newsfeeds.net

Sep 7, 2026 · 12 links

The television is the subject of this issue. LG Ad Solutions executives say on camera that LG "owns the glass," and Gamers Nexus spends two hours on what that means in practice: automatic content recognition on every input plus unpatched holes that turn the set into a listening device. RTINGS put the opt-outs under Wireshark and found they were not fake, but the same feature shows up as a legal agreement on one brand, a picture setting on another, and a menu item you find after setup on a third; declining on a Vizio leaves you with HDMI and coaxial. Spur unpacked 6,038 LG and Samsung apps and found 2,058 renting out the owner's IP address through Bright Data, Massive and Honeygain SDKs, often in shovelware published by the proxy companies themselves. Krebs has LG's ban, TechCrunch has Samsung's, arriving after a Samsung "Editor's Choice" Pac-Man was found carrying the code. Xe Iaso and ansuz report from the servers on the receiving end, where the scraper traffic comes from clean residential IPs and the only defense is banning your neighbors, and Include Security's June piece named the domains to block. Software Freedom Conservancy's GPL suit against Vizio went to a jury in August with ACR named as the thing owners would switch off if they had the source. Plus an EDID blocker for the HDMI cable, a solo developer's ad-free launcher that replaces the Google TV home screen, and Linus buying a 75-inch Sceptre with no operating system at all.

I bought a TV with NO 'Smart' Features (Linus Tech Tips)

youtube.com

"I don't need my TV to be yet another computer to serve ads to me and steal my data. I already got a bunch of those!" The test unit is a 75-inch Sceptre, close to the only current brand still shipping a large 4K panel with no OS. The review is the trade-off made concrete: what a set costs in picture and features when nobody is subsidizing the hardware with your viewing data.

Yearslong fight over users' right to tweak smart TV software heads to trial

arstechnica.com

Software Freedom Conservancy bought seven Vizio TVs, sued in 2021, and asks a California jury to rule that any Vizio owner is a third-party beneficiary of GPLv2 and can demand the complete, buildable source of Vizio OS. "Access to the full code would allow users to make meaningful changes to how their TVs work, including limiting ads or deactivating automatic content recognition." Vizio's defense is that "SFC is not an intended third-party beneficiary." webOS, Tizen and Roku OS are all Linux-based, so the ruling reaches past Vizio. Trial was set for August 10.

Nearly half of LG smart TV apps contain residential proxy SDKs

spur.us

"We scanned 6,038 of them across LG and Samsung; 2,058 were selling your IP address." Not store descriptions, the unpacked webOS and Tizen packages, fingerprinted for Bright Data, Massive and Honeygain/Oxylabs SDK files. Bright Data-named publishers account for 367 apps on their own: "The app is the wrapper. The residential IP is the product." The SDK ships a blocklist for private ranges, which proves the point: "The boundary is not technical; it is enforced by the proxy company's customer vetting." Amazon bans the category and Roku blocks it. LG and Samsung had not, until this report.

Bitflinger TV: an ad-free smart aggregator and TV launcher

bitflinger.net

A solo developer's replacement for the Google TV home screen. "Replaces your launcher and starts on boot (Android TV only) — your content first, ad-free," with one catalog across your subscriptions showing where a title streams and what it costs. Free tier, or $2.99 a month. "We never sell subscriber data." The limit is structural: it sits on top of Android TV, so it removes the ads you see, not the telemetry underneath. The Show HN drew two points and no comments.

Probably check on your smart appliances

xeiaso.net

The Anubis author looks at who is hitting the honeypot. "80-90% of the hits created by the honeypot feature are from IP addresses that do not belong to any existing threat monitoring lists." Over 2.6 million unique IPs across 229 countries, and 89.3% clean by every reputation database. "If I had to guess where most of this traffic is coming from, it's from compromised smart appliances contributing traffic to proxy networks." That is why IP reputation stopped working as a scraper defense.

Smart TV Tracking: we tested whether ACR opt-outs work (RTINGS)

rtings.com

"We found that ACR opt-outs were not fake. When we could clearly identify ACR-related traffic, turning the setting off generally stopped it. But on many TVs, ACR-related data was hard to separate from other background communication, and the path to saying no was inconsistent, confusing, or tied to feature trade-offs." Samsung, Sony and LG showed a clean before-and-after in Wireshark. TCL did not. "Privacy shouldn't require turning a smart TV into a weekend networking project."

ansuz: Bright Data and the smart-TV botnet

gts.cryptography.dog

A self-hoster's view from the receiving end. "Consumers buy these appliances, and then have to choose between watching ads or agreeing to some terms of service... their 'Smart TV' becomes a part of a bot-net which is leased out to Bright Data's customers." The only viable defense is long-lived IP bans, and since IPs are shared, "people might find that their ability to access the web is negatively affected by something like their roommates' choice of TV brand." The demand, as he reads it, "seems to be coming almost entirely from people collecting data to train various types of 'AI'."

LG to ban residential proxies from smart TV apps

krebsonsecurity.com

LG: "A residential proxy network is not an intended use for LG smart TVs... If this option is not removed, these apps will be suspended." Bright Data's defense is that "Every peer opts in through a dedicated screen and receives value in return; every customer is vetted." Spur's answer: "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," and the person tapping accept may be a minor.

Samsung bans smart TV apps that share users' internet connections with strangers

techcrunch.com

A Pac-Man game Samsung itself featured as an "Editor's Choice" carried Bright Data proxy code that switched on once a user accepted a consent screen. Mnemonic's Harrison Sand: "What was reviewed is not necessarily what is running," and "A simple code change on a web server could instantly activate hundreds of millions of smart TVs into a potentially malicious botnet." Traffic analysis pointed to "large-scale scraping of LinkedIn profiles, and for collecting AI training data."

Stopping the smart TV from being used against you

s-config.com

The vector most guides skip is the HDMI cable. Through EDID, the TV identifies itself to a connected laptop and can trigger driver and companion-software installs on the PC that never asked for them: "Malware, by definition, is software you never asked for and was installed without your permission." The fixes run from never giving the set a network connection, to DNS blocking at the router, to an EDID blocker on the cable so the laptop never learns what brand it's plugged into.

Why Smart TVs Track What You Watch: And Why It's So Hard To Stop Them

rtings.com

"Across the TVs we tested, essentially the same technology could appear as a legal agreement, a smart TV service, a picture-enhancement feature, or a setting available only after setup." Vizio was the starkest case: decline data sharing and the set is left with "only HDMI and coaxial inputs," and withdrawing consent later "required fully resetting the TV." Fire TV and TCL hid the controls under "Device Usage Data" and "Interactive Service," on by default.

216,000,000 Spy TVs | The LG Smart TV Problem (Gamers Nexus)

youtube.com

Two-hour Gamers Nexus investigation into LG's webOS sets. The first-party ACR (automatic content recognition) "can pry into your personal life with greater precision than you might realize," and LG Ad Solutions executives say on camera, in their B2B pitches, that LG "owns the glass." Not the buyer. The back half documents unpatched vulnerabilities that can turn the TVs into "covert listening devices," so the ad platform and the attack surface are the same product.

Tags: smart-tv · tv · proxies · advertising · research · scraper · security · hardware · privacy · video · ai · howto · infosec · infrastructure · legal · open-source · opsec · rights · surveillance · tool · tracking