// HACKER NEWS — CYBERSECURITY
GamersNexus and LG: Or why rooting your TV is a bad idea
Whenever I get to see companies eat shit over bad security, shady business practices, and both, I’m excited. And GamersNexus is here to deliver the goods about LG and their smart TVs. https://www.youtube.com/watch?v=6IFVTcM28KA
“LG TVs are able to be utilized as eavesdropping listening devices, in part because of the advertising functionality.”
Now that’s a claim! I’m pumped. On screen, we see log information from the TV, highlighted as unformatted JSON, that includes statements such as “My credit card information” and “My Social Security Number is…”. Pausing and looking at the rest of the logs, we can see that they show the response to the search query (“Here are the search results for My credit card information”).
Looking at it, my assumption about the order of operations here is:
So it’s not always recording and transcribing, at least; they did a voice search. You can make a valid argument for storing these logs alongside the search history (Transcribed or otherwise; I will assume the same would happen if you literally typed them in). It’s not ideal to have that available on device, but it's not the worst issue I’ve seen. I continue the video.They then claim that they could also record from the webcam and microphone while the TV appeared to be off, record from the microphone even when the TV had no network access, which someone with remote access to the TV could access, and said the TV “crawled their network” to find “dozens of unrelated devices.”
I’m not sure what they’re getting with that last one yet, but okay, I think I understand the gist. Due to LG's hubris with their ad tech, there are a bunch of potential security vulnerabilities; at this point, I’m interested in the implications they present, although skeptical that what they’re showing is what they claim so far.
It cuts to a discussion of the tech, where they cut between LG talking up their tech and reach. Can’t disagree here; ad tech sucks and should die. They then show a screen where they state that “LG can collect” the following:
Yes, by definition, a networked computer can do those things. It’s a computer. Do they demonstrate that LG is collecting it? Not yet. Are they sending this data up to their servers? Haven’t shown it. They do show a blurred Wireshark screenshot claiming things are happening. So, maybe something is?
The sinking feeling sets in: I’m two minutes in; the video is two hours long.
It starts focusing on network calls from the TV. There are three security experts cited: MrBruh and U-Turn, people who found and published vulnerabilities in other software and who GamersNexus have reported on, and Wendell from Level1Techs. I don’t know much about the former outside of watching GamersNexus, but on the outset they seem fine, and I do watch and subscribe to Level1Techs too, so I’m aware of him.