If you've got an Apple TV set-top box, that's not enough to protect your privacy if you have an LG television. Unplug Ethernet and tell it to forget your Wi-Fi information.
Smart televisions have a history of being a privacy problem for users. Repeated reports have surfaced over the years about them logging how you use the television, as well as misusing sensors intended to monitor the viewers.
In a September investigation by Gamers Nexus posted to YouTube, LG's smart TVs still continue to be a privacy nightmare. It's pretty bad, given that some models are capable of eavesdropping on your conversations.
Working with security researchers and Level1Techs, the lengthy video put LG OLED televisions under a microscope. Using various tools, including capturing packets with Wireshark, it was found to be conducting a wide array of actions that disregard user privacy, and then sending that data back to LG.
An ad problem
The LG televisions have a function to feed advertising personalized to the user through the smart TV interface. While you can expect that the software can pick up on usage habits to fuel the advertising machine, LG's system goes beyond mere interactions.
As previously discussed, smart TVs also use technology referred to as Automatic Content Recognition, or ACR. Not satisfied with knowing the name of a show or a channel being watched, the feature instead snapshots the screen or audio bytes, which are then analyzed by external servers.
However, it also collects data from the users themselves. Using microphones as part of the setup, such as the one in remote controls, it is capable of recording and transcribing conversations.
Again, these snippets can be sent over to LG Ad Solutions for marketing purposes. That LG arm says it has data from 216 million LG smart TVs around the world, including 49 million in the United States.
That's bad enough. But, as always, it gets worse.
A security nightmare
While the collection of usage data is one thing, the research uncovered many different areas where the tested TVs captured data that probed a little too deep into the user's private life. This included:
- Plaintext transcripts of conversations containing sensitive information that are unconnected to active TV use, namely speech that wasn't a verbal command
- Snippets of audio recorded by the TV
- Recording using a connected webcam
- Recording while the TV appeared to be turned off
- Crawling the user's network for devices
- Determining the TV's geographic location
- Wi-Fi signal strength and channel numbers of nearby networks within range
During testing, the crew was able to see that the smart TV is actively scanning the local network for other hardware. This can include other LG hardware, but also other items like smartphones and smartwatches.
This network snooping also extends to determining the strength of nearby Wi-Fi networks and the accompanying network data.
More troubling is the microphone usage. During testing, the team discovered that the television was able to capture audio from a microphone, even when it was seemingly in standby mode.
That data could be accessed remotely, but it was stored locally when disconnected from the network. When reconnected, the audio was uploaded once more.
Even worse, vulnerabilities in webOS, LG's choice of operating system, allowed the team to pull the audio data and listen in. This effectively makes the smart TV a potential snooping device to a bad actor.
Testing also indicated it didn't necessarily need to just use any included microphones for monitoring. When using a display as a computer monitor, it was capable of getting audio from a connected webcam.
This data was also found to be transcribed to plaintext in memory. Test phrases such as "LG my social security number is..." and "My credit card information" were found in logs.
Make your smart TV dumb now
While the vulnerabilities are being worked on by LG, its practices of capturing user audio and slurping tons of data for remote analysis is a big problem. It's also one that is extremely widespread, since LG's ad features have been around for years.
It's also a process that can't be stopped by simply not using the smart TV functionality. Even if you primarily use an Apple TV with the TV, the same spying elements will be at play.
The only real way to stop this is to make the TV element dumb. You have to both disconnect the physical Ethernet connection if it's hooked up, and turn off the Wi-Fi through the TV's settings.
If you're adept enough at managing your home router, you can block connections at a network level with some firewall rules. This will certainly help if you have multiple LG televisions at home or in an office, as it will cut the connection even for screens you can't directly access.
Even then, it's still going to be locally storing snippets of its snooping data.
While users are seemingly able to tolerate usage-based snooping with little in the way of issues, discovering that audio is being captured and shared in such a blatantly insecure manner is a big problem that needs addressing.
It should've been addressed years ago. But until the public is appalled enough by the snooping possibilities, or the snooping isn't financially worth it to LG, it will continue to be an issue.


