← Back to context

Comment by korzinka

7 days ago

I've bought an LG Smart TV 5 years ago, read t&c where I was supposed to grant them any data they wanted, decided to disagree and kept all network functions disabled. I was ridiculed by my friends for that. At some point, I thought - maybe I'm really crazy to do so? Who am I, a caveman, a luddite? Oh well, I'm not. Not a bad tv though, many HDMI ports!

I have a similar reaction from folks when I don't trust services/devices. Most telling moment was when I refused to upload my license to LinkedIn because I lost 2FA (token on phone, phone destroyed). Microsoft assured me they would "delete the license as soon as it was verified". I've written too many software systems for too many companies, and I do not believe them.

Of course, they'd outsourced to AU10TIX, which did retain the licenses, and got hacked: https://www.404media.co/id-verification-service-for-tiktok-u...

That's from 2024, but we just had a larger breach with IDScan this week.

Sorry for the digression, but the common thread is how much to trust these companies, and my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want. Some paranoia is warranted, I think.

  • > my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want

    Honestly, it's not even that extreme in most cases. I think it's usually not malice, it's incompetence.

    That's why I don't trust big companies with my data. Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.

    • > I think it's usually not malice, it's incompetence.

      Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.

      8 replies →

    • > Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.

      The CEO is responsible for what their company does. If a major breach can occur through the oversight or "incompetence" of one worker, the CEO has already failed, whether through negligence or malice.

      2 replies →

    • Pardon my French but bull-fucking-shit! A CEO _should_ take responsibility for what their subordinates do. It's preposterous to simple throw up our arms and say "oh well, some employees were sloppy so we lost some 100 million user IDs and other sensitive information that we promised not to store but we lied. Oopsie, silly me, pardon my wee incompetence tee-hee". No no no NO NO!

      At some level, and certainly at the level where you get paychecks of 10 million a year for the "huge responsibility you are bearing", then incompetence IS malice!

      3 replies →

    • It's probably both, vis a vis negligence. I just wish it was treated as criminal negligence. This will continue as long as CEO's face no real punishment for mishandling PII.

      1 reply →

    • It's malice. Compliance tends to not "maximize the shareholder value". Why pay millions/year to maintain a compliance team when you can get away with paying a small fine from time to time?

  • Same here when they find out I’ve never had an FB/IG/X etc account. As though having that crap in your life is somehow mandatory.

    People who make poor choices love to pretend that they had no choice at all.

    • 1. Interaction with Meta is virtually mandatory in many places in the world. Try opting out of Meta when your kid's daycare or your building's group chat is on whatsapp.

      2. It doesn't really matter if you opt out, because _other people around you don't_: they take pictures in which you show, they tag you, they talk about you, they send you links, etc. Which means they (Meta) build a shadow profile of you anyway.

      The "personal responsibility angle" is pure fiction.

      4 replies →

  • When are the victims going to start getting significantly compensated for these breaches?

    They will keep happening as long as the consequences are just the cost of doing business.

    • It will be when enough people elect enough politicians who take action against this weaponized incompetence and strip-mining of the peoples' assets.

      Or, if that does not happen, when enough people rise up in revolution and take the compensation for themselves.

      Or, never.

      If enough people vote enough or revolt enough, they cannot be stopped. But the incentives for too few people rising up are too costly. They work hard to keep the equilibrium in that balance.

    • It becomes tricky fast.

      There is obviously a fine that could bankrupt the company: this would be a clear signal "do not do this".

      There are also many cases where people have been doing everything they should have been, and still got hacked (zero days, for instance).

      Now, I do not think people should only be slapped on the wrist in that case: it still needs to be significant so companies carefully decide to store only the data they really do need!

    • I want this data to be treated like HIPAA data. Any company that collects personal data must have a compliance officer, and any breaches should lead to people going to jail. If you collect personal data, you are personally responsible for it.

It’s okay to be a luddite. Not everything needs to have an interface.

Got into a spat with a manager at my apartment complex because I refused to install their app just to deal with a maintenance issue.

He was like, “I don’t see the problem, you have to use the Latch app to open your apartment door.”

To which I replied, “No, I have the door keypad code memorized.”

Just like I don’t need an app to make a log of exit/entry history in a backend database just to enter my apartment via a Bluetooth lock…

…I should not have to install their app to make my apartment livable.

Indeed, my argument was convincing enough to have a resolution which didn’t include installing their app.

  • It's not about being a luddite. In many respects I consider it the opposite. It's engaging with technology in a way that demands standards of behaviour and performance.

    I don't want the new thing because it is the new thing. I want new things that are better.

    People accept abusive technology because they consider that's just the way it is with this new thing. It's a failure to understand what should be considered unacceptable.

  • My apartment complex came to install keypads and centrally managed smart thermostats and I would not let them.

    Thankfully my lease was old enough that I was able to argue against it. I don’t want a 3rd party company tracking my habits, and I don’t want some manager boiling my pets alive while I’m gone because they decided they think our AC is set too low.

    • You got lucky. If you've got an apartment in, say, a healthcare facility, they'll install those thermostats and whatnot. Usually the neighbours are clueless about technology so complaining doesn't get very far at all.

      It's even worse if some staff wrote paranoid in your file, 'cause they'll argue it's good for "exposure".

      4 replies →

  • > you have to use the Latch app to open your apartment door

    So what happens if you arrive home with a dead phone?

    And possibly worse, they have a log of when you come and go?

    • I am a student and where I live most student housing has an app to open the door instead of a normal key. My current place used Bluetooth, the previous one was even more inconvenient because it used NFC. It sucks, and if you accidentally forget your phone at home you're fucked, but the landlords do it because it lets them block old tenants from entering without having to switch the locks.

    • > And possibly worse, they have a log of when you come and go?

      Most apartment buildings in the US already use face-tracking cameras to get this log

  • Does this app work on GrapheneOS? LineageOS? Android betas? Who will troubleshoot issues if it doesn't?

Nah, you're not crazy. I'm also someone who actually reads terms documents, because I find that they're often the only thing that will be truthful about a company's intentions.

And keeping it completely disconnected from the internet should be the default, in my opinion.

  • There is absolutely no reason to read those contracts any more. As Louis Rossman keeps pointing out, most of them now include the ability for them to change terms at any time. That's basically the null contract.

    Since the legal system has once again failed to protect users from corporations, it's up to users to use technical means for self defense.

    • Depends on jurisdiction, just because someone wrote something in a contract doesn’t mean it’s binding.

      In Poland/EU we have an (ever growing) list of forbidden clauses that even when written and signed by consumer are null and void. And I think these can be enacted retroactively - when corporations invent new shady clauses, government steps in and tells them these are invalid.

      This helps to even out the consumer-corporation field.

      14 replies →

    • Interestingly, in Brazil and I'm sure in some other legislations, those contracts are essentially void because there's a presumption the average person does not have the time, patience, or ability to understand every clause—so they are by definition unable to agree to their terms.

      I'd love to have a similar standard applied in the US but I'm not holding my breath.

    • >There is absolutely no reason to read those contracts any more

      For another perspective, check out the comment you're replying to.

    • At the very least, you can be sure they'll never change the terms of the agreement to be more beneficial for you, though.

      So just treat it as a best case scenario, knowing that it can get even worse.

      3 replies →

  • I never understood why any of the smartness had to be built into the TV in the first place. Sure, it's useful for the first year, and then the seriously underpowered hardware they installed into it will have trouble with just about anything.

    I bought a Philips Ambilight OLED TV probably over 8 years now. Brilliant tv, great quality, I still see no reason to replace it at all. But its built in AndroidTV is garbage.

    • Because it’s extremely profitable for them to serve ads and sell PI. Kind of like how the airline industry makes more money off credit card shenanigans than actual plane tickets.

      1 reply →

    • > I never understood why any of the smartness had to be built into the TV in the first place.

      Because technology got ever more complex. A TV of yore? That thing operated on (relatively) simple physics alone, at the cost of requiring an absurd amount of broadcast infrastructure to make sure a TV signal could be received across the country.

      Modern TVs however... digital modulation schemes with a lot of signal processing wizardry allow TV reception with far less broadcast towers and far better quality. You got satellites and with these a myriad of control schemes (DiSEqC, Unicable, ...). You got Pay-TV that requires decryption. You got HDMI CEC to allow your TV to remote control your DVD player.

      And all of that complexity requires firmware which means it can have bugs which means you need a firmware update capability and when you're at that point you can just go and slap something Linux on it and get all the apps for streaming services.

    • Because having the TV play from streaming apps out of the box is pretty useful.

      The problem is we've not enforced any strong regulation against ads, downgrade rights or hack ability.

      I don't need "better performance" from the system built into my TV I just need it to run Kodi.

    • I hear you. This is exactly the reason why I have a digital signage display rather than a Smart TV.

    • Similar boat - Panasonic glass fronted TV. Circa 2013. None of the smart works anymore.

      1080p, but the picture far outstrips most other TVs I've owned to this day.

      I have zero plans to change it, and it's usefulness has outlasted the Chromecast that's connected to it.

      Yes, I put the first ads on Smart TVs. Apologies.

  • > I find that they're often the only thing that will be truthful about a company's intentions.

    Really? Many years ago, I had to physically sign a license with Microsoft to obtain some software. The license was not consistent with the license included with the software. Both licenses effectively said they were the real license and that any other agreement you made with Microsoft was not valid.

    I don't think there was any nefarious intent. It was likely to avoid a situation where Microsoft employees offered terms that were not approved of by the company. Still, it goes to show that it can be awfully difficult to judge the intent of a company.

We replaced our old TV recently with an LG and are really liking it. We do not let it on our network though and keep networking functionality disabled. It's basically a monitor for our Kubuntu Linux laptop sitting behind it. We stream with Chrome and use a mouse and the TV remote for audio. Once in a while we actually watch something on TV itself too. It'd be nice I guess if the built in TV app had DVR but if it does; I couldn't figure out how to make it work. No great loss there.

  • I'm still nervously holding my breath for the first disclosure that a TV manufacturer is using Amazon's distributed Sidewalk Network (or perhaps mobile vehicles, cell-SIMs, LoRa) to remotely gather all that viewing data they've subsidized into your artificially-low TV purchase price .

    But they've been calling "crazy?" for decades.

    • This exactly. Surely some sort of IoT mesh networking will allow exfiltration of data even without having configured your own device.

      I'm hopeful that there will be sufficient distrust that "jailbreaking" or "rooting" TV controller boards will be turnkey enough to move to something like OpenWrt or GrapheneOS but for TVs.

      3 replies →

> I was ridiculed by my friends for that.

The sad part about the privacy discourse is that people not only don't care, but they would argue for the invading party. And I am not talking about your average teenager looking for their next brainrot fix, but highly educated and extremely intellegent people!

I've long since gave up trying to talk to people about these issues. Which unfortunately means I'll surrender to exposing myself to this plague to some degree, considering how herd immunity principles apply here as well.

I had a similar experience regarding Facebook. People would always remark that they thought someone who knew about tech would surely have an account.

People don't say that so much anymore.

It's worth remembering that for all the animosity they face, they did what they told you they were going to do when they asked for your permission to do it.

I have an LG C5 OLED and do not give it internet access. It does not nag, every non-internet feature works fine, the interface is clean, and my Apple TV works just fine.

Is there a list of all LG tracking services and external DNS endpoints?

I'd just block them - and keep local streaming and remote control working

edit: just found out WebOS doesn't support DoH/DoT so nextdns won't work.

I wonder if one of the public dns providers got LG blocklisted natively with specific IP

I think the worst part is that most devices give you no option to disagree.

I bought a DJI action camera, I had watched a bunch of reviews and read the store page. Yet only after buying and turning it on did I discover the device only allows you to use it 5 times before connecting it to the internet and signing up for an account.

There aren’t even any features that require this, it simply bricks itself after the 5th use until you sign up and agree to the terms.

My in-laws were so proud of themselves. I came home one day and they told me they figured out how to connect my TV to the network so that I don’t have to use my Apple TV if I don’t want. I had to take a few deep breaths to keep from yelling. I am very happy with my TCL tv but I trust it about as far as I can throw my father in law.

  • At least with LG you can revoke your consent. I came home to found STT audio recording enabled and I promptly disabled it and lectured the household about privacy.

Mine is still attached to the network, but I’ve turned off all the ad/customisation &AI stuff. Seems to work fine, no ads etc. though usually I’m using it simply as a screen for the AppleTV.

I do have it isolated from other devices on my network, though.

  • If you're only using it as a screen for the AppleTV, why connect it to the network at all?

    • >If you're only using it as a screen for the AppleTV, why connect it to the network at all?

      Not GP, but I do so to make sure my TV doesn't try to connect to a different network. I provide specific IP addresses to the ethernet-connected interface and then block those IP addresses.

      I suppose I could also move the TV to an isolated VLAN, but I spent months (the device was purchased nearly, or perhaps even more than, a decade ago) monitoring network traffic to determine to where (via DNS queries and packet captures) my TV was trying to phone home and blocked all egress for the TV and ingress from the sites/IP addresses to which the TV tried to connect.

      I suppose that newer TVs might be sneakier (with the kind of WiFi surfing mentioned in TFA and/or installing cellular modems) in their attempts to bypass user control and when I need a new TV, I'll burn that bridge when I come to it.

      But for now, my TV can't phone home. Or I'd have thrown it away years ago.

  • Similar, I was only using it as a screen for my shield so I factory-reset it and never re-connected it to wifi.

    It's actually a lot faster now (it's an 8 year old TV, their OS can get a little heavy on older models)

I didn’t care much about data collected but I found that with every update it becomes worse and worse objectively. I had to cut it from in internet so doesn’t get completely unusable

Also, those "smart" TVs aren't really smart, besides that data grabbing, and are really slow. So connecting some mini PC is the way to go.

Only give the permissions you want the device/agent/human to use - no more.

Same for anything whether you trust it or not (or somewhere in between).

I usually go for Samsung TVs, but same, I never give it network access. I use a Fire Stick that gets its power from the TV's USB port. Best as I can tell, turning off the TV turns off power to the Fire Stick.

I keep my off-brand smart TV offline as well, partly just because the next update could brick it. I just use it as a monitor. External Google TV box is the way to go if you want smart functionality.

Same. And one of my requirements was that i can use HDMI ports without agreeing to TOS. Most android TVs do not allow this at all, LG did.

Same, disabled internet access on my LG years ago using the router config. It’s good that it at least doesn’t stop working without internet

Doesn't HDMI have built in Ethernet these days? So any HDMI cable of a certain specification is also a network cable.

I remember these things being discussed a while ago on here, how TVs use their own hard coded DNS ("for safety") rather than any network provided DNS (to avoid filtered DNS ala PiHole), how there's Ethernet in a HDMI cable, how other wireless networks are tried, and how eventually they'll go the car route and just embed a wireless modem in the device.

  • I am not aware of any smart TV that actively solicits a DHCP lease and default route outbound from anything it's plugged into by the 100M ethernet built into a current gen HDMI link. At least not yet. And since I think the default behavior for things like xboxes, playstations and apple TV is not to be a dhcp server and provide routing/NAT, I don't think a lot of things you can plug a TV into (also yet), would provide such function even if the TV tried.

    I'm sure somebody at LG is hard at work on fixing this problem.

    • HDMI Ethernet was included in the spec 15 years ago and not a single consumer device (that I am aware of) ever implemented it.

      Idk why this is so often citied in Smart TV boogeyman arguments.

      1 reply →

Just thinking, if this is an issue, how you can dare to buy a modern car with embedded SIM card and GPS? :)

  • I yanked the OCU (telematics) out of my VW Mk7, and coded out the expectation of its existence from about four other devices with Ross-Tech's VCDS! I also coded out the Bluetooth on my infotainment unit, for good measure. :^)

Yeah. I own an LG TV also of about the same vintage. It doesn't get to talk to the Internet.

This. Why would you even connect TV to the network?

It is well known for like 5 years. Smsrt TVs go through your movies library, and upload screenshots and filenames to internet.

Some will start showing ads after firmware upgrade.

  • Watch the video the article is based on - not connecting to the internet doesn't keep you safe in many cases: https://www.youtube.com/watch?v=6IFVTcM28KA

    • "Watch this two hour long video" is not a particularly useful reply. If you think the TV can exfiltrate your data without an internet connection then you should be able to explain how it could do that in your own words.

      7 replies →

    • This is because they rooted the TV.

      They can just start a capture, record to RAM / storage, and retrieve it later when it is reconnected to the network.

      Otherwise if it's disconnected, it is still hard to exfiltrate the data somewhere. Maybe they could get creative via Bluetooth, but then you would need a cooperating device in proximity of the device.

      1 reply →

  • > This. Why would you even connect TV to the network?

    I happen to have a NAS with family pictures I like to display. I can (and do) firewall that thing, but then you hit other issues like the apps you need to show pictures and movies in the first place not to install/run.

    I've yet to hear of a reasonable recipe to isolate and secure such connected TVs. And don't get me started on Chromecast or other Android dongles, I've no reason to expect better treatment from Google. Some open source hacked-together box, then?

    • > Some open source hacked-together box, then?

      I've just used an old Intel NUC with Debian stable, a remote mini-keyboard and an automounted Samba share on the network forever. It's no more hacked together than any other computer. I do make the mouse pointer and the fonts real big. No apps required. Don't really need the keyboard except for mplayer hotkey presses - just the touchpad on it; if I need to do something that involves typing other than typing a password, I usually ssh in.

      I think people are lowkey addicted to having shit sliding in and out and constantly being advertised to. How do you know what to watch unless somebody is constantly bombarding you with options? If it doesn't look like a star trek control panel, is it really TV?

      If you like that, you can install Kodi. I haven't tried it since it was XBMC because I found the interfaces annoying and it had trouble dealing with networks, but I'm sure it's better.

      > I've yet to hear of a reasonable recipe to isolate and secure such connected TVs

      I don't even try. I overpay for dumb tvs in the present, or underpay for 10 year old tvs pre-Applefication. I've never owned a network capable television, or one with apps. I wouldn't.

      edit: if your NAS is a separate box that can sit in proximity to your television, you could probably just run all of this stuff directly from the NAS. They spend most of their time doing nothing at all.

    • Obviously, as an advertising company, Google should have your utmost scrutiny. But as far as I know, their TV boxes don't ACR your content. If they were the only two options, sticking with your smart TV software instead of using a Google TV box would be a privacy mistake.

      3 replies →

    • You can always just connect your laptop (or some spare laptop) to the TV via HDMI. Not sure why you’d need to “hack together” something. A dedicated HTPC is nicer if you want to use IR remotes and the like.

      1 reply →

  • Did you know that ethernet can run over HDMI? It's called HDMI Ethernet Channel (HEC).

    • Did you know that no one has implemented it? You might as well talk about packet-carrying fairies in your TV. And of course the Apple TV box it’s connected to will be quite happy to share its network connection with arbitrary crap you connect to it.

      But I guess like an xkcd comic, someone is obligated to raise the issue every time TVs come up.

  • I was going to suggest updating firmware initially right after your purchase, but that could also update a list of Wi-Fi credentials so it can continue to connect to the Internet using other nearby access points.

  • The alternative is inconvenient and more expensive. And most people simply don't care.

    • We don't really have alternatives, period. LG is the one in the news today, but pretty much any TV this decade has been doing similar things. Computer monitors max out at 32 inches and the idea of a modern dumb TV is non-existent.

      2 replies →

  • They do screenshot? Do you have a source so I can read more?

    • Yes tv makers were caught doing HDMI fingerprinting. There was a story some years ago about how basically all smart tv makers were sending data to an ad network based in China.

      Samsung were openly bragging about this on their website some years ago (for the benefit of their advertising partners) but have recently muddied the waters when I check their site again, couching it in language mentioning privacy and other evasive language:

      https://www.samsung.com/us/support/answer/ANS10010616/

    • It's (mostly) a US thing; basically subsidizing TV prices with ad revenue. It's how the entry-level companies like Vizio operate, though the "big brand" TV makers are certainly just as guilty here. It's much less of a thing in the EU, where data privacy laws are stricter and TVs are hence (comparatively) more expensive.

      As far as I know, they don't literally scan your media libraries; they screenshot whatever you're watching through HDMI (most often cable / satellite boxes), as those devices don't provide the telemetry that normal apps do. This info is used for audience measurement (thing Nielsen ratings), as well as showing you ads that are actually likely to match your interests.

      1 reply →

    • https://www.ftc.gov/business-guidance/blog/2017/02/what-vizi...

      "Starting in 2014, Vizio made TVs that automatically tracked what consumers were watching and transmitted that data back to its servers. Vizio even retrofitted older models by installing its tracking software remotely. All of this, the FTC and AG allege, was done without clearly telling consumers or getting their consent.

      ...

      "Vizio collected a selection of pixels on the screen that it matched to a database of TV, movie, and commercial content

      https://arxiv.org/pdf/2409.06203 shows LG and Samsung doing something similar