Never connect a smart TV to the internet. Use it as a dumb screen with your choice of media device.
K0balt 2 days ago [-]
It’s been a couple of years but there was some thing about a p2p link between televisions that allowed c&c / exfil even on some brand of televisions that weren’t hooked up to the internet if they were within range of ones that were… so even that might not be enough.
Edit: it was Samsung, where Wi-Fi Direct was always-on, and concurrent with STA mode wifi, enabling other WiFi direct devices potentially to connect to the internet, including other Samsung televisions. Their televisions were also hacked to gain root over a standard DVB broadcast on fully patched firmware lol so it might be possible to pwn a whole city at a time through that vector.
Smart-TV platforms have long done cross-device identification, and there have been some surprisingly aggressive local-device discovery schemes.
In all, smart devices are pretty much surveillance devices, and a privacy nightmare. I have had enough exposure to shady goings on that I am nearly certain that most devices ship with intentional backdoors sold to three letter agencies or malware rings, either by unscrupulous engineers or by the company itself.
It’s just hard to pass on the payday that a wide deployment of a permanent relay/mic/camera/sniffer represents, especially if it’s likely to end up in corporate or industrial environments.
I’ve had speculative offers to compromise smaller projects, and I’m nobody. I have no doubt that engineers working on widely deployed projects and systems are given very attractive offers to provide tailored access.
goda90 2 days ago [-]
We all need to live in Faraday cages now.
LargoLasskhyfv 2 days ago [-]
No.
We need to deploy sophisticated military grade beam forming gizmos for selective signals canceling.
Faraday is caveman copium.
rationalist 2 days ago [-]
Another user on HN that reported that their guest connected their TV to the guest's phone hotspot to watch Netflix.
So you have to go a step further and remove the Wi-Fi card, because there is no guarantee that someone else won't connect the TV to the Internet.
testing22321 2 days ago [-]
Just don’t buy one at all.
Like HP printers. Don’t give your money to companies doing shit things.
Anonyneko 2 days ago [-]
Kinda hard to do when nobody offers dumb TVs with good screens anymore. With printers you have options at least.
CharlesW 2 days ago [-]
You can buy "commercial displays" with very good screens, but you'll pay more.
Don’t buy a tv at all. I have not had one for 20 years, never missed it.
woodgala 2 days ago [-]
Ever heard of TCP/IP over HDMI? It’s a method of exploiting HEC. Connect your smart TV to a streaming platform and it connects to the internet via the video cable. There’s no escape.
Melonai 2 days ago [-]
No I have not heard of it, and it's genuinely baffling! Which consortium thought this up? I don't see one sensible reason to do this apart from just random tinkering or malicious purposes.
phil21 2 days ago [-]
If OP means Ethernet over HDMI it’s in the spec but as far as I’m aware has not been implemented in any mainstream chipsets anything actually uses. It’s one of those theoretical things that is somewhat surprising didn’t happen.
Overall it’s not a bad idea if devices need network connectivity. Have one central “box” get an Ethernet drop and it acts as a switch for your tv/xbox/playstation/media player/etc. The spec was made back when A/V receivers were more popular than they are now. It would cut down on a cable per device.
If OP means an exploit/hack then that’s a bit different.
1 days ago [-]
LargoLasskhyfv 2 days ago [-]
That's part of some spec.
AFAIK it got not used, or not implented in relevant ways.
So far...
CommanderData 2 days ago [-]
Not long until these TVs start partnering with Amazon and other providers to send traffic automatically through near-by devices like smart speakers, disconnecting will be impossible.
Vast majority won't know or care.
The way this gets fixed is laws not workarounds unfortunately.
FerretFred 2 days ago [-]
> Vast majority won't know or care.
This, unfortunately, is the biggest problem those of us care about privacy face, especially when trying to warn people about it.
sublinear 2 days ago [-]
The discussion around privacy is always framed the wrong way.
The authoritarians use the red herring of "nothing to hide", while the liberals only argue on the most sensational abuse cases or somewhat flimsy high-minded principles.
The correct way to get the layperson to care is with a visceral reaction using the relevant buzzwords: "sabotage", "gangstalk", "bully", "witch hunt", etc.
It makes zero sense that the same people who fight so hard over gun rights can completely ignore all the other much uglier ways the powers-that-be can threaten your livelihood.
Nobody ever spells out what "overpolicing" really looks like. Nobody makes clear enough that "the government" is what we call it when we give your literal neighbor special privileges.
Vineetyadav2 2 days ago [-]
are they also doing the meta thing like the algorithms and all
Edit: it was Samsung, where Wi-Fi Direct was always-on, and concurrent with STA mode wifi, enabling other WiFi direct devices potentially to connect to the internet, including other Samsung televisions. Their televisions were also hacked to gain root over a standard DVB broadcast on fully patched firmware lol so it might be possible to pwn a whole city at a time through that vector.
Smart-TV platforms have long done cross-device identification, and there have been some surprisingly aggressive local-device discovery schemes.
In all, smart devices are pretty much surveillance devices, and a privacy nightmare. I have had enough exposure to shady goings on that I am nearly certain that most devices ship with intentional backdoors sold to three letter agencies or malware rings, either by unscrupulous engineers or by the company itself.
It’s just hard to pass on the payday that a wide deployment of a permanent relay/mic/camera/sniffer represents, especially if it’s likely to end up in corporate or industrial environments.
I’ve had speculative offers to compromise smaller projects, and I’m nobody. I have no doubt that engineers working on widely deployed projects and systems are given very attractive offers to provide tailored access.
We need to deploy sophisticated military grade beam forming gizmos for selective signals canceling.
Faraday is caveman copium.
So you have to go a step further and remove the Wi-Fi card, because there is no guarantee that someone else won't connect the TV to the Internet.
Like HP printers. Don’t give your money to companies doing shit things.
https://www.bhphotovideo.com/c/products/Flat-Panel-Displays/...
Don’t buy a tv at all. I have not had one for 20 years, never missed it.
Overall it’s not a bad idea if devices need network connectivity. Have one central “box” get an Ethernet drop and it acts as a switch for your tv/xbox/playstation/media player/etc. The spec was made back when A/V receivers were more popular than they are now. It would cut down on a cable per device.
If OP means an exploit/hack then that’s a bit different.
AFAIK it got not used, or not implented in relevant ways.
So far...
Vast majority won't know or care.
The way this gets fixed is laws not workarounds unfortunately.
This, unfortunately, is the biggest problem those of us care about privacy face, especially when trying to warn people about it.
The authoritarians use the red herring of "nothing to hide", while the liberals only argue on the most sensational abuse cases or somewhat flimsy high-minded principles.
The correct way to get the layperson to care is with a visceral reaction using the relevant buzzwords: "sabotage", "gangstalk", "bully", "witch hunt", etc.
It makes zero sense that the same people who fight so hard over gun rights can completely ignore all the other much uglier ways the powers-that-be can threaten your livelihood.
Nobody ever spells out what "overpolicing" really looks like. Nobody makes clear enough that "the government" is what we call it when we give your literal neighbor special privileges.