RU version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
48% Positive
Analyzed from 2398 words in the discussion.
Trending Topics
#video#device#root#data#voice#rooted#devices#security#bad#more

Discussion (58 Comments)Read Original on HackerNews
His arguments are all
- yes everyone does this not just lg; :)
- yes it can be used to track the user; but unless you literally go into lg ads hq, you can’t say they don’t
- they rooted to trigger this; well the os and system apps don’t need root, we need it to observe.
If the author is here please consider these as the reasons to why an LG customer would be mad.
- They did not knew LG has an ads subsidiary, whose CEOs and executives constantly go on investor meetings claiming “they own the glass”, “they own the living room”, “they own the network and devices” in the “lg household”
- if the above was said by lg tv division it would have still stung less. This was said by an ad company they didn’t knew existed nor did they agree to be associated with when they bought a home appliance.
Stop focusing on the technical details, look at the larger picture.
Also, I anticipated ads on a smart TV (unfortunately it's inevitable), but (wrongly) assumed that such invasive tracking and "we own the glass" would be a bar too low even for the budget manufacturers.
I'm never buying any LG product ever again.
There is substance in what they did. But they should have worked with an actual journalist to frame this properly and create pressure on the overarching topics.
If a TV company (LG or ANY of the others who have Ad-subsidiaries) needs to respond to this video, they can easily reframe the whole topic.
The most blatant example is that they demonstrate in the video that this TV, which has a built-in microphone for voice-control, that can be switched off with a mechanical switch:
1. Will record your voice when you ask it to transcribe your input to a textbox
2. Will process your voice to create this text it shows, as visible on the logs of the rooted OS
3. Will SHOW you that it's transcribing your input on the screen.
This is weakening the whole story.
--
In HN-terms: It's a constant-power, constantly-connected IoT-device with lots of sensors and huge compute-power, located in the center of your home.
There are big topics around this that deserve a huge spotlight, which apply to ALL TV manufacturers:
a. What data is actually being collected about the user, and what is done with this data?
b. How well is security handled on the TV to ensure no malicious usage?
Repeatedly jumping to the conclusion during the video that LG specifically is collecting ALL this local data to spy on you, without clear evidence, this just gives LG an easy way to respond and every other vendor enough room to distance themselves from the whole story.
Actually I think everything you're suggesting is unclear, LG explicitly say they do these things in their ToS. I skimmed their privacy policy, and I'm pretty sure it essentially says they collect all this information and use it for targeted advertising.
This question implies that the answer could be something other than the maximum amount of data collection and monetization of that data they can get away with.
If that statement gives you pause please spend even a short amount of time reading about ad networks, data brokers, and corporate surveillance.
It's either a deliberately contrary or the author has other motives (which may sound ridiculous, but we know that bad actors have been paying people for bad takes for years - Malcolm Gladwell for instance being paid by oil and gas).
> If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.
There are ways to remotely jailbreak LG webOS TVs without user interaction, using the same (or similar) vulnerabilities you use to root your own TV voluntarily.
The main reason tools like https://rootmy.tv are prefixed with disclaimers and require user interaction is because we're being courteous, not because they're technically necessary. (source: I own the rootmy.tv domain)
The security posture of webOS is absolutely terrible, at least, it is in the way LG deploys it.
But vulnerabilities that can be remotely exploited without user interaction (CVSS grade 9-10)?
I presume LG is like most vendors and stops issuing updates for older models after a while. It's pretty hard to keep software up to date when the vendor stops issuing updates.
The video is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across.
They should have decided to set the focus on a specific area and then present every finding around that, i.e.:
1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.
2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.
3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.
All the points and scenarios in the video might be valid, but they jump between those scopes and imply that its all the same, weakening the whole investigation.
If I'm LG and forced to respond to this, I can easily focus on dissecting the voice-input topic as a mere demonstration of the feature and how rooting the TV beforehand just showed the local process of handling it, steering the narrative away from the (IMO) much more important topics...
Wow. Please stop spreading things like this.
Not having root means not owning a device you paid for and have in your home.
Of course root allows you to tinker with your device and make it run what you want, but:
- Rooted devices make devices unpredictable. As shown in the video: How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?
- Re-selling: How do you know that TV you bought is untampered? How do you know it does not have software with malware installed that steals your credentials?
Many rooted devices display during boot a warning that they have been rooted. This is a problem that has been solved for more than a decade, but manufacturers pretend not to know the solution, because they are actively hostile to user freedom.
> How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?
Let's pretend there aren't plenty other ways they could spy on you. If it's bad if a hotel does it, why is it okay if LG does it? Do you honestly trust LG, and the thousands of "partners" that they sell your data to, and every government whose warrants they have to honor?
Your argument reduces to "if the warden lets us out of our jail cells, who will make sure we behave?"
But in this case… I don’t know. The OEM is so actively hostile you might be better off just taking the risk with root if you must purchase it at all (and physically removing the radio/microphone hardware not being an option).
The inevitable outcome of this video is that TV vendors are pushed to harden the security and preserve the trust-chain, because part of the (valid) claim is that nefarious actors may break the security to use the device for spying on you.
With support from an actual journalist, it could be reframed to also emphasize the importance of controlled root-access to monitor and control the devices behavior.
But none of this was done unfortunately, and if I'm LG I don't want to see another video where someone reframes user-initiated voice-input for a web-search as spying initiative by showing some device-logs of the transcription process in parallel...
Do you actually want a channel with 2.66 million subscribers to show how to get remote access to TVs used by millions of people? :-P
The influencer economy is a bit soaked these days. You need to crank up the stakes to keep the viewer's attention.
That does not mean that LG does all that by default.
GamersNexus did an investigation which may overstate the privacy threat posed by LG smart TVs.
Maintaining enemy lists like the one of Drew linked there has been illegal in Germany since 2021 as part of the government's (very necessary!) efforts against hate crimes and right-wing extremism.
Or at least that's my understanding of the law there. Maybe it's exempt based on technicalities.
In any case, I can in many cases emotionally relate to why he is doing that, but.. oof.
Otherwise, they start a voice command service (clearly displayed on the screen) and then say your TV is recording on your conversation. Like duh, of course my TV starts recording voice when I use voice commands.
And of course you have to trust LG with their TV and (not) having access. That same logic applies to every different company.
I always say any serious computer needs blinkenlights and a smart TV has literally millions of them.
216M Spy TVs – The LG Smart TV Problem [video]
https://news.ycombinator.com/item?id=49592375
> If you root or jailbreak your devices, you've, by their very nature, broken their security. If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.
What is this authors point?
LG doesn’t need a root exploit to get this info because they made the fucking thing.
I read the article and then grepped for “Texas” to see if I missed it. The author never mentions the fact that this data collection was only found out initially because of a Texas government lawsuit that LG settled on by agreeing to give “informed consent” to users about data collection and then the warnings started popping up in unexpected places.
Is the author arguing that jailbreaking your device to find out what the manufacturer can do to gather data on you is dangerous because I don’t know, questioning your corporate overlords is bad or something?
This is the major issue with this video: It mixes stuff done by LG (ACR) with stuff done via rooting (audio recording). And now people think LG is 24/7 recording your conversations and uploading them somewhere. This has not been proven.
That nuance is important if you value good journalism.
Otherwise if we're just our here throwing random allegations because "corp bad", might as well say LG 's TVs are turning the frickin' frogs gay.