I've bought an LG Smart TV 5 years ago, read t&c where I was supposed to grant them any data they wanted, decided to disagree and kept all network functions disabled. I was ridiculed by my friends for that. At some point, I thought - maybe I'm really crazy to do so? Who am I, a caveman, a luddite? Oh well, I'm not. Not a bad tv though, many HDMI ports!
I have a similar reaction from folks when I don't trust services/devices. Most telling moment was when I refused to upload my license to LinkedIn because I lost 2FA (token on phone, phone destroyed). Microsoft assured me they would "delete the license as soon as it was verified". I've written too many software systems for too many companies, and I do not believe them.
Of course, they'd outsourced to AU10TIX, which did retain the licenses, and got hacked: https://www.404media.co/id-verification-service-for-tiktok-u...
That's from 2024, but we just had a larger breach with IDScan this week.
Sorry for the digression, but the common thread is how much to trust these companies, and my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want. Some paranoia is warranted, I think.
> my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want
Honestly, it's not even that extreme in most cases. I think it's usually not malice, it's incompetence.
That's why I don't trust big companies with my data. Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.
> I think it's usually not malice, it's incompetence.
Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.
why not both?
[flagged]
It's really not a hot take.
> Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.
I disagree with this as stated. Maybe in the right context you could make a case for it, but in general? Heck no. Intent matters a great deal, and there is no justice in treating someone incompetent (or negligent) the same as someone who is actually malicious. Both things are bad, but the latter is worse than the former even if they lead to the same outcome.
In the context of a company doing something like this, intent does not matter in the slightest.
One could say that simply incentives are wrong so people turn negligent and/or are out of their breadth on a topic.
But is there someone accountable for it being so? Are they malicious? Who is ultimately to blame?
> Intent matters a great deal,
The road to hell is paved with good intentions.
> Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.
The CEO is responsible for what their company does. If a major breach can occur through the oversight or "incompetence" of one worker, the CEO has already failed, whether through negligence or malice.
In China, CEOs go to prison or are executed. Not all the time, but enough. In the US, they are given a golden parachute and make more money at their next posting. There is mostly only failing upwards.
Will the CEO suffer consequences? It seems the worst they face is being fired with a golden parachute.
It's malice. Compliance tends to not "maximize the shareholder value". Why pay millions/year to maintain a compliance team when you can get away with paying a small fine from time to time?
It's probably both, vis a vis negligence. I just wish it was treated as criminal negligence. This will continue as long as CEO's face no real punishment for mishandling PII.
Pardon my French but bull-fucking-shit! A CEO _should_ take responsibility for what their subordinates do. It's preposterous to simple throw up our arms and say "oh well, some employees were sloppy so we lost some 100 million user IDs and other sensitive information that we promised not to store but we lied. Oopsie, silly me, pardon my wee incompetence tee-hee". No no no NO NO!
At some level, and certainly at the level where you get paychecks of 10 million a year for the "huge responsibility you are bearing", then incompetence IS malice!
Uhh. I think you misread my comment pretty badly here. I am not making excuses for anyone.
I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.
Both are inexcusable, but one is more common/likely than the other.
You can certainly link them together and yes leaders should be held responsible no matter what, but from my perspective as the user who had his data leaked, it doesn't really matter how/why it happened, does it?
> I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.
Not being held accountable for negligence or incompetence is the evil machination.
Everything you say should be true on any level playing field. Not in the British public sector where shambolic incompetence is the norm.
Replit was asking for my license to change email address. Jeez
Same here when they find out I’ve never had an FB/IG/X etc account. As though having that crap in your life is somehow mandatory.
People who make poor choices love to pretend that they had no choice at all.
1. Interaction with Meta is virtually mandatory in many places in the world. Try opting out of Meta when your kid's daycare or your building's group chat is on whatsapp.
2. It doesn't really matter if you opt out, because _other people around you don't_: they take pictures in which you show, they tag you, they talk about you, they send you links, etc. Which means they (Meta) build a shadow profile of you anyway.
The "personal responsibility angle" is pure fiction.
My building’s group is on FB. I’ve managed without access for over a decade.
I live a somewhat normal adult life and manage without having anything to do with Meta ¯\_(ツ)_/¯ I probably miss out on some things, but I don’t notice.
All my friends just contact me through other sources.
If you have kids, it’s more difficult - I can acknowledge that.
You’re assuming that my primary concern is my privacy rather than my sanity. I don’t understand how anyone can seek out a non-stop feed of the sort of people who routinely post on FB. I’ve seen exactly what the doom scroll does to people without them realizing it.
So yeah if a business requires me to have an account I’ll find a different business to patronize. Frankly if you’re expecting someone other than you to take responsibility for the media you consume, that’s a problem.
When are the victims going to start getting significantly compensated for these breaches?
They will keep happening as long as the consequences are just the cost of doing business.
It becomes tricky fast.
There is obviously a fine that could bankrupt the company: this would be a clear signal "do not do this".
There are also many cases where people have been doing everything they should have been, and still got hacked (zero days, for instance).
Now, I do not think people should only be slapped on the wrist in that case: it still needs to be significant so companies carefully decide to store only the data they really do need!
It will be when enough people elect enough politicians who take action against this weaponized incompetence and strip-mining of the peoples' assets.
Or, if that does not happen, when enough people rise up in revolution and take the compensation for themselves.
Or, never.
If enough people vote enough or revolt enough, they cannot be stopped. But the incentives for too few people rising up are too costly. They work hard to keep the equilibrium in that balance.
It’s okay to be a luddite. Not everything needs to have an interface.
Got into a spat with a manager at my apartment complex because I refused to install their app just to deal with a maintenance issue.
He was like, “I don’t see the problem, you have to use the Latch app to open your apartment door.”
To which I replied, “No, I have the door keypad code memorized.”
Just like I don’t need an app to make a log of exit/entry history in a backend database just to enter my apartment via a Bluetooth lock…
…I should not have to install their app to make my apartment livable.
Indeed, my argument was convincing enough to have a resolution which didn’t include installing their app.
It's not about being a luddite. In many respects I consider it the opposite. It's engaging with technology in a way that demands standards of behaviour and performance.
I don't want the new thing because it is the new thing. I want new things that are better.
People accept abusive technology because they consider that's just the way it is with this new thing. It's a failure to understand what should be considered unacceptable.
Does this app work on GrapheneOS? LineageOS? Android betas? Who will troubleshoot issues if it doesn't?
> you have to use the Latch app to open your apartment door
So what happens if you arrive home with a dead phone?
And possibly worse, they have a log of when you come and go?
I am a student and where I live most student housing has an app to open the door instead of a normal key. My current place used Bluetooth, the previous one was even more inconvenient because it used NFC. It sucks, and if you accidentally forget your phone at home you're fucked, but the landlords do it because it lets them block old tenants from entering without having to switch the locks.
You have a unique code, don't they already have a log of your coming and goings?
But I would absolutely not install an app for that.
Usually smart lock does not have network connection(due to using battery).
But the app on your phone does not have that limitation.
They do. But the apartment complex gets a nice little kickback, especially since an app for unlocking your front door is one that has at least a plausible argument for having your location, which means a whole bunch of location data that can be mined/sold/both.
> And possibly worse, they have a log of when you come and go?
Most apartment buildings in the US already use face-tracking cameras to get this log
My apartment complex came to install keypads and centrally managed smart thermostats and I would not let them.
Thankfully my lease was old enough that I was able to argue against it. I don’t want a 3rd party company tracking my habits, and I don’t want some manager boiling my pets alive while I’m gone because they decided they think our AC is set too low.
You got lucky. If you've got an apartment in, say, a healthcare facility, they'll install those thermostats and whatnot. Usually the neighbours are clueless about technology so complaining doesn't get very far at all.
It's even worse if some staff wrote paranoid in your file, 'cause they'll argue it's good for "exposure".
You mean if you are permanently resident in a mental institute they don't let you control the temperature? That's hardly surprising...
I read it more as a senior living facility.
Those folks pay out the effing nose, they ought to be allowed to control the temp in their apartment.
Some day, that could be you.
Nah, you're not crazy. I'm also someone who actually reads terms documents, because I find that they're often the only thing that will be truthful about a company's intentions.
And keeping it completely disconnected from the internet should be the default, in my opinion.
There is absolutely no reason to read those contracts any more. As Louis Rossman keeps pointing out, most of them now include the ability for them to change terms at any time. That's basically the null contract.
Since the legal system has once again failed to protect users from corporations, it's up to users to use technical means for self defense.
Depends on jurisdiction, just because someone wrote something in a contract doesn’t mean it’s binding.
In Poland/EU we have an (ever growing) list of forbidden clauses that even when written and signed by consumer are null and void. And I think these can be enacted retroactively - when corporations invent new shady clauses, government steps in and tells them these are invalid.
This helps to even out the consumer-corporation field.
> we have an (ever growing) list of forbidden clauses that even when written and signed by consumer are null and void
I'm pretty sure that's true almost everywhere. Law beats contract. The real question is how strong the laws are. In the US not so much because of small government and stuff, especially in red states.
The law matters very little when enforcing it in court often means a multiyear lawsuit against an opponent which employs an army of attorneys, has effectively unlimited amounts of money, will likely cost you ruinious sums of money, and for an outcome that's far from guaranteed.
You can do that too. You can show up, represent yourself and pay a few hundred dollar court fee, while the big company has to waste hundreds of thousands of dollars to defend themselves from you. You'll probably lose the case if you don't have a lawyer, but in a place like the US, you don't have to pay the other side's legal fees unless the case is frivolous (which it won't be).
>The law matters very little when enforcing it in court often means a multiyear lawsuit against an opponent which employs an army of attorneys, has effectively unlimited amounts of money, will likely cost you ruinious sums of money, and for an outcome that's far from guaranteed.
Or when you can't even enforce anything in court as you've already given up your right to spend all your money suing, as binding arbitration is the required and only mechanism to "resolve disputes." To make it extra fair, the corporation pays the arbitration firm for their "objective" decisions and not you.
What could go wrong?
Has it actually happened that someone went to court and the court told them no, you have to do binding arbitration? Or is it just something they put in the contract to scare you? Has anyone argued they didn't actually agree to what the country thinks they agreed to? You could start by just saying no, you didn't agree to that, and the company will have to prove you did.
In the Gamer's Nexus video, he gets drunk before accepting the terms so that it isn't legal consent. A drunk person can't enter a contract.
>Has it actually happened that someone went to court and the court told them no, you have to do binding arbitration? Or is it just something they put in the contract to scare you? Has anyone argued they didn't actually agree to what the country thinks they agreed to? You could start by just saying no, you didn't agree to that, and the company will have to prove you did.
Yes[0]. For over 100 years.
Next question?
[0] https://en.wikipedia.org/wiki/Arbitration_case_law_in_the_Un...
The US is not small government at all. It’s one of the largest governments in the world. It just exists almost exclusively to serve billionaires.
It’s “small government” when it comes to protecting your individual rights, and full flock powered ai surveillance state when someone has an abortion.
Funny how the type system works in a legislative framework: null AND void
I'm never going to interpret that one with a straight face.
That’s great! Because then you’re left with the simple task of raising it up with the government.
It’s actually the judiciary you’d bring it up with, I believe.
The judiciary is a branch of government. But more crucially, some countries have better consumer protection agencies, eliminating the need for people to go through costly court battles for common sense stuff.
Interestingly, in Brazil and I'm sure in some other legislations, those contracts are essentially void because there's a presumption the average person does not have the time, patience, or ability to understand every clause—so they are by definition unable to agree to their terms.
I'd love to have a similar standard applied in the US but I'm not holding my breath.
>There is absolutely no reason to read those contracts any more
For another perspective, check out the comment you're replying to.
At the very least, you can be sure they'll never change the terms of the agreement to be more beneficial for you, though.
So just treat it as a best case scenario, knowing that it can get even worse.
Just assume the worse then, save yourself some time.
Well yeah, that's kinda the idea, but sometimes it's nice to know what 'the worst' will entail
At this point every EULA or TOS change should begin with the heading:
We Are Altering The Deal. Pray We Don't Alter It Any Further
PS, my technical means are keeping my TV off the internet.
Which doesnt work. LG tvs will scan for availible networks. Someone setting up a new router within range briefly disables encryption and "your" tv will jump on that network and transmit all the stored data.
It is tinfoil hats time, at least for LG tvs.
I guess you could remove the wifi antenna, or otherwise brick the wifi reception ability (faraday cage, lead block, etc). Or - just boycott LG. I'll never buy any of that corporate espionage nonsense, ever.
Also: the US intelligence agencies used Echelon ages ago to monitor what vast swaths of innocent people were up to. I think it's sensible to presume they've got their hooks into these devices too.
Give it a network, but don't allow that network to access the internet.
If it can't phone home, it's not connected.
A technical solution would presumably spoof the spaff but with E2EE and DoH is it possible? So then what, hacking firmware? I guess then TVs get a hard lifespan limit.
I never understood why any of the smartness had to be built into the TV in the first place. Sure, it's useful for the first year, and then the seriously underpowered hardware they installed into it will have trouble with just about anything.
I bought a Philips Ambilight OLED TV probably over 8 years now. Brilliant tv, great quality, I still see no reason to replace it at all. But its built in AndroidTV is garbage.
Because it’s extremely profitable for them to serve ads and sell PI. Kind of like how the airline industry makes more money off credit card shenanigans than actual plane tickets.
Not relevant to the discussion but to your comment, Freakonomics Radio claimed "airline industry makes more money off credit card shenanigans" was not true
https://freakonomics.com/podcast/is-your-plane-ticket-too-ex...
WSJ and Wendover claim it is true.
> I never understood why any of the smartness had to be built into the TV in the first place.
Because technology got ever more complex. A TV of yore? That thing operated on (relatively) simple physics alone, at the cost of requiring an absurd amount of broadcast infrastructure to make sure a TV signal could be received across the country.
Modern TVs however... digital modulation schemes with a lot of signal processing wizardry allow TV reception with far less broadcast towers and far better quality. You got satellites and with these a myriad of control schemes (DiSEqC, Unicable, ...). You got Pay-TV that requires decryption. You got HDMI CEC to allow your TV to remote control your DVD player.
And all of that complexity requires firmware which means it can have bugs which means you need a firmware update capability and when you're at that point you can just go and slap something Linux on it and get all the apps for streaming services.
I hear you. This is exactly the reason why I have a digital signage display rather than a Smart TV.
Similar boat - Panasonic glass fronted TV. Circa 2013. None of the smart works anymore.
1080p, but the picture far outstrips most other TVs I've owned to this day.
I have zero plans to change it, and it's usefulness has outlasted the Chromecast that's connected to it.
Yes, I put the first ads on Smart TVs. Apologies.
It's so you buy a new one every few years instead of keeping the same TV for a decade or two. Capitalism cannot survive when products last a lifetime.
If that’s true, then why is capitalism still around? Should it have died out in a previous generation in which many products did last a lifetime?
It did. We are currently on the fourth or more reinvention of capitalism. It's like ethernet - every time networking technology changes, the new one is called the same thing as the old one. The current fiber-optic switched Ethernet has absolutely nothing in common with the original vampire-tapped coax with media attachment units clamped onto the cable and a serial-port-looking AUI interface running down from the ceiling to the computer. Same for capitalism.
> Capitalism cannot survive when products last a lifetime.
This is totally backwards; capitalism would do fine in such an environment (in the same way that evolution does fine in an environment where organisms live more than just a few seconds; the whole reason we have the notion of a "lifetime" is that our germ line comes from a long line of ancestral DNA that made organisms that outlasted their competition.)
Individual companies might have to hustle to innovate or die, but that too is good for capitalism.
Whoa!
I think maybe I stepped on somebody's agenda?
Both capitalism and evolution depend on the fact that over time, on average, less fit organisms/organizations are displaced by better alternatives. You may not like that, but down-voting anyone who points it out doesn't make it any less true.
Because having the TV play from streaming apps out of the box is pretty useful.
The problem is we've not enforced any strong regulation against ads, downgrade rights or hack ability.
I don't need "better performance" from the system built into my TV I just need it to run Kodi.
> I find that they're often the only thing that will be truthful about a company's intentions.
Really? Many years ago, I had to physically sign a license with Microsoft to obtain some software. The license was not consistent with the license included with the software. Both licenses effectively said they were the real license and that any other agreement you made with Microsoft was not valid.
I don't think there was any nefarious intent. It was likely to avoid a situation where Microsoft employees offered terms that were not approved of by the company. Still, it goes to show that it can be awfully difficult to judge the intent of a company.
I guess neither is valid then, you got the software for free.
Only good until the device starts using a neighbor's LG TV as access point, without telling you, for the sole purpose of upgrading itself and sending this "telemetry".
Zealous Autoconfig https://m.xkcd.com/416/
Non-mobile link: https://xkcd.com/416
Really?
Well that is how Airtags work.
Any iphone/ipad/mac nearby will act as a router for them[1]
Given that we have already established that LG is a shady company, I wouldn't put it beyond them to try to use the same trick.
[1]https://lifehacker.com/tech/how-apple-airtags-actually-work
That is not how AirTags work. They do not reach out to Apple servers at all.
AirTags broadcast an encrypted ID. Phones build lists of ID’s they’ve seen and send the list to Apple.
There is no routing, no ability to send arbitrary data, no active communication of any sort. It’s not a mesh network.
The link you posted makes that pretty clear.
An Apple airtag probably doesn't but it is apparently possible to send some data at a very low rate (the article in [1] says a few bits per hour) over the find my network [2]
[1] https://positive.security/blog/send-my
[2] https://github.com/positive-security/send-my
That's functionally the exact same thing, and if they wanted to send data they could encode it in the "ID".
uh, that is just all the iphones acting as a mesh network for airtag ID’s?
it means you can’t block the tracking by doing anything yourself - you’d also need to block everyone else’s devices too.
Mesh network typically means… a network. Unidirectional, best-effort, randomized IDs are not a network.
And of course you can block the tracking yourself, even though nobody is actually tracking because Apple can’t tell who owns what ID. Just turn off find my on your device.
It's also how Amazon Sidewalk works for many Alexa-enabled devices
Yeah and my worry is, TVs like this can use sidewalk to connect to when they are not provided with internet access by the user (either but plugging into ethernet or connecting WiFi). Leaving the TV with an always-available exfiltration channel for it's espionage of the user's viewing habits.
This is a really bad thing for those of us who until now have just not connected our 'smart' shit to the internet.
Where I live in the EU they don't do sidewalk otherwise I'd have to look at ways to fight it (disassociate connections or DDoS the devices providing sidewalk routing)
Forget GPS jammers, everyone needs a bluetooth jammer.
This. Why would you even connect TV to the network?
It is well known for like 5 years. Smsrt TVs go through your movies library, and upload screenshots and filenames to internet.
Some will start showing ads after firmware upgrade.
Watch the video the article is based on - not connecting to the internet doesn't keep you safe in many cases: https://www.youtube.com/watch?v=6IFVTcM28KA
"Watch this two hour long video" is not a particularly useful reply. If you think the TV can exfiltrate your data without an internet connection then you should be able to explain how it could do that in your own words.
Just because you didn't allow it on your local WiFi doesn't mean it did not connect to the Internet. Your neighbors might have a guest WiFi it can use. Or maybe it has a built-in cell modem. Your data is valuable, there's reason to put effort into getting it.
Wouldn't using a neighbor's Wi-Fi without anyone's permission or instruction violate CFAA or some other law?
Also, wouldn't this be trivial to test by just setting up your own network and seeing if the TV connects?
Xfinity (aka Comcast) routers broadcast a separate network for Comcast subscribers do use from their phone. I don't think it's unreasonable to think that Comcast and TV manufacturer's could have an agreement that would allow TVs to connect.
Using internet access doesn't seem to be illegal. If there's no password you can't even argue it was protected. Residential proxies are legal too (as they should be - fuck cloudflare).
They have permission from the provider, why they are able to log in.
Laws aren't enforced against large companies.
That's what the Ask button is for with the summarize option, to not have to watch unnecessarily-long videos. Apparently it does connect to public hotspots, often run by major providers.
This is because they rooted the TV.
They can just start a capture, record to RAM / storage, and retrieve it later when it is reconnected to the network.
Otherwise if it's disconnected, it is still hard to exfiltrate the data somewhere. Maybe they could get creative via Bluetooth, but then you would need a cooperating device in proximity of the device.
I think the main risk is that if you - or your kids, or your spouse, or a guest, or someone you give/sell the TV to - do connect the TV to the Internet for even a moment years from now, then all those logs you wanted to keep away from LG are likely to delivered.
> This. Why would you even connect TV to the network?
I happen to have a NAS with family pictures I like to display. I can (and do) firewall that thing, but then you hit other issues like the apps you need to show pictures and movies in the first place not to install/run.
I've yet to hear of a reasonable recipe to isolate and secure such connected TVs. And don't get me started on Chromecast or other Android dongles, I've no reason to expect better treatment from Google. Some open source hacked-together box, then?
Apple TV is the best one. No ads, full OS updates for a long time.
There are ads for ATV content.
No, there really aren't.
I turn on the device, the app in the upper left is selected and showing some content from that.
The device sits idle, I get drone footage of landscapes.
If I accidentally bump the wrong button on the remote and get sent into the Apple TV (streaming service) app, sure it advertises producte, but in general there are no ads.
In comparison, Google TV's homescreen is giant ads for content on services I don't subscribe to, Roku is at least as bad, Amazon is worse, and Samsung and LG......oof.
>In comparison, Google TV's homescreen is giant ads for content on services I don't subscribe to
I enable app-only mode on my chromecast and does not see any ads.
But on the Apple TV you don't need to enable or disable anything. There are no ads, there has been no ads and I'm pretty sure there will be no ads.
And the Nvidia Shield is also hot garbage in this regard.
I suppose my next device is an Apple TV or some kind of home brew Linux box.
The shield was great until Google forced ads into it, switched to Apple TV back then and no complaints since.
The shield is vastly superior to the Apple TV. You aren't trapped in Apples wall garden and can install any apps on it. Android TV comes with an awful launcher, but that is easily replaced. There's no sponsor block on Apple TV and there never will be.
No, it's not. Let's start with the disclaimer that I work for Google, not the Android TV team, all words my own, etc.
The Shield at launch was an amazing product - premium UX and hardware, premium price point. Google changed the experience to an ad-loaded mess without providing an opt out for those who had spent hundreds of dollars on the Shield.
I was dogfooder, a huge advocate of the product, and someone who had convinced others to buy the Shield and Android TV devices. That UX revamp and how the team treated their customers (internal and external) turned me off the product for life. I tried the various competitors (XBox, Roku, Amazon) before landing on Apple TV. I now own two Apple TV devices - both of which are still getting updates many years after I bought them - and will continue using them for as long as the product line is maintained.
People in this thread have talked about Apple's clean beautiful ad-free UX, but the apps themselves are far better. Apple sets customer-friendly App Store requirements *and enforces them*. That means:
* The back button always works. It will bring you back to the home page of the app and then to the system launcher. It will not get stuck in an endless loop of "are you sure you want to quit?" and just dismissing that dialog like multiple Android apps do
* No loud obtrusive sounds on app startup (YouTube, Netflix)
* The apps are first-class priorities for developers. Circa 2019, the Paramount+ app was an inconsistent mess where subtitles were broken on some platforms. The Plex app wouldn't transcode certain formats on the XBox, and so on. None of these issues are a problem on Apple TV. Not every app is perfect (Dropout, I love your content, but your app is awful), but none of them are worse than on any competing platform.
Apple TV is a truly incredible product and ecosystem and one that feels like a joy to use. That's not the case for Android TV (now Google TV, I think?) even with a custom launcher.
Perplexity Launcher is free and takes <2 minutes to install on the Shield or other Google TV devices and has zero ads. Being able to sideload apps that will never be allowed on the Apple TV is a major benefit for anything piracy adjacent.
I (and most users) don't care about that. Having a great app for YouTube and other services I use is far more important than being able to stream pirated content.
You can also use the VLC app on an Apple TV to have a free and slightly janky media server. Just drag and drop files through any browser on a computer.
The better Roku hardware I would say is a second best - you can block the as servers fairly easily and then you do have to disable all the crap on the homescreen.
Those aren't exactly cheap.
Just a cursory search on my local used stuff marketplace says I can grab a Gen 3 ATV for 10€. A 1st gen 4k (which is the one I have) is about 100€ and still runs the latest tvOS.
It's more expensive than a 40€ Chromecast, but also SO MUCH BETTER.
Obviously, as an advertising company, Google should have your utmost scrutiny. But as far as I know, their TV boxes don't ACR your content. If they were the only two options, sticking with your smart TV software instead of using a Google TV box would be a privacy mistake.
Typically you will get sambatv or such installed, and technicians for whatever reason tend to click accept/approve during installations. Happened to me n my Google TV thing
Tbf I was talking about first-party Google TV boxes (Google TV Streamer and Chromecast with Google TV.) Likely not perfect for privacy, but not pure evil like built-in smart TV firmware, they support sideloading without time limits, alternative app stores (Flicky/F-Droid) and they're friends/family/roommate/partner friendly with support for DRM-ed streaming apps, Chromecast and pairing with the official YouTube app.
I chose one over the Apple TV because I knew I wouldn't able to stand any limitations on sideloading. For a while I was running a custom build of Wholphin with patched libmpv/libplacebo to work around a bug before the fix was upstreamed. A device without the freedom to do that sort of thing would drive me nuts.
What technicians? When my TV was delivered they pretty much just unboxed it and set it on the floor, not even being willing to help mount it, let alone plugging it in.
You can always just connect your laptop (or some spare laptop) to the TV via HDMI. Not sure why you’d need to “hack together” something. A dedicated HTPC is nicer if you want to use IR remotes and the like.
Yeah, perhaps "hack together" is unnecessarily dismissive, but the experience to match is that of a single peripheral to control everything. The other area I have no interest expanding my knowledge into is the minefield of codecs, HDMI cables, GPU and drivers combos to have something outputting HDR and whatever Dolby's flavour of the month proprietary invention I inevitably come across.
Any SBC like Radxa Rock (cheap) to Orange Pi (powerful). 4k output, a linux you control, play retro games or stream torrent movies.
Not well.
If you only care about file playback, bit still care about things like HDR and quality audio I would recommend something like the OSMC Vero V instead.
It's still relatively cheap, and open source, but also let's you playback something like a blu-ray rip without loss of quality.
It has the other bonus of not requiring any real setup or maintenance.
GBM/DRM Kodi supports HDR video on the Orange Pi 5 family. You can grab whatever audio from HDMI or plug whatever in the usb port, the only advantage of this Vero is the optical out.
The orange pi doesn't do HDR properly. Linux in general doesn't support it natively, and the hardware doesn't provide for it.
On most devices Dolby Vision, etc get downgraded or support only the streaming profiles (profile 5) . If you want full Atmos, Dolby Vision, etc you have to buy one of only a handful of devices. The Vero V is one of them. There are only a few others.
https://osmc.tv/wiki/vero-v/dolby-vision-support/
Does the optical out actually transcode to 5.1 or is it only proper optical when the source has DD built in ?
Wrong number, I have no idea.
Or just buy an old x86 mini pc from ebay, vastly more powerful and less headache.
Mine comes with i5 8500t, 16gb ram and 256gb ssd, and it was like $150.
Just hook up a PC to it?
No idea what NAS you’re using, but I would recommend the Apple TV box.
> Some open source hacked-together box, then?
I've just used an old Intel NUC with Debian stable, a remote mini-keyboard and an automounted Samba share on the network forever. It's no more hacked together than any other computer. I do make the mouse pointer and the fonts real big. No apps required. Don't really need the keyboard except for mplayer hotkey presses - just the touchpad on it; if I need to do something that involves typing other than typing a password, I usually ssh in.
I think people are lowkey addicted to having shit sliding in and out and constantly being advertised to. How do you know what to watch unless somebody is constantly bombarding you with options? If it doesn't look like a star trek control panel, is it really TV?
If you like that, you can install Kodi. I haven't tried it since it was XBMC because I found the interfaces annoying and it had trouble dealing with networks, but I'm sure it's better.
> I've yet to hear of a reasonable recipe to isolate and secure such connected TVs
I don't even try. I overpay for dumb tvs in the present, or underpay for 10 year old tvs pre-Applefication. I've never owned a network capable television, or one with apps. I wouldn't.
edit: if your NAS is a separate box that can sit in proximity to your television, you could probably just run all of this stuff directly from the NAS. They spend most of their time doing nothing at all.
I was going to suggest updating firmware initially right after your purchase, but that could also update a list of Wi-Fi credentials so it can continue to connect to the Internet using other nearby access points.
Did you know that ethernet can run over HDMI? It's called HDMI Ethernet Channel (HEC).
Surely it still needs to be connected to something that has a network connection, though? Doesn't really mean much here.
I'm saying that "it is connected only via a HDMI cable" does not imply "it is not connected to the Internet".
Yes, but support in devices and cables is very limited.
Support in cables is nearly universal, because the same pins in the cable are used for the Audio Return Channel feature that allows a TV to pass audio from its internal apps back out to a soundbar or receiver via the same HDMI cable it takes signals in on from other devices. As far as I'm aware no one has made a cable lacking those pins since 1080p was still the high end.
But yes, support for the ethernet mode as far as I'm aware was never actually implemented in any devices that reached retail availability.
How much would support increase when manufacturers realise how few of their TVs don't get connected to the network?
Even if it did support it, nobody connects their TV to their local network via HDMI, they connect it to their PC. And, as far as I'm aware, no PCs automatically start sharing networking with whichever networks they are connected to.
That could of course change. Could be even a nice feature for connecting your TV to the network via your multi media center, if the bandwidth is good.
LG was caught abusing (although it's hard to argue that it isn't intended behaviour) Windows automatic installation of hardware-related software to install adware. Doesn't take too many tinfoil wraps around one's head to imagine them doing the same to enable network sharing (assuming hardware support is ubiqtuous enough).
https://www.techspot.com/news/113031-lg-alienware-monitors-c...
Proportion of HN users whose TVs don't connect to the internet? Significant
Proportion of non-HN users whose TVs don't connect to the internet? Negligible
Their solution to that is to either use the cell phone network or services like amazon sidewalk where they connect in through your (or a neighbour's) internet-connected device.
I think it’s also possible to piggyback on other devices signed with the same certificate to exfiltrate using BLE. Maybe I’m wrong though.
Not at all, because it uses the same pins as ARC, so the two features can't operate at the same time, and a lot of people use ARC to get audio from TV apps back to a soundbar or receiver.
HDMI Ethernet is dead, it's never going to happen in consumer televisions because it has a hard conflict with a feature a lot of people actually use.
If people really start not connecting them. TV makers will just start including a cellular modem.
Not even game consoles, PCs, even Raspberry Pi don't support it. Which is odd, so there are probably reasons why it's not worth the troubles.
Then you make sure to only use HDMI cables that aren't HEC, in conjunction with not connecting the TV to the internet directly, if you want to keep them isolated.
Did you know that no one has implemented it? You might as well talk about packet-carrying fairies in your TV. And of course the Apple TV box it’s connected to will be quite happy to share its network connection with arbitrary crap you connect to it.
But I guess like an xkcd comic, someone is obligated to raise the issue every time TVs come up.
I use the built-in AirPlay receiver on my Sony TV quite a bit and that requires network access
LG’s AirPlay requires internet access.
christ we need to start rooting tvs and start up a open and secure tv os. i never give my tv os internet access i rely on the appletv for the "smart tv" but if what another poster says is true about lg devices looking for public wifi to exfiltrate data then lol time to start pulling tvs apart and shielding their network components from getting a signal
That basically exists, but runs on external hardware: https://kodi.tv/
There's no need for the TV to be anything but a dumb screen that has only "power on", "power off", "volume up", "volume down" and "mute" functions. Most are probably too underpowered anyway to be useful.
They do screenshot? Do you have a source so I can read more?
Yes tv makers were caught doing HDMI fingerprinting. There was a story some years ago about how basically all smart tv makers were sending data to an ad network based in China.
Samsung were openly bragging about this on their website some years ago (for the benefit of their advertising partners) but have recently muddied the waters when I check their site again, couching it in language mentioning privacy and other evasive language:
https://www.samsung.com/us/support/answer/ANS10010616/
It's (mostly) a US thing; basically subsidizing TV prices with ad revenue. It's how the entry-level companies like Vizio operate, though the "big brand" TV makers are certainly just as guilty here. It's much less of a thing in the EU, where data privacy laws are stricter and TVs are hence (comparatively) more expensive.
As far as I know, they don't literally scan your media libraries; they screenshot whatever you're watching through HDMI (most often cable / satellite boxes), as those devices don't provide the telemetry that normal apps do. This info is used for audience measurement (thing Nielsen ratings), as well as showing you ads that are actually likely to match your interests.
No this is isn't just a US thing anymore. Every TV has automatic content recognition now, of some kind or other. Even in the EU.
https://www.ftc.gov/business-guidance/blog/2017/02/what-vizi...
"Starting in 2014, Vizio made TVs that automatically tracked what consumers were watching and transmitted that data back to its servers. Vizio even retrofitted older models by installing its tracking software remotely. All of this, the FTC and AG allege, was done without clearly telling consumers or getting their consent.
...
"Vizio collected a selection of pixels on the screen that it matched to a database of TV, movie, and commercial content
https://arxiv.org/pdf/2409.06203 shows LG and Samsung doing something similar
https://en.wikipedia.org/wiki/Automatic_content_recognition
https://www.youtube.com/watch?v=IvFu343KNek
The alternative is inconvenient and more expensive. And most people simply don't care.
We don't really have alternatives, period. LG is the one in the news today, but pretty much any TV this decade has been doing similar things. Computer monitors max out at 32 inches and the idea of a modern dumb TV is non-existent.
I meant alternatives to connecting your TV directly to the internet. As in "why would you ever connect your TV to the internet?" is a stupid question - "because I want to watch things on the internet." And it's not like a roku, firetv, or chrome cast dongle is much different (and Apple TV is $200, normal people don't add 20-50% the cost of their TV to do something built in).
> the idea of a modern dumb TV is non-existent.
They're sold as commercial display panels/digital signage and because they're a business product that isn't subsidized by advertising/spyware they cost a good bit more. But the panels and controls are basically identical to high end TVs.
A cheap 4k generic android media box is less than $70 on Amazon. There are dozens of them. I use one because half the apps on my old smart TV don't work anymore. The android ones are always up to date and the UX is better.
Is there any TV on the market that flat out wont work if it can't see the internet?
We replaced our old TV recently with an LG and are really liking it. We do not let it on our network though and keep networking functionality disabled. It's basically a monitor for our Kubuntu Linux laptop sitting behind it. We stream with Chrome and use a mouse and the TV remote for audio. Once in a while we actually watch something on TV itself too. It'd be nice I guess if the built in TV app had DVR but if it does; I couldn't figure out how to make it work. No great loss there.
I'm still nervously holding my breath for the first disclosure that a TV manufacturer is using Amazon's distributed Sidewalk Network (or perhaps mobile vehicles, cell-SIMs, LoRa) to remotely gather all that viewing data they've subsidized into your artificially-low TV purchase price .
But they've been calling "crazy?" for decades.
This exactly. Surely some sort of IoT mesh networking will allow exfiltration of data even without having configured your own device.
I'm hopeful that there will be sufficient distrust that "jailbreaking" or "rooting" TV controller boards will be turnkey enough to move to something like OpenWrt or GrapheneOS but for TVs.
Why not do it yourself?
That is a reasonable push back. The simple answer is a lack of present day need given my TV is a very old Samsung without any need.
I suppose I also assume someone with Android ROM development experience is better positioned to take up organizing such a project as an overall smaller effort, there by being faster and more efficient. Other real life constraints also seem to suggest not pursuing this type of thing in lieu of other things I should be pursuing and already procrastinate. But, here there be dragons, or at the very least a can of worms.
>IoT mesh networking
I'll bet there is already a manufacturer whose TVs can all communicate intratelevisually (non-standard proprietary frequencies) – and then, if even one of them is online... they're all relaying within their private intra-TV spyware meshnets to their various relays.
----
In unrelated news, my 2012 Sony Bravia is still fantastic, even if not for (4K) high-refresh games (the image quality remains fantastic for casual usage).
Same. And one of my requirements was that i can use HDMI ports without agreeing to TOS. Most android TVs do not allow this at all, LG did.
I had a similar experience regarding Facebook. People would always remark that they thought someone who knew about tech would surely have an account.
People don't say that so much anymore.
It's worth remembering that for all the animosity they face, they did what they told you they were going to do when they asked for your permission to do it.
Is there a list of all LG tracking services and external DNS endpoints?
I'd just block them - and keep local streaming and remote control working
edit: just found out WebOS doesn't support DoH/DoT so nextdns won't work.
I wonder if one of the public dns providers got LG blocklisted natively with specific IP
Worse, if you watch the GN video this article is based on you'll find the TV can figure out how to leverage other non obvious networks (threads, etc) to reach LG servers. Worth a watch to see how bad this is: https://www.youtube.com/watch?v=6IFVTcM28KA
Its a 2+ hour video. Do you have a timestamp for this?
There’s a list of them in the Intercepting section of the source video.
Oh, by the way, these things spoof MAC addresses too, so you can't rely on DHCP.
You can spoof MACs all you want, but your MAC is tied to the address I give out. What happens if you spoof addresses? FAFO...
[citation needed]
If you have one, can't you just look at the router to the MAC being reported?
I'm not the one claiming TVs actively spoof their MAC address. Its on the person making claims to provide evidence.
I think the worst part is that most devices give you no option to disagree.
I bought a DJI action camera, I had watched a bunch of reviews and read the store page. Yet only after buying and turning it on did I discover the device only allows you to use it 5 times before connecting it to the internet and signing up for an account.
There aren’t even any features that require this, it simply bricks itself after the 5th use until you sign up and agree to the terms.
I usually go for Samsung TVs, but same, I never give it network access. I use a Fire Stick that gets its power from the TV's USB port. Best as I can tell, turning off the TV turns off power to the Fire Stick.
My in-laws were so proud of themselves. I came home one day and they told me they figured out how to connect my TV to the network so that I don’t have to use my Apple TV if I don’t want. I had to take a few deep breaths to keep from yelling. I am very happy with my TCL tv but I trust it about as far as I can throw my father in law.
At least with LG you can revoke your consent. I came home to found STT audio recording enabled and I promptly disabled it and lectured the household about privacy.
A few models/firmware combinations have found to look for public hotspots when you don't agree to give them network.
have they? what ones?
I have an LG C5 OLED and do not give it internet access. It does not nag, every non-internet feature works fine, the interface is clean, and my Apple TV works just fine.
Mine is still attached to the network, but I’ve turned off all the ad/customisation &AI stuff. Seems to work fine, no ads etc. though usually I’m using it simply as a screen for the AppleTV.
I do have it isolated from other devices on my network, though.
If you're only using it as a screen for the AppleTV, why connect it to the network at all?
So I can turn it on/off using Home Assistant and my phone.
Why not use cheap $10 IR blaster for that? it will connect to home assistant in same manner.
Because it's one more thing that I have to own and maintain; versus a built-in feature?
What a useless feature. Reinventing a worse remote.
It is precisely so I _don't_ have to touch the actual TV remote ever.
>If you're only using it as a screen for the AppleTV, why connect it to the network at all?
Not GP, but I do so to make sure my TV doesn't try to connect to a different network. I provide specific IP addresses to the ethernet-connected interface and then block those IP addresses.
I suppose I could also move the TV to an isolated VLAN, but I spent months (the device was purchased nearly, or perhaps even more than, a decade ago) monitoring network traffic to determine to where (via DNS queries and packet captures) my TV was trying to phone home and blocked all egress for the TV and ingress from the sites/IP addresses to which the TV tried to connect.
I suppose that newer TVs might be sneakier (with the kind of WiFi surfing mentioned in TFA and/or installing cellular modems) in their attempts to bypass user control and when I need a new TV, I'll burn that bridge when I come to it.
But for now, my TV can't phone home. Or I'd have thrown it away years ago.
Similar, I was only using it as a screen for my shield so I factory-reset it and never re-connected it to wifi.
It's actually a lot faster now (it's an 8 year old TV, their OS can get a little heavy on older models)
I didn’t care much about data collected but I found that with every update it becomes worse and worse objectively. I had to cut it from in internet so doesn’t get completely unusable
I keep my off-brand smart TV offline as well, partly just because the next update could brick it. I just use it as a monitor. External Google TV box is the way to go if you want smart functionality.
Also, those "smart" TVs aren't really smart, besides that data grabbing, and are really slow. So connecting some mini PC is the way to go.
Only give the permissions you want the device/agent/human to use - no more.
Same for anything whether you trust it or not (or somewhere in between).
Same, disabled internet access on my LG years ago using the router config. It’s good that it at least doesn’t stop working without internet
Doesn't HDMI have built in Ethernet these days? So any HDMI cable of a certain specification is also a network cable.
I remember these things being discussed a while ago on here, how TVs use their own hard coded DNS ("for safety") rather than any network provided DNS (to avoid filtered DNS ala PiHole), how there's Ethernet in a HDMI cable, how other wireless networks are tried, and how eventually they'll go the car route and just embed a wireless modem in the device.
I am not aware of any smart TV that actively solicits a DHCP lease and default route outbound from anything it's plugged into by the 100M ethernet built into a current gen HDMI link. At least not yet. And since I think the default behavior for things like xboxes, playstations and apple TV is not to be a dhcp server and provide routing/NAT, I don't think a lot of things you can plug a TV into (also yet), would provide such function even if the TV tried.
I'm sure somebody at LG is hard at work on fixing this problem.
HDMI Ethernet was included in the spec 15 years ago and not a single consumer device (that I am aware of) ever implemented it.
Idk why this is so often citied in Smart TV boogeyman arguments.
Because it's there and available should they ever want to use it, and most people would not know that the HDMI cable is potentially another network cable.
Just thinking, if this is an issue, how you can dare to buy a modern car with embedded SIM card and GPS? :)
I yanked the OCU (telematics) out of my VW Mk7, and coded out the expectation of its existence from about four other devices with Ross-Tech's VCDS! I also coded out the Bluetooth on my infotainment unit, for good measure. :^)
Yeah. I own an LG TV also of about the same vintage. It doesn't get to talk to the Internet.
We need a HIPAA for consumer devices.
> I was ridiculed by my friends for that.
The sad part about the privacy discourse is that people not only don't care, but they would argue for the invading party. And I am not talking about your average teenager looking for their next brainrot fix, but highly educated and extremely intellegent people!
I've long since gave up trying to talk to people about these issues. Which unfortunately means I'll surrender to exposing myself to this plague to some degree, considering how herd immunity principles apply here as well.
> Not a bad tv though, many HDMI ports!
that's not a plus, tho
Why?