They are likely going to have access. Lots of things have built in cellular modems these days, and your cable provider already uses your cable modem as a hotspot for other people.
You can do things like physically modifying your TV, or seeing if there are undocumented settings to disable things.
Plus the DNS spying even after disabling their safety stuff (impossible to change DNS on Comcast Xfinity-provided gateway). Still trying to get as good speeds with my own equipment.
Yes. Xfinity is the big one. Their devices create two hotspots: one for the customer and one to power their Xfinity WiFi service and for bandwidth offloading for their cellular service.
Yea this almosts sounds like it could be a great idea with proper execution, nothing like this in the UK. Imagine if they were upfront and said "well knock a tenner (or whatever is reasonable in the US) if you allow your access point to be used as a hotspot"
Major ISPs in the US have been doing it for at least a decade. Xfinity Wifi [1] claims over 20 million wifi hotspots provided through customer routers.
Yes. Cox has been doing it for years. They boast citywide hotspot access for all subscribers. I formerly thought that this hotspot network consisted of dedicated APs which they mount and maintain on utility poles in public places. But that’s just the start.
Every Cox customer has a Panoramic WiFi router that advertises as a member of the “CoxWiFi” SSID, and other customers can authenticate there and access the Internet through your connection. This is on a strictly opt-out basis.
I’ve opted-out, and also my router is permanently in Bridge Mode, so there is no technical way for me to provide anyone a WiFi connection. But all my neighbors do, even if they are blissfully unaware.
The best thing about fibre rollout in my region is that the ONT appears to act as the modem so I don't need to set the modem/router into bridge mode any more.
Absolutely. Independently of the unauthorized sharing of your bandwidth, ISP gateways are notoriously insecure and underspec'ed. They also have nasty backdoors[0].
If its a hotspot you'll have to login to authenticate, so presumably the traffic is uniquely identifiable. I'd hope when LE contact ISP for details theyd be able to go oh that ip address is here but it was actually this persons traffic.
I'm fairly confident that ISPs do not log all customer traffic, especially for an indeterminate amount of time. There would not be enough storage on the planet available.
The traffic was separated so that anything on the public hotspot was not attributed to the private subscriber network.
Secondly for years I lived somewhere very remote so that meant that hardly anyone ever got to use my broadband connection via such a hotspot, but I got to use hundreds of other peoples hotspots when I was somewhere less isolated.
I was quite happy to opt in to this system as I benefitted hugely from it.
It sucks being in an apartment complex because there are always a bunch of unsecured networks floating around that the TV, or whatever, can connect to even if you don't manually do it.
removing the cellular modem from a car can have several unintended consequences.
The geniuses at hyundai refuse to let you operate the heating in some of their electric cars without an internet connection. Yes, you read that right - the only way to operate the HVAC compressor in several hyundai EVs is via their stupid app and the internet. I found out the hard way when i kept noticing that my hyundai EV was not heating the cabin in winter even though i turned the HAVC on. Turns out, as soon as you plug into the wall outlet, the compressor stops.
There is no technical reason for this, other than enshittification.
Would using an older wifi router that you have lying around as a anti-smart device network work? Fire it up with no WAN signal. It's just a radio broadcasting an SSID that you can connect a device to. Are the "smart" devices smart enough to know there is no WAN signal and keep searching for a different connection, or will it be tricked into not being able to connect to the internet?
Except... some of us like to stream content on TVs. And some of us really don't like the idea of maintaining yet another extra piece of hardware for that.
And so your TV does need Internet access.
The same holds for many other devices, in different shapes. Sure, you can opt out of civilization completely to avoid all the side effects of late stage capitalism, but maybe it's worth applying a bit more nuanced thinking to find a balance that doesn't throw you back to the 1800s. (Unless you like the 1800s, in which case, enjoy)
> Except... some of us like to stream content on TVs.
Linux mini-PC running Bigscreen Plasma. No, it can't be used to stream Netflix at native resolution because of DRM. But if you can't live without Netflix content, you can use alternative sources and save money in the process. VacuumTube for YT instead of the official app.
Yes, this is an additional device, but it is not unlike a streaming stick or Android shitbox.
classic linux advice lol. disable the smart features on your TV and then buy a whole computer so you can ... not be able to watch netflix and youtube on your TV
disclaimer: i run a whole variety of home media stuff, so i am one of you - but it's just a funny example of exactly the kind of thing that makes people not do this stuff
I self host a lot, including jellyfin, but I've never tried to do the Linux HTPC. Whenever I look into it everything has changed from a few years ago, it all sounds difficult to get working and keep working, and I give up. I didn't know we had a whole new set of software. It was once MythTV, then XBMC, then something else I can't remember, and now I've lost track.
> I self host a lot, including jellyfin, but I've never tried to do the Linux HTPC.
I think now is the right time to revisit the Linux HTPC, mostly because Plasma 6.7 integrated the new Bigscreen interface. This is a genuine 10-foot desktop environment optimized for TV remotes and controllers. Previously, most Linux HTPCs simply used GNOME/KDE, with the scaling cranked up to 200 or 300%. In terms of apps, I suggest Kodi for local files, VacuumTube as a Youtube TV/Leanback substitute, and Steam or SteamLink for gaming, depending on hardware. With an airmouse remote you can also simply use Firefox or Chromium and stream from pretty much anywhere, subject to resolution restrictions for Netflix and some other services.
Kodi is essentially a media player; it's not a general purpose TV UI like Plasma Bigscreen. Yes, there are a couple of distros out there like OSMC designed to use Kodi for everything, but in my experience they are way too limited. And you really do want a Web browser for streaming, because you are unlikely to find dedicated Linux apps for whatever streaming platform you intend to use. You could presumably run Waydroid and use Android apps, but using the Bigscreen virtual keyboard or a remote with a keyboard on the back is much easier.
If the TV only plugged into the wall for electricity and showed the video that was fed into it via one of its inputs, does that TV qualify as "yet another extra piece of hardware that needs to be maintained"? The only reason it needs "maintenance" is because it does all this extra "smart" stuff. A separate device that has the "smarts" and treats the TV as a bare monitor screen would still be only one device to "maintain".
Back when I first started my career, I generally disagreed. My first job was at a connected device startup in the IoT space. The whole ethos around data was pretty good. Maybe it was because the tech side of the company I worked for was 99% ex-gov contractors (aerospace, low level routers, submarines...).
We collected such minimal information. Basically only enough to allow for OTAs, functionality, and debugging. Thinking back, we could've collected so much more.
I remember when Alexa hit the market and we (as a company) thought there's NO WAY amazon was making any money on them.
Today... NO WAY. Along the way the value stopped being "This product is priced so we can make a profit" and became "The data we collect is more valuable than the sale".
Well, nowadays the purpose of a TV is usually to watch content over the internet, so I wouldn't call it "stupid" to connect the TV to the internet.
You might say it's naive, but is it really naive to buy a TV and expect it to be a device to display audiovisual content and not a spyware/adware machine?
I feel like it's not the user's behavior that should be put into question here, but the borderline criminal behavior of the manufacturer.
This is an exhausting read. From the diminishing use of the word “rape” to the steam of conscious delivery to the blogspam cliches of hyperbole and exclamation.
The malware installed by LG on Microsoft PCs and the spying by smart TVs are both despicable. But I couldn’t get through this article.
I find it so incredibly short sighted to implement such shenanigans. I was set to buy a LG 39GX950B as an upgrade to my current ultrawide until I read that they will automatically install an installer that will ask whether you want to install additional tools every freaking time you plug in the monitor. Absurd.
I disagree, clearly purchasing choices only hurt you and doesn’t help the situation.
Instead we should embrace hacker culture and take by force that which won’t be given to us. By force I mean the gentle kind of force of forcibly owning the stuff you already legally own.
There’s never been a better time, we’re in this sweet spot where we have LLM agents that can help normal people do this stuff, but not yet at the point where a significant amount of the consumer technology we use has been hardened.
> Hah! I don't have to worry about this! I got Linux! For now.. That's true. But EDID transmission still happens
EDID transmission is how monitors communicate their specs to the computer, how is that an issue?
In fact, EDID transmission is one of the reasons you can plug a monitor into your computer and have it "just work", without needing to install additional proprietary drivers (why do this?)
> But what stops LG from convincing the Ubuntu maintainers to make an LG variant of their supposed driver to magically appear in your snap or apt package repository? You hope to God they don't, but the danger is always there.
So the whole argument there is that yes, it is safe, but there exists a nonzero possibility that it won't be in the future? Couldn't the author have just written "this is not an issue on linux" and saved paragraphs of breathless purple prose?
A periodic reminder that you can buy a TV that's not smart. It won't be the fancy Samsung wall-art one and it won't be the absolute shiniest display tech out there, but it will be good enough, it'll be dirt cheap, and it won't have a network port or an 802.11 radio.
[Sceptre](https://www.sceptre.com/TV/4K-UHD-TV-category1category73.htm...)'s 4K series is sold at Wal-Mart, often for under half the web-listed prices. I’ve bought a few at the 42” scale for like $180 shipped. They’re fine and they’re incapable of all the spyware bullshit.
Yep! Our family is on our second one. First was 42” and lasted five years. Current one is 55” and is going on seven years. Both were around $200-250. Picture quality is great for us. Apple TV takes care of streaming. And easy connection to our stereo gives great audio. Cheers!
A bit into tinfoilhat territory but just because they don't advertise that they have an 802.11 radio doesn't mean the devices can't have one. Or an LTE/4G/5G radio.
If the user data is worth that much then I wouldn't be surprised if some manufacturers put such radios in their non-smart TVs in order to try and gather such data.
I live in a densely populated part of a large UK city and (checks `nmcli dev wifi list`) there are 14 distinct wireless networks near me that aren't mine. There's a good chance that any IOT device could find something nearby, and there's even a whole load of LoRa nodes that it could use for a very slow uplink.
> Amid the overall electronics boom thanks to A.I., … one piece of electronics is almost unchanged financially. That is the digital display or flat-panel monitor.
I guess theyre talking about all the electronics being used to populate the various data centre's popping up about the place. The GPUs, RAM and what not
Interesting, I knew about these EDID devices to use to pair with KVM for a slightly better experience, but never thought about their use on this perspective!
It's not a matter of "cheap", even the high end Sony TVs have spyware on them by default. The best thing you can do is get Claude or Codex to adb into your TV and uninstall all the malware, then keep it disconnected from Wifi and use an external box like Apple TV to watch.
Just disconnecting from Wifi often doesn't work because the TV will connect to insecure wifi to upload data and fingerprint what you're watching and who you are.
> Just disconnecting from Wifi often doesn't work because the TV will connect to insecure wifi to upload data
Is there any evidence of this actually happening? It's oft stated yet I've never seen any proof or specific models where this has been observed.
It made more sense when I first heard this theorized back in the early 2010s when smart TVs were becoming more common and unsecured WiFi hadn't vanished completely yet. Now it would be way more logical to include a cheap 5g radio, which has also been alleged but I haven't seen any model shown to include one.
Warren Buffett has often said, "In looking for people to hire, you look for three qualities: integrity, intelligence, and energy. And if you don't have the first, the other two will kill you."
The exact same logic applies to devices you buy. These companies have shown they do not have any integrity. So why would you want buy something from them that is "smart" and never sleeps?
Because our government has failed to protect us from monopolies or duopolies. How many things can you buy with modern technology that you'd say the brand had integrity?
Yea competition only enforces integrity if consumers are selecting for integrity. Without getting into a nitty grityy morality debate, you've got an obvious first issue here that many if not most people dont know what they are buying when it comes to tech, so we cant expect a market to correct for our perceived morality if the consumers havent even got a clue they're being slighted in the first place.
The solution for smart TVs is to not connect it to the Internet and attach an Apple TV. Sure they’ve gotten expensive, but how much is your privacy worth?
Yup. Samsung & Sonys too. Dumb mode, no internet, Apple TV.
Doesn't solve the malware on Windows PCs installed by LG monitors problem. My only solution to that remains to not buy Lucky Goldstar ever since their 14" 640x480 VGA monitor died inside of warranty but they refused to fix it.
The Shield sucks too, unless you go super nerd and fix all its problems. They treat your home screen like a billboard, and I have no faith that they're not stealing all my data either.
Android lets you put on your own launcher. There are many options to choose from in the store and online. It is one the main selling point of Android, you have options and aren't limited to their marketplace.
That’s what I meant by go all super nerd. I don’t want to fight with: my phone, my car, my router, my desktop/laptop, dishwasher, home automation system - just to pull out the surveillance and adware they’ve jammed in there. Life is too short for all that, and I’ve wasted enough time on that as is.
Literally just now it went jamming some Ford 150 ad on me, auto repeating. On the f’ing Home Screen!!
I don’t know what I’ll replace it with, but it sure AF won’t be some corporate owned ad riddled POS like this.
Or attach an xbox or playstation and use the youtube, netflix etc clients on that. Both MS and Sony have a very strong interest in not letting their operating systems become host to virus/worm/trojan categories of software, as it would be a risk of game/content piracy. Yeah, you'll get ads for MS or Sony products and games on the home screen.
But I have a thousand times more confidence that MS will keep the signed, auto-distributed periodic xbox series x operating system updates 'secure' than I do that some random smart tv manufacturer will implement a proper operating system.
What if you want to hook a gaming PC up to a smart TV? Linux has come far in recent years, but Windows is still the most broadly supported gaming OS.
Once awareness of this side-loaded crapware gets out, I'd expect the community to come up with fixes to ensure it doesn't get loaded. In the meantime, this should blow up in the faces of MS, LG, etc. just like things blew up for Sony when they put root-kits on CD's.
Does it play ad-free youtube? I see now that looking at their apple TV doesn't mention much about other products being available, but the app, which I guess is not the same thing, says something about it.
Chromecasts seem to at least have reduced ads, but I'd do almost anything to be able to stream youtube (or ideally any webpage) to an arbitrary screen with functional adblocking.
The article addresses that. This is about the recent controversy where plugging an LG display into a Windows machine caused unwanted software to be installed as a "driver update". Disconnecting the TV from the Internet is completely irrelevant to the article.
You've got to be careful, though. Consider that they have non-deletable apps, tiny amounts of onboard storage, and that every "app" WILL bloat over time. So, with those updates installing the latest version of Netflix, Prime, HBO Max, Paramount, Tubi, LG Channels™ etc... it means it's filling your 4GB or whatever storage fuller and fuller. Eventually the storage will be nearly full, which shouldn't matter, except that it's a computer, and having storage nearly full makes it slow as shit to do everything, even "boot up" and "change inputs".
I don't actually believe the claims of this blog. A driver for a monitor from Windows update allowing mcafee antivirus and/or other programs to be installed automatically? I think more details should be shared. Also contains a long rant about EDID which I think is unwarranted.
It does sound totally ridiculous. Sadly it may not be. Previously discussed: https://news.ycombinator.com/item?id=48956688 "LG monitors silently install software through Windows Update without consent".
You can argue if it actually installs the software or just nags the user to install it, but neither are things microsoft would allow a monitor "driver" to do if they had any integrity.
An install of Windows 11 from MSFT-provided media on an HP desktop PC earlier this year resulted in a ton of HP driver-related crapware on the PC. Windows Update will happily download drivers and user-mode software the driver manufacturer flags as being related.
There is a Group Policy setting under Computer Configuration / Administrative Templates / System / Device Installation / "Prevent automatic download of applications associated with device metadata" that seems to curb most of it, thought I still ended up with a user mode app related to the audio driver.
The reason this keeps happening btw is because we haven't sent anyone to jail over it. Not even when it's clearly criminal, like when Google tracked location data despite opt-out [1], or when LG did what they're doing now but forgot to bury something about it deep in the EULA [2] (we're all totally on board with click-through EULAs having such power, right?)
The 2nd story is crazy - I wonder if I hack LG and start downloading all their trade secrets, when caught, the government would just let me stop the download and face no punishment, if I say I just forgot to ask them for consent. Or maybe it's different if I do the hacking through a backdoored cable I sell them, like they hack us through backdoored TVs.
> Oh, there's a driver update for the LG television. Makes sense, right? It's a fairly recent television, and the drivers will help us take advantage of all of the TV's features. Of course, I'd like Microsoft to download it.
At this point I assume the author was making intentionally bad choices out of morbid curiosity. I can't imagine anyone technical thinking drivers should be required to connect to a TV via HDMI. (or maybe I'm not technical enough)
Windows used to always give a little popup saying it was installing drivers when you plugged shit into it. Now, apparently, TVs are for some reason trojan horsing this.
There's no reason to expect a normal user to think "Yes, this port is the USB port and thus commonly needs driver updates, but that HDMI port does not ever need driver updates." Most people don't even know it's called a USB port, let alone whether it should host driver updates. Besides, I could imagine a scenario where there's some outdated HDMI decoding thing on it. Or maybe just some tech for home theater stuff I'm not aware of.
It's shocking how many comments here didn't bother to read the article. At all.
They're not talking about putting the TV online. The TV is completely offline.
They're talking about plugging the TV into a PC or laptop via HDMI or Displayport (like if you're running an HTPC), which then triggers a companion app update on the PC via Windows Update. This was a news item a few weeks ago with their monitors. They then also discuss a hardware blocker for HDMI or DP to prevent this.
Again, this has nothing to do about the TV's smart apps.
I was unaware of these side-loaded malicious apps until now. This is information consumers need to have.
It's very reminiscent of Sony putting rootkits on CD's. Unwanted, dangerous software is being loaded onto your computer by people you paid money to. The companies involved, including MS, should face serious blowback over this, as Sony did.
This isn't even the worst payload ever delivered through Windows Update. The prize for that should probably go to chip manufacturer FTDI, which once abused the system to publish a driver that would semi-permanently brick USB serial bridge parts the driver detected as counterfeit [1] by exploiting a command that the genuine parts did not implement correctly (how ironic) [2]. The backlash was large enough that Microsoft ended up pulling the update almost immediately, but that did not stop FTDI from trying again a few years later with another driver update that deliberately corrupted data sent through detected-counterfeit parts.
It's about time some company was prosecuted under CFAA for this kind of abuse. This should easily fit the legal definition of "intentional unauthorized computer access."
But we all know, the law is enforced aginst regular people, not corporations. Are corporations ever prosecuted for invoking something on a user's computer without their authorization?
> I was unaware of these side-loaded malicious apps until now. This is information consumers need to have.
I really want to ask, earnestly, how do we communicate these things earlier?
I don't think there's a shortage of HN users that one about this type of bullshit going on. I'm not going to tell you "I told you so", and I'll even attack those that do. But when people who are concerned with these types of issues talk out they get dismissed as being conspiracy theorists or simply too sensitive.
I'll admit that sometimes it can be hard to differentiate, but well respected experts in the tech field have discussed such issues for decades. So I really do want to understand, how do we reach you earlier? Before we get to this point. How do we not just come across as uppity tech nerds screaming "I use arch btw" in furry programmer socks?
I really do think we as a community need to figure out how to reach the public better. We're well past what was considered terrifying in 1984. We aren't a society where big brother could be listening to you at any time, we are living in a society where uncle Mark is watching you all the time. Where uncle Pichai knows who all your friends are. Where uncle Nadella knows when you're awake. They know whose been bad and good but they don't even have the decency to deliver gifts under the Christmas tree. Are we only fighting back because their actions have become so obvious? Or are we fighting is the principle enough?
Its not entirely clear from the article--is the EDID telling Windows to install the driver without asking you, or is it prompting you to install a driver, you are agreeing, then along with the driver comes the junkware?
The EDID is just a model identifier and some capability metadata, it can't tell Windows to do anything.
It's Windows that decides that it should download a driver from Windows Update because it recognises it hasn't got a driver from that hardware, and it's Microsoft that let the vendor submit drivers that are bundled with near malwareto Windows Update.
That is how you end up with walled-garden OSes. Users plug in random device into their computer, the OS vendor tries to simplify operation by installing a device driver that was not vetted, and then users complain they are not protected.
Then the OS vendor will start limiting which devices they support and with very strict review processes.
This is a fair trade off for many. I want my OS to protect me. All things being equal, if my OS doesn’t help shitty vendors install unwanted stuff… good.
It can swing the other way, my options are limited to company’s that pay my OS provider for access.
My OS has no walled garden and also does not randomly install drivers when I plug hardware in. It comes with generic defaults, adds drivers I tell it to, and never modifies anything without me telling it to. Crazy idea.
Basically, Windows has been installing monitor drivers for a very long time automatically. Usually a single INF file. Recently, companies like LG have discovered and abused that by instead of just that single INF file, they are installing software that pushes malware like McAffee anti-virus onto your computer.
More of a Windows Update + MS partner issue than EDID.
One day someone would reverse engineer the data TV feeds back to mother ship, and makes a fake driver to feed it garbage. Or not garbage. I could see some fun and profit a crowdfunded poison data could generate
>You know what? There's really nothing good to watch on TV anyways. If Hollywood has to subsidize the television industry just to keep its base, it doesn't have any money to invest in anything new. Every channel just wants to brainwash you. So throwing the Flat Panel into the garbage might be a good idea anyways.
Definitely have to agree with the author on that. Only use for a TV for me is for playing on the Steam Machine.
I couldn't understand what this article was saying.
There's nothing nefarious about EDIDs. EDIDs are just a way of the monitor to announce its capabilities to the device so that the device and the display can agree on things like resolution, refresh rate, etc. EDIDs are just blobs of data without capability to execute logic, as far as I'm aware.
It sounds like the author is claiming that Windows does some sort of driver update in response to EDID announcements, but OP doesn't explain it at all. If that's true, that would entirely be on the Windows end not on the EDID's end. It sounds like Windows is recognizing LG as the manufacturer declared in the EDID and then downloading a driver for LG. I don't think there's any way for the EDID to declare to the OS that it wants to perform a driver update.
In a nutshell, the article is saying that because you can't guarantee OS vendors won't go down the path Microsoft has (i.e. installing unwanted software as a "driver update" when you plug the display into your computer), it's therefore better to block the EDID just in case your Linux distro vendor goes rogue too. I don't agree with that argument, personally, but that's the argument he's making.
This is indeed what is happening behind the scenes. By default Windows Update will automatically download and install support packages for pretty much any device Windows can identify through manufacturer/device IDs, which includes PCIe and USB devices but also monitors. This is most commonly used to deliver drivers but Microsoft allows these packages to silently install any user-facing application as well, presumably due to peripherals such as GPUs or audio chipsets often requiring "control panels" or similar companion apps.
Around a month ago LG took advantage of this feature by publishing a Windows "driver" for all their TVs and monitors that consisted entirely of payola bloatware, resulting in predictable backlash [1] and the obligatory subsequent HN discussion [2]. None of this has anything to do with the TVs themselves being connected to the internet or not.
The computer should not do something that the user did not specifically command. It should not guess, "Oh, the user plugged in device X. This means I have the user's consent to download and install software."
Me to my normie friends and family: "Never connect your TV to the internet."
Them: "But then how will I get Netflix?"
Me: "Get an Apple TV and connect it to the internet. Then connect that to your TV with an HDMI cable."
Them: "I don't need an Apple TV. I just bought a TV!"
Me: "Apple TV is not a TV. It's a little box."
Them: "Then why does Apple call it a TV?"
Me (snarky): "I told Steve Jobs not to call it a TV but he did it anyway."
Them: "This is all too confusing. Just buy the things and hook it up. Here's my credit card."
Me: "OK"
Them (one month later): "Hey our new TV is working great!"
Me: "Good!"
Them: "Except it shows us an unskippable ad whenever we turn it on, and the ad seems to know a lot about us."
Me: "Um...that shouldn't be happening."
<investigation begins>
Me: "This TV knows your wifi password!"
Them: "Oh yeah! After you left last month the TV asked us if we wanted to 'finish the setup process'. So we did what it told us and now it's happy. Aren't you proud of us for figuring that out all on our own?"
Me (to myself): choose words carefully before speaking, self
I’ve wondering if there is a DD-WRT type firmware project out there for TV firmware. If not how difficult is it to root these? I can’t imagine that they are that secure.
roscas | 8 hours ago
That is just stupid to give internet access to a "smart" tv or a "smart" phone. You have zero control over it.
____tom____ | 8 hours ago
You can do things like physically modifying your TV, or seeing if there are undocumented settings to disable things.
margalabargala | 8 hours ago
Ancalagon | 8 hours ago
Barbing | 7 hours ago
drnick1 | 7 hours ago
Is this for real? This does not affect me as I use my own equipment, but I still find it hard to believe.
WalterGR | 7 hours ago
Instructions for disabling it: https://www.xfinity.com/support/articles/disable-xfinity-wif...
jedbrooke | 7 hours ago
ozlikethewizard | 3 hours ago
akiselev | 7 hours ago
[1] https://en.wikipedia.org/wiki/Xfinity#Xfinity_WiFi
Terr_ | 7 hours ago
https://www.eff.org/deeplinks/2013/06/comcasts-new-neighborh...
ButlerianJihad | 7 hours ago
Every Cox customer has a Panoramic WiFi router that advertises as a member of the “CoxWiFi” SSID, and other customers can authenticate there and access the Internet through your connection. This is on a strictly opt-out basis.
I’ve opted-out, and also my router is permanently in Bridge Mode, so there is no technical way for me to provide anyone a WiFi connection. But all my neighbors do, even if they are blissfully unaware.
saintfire | 7 hours ago
I'm sure that'll end.
DANmode | 4 hours ago
robotnikman | 6 hours ago
drnick1 | 3 hours ago
[0] https://en.wikipedia.org/wiki/TR-069
majorchord | 7 hours ago
How does this work legally when you get in trouble for someone else's activity?
ozlikethewizard | 3 hours ago
ranger_danger | 2 hours ago
alexfoo | 7 hours ago
The traffic was separated so that anything on the public hotspot was not attributed to the private subscriber network.
Secondly for years I lived somewhere very remote so that meant that hardly anyone ever got to use my broadband connection via such a hotspot, but I got to use hundreds of other peoples hotspots when I was somewhere less isolated.
I was quite happy to opt in to this system as I benefitted hugely from it.
skizm | 8 hours ago
drnick1 | 7 hours ago
On a related note, you should absolutely remove the cellular modem from your car as well.
eldaisfish | 7 hours ago
The geniuses at hyundai refuse to let you operate the heating in some of their electric cars without an internet connection. Yes, you read that right - the only way to operate the HVAC compressor in several hyundai EVs is via their stupid app and the internet. I found out the hard way when i kept noticing that my hyundai EV was not heating the cabin in winter even though i turned the HAVC on. Turns out, as soon as you plug into the wall outlet, the compressor stops.
There is no technical reason for this, other than enshittification.
drnick1 | 4 hours ago
Noted. Thank you for reminding us not to buy a Hyundai EV.
DANmode | 4 hours ago
Maybe the engineers wanted to ensure your cabin wouldn’t induce health risks.
DANmode | an hour ago
and they didn’t want to include the variance.
dylan604 | 7 hours ago
blitzar | 8 hours ago
The smart here really isnt the issue.
groby_b | 8 hours ago
And so your TV does need Internet access.
The same holds for many other devices, in different shapes. Sure, you can opt out of civilization completely to avoid all the side effects of late stage capitalism, but maybe it's worth applying a bit more nuanced thinking to find a balance that doesn't throw you back to the 1800s. (Unless you like the 1800s, in which case, enjoy)
drnick1 | 7 hours ago
Linux mini-PC running Bigscreen Plasma. No, it can't be used to stream Netflix at native resolution because of DRM. But if you can't live without Netflix content, you can use alternative sources and save money in the process. VacuumTube for YT instead of the official app.
Yes, this is an additional device, but it is not unlike a streaming stick or Android shitbox.
epiccoleman | 4 hours ago
disclaimer: i run a whole variety of home media stuff, so i am one of you - but it's just a funny example of exactly the kind of thing that makes people not do this stuff
krupan | 3 hours ago
drnick1 | 3 hours ago
I think now is the right time to revisit the Linux HTPC, mostly because Plasma 6.7 integrated the new Bigscreen interface. This is a genuine 10-foot desktop environment optimized for TV remotes and controllers. Previously, most Linux HTPCs simply used GNOME/KDE, with the scaling cranked up to 200 or 300%. In terms of apps, I suggest Kodi for local files, VacuumTube as a Youtube TV/Leanback substitute, and Steam or SteamLink for gaming, depending on hardware. With an airmouse remote you can also simply use Firefox or Chromium and stream from pretty much anywhere, subject to resolution restrictions for Netflix and some other services.
krupan | 2 hours ago
Why would I want to futz around with a web browser on my TV? How am I going to type in my passwords?
drnick1 | 56 minutes ago
thwarted | 7 hours ago
fusslo | 7 hours ago
We collected such minimal information. Basically only enough to allow for OTAs, functionality, and debugging. Thinking back, we could've collected so much more.
I remember when Alexa hit the market and we (as a company) thought there's NO WAY amazon was making any money on them.
Today... NO WAY. Along the way the value stopped being "This product is priced so we can make a profit" and became "The data we collect is more valuable than the sale".
afarah1 | 7 hours ago
You might say it's naive, but is it really naive to buy a TV and expect it to be a device to display audiovisual content and not a spyware/adware machine?
I feel like it's not the user's behavior that should be put into question here, but the borderline criminal behavior of the manufacturer.
dpark | 8 hours ago
The malware installed by LG on Microsoft PCs and the spying by smart TVs are both despicable. But I couldn’t get through this article.
spockz | 8 hours ago
Terr_ | 7 hours ago
Even if they were convenient shenanigans, in the longer term:
Political action > Purchasing Choices > Individual modifications
left-struck | 6 hours ago
Instead we should embrace hacker culture and take by force that which won’t be given to us. By force I mean the gentle kind of force of forcibly owning the stuff you already legally own.
There’s never been a better time, we’re in this sweet spot where we have LLM agents that can help normal people do this stuff, but not yet at the point where a significant amount of the consumer technology we use has been hardened.
ebtebt | 7 hours ago
A non-cohesive angry rant
ImPostingOnHN | 7 hours ago
> Hah! I don't have to worry about this! I got Linux! For now.. That's true. But EDID transmission still happens
EDID transmission is how monitors communicate their specs to the computer, how is that an issue?
In fact, EDID transmission is one of the reasons you can plug a monitor into your computer and have it "just work", without needing to install additional proprietary drivers (why do this?)
> But what stops LG from convincing the Ubuntu maintainers to make an LG variant of their supposed driver to magically appear in your snap or apt package repository? You hope to God they don't, but the danger is always there.
So the whole argument there is that yes, it is safe, but there exists a nonzero possibility that it won't be in the future? Couldn't the author have just written "this is not an issue on linux" and saved paragraphs of breathless purple prose?
majorchord | 7 hours ago
Arubis | 8 hours ago
[Sceptre](https://www.sceptre.com/TV/4K-UHD-TV-category1category73.htm...)'s 4K series is sold at Wal-Mart, often for under half the web-listed prices. I’ve bought a few at the 42” scale for like $180 shipped. They’re fine and they’re incapable of all the spyware bullshit.
AvAn12 | 7 hours ago
gigel82 | 7 hours ago
reaperducer | 7 hours ago
I don't know where you are, so I can't say what availability is like there. But it's worth doing a basic search.
gigel82 | 7 hours ago
alexfoo | 7 hours ago
If the user data is worth that much then I wouldn't be surprised if some manufacturers put such radios in their non-smart TVs in order to try and gather such data.
I live in a densely populated part of a large UK city and (checks `nmcli dev wifi list`) there are 14 distinct wireless networks near me that aren't mine. There's a good chance that any IOT device could find something nearby, and there's even a whole load of LoRa nodes that it could use for a very slow uplink.
hughw | 7 hours ago
[edit: or whatever UK FCC would be]
nobody42 | 7 hours ago
fg137 | 8 hours ago
What is it talking about? What boom?
tripleee | 8 hours ago
gruez | 8 hours ago
tripleee | 7 hours ago
madibo3156 | 6 hours ago
…is the full quote. Come on, guys.
monocasa | 7 hours ago
Terr_ | 7 hours ago
If anything it's the opposite, as memory components become obscenely expensive.
Dfiesl | 7 hours ago
a1o | 7 hours ago
radicaldreamer | 7 hours ago
Just disconnecting from Wifi often doesn't work because the TV will connect to insecure wifi to upload data and fingerprint what you're watching and who you are.
qlte | 7 hours ago
It made more sense when I first heard this theorized back in the early 2010s when smart TVs were becoming more common and unsecured WiFi hadn't vanished completely yet. Now it would be way more logical to include a cheap 5g radio, which has also been alleged but I haven't seen any model shown to include one.
robotnikman | 6 hours ago
left-struck | 6 hours ago
katzgrau | 7 hours ago
Checks out, and I mean that in the kindest way possible
derf_ | 7 hours ago
The exact same logic applies to devices you buy. These companies have shown they do not have any integrity. So why would you want buy something from them that is "smart" and never sleeps?
malfist | 7 hours ago
krupan | 3 hours ago
ozlikethewizard | 3 hours ago
pico303 | 7 hours ago
KerrAvon | 7 hours ago
xbar | 7 hours ago
Doesn't solve the malware on Windows PCs installed by LG monitors problem. My only solution to that remains to not buy Lucky Goldstar ever since their 14" 640x480 VGA monitor died inside of warranty but they refused to fix it.
Larrikin | 7 hours ago
switchbak | 7 hours ago
Larrikin | 5 hours ago
switchbak | 2 hours ago
Literally just now it went jamming some Ford 150 ad on me, auto repeating. On the f’ing Home Screen!!
I don’t know what I’ll replace it with, but it sure AF won’t be some corporate owned ad riddled POS like this.
jqpabc123 | 7 hours ago
walrus01 | 7 hours ago
But I have a thousand times more confidence that MS will keep the signed, auto-distributed periodic xbox series x operating system updates 'secure' than I do that some random smart tv manufacturer will implement a proper operating system.
batch12 | 7 hours ago
beloch | 6 hours ago
Once awareness of this side-loaded crapware gets out, I'd expect the community to come up with fixes to ensure it doesn't get loaded. In the meantime, this should blow up in the faces of MS, LG, etc. just like things blew up for Sony when they put root-kits on CD's.
stalfosknight | 6 hours ago
kulahan | 6 hours ago
mingus88 | 6 hours ago
Unless you are trying to pass through lossless audio the AppleTV 4k is one of the best streamers you can buy right now
kulahan | 6 hours ago
Chromecasts seem to at least have reduced ads, but I'd do almost anything to be able to stream youtube (or ideally any webpage) to an arbitrary screen with functional adblocking.
bigstrat2003 | 6 hours ago
amelius | 6 hours ago
throwawayffffas | 5 hours ago
VCFundedGenYer | 7 hours ago
Smart TVs are to be plugged in to be updated, and that's it.
Their default state is to be permanently offline.
Hook up an Apple TV if you want apps.
Carrok | 7 hours ago
VCFundedGenYer | 7 hours ago
Your statement is false. There are reasons to update.
KerrAvon | 7 hours ago
xp84 | 7 hours ago
uncletammy | 7 hours ago
joshheitzman | 7 hours ago
fckgw | 7 hours ago
hackernudes | 7 hours ago
cobbal | 7 hours ago
You can argue if it actually installs the software or just nags the user to install it, but neither are things microsoft would allow a monitor "driver" to do if they had any integrity.
EvanAnderson | 4 hours ago
There is a Group Policy setting under Computer Configuration / Administrative Templates / System / Device Installation / "Prevent automatic download of applications associated with device metadata" that seems to curb most of it, thought I still ended up with a user mode app related to the audio driver.
jqpabc123 | 7 hours ago
Connect a mini-PC to provide any "smarts" required.
hoppyhoppy2 | 4 hours ago
like_any_other | 7 hours ago
The 2nd story is crazy - I wonder if I hack LG and start downloading all their trade secrets, when caught, the government would just let me stop the download and face no punishment, if I say I just forgot to ask them for consent. Or maybe it's different if I do the hacking through a backdoored cable I sell them, like they hack us through backdoored TVs.
[1] https://inews.co.uk/news/technology/how-to-stop-google-from-...
[2] https://www.cbc.ca/news/science/smart-tvs-that-send-data-wit...
hahajk | 7 hours ago
At this point I assume the author was making intentionally bad choices out of morbid curiosity. I can't imagine anyone technical thinking drivers should be required to connect to a TV via HDMI. (or maybe I'm not technical enough)
BobbyTables2 | 7 hours ago
kccqzy | 7 hours ago
kulahan | 6 hours ago
There's no reason to expect a normal user to think "Yes, this port is the USB port and thus commonly needs driver updates, but that HDMI port does not ever need driver updates." Most people don't even know it's called a USB port, let alone whether it should host driver updates. Besides, I could imagine a scenario where there's some outdated HDMI decoding thing on it. Or maybe just some tech for home theater stuff I'm not aware of.
fckgw | 7 hours ago
They're not talking about putting the TV online. The TV is completely offline.
They're talking about plugging the TV into a PC or laptop via HDMI or Displayport (like if you're running an HTPC), which then triggers a companion app update on the PC via Windows Update. This was a news item a few weeks ago with their monitors. They then also discuss a hardware blocker for HDMI or DP to prevent this.
Again, this has nothing to do about the TV's smart apps.
beloch | 6 hours ago
It's very reminiscent of Sony putting rootkits on CD's. Unwanted, dangerous software is being loaded onto your computer by people you paid money to. The companies involved, including MS, should face serious blowback over this, as Sony did.
spicyjpeg | 6 hours ago
[1] https://en.wikipedia.org/wiki/FTDI#Driver_controversy
[2] https://github.com/therealdreg/ftdibrick#diving-deep
Henchman21 | 4 hours ago
ryandrake | 2 hours ago
But we all know, the law is enforced aginst regular people, not corporations. Are corporations ever prosecuted for invoking something on a user's computer without their authorization?
godelski | an hour ago
I don't think there's a shortage of HN users that one about this type of bullshit going on. I'm not going to tell you "I told you so", and I'll even attack those that do. But when people who are concerned with these types of issues talk out they get dismissed as being conspiracy theorists or simply too sensitive.
I'll admit that sometimes it can be hard to differentiate, but well respected experts in the tech field have discussed such issues for decades. So I really do want to understand, how do we reach you earlier? Before we get to this point. How do we not just come across as uppity tech nerds screaming "I use arch btw" in furry programmer socks?
I really do think we as a community need to figure out how to reach the public better. We're well past what was considered terrifying in 1984. We aren't a society where big brother could be listening to you at any time, we are living in a society where uncle Mark is watching you all the time. Where uncle Pichai knows who all your friends are. Where uncle Nadella knows when you're awake. They know whose been bad and good but they don't even have the decency to deliver gifts under the Christmas tree. Are we only fighting back because their actions have become so obvious? Or are we fighting is the principle enough?
abruzzi | 6 hours ago
fuzzzerd | 6 hours ago
DANmode | 4 hours ago
Mindwipe | 6 hours ago
It's Windows that decides that it should download a driver from Windows Update because it recognises it hasn't got a driver from that hardware, and it's Microsoft that let the vendor submit drivers that are bundled with near malwareto Windows Update.
warkdarrior | 5 hours ago
Then the OS vendor will start limiting which devices they support and with very strict review processes.
drfloyd51 | 4 hours ago
It can swing the other way, my options are limited to company’s that pay my OS provider for access.
ndriscoll | 3 hours ago
pseudosavant | 5 hours ago
More of a Windows Update + MS partner issue than EDID.
garciansmith | 4 hours ago
kova12 | 7 hours ago
robotnikman | 6 hours ago
Definitely have to agree with the author on that. Only use for a TV for me is for playing on the Steam Machine.
mtlynch | 6 hours ago
There's nothing nefarious about EDIDs. EDIDs are just a way of the monitor to announce its capabilities to the device so that the device and the display can agree on things like resolution, refresh rate, etc. EDIDs are just blobs of data without capability to execute logic, as far as I'm aware.
It sounds like the author is claiming that Windows does some sort of driver update in response to EDID announcements, but OP doesn't explain it at all. If that's true, that would entirely be on the Windows end not on the EDID's end. It sounds like Windows is recognizing LG as the manufacturer declared in the EDID and then downloading a driver for LG. I don't think there's any way for the EDID to declare to the OS that it wants to perform a driver update.
bigstrat2003 | 6 hours ago
spicyjpeg | 6 hours ago
Around a month ago LG took advantage of this feature by publishing a Windows "driver" for all their TVs and monitors that consisted entirely of payola bloatware, resulting in predictable backlash [1] and the obligatory subsequent HN discussion [2]. None of this has anything to do with the TVs themselves being connected to the internet or not.
[1] https://youtube.com/watch?v=Q9uefFYe6bM
[2] https://news.ycombinator.com/item?id=48956688
ryandrake | 2 hours ago
This is the root problem.
The computer should not do something that the user did not specifically command. It should not guess, "Oh, the user plugged in device X. This means I have the user's consent to download and install software."
DavideNL | 47 minutes ago
If i understand correctly:
1. TV is offline
2. Plug HDMI or DisplayPort into laptop
3. Windows (Update) on laptop recommends to install LG display driver
4. The LG display driver then installs all the bloat
dreamcompiler | 6 hours ago
Them: "But then how will I get Netflix?"
Me: "Get an Apple TV and connect it to the internet. Then connect that to your TV with an HDMI cable."
Them: "I don't need an Apple TV. I just bought a TV!"
Me: "Apple TV is not a TV. It's a little box."
Them: "Then why does Apple call it a TV?"
Me (snarky): "I told Steve Jobs not to call it a TV but he did it anyway."
Them: "This is all too confusing. Just buy the things and hook it up. Here's my credit card."
Me: "OK"
Them (one month later): "Hey our new TV is working great!"
Me: "Good!"
Them: "Except it shows us an unskippable ad whenever we turn it on, and the ad seems to know a lot about us."
Me: "Um...that shouldn't be happening."
<investigation begins>
Me: "This TV knows your wifi password!"
Them: "Oh yeah! After you left last month the TV asked us if we wanted to 'finish the setup process'. So we did what it told us and now it's happy. Aren't you proud of us for figuring that out all on our own?"
Me (to myself): choose words carefully before speaking, self
Telaneo | 5 hours ago
'Your TV is evil and has tricked you. I'm sorry I was unable to protect you.'
testing22321 | 6 hours ago
In Australia TV is colloquially called “the idiot box”
A foreign friend asked, “is that because there are only idiots on there, or because you turn into one if you watch too much?”
Yes.
CommanderData | 6 hours ago
Who the fuck invited them into the living room? They say it's optional and opt in but I really don't believe that.
Edit: it's called ACR and a much bigger problem then I originally thought. Wow.
TacticalCoder | 6 hours ago
For that link only TFA is worth it.
advael | 5 hours ago
briandw | 4 hours ago
tehnoslow | 4 hours ago