deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (hnrss.org)

GamersNexus claims LG TVs can eavesdrop; technical critique says evidence falls short

GamersNexus alleges LG smart TVs can be turned into listening devices that map home networks, but a widely shared critique argues the encrypted traffic shown never proves what data actually leaves the set.

GamersNexus claims LG TVs can eavesdrop; technical critique says evidence falls short

What GamersNexus alleges

GamersNexus has published a roughly two-hour investigation into LG's WebOS televisions arguing that the sets can function as eavesdropping devices, with the advertising stack built into the platform described as a contributing factor. The video has since drawn a detailed rebuttal in a blog post that reached the Hacker News front page, whose author contends that several of the most dramatic claims outrun the evidence actually shown.

According to the video, as recounted in the critique, the team found log files on the television containing transcripts of spoken phrases, including references to credit card details and a Social Security number. GamersNexus further asserts that the set could record from its camera and microphone while appearing to be powered off, keep capturing audio with networking disabled for later retrieval by anyone with remote access, and sweep the local network, cataloguing dozens of unrelated devices.

A screen in the video also lists what LG is said to be capable of collecting: the viewer's IP address and approximate location, the names, signal strengths and channel assignments of nearby Wi-Fi networks, and the internal addresses of other devices on the network — including office phones with no connection to the TV whatsoever.

Where the critique pushes back

The blog post's author reads the transcripts differently. The log entries appear next to search responses, suggesting the testers performed a voice search, spoke the test phrases, and the operating system then logged the query and its results. That is not continuous recording, the author argues, and while storing such logs on the device is questionable, it is a long way from proof of covert transcription.

The alleged network crawling fares no better in this reading. The traffic highlighted in the video, with commentary from security researcher MrBruh, consists of standard discovery protocols — mDNS, SSDP and reverse DNS — plus Kasa and LIFX smart-home chatter. The author notes that practically every IoT device and media player emits similar traffic, and that probing for Samba shares or DLNA servers is ordinary behavior for a television. What would be genuinely damning — pairing discovered hostnames with a unique identifier and uploading them to LG's servers or advertisers — is never demonstrated, the post says.

That gap recurs throughout the investigation. LG encrypts its connections with HTTPS, so the Wireshark captures shown expose little beyond DNS requests and endpoint names such as LG Telemetry and LG Channels Telemetry. Wendell of Level1Techs — one of three outside experts consulted, alongside MrBruh and U-Turn, both of whom GamersNexus has previously covered — acknowledges on camera that decrypting the payloads would require a man-in-the-middle setup. Without it, call counts and request sizes establish frequency, not content.

The claims that partially hold up

One finding the author concedes has substance concerns LG's FAST-channel streaming partner Amagi. The playout URLs embed an Amagi channel ID, the channel name (CNN US in the captured example) and a platform-region code, so anyone able to observe the lookups could infer which channel was being watched and timestamp channel changes. Even here the author disputes the video's framing: on a switched network, another device cannot passively read a television's DNS requests without control of the router or ARP spoofing, and the leak stems from Amagi's URL scheme rather than LG alone, meaning other services built on Amagi behave the same way.

On automatic content recognition, MrBruh contends that ACR processing applied even to an HDMI input, citing a study shown in the video. The blog author read that study and found its researchers likewise could not decrypt the TV's payloads; whether HDMI fingerprinting actually occurs remains an open question the study itself flags for future work.

Why it matters

The disagreement is less about whether smart TVs deserve scrutiny — ACR fingerprinting and advertising telemetry are longstanding, well-documented concerns — than about what encrypted traffic can prove. Endpoint counts and DNS logs show that a television communicates with advertising infrastructure, not what it transmits, and presenting routine IoT discovery as surveillance makes legitimate criticism easier to dismiss. For owners, the episode is sobering either way: because the set's traffic is encrypted, ordinary users have no practical way to audit what their television sends, and the strongest confirmed finding — voice queries stored in readable logs on the device itself — is reason enough to treat built-in microphones and voice search with caution.

  • #smart-tv
  • #security
  • #privacy
  • #lg
  • #webos

Related posts