Never connect a smart TV to the internet. Use it as a dumb screen with your choice of media device.
K0balt 42 minutes ago [-]
It’s been a couple of years but there was some thing about a p2p link between televisions that allowed c&c / exfil even on some brand of televisions that weren’t hooked up to the internet if they were within range of ones that were… so even that might not be enough.
Edit: it was Samsung, where Wi-Fi Direct was always-on, and concurrent with STA mode wifi, enabling other WiFi direct devices potentially to connect to the internet, including other Samsung televisions. Their televisions were also hacked to gain root over a standard DVB broadcast on fully patched firmware lol so it might be possible to pwn a whole city at a time through that vector.
Smart-TV platforms have long done cross-device identification, and there have been some surprisingly aggressive local-device discovery schemes.
In all, smart devices are pretty much surveillance devices, and a privacy nightmare. I have had enough exposure to shady goings on that I am nearly certain that most devices ship with intentional backdoors sold to three letter agencies or malware rings, either by unscrupulous engineers or by the company itself.
It’s just hard to pass on the payday that a wide deployment of a permanent relay/mic/camera/sniffer represents, especially if it’s likely to end up in corporate or industrial environments.
I’ve had speculative offers to compromise smaller projects, and I’m nobody. I have no doubt that engineers working on widely deployed projects and systems are given very attractive offers to provide tailored access.
goda90 29 minutes ago [-]
We all need to live in Faraday cages now.
rationalist 33 minutes ago [-]
Another user on HN that reported that their guest connected their TV to the guest's phone hotspot to watch Netflix.
So you have to go a step further and remove the Wi-Fi card, because there is no guarantee that someone else won't connect the TV to the Internet.
Vineetyadav2 3 hours ago [-]
are they also doing the meta thing like the algorithms and all
Edit: it was Samsung, where Wi-Fi Direct was always-on, and concurrent with STA mode wifi, enabling other WiFi direct devices potentially to connect to the internet, including other Samsung televisions. Their televisions were also hacked to gain root over a standard DVB broadcast on fully patched firmware lol so it might be possible to pwn a whole city at a time through that vector.
Smart-TV platforms have long done cross-device identification, and there have been some surprisingly aggressive local-device discovery schemes.
In all, smart devices are pretty much surveillance devices, and a privacy nightmare. I have had enough exposure to shady goings on that I am nearly certain that most devices ship with intentional backdoors sold to three letter agencies or malware rings, either by unscrupulous engineers or by the company itself.
It’s just hard to pass on the payday that a wide deployment of a permanent relay/mic/camera/sniffer represents, especially if it’s likely to end up in corporate or industrial environments.
I’ve had speculative offers to compromise smaller projects, and I’m nobody. I have no doubt that engineers working on widely deployed projects and systems are given very attractive offers to provide tailored access.
So you have to go a step further and remove the Wi-Fi card, because there is no guarantee that someone else won't connect the TV to the Internet.