And then your neighbor spins up an unprotected network or something like xfinity which they could have a deal with and it connects there and phones home anyways.

I hear this a lot “TVs will just connect to a nearby unprotected WiFi network!” But I ve never seen any evidence of it. It appears to just be speculation, unless you have an actual source?

Its always speculation that would be trivial to actually test.

1. Do not connect to network 2. Create unauthenticated WiFi network 3. Monitor WiFi network

Strange no one has ever done this simple af test to backup their claims

If TV manufacturers wanted to be underhanded then they could actually make this much harder to detect by delaying the connection to new unauthenticated networks for e.g. months or only after seeing another device connect and then using that device's MAC when it is not around.

Still super easily detectable even if they clone a MAC.

I have an unprotected guest network with a captive portal and an LG C1. I have never seen the LG pop up in the logs for the guest network.

Because they don't. It's too much guesswork, and honestly pretty complicated. From the user perspective the TV would appear to go offline every now and then, so also somewhat easily detected.

It's much easier to just throw a $10 5G modem in there, pay the $2/year subscription fee for service, and extract data that way. Assuming a 5-10 year relevant lifespan of the TV, they'd throw $20-$30 on top of the sales price for the modem and 10 years of service.

The 5G modem could run completely independent of the wifi network, be a completely different circuit, and you'd never know it was there.

Except they don’t do that either. I’m not aware of any TV that bundles a 5G modem. Are you?

almost all new cars have cellular modems reporting all kinds of shit, something like over 90% of new cars. what makes you think tv companies aren’t?

even the ones that aren’t yet, we’d be incredibly incredibly naive to think it’s not on their radar.

Cars having 5G connectivity is something that consumers actually want, it’s well documented on the spec sheets and marketing material, and obviously in a car WiFi is not going to work in most places. None of those things apply to TVs.

For one, you can take apart your TV and see that it doesn't have a SIM card

Can you spot a device like this : https://www.intersign.dk/cdn/shop/products/868e2a0dce897d05a...

The linked image shows a module meant for easy integration, but it could also simply be a part of the main board of the TV. They could "hide" the GSM antenna alongside the wifi antenna.

They could also use something like Amazon Sidewalk or ATSC 3.0's dedicated return channel.

They could (although I’m not sure of the 80Kbps that Amazon sidewalk allows is really sufficient for the purpose of uploading ACR data), but is there any evidence that any TV manufacturer actually is? The reality is, why would they bother? 95% percent of people that buy a “Smart TV” hook it right up to their WiFi as soon as they take it out of the box.

80Kbps is enough, after all they don't want to accidentally ddos their server.

ACR isn't generally a lossless 4K snap shot but indexed 32x32 pixel blocks from arbitrary locations on screen. In some cases it's even a fuzzy hash of the content source, and while 80Kbps isn't a lot, you can still push out data in a timely manner.

Seeing how things have recently been developing, I'd bet on it already being the case or at least in active development.

If you think its already the case, how come nobody can provide any evidence of it? As stated above, it’s trivial to test. Surely if Brand X was doing this, there’d already be blog posts, youtube videos, HN posts, etc. about it?

And what exactly would they use that particular access path for ?

I could see a threat if the TV had access to the internet and could establish a TLS tunnel or similar from the mothership, and execute commands on my LAN (or IoT network as it stands), and report back. That could establish a command & control channel that could potentially orchestrate an attack on my infrastructure via the TV.

However, reporting that "network X exists and has these devices" over a different network complicates things a fair bit. In theory they could still use the TV as a command and control platform, but it would have to switch networks between my closed network and the open network in order to execute commands and report results. Not saying it's impossible, just very unlikely.

Besides, the TVs are not alone in being cut off from the internet. I have two IoT networks, one for trusted devices (AppleTVs, Sonos, and the likes), and one for untrusted devices like TVs. They run on different VLANs, and anything on the untrusted IoT network can pretty much only talk to itself (client isolation) and the gateway, and there's no internet and no open ports to any other VLAN.

> And what exactly would they use that particular access path for ?

Uploading the weeks, months, or years of locally-stored activity [0] data? Text compresses really well and local storage used to be very cheap.

[0] ...mic voice transcription, how often you use the thing, for how long, and a best guess (because of lack of time sync) at when, "automated content detection" logs [1], names of files you've fed to the thing, -if equipped with a camera- number of people in the room and interesting information about them, etc, etc, etc...

[1] ...assuming that that can be done with data loaded from the factory, which I kinda doubt...

Two things:

1) What I called "automated content detection" is apparently called "automated content recognition", abbreviated as "ACR".

2) That weeks, months, or years of locally-stored activity I mentioned can also contain historical ACR records. Given that the audio and video of what's being displayed on the screen is "fingerprinted", those fingerprints can be saved just like everything else picked up by the "TV" and uploaded whenever the thing next has Internet connectivity. The "TV" manufacturer will lose the "what are they doing right now?" aspect of the feature, but the "what have they been doing?" aspect of the feature will work just fine.

Directly related is this section of this Gamers Nexus investigation, but the entire video seems to be worth watching if you're not rather familiar with the topic: <https://youtube.com/watch?v=6IFVTcM28KA&t=26m47s>