Need help?
<- Back

Comments (52)

  • adithyassekhar
    I think the author took the wrong message from the video.His arguments are all- yes everyone does this not just lg; :)- yes it can be used to track the user; but unless you literally go into lg ads hq, you can’t say they don’t- they rooted to trigger this; well the os and system apps don’t need root, we need it to observe.If the author is here please consider these as the reasons to why an LG customer would be mad.- They did not knew LG has an ads subsidiary, whose CEOs and executives constantly go on investor meetings claiming “they own the glass”, “they own the living room”, “they own the network and devices” in the “lg household”- if the above was said by lg tv division it would have still stung less. This was said by an ad company they didn’t knew existed nor did they agree to be associated with when they bought a home appliance.Stop focusing on the technical details, look at the larger picture.
  • Retr0id
    > If you root or jailbreak your devices, you've, by their very nature, broken their security.> If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.There are ways to remotely jailbreak LG webOS TVs without user interaction, using the same (or similar) vulnerabilities you use to root your own TV voluntarily.The main reason tools like https://rootmy.tv are prefixed with disclaimers and require user interaction is because we're being courteous, not because they're technically necessary. (source: I own the rootmy.tv domain)
  • rickdeckard
    Thanks for the write-up, it reflects my own impression of the video.The video is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across.They should have decided to set the focus on a specific area and then present every finding around that, i.e.:1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.All the points and scenarios in the video might be valid, but they jump between those scopes and imply that its all the same, weakening the whole investigation.If I'm LG and forced to respond to this, I can easily focus on dissecting the voice-input topic as a mere demonstration of the feature and how rooting the TV beforehand just showed the local process of handling it, steering the narrative away from the (IMO) much more important topics...
  • taylorfinley
    This reads like a PR crisis management firm planted article. it probably isn't, but it reads like one. It muddies the waters with vague implications and suggests we cannot infer anything from encrypted packets. If your screen is showing content sourced over HDMI and the packets are heading to the ACR endpoint, I think it's safe to infer HDMI is being ACR'd.
  • pmlnr
    > If you root or jailbreak your devices, you've, by their very nature, broken their security.Wow. Please stop spreading things like this.Not having root means not owning a device you paid for and have in your home.
  • wewewedxfgdf
    I'll save you the time and effort trying to work out the point being made:GamersNexus did an investigation which may overstate the privacy threat posed by LG smart TVs.
  • badsectoracula
    > If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.Do you actually want a channel with 2.66 million subscribers to show how to get remote access to TVs used by millions of people? :-P
  • bob1029
    > What am I meant to take away from this? If you look at other IoT devices, they’re going to show the same thing. But here it’s presented as bad. Why?The influencer economy is a bit soaked these days. You need to crank up the stakes to keep the viewer's attention.
  • fulafel
    Seems incoherent. What exactly is the bad idea and why? Are they rediscovering "don't run stuff needlessly as root"?
  • hypfer
    Semi-OT, possibly interesting:Maintaining enemy lists like the one of Drew linked there has been illegal in Germany since 2021 as part of the government's efforts against hate crimes and right-wing extremism.Or at least that's my understanding of the law there. Maybe it's exempt based on technicalities.In any case, I can in many cases emotionally relate to why he is doing that, but.. oof.
  • nalekberov
    Anyone who uses GenAI for content creation, isn't worth my time. My rationale is simple: If I wanted to, I could have asked "AI" to generate that content for me, when I am spending my time consuming your content, I expect to get something unique.
  • LoganDark
    They rooted the TV to study it. They're not saying you're in sudden danger of attackers rooting your TV and running commands over SSH. They're saying there's evidence that certain data is collected when you wouldn't want it to be, and there are any number of potential vulnerabilities that could provide hackers access, on top of LG potentially having access as well which you also probably wouldn't want.
  • rbanffy
    Now I want to build a cluster of rooted WebOS TVs.I always say any serious computer needs blinkenlights and a smart TV has literally millions of them.
  • ChrisArchitect
    Related:216M Spy TVs – The LG Smart TV Problem [video]https://news.ycombinator.com/item?id=49592375
  • lovich
    > Now, what he’s showing can be pretty scary. I wouldn’t want any attacker to be able to record me without knowing. But it’s important to remember the context here: earlier in the video, Wendell rooted the TV. He has full access to everything on it. To run those commands and programs, he had to log into WebOS via SSH and run them on the device. He didn't show remoting calling those commands, nor was this done on an unmodified device.> If you root or jailbreak your devices, you've, by their very nature, broken their security. If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.What is this authors point?LG doesn’t need a root exploit to get this info because they made the fucking thing.I read the article and then grepped for “Texas” to see if I missed it. The author never mentions the fact that this data collection was only found out initially because of a Texas government lawsuit that LG settled on by agreeing to give “informed consent” to users about data collection and then the warnings started popping up in unexpected places.Is the author arguing that jailbreaking your device to find out what the manufacturer can do to gather data on you is dangerous because I don’t know, questioning your corporate overlords is bad or something?