The monitors aren't installing anything. That headline was a lie.
It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs. That's why the problem affected older monitors too - it's the update side that suddenly started to ship malware.
> It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs
This is also a misrepresentation. Microsoft has provided LG with a certificate to sign its driver packages with, and allows LG to upload packages to Windows Update, which includes a feature to install sidecar applications. Now, the spirit of this feature is that any application is meant to provide genuine configuration functionality or some graphical front end to the driver's configuration knobs.
LG then abused that feature to provide adware. Now, there are millions of hardware vendors. One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.
Sometimes one actually wants the app that comes with the device, like AMD's and NVIDIA's configuration trays.
Even so, I fully expect that after this debacle MS will disable this stuff. There is precedent for this. Synaptics/ELAN/Alps touchpad tray applications largely disappeared after MS implemented precision touchpads somewhere in 2015, and suddenly Windows touchpads became as precise as those on Macs. Likewise with RGB peripherals. Even GPU driver applications have increasingly become less useful as the most important features—power control, adaptive sync, HDR, etc have moved into native Windows settings.
Because at scale, that doesn't work, I think, even money no object, because it's a task that requires a lot of domain knowledge, but also is monotonous and offers little in the way of satisfaction or looking good on your resume, so the candidates you're trying to hire aren't very junior, and also are not going to like the work.
IIRC, at least 15 years ago, that's exactly what they did. They published a tool suite that your driver should pass before submission because otherwise it would fail when they got to it. I think the submissions were fully automated by that time.
> One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.
Maybe not, but LG has violated this trust and should therefore be either fined or severely restricted by Microsoft. Banning will likely cause more problems than solutions, but they shouldn't get away with this.
Adware was a huge problem during the Windows XP era, can't believe it's coming back now through Microsoft's official channels.
Also I doubt there's actually millions of hardware vendors. But that aside, Microsoft has a duty to vet everything that they offer through their channels. If it's too expensive for them to do, do like Apple did and have those that want to make use of their distribution network (and trust) pay them.
> I doubt there's actually millions of hardware vendors.
Almost certainly correct because there are only 2^16 USB manufacturer IDs, of which (warning, Google AI quick result...) only 3400 are used. Tiny vendors of e.g. USB drives often seem to use the vendor and device ID of the interface chip manufacturer, but that's probably a good filter for really unimportant ones. Of course not every device has USB, but most major hardware vendors implement USB somewhere and have an official USB vendor ID.
> after MS implemented precision touchpads somewhere in 2015, and suddenly Windows touchpads became as precise as those on Macs.
There’s still a world of difference between a MacBook touchpad and a windows one. My work laptop (18 month old dell XPS) can’t hold a candle to my 6 year old MacBook’s trackpad.
> Likewise with RGB peripherals. Even GPU driver applications have increasingly become less useful as the most important features—power control, adaptive sync, HDR, etc have moved into native Windows settings.
The peripherals still need the addons though; I have ASUS armory crate, Corsair iCue and MSI center for my Motherboard, cooler and GPU respectively. They all suck.
> There’s still a world of difference between a MacBook touchpad and a windows one. My work laptop (18 month old dell XPS) can’t hold a candle to my 6 year old MacBook’s trackpad.
The latest Dell trackpads are quite bad. Price or the product being premium or not unfortunately does not tell you if it will have a good trackpad or not. And it changes over time (Dell XPS used to have really good trackpads)
Basically you have to go to a store and try or find reviews that actually pay attention to this.
> There’s still a world of difference between a MacBook touchpad and a windows one
Oddly I've found otherwise (Dell Precision notebook from 2021, and Surface Laptop). It might be macOS's animations and smoothing interfering here, but I've found that my Windows touchpads are much more responsive, especially when swiping between desktops.
> The peripherals still need the addons though
Ugh, this is annoying. Hardware vendors need to be banned from writing lousy, inefficient, unsafe software.
My point is not to shift the blame to Microsoft; it's primarily LG that's at fault here.
My point here is simply that it's not the monitor that is installing this. Neither the malware nor the URLs to malware exist on the device - they get fetched as part of normal OS-side auto-provisioning, which is the part that was compromised.
This is a primary LG fault, however I would say that Microsoft also has a fair bit of blame here.
They are downloading and installing something without the users consent.
It's nice to have drivers work without any intervention, same with "helper software" but along side the ease of use they also took on the responsibility.
If I download some random .exe from the net; I have to confirm that I want to run it, sometimes I even have to right click and unblock it to allow it to run, because it is "untrusted".
Their signature key, their auto-run system, everything done for ease of use means they own this.
Yes, and it's only possible thanks but no thanks to MicroSlop.
And it's not like MS is too poor to do anything useful for their customers. They just don't want to unless the cost-benefit analysis pans out in their favor. The customer is worth as much as their wallet.
I can only imagine the meetings at microsoft HQ where they all sat around a table and crossed their fingers and hoped that vendors would act in the spirit of their design.
> One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.
If you're going to allow 3rd parties to install software on potentially billions of computers with far reaching privileges then you better have something in place other than 'just trust me bro'.
Why's that? "Just trust me bro" is the security model of all closed source, proprietary software. OMG, the program with secret source code is doing shady stuff? I'm shocked - shocked!
Hard to get worked up over "3rd parties" when even 1st parties cheerfully stomp all over the interests of their users. That ship sailed, caught fire, and sank to the bottom of the ocean the day Candy Crush appeared in the goddamned Start menu.
The situation is very different on Macs. Apple control almost the entire hardware stack of the machines that macOS runs on. They make it an absolute pain in the neck to run any application not blessed by attestation. This attestation server is also frequently offline. They've also made it very difficult to write things like filesystem drivers, having completely pulled that functionality from more recent versions of macOS. In fact, if I recall correctly one cannot ship a third-party kext on more recent Macs, especially ARM ones. As such, hackintoshing has basically vanished as a hobby.
At least on Windows, the most you get is a scare screen saying 'this app is from an unidentified developer'. I know what I'd rather have.
I would say it's neither a lie nor misinformed. It 's a punchier headline that can be justified by what the user experiences. The user connects a monitor which causes ads to appear. The rest of this Rube Goldberg contraption is a mere detail.
The headline isn't a lie, even if you can technically nitpick it.
The manufacturer implemented choices to deliberately install the software when the monitors are connected. The mechanism is not important to why this is outrageous.
Wait, you're saying a monitor can just advertise a URL over the video connection for its driver and then Windows will blindly install it, without user confirmation? I thought that LG had submitted these "drivers" (adware) to Microsoft and they approved it.
As far as I'm aware, the monitor does not transmit a URL. Windows is looking at the hardware's vendor and device IDs and using those to look up and download the "drivers" that LG has stated are for that device.
2. Windows Update runs automatically and not (usually) manually
3. Automatic update can't even be disabled, only manually postponed a bit
At least 2 and 3 are different on virtually every Linux distro. Also, I find it very unlikely that they would accept such behavior.
To give MS the benefit of the doubt here, now that this happened and has been reported on they might decide to enforce stricter rules on manufacturers in the future. But as a Windows user you don't have a choice in case you don't like how they decide and how their decisions might change again later.
I believe you register your device with Microsoft so Windows can automatically obtain and install drivers for them when they are plugged in.
What LG sent in for installation is not a simple .inf or .sys/.dll file. They sent in a whole bag of software which does all the nasty things, and Microsoft doesn't vet or care about the software installed as the "driver" of the hardware.
This is actually a feature of the .inf by design, an AddSoftware directive. It can even link to apps from the store instead of bundling them with the driver. This is designed to install settings panels like the ones for GPUs.
I guess that from Microsoft's perspective, the driver itself wasn't suspicious, but it installs a questionable sidecar app they would have never vetted anyway.
But in a Plug-and-Play world, its addition is noticed by the operating system -- as has been normal for decades.
Microsoft's Windows operating system sees this new hardware ID and then goes forth to install whatever-the-fuck software it associates with that identification, presumably as a service to the user. (Did Microsoft approve it? Dunno. I'm just over hear eating popcorn.)
I would say 95%+ do just this. The Debian, Ubuntu, and even Fedora repos are very large and include all the software you could ever want. And then flathub takes the rest.
It’s really only arch with the AUR and some others where completely untrusted packages are used. This is legitimately a better model than what windows does, although Microsoft has been trying to change this with winget.
> Increasingly software is distributed by "curl dodgysite.com/get.sh|sudo bash -"
I don't think this is the norm at all. I have seen curl/bash install scripts for tools like Claude Code, but they don't use sudo, and the expectation is that you deploy them in isolated user accounts or containers.
Paste that in the macOS Terminal, a Linux shell or WSL. The script explains what it will do and then pauses before it does it. Read about other installation options.
== k3s ==
K3s provides an installation script that is a convenient way to install it as a service on systemd or openrc based systems. This script is available at https://get.k3s.io. To install K3s using this method, just run:
These scripts have lines like
> abort "Need sudo access on macOS (e.g. the user ${USER} needs to be an Administrator)!"
> the expectation is that you deploy them in isolated user accounts or containers.
Why are you lying right now? This is a norm across the dev tools world for businesses to distribute dodgy curl piped to bash scripts that users install without question, popular examples: homebrew, docker, nvm, bun, deno, k3s. There is zero "expectation" given by any of these install scripts that they are isolated. Can you even find a single source online that suggests doing what you said for you to think its a commonly held expectation?
There is one major difference: those install under your users. I haven’t seen a windows installer that didn’t require admin. Some older Linux apps require sudo. They don’t need to do that anymore, not for a while. We have xdg standards of where to install stuff in a users home directory.
It is such glaring security hole that there was an old submission about filling such install script with `sleep` commands and detecting it on server side, to send different versions for downloading (and reviewing) and for actual direct execution.
Famously, the Linux kernel does not have a stable ABI for drivers. As a result, by far the majority of drivers are in-tree, maintained by the kernel folks as part of the kernel.
The Linux approach has the downside of not having the drivers if a vendor has not been working with the kernel community before launch (or for those who haven't upgraded to a kernel that has the driver, e.g. a LTS release).
On the other hand, the driver is maintained by kernel developers, not created by the hardware developer who is not getting paid after they sell the device. This helps avoid abandoned / vulnerable drivers, or having the hardware dev search for... alternative revenue streams, as in this case.
If you're trying to say that Microsoft implemented a method of delivering specifically malware executables to every PC, I've got a bridge to sell to you.
Linux's 'security model’ has plenty of holes. The very fact the kernel and much of its user-mode is written in C almost guarantees that its security model is worthless. The Linux ecosystem operates on trust and respect that can and has been easily abused by bad actors to provide supply-chain pwnage.
There have been so many zero-click local privilege escalation CVEs I've lost track.
AUR is an effectively unmoderated user repo. It’s not Arch Linux’s core repository, nor is it enabled by default or indeed even possible to use without manual downloads from outside the package manager.
You have confidence you are actually downloading the same foo as everyone else. And if there were an issue there would be pushback. Not so if you get some random exe from warez.com
Yes it isn't perfect, it's still a lot better than windows land.
I think you can probably find a better example, even if less recent. The AUR is unofficial and not properly vetted in the same way as the actual Arch repos, Debian repos, etc.
Implementation bugs are not holes in the security model. Linux has plenty of those, as does Windows.
Windows security model trusts, downloads, and immediately executes arbitrary software when a new untrusted device is plugged in, without asking the user.
I guess with more and more consumer devices running Linux based OSes (SteamOS, Android, Bazzite, Silverblue, ..) that becomes more and more interesting.
And unfortunately the "I'm safe on my non-windows-system" argument doesn't count for long, as the 99% muggle crowd justifies a shift to a world where our non-certified (=> 'insecure') systems are not supported by big companies anymore, as it's currently happening on Android.
A tech YouTuber showing this off and all the anti consumer behavior. I’m assuming this threads article is for an LG PR piece trying to redirect anger at the app developers to hide the fact that they are engaged in the same behavior themselves.
I'm mostly very happy with my LG C4 as a home theatre centerpiece, and I did have it online so that I could use the apps for YouTube and Jellyfin. However, the lack of support for modern 4k rips (HEVC+DTS) ended up being a dealbreaker and I finally ditched the built in software for a fire stick instead.
No transcoding, no weird codec issues, just the raw files direct streamed from the underpowered Unraid box, into the back of the AVR where the audio is handled correctly and the video is sent to the screen.
There is always android VLC app to decode anything, you just need enough power in chipset to handle that. Not perfect, had some quirks unseen on desktop VLC but generally fine.
But yeah external stick is much safer solution, then even tvs like TLC are a great brand.
No thanks, I prefer owning my media in a way that corporations can't just take it away whenever they feel like and where I can use (open source) players of my choosing.
You have 3 replies all saying the same thing, install a ATV...
But the replies are missing the point that most people aren't techies and won't go do this. They go to big box store, buy the tv, ask if it has netflix, done.
Never once had a problem with an LG because I've never given it internet access. A trustworthy set top box handles everything instead. Concerned that might not be an option in the future.
Smart TVs replaced dumb TVs not out of consumer demand, but out of subsidy from commercial databrokers and streaming services. Despite adding $100 of hardware they were priced $100 cheaper.
> Smart TVs replaced dumb TVs not out of consumer demand […]
The consumer demand was/is for cheaper, and data mining is how OEMs got there. The general public got what they want, and OEMs got to keep their margins: "win-win".
It's the same thing with (US?) airlines: people wanted cheaper, and that's what was offered and they chose.
I'm always wondering how hard it would be to just remove the hardware for spying. Just keep enough hardware to make it a dumb panel, remove the webos logic boards, wifi antenna, etc.
Press the button to turn off the power strip when you're not watching it.
The other solution for those who have a flat white wall (or are willing to install a projection screen) and which I used for years and years: use a dumb projector. There are plenty of perfectly fine dumb projectors and they're very cheap too (compared to the equivalent TV). This also made for the largest diagonal I ever had, in a huge living room, which was really great: basically turning the living room into a mini home theater. I painted the walls etc. accordingly, including a special paint for the white projection wall and black for the side and back walls. This was a better experience than any $$$ TV.
Sadly atm I can't use my projector for my wall ain't flat and I can't install a projection screen and I've got nowhere to put my projector: I could use a short-throw one but the place ain't mine and I'm not allowed to drill holes etc.
So atm it's... Pressing the button on the power strip that powers the LG TV. I know, I know: doesn't help much when the TV is on.
Next thing to do is separate all the junk devices (TV, smartphones [the ultimate spying device btw, much more than your TV], smartwatches, tables, etc.) from your proper stuff (e.g. your important PC running Linux/FreeBSD/etc.). I use different physical LANs (and a bridge/router) but VLANs would do too.
Many cheap home routers also by default offer at least a "guest" network: a perfect place the TV and your relatives' devices when they visit and want access. Set usage quota on the guest network too.
At some point all these devices shall use other networks than yours, so you'll be sorry out of luck anyway. But as long as they don't come with their own battery, pressing the button on the power-strip is some kind of giant low-cost "hack this" middle finger.
Unfortunately they make arguably the best OLEDs and webOS is pretty decent to use (especially compared to the terrible OS that Samsung and Sony run). I think the best thing people can do is update their firmware then disconnect it from the internet. Using an AppleTV or similar provides a better experience than any TVs built in apps anyway.
I don’t ever use their “smart” functionality (that’s what my Apple TV is for) but I’ve never had any issues with the Google TV (Android) build that Sony ships. It doesn’t nag me about being kept offline, is reasonably fast, and doesn’t even show its home screen unless I specifically summon it, so it checks my boxes.
reasonably important, if you're never connecting your lg tv to any network, and just connecting it to an AppleTV or something and letting HDMI-CEC control it so you never even see their OS.
Exactly this. And with an Apple TV 4K Ethernet, you've got a bonus Thread border router for smart home devices. I actually didn't even realize that initially, but was very pleased when I found IKEAs latest round of Matter over Thread devices paired nicely with it and my existing Home Assistant + Hue setup.
Exactly. If you get the best today it'll be the second best tomorrow anyway. Absolute position is undetectable, you can only perceive change. Use that to your advantage and stay off the treadmill.
If you care about malware you do not plug it into the internet. I think windows computers are pretty mallwareish as well or at least spyware. People who buy Oled buy them because they care about PQ.
If you care about home cinema it's important. There's a pretty big jump down. You can look up the specs and reviews of the C and G series from LG. Anecdotally quite a few times when people see my 7 year old LG C9 I've had them ask if it was some new expensive TV as they are so impressed with the picture.
- No Dolby Vision support, only HDR10+
- Issues with judder/micro stutter
- History of nerfing TVs via OTA updates
- HDMI ports randomly failing
- Bad HDMI-CEC implementation
- Selling completely different panel generations under the exact same model names.
Samsung scored highest on https://www.rtings.com/ for my criteria, and I'm happy with the purchase. I didn't connect it to the network, of course. (I had to stop my handyman from connecting it and he seemed to think I was crazy for insisting.)
"I work in software. I have seen things you people wouldn't believe. Attack ships on fire off the shoulder of Orion. I watched C-beams glitter in the dark near the Tannhäuser Gate..."
I'm aware of that setting, but this is the Samsung baseline. The panels they export for OEMs / other manufacturers don't seem to have the same hyper saturation. Even just standing next to someone using a Samsung phone or tablet you can often spot it straight away we know you what to look for.
You can replace the Android TV launcher with an alternative like Projectivy [1] to get rid of whatever nonsense the stock launcher tries to push. Add Flicky [2] to address F-Droid and you've got a nuisance-free Android TV.
I’m perfectly happy with the status quo where a subsidized $25 Onn 4K streamer from Walmart can easily be turned into a snappy, ad-free, LAN hosted Jellyfin box, with remappable remote buttons after <10min of “effort” to install (and remove) a handful of apps.
I haven’t looked at the stock Google TV home screen on any of my devices in years.
I thought webOS was pretty decent initially. But LG never provided even a single major update to my TV in a decade, so that just about cancels any possible benefits from the faster code. I'm using Chromecast for several years now, bypassing and ignoring webOS completely. But the initial idea was nice, all those years ago.
Just to clarify - my LG TV is old (10 or maybe 11?), pre-OLED, and webOS on it was version 3.0. Maybe situation has improved with newer models, I don't know. The problem with TVs, is that they really work for a long time just fine and I see no reason to change it ahead of other more needed upgrades. It doesn't fall to the ground like phones, there is no degrading battery or degrading rubber/textile parts, TVs are really robust. So it would have been nice if the software for such long living hardware was also supported accordingly and that buyers would be informed about that in advance and that was my expectation for webOS/LG originally - since it is in C++, uses modern and maintained QT framework, snappy and LG is a bigcorpo, I expected it to keep up. But nope :( .
How old are these and how often / how long are they turned on? My OLED TV is over two years old now without any issues even though it gets frequent usage.
You know your phone is OLED right? I'm assuming you left a still image on without the inbuilt screen refresher enabled or something? I remember seeing that way back in the early OLED days but not on good TVs in the last 8~ years.
I thought this, but random updates and changes for my apps in dev mode got too annoying; switching to full root has made my apps stable and turned off the prompts to upgrade the OS. It was worth it.
The problem I have is....it just works. I'm tired of having to manage 50 different devices to let my son watch some Gabbys Dollhouse on the TV. Our LG CX is now 6 years old and it just works. I only need one remote for all the apps and sound, and I don't need to worry about another device. I've tried both Apple TV and Amazon Fire Stick, and both were (subjectively) worse experiences than just using the apps built into the TV. So.....in the interest of making my life feel less like an IT admin of my own house....I think I'll just use the built in apps and keep my TV connected to the internet.
It's called a hyperbole. But I already have to babysit a NAS and a media server, and make sure the Playstation and Xbox are up to date and signed in, the last thing I want is another device just to watch netflix on.
>>True with Roku
Can the Roku remote change the input source on the TV?
> But I already have to babysit a NAS and a media server
Is the NAS TV related? Why do you need these? My media is all on my PC, and I don't consider maintaining that as part of my TV burden. I have to maintain it anyway.
And what maintenance do you need for the PS and XBox? You just turn it on when you use it, and let it auto-update.
> Can the Roku remote change the input source on the TV?
Fair point.
Normally, I change the source only once during a whole session, so I do that right in the beginning if I need to.
I would love it if I could disable bluetooth on the TV. I have never connected it to any network and its still blaring "HELLO SOMEONE NEARBY HAS AN LG TV" to the entire neighbourhood 24/7.
My LG DualUp monitors (with no internet access) recently triggered some LG Adware Bullshit to install on my Windows laptop. So I'd say stop using LG anything (or Windows anything since they're voluntarily in on the scam too lol). If you want the 2560x2880, maybe buy the knock-off INNOCN vertical monitors.
I would probably have a DualUp by now if I could find one available anywhere: it's a very appealing form factor. I looked at the INNOCN site, but only see normal-looking monitors there; do you have a model name or any pointers I could search for?
I will say I have two DualUp monitors and they are my favorite monitors I ever had so I'm sad I can no longer recommend them. 2560x2880 is perfect for programming, researching, writing documents, graphics work, and so on.
The INNOCN knockoff is the INNOCN 28C1Q. Likely the same panel.