137 pointsby DemiGuru4 hours ago19 comments
  • 12_throw_awayan hour ago
    42% of the apps on LG's platform have these quasi-malware SDKs in them? Seems kinda bad, whether it's due to negligence or just pure incompetence? You'd think there might be legal consequences for a corporation that lets their app store turn into a malware delivery system?
  • s1ncere2 hours ago
    Stop hooking up your LG tv to any network
    • michaelchisari7 minutes ago
      Never once had a problem with an LG because I've never given it internet access. A trustworthy set top box handles everything instead. Concerned that might not be an option in the future.
    • 5kg2 hours ago
      • ahartmetzan hour ago
        Fine with Linux though :)

        LG's behavior isn't fine, but their monitors don't install crapware on Linux.

    • mikepurvisan hour ago
      I'm mostly very happy with my LG C4 as a home theatre centerpiece, and I did have it online so that I could use the apps for YouTube and Jellyfin. However, the lack of support for modern 4k rips (HEVC+DTS) ended up being a dealbreaker and I finally ditched the built in software for a fire stick instead.

      No transcoding, no weird codec issues, just the raw files direct streamed from the underpowered Unraid box, into the back of the AVR where the audio is handled correctly and the video is sent to the screen.

    • MiddleEndianan hour ago
      My LG DualUp monitors (with no internet access) recently triggered some LG Adware Bullshit to install on my Windows laptop. So I'd say stop using LG anything (or Windows anything since they're voluntarily in on the scam too lol). If you want the 2560x2880, maybe buy the knock-off INNOCN vertical monitors.

      https://old.reddit.com/r/pcmasterrace/comments/1v1pkbs/lg_sp... ← examples of others who ran into the same shit

    • 2 hours ago
      undefined
    • CivBase2 hours ago
      Stop buying LG TVs.
      • kaelwd2 minutes ago
        And buy what? Smasnug? Sony? They're all uniquely shit.
      • smcleod2 hours ago
        Unfortunately they make arguably the best OLEDs and webOS is pretty decent to use (especially compared to the terrible OS that Samsung and Sony run). I think the best thing people can do is update their firmware then disconnect it from the internet. Using an AppleTV or similar provides a better experience than any TVs built in apps anyway.
        • cosmic_cheese35 minutes ago
          I don’t ever use their “smart” functionality (that’s what my Apple TV is for) but I’ve never had any issues with the Google TV (Android) build that Sony ships. It doesn’t nag me about being kept offline, is reasonably fast, and doesn’t even show its home screen unless I specifically summon it, so it checks my boxes.
        • meyan hour ago
          How important is "the best" OLED vs the second best or 100th best OLED? I am personally ok not buying the bleeding edge to not get malware onto my OS.
          • notatoadan hour ago
            reasonably important, if you're never connecting your lg tv to any network, and just connecting it to an AppleTV or something and letting HDMI-CEC control it so you never even see their OS.
            • StumpChunkmanan hour ago
              Exactly this. And with an Apple TV 4K Ethernet, you've got a bonus Thread border router for smart home devices. I actually didn't even realize that initially, but was very pleased when I found IKEAs latest round of Matter over Thread devices paired nicely with it and my existing Home Assistant + Hue setup.
          • theplumberan hour ago
            If you care about malware you do not plug it into the internet. I think windows computers are pretty mallwareish as well or at least spyware. People who buy Oled buy them because they care about PQ.
          • globular-toast10 minutes ago
            Exactly. If you get the best today it'll be the second best tomorrow anyway. Absolute position is undetectable, you can only perceive change. Use that to your advantage and stay off the treadmill.
          • an hour ago
            undefined
          • Bud39 minutes ago
            [dead]
        • pjmlp23 minutes ago
          Have to agree, WebOS is much better than Android TV OS, with ads on the dashboard.
        • jedbergan hour ago
          I haven’t looked recently but last I checked Samsung made the best panels. Has that changed recently?
          • dodslaser40 minutes ago
            Samsung is good, except:

            - No Dolby Vision support, only HDR10+ - Issues with judder/micro stutter - History of nerfing TVs via OTA updates - HDMI ports randomly failing - Bad HDMI-CEC implementation - Selling completely different panel generations under the exact same model names.

          • smcleodan hour ago
            Their panels are often over-saturated with that fake HDR like look, similar to their phones.
            • ahartmetzan hour ago
              Most screens come with "showroom settings" out of the box. You need to configure them to something more neutral once and then it's fine.
              • smcleod34 minutes ago
                I'm aware of that setting, but this is the Samsung baseline. The panels they export for OEMs / other manufacturers don't seem to have the same hyper saturation. Even just standing next to someone using a Samsung phone or tablet you can often spot it straight away we know you what to look for.
          • nvme0n1p1an hour ago
            Samsung scored highest on https://www.rtings.com/ for my criteria, and I'm happy with the purchase. I didn't connect it to the network, of course. (I had to stop my handyman from connecting it and he seemed to think I was crazy for insisting.)
            • ahartmetzan hour ago
              "I work in software. I have seen things you people wouldn't believe. Attack ships on fire off the shoulder of Orion. I watched C-beams glitter in the dark near the Tannhäuser Gate..."
      • matheusmoreiraan hour ago
        Aren't they the only TVs that can be jailbroken?
  • akersten2 hours ago
    is this some kind of tactical distraction from the other LG headlines this week?

    I thought residential proxies are already banned from SmartTV apps by virtue of practically every APK under the sun being subject to the Google Play terms of service.

    • Marsymars2 hours ago
      > I thought residential proxies are already banned from SmartTV apps by virtue of practically every APK under the sun being subject to the Google Play terms of service.

      The platforms in question here are webOS and Tizen, neither of which are Android or use the Google Play Store.

    • ssl-32 hours ago
      That only applies to the subset of TVs that use Google TV/Android TV.

      Not so much for the rest of them that have operating systems with names like Roku TV OS, Tizen, WebOS, and Fire TV OS. They do their own things.

    • ranger_danger2 hours ago
      LG webOS is not Android though, it's from the old Palm/HP devices of the early 2010s. And I'm pretty sure there are still tons of play store apps with these proxy SDKs in them, advertised/consented or not.
  • glimshe2 hours ago
    My TV doesn't know my router's wi-fi password.
    • declan_roberts2 hours ago
      My TV thinks it's January 1st 1970.
      • kazinator4 minutes ago
        [delayed]
      • charles_f4 minutes ago
        My TV isn't even connected to power
      • mc3301an hour ago
        Every time anything asks for a DOB or anything like that, I enter the earliest date their system allows. Been doing it for decades.

        I guess that might make me more trackable?

        • ahartmetzan hour ago
          At least you could get some interesting ads. Do you want to participate in a longevity study?
    • amazingman2 hours ago
      Hope you don't have any open WiFi networks nearby. IMO it's better to put it on one of your networks and isolate it from the internet and other devices.
      • tyre2 hours ago
        Yes. I bought a Samsung TV and there isn’t a way to set up Art Mode without the internet. So first you have to get a raspberry pi, install pi hole, then switch your router’s DNS.

        What a wild experience 2026 is. But I do feel like a wizard.

        • walrus01an hour ago
          You don't need an actual physical raspberry pi to temporarily run pihole on your LAN, you can, for instance, install a barebones debian VM inside any common hypervisor on your laptop like virtualbox or qemu, then install pihole on that basic debian x86-64 system.
          • an hour ago
            undefined
        • entropie2 hours ago
          They might hardcode DNS. It's not certain that this will work.
          • slauan hour ago
            This is why I’m a bit conflicted about DoH and ODoH. Firefox and Chrome have defaulted to DoH for years if I’m not mistaken (although I’m in Europe so I believe my FF still uses regular DNS instead of DoH by default).

            This also means that DoH effectively sends all your queries to CloudFlare on FF. Chrome is slightly smarter and tries to map your DNS provider to a DoH implementation if known.

            • tkelan hour ago
              I have my router set with iptables rules to block/redirect all port 53 and you can also add known DoH to a blocklist to try and force LAN devices to use your router DNS.
          • CyberDildonicsan hour ago
            You can intercept normal DNS with iptables rules.

            The best way to deal with a TV you don't trust is what no one wants to hear.

            Open up the back and disconnect the wifi antenna. It is easy to open them up and everything is pretty simple and obvious once you do.

      • MrDrMcCoy2 hours ago
        If it connects to another network, it's somebody else's problem. Unless of course, it has a built in webcam or microphone.
      • RiverCrochet2 hours ago
        I haven't seen any open WiFi networks around me in years. I don't think it's a thing anymore; it's definitely not something a TV company can rely on.
        • baby_souffle2 hours ago
          They're not unheard of in cities. Hotels and shopping malls have them. Some residential ISPs will also broadcast a public access point using a slice of each customer's bandwidth allocation...
          • dhosekan hour ago
            When I had Comcast internet, I could get on those, but it required a network profile to actually connect to the internet. That said, I wouldn’t put it past TV makers and Comcast to collude on using this to allow backdoor network exfiltration.
      • Hamukoan hour ago
        I have an open guest network with a captive portal, and not once have I seen my LG TV try to connect to it.
    • walrus012 hours ago
      I've said it before on HN a long time ago but I'll repeat myself, I have about a thousand times more confidence that Sony and/or Microsoft will keep their PS5 and Xbox operating systems secure and not crapped up with stuff like this, than I do that random TV manufacturers will not result in a cybersecurity or privacy disaster.

      Yeah, the PS and Xbox OSes show you ads, and they have telemetry. But both companies also have an extremely important core functional need of keeping them secure, because possible fuckery with the OS could result in game piracy/DRM bypasses and a direct threat to their revenue models.

      • thewebguyd10 minutes ago
        The gaming consoles aren't subsidized via the data collection like smart TVs are via content recognition (selling everything on your screen to advertisers).

        Consoles are sometimes sold at a loss, but the revenue model is different. Playstation plus/game pass, a cut of game sales and microtransactions, exclusives, and accessories.

        No one should ever connect their TV to the internet. There just isn't any reason to, get access to your streaming apps another way.

    • gboss2 hours ago
      Pretty sure they can get internet through the HDMI cord from Roku or similar device
      • MrDrMcCoy2 hours ago
        Source? HDMI includes Ethernet in the spec, but I've never heard of any devices actually implementing it.
      • RiverCrochet2 hours ago
        That would require the Roku to specifically be set up to act as a router. You can't just connect to a random device that's not specifically a router/AP and use its internet connection.

        Since Roku like other smart TV companies makes money off of user data captur, it's not incentivized to enable those conditions for a downstream device, especially if not specifically advertised as a feature.

      • mikestewan hour ago
        This again? Yes, it’s in the spec. No, no one has been shown to have actually implemented it. No streaming box is going to allow random devices to use their connection.
      • walrus01an hour ago
        does a roku provide a dhcp server, issue a dhcp lease, do NAT and routing to things that are plugged into it over the 100M ethernet built into a current gen HDMI link?
    • aussieguy12342 hours ago
      This is the best approach
  • yodonan hour ago
    If other non-Android-based TV manufacturers follow, this will have a much bigger impact on the spread (and cost) of scraping than either Anubis or Cloudflare.
  • ram_rattle2 hours ago
    Apparently all these vendors did nothing to prevent this, a nice article from spur intelligence

    https://www.cbsnews.com/newyork/video/how-smart-tvs-may-be-s...

  • 0xblinqan hour ago
    I'm very worried with all this bullshit around TVs.

    I've been running the same Samsung UE40C6530 since 2010. It's 16 f'ng years and the thing works flawlessly like the first day. No other electronic device in my life worked so well, during so long.

    But I'm about to move to a new home, and it feels like it's about time to get something more modern, at least a 4k TV.

    But I'm honestly totally lost at what to buy. I do not want a "Smart" tv that's slow to start, bloated with crap, installing updates every day, and maybe even spying on me.

    I want a plain, old, normal TV. If possible without Android or any advanced operating system. Just a TV. I'll plug external content myself, either via a Chromecast device, or something similar. I don't want my TV to be a full fledged computer.

    Is there such a thing? What would you buy nowadays? It seems you're forced to get yet another computer to maintain and be worried about whatever you buy.

    • orly0127 minutes ago
      I've heard you are not forced to connect to wifi, and on most of them you can connect make it default certain HDMI input. Latency to turn on/off might be less good than the 2010 one, but other than that this might be a very good way to do it.
    • Fantosisman hour ago
      You buy a commercial panel used for advertising/signage that's 3x the price of the "Smart" consumer panels.
      • thewebguyd8 minutes ago
        the smart consumer panels would also be more expensive if they weren't subsidized via the spyware.
    • jdmarble43 minutes ago
      If you’re fine with “okay” picture quality, try a Sceptre. You can get them on Amazon. I’ve had good success with them. I heard you can still disable some smart features on Sony TVs.
    • Bud35 minutes ago
      [dead]
  • kh2engaban hour ago
    Is there a (technical) difference between a residential proxy and bot network node?
    • Nursiean hour ago
      A figleaf of "We gave ourselves permission on page 247, paragraph 3 of your user agreement"
  • spudlyo2 hours ago
    One day there will be a decent TV that can be relatively easily hacked to run on open source firmware. My wife and I are moving soon, and I'm happy we've decided not to have a TV in the new place. Neither of our current LG TV's have ever been connected to the network, but it will feel good when I sell or give the cursed things away.
  • 4rt2 hours ago
    lg's had a good run of being a monitor, their software was a bit shit but the hardware supported e-arc etc.

    i've got 2 expensive lg tvs and i bought them because you don't need to use their remote, it just turns on and shows the picture.

  • jchw2 hours ago
    None of my TVs are connected to the Internet. That said, I could really do with a better open source fullscreen UI, especially since I mainly just want a web browser that works good. I'm just using KDE Plasma with a custom daemon to control the TV power state over an HDMI CEC adapter plus an old K830 keyboard.

    I'm, frankly, a bit annoyed by this whole thing; I'd rather have USB adapter RF wireless because it is simpler to deal with vs Bluetooth, but actually I can't even find other Bluetooth keyboards that are as compelling as this K830 and worse yet, they don't even make the K830 anymore. I don't really mind KDE Plasma with just some minor customizations but I don't really like any of the options like Kodi. Maybe Plasma BigScreen will eventually be what I want for that. And finally, HDMI CEC is a pain in the ass. For reasons, I actually use an adapter to get CEC support on a normal PC platform, because most PC HDMI ports can't do it. And also, it's just a bizarre and overly complicated thing. I have it working reliably, but it took some time to iron out all the kinks, particularly because my TV responds quite differently depending on how recently it was powered off.

    I really just want a big monitor and to basically just use DPMS... Like a computer does, but large computer monitors tend to be expensive and don't always have remote controls, which admittedly are handy.

    • saint_yossarianan hour ago
      K400+ user here, you might be interested in the upcoming Framework Wireless Touchpad Keyboard.
  • xena2 hours ago
    This is the best news I've heard all week. Finally good news for once!
  • BrenBarn33 minutes ago
    The messed up thing is that we need to rely on LG to stop allowing it rather than just making it illegal.
  • charcircuit35 minutes ago
    >“The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”

    Note that the same applies for the other privacy invasive webos features. But since that doesn't harm big tech's monopoly they will conveniently avoid mentioning it.

  • pixl972 hours ago
    I mean, why didn't they do that from the start?
    • steele2 hours ago
      Honeypot for more logos
  • symfoniq2 hours ago
    This is madness.

    Only LG themselves should be able to have this kind of invasive control over your television.

  • jocelyner2 hours ago
    [dead]
  • cognitiveinline2 hours ago
    Sharing a slice of your internet in a privacy preserving way in exchange for something of value, seems fair, no?
    • walrus012 hours ago
      Grey market residential proxy service providers are one of the most common methods of implementing bot spam, social media manipulation and plenty of straight-out fraud.

      There's all kinds of things that malicious actors want to do where they value coming from an ordinary (comcast, charter, centurylink, shaw cable, whatever) residential IP.

      • cognitiveinlinean hour ago
        You make a good point. I've reassessed and agree this is shady, and not a good pattern. And should be disabled/abolished.
      • charcircuit2 hours ago
        Just because others abuse privacy doesn't mean that we should remove privacy from everyone else. They also let you get around geoblocking.
        • nvme0n1p1an hour ago
          You're free to let strangers download illegal images from a proxy running on your IP, but I sure as hell won't.
          • charcircuit36 minutes ago
            If you don't want to share your internet with others, that is your choice, but please don't make seem like you are only sharing the internet with criminals. That is a harmful belief to spread.
      • hokumguru2 hours ago
        I mean, some of us have legitimate business needs to get past cloudflares frankly somewhat bs gatekeeping business model, however
        • walrus012 hours ago
          Sure, I do as well, I have my own VPN into my home office that lets me run traffic outbound through its default gateway while I'm somewhere else. But letting random third parties I don't know run traffic through my house is another thing entirely.
    • ryandrake2 hours ago
      Only if the app provides 1. prominently-displayed, informed consent, 2. an option to opt-out without losing app functionality, or 3. joining the botnet provides some kind of actual benefit to the user, besides just money to the developer.
      • mirashii2 hours ago
        Add to that list respecting the TOS of the user's ISP so that the user does not get banned, and providing some sort of remuneration if illicit activity through the proxy causes problems for the primary user, and then _maybe_ you could call this all not shady as fuck.
        • ryandrake2 hours ago
          If only ISPs would actually crack down on (usually unwitting) users whose systems are participating in a malicious botnet or otherwise have their networks compromised. They could offer temporary disconnection + anti-malware support to get the user cleaned up, if they actually gave a shit.
          • walrus012 hours ago
            No residential last mile broadband ISP at the scale of hundreds of thousands or millions of customers is presently willing to spend the salary/benefits/fully loaded employee cost on the massive teams of (somewhat technically clued in, not low wage) people it would take to effectively implement this.
      • krackers2 hours ago
        Apparently at least one of the apps mentioned does that. From the article

        >A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node.

        • ryandrake2 hours ago
          I wonder how informed the end user actually is, and if it's disclosed to them what kind of content might pass through their network as a result of agreeing.
          • charcircuitan hour ago
            Most traffic is normal scraping like checking amazon prices.
      • cognitiveinline2 hours ago
        No need of (2) and (3) - the user can choose to not install/use the app. (1) is the right fair boundary.
        • ryandrake2 hours ago
          Those apps just shouldn't exist.

          I don't know how "join your users to a botnet" became some kind of legitimized monetization scheme. Ads are bad enough. What's next? "Participate in a DDOS in order to use our app?"

          • Dylan16807an hour ago
            Sometimes it's botnet, sometimes it's just accessing netflix without hitting big IP range bans.

            If there are proxy apps that only do the latter sort of work than I'm actually in favor of them existing and being widespread.

          • NopIdoN2 hours ago
            "train our machine to identify traffic lights" or something
      • LoganDark2 hours ago
        Some residential proxy providers offer a few cents for the use of your network.
    • oasisbob2 hours ago
      No.

      I'm surprised Comcast or some other ISP doesn't step in with a claim of tortious interference. Reselling or granting access to the ISPs services like this is almost always against the ISPs terms of service.

      The consumer is in no place to consent to this exchange.

      • Dylan16807an hour ago
        On the other hand if you want to resell 2% of your bandwidth the ISP shouldn't have any say in that.
        • ButlerianJihad24 minutes ago
          Oh yes they can. If I'm a consumer, I pay for my connection that is sold to me and held in my name. I have no right to "resell" or "sublet" part of that. It is usually spelled out in the Terms of Service or Acceptable Use Policy.

          At the very least, consumer connections explicitly disallow "Commercial Use". That means that you can't use them to run a business. You can't use them to turn a profit. You can't use them to generate revenue. That means no running servers, and that means no "reselling 2% of your bandwidth" for a few pennies because some Euro-Trash-Stranger wants to borrow it!

    • nullsanity2 hours ago
      [dead]
  • boredatomsan hour ago
    Tell your relatives, buy an apple tv
    • amliban hour ago
      I don't think apple makes actual tvs
      • boredatomsan hour ago
        Whats your point exactly? Are you purposely being obtuse?

        Plenty of uninformed people let their tv on the network, they shouldn’t. A separate box should instead. Tell me I'm wrong?