Hacker News new | past | comments | ask | show | jobs | submit

GamersNexus and LG: Or why rooting your TV is a bad idea

https://leaflet.pub/p/did:plc:yhgc5rlqhoezrx6fbawajxlh/3muwrqenzfk2n
I think the author took the wrong message from the video.

His arguments are all

- yes everyone does this not just lg; :)

- yes it can be used to track the user; but unless you literally go into lg ads hq, you can’t say they don’t

- they rooted to trigger this; well the os and system apps don’t need root, we need it to observe.

If the author is here please consider these as the reasons to why an LG customer would be mad.

- They did not knew LG has an ads subsidiary, whose CEOs and executives constantly go on investor meetings claiming “they own the glass”, “they own the living room”, “they own the network and devices” in the “lg household”

- if the above was said by lg tv division it would have still stung less. This was said by an ad company they didn’t knew existed nor did they agree to be associated with when they bought a home appliance.

Stop focusing on the technical details, look at the larger picture.

loading story #49606694
loading story #49606358
loading story #49606424
loading story #49606603
loading story #49605889
Thanks for the write-up, it reflects my own impression of the video.

The video is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across.

They should have decided to set the focus on a specific area and then present every finding around that, i.e.:

1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.

2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.

3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.

All the points and scenarios in the video might be valid, but they jump between those scopes and imply that its all the same, weakening the whole investigation.

If I'm LG and forced to respond to this, I can easily focus on dissecting the voice-input topic as a mere demonstration of the feature and how rooting the TV beforehand just showed the local process of handling it, steering the narrative away from the (IMO) much more important topics...

Yeah if GN wants to keep my attention on this topic they need to edit out all the stuff about normal Wi-Fi stack behaviors and normal local device discovery behaviors. They didn't need to pad their feature-length video with these non-issues.
And how they asked the device for voice-input for a websearch via the UI, and the device proceeded to perform voice transcription, filling the searchbox with everything that was said...
They are pretty infamously overly verbose.
GN has sadly been trending towards overly long, rambly clickbait videos in recent years, in line with the rest of Youtube. Most of their videos could easily convey the same information with a third of the length.

It's unfortunate, because they're one of the few voices speaking out about issues like this.

loading story #49606104
This reads like a PR crisis management firm planted article. it probably isn't, but it reads like one. It muddies the waters with vague implications and suggests we cannot infer anything from encrypted packets. If your screen is showing content sourced over HDMI and the packets are heading to the ACR endpoint, I think it's safe to infer HDMI is being ACR'd.
loading story #49605870
loading story #49605888
loading story #49605990
loading story #49606646
loading story #49605986
loading story #49606621
loading story #49606223
loading story #49606014
loading story #49606021
loading story #49606560