top 50 comments

sorted by: hot top controversial new old
[–] 89 points 3 days ago (5 children)

These Smart TVs are hanging in lots of meeting rooms at companies around the world. I wonder how many IT departments thought about checking for this.

  • source
  • hideshow 5 child comments
  • [–] 40 points 3 days ago (1 child)

    They don't care... Most of the "IT departmens" at the companies I worked for were not interested in security stuff besides the employees' endpoints.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 17 points 3 days ago

    I used to work for an MSP (Managed Service Provider), can confirm. Security is something I had to redirect attention to on a day-to-day basis. Even then, the company was more concerned with appearance and audit compliance than security.

    I have worked at IT companies that really did care about security, but those companies were driven by management and staff that personally cared about IT security. One of them was a certificate authority.

    Here's a story about physical security from before that time.

    I once had equipment in a Data Center that was embedded in the 4th floor of an office building. There was a mantrap at the entrance, designed to prevent you from walking away with the main DC door open, or letting people tailgate in to it. One of the doors of the mantrap was a sliding door, disguised as a bit of the hallway.

    The sliding door was locked with a maglock on the thin end, so when it fully closed, it locked and you couldn't slide it open without a key card, from inside or out.

    ...unless you bumped in to it with your shoulder, which separated the lock and opened the door. Which, after it was figured out (about 1 month), happened all the time. People would get let in to the DC without a card that opened that specific door. (DC security control provisioned the main door was separate from building control, which managed the sliding door).

    When they tried to get out later, they'd get stuck in the mantrap, then they'd wait for someone to let them out (pre-cellphones). That person would then show them the trick. This was so common they turned off the forced-lock alarm. This lead to the mantrap being useless, and people propping the DC door open for ease of access when moving stuff in and out.

    This was put in place in 2001, and I visited the building last year in 2025, it's still in place today.

    It's worth noting that this DC was shared by multiple competitive reinsurers, ISPs and financial agencies. The were no cameras outside or inside, and you could poke most server reset buttons through the rack cages with the ink cartridge of a ball point pen. Not everyone was shown that trick.

  • source
  • parent
  • [–] 8 points 3 days ago* (last edited 3 days ago)

    There are enterprise versions that cost a lot more, but come without the bloat or spyware, that are typically included in office installations at larger firms. Sometimes it is possible to obtain one for home use when an office is being renovated.

  • source
  • parent
  • [–] 33 points 3 days ago (2 children)

    i wonder what our stock phones are doing.

  • source
  • hideshow 2 child comments
  • [–] 55 points 3 days ago

    And it's no only LG, it's all of them

    "LG Isn't the Only TV Company Spying on You" https://youtu.be/IvFu343KNek

  • source
  • [–] 21 points 3 days ago

    All you need to know is the US military bas to block ad Ids on their soldiers phones to stop people from buying data with a credit card to find them.

    It cannot continue to be acceptable for companies to track anyone and everyone at this level.

  • source
  • [–] 39 points 3 days ago (12 children)

    My Samsung TV will never see a WiFi password in its life.

  • source
  • hideshow 12 child comments
  • [–] 22 points 3 days ago* (7 children)

    Some have esims and 4/5g modules installed already for "telemetry".

  • source
  • parent
  • hideshow 7 child comments
  • [–] 11 points 3 days ago (2 children)

    For real? You've got a source for that? Because that's probably not cheap to do for continued use.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 12 points 3 days ago (2 children)

    I have AdGuard running on the router as a preventative measure, and it’s an older Samsung Q65 that doesn’t have any confirmed 5g modules. I should probably block its MAC address for added security though.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 7 points 3 days ago (3 children)

    I have an open guest network and the neighbour's TV is on it...

  • source
  • parent
  • hideshow 3 child comments
  • [–] 3 points 3 days ago (2 children)

    That’s wild. I guess I need to do a review of my setup…

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 3 days ago (1 child)

    It's completely isolated from my own network. Ironically, it would almost be safer to put my TV on it instead of my home network.

    The annoying thing is that if I have a dedicated clanker VLAN, I can't cast to my TV.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 23 points 3 days ago (3 children)

    Watched this last night. I'm wondering if I could make money lobotomizing smart TVs. Remove the WiFi antenna and either remove the mic or put a actual hardwire switch to it.

  • source
  • hideshow 3 child comments
  • [–] 14 points 3 days ago* (2 children)

    You'd have to test whether the TV's firmware allows it to run without the microphone or WiFi. Some manufacturers will anticipate people trying to control their own tech and shut their device down at any sign of tampering.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 12 points 3 days ago

    While I haven't heard about any TVs that do this, seems like only a matter of time until Tvs that won't function unless they can contact the mothership.

    It wouldn't be hard to make it. Or w/e other consumer devices. Just gate all functionality behind the user "agreeing". Most ppl will click OK on literally anything.

    By clicking agree, you accept that we or our 1829 partners can break into your house, steal your shit, shoot your puppy, plant rootkits in all your devices, piss in your pot of soup, and set the place on fire before we go. Millions of ppl -> Clicks OK.

  • source
  • [–] 12 points 3 days ago (7 children)

    I'm wondering if something like a PiHole can "fake" a connection for these devices.

  • source
  • hideshow 7 child comments
  • [–] 11 points 3 days ago (6 children)

    I don't know about that part (though would like to know as well), this is currently blocked on my pi-hole:

    including my custom RegExs. This surely helps but there are domains constantly pop-up every now and then, so it's not fool-proof.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 6 points 3 days ago* (3 children)

    It put my TV in its own group in pi-hole, blocked everything (.*) for that group, and then whitelisted what I wanted the TV to be able to get to.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 2 points 3 days ago (2 children)

    I should try this. I presume you would need static IP on your TV?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 3 days ago (1 child)

    You can also add devices to groups by MAC address or hostname, but a static IP might be best.

    I only need a couple of domains to work. My way could be a hassle if you need to figure out whitelists for a few services.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 4 points 3 days ago (1 child)

    I caught an app that my daughter's school uses called ClassDojo that wouldn't work at my company for some reason. I had to reach out to our security admin and it turns out it was doing DNS lookups by bypassing my company's DNS server. I submitted a ticket to the company and they ended up either designing the app to fallback to the device's assigned DNS or either probably doing something else shady. Idk, it works now.

    My point is there's more than one way to do a DNS lookup.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 2 days ago

    Yeah that looks suspicious.

    It's definitely not fool-proof, apparently they can bypass DNS for their connections too. On the other hand, IP block is a thing as well, so maybe it's a double-edged sword for them.

  • source
  • parent
  • [–] 8 points 3 days ago

    So, We should take lg employees hostage. Tell them we're just extracting useful data to sell.

    Or you know Luigi because let's be real none of us getting a dime.

  • source
  • [–] 10 points 3 days ago (12 children)

    Even if you never connect to wifi TVs can seek out open connections, so is there a way to disrupt or weaken the wifi signal range on TVs without physically opening it?

  • source
  • hideshow 12 child comments
  • load more comments (11 replies)
    [–] 6 points 3 days ago

    I wonder if they just call a MS Win11 API to get their tracking ID just to make it a well rounded spy conglomerate

  • source
  • load more comments
    view more: next ›