Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
65% Positive
Analyzed from 14738 words in the discussion.
Trending Topics
#audio#tvs#don#acr#data#device#video#recording#voice#more
Discussion Sentiment
Analyzed from 14738 words in the discussion.
Trending Topics
Discussion (460 Comments)Read Original on HackerNews
> ACR uses audio fingerprinting technology using the TV’s internal audio processor (not a speaker) to identify content and does not collect screenshots, screen recordings, video recordings, voice recordings, or other audio recordings from the TV.
So they are claiming that ACR is done entirely through audio processing, and no visual data from the screen itself is used? That...doesn't seem plausible.
This paper from 2024 investigated both Samsung and LG and found that they both capture screen images for ACR, and send the resulting hash (not the raw content) back to the manufacturer for identification.
https://arxiv.org/html/2409.06203v1
We're going to have to get saavy in pulling apart the distinction between "I look at everything and then send a nice summary back to my manufacturer" and "I send everything back to my manufacturer". As AI gets cheaper and more efficient, it'll be baked into everything, and will distill signal at the edge and send the good bits back to central command. I fear the legalese in the ToS will obscure this new way of "not collecting" user information.
It's probably easier to do and every bit as accurate as just using a screenshot.
And it's still exactly what I don't want them doing. There's literally zero reason for LG to be building an advertising profile on me because I was foolish enough to buy one of their TVs. This isn't something that makes their products better, it's spying.
Here's how it's been done in the past
https://www.cameronmacleod.com/blog/how-does-shazam-work
Audio is a bit easier to turn into a fingerprint for identification vs video. Video has a lot of smaller subtle changes that happen from things like compression which make it a lot harder to identify. It's why youtube still hasn't figured out piracy, but they'll knock you immediately if you play 5 seconds of copyrighted music.
When I buy something from the store, my relationship is between me and the store, for the 30 seconds it takes for me to pay for it. I don't want an ongoing relationship with the device manufacturer. I don't want to be tethered in any way to the manufacturer. I don't want to have an account with the manufacturer. I don't want the device sending anything to the manufacturer, advertising related, telemetry, or even a single bit "user has used your product." Do you get it, manufacturers?? I don't want any kind of relationship with you! I want to purchase my product and use it by myself not with you.
I think it depends on the device. If I buy an iPhone, I have the expectation of installing apps on it after purchase, and that necessarily involves a relationship with the app store provider (ie. Apple), not the store I bought the phone from.
With a TV, I suppose it depends on whether I want to install media apps like Prime Video or Netflix on it. I understand that there will be people who don't want that, in which case I agree with you. But others want to be able to run this stuff somehow, whether it's directly on the TV or via some HDMI device like a Chromecast or a Fire Stick. At that point, they _do_ want a relationship with some hardware manufacturer so that the third party app can be delivered to run on the hardware.
Truly though, smart-home stuff runs the whole gamut of privacy and device manufacturer relationships. eg: I have used three different smart/room AC units:
- one requires its own cloud-enabled app for any remote connectivity, no HomeKit integration - one integrates with HomeKit but then leaves an upgrade hint that can only be done through an app with a login - one integrates with HomeKit and pretty much just works
HomeKit then allows me to remotely control via HomePod/AppleTV acting as a router ... of course this is just a different cloud connectivity but with on-premises devices controlling other on-premises devices.
For each manufacturer of smart devices, there is potentially a separate cloud where data is being funneled through. Some devices support multiple upstreams.
I get that Matter should be a way to fix it but the reality feels more like https://xkcd.com/927/
Part of me just wants dumb devices back. Get rid of buttons on a microwave (just give me a knob for time and maybe another knob for power setting.) Remove touchscreens from cars (mine glares at me with certain sun-angles.) Bring back the desktop/computer hutch and phones that don't live in your pocket. However, having the ability to start cooling my bedroom 45 minutes before I arrive home is ... pretty compelling too.
I feel like the world is bossed by people who read (well, ok listened to a 5 minute summary on a grindlife podcast at 1.5x speed) about the Trojan Horse and thought they smelled a business opporunity.
the whole DMCA/Takedown process is another shenanigan ripe for abuse. Not real copyright enforcement.
Unless the piracy is silent, surely audio fingerprinting would catch it?
It's going to be so easy to determine who you voted for, given a record of every TV show and news programme you've watched, to 90% accuracy. Or to determine if you'd be a "corporate culture fit" when you're next looking for a job. Or an apartment. Or to find whether anything matching the hash of some trade secret documents was displayed on your TV (or ever connected to it [1]) - the "advertising" firm will be forced to hand over documents on you through lawsuit discovery and the wonderful 3rd party doctrine.
Have you been watching media associated with "woke subversion"? "Islamic extremism"? "Far-right hate"? "Incitement to subversion of state power" [2]?
They're not building an advertising profile. They're building a profile. Ads are just the most common known use-case at the moment. But the profile will remain long after ads become the least of your concerns. Consider how such a profile would have been used during the cultural revolution.
If the government required you to submit a record of every book you read or own, people would rightly freak out. How is this any different?
[1] LG Smart TVs log USB filenames and viewing info to LG servers - https://news.ycombinator.com/item?id=6759426
[2] Hong Kong's Tiananmen activists sentenced to up to seven years in prison - https://www.bbc.com/news/articles/cvgyvk2djk4o
And there's of course also Sinclair's law, so even people who should know better might be either willingly ignorant or just not care if it means that they can maintain their quality of life, moral bankruptcy be damned. Similar arguments can be raised for example with the anthropogenic climate catastrophe or other abhorrent phenomena where there's a big chasm in the knowledge between laymen vs experts.
It is exceedingly difficult to convince someone that something is a problem unless said problem is staring the person in the face.
Audio is much easier to fingerprint and match against content.
Eventually, a digital signal needs to be converted into pixels on a screen. Once that happens, it's trivial to also pipe those pixels into a screenshot.
It's the reason DRM for digital media is pretty dumb IMO. The most sophisticated DRM still has to be decoded at some point for the end user to enjoy it. It can always be broken with a camcorder (though quality suffers). However, there exists devices which decode the HDMI signal so doing a pure digital signals.
Wrong. They claim it doesn't record video. Recording means saving permanently - live processing is not recording. ACR is processing the video output live.
Notice what they don't say at all. ACR is just one type of spying. A completely separate feature records what you say from the microphone. They only claimed ACR doesn't do that, which we knew. They did not claim the TV doesn't do that.
This is a carefully crafted PR statement, to avoid saying any lies while making it sound like the accusation was wrong, but it does not actually say the accusation was wrong. We can infer that the likely reason it doesn't say the accusation was wrong is that the accusation is right. Instead, it says several other things, which sound like they are refuting the accusation but are actually refuting other things that nobody said.
They are claiming three things:
1) that the speaker (the electromagnet and cone) is not processing any video data, and that it is not performing any analysis of the audio data.
2) All the data the speaker gets is processed by an ``ACR'' processor.
3) The ACR's audio fingerprinting algorithm does not use video data.
It says nothing about whether the ACR fingerprints or sends other data, or if there is a "VCR" or some other chip that separately processes the video. It definitely doesn't say anything about the processing done on the server side, whether they can sell residential proxy access, etc, etc.
At least my TCL TV has a physical switch to disable the microphone (and has never seen the internet, of course). It complains the switch is off at boot every once in a while. There are no complaints about the network unless I accidentally push one of the eight "Google, spy harder!" buttons on the remote.
Debatable and definitely semantic - at the very least this requires putting the audio into a buffer, so a newly mallocd block of memory. Sure, it’s not a recording in a conventional sense, but it is a copy of data.
And specifically, they are not confirming or denying that video fingerprinting are done.
What I think is likely is, as the paper states, that they fingerprint both audio and video. Upload both to their servers. But they end up using only the audio fingerprint for ACR. In this situation, neither LG's statement, nor the paper's statement, nor the GamerNexus folks's claims are incompatible with each other.
It even makes sense from a technical standpoint: it is far easier to uniquely identify content by audio than by video, as a fingerprint of a few milliseconds of audio is pretty darn ideal, compared to fingerprinting even a single video frame which has hundreds of ways it could be compressed depending on codecs, bitrate, resolution, etc.
It apparently is.
Do you know the Nielsen Ratings? That's exactly how they know what people are watching these days. I've been contacted by them to be one of their subjects. They ship you a device that listens and recognizes based on content. They look for certain "fingerprints" in the audio and match against that - it's not capable of recording our conversations, etc (or so they claimed).
I participated once or twice a good number of years ago, and it was kind of a pain: It involved keeping a paper ledger of what was watched, and when. Correspondence was all handled by regular mail.
(As I recall, they included a small amount of cash ~every time they sent more correspondence and this was a primary motivator to keep going with it.)
If you explained how the box was hooked up, it would be easier to judge whether there was a chance you were correct.
As it is, your description isn’t even clear whether or not the box contains a microphone.
It's been done for at least good 15 years.
(your car infotainment also likely has nielsen tech in it most likely, as they bought arbitron and gracenote)
When Nielsen first started collecting data (1950s), they handed out diaries to a group of around 5 000 selected households. Nielsen would then collect these diaries and extrapolate viewing patterns across the entire population.
After that came phone surveys. Next step (1980s) was the "people meter", a small box attached to the TV that could automatically detect which channel was tuned and which household members were in the room.
In the 1990s the set-top box made all of that redundant as the cable and satellite providers could directly see which channel every single box was tuned to at all times.
What we watch is not OK to be fed ads, especially if I wasn't using their service to being with and its monitoring the audio from any input to do this.
In this way, smart tvs and smart home devices are effectively hostile devices behind your router at home.
At that time during testing Cognitive could literally see what we were playing on our TV (not full video but the frames used for fingerprinting)
They don’t use Cognitive anymore for obvious reasons and there are several audio based ACR solutions but they always had issues with sections of video without much audio to work off of so we’re always considered inferior. They are fine for usage data however.
Anyway my $0.02
To me, this is really an admission.
- ACR uses audio fingerprinting
- ACR does not collect screen recordings
Both can be true if the TV hashes the frames locally and ACR “collects” the hashes.
To be clear: I do not agree with any of Samsung's and LG's efforts to record sounds/words from user homes!
https://www.reddit.com/r/LGOLED/s/x8iBNCPya5
In what way? Dramatically lower processing and signature complexity. Audio signature matching is trivial and extremely well known. I see absolutely nothing implausible about this, and it seems a robust, viable solution.
> This paper from 2024 investigated both Samsung and LG and found that they both capture screen images for ACR, and send the resulting hash (not the raw content) back to the manufacturer for identification.
That paper found no such thing. That paper actually demonstrated that they have no clue how the ACR happened, they just demonstrated that playing content yielded content IDs. It is more likely they were witnessing audio ACR happening, exactly as LG described.
I could probably come up with a use for that, but it's about as likely as coming up with a plan for one of the Raspberry Pi Zero Ws that are sitting in the drawer.
Spying on people without explicit consent (in a situation where you can say no without penalty) is the issue.
As per HN thread last week
so they aren't even denying listening in on everything?
They still claim to get your media's audio, but deny using the microphones.
[0] https://www.lg.com/us/terms
What is anonymous: we record all the hashs from all the programs people are watching to identify people watching the same thing.
What is not anonymous: we hash all the content in the world, along with hashing the content people are watching, and reconstruct what they watched.
We probably shouldn't: doing any of this horseshit is a good reason to return a product. We should start doing that en mass until they get the idea.
The majority of the problem is also simply the ability to record. Putting a remote control listening hardware on a device that runs a plethora of 3rd party apps and with full connection to the internet means that even if LG isn't controlling that mic, someone else will be.
> If no wake word is detected, the audio is processed locally, promptly deleted, and is not transmitted to LG servers.
This statement could still be true when:
* The audio transmission is to non-LG servers (e.g., Alphonso).
* The audio isn't transmitted, but the text transcription is.
- The television has voice control.
- The television has a manually triggered speech-to-text feature so you don't have to type with tv remote.
Here’s some examples:
- We don’t record continuously -> We record nearly all the time, only stopping to upload the recording.
- We do not sell your data -> But we do “share” it.
- All your data is protected from unauthorized LLM scraping -> But we define all the big tech companies as authorized scraping.
I get the voice commands but it shouldn't be possible for them to always record everything anyone in the vicinity says without explicitly activating the command (and it should be impossible to hack it, i.e. it should be implemented in hardware not buggy software)
No. Stop minimizing their abuse.
How many other household devices have a microphone whose primary function is orthogonal to recording audio?
Microphones in tvs are a useful accessibility feature when they enable voice commands for the user, and allow them to be used as voice assistants.
They also enable tvs with a camera and microphone to be used as video calling or audio calling interfaces. Used well we get star Trek view screens, used poorly we get little brother monitoring.
For those interested, it turns the tv into an interactive terminal for voice and camera powered video games, which are becoming more popular.
Unfortunately advertising and tracking incentives drive the abuse cases to the top and will crush the positive use cases :(
I'm still not purchasing a television. The last thing I need is more screen time in my life.
Fully solve it by disconnecting network cable/Wi-Fi so there's no internet.
For me a TV set only receives FTA signals and has connectors for local media/AV input. It ceases to be a TV set when it starts doing what my PCs and laptops do.
(Anonymity is the reason why FTA broadcasting is still so very important, by design it's only one-way — broadcaster to listener/viewer. Unfortunately smart TVs and the internet subvert anonymity by design.)
Made nearly moot by the presence of microphones in most (all?) modern remotes.
I say nearly moot because its worth noting the ability to operate a physical remote may itself be prohibitive to some.
So in effect, there are a multitude microphones in a modern LG environment.
Edit: also the mic in the remote has a function to calibrate the speakers to the room (correcting for the impulse response of the room basically) which can make the audio much better.
That seems unwise, no matter how helpful the features are.
IIRC I saw already Bruce Schneider's blog some team proof of concept where they listened using laptop speakers what was spoken in that room. Audio quality wasn't perfect, but it making sense what was spoken was good enough.
The warning has been there for 80 years and still most are unaware. When Vespasian built the Colosseum it was to help rule over the unruly. Netflix and ilk are its modern incarnation.
Some "smart" TVs could do skype in the past, I'm not sure if they needed external headsets of worked with builtin mikes.
Exactly, and recent announcements like Apple normalising always on recording, even wrapped in “big promises” on privacy, deserve a lot more attention and strong regulation.
LG TVs caught spying even when offline or on standby - https://news.ycombinator.com/item?id=49612329 - Sept 2026 (359 comments)
GamersNexus and LG: Or why rooting your TV is a bad idea - https://news.ycombinator.com/item?id=49605424 - Sept 2026 (133 comments)
A Screensaver for LG's Spying Smart TVs - https://news.ycombinator.com/item?id=49605356 - Sept 2026 (13 comments)
LG TVs aren't the only ones spying on you [video] - https://news.ycombinator.com/item?id=49575176 - Sept 2026 (18 comments)
LG Smart TVs logging USB filenames and viewing info to LG servers https://doctorbeet.blogspot.com/2013/11/lg-smart-tvs-logging...
HackerNews discussion (178 comments): https://news.ycombinator.com/item?id=6759426
The vast majority of consumers are not going to spend another $100-300 on a media player device like an Apple TV, Roku, or nVidia shield. They will use the built in app functionality.
And even those who don't - a very surprising to me number people use the "free channels" most TVs ship with. It's like the streaming version of broadcast OTA I guess for a certain consumer segment.
Yup. How does that make you feel? Because for me, it was the moment when the border to not only blatantly, but also actively evil was passed.
They may be optional features but I’m pretty sure when I set up my tv and got to the screen where you are required to agree to the various terms and privacy legalese the “happy path” was to hit the “accept all” button vs use the remote to navigate into each one, read, and only activate the few required to use the tv. I would not call this dark pattern “optional” by default.
The lawyers conclusion is that a non-lawyer basically has no chance of correctly interpreting the contract and the TV auto-standby almost made it physically impossible for the staff member to even read it.
The „happy path“ is the only path, for all practical purposes.
This sort of malicious compliance of using T&C to enable bad behaviour by corporations needs to be fixed with laws.
Reminds me of cookie banners, the dark pattern where they've decided to be deliberately verbose and annoying in order to get people to take the easy path and agree to let them continue doing their bad behaviour.
Maybe Sony is better, based on my memory, but I doubt it now without evidence.
Their statements don’t align with the reality I’ve experienced as a customer. My TV is not connected to the network, because the setup process left me with 0 trust that LG wouldn’t be collecting information regardless of my settings, or that I didn’t miss something. There was also the risk that they’d add a new “feature” with an update which would I’d be automatically opted in to.
Until they start selling truly dumb TVs, I’m not going to trust anything and their statements fall flat.
Opt-in used to mean that it was disabled until you explicitly click somewhere to enable it.
Opt-in: take action to have the feature.
Opt-out: take action to not have the feature.
> ACR is an optional feature that is turned off by default. To enable ACR, a user must accept LG’s Viewing Information Agreement, which describes how ACR works.
Which I take to mean that when you agree to the terms, it enables the feature.
Anyway, last year my phone died and I bought a new one made by Samsung. I had to opt out of collection like 4 or 5 times with confusing buttons, and there is a lot of crapware installed by default, and then the phone offered to install two additional apps. I almost sure I said no, but one of them got installed anyway.
LG adopted the "Maybe Later" dark pattern for opt-in to ACR, at least in some markets. Though I guess you never know for sure with A/B testing.
> LG went on to say that beyond the aforementioned instances, "the TVs do not collect or record ambient conversations."
LG is contradicting themselves here. In order to detect a wake word then they must be collecting or recording ambient conversations.
I think the main questions are:
1. Is it fully supported to use LG TVs disconnected from the internet.
2. Are wake word voice controls and ACR truly opt-in. They claim it is in the statement but (as others have mentioned) I remain skeptical what definition of “opt-in” they are using.
Update: some of this is becoming a semantic discussion on the definitions of “recording” and “collecting”, but to circumvent this I would say:
If a device can detect words in my ambient conversations and depending on what it detects (accurate or not) it can send that audio to the cloud, I would describe that device as “collecting or recording ambient conversations”
I don't know how LG TVs do it, but e.g. many smartphones use a dedicated ASIC/audio processing chip that does not really record anything, but specifically listens for the wake word and discards all other audio to save power/battery life. I think this distinction is relevant, because there is a huge privacy difference between streaming a live audio stream to the cloud to detect a wake word and a specialized audio processor that has a small buffer only for detecting the wake word, where the audio does not leave that processor.
Theoretically, you could call that few-second buffer recording, but I don't think that would be collecting/recording ambient conversations to most people, since it's ephemeral and does not leave your device.
The question, of course, is what happens in LG TVs.
No, it's arguably accurate because "record" implies it's being persisted. Otherwise something as simple as a sound meter (which needs a microphone to operate) is "recording".
There's a risk here that we will talk-past one another while using different meanings of the same words, so let me offer a scenario:
AcmeTV has an isolated component which taps microphone input, records to a 5-second ring buffer, and on "Wakey-Wakey" triggers an alert flag. Assume it works perfectly accurately.
Would you accuse AcmeTV of "recording or collecting ambient conversations" on the basis of that component constantly reading microphone data?
Personally I wouldn't, because it's not the same kind of "recording" we consumers are concerned about.
This combines with two other dangers, one of unintended recordings when the wake word is triggered unintentionally, and one of intended recordings by third parties based on various other wake/watch words. They already have it in the T&C that they will share this data with law enforcement, so it's not that far fetched that these TVs and other appliances will spy on people in the home far more effectively than even the East German Stasi could have ever imagined.
Well this is a silly assumption. Wake word false positives happen all the time. (“No Siri, I wasn’t talking to you…”)
The point is that ethical implementations do exist, and them working does not rely on anything close to perfection--so nitpicking that word isn't helpful.
Nearby, another AcmeTV or business partner device picks up the sound and sends it to AcmeHQ.
The former device "never transmits your viewing behavior to Acme". The latter device "never records your viewing behavior".
Or, in a heavily-paraphrased nutshell:
Then, when the system was more awake, it would attempt to figure out whether the wakeword was real or not (e.g. sometimes certain words and word pairs have a very similar sonic signature to 'Alexa'), and if it felt confident enough then it would begin streaming audio to the back end for significantly improved voice recognition.
Since Amazon took (and as far as I know still takes) voice privacy incredibly seriously, voice recordings and data were treated as essentially radioactive waste, deleted as soon as legally possible, and secured against even internal Alexa developer access.
I personally don't have the same level of confidence in security with LG, who seem to think they don't have as much to lose as far as customer trust goes and might as well exploit the heck out of the systems they have. I suspect that problem, which Amazon has so far pretty successfully avoided for the most part, is self-correcting over time.
lol no https://apnews.com/article/amazon-privacy-echo-7fb3c19fa7f66...
> When I worked for Alexa
Look I know it's easy to believe these things when your paycheck depends upon it, god knows I've convinced myself of a convenient fact or two when it was necessary for me to get through the day. But afterwards, without a financial interest, you owe it to yourself to go back and think about it again.
Is this what is done with the "Audio was not intended for this device" entries in the Review Alexa History section of the Alexa app?
Fuck that. Dystopian shit with people yelling brand names in their homes.
Edit: I forgot people already be yelling Alexa/Siri/Google. I can't imagine a future when you have to yell to each brand in your home. "Hey Sony, turn on the PS7. LG what's on the fridge? Samsung, start the cycle in the dishwasher".
[0] https://weowntheglass.com
My own self-made guillotine blade is emblazzened with the phrase "why support convicted rapists?"
Definitely a thought-provoker. Nice website.
With out the user the content would have never been created. Users are the content creates and now the push to remove their owners ship of their actions and move it to the wealthy.
Greed begets more greed.
New iPhones are expensive, more than $1000. Yet most people who get them finance it through their cellular carrier, usually 2 year plans, so it's just $30-$50 tacked on to the monthly cellphone bill. So ... no one cares unless it's going to double their bill.
Let's say the RAMopocalypse and other AI-driven chip pressues drives everything up even more; let's say now-cheap TVs are now $2000 or $3000. No biggie. Your cellphone company can offer you an eSIM-locked TV with bundled network and services, on a 5 year plan with free lifetime service and replacement, adding just $30-$40 to your bill for 5 years. Maybe it will include something like Family Tracker Life360 Intercom as a value-add - talk to your children to/from the TV to/from any phone on your plan, anywhere, anytime. Safety, etc.
Same thing with your laptop, home IoT/security devices, etc.
If ATSC 3.0 dies and gives way to 5g Broadcast, it'll be another enabler for something like this.
That's when the real lock-in will happen.
Cars already do, and the solution is well-known: find the bug, and squash it. Yes, your car will still work, and you cannot be denied warranty because of this. The cellular modem is more or less accessible depending on the make and model.
https://youtu.be/ToP9xfLDSME
"Does the NSA collect any type of data at all on millions or hundreds of millions of Americans?"
"No, sir."
That case sure put Mark Russinovich on everyone’s radars, at least.
Good times.
As the saying goes, this is what radicalized me. If any one of us did anything close to this we would be treated like Aaron Swartz and given a 35+ year prison sentence.
But in the Sony case the DOJ didn't even threaten criminal charges.
Sure, to use the TV you need to go past the EULA screen. And the button right in front of you, pre-selected - is agree to all terms. And after pressing OK, you now have ACR turned on. But you did that, it wasn't on by default.
Okay I can take my soul sucking corporate hat off now.
Its looks like the sort of stuff that happens to a tragic fantasy hero after a Faustian deal. Except they would've asked for riches, love or eternal youth, we on the other hand just want our middling-quality tv to work.
And that's where the problem is.
TVs should be TVs. Phones should be phones. Cars should be cars. If the manufacturers can't help themselves adding other stuff that is for their own benefit and not the product owner's and some of it so bad that it needs legal weasel words to CTA and competition in the market is insufficient to kill these practices off then it's time for heavy-handed regulation.
Maybe we say you can't sell any product in these categories in our country with any remote connectivity at all except for specifically permitted uses. Maybe the penalty for wilful violation is a warning with a big fine. Maybe the penalty for repeated wilful violation is fines that are an existential threat to the business and personally barring the corporate executives from holding corporate office for the next five years. That kind of thing.
They at least use a pattern where you need to accept terms of use & privacy policy when you download an app. Same screen has option to accept other agreements like ACR. However by default "select all" option is highlighted so people will often click that.
Slightly earlier on video they state that certain ad related things got turned on automatically during software updates.
source: i made it up
2. We might log something but it is local only and these specific features
3. Okay maybe we'll log a little but the TOS gives us permission
4. Yes we log and record everything and this is why it's a good thing; you ought to pay us actually
Kentucky passed HB 692 unanimously requiring smart TVs to ask permission if they are going to be spying on us. Ask your state legislature to follow their lead and pass some very popular consumer privacy protection.
Feels like in the age of Claude Code the answer should be to strip out the evil side of the Faustian bargain of adtech-subsidized smart devices.
Hackers should not spend mental energy pulling apart the language of Satan’s PR department. That energy is better spent exorcizing the demons out of their devices.
Also they provided a statement earlier to Gizmodo: https://news.ycombinator.com/item?id=49628328
I am absolutely certain that ACR was enabled on our new TV by default, back some years ago. I am nearly certain their voice recognition, and advertising spying were enabled on our TV by default.
If none of this is truly "enabled by default" then this is a recent development.
I discovered this many years ago and did some deep dives, and unfortunately didn't publish anything about it. Lesson learned.
I really wish there was a better way to do a media center linux.
As others have pointed out, you’re presented this at the same time as normal ToS. So it’s very confusing to even me what to opt in to use basic TV functionality.
It absolutely feels like a dark pattern.
1 - https://www.texasattorneygeneral.gov/news/releases/attorney-...
The definition of “process” is really important and is missing. LG could process all transcripts on their servers too and stay within a very wonky definition of “process” on the TV that excludes transcription and transmission.
So, was realme transcribing all conversations and uploading it? Can someone answer?
For example, let's say an ad network knows your and your friends' location, and knows you've met because you've been close together frequently, or are using the same wifi network. You talk about perfumes, then later one of them looks up perfumes on their phone. Google would usually have access to this much metadata, and will likely serve you perfume ads because of your friend who later looked it up.
This doesn't directly answer your question though. The answer would be - it's possible, but a lot is possible without that.
[1] https://archive.is/OyuUO
That means if you search for something, not even clicking on it, it's possible for ads network to connect your search topic with your spouse.
It's more likely that this is all due to external forces. Having your device on the same network, in close enough proximity to detect each other, for instance, combined with one of your friends having Googled the stuff you were talking about.
Or just basic data collection. There's the classic story about how supermarkets know you're pregnant before you do, just based on the groceries you buy (no, not pregnancy tests). Ad networks buy and collect a humongous amount of information about everyone and serve ultra specific targeted ads based on nothing more than pattern matching based on what the rest of humanity is doing.
It's impossible to rule out that the thing did run a 24/7 TTS service, but I think the depressing fact that ad networks don't need to listen to our conversations to know what we're talking about is more probable.
And your phone most likely already listens all the time to catch an "Hey, Google" (or something similar).
For example, last week I was complaining to my spouse about shoulder pain and how I was afraid I may need another surgery. YouTube has suddenly starting flooding my feed with videos about "shoulder exercises to avoid surgery." I hadn't searched any of those terms, purchased anything or visited an orthopedic, so I don't know what else could possibly explain it.
That’s the next possibility to eliminate.
I am positive I get ads based on the interests of other people the wifi where I live.
Our approach is guided by four principles:
Transparency – Helping users understand how smart TV features work and how related data may be used.
User Choice – Giving users meaningful control over optional features and services.
Informed Consent – Supporting informed decisions through clear and manageable consent choices.
Continuous Improvement – Continuously improving privacy controls, transparency, and security protections.
--------------------
Transparency:
This document isn't terribly easy to understand by the standards of traditional TV's. You have to pay close attention to figure out what is and isn't going on, and when. It also should have been taped to the front of every LG TV when it comes out of the box.
User Choice:
There is extensive explanation of how what LG TV's are doing isn't nefarious, but the fact remains that there's no switch to turn it off. Why not just put a simple hardware on/off switch on these TV"s to turn off all connectivity? Maybe some users want dumb TV's, or maybe they just don't want to worry about all of this.
Informed Consent:
Buyers apparently consented to this at the store. Now you're finally informing them. That's now how informed consent works.
Continuous Improvement:
I'll believe LG and other Smart TV manufacturers are serious about this when they add a hardware wifi on/off switch, and not a moment before.
OLED productions costs have fallen, and the yields have gotten better — displays of all kinds have gotten cheaper, not just TVs; OLEDs have started showing up in products they haven’t before for cost reasons, etc.
The manufacturers make some profit on the data they harvest, sure; but the biggest BOM costs of TVs have definitely also dropped sharply.
Companies like Vizio make vastly more on the ads and data than they do on the tvs.
Some quarters they even take a loss. They took a $7m bath on hardware while booking about $120m on ads and data.
We’re never getting good tv’s back. It’s only going to get worse. Now they’re starting in on monitors.
The only lifeline would be consumer protection, which obviously won’t happen in the US.
When they spend 400 on a tv and sell it for 410 and sell the data for 40 it doesn’t mean the data makes 4 times as much as the tv. The cost of gathering that data is still 400, they have nothing to sell without spending 409 in the hardware.
They have good accountants isn’t it?
Unless this stuff is made literally illegal they will keep doing it, because it's far more profitable than the alternatives. This is precisely why ideas like paying for a privacy respecting option on Facebook could never work.
If their claim that ACR is "opt-in" is correct it does give them some slack.
And just because everybody else does it too don't make it right.
It's presented as a series of checkboxes when you're using their native WebOS. As if to use Netflix you have to agree to ToS. One of the checkboxes says "ACR" without defining what that is.
The default is "Select All" and submit. There's no "Select Minimal" or somesuch.
"Do not continuously record or transmit"
Soooo....
Kind of like so many ink jet printers where the manufacturers will sell you the printer at or below cost with the expectation of making it up with overpriced ink cartridges.
GamersNexus just released a brand new followup to LG's response and it's damning: https://www.youtube.com/watch?v=ToP9xfLDSME
A TV that's plugged into power and is on your LAN is way too opaque about what it's doing when, and it has access to too many ways of sensing what you are doing.
So the TV gets advertised as "$$$, but basically $$ if you sign up to be surveilled and get a $/month check back." If the company sets $/month too low--or is too creepy about what they collect--people just won't opt-in.
But what happens if they promise big pay-backs but routinely cancel from their side? That's a problem, but at least it's a kind the market [0] can handle when it comes to reputation and bad reviews.
[0] "Markets are good, use them." -- "OK, fine, you must price this on a market." -- "NOT LIKE THAT!"
Well, such thing has kinda appeared for mobile phone contracts. You can save and entire buck, if you agree for your data to be used for marketing purposes. Except, after accepting the deal, you still pay exactly the same monthly amount, as before they introduced that option.
If ACR is turned on when I install an app, and click 'next', 'next', 'open' then that is not an OPT-INT feature.
If I have to perform an action to not have ACR during normal use of the TV then that is OPT-OUT in my opinion.
Instead, I connect a Google TV Streamer, as I'm in the Google ecosystem. For my friends in the Apple ecosystem, I tell them to do the same with an Apple TV box.
Burden of proof is on LG, not on us and instead of they play dishonest games!
So, it is double-confirmed dishonesty and they should not be trusted further on EVER!
I might add that even though I know better, I have fallen for some smart led lamps etc. I change them with regular bulbs as they break.
They noted the discovery traffic with Wireshark, and commented on LG boasting about how many connected devices their networks can see.
This remains to be a larger issue than the clear fact LG TVs can easily be used as remote spy devices, even when offline, by wirelessly remote connected agents.
And content recommendations, services and advertisements are exactly what most customers don't want.
From their statement. This entire thing is contradictory. You cannot both say "not converted to text, stored, or transmitted", while at the same time saying the results may be generated and stored in the form of logs.
We need to hold companies responsible for this shit.
Disconnecting “smart tv” from internet to use Apple TV is possible and might work, but you will get nagged to reconnect all the time. And TV mfr will eventually try to find workarounds - purchase access to wireless connections from large-footprint connectivity providers (Xfinity WIFI, 4g/5g networks, etc) or create a p2p network among their own connected devices. I doubt they do it right now as it’s less profitable to focus on niche audience, but eventually it might become profitable enough.
LG are amongst equals here. I've seen devices (TVs/cameras) do ping sweeps and then port scans.
I have two VLANs at home: THINGS for IoT and SEWER for things that look really dodgy.
I drive a (Seic) MG4 EV. I use the Home Assistant integration for that and put up with the rest. To be fair I live in the UK and we are quite efficiently ... observed.
This would be a nice public service for gamers nexus that happened to buy a lot of these devices. :P
I can say from experience in several devices (but not an LG TV) that removing dedicated bluetooth chipsets so far has left devices functional. ... but some things implement their bluetooth as part of the ESP32 that is the whole kit and kaboodle, so you can't remove it.
As to why someone would remove these components -- in addition to the explicit spying LG is doing, there are companies dragnet collecting BTLE device identifiers <> gps collecting, including collecting them via phone apps. This means that if you have any BTLE devices that are frequently with you or otherwise connected to your identity it may be possible for a threat actor to determine your location(s) from largely unregulated commercial databases.
I don't use BTLE at all, so this 'functionality' is a pure risk to me.
Trust broken, words out, and their statement doesn’t really do anything to mending that.
I still have an 1080p TV because I can't be arsed to do the research on what 4k TV won't spy on me.
It helps that most "content" isn't worth 4k anyway.
from: https://web.archive.org/web/20201201175708/http://blog.ptsec...
Highly efficient" is 25mW at 33MHz. According to the Wikipedia page, it can run even when the PC is off but plugged in or connected to battery. an ARM Cortex M0-4 will use even less power in idle. All it needs is a tiny capacitor and bootrom and a secret flash storage to record audio and upload it once internet becomes available
"The Intel Management Engine always runs as long as the motherboard is receiving power, even when the computer is turned off. This issue can be mitigated with the deployment of a hardware device which is able to disconnect all connections to mains power as well as all internal forms of energy storage. The Electronic Frontier Foundation and some security researchers have voiced concern that the Management Engine is a backdoor.
Intel's main competitor, AMD, has incorporated the equivalent AMD Secure Technology (formally called Platform Security Processor) in virtually all of its post-2013 CPUs."
https://en.wikipedia.org/wiki/Intel_Management_Engine
There are countless low or passive power audio devices since the Thing that can record and upload/bounce audio to receiveing devices: https://en.wikipedia.org/wiki/The_Thing_(listening_device)
Go figure. People are strange.
And yes, that ME and PSP are on every cpu since I can't remember, Thinkpad T60 was probably one of the last ones without spy tech.
They should never be network connected. Ever.
It doesn't matter if they are a domestic or commercial device.
Consider their usage in emergency response centres, situation rooms, infrastructure monitoring, meeting rooms in government offices, boardrooms at publicly listed companies, trading desks, or peoples homes as their source of news.
They have access to every pixel shown. They'll also likely have a full audio feed even if audio is passing through another system. You can have all the security control that you like on upstream systems, strong integrity guarantees, and comprehensive validation of that. This is the device where you are most open to exfil or tampering before it's shown to someone.
Even if the vendor isn't the one trying to actively exploit you they're almost universally running some form of incredibly dated, unpatched, and unhardened OS that is riddled with nightmare material vulnerabilities. Don't even put them on your IoT/untrusted network. If you need to control them, use CEC/DDC or a serial connection. Preferably unidirectional.
This is probably obvious to most people, but I will mention just the same: do not install the antenna that the TV comes with.
Wifi antennas would typically be internal and unrelated to the one F-Type coaxial connector one would typically think of as the "antenna" input.
Can't really stop the internal module from scanning and connecting to open access points unless you control the software.
It doesn’t matter how it’s done at all, this is still 100% scumbaggery.
I blame two parties: the company, and the lack of law enforcement that goes after that company with fines large enough to end its existence and/or jail time for its executives.
Corporate veil blah blah blah. Antitrust or pierce it. Enough is enough.
It’s high time for an entirely new branch of legal theory and code in the United States: Corporate Criminal Law.
Every day I want to keep tech more fenced and far from me and only use it for what I need.
We should have laws that limit this kinda of “agreements”
It's insane that something you purchase can force a post purchase EULA before it can do anything.
Imagine buying a shirt but there's a 10 page EULA that says you agree to arbitration as soon as you break the seal. Or a blender, or an oven, or a refrigerator.
A lot of the "smart" electronics are in fact just that, they are sneaking in EULAs to use an app to connect to the device which robs you of your rights and protections as a consumer "Oh, the law says we have to give a 10 year warranty, but unfortunately you installed our app to work with your device which says you agree to forgo the warranty and pay us for the right to sue".
https://gdpr.eu/gdpr-consent-requirements/
The problem is the capacity to litigate is far surpassed by the world's speed and volume of doing bad.
This is a case where companies' actions should be treated like parking tickets: a fine is issued summarily, with option to appeal, not a slow process of litigation having to happen before a fine is issued.
> LG smart TVs do not continuously record or transmit users’ conversations.
"or" is ambiguous in the English language. A lawyer can rightly argue that they mean exclusive or and thus they are being technically truthful as long as they both continuously record and transmit users' conversations. They can resolve this ambiguity by stating each element as a independent sentence.
"continuously" means without end. A lawyer can rightly argue that as long as the recording can end in a single instance, then they are being technically truthful.
> Speech-to-text processing begins only if a user activates a voice interaction through a supported wake-word feature or by pressing the voice (or AI) button on the remote control.
"processing begins" makes no indication as to when it ends. A lawyer can rightly argue that as long as you use a wake-word a single time or press the voice button on the remote control a single time, they can begin processing and never stop. They can resolve this ambiguity by stating that they only process audio during a session and that session has a strict maximum duration.
Also, it makes no statement as to audio processing, only speech-to-text processing. A lawyer can rightly argue that as long as they do not convert the speech to text and just directly transmit the audio they are being truthful. They can resolve this ambiguity by removing the narrowly defined "speech-to-text" and changing it to "audio". Weird their lawyers made this so specific.
> Audio used for wake-word detection is processed locally on the TV and, if no wake word is detected, audio is not converted to text, stored, or transmitted.
Narrowly defined to be only "Audio used for wake-word detection". A lawyer can rightly argue that if they make a second copy of the audio that does not go to wake-word detection, then they can convert it to text, store, and transmit it. They can resolve this ambiguity by removing the narrowly defined "Audio used for wake-word detection" to just state that they do not convert to text, store, or transmit any audio outside of a session. Weird their lawyers made this so specific.
> Voice-recognition results and related technical logs may be generated as part of processing a voice command. These records are associated with specific voice interactions and do not indicate continuous recording of conversations occurring outside an active voice recognition session.
"These records ... do not indicate continuous recording" is not a denial that they are continuously recording. It merely states that it does not indicate continuous recording. A lawyer can rightly argue that as long as they have at least one record that is not associated with a continuous recording, then they are being truthful. No need to remove ambiguity here as it would be covered by the above fixes.
> Speech-recognition results may be used to support voice-related features but are not uploaded later when the TV is offline or when connectivity is restored.
"but are not uploaded later when the TV is offline or when connectivity is restored". Again, "or". Only mentions later, no statement about "now". Their lawyers can rightly argue that as long as they upload them immediately they are being truthful.
"uploaded later when the TV is offline" is illogical nonsense, how is it uploading when it is offline? Their lawyers can rightly argue that as long as they upload later when the TV is online and the TV never lost connectivity, then they are being truthful.
They can remove the ambiguity by stating that they never upload the speech-recognition results or only retain them until the voice-related feature has completed the task. Weird how their lawyers made this so specific.
> ACR uses audio fingerprinting technology using the TV’s internal audio processor (not a speaker) to identify content and does not collect screenshots, screen recordings, video recordings, voice recordings, or other audio recordings from the TV.
Again, "or". "uses" does not mean exclusively uses. "collect" only means ACR does not collect it. This does not indicate that screenshots, screen recordings, video recordings, voice recordings, or other audio recordings are not collected by other processes. It does not indicate that they do not use the resources collected by those other processes. They can remove the ambiguity by stating that ACR does not "use" these data sources and exclusively uses audio fingerprinting technology. Weird how their lawyers made this so specific.
Truly so odd how their lawyers make such precise, minute, and nuanced distinctions for their benefit, but leave everything else so ambiguous they can rightfully argue a tortured interpretation is technically truthful. If they were lawyers on behalf of the consumers, they would never accept such ambiguous language. Must be accidental.
LG is truly an adversial party in all of this.
It’s basically stealing.
Would you want some device connecting to your network that is not under your control?
And before you answer “well, you should lock it down,” yes, that’s true, but we do not blame the victim if they fail to do so. An unlocked door is not an invitation.
A TV not on the Internet is basically worthless these days, unless you have a third-party streaming device like a Fire or Shield--and then you're just moving the trust point from the TV itself to the streaming device, and the same concerns exist. Do you trust Amazon any more than you trust LG?
That's exactly the sort of thing I could see LG piggy backing on. Your neighbor might have spectrum so the LG TV connects to it's private network to phone home.
If you live in a dense city, there's a good chance you can reach an open network. When I lived in midtown Manhattan, there were around 500 SSIDs reachable from my apartment.
We use a Kubuntu Linux laptop behind the TV with a wireless mouse and keyboard (for searching and stuff), stream in Chrome, works great. And yes, we trust this combination.
> Do you trust Amazon any more than you trust LG?
We don't use Amazon device products just because we use Kubuntu Linux on PC's in our home but yes based on LG's behavior we trust Amazon more and we don't put our LG TV or any of our LG appliances we bought a few years ago, on the Internet.
Forgot to mention - there were no improvements whatsoever in terms of functionality.
They made customers feel like suckers for trusting the Brand.
Their LG logo was literally on the signed evidence. What a bunch of clowns getting exposed by community reporters. Thanks Steve. =3
They also specify "for advertising purposes" in the response. It's pretty selective in that wording because it implies that it may be used for other purposes.
What am I missing; was it the rootkit itself that added the functionality to do background recording and dictation? I fucking doubt it.
It should be Tom's Hardware thing to releal this type of a scam.
The only way these companies get put in their place is if their products are used to exfiltrate the video or audio of a powerful politician doing something compromising.
Here in Australia cops liked to hide behind bushes at the bottom of a hill with a speed camera / radar as a revenue collection exercise. They kept fining politicians speeding between Sydney and Canberra, and used photos as evidence showing said politicians with women other than their wives in the passenger seats. So the rules were changed so every speed camera needs at least three warning signs before you reach it.
Yeah, it’s naked self interest but it’s the only way things get done in the world.
Someone, perhaps a white hat hacker, needs to start hacking into LG TVs and publishing senators’ wives screaming the name of “the help” in ecstasy while the man of the house is in DC. Or post audio of senators accepting bribes. Whatever, use your imagination!
Suddenly, almost miraculously, privacy will matter, LG executives will be dragged over hot coals, some might even go to federal prison over wire tapping or espionage charges. Same as Huawei.
But my mark words, until a Senator feels burning hot shame over something exfiltrated from their TV, exactly zero changes will happen to consumer protection laws.
LG will do damage control for a few days.
By next week you will all forget this.
Nothing will change.
What is that? And why does it only happen on that website?
Connect your own devices and smarts to it.
A broader issue is that it does any kind of recording, or processing of the signals around the tv (from a microphone) or what is displayed on the tv (image) is both extremely private.
Privacy has been violated by LG according to their own wording. a way that is not controlled by settings.
What might LG want with an anonymized hash of the audio being played or shown on someone's screen?
Existing ad matching technology can link it with the video of what you're watching to build a shadow profile of you and then sell the attention of your eyeballs to advertising.
From there, simply what you watch, at what time, for how long roughly sets up a wonderful demographic of age, gender, interests, and all that fun stuff. This is an area of tv and video advertisign that has existed for a long time including online and cable tv boxes.
LG's statement that it doesn't move your info anywhere about what is being watched via audio seems to be a variant of this. Using the audio fingerprint, their software could request an ad for it from another system and direction.
So your information may not leave the TV indirectly, but thsi type of a mechanism does exist in cable tv boxes, etc.
With TVs absorbing the OTT (set top box) functions they are absorbing this too so their claims of how big their market is probably tied to being able to sell advertising into that ecosystem.
It’s likely an unadvertised function only for the benefit and leverage of LG and may be buried in signing your life away to use their “smart” tv functions as well.
A tiny crack in LG tvs can be an attack vector for security and safety. Whether it's audio, or video, or anything.
The best TV is a dumb tv, with all internet disabled and plug in your own smarts that you can hopefully manage better.
A brand is a promise of an experience. This brand has broken a promise and it can’t be pretending it didn’t.
https://youtu.be/krj5NM-6tfU
Yeah, they fucking *would*.
I.e: these will probably trickle down to me
It doesn't matter whether they deny specific methods when their execs are quoted giving specific outcomes that require literal spying.
Fuck off LG, and the rest of you doing the same shit.
Maybe an answer is a stripped-down Linux distro for smart TV chipsets that let users clearly disable said features entirely? Since I doubt anyone is going to willingly "go back" to dumb displays when so much data and ad revenue is on the line.
I think this is all disingenuous and will stay that way until the public asks the right questions to the right people
the CEO of the obvious organization can go in front of Congress and truthfully say “Senator, we are not listening, targeting is based on browsing patterns and data brokers”
while the targeted ads and timelines remain based on all those other inputs, and also audio