50% of LG and Samsung smart TV apps embed residential proxies

2 Likes

I’m not sure what to recommend as a mitigation

The best option, ‘dont use smart TVs, watch local media only’. But the vast majority of normal consumers lack the time/money/tech skills to manage a local media server

Maybe, stick to cable? But again, most households now consider streaming services to be a utility

‘Dont install untrusted software’ is useful advice to those who know what theyre doing. To a novice, the distinction may be much less meaningful. And while this article discusses backdoors in applications, the backdoor could just as easily be buried in the OS or firmware

TV has become a blight to privsec, and unlike other platforms, doesnt really have a strong & accessible alternative

3 Likes

I think the easiest mitigation is to use an Apple TV or similar system to completely avoid using the native TV OS.

Just don’t connect the TV to the internet at all and steam via another device connected via HDMI.

3 Likes

How much risk does that actually reduce? Unless you’re using a secure device as a source (a PG-recommended Linux distro, for example), wouldn’t the auxiliary HDMI streaming device have LAN access, and theoretically present an identical attack surface?

Agree, AppleTV is probably the best mainstream plug-and-play option, just due to how brutally locked down secure the iOS ecosystem is

2 Likes

The TV would only be connected to the external streaming device through HDMI as a video output device.

To my knowledge, the malicious applications of concern are running on the TV OS. The TV OS has no way ‘out’ to the internet via the HDMI connection to the streaming device. They need the native TV OS to have a data connection itself.

1 Like

I do agree: disconnecting the TV from internet neutralizes the threat to the TV, and this malware cant infect a secondary device from the TV over HDMI

It did read to me as though the supply chain attack happened through third-party apps installed via the TV’s app store:

Spur’s Trevor Sutter downloaded and unpacked smart TV application packages instead of relying on store descriptions or developer disclosures, and analyzed them

If you are using a ‘streaming stick’ like Roku or Firestick, I would think their separate apps would be as susceptible as those on the TV’s app

I would also be inclined to believe the streaming stick OS is no more secure than the TV OS, in the event malware does get installed at a firmware level from the factory

2 Likes

From the article it’s not clear if these SDK are used by pre-installed apps or by apps users can install themselves. Both are really bad but a pre-installed residential proxy is way worse

1 Like

That is an important nuance. An Apple TV would be a safe option but if using less locked down devices like Fire Stick or Roku there are other concerns that present themselves.

2 Likes