Hacker News new | ask | show | jobs
by 12_throw_away 10 days ago
42% of the apps on LG's platform have these quasi-malware SDKs in them? Seems kinda bad, whether it's due to negligence or just pure incompetence? You'd think there might be legal consequences for a corporation that lets their app store turn into a malware delivery system?
5 comments

It's not "quasi-malware," it is malware.
15 years ago people would've called it spyware.
20 years ago people would've called it a trojan horse.

But then, by standards of two decades ago, every website that cannot legally avoid showing a GDPR popup would be classified as malware. As it should be today. Alas, standards have changed.

> But then, by standards of two decades ago, every website that cannot legally avoid showing a GDPR popup would be classified as malware. As it should be today. Alas, standards have changed.

I don't think you've read GDPR. In Europe (at least my part), *every* organization has a GDPR policy you need to agree to. Your child's school. Summer camps. Etc. Most are also conservative and reasonable.

What's broken is the GDPR popup with a dozen "legitimate interest" toggles for spying on you.

That was exactly the point OP was making.
That pop up is not required by GDPR

You only need explicit consent from the user for tracking you do not require for valid business purposes

It's like complaining that OSHA sucks because every time you visit the grocery store you have to sign a waver that if they throw you in a wood chipper, you cant sue them.

That problem is not with liability wavers!

What feels really crummy to me is how many people don't seem to know that websites cannot really prevent you from using them if you reject optional cookies, so average people are afraid that if they say no, they can't use websites.

Funny some you can't say no, so I'm like alright guess I'm not going in
There were no cookie popups 20 years ago.
Err, there were, prepare to feel old "Cookie consent pop-ups first started appearing following the adoption of the ePrivacy Directive in 2002" 25 years!
I beg to differ, there absolutely was cookie popups. We also had popup windows, popup ads, java applets that melted your cpu, and browsers with no grid. Oh, and we had Shockwave and Flash…
I think they meant that the use of cookies for analytics/tracking, which is what triggers the popup requirement, would have been considered malicious.
Indeed.
Some browsers would individually request you approve each cookie s website set. This is a feature of the browser itself that the website is unable to control. Lynx still has this option, I believe.
Yes, let's put the Overton window back where it used to be.
... If it was spying—,it isn't
My understanding is that these apps' TOS explains that by using the app you consent to having third party traffic routed through your device. For example [1] the Hola VPN's free users agree to let third party traffic get routed through their networks. Now, how closely users actually read the TOS is a different story, but it's arguably not malware on the grounds that users are, at least on paper, informed and agree to this behavior.

1. https://en.wikipedia.org/wiki/Hola_(VPN)

Nope, still malware. Arguing that people can technically read the TOS is (maliciously?) ignoring the social contract that most of us live by (i.e. don't trick people and screw them).
My understanding of malware is that it must cause some problem for the user.
Slowing down your internet connection due to using your bandwidth without your knowledge, getting blocked by websites due to malicious traffic from your IP address, extra annoying captchas due to the same. Those were just the first 3 things off the top of my head.
Got plenty of bandwidth, sites block you regardless, you get captchas regardless. Plus, IP addresses rotate once a day so you're just as likely to get someone else's bad reputation anyway.

To sue them you'd have to show some actual, concrete harm. For example you contact a site that is blocking you and they tell you it's due to a certain request and you trace that request to the proxy.

  > Plus, IP addresses rotate once a day 
This is entirely specific to the user’s ISP, my “dynamic” IP goes months without changing.

And I would be miserable if I were subjected to the volume of captchas and blocks on my regular internet connection that I see on the occasion I use Tor.

It's all above board though, as you, the user, agreed to the terms & conditions for installing said app.

This won't change unless governments create and enforce laws.

It is, though. Why should I not be able to agree, with sufficiently informed consent, to route traffic through a connection I operate via a computer I own using software I've chosen of my own free will to install?

What's the difference between running a Tor exit node and a "residential proxy" except optics?

Look: I'm 100% for banning secret proxies that hide from the user, but stopping people knowingly and voluntarily running these proxies is a violation of fundamental software freedom tenets.

The difference is the user. Your average smart TV user doesn't know what a residential proxy is, hell who's installing/playing the games but children? Consumer regulation to protect consumers from a knowledge disparity that leads to uninformed consent isn't a bad thing imo.
We're not talking about people voluntarily installing proxies, we're talking about proxies piggy backing on apps that are marketed for an entirely different purpose.
The article is clear that LG is talking about banning all proxies, even voluntarily installed ones. A smart TV is a computer. Why should the owner of a computer not be allowed to run any program he wants?
That is not the case.

The article is quite clear that LG runs an "app store" where 42% of the "apps" likely contain residential proxies, and LG is going to make its "app store" developers stop doing that. From TFA:

> “A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said. “If this option is not removed, these apps will be suspended.”

This says nothing about your own software installed on the TV, should that be possible.

But even if you ran your own software on your TV, would you run a proxy service? Given you already have a residential ISP, you wouldn't need to hook your TV up to a botnet and buy residental ISP access for your scrapers via your own, or other unwitting suckers', TVs.

Your hypothetical of wanting to run a Tor exit node is silly. Most Tor exit node operators run them knowingly on dedicated hardware, usually in a datacentre, not their own home, and prepare themselves legally for when they inevitably get emails from law enforcement, or worse, raided. You'd almost certainly firewall the destinations it can reach, you wouldn't let it have access to your own network, and you wouldn't run it on your TV.

It very much is the case. Your own quote contradicts you. A smart tv is definitely a computer (one of the selling points is literally that it runs arbitrary apps) and LG is declaring that this "is not an intended use for LG smart TVs" and banning it.

There is certainly a conversation to be had regarding consumer protection laws, the nature of an appliance, and the trade-offs thereof but this is not that conversation and I don't think you engaged in good faith with the comment you replied to.

Some people do run Tailscale proxies in their home, and an always-on device like a TV is a good place to run it.
It all comes back to this. I pay for the network, I'm liable for it: I decide what comes through it.
Terms and conditions are not the get out of consumer protections free card that you think it is.
They are, unless governments actually crack down.

A lack of enforcement actions has caused situations like this.

Why would LG do better when it's cheaper to not?

Are there laws against clauses in the T&Cs that allow companies to arbitrarily change the said T&Cs? Are there laws against clauses that prevents consumers from suing companies? Unless there are, T&Cs absolutely are the get out of jail free card both on paper and in the real world.
I mostly agree, but it's the lack of enforcement that's the Get out of Jail Free card, not the T&C
> It's all above board though, as you, the user, agreed to the terms & conditions for installing said app.

I have an LG TV, about 6 years old now. For a while it was connected to the internet. Every time I turned it on, after a ~20s delay, it would pop up asking me to install an update and I would press RIGHT + OK to select the "No" button because it worked fine and previous updates just made it slower, added ads etc.

Eventually, the remote dropped the button press for RIGHT, and just got the OK. Or maybe I just pressed the buttons too fast -- the interface is laggy and I'd developed muscle memory. This started the software update with no way to cancel from the UI. Once it updated, it made me accept a new EULA just to continue using the TV in the way I already used it (which was mostly as an HDMI display). There was no way to even get to the settings dialog to perform a factory reset without accepting the EULA. The device was held hostage until I said "Accept."

This is the level of consent implied by accepting the EULA on a TV: none. It's bullshit. Computers should never have been put in TVs, and a smart TV should never be connected to the internet.

Then you took it back to the store for a refund, right?
They've seen the ruckus that follows from controlling / curating the app store experience. For example, see the comments at https://news.ycombinator.com/item?id=45017028
That's for a general purpose computing platform that a smartphone is.

This is for a fucking TV.

Phone is now smart phone. TV is now smart TV.

Very unfortunate.

Glad my 2007 Sony Bravia still works, even if only standard HD.

Some might say that a smart phone and a smart TV have a lot of similarities.
And those people will be wrong.

Besides, there's no shortage of dumb phones and featurephones on the market. We want the same for TVs.

> You'd think there might be legal consequences

I own an airgapped LG TV. Does anyone actually want to go class action/mass arb?

Airgapped is harder than you might think. If your TV finds an open network (neigbours?) it will use that one. And it is only a matter of time before they have cellular capabilities too.
> If your TV finds an open network (neigbours?) it will use that one

I looked into this last year while researching TVs and couldn’t find anything to substantiate it.

When was the last time you saw a completely open residential wifi access point in the wild?

This seems a little like worrying about getting Dodo poisoning.

Mine up until a few months ago. Didn't really care because you'd have to stop literally in front of my house to access it. And living on a street with only about 4 properties, that would merit a visit from me asking why you're parked in front of my house.
> When was the last time you saw a completely open residential wifi access point in the wild?

I have family who get frustrated with their home Wi-fi and about every other year conclude the solution is to unsecure the connection.

I'm not sure Comcast would even let me do that today, though I haven't tried. I gave up running my own home router and WiFi a few years ago, they just made it too much of a PITA.
maybe not residential, but if you are close to a coffee shop or bar or anything else that offers it...
I genuinely don't recall the last time I saw one of those that didn't require me to at least go to a registration page to accept the terms and conditions in order to actually transmit any traffic.
Maybe 10 years ago. Very few homes have an open network today, ISPs all ship their routers with random passwords and/or force the customer to create a WiFi password during setup.
Comcast still defaults to adding an Xfinity access point to their routers for other customers to use.
Which requires login (and a separate paid subscription these days).
> Airgapped is harder than you might think

Probably. The LG TV I have doesn't have cellular, but does have a removeable Wifi/Bluetooth module [1]. You have to disconnect a ribbon, unscrew the module and then pop it out.

[1] https://www.manualslib.com/manual/3140596/Lg-Oled83g3-Series...

Sometimes those "modules" are just the antenna, and the Wifi is quite capable of connecting with no antenna at all.
All radios (including those that do wifi stuff inside of televisions) need an antenna in order to perform wireless communications.

An antenna may be obvious and external (like one on the fender of a 1979 Ford Pinto), or built with very deliberate PCB traces (as with a Raspberry Pi), or incidental (some component of the device behaves as an antenna, even if unintentionally), or a combination of these things, or something else entirely.

But whatever its form: An antenna must be present or wireless RF communication simply can't occur.

Make it a tinfoil hat :-)
Aah yes, the ol' "Emergency Wi-Fi Connection" Nintendo uses to make really scary anti-piracy screens where they dial 911 and call the cops on you playing a pirated version of New Super Mario Bros U.
LG's own code is quasi-malware