Hacker News new | ask | show | jobs
by s1ncere 11 days ago
Stop hooking up your LG tv to any network
12 comments

Fine with Linux though :)

LG's behavior isn't fine, but their monitors don't install crapware on Linux.

The monitors aren't installing anything. That headline was a lie.

It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs. That's why the problem affected older monitors too - it's the update side that suddenly started to ship malware.

> It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs

This is also a misrepresentation. Microsoft has provided LG with a certificate to sign its driver packages with, and allows LG to upload packages to Windows Update, which includes a feature to install sidecar applications. Now, the spirit of this feature is that any application is meant to provide genuine configuration functionality or some graphical front end to the driver's configuration knobs.

LG then abused that feature to provide adware. Now, there are millions of hardware vendors. One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.

Sometimes one actually wants the app that comes with the device, like AMD's and NVIDIA's configuration trays.

Even so, I fully expect that after this debacle MS will disable this stuff. There is precedent for this. Synaptics/ELAN/Alps touchpad tray applications largely disappeared after MS implemented precision touchpads somewhere in 2015, and suddenly Windows touchpads became as precise as those on Macs. Likewise with RGB peripherals. Even GPU driver applications have increasingly become less useful as the most important features—power control, adaptive sync, HDR, etc have moved into native Windows settings.

> One can't expect that every driver package submission from every vendor is thoroughly vetted every time

Why not? Microsoft isn't a struggling startup. They can afford to do just that.

Because at scale, that doesn't work, I think, even money no object, because it's a task that requires a lot of domain knowledge, but also is monotonous and offers little in the way of satisfaction or looking good on your resume, so the candidates you're trying to hire aren't very junior, and also are not going to like the work.
IIRC, at least 15 years ago, that's exactly what they did. They published a tool suite that your driver should pass before submission because otherwise it would fail when they got to it. I think the submissions were fully automated by that time.
> One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.

Maybe not, but LG has violated this trust and should therefore be either fined or severely restricted by Microsoft. Banning will likely cause more problems than solutions, but they shouldn't get away with this.

Adware was a huge problem during the Windows XP era, can't believe it's coming back now through Microsoft's official channels.

Also I doubt there's actually millions of hardware vendors. But that aside, Microsoft has a duty to vet everything that they offer through their channels. If it's too expensive for them to do, do like Apple did and have those that want to make use of their distribution network (and trust) pay them.

> I doubt there's actually millions of hardware vendors.

Almost certainly correct because there are only 2^16 USB manufacturer IDs, of which (warning, Google AI quick result...) only 3400 are used. Tiny vendors of e.g. USB drives often seem to use the vendor and device ID of the interface chip manufacturer, but that's probably a good filter for really unimportant ones. Of course not every device has USB, but most major hardware vendors implement USB somewhere and have an official USB vendor ID.

I agree with you on the precedent

> after MS implemented precision touchpads somewhere in 2015, and suddenly Windows touchpads became as precise as those on Macs.

There’s still a world of difference between a MacBook touchpad and a windows one. My work laptop (18 month old dell XPS) can’t hold a candle to my 6 year old MacBook’s trackpad.

> Likewise with RGB peripherals. Even GPU driver applications have increasingly become less useful as the most important features—power control, adaptive sync, HDR, etc have moved into native Windows settings.

The peripherals still need the addons though; I have ASUS armory crate, Corsair iCue and MSI center for my Motherboard, cooler and GPU respectively. They all suck.

> There’s still a world of difference between a MacBook touchpad and a windows one. My work laptop (18 month old dell XPS) can’t hold a candle to my 6 year old MacBook’s trackpad.

The latest Dell trackpads are quite bad. Price or the product being premium or not unfortunately does not tell you if it will have a good trackpad or not. And it changes over time (Dell XPS used to have really good trackpads)

Basically you have to go to a store and try or find reviews that actually pay attention to this.

> There’s still a world of difference between a MacBook touchpad and a windows one

Oddly I've found otherwise (Dell Precision notebook from 2021, and Surface Laptop). It might be macOS's animations and smoothing interfering here, but I've found that my Windows touchpads are much more responsive, especially when swiping between desktops.

> The peripherals still need the addons though

Ugh, this is annoying. Hardware vendors need to be banned from writing lousy, inefficient, unsafe software.

My point is not to shift the blame to Microsoft; it's primarily LG that's at fault here.

My point here is simply that it's not the monitor that is installing this. Neither the malware nor the URLs to malware exist on the device - they get fetched as part of normal OS-side auto-provisioning, which is the part that was compromised.

This is a primary LG fault, however I would say that Microsoft also has a fair bit of blame here.

They are downloading and installing something without the users consent.

It's nice to have drivers work without any intervention, same with "helper software" but along side the ease of use they also took on the responsibility.

If I download some random .exe from the net; I have to confirm that I want to run it, sometimes I even have to right click and unblock it to allow it to run, because it is "untrusted".

Their signature key, their auto-run system, everything done for ease of use means they own this.

Otherwise what does "trusted" mean?

Yes, and it's only possible thanks but no thanks to MicroSlop.

And it's not like MS is too poor to do anything useful for their customers. They just don't want to unless the cost-benefit analysis pans out in their favor. The customer is worth as much as their wallet.

>Even so, I fully expect that after this debacle MS will disable this stuff.

Isn't the debacle over? MS know about this by now. What's stopping them from killing it today?

A late resolution is barely a resolution at all. None of this functionality needs new Windows features.

I can only imagine the meetings at microsoft HQ where they all sat around a table and crossed their fingers and hoped that vendors would act in the spirit of their design.
If they aren't willing to vet, they should at least be keeping the update minimal. Ie no 'sidecar' apps.

Self signing a driver should mean just that, not a driver, and a load of other things we feel like foisting on the user.

Half the reason I moved to Linux is because I just wanted to print something without getting a load of advertising from a printer company.

The commercial software landscape more and more reminds me of a civil war torn town. Everyone shooting at everyone, a dark forest through and through
It’s more a tragedy of the commons, we are the commons.
> One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.

If you're going to allow 3rd parties to install software on potentially billions of computers with far reaching privileges then you better have something in place other than 'just trust me bro'.

Why's that? "Just trust me bro" is the security model of all closed source, proprietary software. OMG, the program with secret source code is doing shady stuff? I'm shocked - shocked!

Hard to get worked up over "3rd parties" when even 1st parties cheerfully stomp all over the interests of their users. That ship sailed, caught fire, and sank to the bottom of the ocean the day Candy Crush appeared in the goddamned Start menu.

> One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.

Apple seem to do a pretty decent job of just that

The situation is very different on Macs. Apple control almost the entire hardware stack of the machines that macOS runs on. They make it an absolute pain in the neck to run any application not blessed by attestation. This attestation server is also frequently offline. They've also made it very difficult to write things like filesystem drivers, having completely pulled that functionality from more recent versions of macOS. In fact, if I recall correctly one cannot ship a third-party kext on more recent Macs, especially ARM ones. As such, hackintoshing has basically vanished as a hobby.

At least on Windows, the most you get is a scare screen saying 'this app is from an unidentified developer'. I know what I'd rather have.

> That headline was a lie.

Kinda agree but let's call it "misinformed" or something, instead of a lie.

I would say it's neither a lie nor misinformed. It 's a punchier headline that can be justified by what the user experiences. The user connects a monitor which causes ads to appear. The rest of this Rube Goldberg contraption is a mere detail.
Those details are the only thing that matter. Without them, all you have is superstition.
The headline isn't a lie, even if you can technically nitpick it.

The manufacturer implemented choices to deliberately install the software when the monitors are connected. The mechanism is not important to why this is outrageous.

I disagree, the mechanism is the only important thing. Everything else is storytelling and superstition.
Another win for the Linux security model (software installed and updated manually from vetted repos only).
Wait, you're saying a monitor can just advertise a URL over the video connection for its driver and then Windows will blindly install it, without user confirmation? I thought that LG had submitted these "drivers" (adware) to Microsoft and they approved it.
As far as I'm aware, the monitor does not transmit a URL. Windows is looking at the hardware's vendor and device IDs and using those to look up and download the "drivers" that LG has stated are for that device.
I think the point is that:

1. Yes Windows must have "approved" the drivers

2. Windows Update runs automatically and not (usually) manually

3. Automatic update can't even be disabled, only manually postponed a bit

At least 2 and 3 are different on virtually every Linux distro. Also, I find it very unlikely that they would accept such behavior.

To give MS the benefit of the doubt here, now that this happened and has been reported on they might decide to enforce stricter rules on manufacturers in the future. But as a Windows user you don't have a choice in case you don't like how they decide and how their decisions might change again later.

https://github.com/raphire/win11debloat

This has an option to disable downloading of auxiliary apps when a device is connected. Yes, it's a Windows Update thing.

> Prevent Windows from auto-installing device companion apps, like LG Monitor App, Alienware Command Center and more.

I believe you register your device with Microsoft so Windows can automatically obtain and install drivers for them when they are plugged in.

What LG sent in for installation is not a simple .inf or .sys/.dll file. They sent in a whole bag of software which does all the nasty things, and Microsoft doesn't vet or care about the software installed as the "driver" of the hardware.

This is actually a feature of the .inf by design, an AddSoftware directive. It can even link to apps from the store instead of bundling them with the driver. This is designed to install settings panels like the ones for GPUs.

https://learn.microsoft.com/en-us/windows-hardware/drivers/i...

I guess that from Microsoft's perspective, the driver itself wasn't suspicious, but it installs a questionable sidecar app they would have never vetted anyway.

Eh? No.

It's just a device attached to a computer.

But in a Plug-and-Play world, its addition is noticed by the operating system -- as has been normal for decades.

Microsoft's Windows operating system sees this new hardware ID and then goes forth to install whatever-the-fuck software it associates with that identification, presumably as a service to the user. (Did Microsoft approve it? Dunno. I'm just over hear eating popcorn.)

> Eh? No.

That's what I thought. It is vetted software, just like on Linux. Microsoft just doesn't care if it shows ads.

> software installed and updated manually from vetted repos only

So something most desktop Linux users don't do.

Virtually all desktop Linux users do. The biggest exception is AUR as its not vetted.
I would say 95%+ do just this. The Debian, Ubuntu, and even Fedora repos are very large and include all the software you could ever want. And then flathub takes the rest.

It’s really only arch with the AUR and some others where completely untrusted packages are used. This is legitimately a better model than what windows does, although Microsoft has been trying to change this with winget.

'desktop Linux' is a term used when the majority of Linux users don't support your argument.
Are you disputing that the repos are vetted or that users use them???
most of my machines use unnatended-upgrades

Increasingly software is distributed by "curl dodgysite.com/get.sh|sudo bash -", no different to running "install.exe" on windows

Surely Windows Update is a vetted repo as much as arch or debian

> Increasingly software is distributed by "curl dodgysite.com/get.sh|sudo bash -"

I don't think this is the norm at all. I have seen curl/bash install scripts for tools like Claude Code, but they don't use sudo, and the expectation is that you deploy them in isolated user accounts or containers.

== Docker ==

Docker provides a convenience script at https://get.docker.com/ to install Docker into development environments non-interactively.

== Homebrew ==

/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/inst...)"

Paste that in the macOS Terminal, a Linux shell or WSL. The script explains what it will do and then pauses before it does it. Read about other installation options.

== k3s ==

K3s provides an installation script that is a convenient way to install it as a service on systemd or openrc based systems. This script is available at https://get.k3s.io. To install K3s using this method, just run:

These scripts have lines like

> abort "Need sudo access on macOS (e.g. the user ${USER} needs to be an Administrator)!"

> # --- use sudo if we are not already root ---

> the expectation is that you deploy them in isolated user accounts or containers.

Why are you lying right now? This is a norm across the dev tools world for businesses to distribute dodgy curl piped to bash scripts that users install without question, popular examples: homebrew, docker, nvm, bun, deno, k3s. There is zero "expectation" given by any of these install scripts that they are isolated. Can you even find a single source online that suggests doing what you said for you to think its a commonly held expectation?

There is one major difference: those install under your users. I haven’t seen a windows installer that didn’t require admin. Some older Linux apps require sudo. They don’t need to do that anymore, not for a while. We have xdg standards of where to install stuff in a users home directory.
Tons of Windows apps these days install into user's AppData these days. Its common for installers to ask "Install for everyone or just me".
Nah, install.exe must be signed by a certificate authority or you get 10 prompts, and they do revoke certificates.
sudo dkpg -i FileYouDownloadedFromAnywhere.deb
Let's be real, in most cases it is:

    curl -s script.random-guy.net | sh
It is such glaring security hole that there was an old submission about filling such install script with `sleep` commands and detecting it on server side, to send different versions for downloading (and reviewing) and for actual direct execution.

    wget https://raw.githubusercontent.com/timofurrer/russian-roulette/master/russian-roulette -O - | sudo bash
I use those scripts to improve the likelyhood it'll fail to do anything useful.

I even used uname as a fuzzing tool, and that broke builds spectacularly. There's now a more reasonable uname in the sandbox for builds.

the method you describe is clearly only done by people that are irresponsible and most probably stupid.

and no, this is not how most software is installed

Almost never occurs as the repos contain a ton of software.
Surely you mean Linux security model (not relevant enough to be targeted by big tech)?
Famously, the Linux kernel does not have a stable ABI for drivers. As a result, by far the majority of drivers are in-tree, maintained by the kernel folks as part of the kernel.

The Linux approach has the downside of not having the drivers if a vendor has not been working with the kernel community before launch (or for those who haven't upgraded to a kernel that has the driver, e.g. a LTS release).

On the other hand, the driver is maintained by kernel developers, not created by the hardware developer who is not getting paid after they sell the device. This helps avoid abandoned / vulnerable drivers, or having the hardware dev search for... alternative revenue streams, as in this case.

It's not a weakness that they targeted and exploited, it's a feature that was purposefully implemented by Microsoft.
If you're trying to say that Microsoft implemented a method of delivering specifically malware executables to every PC, I've got a bridge to sell to you.

Let's not diminish LG's part in all this.

> Another win for the Linux security model

I swear, OSs have become sports teams.

Linux's 'security model’ has plenty of holes. The very fact the kernel and much of its user-mode is written in C almost guarantees that its security model is worthless. The Linux ecosystem operates on trust and respect that can and has been easily abused by bad actors to provide supply-chain pwnage.

There have been so many zero-click local privilege escalation CVEs I've lost track.

Arch Linux AUR malware: https://lists.archlinux.org/archives/list/aur-general@lists....

AUR is an effectively unmoderated user repo. It’s not Arch Linux’s core repository, nor is it enabled by default or indeed even possible to use without manual downloads from outside the package manager.
There's still a security there though.

You have confidence you are actually downloading the same foo as everyone else. And if there were an issue there would be pushback. Not so if you get some random exe from warez.com

Yes it isn't perfect, it's still a lot better than windows land.

I think you can probably find a better example, even if less recent. The AUR is unofficial and not properly vetted in the same way as the actual Arch repos, Debian repos, etc.
> Linux's 'security model’ has plenty of holes.

Implementation bugs are not holes in the security model. Linux has plenty of those, as does Windows.

Windows security model trusts, downloads, and immediately executes arbitrary software when a new untrusted device is plugged in, without asking the user.

yet?

I guess with more and more consumer devices running Linux based OSes (SteamOS, Android, Bazzite, Silverblue, ..) that becomes more and more interesting.

And unfortunately the "I'm safe on my non-windows-system" argument doesn't count for long, as the 99% muggle crowd justifies a shift to a world where our non-certified (=> 'insecure') systems are not supported by big companies anymore, as it's currently happening on Android.

The LG scandal specifically relies on the fact windows will auto install OEM crapware as soon as you plug it in. No other OS does that.
Huh? What does WebOS have to do with windows?
LG monitors not TVs
"Fortunately", agent Poettering is on the case, implementing remote attestation for Linux so we can all be secure. Barf.
https://youtu.be/Q9uefFYe6bM

A tech YouTuber showing this off and all the anti consumer behavior. I’m assuming this threads article is for an LG PR piece trying to redirect anger at the app developers to hide the fact that they are engaged in the same behavior themselves.

I'm mostly very happy with my LG C4 as a home theatre centerpiece, and I did have it online so that I could use the apps for YouTube and Jellyfin. However, the lack of support for modern 4k rips (HEVC+DTS) ended up being a dealbreaker and I finally ditched the built in software for a fire stick instead.

No transcoding, no weird codec issues, just the raw files direct streamed from the underpowered Unraid box, into the back of the AVR where the audio is handled correctly and the video is sent to the screen.

There is always android VLC app to decode anything, you just need enough power in chipset to handle that. Not perfect, had some quirks unseen on desktop VLC but generally fine.

But yeah external stick is much safer solution, then even tvs like TLC are a great brand.

I had a TCL TV unrelated to the programming language, and the ghosting was awful.
Want to stream Netflix? Disney+? Hulu?

You need to hook something up to a network, and another device would have similar risks.

Setting up a sandboxed VPC or auditing traffic is beyond the means of the average TV owner.

Apple TV is the usual recommendation.
> and another device would have similar risks

Do you think an Apple TV and a Walmart special TV have same risks? I don't. I give the Apple device my network credentials and the TV never sees them.

>You need to hook something up to a network, and another device would have similar risks.

Another device might not give the free reign for all shitty malware like they do. Apple TV for one wouldn't.

> Want to stream Netflix? Disney+? Hulu?

No thanks, I prefer owning my media in a way that corporations can't just take it away whenever they feel like and where I can use (open source) players of my choosing.

The problem is that the LG company went full-spyware. It's not a mere risk, they turned hostile on their customers.
You have 3 replies all saying the same thing, install a ATV...

But the replies are missing the point that most people aren't techies and won't go do this. They go to big box store, buy the tv, ask if it has netflix, done.

They won't (and shouldn't need to) install a ATV.

Never once had a problem with an LG because I've never given it internet access. A trustworthy set top box handles everything instead. Concerned that might not be an option in the future.
That is my problem. What can you trust anymore? Is there an appliance out there that can do the basics and not be a malware gateway?
Smart TVs replaced dumb TVs not out of consumer demand, but out of subsidy from commercial databrokers and streaming services. Despite adding $100 of hardware they were priced $100 cheaper.
> Smart TVs replaced dumb TVs not out of consumer demand […]

The consumer demand was/is for cheaper, and data mining is how OEMs got there. The general public got what they want, and OEMs got to keep their margins: "win-win".

It's the same thing with (US?) airlines: people wanted cheaper, and that's what was offered and they chose.

Faustian barging, the worst part is people are simple unaware of the dealings
Consumers will happily sell their data for a $100 discount. Hell they'll waste 20 minutes watching adverts to save $1.
I'm always wondering how hard it would be to just remove the hardware for spying. Just keep enough hardware to make it a dumb panel, remove the webos logic boards, wifi antenna, etc.
Is there still any specific brand known for dumb tv's that features the quality and 'non smart' options of the smart variants?
Many OEMs have "commercial" / "corporate" displays that may be applicable:

* https://www.samsung.com/us/business/displays/

You could give it a vpn to a public cloud provider so that even if they run residential proxies they still get a dirty vps IP.

Admittedly this doesn't stop the presumed screenshotting and microphone use and worse

LG now installs adware when you merely connect one of their monitors to a Windows PC.
Press the button to turn off the power strip when you're not watching it.

The other solution for those who have a flat white wall (or are willing to install a projection screen) and which I used for years and years: use a dumb projector. There are plenty of perfectly fine dumb projectors and they're very cheap too (compared to the equivalent TV). This also made for the largest diagonal I ever had, in a huge living room, which was really great: basically turning the living room into a mini home theater. I painted the walls etc. accordingly, including a special paint for the white projection wall and black for the side and back walls. This was a better experience than any $$$ TV.

Sadly atm I can't use my projector for my wall ain't flat and I can't install a projection screen and I've got nowhere to put my projector: I could use a short-throw one but the place ain't mine and I'm not allowed to drill holes etc.

So atm it's... Pressing the button on the power strip that powers the LG TV. I know, I know: doesn't help much when the TV is on.

Next thing to do is separate all the junk devices (TV, smartphones [the ultimate spying device btw, much more than your TV], smartwatches, tables, etc.) from your proper stuff (e.g. your important PC running Linux/FreeBSD/etc.). I use different physical LANs (and a bridge/router) but VLANs would do too.

Many cheap home routers also by default offer at least a "guest" network: a perfect place the TV and your relatives' devices when they visit and want access. Set usage quota on the guest network too.

At some point all these devices shall use other networks than yours, so you'll be sorry out of luck anyway. But as long as they don't come with their own battery, pressing the button on the power-strip is some kind of giant low-cost "hack this" middle finger.

Stop buying LG TVs.
Unfortunately they make arguably the best OLEDs and webOS is pretty decent to use (especially compared to the terrible OS that Samsung and Sony run). I think the best thing people can do is update their firmware then disconnect it from the internet. Using an AppleTV or similar provides a better experience than any TVs built in apps anyway.
I don’t ever use their “smart” functionality (that’s what my Apple TV is for) but I’ve never had any issues with the Google TV (Android) build that Sony ships. It doesn’t nag me about being kept offline, is reasonably fast, and doesn’t even show its home screen unless I specifically summon it, so it checks my boxes.
How important is "the best" OLED vs the second best or 100th best OLED? I am personally ok not buying the bleeding edge to not get malware onto my OS.
reasonably important, if you're never connecting your lg tv to any network, and just connecting it to an AppleTV or something and letting HDMI-CEC control it so you never even see their OS.
Exactly this. And with an Apple TV 4K Ethernet, you've got a bonus Thread border router for smart home devices. I actually didn't even realize that initially, but was very pleased when I found IKEAs latest round of Matter over Thread devices paired nicely with it and my existing Home Assistant + Hue setup.
And if you install Tailscale you can even use it as an exit node to surf from home when you're traveling.
I would suggest a mini-PC running Linux and Plasma Bigscreen instead of an AppleTV if you want something 100% private and user-controlled.
my priority for a TV isn't privacy or user control, it's minimizing annoyance. and appletv, roku, or similar streaming boxes delivers that best.
Unless you're using streaming services like Netflix, in which case you're stuck with 720p because of widevine.
Do you recommend any specific distro for this?
Exactly. If you get the best today it'll be the second best tomorrow anyway. Absolute position is undetectable, you can only perceive change. Use that to your advantage and stay off the treadmill.
7 years into my C9 and it never fails to impress.
Exactly. I could probably get a 10 year old panel and be happy with it.
If you care about malware you do not plug it into the internet. I think windows computers are pretty mallwareish as well or at least spyware. People who buy Oled buy them because they care about PQ.
If you care about home cinema it's important. There's a pretty big jump down. You can look up the specs and reviews of the C and G series from LG. Anecdotally quite a few times when people see my 7 year old LG C9 I've had them ask if it was some new expensive TV as they are so impressed with the picture.
2nd best, not. 100th, better to get a great LCD than a junk OLED?
I haven’t looked recently but last I checked Samsung made the best panels. Has that changed recently?
Samsung is good, except:

- No Dolby Vision support, only HDR10+ - Issues with judder/micro stutter - History of nerfing TVs via OTA updates - HDMI ports randomly failing - Bad HDMI-CEC implementation - Selling completely different panel generations under the exact same model names.

Also: Samsung thinks "your" TV is perfect place for them to display their ads.
Samsung scored highest on https://www.rtings.com/ for my criteria, and I'm happy with the purchase. I didn't connect it to the network, of course. (I had to stop my handyman from connecting it and he seemed to think I was crazy for insisting.)
I installed a Pihole and set an edge router to direct any port 53 traffic that wasn’t from the Pihole, to the Pihole.

That made a Samsung behave a little better. But giving it no network access is better.

"I work in software. I have seen things you people wouldn't believe. Attack ships on fire off the shoulder of Orion. I watched C-beams glitter in the dark near the Tannhäuser Gate..."
Eddy currents causing pressurized air deflecting cosmic rays striking drive platters flipping bits...
Their panels are often over-saturated with that fake HDR like look, similar to their phones.
Most screens come with "showroom settings" out of the box. You need to configure them to something more neutral once and then it's fine.
I'm aware of that setting, but this is the Samsung baseline. The panels they export for OEMs / other manufacturers don't seem to have the same hyper saturation. Even just standing next to someone using a Samsung phone or tablet you can often spot it straight away we know you what to look for.
Over saturated HDR is a good default in times when all TV shows only use various shades of pitch black.
That goes away if you set them in filmaker mode.
No, qd-oled is still best, LG is closing the gap with tandem oled but is still the second best panel tech.
Samsung is worse, their OS is horrendous. LG allows local control fairly well and has Home Assistant support.

Samsung is a complete mess, now charging $5/month to use smarthings with no local control. I'll never buy Samsung.

Have to agree, WebOS is much better than Android TV OS, with ads on the dashboard.
As long as you keep it off the internet. Otherwise it’s absolute loaded with adverts everywhere.
Not the 2020 version I have, it has a suggested shows row from the apps I have already installed, which makes sense.

Android TV even has ads for Disney and Apple, which I never installed.

I have a 2026 LG, attached to the internet - absolutely no ads. You need to tweak the settings
You can replace the Android TV launcher with an alternative like Projectivy [1] to get rid of whatever nonsense the stock launcher tries to push. Add Flicky [2] to address F-Droid and you've got a nuisance-free Android TV.

[1] https://github.com/spocky/miproja1

[2] https://github.com/mlm-games/flicky

Thanks, however is kind of the problem, it shouldn't be a thing in first place.
I’m perfectly happy with the status quo where a subsidized $25 Onn 4K streamer from Walmart can easily be turned into a snappy, ad-free, LAN hosted Jellyfin box, with remappable remote buttons after <10min of “effort” to install (and remove) a handful of apps.

I haven’t looked at the stock Google TV home screen on any of my devices in years.

>I think the best thing people can do is update their firmware then disconnect it from the internet.

We don't need treats this badly.

I thought webOS was pretty decent initially. But LG never provided even a single major update to my TV in a decade, so that just about cancels any possible benefits from the faster code. I'm using Chromecast for several years now, bypassing and ignoring webOS completely. But the initial idea was nice, all those years ago.
Really? I've had many updates over the 7 years since my c9 was released, still getting them as recent as earlier this year I think.
Just to clarify - my LG TV is old (10 or maybe 11?), pre-OLED, and webOS on it was version 3.0. Maybe situation has improved with newer models, I don't know. The problem with TVs, is that they really work for a long time just fine and I see no reason to change it ahead of other more needed upgrades. It doesn't fall to the ground like phones, there is no degrading battery or degrading rubber/textile parts, TVs are really robust. So it would have been nice if the software for such long living hardware was also supported accordingly and that buyers would be informed about that in advance and that was my expectation for webOS/LG originally - since it is in C++, uses modern and maintained QT framework, snappy and LG is a bigcorpo, I expected it to keep up. But nope :( .
I have mine attached to the internet, but it does take a good 30 minutes plus Googling to find out all the places that you have to turn stuff off.
3 out of 4 OLED screens in my household suffer from burned pixels. It's the early 90s all over again with OLED.
How old are these and how often / how long are they turned on? My OLED TV is over two years old now without any issues even though it gets frequent usage.
I don't buy a TV every 2 years, that's absurd. If I buy a TV, it better work for > 10 years.
You are attacking a straw man instead of answering the question.
I have 3 LG OLEDs of all different generation and they all still go great. It is by far the best tv you can get vs other manufacturers.
You know your phone is OLED right? I'm assuming you left a still image on without the inbuilt screen refresher enabled or something? I remember seeing that way back in the early OLED days but not on good TVs in the last 8~ years.
Yes, that's what bothers me. OLED was the newfangled improved technology, but I'd rather hold out until something better becomes affordable.
Aren't they the only TVs that can be jailbroken?
I decided there wasn't much to do if I did:

https://www.webosbrew.org/rooting/

I thought this, but random updates and changes for my apps in dev mode got too annoying; switching to full root has made my apps stable and turned off the prompts to upgrade the OS. It was worth it.
And buy what? Smasnug? Sony? They're all uniquely shit.
The problem I have is....it just works. I'm tired of having to manage 50 different devices to let my son watch some Gabbys Dollhouse on the TV. Our LG CX is now 6 years old and it just works. I only need one remote for all the apps and sound, and I don't need to worry about another device. I've tried both Apple TV and Amazon Fire Stick, and both were (subjectively) worse experiences than just using the apps built into the TV. So.....in the interest of making my life feel less like an IT admin of my own house....I think I'll just use the built in apps and keep my TV connected to the internet.
> I'm tired of having to manage 50 different devices to let my son watch some Gabbys Dollhouse on the TV.

Other than the TV, most people really have only one device (Roku, AppleTV, etc). Why do you need so many?

> I only need one remote for all the apps and sound,

True with Roku.

It's called a hyperbole. But I already have to babysit a NAS and a media server, and make sure the Playstation and Xbox are up to date and signed in, the last thing I want is another device just to watch netflix on.

>>True with Roku

Can the Roku remote change the input source on the TV?

> But I already have to babysit a NAS and a media server

Is the NAS TV related? Why do you need these? My media is all on my PC, and I don't consider maintaining that as part of my TV burden. I have to maintain it anyway.

And what maintenance do you need for the PS and XBox? You just turn it on when you use it, and let it auto-update.

> Can the Roku remote change the input source on the TV?

Fair point.

Normally, I change the source only once during a whole session, so I do that right in the beginning if I need to.

I would love it if I could disable bluetooth on the TV. I have never connected it to any network and its still blaring "HELLO SOMEONE NEARBY HAS AN LG TV" to the entire neighbourhood 24/7.
My LG DualUp monitors (with no internet access) recently triggered some LG Adware Bullshit to install on my Windows laptop. So I'd say stop using LG anything (or Windows anything since they're voluntarily in on the scam too lol). If you want the 2560x2880, maybe buy the knock-off INNOCN vertical monitors.

https://old.reddit.com/r/pcmasterrace/comments/1v1pkbs/lg_sp... ← examples of others who ran into the same shit

I would probably have a DualUp by now if I could find one available anywhere: it's a very appealing form factor. I looked at the INNOCN site, but only see normal-looking monitors there; do you have a model name or any pointers I could search for?
I will say I have two DualUp monitors and they are my favorite monitors I ever had so I'm sad I can no longer recommend them. 2560x2880 is perfect for programming, researching, writing documents, graphics work, and so on.

The INNOCN knockoff is the INNOCN 28C1Q. Likely the same panel.

https://www.amazon.com/dp/B0BWDMYK83?peakEvent=4&dealEvent=1...

https://www.newegg.com/p/3D4-007R-00003

Out of stock on Amazon and Newegg

Stop buying LG tvs.
Stop buying LG