The discovery, detailed in Spur’s research published on July 2nd, highlighted a concerning trend across smart TV ecosystems. The investigation found that over 42 percent of apps downloadable on LG smart TVs were embedding residential proxy SDKs, effectively turning these devices into always-on proxy servers. This practice was also prevalent on Samsung’s Tizen operating system, with more than a quarter of its apps containing similar components. The implications of such widespread integration are far-reaching, potentially exposing users to security vulnerabilities and privacy risks without their full comprehension or explicit consent.

In an interview with KrebsOnSecurity, John Taylor, LG Senior Vice President, confirmed the company’s commitment to addressing this issue. He stated that LG is actively working with app developers to remove the residential proxy functionality from their webOS applications. Developers who fail to comply with this directive will face the suspension of their apps from the platform. Taylor emphasized that a residential proxy network is not an intended use for LG smart TVs and that the company is dedicated to preventing such functionalities from being integrated into its smart TV apps moving forward. He further elaborated that LG’s evaluation process for developer-submitted apps is being strengthened to include a more rigorous review of applications incorporating residential proxy SDKs, ensuring platform quality and an enhanced user experience.

Residential proxy networks operate by allowing app makers to monetize their creations. Developers can integrate SDKs provided by proxy companies, which, in exchange for a fee, enable users’ devices to act as proxy nodes. These nodes are then rented out to paying customers who can route their internet traffic through them. Spur’s research indicated that these proxy SDKs were being bundled into a wide array of applications, ranging from simple games like Pac-Man to screensavers and file utility applications. This broad integration means that users are often unknowingly participating in these proxy networks simply by using everyday applications on their smart TVs.

The security firm Spur’s report identified Bright Data as a dominant provider of residential proxy SDKs across both LG and Samsung smart TV platforms. In a statement to KrebsOnSecurity, Bright Data asserted that its network operates on a foundation of consent and responsibility, adhering to the terms set by LG and Samsung. The company claims that every peer user explicitly opts in through a dedicated screen and receives value in return for their participation. Furthermore, Bright Data stated that its customers undergo a vetting process, and its practices have undergone two independent audits by PwC. The company maintains its commitment to an open and transparent internet, facilitating responsible data access for legitimate businesses, researchers, and institutions.

LG to Ban Residential Proxies from Smart TV Apps

Bright Data and other proxy providers mentioned in Spur’s report consistently emphasize their adherence to stringent "know-your-customer" (KYC) processes to validate the legitimacy of their service users. These services are often utilized for content-scraping activities. The proxy companies also claim to implement technological safeguards to prevent customers from accessing or controlling other devices on the proxy user’s local network. However, Spur argues that the fundamental issue lies not with the existence of residential proxy networks but with their pervasive integration into devices that consumers do not typically consider computers and are not equipped to audit.

Trevor Sutter of Spur articulated a critical concern: "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight." He further highlighted the amplified risk when consent is obtained from individuals within a household who may not fully understand the implications, such as minors, who might inadvertently grant permission for their television to be used as a proxy node. The lack of clear, ongoing, and informed consent is a central tenet of the criticism leveled against the widespread use of these SDKs.

LG’s decisive action to remove residential proxy SDKs from its app store is a significant step towards safeguarding its users. However, this development comes shortly after LG faced criticism for another questionable partnership involving McAfee security products. Reports from the YouTube channel Gamers Nexus revealed that certain LG LCD monitors automatically install an application that promotes paid McAfee antivirus subscriptions. This installation occurs through Windows Update without an explicit user approval prompt, raising concerns about the transparency and user control over software installations on LG devices.

The situation with residential proxies on smart TVs underscores a growing challenge in the connected device landscape. As more everyday objects become internet-enabled, the potential for their misuse or exploitation increases. LG’s proactive stance on this issue, while commendable, also serves as a wake-up call for the entire smart TV industry and consumers alike to be more vigilant about the applications they install and the permissions they grant on their devices. The company’s commitment to strengthening its app review process is a positive development, but ongoing scrutiny and user education will be crucial in ensuring the continued security and privacy of smart TV users. The move also highlights the evolving landscape of app monetization and the ethical considerations that arise when user devices are leveraged for third-party services. The industry is now tasked with finding a balance between developer revenue streams and the paramount importance of consumer privacy and digital security.