Of course, they'd outsourced to AU10TIX, which did retain the licenses, and got hacked: https://www.404media.co/id-verification-service-for-tiktok-u...
That's from 2024, but we just had a larger breach with IDScan this week.
Sorry for the digression, but the common thread is how much to trust these companies, and my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want. Some paranoia is warranted, I think.
Honestly, it's not even that extreme in most cases. I think it's usually not malice, it's incompetence.
That's why I don't trust big companies with my data. Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.
Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.
I disagree with this as stated. Maybe in the right context you could make a case for it, but in general? Heck no. Intent matters a great deal, and there is no justice in treating someone incompetent (or negligent) the same as someone who is actually malicious. Both things are bad, but the latter is worse than the former even if they lead to the same outcome.
But is there someone accountable for it being so? Are they malicious? Who is ultimately to blame?
The road to hell is paved with good intentions.
The CEO is responsible for what their company does. If a major breach can occur through the oversight or "incompetence" of one worker, the CEO has already failed, whether through negligence or malice.
At some level, and certainly at the level where you get paychecks of 10 million a year for the "huge responsibility you are bearing", then incompetence IS malice!
I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.
Both are inexcusable, but one is more common/likely than the other.
You can certainly link them together and yes leaders should be held responsible no matter what, but from my perspective as the user who had his data leaked, it doesn't really matter how/why it happened, does it?
Not being held accountable for negligence or incompetence is the evil machination.
People who make poor choices love to pretend that they had no choice at all.
2. It doesn't really matter if you opt out, because _other people around you don't_: they take pictures in which you show, they tag you, they talk about you, they send you links, etc. Which means they (Meta) build a shadow profile of you anyway.
The "personal responsibility angle" is pure fiction.
I live a somewhat normal adult life and manage without having anything to do with Meta ¯\_(ツ)_/¯ I probably miss out on some things, but I don’t notice.
All my friends just contact me through other sources.
If you have kids, it’s more difficult - I can acknowledge that.
So yeah if a business requires me to have an account I’ll find a different business to patronize. Frankly if you’re expecting someone other than you to take responsibility for the media you consume, that’s a problem.
They will keep happening as long as the consequences are just the cost of doing business.
There is obviously a fine that could bankrupt the company: this would be a clear signal "do not do this".
There are also many cases where people have been doing everything they should have been, and still got hacked (zero days, for instance).
Now, I do not think people should only be slapped on the wrist in that case: it still needs to be significant so companies carefully decide to store only the data they really do need!
Or, if that does not happen, when enough people rise up in revolution and take the compensation for themselves.
Or, never.
If enough people vote enough or revolt enough, they cannot be stopped. But the incentives for too few people rising up are too costly. They work hard to keep the equilibrium in that balance.
Got into a spat with a manager at my apartment complex because I refused to install their app just to deal with a maintenance issue.
He was like, “I don’t see the problem, you have to use the Latch app to open your apartment door.”
To which I replied, “No, I have the door keypad code memorized.”
Just like I don’t need an app to make a log of exit/entry history in a backend database just to enter my apartment via a Bluetooth lock…
…I should not have to install their app to make my apartment livable.
Indeed, my argument was convincing enough to have a resolution which didn’t include installing their app.
I don't want the new thing because it is the new thing. I want new things that are better.
People accept abusive technology because they consider that's just the way it is with this new thing. It's a failure to understand what should be considered unacceptable.
Thankfully my lease was old enough that I was able to argue against it. I don’t want a 3rd party company tracking my habits, and I don’t want some manager boiling my pets alive while I’m gone because they decided they think our AC is set too low.
It's even worse if some staff wrote paranoid in your file, 'cause they'll argue it's good for "exposure".
Those folks pay out the effing nose, they ought to be allowed to control the temp in their apartment.
So what happens if you arrive home with a dead phone?
And possibly worse, they have a log of when you come and go?
But I would absolutely not install an app for that.
But the app on your phone does not have that limitation.
Most apartment buildings in the US already use face-tracking cameras to get this log
And keeping it completely disconnected from the internet should be the default, in my opinion.
Since the legal system has once again failed to protect users from corporations, it's up to users to use technical means for self defense.
In Poland/EU we have an (ever growing) list of forbidden clauses that even when written and signed by consumer are null and void. And I think these can be enacted retroactively - when corporations invent new shady clauses, government steps in and tells them these are invalid.
This helps to even out the consumer-corporation field.
I'm pretty sure that's true almost everywhere. Law beats contract. The real question is how strong the laws are. In the US not so much because of small government and stuff, especially in red states.
Or when you can't even enforce anything in court as you've already given up your right to spend all your money suing, as binding arbitration is the required and only mechanism to "resolve disputes." To make it extra fair, the corporation pays the arbitration firm for their "objective" decisions and not you.
What could go wrong?
In the Gamer's Nexus video, he gets drunk before accepting the terms so that it isn't legal consent. A drunk person can't enter a contract.
Yes[0]. For over 100 years.
Next question?
[0] https://en.wikipedia.org/wiki/Arbitration_case_law_in_the_Un...
It’s “small government” when it comes to protecting your individual rights, and full flock powered ai surveillance state when someone has an abortion.
I'm never going to interpret that one with a straight face.
I'd love to have a similar standard applied in the US but I'm not holding my breath.
For another perspective, check out the comment you're replying to.
So just treat it as a best case scenario, knowing that it can get even worse.
We Are Altering The Deal. Pray We Don't Alter It Any Further
It is tinfoil hats time, at least for LG tvs.
Also: the US intelligence agencies used Echelon ages ago to monitor what vast swaths of innocent people were up to. I think it's sensible to presume they've got their hooks into these devices too.
A technical solution would presumably spoof the spaff but with E2EE and DoH is it possible? So then what, hacking firmware? I guess then TVs get a hard lifespan limit.
I bought a Philips Ambilight OLED TV probably over 8 years now. Brilliant tv, great quality, I still see no reason to replace it at all. But its built in AndroidTV is garbage.
https://freakonomics.com/podcast/is-your-plane-ticket-too-ex...
WSJ and Wendover claim it is true.
1080p, but the picture far outstrips most other TVs I've owned to this day.
I have zero plans to change it, and it's usefulness has outlasted the Chromecast that's connected to it.
Yes, I put the first ads on Smart TVs. Apologies.
This is totally backwards; capitalism would do fine in such an environment (in the same way that evolution does fine in an environment where organisms live more than just a few seconds; the whole reason we have the notion of a "lifetime" is that our germ line comes from a long line of ancestral DNA that made organisms that outlasted their competition.)
Individual companies might have to hustle to innovate or die, but that too is good for capitalism.
I think maybe I stepped on somebody's agenda?
Both capitalism and evolution depend on the fact that over time, on average, less fit organisms/organizations are displaced by better alternatives. You may not like that, but down-voting anyone who points it out doesn't make it any less true.
The problem is we've not enforced any strong regulation against ads, downgrade rights or hack ability.
I don't need "better performance" from the system built into my TV I just need it to run Kodi.
Really? Many years ago, I had to physically sign a license with Microsoft to obtain some software. The license was not consistent with the license included with the software. Both licenses effectively said they were the real license and that any other agreement you made with Microsoft was not valid.
I don't think there was any nefarious intent. It was likely to avoid a situation where Microsoft employees offered terms that were not approved of by the company. Still, it goes to show that it can be awfully difficult to judge the intent of a company.
Any iphone/ipad/mac nearby will act as a router for them[1]
Given that we have already established that LG is a shady company, I wouldn't put it beyond them to try to use the same trick.
[1]https://lifehacker.com/tech/how-apple-airtags-actually-work
AirTags broadcast an encrypted ID. Phones build lists of ID’s they’ve seen and send the list to Apple.
There is no routing, no ability to send arbitrary data, no active communication of any sort. It’s not a mesh network.
The link you posted makes that pretty clear.
it means you can’t block the tracking by doing anything yourself - you’d also need to block everyone else’s devices too.
And of course you can block the tracking yourself, even though nobody is actually tracking because Apple can’t tell who owns what ID. Just turn off find my on your device.
This is a really bad thing for those of us who until now have just not connected our 'smart' shit to the internet.
Where I live in the EU they don't do sidewalk otherwise I'd have to look at ways to fight it (disassociate connections or DDoS the devices providing sidewalk routing)
It is well known for like 5 years. Smsrt TVs go through your movies library, and upload screenshots and filenames to internet.
Some will start showing ads after firmware upgrade.
Also, wouldn't this be trivial to test by just setting up your own network and seeing if the TV connects?
They can just start a capture, record to RAM / storage, and retrieve it later when it is reconnected to the network.
Otherwise if it's disconnected, it is still hard to exfiltrate the data somewhere. Maybe they could get creative via Bluetooth, but then you would need a cooperating device in proximity of the device.
I happen to have a NAS with family pictures I like to display. I can (and do) firewall that thing, but then you hit other issues like the apps you need to show pictures and movies in the first place not to install/run.
I've yet to hear of a reasonable recipe to isolate and secure such connected TVs. And don't get me started on Chromecast or other Android dongles, I've no reason to expect better treatment from Google. Some open source hacked-together box, then?
I turn on the device, the app in the upper left is selected and showing some content from that.
The device sits idle, I get drone footage of landscapes.
If I accidentally bump the wrong button on the remote and get sent into the Apple TV (streaming service) app, sure it advertises producte, but in general there are no ads.
In comparison, Google TV's homescreen is giant ads for content on services I don't subscribe to, Roku is at least as bad, Amazon is worse, and Samsung and LG......oof.
I enable app-only mode on my chromecast and does not see any ads.
I suppose my next device is an Apple TV or some kind of home brew Linux box.
The Shield at launch was an amazing product - premium UX and hardware, premium price point. Google changed the experience to an ad-loaded mess without providing an opt out for those who had spent hundreds of dollars on the Shield.
I was dogfooder, a huge advocate of the product, and someone who had convinced others to buy the Shield and Android TV devices. That UX revamp and how the team treated their customers (internal and external) turned me off the product for life. I tried the various competitors (XBox, Roku, Amazon) before landing on Apple TV. I now own two Apple TV devices - both of which are still getting updates many years after I bought them - and will continue using them for as long as the product line is maintained.
People in this thread have talked about Apple's clean beautiful ad-free UX, but the apps themselves are far better. Apple sets customer-friendly App Store requirements *and enforces them*. That means:
* The back button always works. It will bring you back to the home page of the app and then to the system launcher. It will not get stuck in an endless loop of "are you sure you want to quit?" and just dismissing that dialog like multiple Android apps do
* No loud obtrusive sounds on app startup (YouTube, Netflix)
* The apps are first-class priorities for developers. Circa 2019, the Paramount+ app was an inconsistent mess where subtitles were broken on some platforms. The Plex app wouldn't transcode certain formats on the XBox, and so on. None of these issues are a problem on Apple TV. Not every app is perfect (Dropout, I love your content, but your app is awful), but none of them are worse than on any competing platform.
Apple TV is a truly incredible product and ecosystem and one that feels like a joy to use. That's not the case for Android TV (now Google TV, I think?) even with a custom launcher.
It's more expensive than a 40€ Chromecast, but also SO MUCH BETTER.
I chose one over the Apple TV because I knew I wouldn't able to stand any limitations on sideloading. For a while I was running a custom build of Wholphin with patched libmpv/libplacebo to work around a bug before the fix was upstreamed. A device without the freedom to do that sort of thing would drive me nuts.
If you only care about file playback, bit still care about things like HDR and quality audio I would recommend something like the OSMC Vero V instead.
It's still relatively cheap, and open source, but also let's you playback something like a blu-ray rip without loss of quality.
It has the other bonus of not requiring any real setup or maintenance.
On most devices Dolby Vision, etc get downgraded or support only the streaming profiles (profile 5) . If you want full Atmos, Dolby Vision, etc you have to buy one of only a handful of devices. The Vero V is one of them. There are only a few others.
Mine comes with i5 8500t, 16gb ram and 256gb ssd, and it was like $150.
I've just used an old Intel NUC with Debian stable, a remote mini-keyboard and an automounted Samba share on the network forever. It's no more hacked together than any other computer. I do make the mouse pointer and the fonts real big. No apps required. Don't really need the keyboard except for mplayer hotkey presses - just the touchpad on it; if I need to do something that involves typing other than typing a password, I usually ssh in.
I think people are lowkey addicted to having shit sliding in and out and constantly being advertised to. How do you know what to watch unless somebody is constantly bombarding you with options? If it doesn't look like a star trek control panel, is it really TV?
If you like that, you can install Kodi. I haven't tried it since it was XBMC because I found the interfaces annoying and it had trouble dealing with networks, but I'm sure it's better.
> I've yet to hear of a reasonable recipe to isolate and secure such connected TVs
I don't even try. I overpay for dumb tvs in the present, or underpay for 10 year old tvs pre-Applefication. I've never owned a network capable television, or one with apps. I wouldn't.
edit: if your NAS is a separate box that can sit in proximity to your television, you could probably just run all of this stuff directly from the NAS. They spend most of their time doing nothing at all.
But yes, support for the ethernet mode as far as I'm aware was never actually implemented in any devices that reached retail availability.
That could of course change. Could be even a nice feature for connecting your TV to the network via your multi media center, if the bandwidth is good.
https://www.techspot.com/news/113031-lg-alienware-monitors-c...
Proportion of non-HN users whose TVs don't connect to the internet? Negligible
HDMI Ethernet is dead, it's never going to happen in consumer televisions because it has a hard conflict with a feature a lot of people actually use.
But I guess like an xkcd comic, someone is obligated to raise the issue every time TVs come up.
There's no need for the TV to be anything but a dumb screen that has only "power on", "power off", "volume up", "volume down" and "mute" functions. Most are probably too underpowered anyway to be useful.
Samsung were openly bragging about this on their website some years ago (for the benefit of their advertising partners) but have recently muddied the waters when I check their site again, couching it in language mentioning privacy and other evasive language:
As far as I know, they don't literally scan your media libraries; they screenshot whatever you're watching through HDMI (most often cable / satellite boxes), as those devices don't provide the telemetry that normal apps do. This info is used for audience measurement (thing Nielsen ratings), as well as showing you ads that are actually likely to match your interests.
"Starting in 2014, Vizio made TVs that automatically tracked what consumers were watching and transmitted that data back to its servers. Vizio even retrofitted older models by installing its tracking software remotely. All of this, the FTC and AG allege, was done without clearly telling consumers or getting their consent.
...
"Vizio collected a selection of pixels on the screen that it matched to a database of TV, movie, and commercial content
https://arxiv.org/pdf/2409.06203 shows LG and Samsung doing something similar
> the idea of a modern dumb TV is non-existent.
They're sold as commercial display panels/digital signage and because they're a business product that isn't subsidized by advertising/spyware they cost a good bit more. But the panels and controls are basically identical to high end TVs.
Is there any TV on the market that flat out wont work if it can't see the internet?
But they've been calling "crazy?" for decades.
I'm hopeful that there will be sufficient distrust that "jailbreaking" or "rooting" TV controller boards will be turnkey enough to move to something like OpenWrt or GrapheneOS but for TVs.
I suppose I also assume someone with Android ROM development experience is better positioned to take up organizing such a project as an overall smaller effort, there by being faster and more efficient. Other real life constraints also seem to suggest not pursuing this type of thing in lieu of other things I should be pursuing and already procrastinate. But, here there be dragons, or at the very least a can of worms.
I'll bet there is already a manufacturer whose TVs can all communicate intratelevisually (non-standard proprietary frequencies) – and then, if even one of them is online... they're all relaying within their private intra-TV spyware meshnets to their various relays.
----
In unrelated news, my 2012 Sony Bravia is still fantastic, even if not for (4K) high-refresh games (the image quality remains fantastic for casual usage).
People don't say that so much anymore.
It's worth remembering that for all the animosity they face, they did what they told you they were going to do when they asked for your permission to do it.
I'd just block them - and keep local streaming and remote control working
edit: just found out WebOS doesn't support DoH/DoT so nextdns won't work.
I wonder if one of the public dns providers got LG blocklisted natively with specific IP
I bought a DJI action camera, I had watched a bunch of reviews and read the store page. Yet only after buying and turning it on did I discover the device only allows you to use it 5 times before connecting it to the internet and signing up for an account.
There aren’t even any features that require this, it simply bricks itself after the 5th use until you sign up and agree to the terms.
I do have it isolated from other devices on my network, though.
Not GP, but I do so to make sure my TV doesn't try to connect to a different network. I provide specific IP addresses to the ethernet-connected interface and then block those IP addresses.
I suppose I could also move the TV to an isolated VLAN, but I spent months (the device was purchased nearly, or perhaps even more than, a decade ago) monitoring network traffic to determine to where (via DNS queries and packet captures) my TV was trying to phone home and blocked all egress for the TV and ingress from the sites/IP addresses to which the TV tried to connect.
I suppose that newer TVs might be sneakier (with the kind of WiFi surfing mentioned in TFA and/or installing cellular modems) in their attempts to bypass user control and when I need a new TV, I'll burn that bridge when I come to it.
But for now, my TV can't phone home. Or I'd have thrown it away years ago.
It's actually a lot faster now (it's an 8 year old TV, their OS can get a little heavy on older models)
Same for anything whether you trust it or not (or somewhere in between).
I remember these things being discussed a while ago on here, how TVs use their own hard coded DNS ("for safety") rather than any network provided DNS (to avoid filtered DNS ala PiHole), how there's Ethernet in a HDMI cable, how other wireless networks are tried, and how eventually they'll go the car route and just embed a wireless modem in the device.
I'm sure somebody at LG is hard at work on fixing this problem.
Idk why this is so often citied in Smart TV boogeyman arguments.
The sad part about the privacy discourse is that people not only don't care, but they would argue for the invading party. And I am not talking about your average teenager looking for their next brainrot fix, but highly educated and extremely intellegent people!
I've long since gave up trying to talk to people about these issues. Which unfortunately means I'll surrender to exposing myself to this plague to some degree, considering how herd immunity principles apply here as well.
that's not a plus, tho