LG Electronics USA has announced a decisive move to suspend any applications built for its smart TVs that enable the transformation of a user’s television into an "always-on" residential proxy node, a development stemming from recent research that exposed a significant vulnerability in the webOS app ecosystem. This proactive stance comes less than a month after security firm Spur released findings indicating that over 42 percent of games and other applications available on LG’s webOS store allowed unknown third parties to reroute their internet traffic through unsuspecting users’ televisions, raising serious questions about data security and user privacy.

The research, initially highlighted on KrebsOnSecurity on July 2nd, delved into the alarming prevalence of residential proxy software development kits (SDKs) embedded within smart TV applications. Spur’s investigation revealed that not only did a substantial portion of LG’s webOS apps facilitate this proxy functionality, but also that over a quarter of apps designed for Samsung’s Tizen operating system exhibited similar components. These SDKs essentially turn a user’s smart TV into a relay point for internet traffic, unbeknownst to the primary user, potentially exposing their home network to various risks and compromising their online privacy.

In direct response to Spur’s compelling research, John Taylor, Senior Vice President at LG, communicated to KrebsOnSecurity that the company is actively collaborating with app developers to eliminate the residential proxy option from their applications on the webOS platform. Taylor emphasized that LG views a residential proxy network as an "unintended use" for its smart TVs and stressed that developers failing to comply with this directive will face the suspension of their applications. "LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor stated. "If this option is not removed, these apps will be suspended."

LG’s commitment to safeguarding its users extends beyond immediate action, with Taylor affirming the company’s dedication to preventing residential proxy networks from infiltrating its smart TV apps in the future. He confirmed that the company’s comprehensive review of existing applications is already "well underway." Elaborating on the company’s ongoing efforts, Taylor added, "As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs." This indicates a shift towards a more rigorous vetting process for all applications seeking a place on the LG smart TV platform, aiming to preemptively identify and block potentially harmful integrations.

LG to Ban Residential Proxies from Smart TV Apps

The monetization model behind these residential proxy SDKs involves app makers partnering with proxy providers. These providers compensate developers for embedding SDKs that effectively rent out the user’s device as a residential proxy node to paying customers. Spur’s research uncovered that these SDKs were bundled into a wide array of applications on LG and Samsung smart TVs, ranging from seemingly innocuous games like Pac-Man to essential utilities such as screensavers and file management tools. This widespread integration across diverse app categories highlights the pervasive nature of the issue and the potential for a large number of users to be unknowingly participating in these proxy networks.

Spur’s report specifically identified Bright Data as a dominant player in the residential proxy network space, accounting for a majority of the proxy SDKs found on both Samsung and LG smart TVs. In a statement provided to KrebsOnSecurity, Bright Data defended its practices, asserting that its network operates on principles of consent and responsibility and adheres to the terms set by LG and Samsung. "Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC," the company stated. "We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain."

Bright Data and other proxy providers implicated in Spur’s report maintain that they implement stringent "know your customer" (KYC) processes to verify the legitimacy of their service users, whose activities often involve content scraping. Furthermore, these companies claim to employ technological safeguards to prevent their proxy service customers from accessing or controlling other devices within the proxy user’s local network, a crucial measure to mitigate potential network-level threats.

However, Spur’s perspective offers a critical counterpoint, arguing that the fundamental issue lies not with the existence of residential proxy networks themselves, but with their seamless integration into devices that consumers do not typically perceive as computers and are ill-equipped to scrutinize. Trevor Sutter of Spur articulated this concern, stating, "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight." He further elaborated on the amplified risks: "The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors." This highlights the ethical quandary of obtaining consent from individuals who may not fully comprehend the implications or have the authority to grant such permissions.

LG’s decision to remove residential proxy SDKs from its app store is widely regarded as a positive step towards enhancing platform security and user privacy. Nevertheless, the company has recently faced scrutiny for a separate, albeit unrelated, questionable partnership. Earlier this week, the YouTube channel Gamers Nexus exposed that certain LG LCD monitors automatically install an application that promotes paid McAfee antivirus subscriptions. This installation occurs via Windows Update without requiring user approval, raising concerns about the transparency and user control over software bundled with hardware. This McAfee incident, coupled with the residential proxy issue, suggests a broader pattern of LG needing to re-evaluate its app and software integration strategies to prioritize user trust and security. The company’s commitment to strengthening its app evaluation process is therefore crucial for rebuilding and maintaining user confidence in its smart TV ecosystem and beyond. The implications of these decisions extend to the broader smart TV market, potentially setting a precedent for other manufacturers to address similar vulnerabilities and enhance their platform governance. The ongoing dialogue between manufacturers, security researchers, and app developers will be critical in shaping the future of secure and user-friendly smart home technology.