an iPhone" Just dont do idiotic shit like that then.
When I buy a computer, I have the expectation of installing apps on it after purchase, and that doesn't necessitate any relationship at all with any app store provider of any sort (ie. Apple).

(When I buy a pocket supercomputer, I have that same exact expectation. It's often left unsatisfied, but I still have it.)

> I think it depends on the device. If I buy an iPhone, I have the expectation of installing apps on it after purchase, and that necessarily involves a relationship with the app store provider (ie. Apple)

I bought my Pixel from Google and don't want any relationship with Google whatsover. In fact, I wiped the stock OS and installed Graphene for this reason. My apps come from various sources, none of which is Google.

> If I buy an iPhone, I have the expectation of installing apps on it after purchase, and that necessarily involves a relationship with the app store provider (ie. Apple), not the store I bought the phone from.

That's because Apple supplies both the hardware and the software. Being a software supplier - the only such supplier - they need to keep being involved. This wouldn't be the case if third-party OSes existed for the iPhone - it doesn't need to be the case for M1/M2 MacBooks, for example, thanks to Asahi, or for any x86-based hardware.

Wait your saying it’s not cool if you buy carrots from the grocery store that have embedded sensors so that when you eat them and they pass through you they build a health profile and determine what types of supplements are best to advertise to you?
> There's literally zero reason for LG to be building an advertising profile on me because I was foolish enough to buy one of their TVs.

I feel like the world is bossed by people who read (well, ok listened to a 5 minute summary on a grindlife podcast at 1.5x speed) about the Trojan Horse and thought they smelled a business opporunity.

By and large, that has been my experience.
Is it within fair use to surreptitiously record copyrighted music?
> It's why youtube still hasn't figured out piracy, but they'll knock you immediately if you play 5 seconds of copyrighted music.

Unless the piracy is silent, surely audio fingerprinting would catch it?

> It's why youtube still hasn't figured out piracy Are you sure that's even on their roadmap. If they profit from piracy why would they care.

the whole DMCA/Takedown process is another shenanigan ripe for abuse. Not real copyright enforcement.

> an advertising profile

It's going to be so easy to determine who you voted for, given a record of every TV show and news programme you've watched, to 90% accuracy. Or to determine if you'd be a "corporate culture fit" when you're next looking for a job. Or an apartment. Or to find whether anything matching the hash of some trade secret documents was displayed on your TV (or ever connected to it [1]) - the "advertising" firm will be forced to hand over documents on you through lawsuit discovery and the wonderful 3rd party doctrine.

They're not building an advertising profile. They're building a profile. Ads are just the most common known use-case at the moment. But the profile will remain long after ads become the least of your concerns. Consider how such a profile would have been used during the cultural revolution.

[1] LG Smart TVs log USB filenames and viewing info to LG servers - https://news.ycombinator.com/item?id=6759426

The difference with the book example is that having to hand over a list of books is tangible whereas technological profiling is extremely subtle and abstract in comparison. As IT professionals it's of course easy to see the ways that this kind of stuff can be abused, whereas the probability that someone outside of the industry or otherwise not interested in computers to be "woke" enough about the digital panopticon is diminishingly rare.

And there's of course also Sinclair's law, so even people who should know better might be either willingly ignorant or just not care if it means that they can maintain their quality of life, moral bankruptcy be damned. Similar arguments can be raised for example with the anthropogenic climate catastrophe or other abhorrent phenomena where there's a big chasm in the knowledge between laymen vs experts.

It is exceedingly difficult to convince someone that something is a problem unless said problem is staring the person in the face.

isnt that worse?, they're constantly recording audio in all homes and sending back results.
> ACR uses audio fingerprinting technology

so they aren't even denying listening in on everything?

"Everything" would include the microphone, both in the remote and the TV. They're claiming to split off the audio, with one path going to the speakers (and there to your ears), and the other path being hashed (and from there to LG).

They still claim to get your media's audio, but deny using the microphones.

If they don’t use the microphones why do they have a statement in their Terms of Service to not say sensitive things in front of your TV? It says the TV owner is "solely responsible" for obtaining all necessary consents from third parties whose voices may be recorded by the device, and must warn household members and guests that their voices may be recorded, and if someone does not agree, the TV's microphone and voice functions need to be turned off. [0]

[0] https://www.lg.com/us/terms

>If they don’t use the microphones why do they have a statement in their Terms of Service to not say sensitive things in front of your TV?

Other people have mentioned there's other voice features like diction/voice control, so it's plausibly for that.

That's probably the program that uploads everything you say then. Nobody thought the ACR was doing that.
> If they don’t use the microphones why do they have a statement in their Terms of Service to not say sensitive things in front of your TV?

1. The introduction says that Smart TVs are not included in this ToS ("not including Smart TVs").

2. Where do the terms say anything about "sensitive" content? The closest thing I see is section 4.d, but that's just about wiretapping/privacy laws in general.

Which paragraph?
They deny ACR uses the microphones. Big difference. Nobody thought ACR used the microphones.
They explicitly state that the audio ACR is done through the "TV’s internal audio processor". e.g. rendered audio, not recorded audio. I mean, you could stretch the claim to have it internal include recorded audio, but that seems dubious.
Why are you giving a shady company with shady terms and shady history the benefit of the doubt?
Because when people cry wolf, and then there is no wolf, it actually harms the consumer by lowering everyone's guard. Have people not learned this yet?

Gamers Nexus discovered recently, through their "AMD blacklisting" bit (when some relatively minor mid-lifecycle refresh of a product they didn't get a demo unit, so it turned into some "we are the truthsayers!" bit), that doing the Louis Rossmann routine earns them loads of links and clicks. So they're firmly in the cry wolf territory now, and it makes me more dubious of their claims that the people they are questioning.

This whole space is filled with bullshit now. Saw another video where a big channel talks about why TVs are so cheap now, and they then explain it that it's because they sell your data. In the real world, the selling data bit, ACR, and so on, is absolutely tiny dollars business. TVs are cheap because massive factories are pumping out these almost entirely plastic products in enormous numbers, and they're extremely cheap to make, and the IP has all been long amortized out.

Still doesn’t mean they’re not selling the data?
I agree with you that accusations need to be backed by proofs and the kneejerk reactions on HN are embarrassing to read and unhelpful. Big bad evil corp, every single time. I mean those reactions are all over social media, but I just expected a little bit less knee jerk from HN.

> In the real world, the selling data bit, ACR, and so on, is absolutely tiny dollars business. TVs are cheap because massive factories are pumping out these almost entirely plastic products in enormous numbers, and they're extremely cheap to make, and the IP has all been long amortized out.

Unfortunately that part if your comment is provably false in at least one instance: Vizio. It's a shame, I thought we were on the same page about spreading half truths.

Vizio's numbers are famously public due to its recent sale. We know they lost money on most televisions sold (not all!), and they made it up in ad revenue and content distribution from those TVs. It doesn't prove that LG loses money on its TVs, but it's clearly not as clear cut as you make it out to be.

> Vizio's numbers are famously public due to its recent sale.

Vizio's numbers were public because they went public in 2021 and like every public corporation they have to report numbers. The sale to Walmart actually made their numbers private again because while they're a part of public company still, it's now thoroughly washed in such a mass of numbers it disappears in any quantifiable way.

> It doesn't prove that LG loses money on its TVs, but it's clearly not as clear cut as you make it out to be

How clear cut do you think I made it? You seem to be claiming my comment said something it didn't.

TVs are being subsidized by secondary businesses for some vendors, to some degree, but that isn't why TVs are cheap. If you completely removed that factor, some makers would be slightly more expensive...but not by that much at all.

Like people do a lot of clever positioning to grossly overstate how much they make from this. And it's worth noting that much if not most of the revenue people ascribe to "ads" or privacy invasion on Vizio, actually came from their Connected+ platform. Vizio had a platform, just like Apple does, and just like Apple they took a cut of every subscription signed up for, or piece of media purchased.

I remember back in the day when laptops had a bunch of pre-installed junk and stupid stickers all over them -- at least in the Windows world -- and people would claim this "subsidized" the laptop. That it made it much less expensive. Some people ran the numbers and it was utterly marginal, but they did it because the average person simply didn't care. If they just increased the price the tiny amount and removed that shit the product would be better, but if most people don't care and you can eek out a tiny bit more, they do it.

I agree with you re Gamers Nexus, but honestly I'd rather have Gamers Nexus than not anyways.

> Saw another video where a big channel talks about why TVs are so cheap now, and they then explain it that it's because they sell your data. In the real world, the selling data bit, ACR, and so on

> is absolutely tiny dollars business. TVs are cheap because massive factories are pumping out these almost entirely plastic products in enormous numbers,

Right, and Windows Recall is not technically spying on what you're doing etc. etc.

It seems to me like you're being pedantic but essentially end up seeming like shady corporate practices are fine with you over somewhat inaccurate claims that nonetheless point to a real problem?

Yes, TVs aren't cheap because of (only/primarily) ACR but the points stands that ACR shouldn't be a thing on a TV I fully paid for and nobody but me, who paid for the TV, should 'own the glass'.

They're not denying anything about programs other than ACR. That's telling. They didn't say "your TV doesn't listen" or "your TV doesn't collect"
this is clearly an "anonymization" claim.

What is anonymous: we record all the hashs from all the programs people are watching to identify people watching the same thing.

What is not anonymous: we hash all the content in the world, along with hashing the content people are watching, and reconstruct what they watched.

> So they are claiming that ACR is done entirely through audio processing, and no visual data from the screen itself is used? That...doesn't seem plausible.

It apparently is.

Do you know the Nielsen Ratings? That's exactly how they know what people are watching these days. I've been contacted by them to be one of their subjects. They ship you a device that listens and recognizes based on content. They look for certain "fingerprints" in the audio and match against that - it's not capable of recording our conversations, etc (or so they claimed).

The Shazam app on my wife’s iPhone can identify TV shows and movies very quickly, sometimes nearly instantly. Not sure how it does that.
TV shows are completed and in the can well before air date. It is entirely plausible that the interested party in having the content identifiable by Shazam like services submit whatever needs to be submitted for new content
I have also wondered about the possibility of media emitting some kind of hidden identifier. Can normal speakers emit noise outside of human hearing that could contain a unique id? Would not even need to be a lot of data that could be broadcast.
That's not necessary. If a service has access to the raw audio of a show, it can fingerprint each second of that audio in a way that can be matched in a tiny amount of computation even for a recording in a noisy environment.

That can't recognize what you say. But, it can ID where you are in a specific show out of zillions of hours of shows.

Notably, the caught the TV also recording and transmitting recorded audio and transcripts from the microphone.
Honestly, it doesn’t even need to be outside the range of human hearing.

A quick search for “audio steganography” should answer your question (and be a fun rabbit hole if you find that sort of topic interesting)

Yes, it's possible. Some sports broadcasts do this. The ones I'm familiar with use a high pitched tone on the edge of human hearing but still audible to most people.

Streaming services watermark the video as opposed to the audio as I understand it.

But that's for tracing pirated content back to the originating user account. It's not particularly useful (also entirely unnecessary and overly complicated) if your goal is to ID a piece of content as opposed to an account.

Live broadcasts make it hard for Shazam type apps to ID something from a fingerprint, so they need something else to help.
Signals analysis is pretty refined and not THAT compute intense.
I know a guy who made a Shazam-like phone app that can listen to a few seconds of noisy audio and make a fingerprint that can be used to quickly ID those specific few seconds out of a pre-fingerprinted archive of an enormous amount of audio (zillions of hours of TV). Making the fingerprint requires a tiny amount of very smart code (in C with no dependencies). But, the fingerprint is not useful for understanding audio that's not in the archive.
It's how things were always done. The content from broadcasters has/had audio watermarks...frequencies which humans can't hear.
As far as I know, watermarks never took off because the technical complexity and lack of standardization. Nielsen researched and developed ACR technology but it never required watermarks.

When Nielsen first started collecting data (1950s), they handed out diaries to a group of around 5 000 selected households. Nielsen would then collect these diaries and extrapolate viewing patterns across the entire population.

After that came phone surveys. Next step (1980s) was the "people meter", a small box attached to the TV that could automatically detect which channel was tuned and which household members were in the room.

In the 1990s the set-top box made all of that redundant as the cable and satellite providers could directly see which channel every single box was tuned to at all times.

> watermarks never took off because the technical complexity and lack of standardization

Both audio (sports) and video (netflix et al) watermarks are alive and well. They are used to trace piracy (ie account ID), not for content ID (at least AFAIK).

Regardless of it being how it always was done, such a finger print can easily be injected into LG's advertising ecosystem to infer everything about your demographic and what your interests and income might be and hit you with more specialized ads.

What we watch is not OK to be fed ads, especially if I wasn't using their service to being with and its monitoring the audio from any input to do this.

In this way, smart tvs and smart home devices are effectively hostile devices behind your router at home.

Yes. It’s also horrible that they have microphones in your home listening to your conversations. LG knowing what I’m watching is awful, but it seems even worse for LG to listen in to the conversation I have with my loved ones about it after. I don’t want to be under surveillance in my own home.
Both are unacceptably egregious and done for zero benefit of the customer and a disproportionate and asymmetric benefit for the manufacturer.

I've been trying to learn how to secure LG TVs, and saw that some people do seem to jailbreak them withan open version of webOS.

> I've been trying to learn how to secure LG TVs

It’d be wonderful if we had a grapheneos equivalent for tvs. They’re very capable Android devices. Such a pity “we don’t own the glass”.

The good news is there is no good reason to plug the TV into the internet.
To watch movies from a streaming service?
Use Apple TV for that.
I.e. spend more money to do things the TV can perfectly well do. We should make the spying illegal so we can use the devices we buy to their full potential without being sold to advertisers. "Give money to this other company that may or may not also be collecting data and may also sell you out in the future" is a suboptimal solution.
I don't think we can do anything substantial. So I'm going to just use this "suboptimal" solution.
If you want true, verifiable privacy and control, it's not an Apple TV that you need. Any old laptop or desktop computer can be used to stream content from the Internet using a Web browser or other "apps."
E.g. Netflix doesn't let you to stream 4k video in browser afaik. So no, it's not a good option.
Always, and only use an external device for streaming services, never the software built into the TV.

Apple TV, Android TV or other devices are perfectly capable and better integrate with mobile and other devices in your network.

The tradeoff consumers are sold is trading convenience of in device apps for security.

Smart home devices like TVs, and thermostats should be treated as default hostile and isolated on a guest wireless network instead of your main one.

Also, they didn't claim that.
Is that how they do it lately?

I participated once or twice a good number of years ago, and it was kind of a pain: It involved keeping a paper ledger of what was watched, and when. Correspondence was all handled by regular mail.

(As I recall, they included a small amount of cash ~every time they sent more correspondence and this was a primary motivator to keep going with it.)

> That...doesn't seem plausible.

In what way? Dramatically lower processing and signature complexity. Audio signature matching is trivial and extremely well known. I see absolutely nothing implausible about this, and it seems a robust, viable solution.

> This paper from 2024 investigated both Samsung and LG and found that they both capture screen images for ACR, and send the resulting hash (not the raw content) back to the manufacturer for identification.

That paper found no such thing. That paper actually demonstrated that they have no clue how the ACR happened, they just demonstrated that playing content yielded content IDs. It is more likely they were witnessing audio ACR happening, exactly as LG described.

Get saavy...? More like "will require trust that manufacturers are honest" -- which I won't believe for a miliesecond.
Yeah, I don't know what I was thinking when I wrote that. No one reads the ToS anyway. Just stop buying TVs, now that Sceptre stopped delivering the last models of consumer dumb TVs.
Given all requirements studio have for video DRM, I’d say audio-only fingerprinting is quite plausible.

As far as I can tell from the paper you linked, they never analyzed what was actually captured, only that it was being captured and transmitted. The only citation they give for it being “frames” is a link to LG’s privacy policy that says it captures audio samples.

The key problem is content identification, not how it is done. Seems like they are doing "look over there!" thing.
on-device transcript of audio recording is not audio recording ;)
No, I think they’re saying two separate things:

- ACR uses audio fingerprinting

- ACR does not collect screen recordings

Both can be true if the TV hashes the frames locally and ACR “collects” the hashes.

They're almost certainly being pedantic about what it means to "collect a recording".
Does it matter? Whether they are doing it on device or in the cloud, they are still recording what their customers say and collecting data on it without their consent.

To me, this is really an admission.

How they spy on people isn't the issue.

Spying on people without explicit consent (in a situation where you can say no without penalty) is the issue.

> So they are claiming that ACR is done entirely through audio processing, and no visual data from the screen itself is used? That...doesn't seem plausible.

Wrong. They claim it doesn't record video. Recording means saving permanently - live processing is not recording. ACR is processing the video output live.

Notice what they don't say at all. ACR is just one type of spying. A completely separate feature records what you say from the microphone. They only claimed ACR doesn't do that, which we knew. They did not claim the TV doesn't do that.

This is a carefully crafted PR statement, to avoid saying any lies while making it sound like the accusation was wrong, but it does not actually say the accusation was wrong. We can infer that the likely reason it doesn't say the accusation was wrong is that the accusation is right. Instead, it says several other things, which sound like they are refuting the accusation but are actually refuting other things that nobody said.

Exactly, otherwise LG legal would be threatening the authors to publish an apology or be sued.
If they aren't suing they are guilty as hell. Even if they were only most guilty they would sue; their legal dept knows they have no legs to stand on.
> processing is not recording

Debatable and definitely semantic - at the very least this requires putting the audio into a buffer, so a newly mallocd block of memory. Sure, it’s not a recording in a conventional sense, but it is a copy of data.

This is such a programmer view. No lawyer would think that a graphic equaliser records audio.
You'll be delighted to learn that this exact reasoning had, in fact, been used by the copyright industry against (illegal) movie streaming websites. If I remember correctly, this was in Germany and was, after a relatively short time, no longer accepted by the courts.
Read it more carefully.

They are claiming three things:

1) that the speaker (the electromagnet and cone) is not processing any video data, and that it is not performing any analysis of the audio data.

2) All the data the speaker gets is processed by an ``ACR'' processor.

3) The ACR's audio fingerprinting algorithm does not use video data.

It says nothing about whether the ACR fingerprints or sends other data, or if there is a "VCR" or some other chip that separately processes the video. It definitely doesn't say anything about the processing done on the server side, whether they can sell residential proxy access, etc, etc.

At least my TCL TV has a physical switch to disable the microphone (and has never seen the internet, of course). It complains the switch is off at boot every once in a while. There are no complaints about the network unless I accidentally push one of the eight "Google, spy harder!" buttons on the remote.

[delayed]
From reading other responses, it seems there is an assumption the image itself is fingerprinted. The digital content is encoded, there is essentially a barcode on your TV screen with lines running horizontally that you cannot see with the human eye. The encoding is picked up as the signal, it does not need to see or recognize if that is your favorite actress on the screen.
Tom's response: "Sounds good, please don't take offense at me adding https://github.com/furkan-bayrak/lg-tv-blocklist to the PiHole. Can never be too safe, right?"
[dead]
Yeah, I went with just the Safe settings for now as I am leaving for the week and didn’t want the rest of the house to have to fix something.
The thing which depresses me the most is all these so-called smart TV's are giant Arm computers that run malicious software. Imagine if we could re-flash your TV with Linux or whatever.
> We're going to have to get saavy in pulling apart the distinction between

We probably shouldn't: doing any of this horseshit is a good reason to return a product. We should start doing that en mass until they get the idea.

I can’t speak to how LG does this now but I ran an agency that built Smart TV apps and built one of the first ACR powered apps on LG about 10 years ago. We were working with a company called “Cognitive Networks” which later was bought by Vizio and is now their Inscape product. At that time one use case wasn’t just tracking but actual interactive “sync to broadcast” apps (you can still do this, no one does and I don’t know why)

At that time during testing Cognitive could literally see what we were playing on our TV (not full video but the frames used for fingerprinting)

They don’t use Cognitive anymore for obvious reasons and there are several audio based ACR solutions but they always had issues with sections of video without much audio to work off of so we’re always considered inferior. They are fine for usage data however.

Anyway my $0.02

Well, not that Apple is doing it all their fans will claim it's ok
especially when emebeddings are enough to recover original signal if the model is built for it, which these no doubt are.
Real question here: As I understand, voice (sound) recognition technology mostly uses hidden Markov models, instead of LLM/AI. Do I misunderstand? I think this is how Dragon NaturallySpeaking and Shazam works.

To be clear: I do not agree with any of Samsung's and LG's efforts to record sounds/words from user homes!

ACR is "not enabled by default"? Is this actually true or is it one of those weasley technicalities where the tv ships with it turned off, but once you connect the tv to the internet it turns on?
it turns on when you agree to the 197 page arbitration agreement

source: i made it up

I bet it's inadvertently enabled if you want to watch Netflix within 5 minutes of powering on the TV and rush through its setup
https://youtu.be/6IFVTcM28KA?t=1370

They at least use a pattern where you need to accept terms of use & privacy policy when you download an app. Same screen has option to accept other agreements like ACR. However by default "select all" option is highlighted so people will often click that.

Slightly earlier on video they state that certain ad related things got turned on automatically during software updates.

Technically when you turn the TV on for the first time, ACR is not enabled. Ergo, not enabled by default.

Sure, to use the TV you need to go past the EULA screen. And the button right in front of you, pre-selected - is agree to all terms. And after pressing OK, you now have ACR turned on. But you did that, it wasn't on by default.

Okay I can take my soul sucking corporate hat off now.

Soul sucking is right.

Its looks like the sort of stuff that happens to a tragic fantasy hero after a Faustian deal. Except they would've asked for riches, love or eternal youth, we on the other hand just want our middling-quality tv to work.

Yeah, that's why I only agreed to the minimal terms needed to use the tv, everything else is unchecked
Seems kind of outrageous you had to agree to any terms, even minimal ones. TVs existed for many decades without needing terms.
Yeah you'd think they should allow a "dumb TV mode" where you agree to nothing.
Sure, to use the TV you need to go past the EULA screen.

And that's where the problem is.

TVs should be TVs. Phones should be phones. Cars should be cars. If the manufacturers can't help themselves adding other stuff that is for their own benefit and not the product owner's and some of it so bad that it needs legal weasel words to CTA and competition in the market is insufficient to kill these practices off then it's time for heavy-handed regulation.

Maybe we say you can't sell any product in these categories in our country with any remote connectivity at all except for specifically permitted uses. Maybe the penalty for wilful violation is a warning with a big fine. Maybe the penalty for repeated wilful violation is fines that are an existential threat to the business and personally barring the corporate executives from holding corporate office for the next five years. That kind of thing.

On LG TVs there are about 5 separate agreements you need to accept. You dont need to accept them all to use the tv, but in the initial setup LG puts a handy 'Accept All' button front and center, which agrees to all 5 incrluding the unnecessary ones and turns on the ACR feature. This is the dark pattern most people are pissed about.
You need to accept them to use most any of the apps though which is super sleazy
But again the real question is why a TV should need users to accept any kind of post-sale agreement at all to be used normally (meaning "as reasonably expected and/or explicitly advertised").

Maybe the simplest solution is to pass a consumer protection law that completely nullifies any such post-sale agreements and makes pre-sale agreements enforceable only if they have massive prominence and standardised warnings on the packaging like the ones we require here in England on tobacco products. Then everyone can just use the regular tech security and privacy laws against any company that is spying on its customers or compromising their home networks without consent - which would probably be any company that operated this kind of scheme at all because I doubt many manufacturers would want to print "WARNING: USING THIS PRODUCT DAMAGES THE SECURITY AND PRIVACY OF YOUR HOME AND DEVICES" in six inch high lettering on their boxes.

I'm no lawyer, but afaik so-called "shrink-wrap" licence agreements, where vendor would like people to believe you've agreed by buying & using the product, are null & void legally speaking. Primarily because there's no way to say "no" before unboxing the product.

It's okay to ASK for permissions afterwards, if user can decline. But if such permissions are required to use the device normally, then the proper course of action is decline, if product then fails to do its job, take it back to store as broken & demand money back (no, coupons won't do!). Any seller refusing at that point would have a hard time avoiding legal repercussions should you decide to pursue it.

That is: in countries with reasonable consumer protection laws (like EU).

Why don’t you read LG’s actual statement, which states that it “requires separate explicit user opt-in consent and can be disabled at any time through the TV settings.”
Note that their statement could also be true if they record 99% of the time. We need to start calling companies out for meaningless weasel statements like "We don't record continuously".

The majority of the problem is also simply the ability to record. Putting a remote control listening hardware on a device that runs a plethora of 3rd party apps and with full connection to the internet means that even if LG isn't controlling that mic, someone else will be.

As someone who hasn’t owned a television in decades, why would a TV even need a microphone in the first place?

How many other household devices have a microphone whose primary function is orthogonal to recording audio?

Voice recognition is really useful when searching. It's annoying to type with a TV remote. Also you can just say what you want like "play breaking bad on Netflix" and it'll just do it.

Edit: also the mic in the remote has a function to calibrate the speakers to the room (correcting for the impulse response of the room basically) which can make the audio much better.

Since you're using it for Netflix, etc I assume it has unrestricted Internet access. With that and microphone access, you're giving tacit permission to capture and upload basically whatever it wants, to whoever it wants.

That seems unwise, no matter how helpful the features are.

The reason is annoying to type is that they prefer you say it out loud, not because they can't provide a better ui.
Even with easy typing, it's a single step (say what you want) vs multiple UI operations. This applies to cars too.
(comment deleted)
In any case, "We don't record continuously" is still recording. They should not be recording at all!
Enough with the knee jerk reactions. They have to record in some cases. You don't have to like those features, but plenty of people want those features.

- The television has voice control.

- The television has a manually triggered speech-to-text feature so you don't have to type with tv remote.

(comment deleted)
You'd think if that was all they recorded for, they would be saying it very loudly to end the speculation that weasel-wording leads to.
But they did say that? "LG TVs process voice data only when the voice button on the remote control is pressed and held, or when a wake word such as 'Hi LG' is recognized after the user has activated the Far-Field voice recognition feature."
> Enough with the knee jerk reactions.

No. Stop minimizing their abuse.

You simply do not say something like “we don’t record continuously” if the reality is that you only record when voice control or speech to text is active. Given the entire industry’s track record, the only sane thing to do when confronted with weasel wording is to assume the truth is the worst possible interpretation that isn’t a blatant lie, and even then, sometimes it is just a blatant lie.

Here’s some examples:

- We don’t record continuously -> We record nearly all the time, only stopping to upload the recording.

- We do not sell your data -> But we do “share” it.

- All your data is protected from unauthorized LLM scraping -> But we define all the big tech companies as authorized scraping.

None of that requires recording and has been done with embedded hw with local software for years.
Enough with the corporate shilling. Go back to your manufacturer for a factory reset
Find one person who when asked if you they want the useful feature of LG always recording everything they watch on their TVs and selling that data to third parties without giving anything in return would answer yes.

I get the voice commands but it shouldn't be possible for them to always record everything anyone in the vicinity says without explicitly activating the command (and it should be impossible to hack it, i.e. it should be implemented in hardware not buggy software)

Recording is not the same as listening
> The majority of the problem is also simply the ability to record.

Exactly, and recent announcements like Apple normalising always on recording, even wrapped in “big promises” on privacy, deserve a lot more attention and strong regulation.

Yes. Another example:

> If no wake word is detected, the audio is processed locally, promptly deleted, and is not transmitted to LG servers.

This statement could still be true when:

* The audio transmission is to non-LG servers (e.g., Alphonso).

* The audio isn't transmitted, but the text transcription is.

or a hash like other audio recognition techniques.
Easy solution. Do not connect your TV to the internet.
Agreed. I leave my tv disconnected from the internet, and connect my Apple TV instead… the default UX on most tvs is so much slower and add-riddled than Apple’s
(comment deleted)
> Audio used for wake-word detection is processed locally on the TV and, if no wake word is detected, audio is not converted to text, stored, or transmitted. Voice-recognition results and related technical logs may be generated as part of processing a voice command. These records are associated with specific voice interactions and do not indicate continuous recording of conversations occurring outside an active voice recognition session.

From their statement. This entire thing is contradictory. You cannot both say "not converted to text, stored, or transmitted", while at the same time saying the results may be generated and stored in the form of logs.

We need to hold companies responsible for this shit.

Remember that one time when music CDs from Sony MBG installed a rootkit on your PC that continuously sent whatever MP3s you had on your PC back to them?
I was alive for that but had forgotten about it…wild.
absolutely. i still jerkoff manually
Remember when Amazon deleted books from customers' Kindles (eBook reader), and the book they decided to remotely burn was .. 1984 from Orwell.
Yep and they were fined a paltry 6 million dollars or so. For actively distributing and infecting users with malware. This on annual sales exceeding $3B.

That case sure put Mark Russinovich on everyone’s radars, at least.

Good times.

Remember that time when NSA director James Clapper reassured us they're not the baddies.

"Does the NSA collect any type of data at all on millions or hundreds of millions of Americans?"

"No, sir."

How can we lock down a TV, still use it but trust we aren't being spied on?
> "LG also said that its features like “Automatic Content Recognition (ACR), voice recognition, and interest-based advertising are optional,” and “not enabled by default.”

I am absolutely certain that ACR was enabled on our new TV by default, back some years ago. I am nearly certain their voice recognition, and advertising spying were enabled on our TV by default.

If none of this is truly "enabled by default" then this is a recent development.

I discovered this many years ago and did some deep dives, and unfortunately didn't publish anything about it. Lesson learned.

A few months ago, my Roku TV started displaying these weird popups, saying something like, "Looks like you're watching college basketball. Did you know Roku-TV also has college basketball?" - something like that. Well, for the Roku device, yes, there was a setting I could disable, but (1) Roku pushed this 'feature' and made it default without my knowledge/consent, and (2) the config setting says the popups will stop, but it doesn't mention the data collection; my assumption is they're still collecting that data for their own data analytics purposes.
Pretty much the exact reason I stopped using Roku. I bought a streaming device to stream, but apparently roku decided selling devices wasn't lucrative enough so they started selling ads instead.

I really wish there was a better way to do a media center linux.

Same experience here. Roku has been doing opt-in ACR for a while now. Pulled the ethernet cable out that same day.
It is not enabled by default, but conveniently it's toggled on if you accept the ACR terms of service - including if you select "agree to all" - during TV setup and/or when downloading or updating any apps.
If you live in the United States you should find out who your state senator and representative are and write a letter to them asking them to propose, and support legislation prohibiting spying and increasing consumer privacy protection.

Kentucky passed HB 692 unanimously requiring smart TVs to ask permission if they are going to be spying on us. Ask your state legislature to follow their lead and pass some very popular consumer privacy protection.

I've one question: I've used android phone (realme, which is chinese). And i remember that whenever we used to discuss somethings among our friends, i started used to get ads realated to that on my laptop, phone within atmost a hour.

So, was realme transcribing all conversations and uploading it? Can someone answer?

Wired wrote an article in 2017 [1] on whether it's possible/probable to do that. Technology has evolved a lot since then, so it's a lot more feasible, but the article describes how far metadata alone can go.

For example, let's say an ad network knows your and your friends' location, and knows you've met because you've been close together frequently, or are using the same wifi network. You talk about perfumes, then later one of them looks up perfumes on their phone. Google would usually have access to this much metadata, and will likely serve you perfume ads because of your friend who later looked it up.

This doesn't directly answer your question though. The answer would be - it's possible, but a lot is possible without that.

[1] https://archive.is/OyuUO

People always dismiss this as FUD but it's been happening to me more than ever. I know in many cases it is more likely that firms are acquiring purchase histories and location data but that doesn't explain other incidents.

For example, last week I was complaining to my spouse about shoulder pain and how I was afraid I may need another surgery. YouTube has suddenly starting flooding my feed with videos about "shoulder exercises to avoid surgery." I hadn't searched any of those terms, purchased anything or visited an orthopedic, so I don't know what else could possibly explain it.

It could have been something as simple as lingering on some kind of content related to physical therapy on a social media feed before scrolling past it, or maybe your wife googled it and it got correlated via network?
The alternative explanation is that your spouse searched up something related to your situation.

That’s the next possibility to eliminate.

I agree with the conclusion, but the whole article is obviously AI slop.
Absolutely not a good read. Informative, but it tortures the language, as is usual for slop.
I think, sadly, I'm becoming immune to slop because I (till now) believed I'm good at reading through LLM junk and that read quite normally to me. How annoying. My apologies never the less.
There is a real possibility that either something you saw triggered the conversation and/or that you remember the ad because you spoke about it. It’s enough to linger on an ad for the platform to recognize your interest and serve you more ads like it.
I think the disappointing reality is that those ad networks have enough access to the content of your attention (and therefore what you talk to your friends about) that the technical cost and risk of surreptitious audio monitoring just isn't necessary.
You don't need monitoring for that to work. Just something like "Hey, Google". The device knows a bunch of keywords and when it hears them it's bingo. As long as your laptop and phone are logged into the same local network with the same public IP they'll get the same ads.

And your phone most likely already listens all the time to catch an "Hey, Google" (or something similar).

It's technically possible but very unlikely. Running TTS continuously is a big battery drain and slows down the rest of the phone while you're using it. Google has a live TTS service for hearing impaired which I've run for a while to test it, and even with it practically built into the OS it's sucking up battery like you'd expect it to.

It's more likely that this is all due to external forces. Having your device on the same network, in close enough proximity to detect each other, for instance, combined with one of your friends having Googled the stuff you were talking about.

Or just basic data collection. There's the classic story about how supermarkets know you're pregnant before you do, just based on the groceries you buy (no, not pregnancy tests). Ad networks buy and collect a humongous amount of information about everyone and serve ultra specific targeted ads based on nothing more than pattern matching based on what the rest of humanity is doing.

It's impossible to rule out that the thing did run a 24/7 TTS service, but I think the depressing fact that ad networks don't need to listen to our conversations to know what we're talking about is more probable.

No phone has ever been caught doing that. But TVs and phones have been caught collaborating. What brand is your TV?
I think it's metadata. Whenever you visit a website, there are many things that track you: 1. The website itself is sending your activities to ads platforms, with your hashed email address and phone number if you're signed in. It does not allow ads platform to reach you directly but email address hash is pretty pinpoint. Everyone hash the same way so it's easy for ads platform to track you across the internet. 2. The website loads trackers which monitor your activities across different websites.

That means if you search for something, not even clicking on it, it's possible for ads network to connect your search topic with your spouse.

The leaked advertising pitch videos from them where they say "we own the glass" as a pitch to potential advertising partners, about a tv they sold me just viscerally pissed me off so I'm kind of just done with them even if thats an irrationally strong response. The whole attitude just makes me so mad.
Leaving TVs disconnected from the internet is the only way to ignore this.

Connect your own devices and smarts to it.

A broader issue is that it does any kind of recording, or screen capture, or hashing, ever, even for a millisecond in a way that is not controlled by settings.

A tiny crack in LG tvs can be an attack vector for security and safety.

It’s likely an unadvertised function only for the benefit and leverage of LG and may be buried in signing your life away to use their “smart” tv functions as well.

A brand is a promise of an experience. This brand has broken a promise and it can’t be pretending it didn’t.