cross-posted from: https://lemmy.world/post/51634640
A new Gamers Nexus investigation found a retail LG TV actively scanning the local network for phones, laptops, smartwatches and other connected devices, while also capturing microphone audio when the screen appeared to be in standby. The investigation found voice data being stored locally even after the TV was disconnected from the network, with the queued data uploaded once connectivity returned. Researchers also uncovered webOS vulnerabilities that could potentially turn the television into a remotely controlled surveillance device. The really unsettling part isn’t just the advertising angle. It’s the fact that a consumer television can sit inside your trusted network, enumerate other devices, access a microphone, store collected data locally and communicate with external infrastructure. Put that same device in a corporate office, hospital, hotel or conference room and the security implications become considerably more serious. I went through the investigation in detail, including the network scanning, microphone behavior, ACR, webOS attack surface, offline data collection and practical mitigations



Mh. What about… creating a guest network, connecting that abomination to that and deleting the guest network? Hopefully it can remember only one…
Why wouldn’t a company this dedicated to advertising just install a cheap cell network modem in them? You’re talking pennies on a device that costs hundreds of dollars.
While this is possible, ongoing network costs are involved with that. Also, hard to hide a cell network modem.
Not so sure if that is done when many people connect their device to their WiFi anyway, if they are forced to because some settings can be changed only with the app?
My TV is wired to the router but blocked from WAN access.
Only connected to the internet to install jellyfin on it.