News: 0184574956

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

LG To Ban Residential Proxies From Smart TV Apps (krebsonsecurity.com)

(Wednesday July 22, 2026 @05:00PM (BeauHD) from the cease-and-desist dept.)


An anonymous reader quotes a report from KrebsOnSecurity:

> The home appliance giant LG Electronics USA said this week it [1]plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node . The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV. On July 2, [KrebsOnSecurity] [2]featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur [3]found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one's television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung's Tizen operating system had similar residential proxy components.

>

> Responding to questions about Spur's research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended. "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor said. "If this option is not removed, these apps will be suspended." Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company's review of those apps is "well underway now."

>

> "As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor wrote in an emailed statement. [...] "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Spur's Trevor Sutter wrote. "The risk is amplified when consent comes from individuals within the household who use the device but shouldn't give consent, such as minors."

LG is also facing criticism for monitors that [4]automatically install software promoting paid McAfee subscriptions through Windows Update without user approval.



[1] https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/

[2] https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/

[3] https://spur.us/blog/smart-tv-apps-residential-proxy-sdks

[4] https://hardware.slashdot.org/story/26/07/20/1736218/lg-monitors-silently-install-adware-like-app-on-windows-pcs



It makes me so sad.... (Score:2)

by brokenin2 ( 103006 )

...that I never gave my LG TV a connection to the internet... Now if only I could get rid of that damn nag message warning my that I have no network connection and that I should set it up so I can get updates...

this (Score:2, Interesting)

by drinkypoo ( 153816 )

This is why webos is shit, and also why I never connected my LG TV to a network.

It's too bad that Google has been shitting up android tv. It's super hard to get useful software onto it. Even most apps which will work fine aren't marked as such so you can only sideload them.

As such, all of the choices are now crap except using a PC

Re:this (Score:5, Informative)

by allo ( 1728082 )

That is not a WebOS problem. Privacy advocates and consumer protection groups have been warning about such SDKs for Android and iOS for over a decade.

The deal is simple: The SDK maker says, "Add this zip file and this line of XML, and you get a nice dashboard detailing who your users are. Here are 20 pages of fine print you better not read." The developer adds the SDK and receives a nice dashboard (and possibly even a few cents per installation), while the SDK creator gains a massive amount of user tracking data.

Usually, people say, "Damn, users don't read the fine print," but the first person who should have read it is the app developer. They literally sold their users by failing to read the SDK's fine print. They likely incorporated paragraphs of template Terms of Service from the SDK creator into their own terms (possibly without reading them, too), so legally everything is fine.

In addition to tracking, providing "residential proxies" is another opportunity for these companies. There are all kind of users who like to access something inconspicuously so they cannot just use a AWS IP for their bot, so there is a market for renting out residential internet connections. And giving people making popular apps a few cents you can get a lot of proxies on consumer devices.

The advantage of (LG) TVs is not WebOS (which rather diminishes the choice of compatible SDKs), but that many Smart TVs are always on with only the screen powered down. As they do not run on battery, nobody notices when they are busy as proxy servers, because there is no battery to drain and in standby nobody notices a slowdown of the system and nobody suspects that a possible slowdown of the internet connection is caused by the TV that's on standby.

Re: (Score:3)

by Local ID10T ( 790134 )

The answer to this problem is the same as for every other piece of software:

Stop embedding other peoples code into your code if you have not fully vetted and understood it.*

When you embed or link other people's code into your code, it becomes your responsibility. If you are not competent to understand/vet/maintain the full code base, then you are not competent to be in charge (lead developer/maintainer/architect/whatever-you-want-to-call-it).

This is not to say that less proficient coders cannot be part of

Re: (Score:2)

by radarskiy ( 2874255 )

"Stop embedding other peoples code into your code if you have not fully vetted and understood it.*"

Tell us more about how you read every line of your favorite libc.

And your second favorite libc.

Re: (Score:2)

by Local ID10T ( 790134 )

You didn't? I grew up a computer geek. I actually read this kind of stuff for fun... .

But my point only applies to the functions you are using -you don't need to know all of glibc by heart, but if you are including #menumaker_4.0c you should step thru it before trusting it to not be malicious. When you include it in your app -YOU- are accepting responsibility for what it does on your clients machine.

Re: (Score:2)

by CommunityMember ( 6662188 )

> It's too bad that Google has been shitting up android tv. It's super hard to get useful software onto it. Even most apps which will work fine aren't marked as such so you can only sideload them.

That is at least partially on the app developers themselves, who do not add android tv compatibility to the manifest (so the play store will not offer it on the play store for android tv). Admittedly, some developers probably don't think there is sufficient interest to make it worthwhile to make any required changes for android tv (the legacy leanback or modern jetpack compose changes), but others probably don't even test their app on the emulator to see if it works (and could be enabled).

And then there

Why do people buy this garbage? (Score:5, Informative)

by CEC-P ( 10248912 )

Their LG smart washers sometimes use 42GB of bandwidth per day randomly and nobody knows why.

Their monitors load malware/spam onto your computer randomly, when they feel like it.

Their TVs turn your network into a Tor node or however the fuck this works.

That's three strikes and it only takes one strike to receive a lifetime brand-wide ban in my game.

Re: (Score:1, Flamebait)

by The-Ixian ( 168184 )

If only there was a way to not connect these things to your network...

Re: (Score:3)

by almitydave ( 2452422 )

> If only there was a way to not connect these things to your network...

That will likely work for now, but it's only a matter of time before they do what cars do and include cell network connectivity. I'm sure the only reason they don't already is that it's harder to justify the cost on something in the $1k range (rather than the $30k+ for cars), but someday one of them will figure that ongoing revenue streams justify the connectivity costs.

Re: Why do people buy this garbage? (Score:3)

by EldoranDark ( 10182303 )

Samsung already got away with requiring a connection. Iirc, in South Africa. Because TV needs to confirm it's not stolen.

Re: (Score:2)

by taustin ( 171655 )

Is there anything about this company that isn't shady? I don't recall ever seeing anything good about them.

Re: (Score:3)

by test321 ( 8891681 )

> Is there anything about this company that isn't shady?

Their OLED panels

Re: (Score:2)

by CEC-P ( 10248912 )

OEM screens. About half of all LCDs in the world are LG. The rest are Samsung. The remaining % (lol) is garbage from Chimei and Changwah if I remember correctly.

Re: (Score:2)

by eepok ( 545733 )

Because comparably few people actually have the time to figure out what their TV (or the TVs from other brands) are doing aside from displaying video and emitting audio.

Re: (Score:2)

by sodul ( 833177 )

I used to like LG appliances, they do work well ... until they don't.

My final LG purchase was a double oven, which does cook very well. Unfortunately a very small plastic trim piece was broken, and it took me weeks of pinging LG support and social media teams to get them to replace it under warranty. I only wanted them to comply with the California right to repair law so I could just fix it myself, but they told me their corporate policies did not allow for that. When a tech finally showed up he did replace

How is this a thing? (Score:4, Insightful)

by itsme1234 ( 199680 )

Yes, I understand, "smart" TVs, wouldn't trust them as far as I could throw them.

But nearly half the apps are backdoors to your network?! Isn't this federal pound me in the *&s prison level stuff (or whatever the equivalent would be in the relevant jurisdiction)?

Re: (Score:2)

by ffkom ( 3519199 )

Corporations installing backdoors on their customers computers has been going on for decades, and apparently they pay enough lobbying money to never be significantly punished for such crimes. Remember [1]Sony doing this since at least 2005 [wikipedia.org]?

[1] https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal

Now we know (Score:3)

by SumDog ( 466607 )

I've seen a lot of these residential proxy services. They are expensive! Now we know how they work! This is probably just going to make the cost of those services skyrocket.

The consumer having no control (Score:2)

by hwstar ( 35834 )

or visibility of what's in any of these TV apps is the whole reason why smart TV's never get Internet connectivity in my house. I use a Linux PC to serve video via HDMI.

I suppose TV manufacturers could make it impossible to use the smart TV if you never connect it to the Internet, but they'd probably see mass returns to the store if they tried that. Of course, they could make smart TV purchases non-returnable and non-refundable, but that would be cutting off their nose to spite their face.

I have a theory ab

Re: (Score:2)

by blahbooboo2 ( 602610 )

> I suppose TV manufacturers could make it impossible to use the smart TV if you never connect it to the Internet, but they'd probably see mass returns to the store if they tried that.

LOL sure they would! Given how ad supported video streaming is more popular than paid, the number of robot vacuums and smart lights require online setup, don't hold your breath on those TV returns.

Re: (Score:2)

by SumDog ( 466607 )

I suppose TV manufacturers could make it impossible to use the smart TV if you never connect it to the Internet, but they'd probably see mass returns to the store if they tried that.

They're getting close. Wal-Mart's TV brands (Onn and they recently bought Vizio too) will not work without a Wal-mart account ... and people are still buying them. I thought it was required just to use them as TVs, but doing some more research, it seems you can still use HDMI without a Wal-mart account. But I bet in a y

Re: (Score:2)

by hwstar ( 35834 )

I'm aware of that. If all else fails I guess we'll be watching TV from large computer monitors without tuners and Ethernet jacks. If they some how take that away, there's always books from the public library.

Yes but what apps specifically were proxying? (Score:2)

by blahbooboo2 ( 602610 )

Most apps are barely used and are garbage. They omit what apps were specifically caught proxying and the number of installations.

Was it any of the big ones such as Netflix, Amazon Prime, Hulu etc?

Re: (Score:2)

by tlhIngan ( 30335 )

> Most apps are barely used and are garbage. They omit what apps were specifically caught proxying and the number of installations.

> Was it any of the big ones such as Netflix, Amazon Prime, Hulu etc?

No it's not the big ones, because those have reputations to uphold.

It's always the questionable apps - you know the apps you see in ads and such, and there are almost always clones of everywhere. Especially if it's a paid app and suddenly there's a free clone of it.

And they're really there to offer exit nodes for V

LG Speed-Running Bad Reviews and Boycotts... (Score:2)

by eepok ( 545733 )

I give it no more than 2 weeks before it becomes common knowledge that LG is worse than Samsung. Not only do their newer computer monitors automatically install adware on your computer without your permission or notice, but not their smartTVs will stop allowing you access to apps if you use a proxy in your own damn house and on your own damn network.

How financially desperate must they be?

Re: (Score:2)

by gargeug ( 1712454 )

And they are always forcing updates on you (or annoying you incessantly to where you give in and install the update) that load in new services that make money off you, like ACR. They don't disclose that it is there and enabled by default, and hide the ability to turn it off way down in the settings where 95% of people would never go.

Texas AG just won a settlement with them that they must disclose ACR and only enable it via upfront consumer consent. And no more selling user data to China. That really says ho

The first duty of a revolutionary is to get away with it.
-- Abbie Hoffman