cross-posted from: https://lemmy.world/post/51634640

A new Gamers Nexus investigation found a retail LG TV actively scanning the local network for phones, laptops, smartwatches and other connected devices, while also capturing microphone audio when the screen appeared to be in standby. The investigation found voice data being stored locally even after the TV was disconnected from the network, with the queued data uploaded once connectivity returned. Researchers also uncovered webOS vulnerabilities that could potentially turn the television into a remotely controlled surveillance device. The really unsettling part isn't just the advertising angle. It's the fact that a consumer television can sit inside your trusted network, enumerate other devices, access a microphone, store collected data locally and communicate with external infrastructure. Put that same device in a corporate office, hospital, hotel or conference room and the security implications become considerably more serious. I went through the investigation in detail, including the network scanning, microphone behavior, ACR, webOS attack surface, offline data collection and practical mitigations

you are viewing a single comment's thread
view the rest of the comments
[–] 9 points 18 hours ago (1 child)

Apparently not solved. They can connect to open (and hidden) networks without your consent.

Per the marketing chief at LG; (paraphrased, from memory) "we own the glass, and we know everything beyond the glass."

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 18 hours ago (3 children)

    They can connect to open (and hidden) networks without your consent.

    That's a wild claim and either I accidentally skipped a paragraph in the article or you should cite a source. Quick googling doesn't show up anything of that sort for me.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 1 point 1 hour ago

    I don't have any specific evidence on hand, but I do know a lot about the technology and companies involved from working in adjacent fields (cloud architecture) and it is absolutely plausible that they can and do. If they are not doing it already (and I believe it is highly doubtful that at least some devices do not already do this) then it is certainly on their roadmap. Many consumer IoT/media devices have invisible, hidden wireless networks built in and have for years. If it's advertised, it may boast some sort of "quick connect", "auto configuration" or other convenience feature, it may be genuinely required for low-latency/quality-of-service (for example on most modern TV services which supply the channels by IPTV behind the scenes), but it's always on, it's always listening, and it's only a friendly partnership agreement away from being used for whatever "legitimate" purposes a company may dream of.

    Tech surveillance is extremely out of hand and has gone so far beyond anything would consider reasonable, I understand that you would instinctively reject it as too extreme to be believable. But in the industry it's completely normalized and they don't even give it a second thought, it's just business as usual.

  • source
  • parent
  • [–] 1 point 5 hours ago

    Look for articles about amazons sidewalk network and devices that connect to it without any kind of authorization from users.

    That shit has been around since the echo came out and it’s open to any manufacturer.

    There’s are lots of articles but my phone is too slow to load them at the moment.

  • source
  • parent
  • [–] 1 point 18 hours ago

    I'm looking for a source as well. The "apparently" I used was supposed to cover the whole comment, but I can see how it didn't.

    The video goes into detail, and could be staged, but comments seem to support the idea anyway.

    Amazon devices are known to do this with other Amazon products to create a mesh.

    It's not outside the realm of possibility.

  • source
  • parent