AI & TechBigTech CompaniesCybersecurityDigital MarketingNewswireTechnology

LG Bans Residential Proxies from Smart TV Apps

▼ Summary

– LG Electronics USA announced it will suspend smart TV apps that turn the television into an always-on residential proxy node.
– Research by security firm Spur found over 42% of LG smart TV apps and more than a quarter of Samsung Tizen apps contain residential proxy SDKs.
– LG is working with developers to remove the proxy option from apps on webOS, and non-compliant apps will be suspended.
– Bright Data, a major proxy provider, stated its network operates with user consent and compliance with LG and Samsung terms.
– Spur criticized the lack of meaningful transparency and consent in proxy SDKs, noting risks when household members like minors can inadvertently consent.

LG Electronics USA announced this week that it will suspend any smart TV applications that convert a user’s television into an always-on residential proxy node. The decision arrives less than a month after security researchers discovered that over 42 percent of games and other apps available on LG’s webOS store allow unknown third parties to route their internet traffic through a user’s TV.

On July 2, security firm Spur published research examining the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found that more than 42 percent of downloadable apps on LG smart TVs include SDKs that effectively turn a television into a permanent proxy node. Additionally, over a quarter of apps designed for Samsung’s Tizen operating system contained similar residential proxy components.

In response to questions about Spur’s findings, LG Senior Vice President John Taylor told KrebsOnSecurity that the company is collaborating with app developers to remove the residential proxy option from their apps on the webOS platform. Developers who fail to comply, he warned, will see their apps suspended.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said. “If this option is not removed, these apps will be suspended.”

Taylor emphasized that LG is committed to keeping residential proxy networks out of its smart TV apps moving forward, and that the company’s review of these apps is “well underway now.”

“As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs,” Taylor wrote in an emailed statement.

App developers seeking to monetize their creations can turn to residential proxy providers, which pay developers to include SDKs that transform the user’s device into a residential proxy node rented to paying customers. In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and file utilities.

Spur’s report identified Bright Data as the dominant residential proxy network across both Samsung and LG smart TVs. In a statement shared with KrebsOnSecurity, Bright Data said its network is built on consent and responsibility and operates within LG and Samsung terms.

“Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC,” the statement reads. “We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain.”

Bright Data and other proxy providers named in Spur’s report all say they follow rigorous know-your-customer processes to validate legitimate uses of their services, which are often heavily tied to content-scraping activities by customers. The proxy companies also claim they incorporate technological countermeasures to prevent proxy service customers from interacting with and controlling other devices on the proxy user’s local network.

Spur argues the problem is not that residential proxy networks exist, but rather that they are being embedded at scale in devices most consumers do not think of as computers and are not equipped to audit.

“A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight,” Spur’s Trevor Sutter wrote. “The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”

LG’s announcement that it is culling residential proxy SDKs from its app store is welcome news, but the company recently faced criticism for another questionable partnership: promoting McAfee security products through software drivers included in its high-end LCD monitors.

Earlier this week, the YouTube channel Gamers Nexus demonstrated that certain LG LCD monitors automatically install an app promoting paid McAfee antivirus subscriptions, and that the app arrives through Windows Update without an approval prompt.

(Source: Krebs on Security)

Topics

residential proxy networks 95% smart tv security 92% lg smart tvs 90% sdk privacy risks 88% app monetization 85% consumer consent 82% bright data 80% samsung tizen os 78% spur research 76% lg app suspension 74%