In a significant move to bolster user privacy and security, LG Electronics USA announced this week its intention to prohibit applications on its smart TV platform that transform user televisions into persistent residential proxy nodes. This decisive action follows a recent exposé by the security firm Spur, which revealed a disturbing prevalence of such proxy software development kits (SDKs) within LG’s webOS app store. The research indicated that over 42% of available apps on LG smart TVs incorporated these SDKs, allowing unknown third parties to route their internet traffic through unsuspecting users’ televisions. This practice effectively turns home entertainment devices into always-on gateways for potentially illicit online activities, raising serious privacy and security concerns for consumers.

The revelation by Spur, detailed in a report published on July 2nd, sent ripples through the smart TV industry. The security firm’s in-depth analysis examined the widespread integration of residential proxy SDKs not only on LG’s webOS but also on Samsung’s Tizen operating system. Their findings indicated that more than a quarter of apps designed for Samsung’s Tizen OS also contained similar residential proxy functionalities. Residential proxy networks operate by allowing users to rent out their internet connection and IP address to others, who can then use it to browse the web anonymously or conduct various online activities. While legitimate uses for such services exist, their integration into smart TV apps, often without explicit and easily understandable user consent, presents a significant vulnerability.

In direct response to Spur’s findings and inquiries from KrebsOnSecurity, John Taylor, LG Senior Vice President, confirmed the company’s commitment to rectifying the situation. Taylor stated that LG is actively collaborating with app developers to remove the residential proxy functionality from their applications on the webOS platform. He unequivocally declared that any developer failing to comply with this directive will face the suspension of their apps. "A residential proxy network is not an intended use for LG smart TVs," Taylor emphasized in an email statement, underscoring the company’s stance against this unauthorized utilization of its devices. "LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended."

Taylor further elaborated on LG’s proactive approach, assuring that the company is dedicated to preventing residential proxy networks from being embedded in its smart TV apps moving forward. He confirmed that a thorough review of existing apps is already "well underway." LG’s commitment to enhancing platform quality and user experience extends to strengthening its evaluation processes for all developer-submitted applications. This includes a heightened focus on identifying and scrutinizing apps that incorporate residential proxy SDKs. This proactive stance signifies LG’s recognition of the potential risks associated with such SDKs and its determination to safeguard its users.

The monetization strategy for app makers often involves partnering with residential proxy providers. These providers compensate developers for integrating SDKs that transform users’ devices into proxy nodes, which are then rented out to paying customers. Spur’s research uncovered that these residential proxy SDKs were bundled with a wide array of applications on LG and Samsung smart TVs, ranging from simple games like Pac-Man to essential utilities such as screensavers and file managers. This broad integration highlights the pervasive nature of the issue and the diverse range of apps affected.

LG to Ban Residential Proxies from Smart TV Apps – Krebs on Security

The security firm’s report specifically identified Bright Data as the dominant residential proxy network, accounting for a significant majority of proxy SDKs found on both LG and Samsung smart TVs. In a statement provided to KrebsOnSecurity, Bright Data defended its practices, asserting that its network is built on consent and responsibility and operates in accordance with LG and Samsung’s terms. "Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC," the company stated. Bright Data further expressed its commitment to an "open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain."

Bright Data and other proxy providers named in Spur’s report maintain that they implement stringent know-your-customer (KYC) processes to verify the legitimacy of their service users, often linking their services to content-scraping activities. Additionally, these companies claim to employ technological safeguards to prevent customers of their proxy services from accessing or controlling other devices on the proxy user’s local network. However, critics argue that the mere existence of these safeguards does not fully mitigate the inherent risks, particularly when consent mechanisms are not robust or transparent enough.

Spur’s analysis emphasizes that the core of the problem lies not in the existence of residential proxy networks themselves, but in their widespread integration into devices that consumers do not typically perceive as computers and are ill-equipped to audit. Trevor Sutter of Spur articulated this concern, stating, "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight." He further highlighted the amplified risk when consent is provided by individuals within a household who may not fully understand the implications or are not authorized to grant such permissions, such as minors. The argument is that the current consent models are insufficient to protect vulnerable users.

LG’s decision to remove residential proxy SDKs from its app store is a welcome development, addressing a significant privacy and security loophole. However, this move comes shortly after the company faced criticism for a separate questionable partnership involving McAfee security products. Reports emerged this week, highlighted by the YouTube channel Gamers Nexus, detailing how certain LG LCD monitors automatically install an application promoting paid McAfee antivirus subscriptions. This installation occurs via Windows Update without any explicit user approval prompt, raising concerns about pre-installed software and potentially unsolicited promotional activities. This incident, while distinct from the proxy issue, points to a broader pattern of scrutinizing LG’s software practices and partnerships.

The update from Bright Data on July 22nd provides their perspective on the matter, underscoring the ongoing dialogue and differing viewpoints surrounding the integration of residential proxy technology in consumer devices. The situation highlights the complex interplay between app developer monetization strategies, the capabilities of residential proxy networks, and the imperative for consumer privacy and security in the ever-expanding landscape of connected devices. LG’s decisive action represents a crucial step towards mitigating these risks and restoring user confidence in their smart TV ecosystem.