The influencer economy is a bit soaked these days. You need to crank up the stakes to keep the viewer's attention.
> If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.
There are ways to remotely jailbreak LG webOS TVs without user interaction, using the same (or similar) vulnerabilities you use to root your own TV voluntarily.
The main reason tools like https://rootmy.tv are prefixed with disclaimers and require user interaction is because we're being courteous, not because they're technically necessary. (source: I own the rootmy.tv domain)
The security posture of webOS is absolutely terrible, at least, it is in the way LG deploys it.
But vulnerabilities that can be remotely exploited without user interaction (CVSS grade 9-10)?
The video is quite a mixed set of topics mangled together, which is a pity because IMO a cleaner separation would be more beneficial to get the point across.
They should have decided to set the focus on a specific area and then present every finding around that, i.e.:
1. The Ad data-collecting platform TV-manufacturers are operating, what data they collect and how they use it.
2. The vulnerabilities of the OS in a SmartTV, and the potential issues to exploit them for malicious purposes.
3. The general behavior of the device when connected to your network, with features like voice control, App control, Smart Home etc. enabled, and how it may expose information about yourself.
All the points and scenarios in the video might be valid, but they jump between those scopes and imply that its all the same, weakening the whole investigation.
If I'm LG and forced to respond to this, I can easily focus on dissecting the voice-input topic as a mere demonstration of the feature and how rooting the TV beforehand just showed the local process of handling it, steering the narrative away from the (IMO) much more important topics...
216M Spy TVs – The LG Smart TV Problem [video]
> If you root or jailbreak your devices, you've, by their very nature, broken their security. If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.
What is this authors point?
LG doesn’t need a root exploit to get this info because they made the fucking thing.
I read the article and then grepped for “Texas” to see if I missed it. The author never mentions the fact that this data collection was only found out initially because of a Texas government lawsuit that LG settled on by agreeing to give “informed consent” to users about data collection and then the warnings started popping up in unexpected places.
Is the author arguing that jailbreaking your device to find out what the manufacturer can do to gather data on you is dangerous because I don’t know, questioning your corporate overlords is bad or something?
badsectoracula•34m ago
Do you actually want a channel with 2.66 million subscribers to show how to get remote access to TVs used by millions of people? :-P
Krutonium•30m ago
jaimex2•16m ago
Arcuru•16m ago
supriyo-biswas•9m ago