Home appliance giant LG Electronics USA has announced a significant policy shift, declaring its intention to suspend any applications developed for its smart TVs that transform a user’s television into an always-on residential proxy node. This decisive move comes less than a month after a comprehensive study by security firm Spur revealed a disturbing prevalence of such functionality within LG’s webOS app store. The research indicated that over 42 percent of games and other applications available for download on LG’s platform allowed unknown third parties to reroute their internet traffic through unsuspecting users’ televisions. This finding paints a concerning picture of how personal devices, intended for entertainment, are being surreptitiously repurposed for potentially exploitative purposes.

The investigation by Spur, which was highlighted by KrebsOnSecurity on July 2nd, delved into the widespread integration of residential proxy software development kits (SDKs) within smart TV applications. Their findings were stark: a significant majority of apps on LG’s webOS platform harbored these SDKs, effectively turning televisions into persistent proxy nodes. Even Samsung’s Tizen operating system, another major player in the smart TV market, was found to have a substantial proportion of its apps (over a quarter) incorporating similar residential proxy components. This widespread adoption suggests a systemic monetization strategy employed by app developers, leveraging user devices without explicit, ongoing, and informed consent.

In direct response to the concerns raised by Spur’s research, John Taylor, LG’s Senior Vice President, communicated the company’s commitment to rectifying the situation. Speaking to KrebsOnSecurity, Taylor confirmed that LG is actively collaborating with app developers to eliminate the residential proxy functionality from their webOS applications. He issued a clear ultimatum: developers who fail to comply with this directive will face the suspension of their apps from the LG Content Store. "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor stated. "If this option is not removed, these apps will be suspended." This firm stance signals LG’s recognition of the security and privacy implications associated with these practices and its determination to protect its user base.

Taylor further emphasized LG’s ongoing commitment to preventing the proliferation of residential proxy networks within its smart TV ecosystem. He assured that the company’s review process for existing applications is already in full swing. "As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor elaborated in his emailed statement. This proactive approach suggests a long-term strategy to safeguard the integrity of the webOS platform and maintain user trust. The company’s commitment to a more rigorous app evaluation process is crucial for preventing future instances of this nature.

The practice of embedding residential proxy SDKs is often driven by a desire for app developers to monetize their creations. Proxy providers, in turn, compensate developers for integrating these SDKs, which then allow paying customers to route their internet traffic through the user’s device. This effectively turns the user’s smart TV into a rented IP address, potentially used for a variety of purposes, including web scraping, bypassing geo-restrictions, and even more illicit activities. Spur’s research revealed that these proxy SDKs were not confined to niche applications but were found bundled with seemingly innocuous software, ranging from classic games like Pac-Man to essential utilities like screensavers and file managers. This broad integration underscores the pervasive nature of the issue and the ease with which users could unknowingly participate in these proxy networks.

LG to Ban Residential Proxies from Smart TV Apps

The report by Spur identified Bright Data as a dominant player in the residential proxy market, accounting for a significant majority of the proxy SDKs found on both LG and Samsung smart TVs. In a statement provided to KrebsOnSecurity, Bright Data defended its operations, asserting that its network is founded on principles of consent and responsibility, and that it adheres to the terms of service set by LG and Samsung. "Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC," the company stated. "We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain." While Bright Data emphasizes user consent and rigorous vetting, the sheer volume of apps incorporating these SDKs, and the potentially unclear nature of the consent prompts within them, raises questions about the true extent of informed user participation.

Both Bright Data and other proxy providers mentioned in Spur’s report maintain that they implement stringent "know your customer" (KYC) processes to verify the legitimacy of their service users. These services are often utilized for content-scraping activities, where customers gather publicly available data from the internet. Furthermore, these proxy companies claim to employ technological safeguards designed to prevent their customers from accessing or controlling other devices on the proxy user’s local network. This is a critical point, as the potential for unauthorized access to a user’s home network is a significant security concern.

However, Spur’s perspective highlights that the fundamental issue is not the existence of residential proxy networks themselves, but their widespread and often inconspicuous integration into devices that consumers do not typically consider powerful computers and are not equipped to monitor for such activities. Trevor Sutter of Spur articulated this concern, stating, "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight." He further elaborated on the amplified risk: "The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors." This raises important ethical considerations about who has the authority to consent to such data-sharing practices within a household.

LG’s decision to actively remove residential proxy SDKs from its app store is a commendable step forward, particularly in light of recent scrutiny over another questionable partnership. The company recently faced criticism for its collaboration with McAfee, which involved the pre-installation of security software drivers via Windows Update on its high-end LCD monitors. This unsolicited installation, which occurred without explicit user approval prompts, sparked concerns about the transparency and user control offered by LG’s hardware. The Gamers Nexus YouTube channel brought this issue to light, demonstrating how certain LG LCD monitors automatically install an application that promotes paid McAfee antivirus subscriptions through Windows Update. This pattern of introducing third-party software without clear user consent, whether through app stores or operating system drivers, suggests a broader need for LG to re-evaluate its approach to partnerships and user privacy across its product lines.

Update, July 22, 1:06 p.m. ET: This report has been updated to include a statement from Bright Data, addressing the concerns raised by Spur’s research.