LG Electronics USA is taking a decisive stand against the misuse of its smart TV platform, announcing plans to suspend any applications that transform user televisions into residential proxy nodes. This proactive measure comes in the wake of alarming research revealing that a significant portion of apps available on LG’s webOS store were found to be routing unknown third-party internet traffic through unsuspecting users’ TVs. The security firm Spur conducted an in-depth analysis, uncovering that over 42% of games and other applications on LG’s smart TV platform harbored these residential proxy capabilities. This widespread integration of proxy software development kits (SDKs) raises serious privacy and security concerns for consumers, turning their entertainment devices into unwitting participants in potentially opaque internet activities.
The findings by Spur, detailed in a report published on July 2nd, painted a stark picture of the smart TV app landscape. The firm’s research extended to Samsung’s Tizen operating system as well, where it discovered that more than a quarter of the available apps also contained similar residential proxy components. This prevalence suggests a broader industry trend where app developers are leveraging these SDKs as a monetization strategy, offering developers a financial incentive to embed them within their applications. Essentially, app makers are allowing residential proxy providers to rent out their users’ internet connections to paying customers. These customers, often businesses or researchers, utilize these proxies for various purposes, including web scraping and data collection, thereby anonymizing their online activities by appearing to originate from a residential IP address.
In response to KrebsOnSecurity’s inquiries regarding Spur’s findings, LG Senior Vice President John Taylor confirmed the company’s commitment to addressing this issue. Taylor stated that LG is actively collaborating with app developers to eliminate the residential proxy functionality from their webOS applications. He emphasized that a residential proxy network is not an intended use for LG smart TVs and that failure to comply with this directive will result in the suspension of offending applications. "If this option is not removed, these apps will be suspended," Taylor asserted, underscoring the seriousness of LG’s stance.
Taylor further elaborated on LG’s ongoing efforts to enhance the quality and user experience of its smart TV platform. He indicated that the company is committed to preventing residential proxy networks from being integrated into its smart TV apps moving forward. LG’s review of existing applications is described as "well underway now," with the company planning to strengthen its evaluation processes for all developer-submitted apps, particularly those incorporating residential proxy SDKs. This strengthened oversight aims to safeguard users from having their devices exploited without their full understanding or consent.
The monetization model for these residential proxy SDKs is relatively straightforward: proxy providers pay app developers to integrate their SDKs. These SDKs then enable the user’s device, in this case, an LG smart TV, to function as a proxy node. Paying customers can then route their internet traffic through these nodes, effectively masking their true origin. Spur’s investigation found these proxy SDKs embedded in a wide array of applications, ranging from simple games like Pac-Man and screensavers to essential file utility applications. This broad integration means that even casual users downloading seemingly innocuous apps could inadvertently be contributing to a residential proxy network.

The security firm’s report specifically highlighted the residential proxy network Bright Data as a dominant player, accounting for a significant majority of proxy SDKs found across both LG and Samsung smart TVs. In a statement provided to KrebsOnSecurity, Bright Data defended its practices, asserting that its network operates on principles of consent and responsibility and adheres to the terms set by LG and Samsung. The company claims that every user, or "peer," opts into the network through a dedicated consent screen and receives value in return for their participation. Furthermore, Bright Data states that all its customers undergo a vetting process, and its operations have been independently audited by PwC. "We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain," a Bright Data spokesperson stated.
Bright Data and other proxy providers named in Spur’s report maintain that they implement rigorous "know-your-customer" (KYC) processes to ensure the legitimacy of their customers’ usage. These uses are often associated with content-scraping activities. The proxy companies also claim to employ technological safeguards designed to prevent customers from accessing or controlling other devices on the user’s local network, a critical concern for home network security. This would include preventing the kind of local network exploitation that has been observed with other botnet activities.
However, Spur argues that the fundamental issue lies not with the existence of residential proxy networks, but with their pervasive integration into devices that consumers do not typically perceive as computers and are not equipped to audit. Trevor Sutter of Spur expressed concerns about the adequacy of user consent in this context. "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Sutter wrote. He further emphasized the amplified risk when consent is given by individuals within a household who may not fully comprehend the implications, such as minors who use the device but should not be making such decisions.
LG’s decision to ban residential proxy SDKs from its app store is a welcome development, reflecting a growing awareness of the potential for smart devices to be misused. However, this move comes shortly after LG faced criticism for another questionable partnership involving McAfee security products. Reports emerged earlier this week, highlighted by the YouTube channel Gamers Nexus, detailing how certain LG LCD monitors automatically install an application that promotes paid McAfee antivirus subscriptions. This installation reportedly occurs through Windows Update without requiring explicit user approval, raising further questions about LG’s approach to user consent and data privacy. The Gamers Nexus investigation pointed out that the McAfee app arrives via Windows Update, a method that typically bypasses explicit user permission prompts for third-party software installations, making it a less transparent and potentially intrusive user experience. This incident underscores a pattern where LG’s partnerships, while potentially offering benefits, have also raised concerns about user control and transparency. The company’s commitment to enhancing platform quality, as stated by John Taylor, will be tested by its ability to navigate these complex partnerships and ensure user trust moving forward. The evolving landscape of smart device functionality necessitates robust security measures and transparent user agreements, principles that LG appears to be increasingly embracing in response to industry scrutiny and user concerns. The company’s proactive stance on residential proxies signifies a step towards a more secure and user-centric smart TV ecosystem.

