In a significant move to bolster user privacy and network security, LG Electronics USA has announced its intention to suspend all applications on its webOS smart TV platform that facilitate the transformation of a user’s television into an always-on residential proxy node. This decisive action comes in the wake of alarming research revealing that over 42% of apps available on LG’s webOS store were found to incorporate software development kits (SDKs) enabling unknown third parties to reroute their internet traffic through unsuspecting users’ televisions. The move underscores a growing industry concern over the potential misuse of smart devices for covert data routing and network exploitation.
The investigation, spearheaded by the cybersecurity firm Spur, highlighted the widespread prevalence of residential proxy SDKs not only on LG’s smart TVs but also on Samsung’s Tizen OS. Spur’s findings, initially published on July 2nd and subsequently detailed in a report, indicated that more than a quarter of apps on Samsung’s platform also contained similar proxy functionalities. This widespread integration of residential proxy SDKs, often bundled with seemingly innocuous applications like games, screensavers, and utility tools, raised serious questions about user consent and the potential security implications for millions of households.
Responding directly to Spur’s research, John Taylor, LG Senior Vice President, confirmed the company’s commitment to eradicating this practice. "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor stated in an interview with KrebsOnSecurity. He further emphasized the enforceability of this policy, declaring, "If this option is not removed, these apps will be suspended." LG’s proactive stance signifies a strong dedication to safeguarding its user base and maintaining the integrity of its smart TV ecosystem.
Taylor elaborated on LG’s ongoing efforts, assuring that the company’s review of existing applications is "well underway now." He reiterated LG’s commitment to preventing the inclusion of residential proxy networks in future app submissions, stating, "As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs." This enhanced evaluation process is crucial for preventing similar vulnerabilities from emerging in the future and ensuring a more secure environment for LG smart TV users.

The monetization model that fuels the integration of residential proxy SDKs involves app developers partnering with proxy providers. These providers compensate developers for embedding their SDKs, which then allow paying customers to utilize the user’s device as a residential proxy node. This essentially means that the user’s IP address and internet connection become a gateway for other users’ online activities, often for purposes such as web scraping or circumventing geo-restrictions. Spur’s research identified the residential proxy network Bright Data as being a significant contributor to the prevalence of these SDKs across both LG and Samsung smart TV platforms.
In response to the allegations, Bright Data issued a statement to KrebsOnSecurity, asserting that its network operates on principles of consent and responsibility, and that its practices adhere to the terms set by LG and Samsung. "Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC," the statement read. "We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain." Bright Data emphasized its commitment to rigorous know-your-customer processes and technological safeguards designed to prevent proxy service customers from interacting with or controlling other devices on a user’s local network.
While proxy providers like Bright Data maintain that their services are used responsibly and with user consent, critics like Spur argue that the fundamental issue lies in the scale and nature of their deployment. Spur’s Trevor Sutter contended that "a one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight." He further highlighted the amplified risk when consent is obtained from individuals within a household who may not fully understand the implications, such as minors, or who may not have the authority to grant such permissions. The concern is that consumers often do not perceive their smart TVs as full-fledged computers capable of being exploited in such ways, making them less likely to scrutinize app permissions.
LG’s decision to ban residential proxy SDKs is a positive development for user privacy and network security. However, this move comes amidst scrutiny over another controversial partnership involving LG. Recently, the YouTube channel Gamers Nexus exposed that certain LG high-end LCD monitors were automatically installing an application that promotes paid McAfee antivirus subscriptions. This installation occurs via Windows Update without explicit user approval, raising concerns about unsolicited software distribution and the bundling of security products without clear user consent. This incident, separate from the smart TV proxy issue, further casts a shadow on LG’s practices regarding software integration and user transparency across its product lines.
The implications of LG’s ban on residential proxies extend beyond its own platform. It sets a precedent for other smart TV manufacturers and could influence app developers to reconsider their monetization strategies. The widespread integration of proxy SDKs in smart home devices presents a complex challenge, balancing the desire for app developer revenue with the paramount need for user privacy and network security. As the internet of things continues to expand, ensuring robust security measures and transparent user consent mechanisms will be critical in building and maintaining consumer trust. The ongoing efforts by companies like LG to address these vulnerabilities are a step in the right direction, but continuous vigilance and proactive security measures will be essential to navigating the evolving landscape of smart device security. The industry’s response to such findings will shape the future of smart device ecosystems and the trust users place in them.

