• kreskin@lemmy.world
    link
    fedilink
    English
    arrow-up
    154
    ·
    1 day ago

    Go to any mid sized or larger company and run a port scan and you’ll be immediately found and taken to the woodshed or fired.
    But I guess doing it unannounced in peoples home is just fine.

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        37
        ·
        1 day ago

        You wouldn’t add them to the network. HDMI to the conf room table or a dedicated phone controller. Maybe an HDMI matrix.

        Forget the TV calling home for advertisement info, i’m worried about holes in their screen mirroring and microphone that would let people snoop from the floors above/below me. If we need smart features, we tie them to either real media hardware, or plug them to a small computer.

    • rumba@lemmy.zip
      link
      fedilink
      English
      arrow-up
      25
      ·
      1 day ago

      Media bullshit at work gets its own isolation VLAN.

      If they were serious enough to buy serious equipment, I wouldn’t have to do it. I’d still do it, but I wouldn’t have to.

      • JustEnoughDucks@slrpnk.net
        link
        fedilink
        English
        arrow-up
        22
        ·
        1 day ago

        They literally run speech to text, store it and exfiltrate it to their servers…

        Even if you deny internet access, it can hop to other smart devices of the same brand using hidden SSIDs and exfiltratr data that way, or if the TV gets sold and connected to a network, all of the stored conversations will get sent to their servers. This was from the original GN investigation and associated security researchers

        There isn’t really something one can network-admin a way out of it seems, sadly…

        • rumba@lemmy.zip
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          1
          ·
          21 hours ago

          is there any actual evidence of

          it can hop to other smart devices of the same brand using hidden SSIDs and exfiltratr data that way,

          because that’s a touch paranoid sounding

          • JustEnoughDucks@slrpnk.net
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            4 hours ago

            Capability

            Well this is something that every cheap WiFi chip can do in the last decade. Share WiFi through a hotspot. Hell, ESPHome does it by default just for ease of use and fallback debugging. Here is a very old project , dirt cheap chip that does it

            Ease of Implementation

            They already broadcast hidden SSIDs for direct connection for features like screen mirroring, etc… Researchers have exploited this exact thing for attack vector testing (though they weren’t testing the TV itself data ex filtration)

            There is no way, with all of the privacy intrusions + their blatant disregard for network security (See GN video) and LG’s own advertiser marketing claims, that they don’t do that.

            Other “sounds paranoid” things companies are doing

            It isn’t like “they are tracking you in your own house from WiFi through your walls” (which now ALSO has been proven correct and is now an advertised “feature” for american ISPs) yet here we are. https://www.sciencedaily.com/releases/2026/05/260522023127.htm, https://en.wikipedia.org/wiki/WiFi_Sensing, https://www.theverge.com/news/981381/comcast-xfinity-shield-wifi-motion-sensing

            Automatic content recognition is also done by every manufacturer and also a “very paranoid” thing 5 years ago.

            Not to mention literally this whole wiretap scandal that OP report is from.

            From the original report itself, they also constantly scan all devices on the network, Bluetooth, and in the free bands their radios can pick up and log them so they know every device that has passed in their range, characteristics, and WiFi + Bluetooth geolocating is quite a standard practice for years for “increasing location accuracy”

            LG themselves bought a company that links your real identification from retailers to a unique product number so LG will be able to actually be certain that a specific person is associated with the spied data instead of a guess based on accounts. (Also in GN investigation video 1)

            Profitability

            From their own financial reports as highlighted in the original investigation, LG’s profits from TV-based selling to advertisers and data brokers is literally more than their profits from selling the TVs themselves.

            What else would stop them?

            So we have established that it is dead simple, cheap, functionality already built into other features and profitable. The only other motive left would be ethics, but from the research by GN (reported on in the OP), they simply spy on you anyway, and when caught because that is illegal, they got a slap on the wrist (see US Texas lawsuit settlement), and changed their terms of service to say “you give your and everyone in your household’s express consent to comply to your local wiretapping laws” (using exactly the language “wiretapping”. So we can also establish that they have absolutely no ethics around data ex filtration, and no regard for legality and willingness to pay the small fines.

            What would be the motive for them to look at this feature and say “nah, we aren’t going to do that extremely easy thing”? Laziness would be the only one that I could see, in which case, it will appear in future models at some point.

            It is not as though they have to stream video through it, raw text data is incredibly small. A whole 300 page e-book can be around 1MB. It is uploaded in under 1 second and it is encrypted, so it blends in with other traffic.

            • rumba@lemmy.zip
              link
              fedilink
              English
              arrow-up
              1
              ·
              19 hours ago

              Keep in mind, they have to pay for those services, to identify traffic on your tv that’s presumably not registered to a meaningfull address.

              FireTV could conceivably do it because they own the ecosystem, but even then, that’s a low-bandwidth network and doesn’t tie you to a physical address, just that the traffic is in your general neighborhood.

              • lemming741@lemmy.world
                link
                fedilink
                English
                arrow-up
                2
                ·
                15 hours ago

                They don’t need an address, they have your Bluetooth MAC.

                My point is, they’re all trying to create Networks that only they control, and you cannot stop

      • nfh@lemmy.world
        link
        fedilink
        English
        arrow-up
        9
        ·
        1 day ago

        VLAN? Why would you let a monitor have a network connection? Grab the Mac address, and put it on a denylist so you don’t accidentally give it an IP address as part of your setup procedure.

        • rumba@lemmy.zip
          link
          fedilink
          English
          arrow-up
          5
          ·
          1 day ago

          smart boards, remote power off. I generally prefer (as I mentioned in other comments) to run them from PCs or an HDMI matrix, but I’ve had reasons to network-connect some here and there.