news.mlab.sh
Back to the feed
threat-intel

LG to Ban Residential Proxies from Smart TV Apps

Medium
Summary

LG Electronics USA is suspending smart TV apps that utilize residential proxy SDKs, following research by Spur which found that over 42% of apps on the webOS platform were incorporating these components. This allows third parties to route internet traffic through the TV, raising privacy and security concerns. LG is working with developers to remove the proxy functionality, with apps failing to comply facing suspension. The move follows a previous controversy regarding McAfee security product promotion via software drivers.

LG Electronics USA announced plans to suspend any apps built for its smart TVs that turn a user’s television into an always-on residential proxy node. This action follows research by security firm Spur, which discovered that over 42 percent of apps available for download on LG’s webOS platform include SDKs that enable residential proxy functionality. These SDKs allow third parties to route internet traffic through the user’s TV, potentially exposing user data and activity.

Responding to Spur’s findings, LG Senior Vice President John Taylor stated that residential proxy networks are not intended for use on LG smart TVs and that the company is collaborating with app developers to remove this functionality from their apps on the webOS platform. Developers who fail to comply will have their apps suspended.

LG is committed to strengthening its app evaluation process and preventing residential proxy SDKs from being incorporated into future apps. The company acknowledges that the issue isn't the existence of residential proxies, but rather their widespread inclusion in devices that are not typically considered computers and lack user oversight.

Bright Data, a proxy provider, accounted for a majority of proxy SDKs across both Samsung and LG smart TVs. Bright Data declined to comment on the findings. Proxy providers maintain they implement rigorous customer validation processes to ensure legitimate use of their services, often linked to content-scraping activities. They also incorporate technological measures to prevent proxy service customers from controlling other devices on the user’s local network.

This announcement comes after LG previously faced criticism for promoting McAfee security products through software drivers included in its high-end LCD monitors, automatically installing an app via Windows Update without user consent.

Read the full article at Krebs on Security