LG Electronics USA has announced its intention to suspend any applications developed for its smart TVs that transform a user’s television into an always-on residential proxy node, a move that comes less than a month after researchers revealed that over 42% of apps available on LG’s webOS store enabled unknown third parties to route their internet traffic through users’ televisions. The security firm Spur, in research published on July 2nd, uncovered the pervasive presence of residential proxy software development kits (SDKs) within smart TV applications. Their findings indicated that a staggering 42% of apps available for download on LG smart TVs incorporate SDKs that effectively turn the television into a perpetual proxy node. Furthermore, over a quarter of applications designed for Samsung’s Tizen operating system were found to contain similar residential proxy functionalities.

In response to these alarming revelations, LG Senior Vice President John Taylor confirmed to KrebsOnSecurity that the company is actively collaborating with app developers to eliminate the residential proxy option from their webOS platform applications. Taylor unequivocally stated that apps failing to comply with this directive will face suspension, emphasizing that "A residential proxy network is not an intended use for LG smart TVs." He further elaborated that LG is committed to preventing the integration of residential proxy networks into its smart TV applications moving forward, and that the company’s app review process is already "well underway." Taylor assured that LG will continue to strengthen its evaluation procedures for developer-submitted apps, including those that utilize residential proxy SDKs, as part of its ongoing commitment to enhancing platform quality and user experience.

The monetization strategies employed by app developers can sometimes involve partnering with residential proxy providers. These providers compensate developers for integrating SDKs that effectively transform user devices into residential proxy nodes, which are then rented out to paying customers. Spur’s investigation revealed that residential proxy SDKs were embedded in a wide array of applications on both LG and Samsung smart TVs, ranging from simple games like Pac-Man to screensavers and utility applications.

The residential proxy network Bright Data was identified as the primary provider of these proxy SDKs across both Samsung and LG smart TVs. In a statement provided to KrebsOnSecurity, Bright Data asserted that its network operates on principles of consent and responsibility, and that its practices are compliant with LG and Samsung’s terms of service. A spokesperson for Bright Data stated, "Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC." They further expressed their commitment to an open and transparent internet, enabling legitimate businesses, researchers, and institutions to responsibly access publicly available data.

LG to Ban Residential Proxies from Smart TV Apps – Krebs on Security

Bright Data and other proxy providers mentioned in Spur’s report maintain that they adhere to rigorous know-your-customer processes to verify the legitimacy of their service users, with a significant portion of their clientele engaged in content-scraping activities. These proxy companies also claim to implement technological safeguards to prevent customers of their proxy services from interacting with or controlling other devices on the proxy user’s local network.

However, Spur argues that the fundamental issue lies not with the existence of residential proxy networks, but with their widespread integration into devices that consumers do not typically perceive as computers and are ill-equipped to scrutinize. Trevor Sutter of Spur articulated this concern, stating, "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight." He highlighted the amplified risk when consent is obtained from individuals within a household who may not fully comprehend the implications, such as minors.

LG’s decision to purge residential proxy SDKs from its app store is a commendable step. However, the company has recently faced criticism for a separate, questionable partnership involving the pre-installation of McAfee security products through software drivers included in its high-end LCD monitors. Earlier this week, the YouTube channel Gamers Nexus demonstrated that certain LG LCD monitors automatically install an application promoting paid McAfee antivirus subscriptions, which is delivered via Windows Update without requiring user approval.

Update, July 22, 1:06 p.m. ET: A statement from Bright Data has been incorporated into this report.