GamersNexus and LG: Or why rooting your TV is a bad idea
leaflet.pub91 points by drasticactions 6 hours ago
91 points by drasticactions 6 hours ago
I think the author took the wrong message from the video.
His arguments are all
- yes everyone does this not just lg; :)
- yes it can be used to track the user; but unless you literally go into lg ads hq, you can’t say they don’t
- they rooted to trigger this; well the os and system apps don’t need root, we need it to observe.
If the author is here please consider these as the reasons to why an LG customer would be mad.
- They did not knew LG has an ads subsidiary, whose CEOs and executives constantly go on investor meetings claiming “they own the glass”, “they own the living room”, “they own the network and devices” in the “lg household”
- if the above was said by lg tv division it would have still stung less. This was said by an ad company they didn’t knew existed nor did they agree to be associated with when they bought a home appliance.
Stop focusing on the technical details, look at the larger picture.
Yes, as the owner of an LG OLED, I paid a premium for a good quality panel, and expect it to be mine.
Also, I anticipated ads on a smart TV (unfortunately it's inevitable), but (wrongly) assumed that such invasive tracking and "we own the glass" would be a bar too low even for the budget manufacturers.
I'm never buying any LG product ever again.
I own an LG TV as well, and while I assume the Mi TV Box 4K tracks me instead, at least it's unpowered while the TV is off, and the TV itself is not connected to my network. I have updated TVs/soundbars/etc, but only through USB. When they remove that option is the day I stop being a customer, moving to one that still does.
Better yet would be never needing an update, but alas.
I have an LG OLED as well. When I bought it, it was the previous year's flagship. I am also mad at this.
I also had an LG washing machine. The dispenser plastic drawer broke after a year of use. After over a week of multiple emails and calls with the shop, LG themselves and third-party spares shops trying to get a replacement, I bought a Bosch.
I am also never buying anything from LG again.
Your broken waking machine drawer is an orthogonal problem, and perhaps not specific to one corp. Plastic parts break but, OTOH, overbuilding consumes resources with diminishing utility. A deep spare parts market is a cost.
May i suggest basic home repair? Two techniques that work in many cases are:
- "welding" with a soldering iron, using cable tie as a filler rod. You'll want good ventilation and a sacrificial tip - epoxy repair putty
Superglue (cyanoacrylate) tends to give disappointing results on its own, but can be a good first step before putty. Putty can be reinforced with some kind of fibre. Never use cyanoacrylate with the welding technique (cyanide).
I don't love the model profusion that makes spare parts markets inefficient, but free markets are inefficient all over the place. Price in the externalities.
I agree with the author, the point is that the way the video and the overall research was done, the entire message was diluted too much.
There is substance in what they did. But they should have worked with an actual journalist to frame this properly and create pressure on the overarching topics.
If a TV company (LG or ANY of the others who have Ad-subsidiaries) needs to respond to this video, they can easily reframe the whole topic.
The most blatant example is that they demonstrate in the video that this TV, which has a built-in microphone for voice-control, that can be switched off with a mechanical switch:
1. Will record your voice when you ask it to transcribe your input to a textbox
2. Will process your voice to create this text it shows, as visible on the logs of the rooted OS
3. Will SHOW you that it's transcribing your input on the screen.
This is weakening the whole story.
--
In HN-terms: It's a constant-power, constantly-connected IoT-device with lots of sensors and huge compute-power, located in the center of your home.
There are big topics around this that deserve a huge spotlight, which apply to ALL TV manufacturers:
a. What data is actually being collected about the user, and what is done with this data?
b. How well is security handled on the TV to ensure no malicious usage?
Repeatedly jumping to the conclusion during the video that LG specifically is collecting ALL this local data to spy on you, without clear evidence, this just gives LG an easy way to respond and every other vendor enough room to distance themselves from the whole story.
> What data is actually being collected about the user, and what is done with this data?
This question implies that the answer could be something other than the maximum amount of data collection and monetization of that data they can get away with.
If that statement gives you pause please spend even a short amount of time reading about ad networks, data brokers, and corporate surveillance.
Yeah, I wouldn't vouch for a US court, but lucky me I'm in the EU, where the answer "the maximum amount of data collection and monetization of that data they can get away with" is not compliant to the requirements of GDPR.
So even IF that would be a sufficient answer in a court of US, it would not be sufficient in a court of an EU country.
--> Hence my point on how the overall message was diluted too much.
See, you may look at all this as "nothing can be done anyway, so let's bunch it all together and rant about it as emotionally as possible". But I look at it as "this is all potential evidence that a law was either already broken or needs to have a loophole closed"
But you won't get any of this done by spraying all over how normal this is and how everyone does it anyway. You get this done with a precise shot at ONE of them, concise enough to pin them down while aiming at the next one.
LG's terms of service essentially state that they will record any voice commands and store them for 6 months. They explicitly say they may store them in Korea. https://us.lgappstv.com/main/terms
Actually I think everything you're suggesting is unclear, LG explicitly say they do these things in their ToS. I skimmed their privacy policy, and I'm pretty sure it essentially says they collect all this information and use it for targeted advertising.
Yeah, and here's the part that's interesting to me as a EU-consumer: This wording doesn't exist in the European ToS: https://gb.lgappstv.com/main/terms#tabContentTerms6
So there's the angle that US is lacking the proper regulation, and the angle that LG may have violated its ToS in the EU.
But neither of this is going to get pinned down if everything is bunched together without focus and clear evidence...
The numerical majority of developed counties have some kind of privacy law. Murrica is an outlier, because of course it is.
LG has an ads subsidiary, whose CEOs and executives constantly go on investor meetings claiming “they own the glass”, “they own the living room”, “they own the network and devices” in the “lg household”
Uhm every tech bro does this it is what makes the tech industry a fucking Bond villain lol.
It's such a bad take.
It's either a deliberately contrary or the author has other motives (which may sound ridiculous, but we know that bad actors have been paying people for bad takes for years - Malcolm Gladwell for instance being paid by oil and gas).
I was also a bit disappointed with the video. I don't usually watch the channel, but the previous video on LG with the McAfee thing was good. This one, well it has important points and exposes some very valid concerns. However I mostly agree with the linked article, it does not properly spell out what they actually can prove, and what's just conjecture. The video gets lauded as investigative journalism, I think the technical details are important to get right and make clear to non-tech people. A normal consumer would have no idea how to really judge the danger to their privacy after watching this, they'd come away thinking that for sure someone can listen in on their living room.
> If you root or jailbreak your devices, you've, by their very nature, broken their security.
> If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.
There are ways to remotely jailbreak LG webOS TVs without user interaction, using the same (or similar) vulnerabilities you use to root your own TV voluntarily.
The main reason tools like https://rootmy.tv are prefixed with disclaimers and require user interaction is because we're being courteous, not because they're technically necessary. (source: I own the rootmy.tv domain)
Most of what I’m reading on rootmy.tv says the vulnerability it exploits has been fixed. So, if one were to keep software up to date on their TV, there is an improbably small chance it can actually be remotely jailbroken — am I reading this right?
The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining. There are also more up-to-date rooting tools beyond rootmy.tv.
The security posture of webOS is absolutely terrible, at least, it is in the way LG deploys it.
> The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining.
But vulnerabilities that can be remotely exploited without user interaction (CVSS grade 9-10)?
Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.
I'm guessing that you're exploiting some sort of exploit (buffer overflow???) on the DVB-T demodulator
> only RF down the TV antenna input
Holy shit. RF to zero-click exploit is a new one. I guess digital-everything wasn't always a good idea, this probably wouldn't ever have been a problem with analogue antennas and CRTs.
What are the people at LG even doing?
Teletext was available in analogue times. So I could well imagine there to be a possible avenue of exploits with it too. Would take a bit of time, but I see no reason why wouldn't some data result in a incorrect handling.
Exploiting what? There wasn’t any software hierarchy for Teletext to escape from in analogy TVs. If you found a bug in the Teletext chip you couldn’t then go on to do anything to the TV set aside print different data to the screen. And since you’re already tuned into that radio frequency and controlling the data sent on it, you already have control of what’s sent to the TV screen already anyway so who cares?
As an aside, I once interviewed one of the guys who wrote Teletext processors for analog TVs. He was a very interesting individual.
> Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.
So no responsible disclosure, I see.
Not knowing any more details, it still sounds like you'd still need the user to tune to the actual frequency on the correct receiver (to cause some buffer overflow?). But then still there's no internet to do anything. So you'd need some very specific f/up exploit to then change local settings on the device I imagine.
Either way, would be a great opportunity to demonstrate this in a video, now that there's attention on the topic, to further amplify the pressure on LG's "terrible security posture" as you say.
> So no responsible disclosure, I see.
If I, a corporation, declare that I only accept security reports carved on clay tablets in ancient greek and hand-delivered to my office in Timbuktu during a total solar eclipse - does that stop responsible security researchers from disclosing their findings publicly?
Of course not.
If the guy sends a clear message to the best public contact address he can find with 15 minutes of searching; and gives them 30 days to patch before publicly disclosing the bug; then he's performed responsible disclosure.
The vendor's corporate policies and release cycles and contact addresses and triage procedures are their problem.
> So no responsible disclosure, I see.
If the manufacturers responsibly included a responsible way to install custom software/firmware, perhaps people would feel more inclined to help them. Their current attitude buys them very little goodwill.
> So no responsible disclosure, I see.
Huh?
You stated that you're "sitting on one that doesn't even require an internet connection [..] I'm waiting for my model to go EOL before I release it"
I read this as "Wait until the model is EOL, hoping it won't be disclosed and fixed until then and also not fixed afterwards"
Is this not what you meant to say?
Responsible disclosure makes sense when the user and the manufacturer have the same goal of the product being secure. Jailbreaking is a case where the user and the manufacturer have opposing goals: the user wants to be in charge their hardware, the manufacturer wants to prevent the user from being in charge of their own hardware. Responsible disclosure doesn't make sense, the manufacturer would just patch the vulnerability before users could use it.
If manufacturers had a sanctioned way for the user to get root access to their own hardware, responsible disclosure would've made sense, but as it is, vulnerabilities are a useful tool for the owner of the device.