216,000,000 LG Smart TVs are spying on you - Gamers Nexus (www.youtube.com)
from newcool1230@lemmy.ml to privacy@lemmy.ml on 07 Sep 11:56
https://lemmy.ml/post/52408726

#privacy

threaded - newest

siravious@lemmy.world on 07 Sep 12:42 next collapse

I wonder if they just call a MS Win11 API to get their tracking ID just to make it a well rounded spy conglomerate

generator@lemmy.zip on 07 Sep 12:56 next collapse

And it’s no only LG, it’s all of them

“LG Isn’t the Only TV Company Spying on You” youtu.be/IvFu343KNek

e8d79@discuss.tchncs.de on 07 Sep 13:15 next collapse

These Smart TVs are hanging in lots of meeting rooms at companies around the world. I wonder how many IT departments thought about checking for this.

Ildsaye@hexbear.net on 07 Sep 14:17 next collapse

There are enterprise versions that cost a lot more, but come without the bloat or spyware, that are typically included in office installations at larger firms. Sometimes it is possible to obtain one for home use when an office is being renovated.

clmbmb@lemmy.dbzer0.com on 07 Sep 14:57 next collapse

They don’t care… Most of the “IT departmens” at the companies I worked for were not interested in security stuff besides the employees’ endpoints.

med@sh.itjust.works on 07 Sep 18:33 collapse

I used to work for an MSP (Managed Service Provider), can confirm. Security is something I had to redirect attention to on a day-to-day basis. Even then, the company was more concerned with appearance and audit compliance than security.

I have worked at IT companies that really did care about security, but those companies were driven by management and staff that personally cared about IT security. One of them was a certificate authority.

Here’s a story about physical security from before that time.

I once had equipment in a Data Center that was embedded in the 4th floor of an office building. There was a mantrap at the entrance, designed to prevent you from walking away with the main DC door open, or letting people tailgate in to it. One of the doors of the mantrap was a sliding door, disguised as a bit of the hallway.

The sliding door was locked with a maglock on the thin end, so when it fully closed, it locked and you couldn’t slide it open without a key card, from inside or out.

…unless you bumped in to it with your shoulder, which separated the lock and opened the door. Which, after it was figured out (about 1 month), happened all the time. People would get let in to the DC without a card that opened that specific door. (DC security control provisioned the main door was separate from building control, which managed the sliding door).

When they tried to get out later, they’d get stuck in the mantrap, then they’d wait for someone to let them out (pre-cellphones). That person would then show them the trick. This was so common they turned off the forced-lock alarm. This lead to the mantrap being useless, and people propping the DC door open for ease of access when moving stuff in and out.

This was put in place in 2001, and I visited the building last year in 2025, it’s still in place today.

It’s worth noting that this DC was shared by multiple competitive reinsurers, ISPs and financial agencies. The were no cameras outside or inside, and you could poke most server reset buttons through the rack cages with the ink cartridge of a ball point pen. Not everyone was shown that trick.

umbrella@lemmy.ml on 07 Sep 19:35 next collapse

we are not paid to care about TVs. or privacy at all, too “paranoid”.

so we don’t lmao.

DannyMac@sh.itjust.works on 07 Sep 20:17 collapse

Usually those are commercial models. Those shouldn’t have mics, but are usually connected to Ethernet/Wi-Fi for remote control or signage applications.

orca@orcas.enjoying.yachts on 07 Sep 13:41 next collapse

My Samsung TV will never see a WiFi password in its life.

comrade_twisty@feddit.org on 07 Sep 13:45 next collapse

Some have esims installed already for “telemetry”.

orca@orcas.enjoying.yachts on 07 Sep 13:57 next collapse

I have AdGuard running on the router as a preventative measure, and it’s an older Samsung Q65 that doesn’t have any confirmed 5g modules. I should probably block its MAC address for added security though.

Thunderbird4@lemmy.world on 07 Sep 18:28 collapse

I’ve read that DNS level blocking often doesn’t stop this kind of telemetry because it goes directly to an IP without a DNS query involved.

orca@orcas.enjoying.yachts on 07 Sep 19:33 collapse

Hey, good catch. I didn’t think of that.

Feyd@programming.dev on 07 Sep 14:40 next collapse

Can you provide a reference for this? While technically possible, I don’t think this has actually happened, and spreading misinformation is counter productive.

rollerbang@lemmy.world on 07 Sep 15:43 collapse

For real? You’ve got a source for that? Because that’s probably not cheap to do for continued use.

luipaard0011@lemmy.zip on 07 Sep 18:02 next collapse

Someday. Sounds crazy but someday it will be profitable to do it, like a Skynet rising

PushButton@lemmy.world on 07 Sep 18:43 collapse

I worked with IoT devices with a “5g” radio. The company had to pay a cellular contract just like anybody else.

I HIGHLY doubt LG is going to pay for that.

pHr34kY@lemmy.world on 07 Sep 23:32 collapse

I have an open guest network and the neighbour’s TV is on it…

orca@orcas.enjoying.yachts on 07 Sep 23:56 collapse

That’s wild. I guess I need to do a review of my setup…

pHr34kY@lemmy.world on 08 Sep 00:29 collapse

It’s completely isolated from my own network. Ironically, it would almost be safer to put my TV on it instead of my home network.

The annoying thing is that if I have a dedicated clanker VLAN, I can’t cast to my TV.

Aqarius@lemmy.world on 08 Sep 06:46 collapse

Yeah, I already blocked it from half the internet, as soon as I figure out casting it’s getting cut off completely.

BrilliantBadger@piefed.ca on 07 Sep 14:05 next collapse

And if you click the YT link, Google is spying on you. Sad no alternative is given, but that would hurt the bottom line, right?

bert@lemmy.monster on 07 Sep 15:23 next collapse

Open said link in your front end of choice

Save yourself the time you spent writing this

Profit

BrilliantBadger@piefed.ca on 07 Sep 15:40 collapse

Folks sure get cranky & defensive when the hypocrisy of their favorite “privacy” influencers cashing in on them is called out.

Talk the talk, but won’t walk the walk.

Sad.

SusanoStyle@lemmy.ml on 07 Sep 16:15 collapse

Look you are right, but everything that promotes awareness about privacy it’s a plus in my book.

Being the devil’s advocate, nexus gamer is not a privacy channel. They are a tech one that started doing some journalism and they seem to be new to the privacy side of things. This story come about after the monitor ad pop stuff.

Related rant: For me phones are way more scary, they are everywhere, and you have no control on your friends and family devices. You can´t ask everyone to buy pixels and install graphene os on them.

BrilliantBadger@piefed.ca on 07 Sep 18:31 collapse

Its an interesting topic of discourse, no?

And certainly some argument such as “more eyes” can be a valid part of the overall discussion.

For myself, I would counter that posting YT links in a privacy focused community is defeatist in nature. Literally rewarding a platform, influencers that actually have no genuine interest in the topic, other than they found a new crowd they can cash in upon.

Obviously I didn’t watch, but informed guess – the video was 10 times longer than it needed to be, filled with fluff to fit in ever more commercials and/or inline promotions?

Does anyone interested in privacy not know TVs are invasive & nasty?

Perhaps. So start a topic upon it, without feeding the beast you wish to slay. Its truly a good discussion. And much valuable input from those who have confronted it can be shared.

I do agree, phones are horrific, and none of my crowd cares about privacy. Running a degoogled OS, no microG, no play store, only open source apps. We all try to take whatever steps we can, and its not easy, including changing ones online habits, usually the biggest obstacle. Which makes putting YT links in these privacy forums insulting.

Seriously. That is my (unpopular) opinion. I call it my ongoing journey to walk the walk best as able.

One can be offended, or reflect upon their habits effecting real change. I’ll end my rants on this topic now. Cheers, mate!

SusanoStyle@lemmy.ml on 07 Sep 23:23 collapse

Yeah you are right, posting a youtube link was a bad call from op, even the rules on the forum frown on it. (First rule even!) A better approach would have been a summary or article with the important points.

And I have to be fair with you… you guessed right. The video is too long, I had to skip a lot since they were repeating the same things over and over. Worse part is that, my awareness pitch, fell flat. I just checked the comments in the video, half of the section reads like this:

“I wont buy from LG anymore” “FuckLG” “Thas why i don’t use tvs”

They didn’t understand that the problem is bigger than one brand or device, that there’s a whole system behind this. Nor the irony of being horrified of spying software while signed to google services.

Sigh… maybe i shouldn’t rush to be a devil’s advocate anymore… it always bites me back.

Anyways, I still think is important to reach people where they are, and youtube videos should help, it has reach and its were the more oblivious guys are. Although, it would have been really really nice from them to host it in a less hostile platform for everyone else.

Now like you, i will end my rant here. Loved yours, even if it was a little spicy, which may have offended some people. But there was truth there, and for me at least, made me reconsider some things.

Cheers!

SolarPunker@slrpnk.net on 07 Sep 14:58 next collapse

I’m wondering if something like a PiHole can “fake” a connection for these devices.

muhyb@programming.dev on 07 Sep 17:06 collapse

I don’t know about that part (though would like to know as well), this is currently blocked on my pi-hole:

<img alt="" src="https://i.ibb.co/v4JQYdQY/Screenshot-2026-09-07-at-18-02-15.png"> including my custom RegExs. This surely helps but there are domains constantly pop-up every now and then, so it’s not fool-proof.

ryper@lemmy.ca on 07 Sep 19:00 next collapse

It put my TV in its own group in pi-hole, blocked everything (.*) for that group, and then whitelisted what I wanted the TV to be able to get to.

muhyb@programming.dev on 07 Sep 19:11 collapse

I should try this. I presume you would need static IP on your TV?

ryper@lemmy.ca on 07 Sep 20:17 collapse

You can also add devices to groups by MAC address or hostname, but a static IP might be best.

I only need a couple of domains to work. My way could be a hassle if you need to figure out whitelists for a few services.

muhyb@programming.dev on 08 Sep 18:24 collapse

Yeah, I guess that would work too.

It is a hassle but usually only done once or at least between some intervals. My RegExs were also a hassle though.

DannyMac@sh.itjust.works on 07 Sep 20:24 collapse

I caught an app that my daughter’s school uses called ClassDojo that wouldn’t work at my company for some reason. I had to reach out to our security admin and it turns out it was doing DNS lookups by bypassing my company’s DNS server. I submitted a ticket to the company and they ended up either designing the app to fallback to the device’s assigned DNS or either probably doing something else shady. Idk, it works now.

My point is there’s more than one way to do a DNS lookup.

muhyb@programming.dev on 08 Sep 18:27 collapse

Yeah that looks suspicious.

It’s definitely not fool-proof, apparently they can bypass DNS for their connections too. On the other hand, IP block is a thing as well, so maybe it’s a double-edged sword for them.

FineCoatMummy@sh.itjust.works on 07 Sep 17:40 next collapse

While I haven’t heard about any TVs that do this, seems like only a matter of time until Tvs that won’t function unless they can contact the mothership.

It wouldn’t be hard to make it. Or w/e other consumer devices. Just gate all functionality behind the user “agreeing”. Most ppl will click OK on literally anything.

By clicking agree, you accept that we or our 1829 partners can break into your house, steal your shit, shoot your puppy, plant rootkits in all your devices, piss in your pot of soup, and set the place on fire before we go. Millions of ppl -> Clicks OK.

degen@midwest.social on 07 Sep 18:20 next collapse

Shit, I don’t even own that many TVs

PixeIOrange@lemmy.world on 07 Sep 18:25 next collapse

Must be loud for anyone listening if i flick against the tv (or phone or any other internet device) so i do it regulary to repel the cia 😡

Bluedragon012@lemmy.world on 07 Sep 19:08 next collapse

So, We should take lg employees hostage. Tell them we’re just extracting useful data to sell.

Or you know Luigi because let’s be real none of us getting a dime.

umbrella@lemmy.ml on 07 Sep 19:36 next collapse

i wonder what our stock phones are doing.

yaroto98@lemmy.world on 07 Sep 23:13 collapse

All this and more.

umbrella@lemmy.ml on 07 Sep 23:51 collapse

next time you are setting up your samsung phone, give the agreement a read.

motruck@lemmy.zip on 07 Sep 23:32 next collapse

All you need to know is the US military bas to block ad Ids on their soldiers phones to stop people from buying data with a credit card to find them.

It cannot continue to be acceptable for companies to track anyone and everyone at this level.

Manalith@midwest.social on 08 Sep 22:12 collapse

Absolutely wild that Sceptre seems to be the last brand without a smart TV, is generally cheaper, and has more ports than the Samsung one I bought a few years ago, which can’t be better than LG