Summary Many smart TV apps include proxy SDKs that let third parties route web traffic through your home IP. Smart TVs are ideal hidden hosts: always online, static IPs, and unlikely to alert owners to background proxying. One-time prompts don't give real consent; review apps, remove unused, and reject vague 'bandwidth sharing' offers. Smart TVs have always been a slightly awkward compromise. We buy them for the screen, then spend the next several years dealing with accounts, app stores, software updates, and menus that seem determined to get between us and whatever we wanted to watch. All of that is annoying enough when the television is only collecting viewing data or pushing sponsored recommendations. Researchers have now found something much stranger: thousands of TV apps contained software that could turn the television into a residential proxy, letting someone else’s internet traffic leave through the owner’s home connection without most people having any idea it was happening. The harmless app on your TV may be doing more A simple television game can quietly become network infrastructure Security firm Spur examined 6,038 apps distributed through LG’s webOS and Samsung’s Tizen platforms and found residential proxy software in 2,058 of them. More than 42% of the LG apps it scanned contained one of these software development kits, along with more than a quarter of the Samsung apps. That’s not a small handful of obviously shady utilities buried at the bottom of an app store. The software showed up in games, clocks, screensavers, cooking apps, file tools, and other downloads that sound harmless enough to install once and forget about. A residential proxy allows a customer to send web traffic through an internet connection in someone’s home. To the site receiving that traffic, the request appears to come from an ordinary household IP address rather than a VPN, cloud server, or obvious automation platform. There are legitimate reasons companies might want that, including checking regional prices or seeing how a website behaves from another location. There are also plenty of less reassuring uses, such as account abuse, aggressive scraping, advertising fraud, or any other activity that works better when it looks like a normal person browsing from a normal house. The person sitting in front of the television usually isn’t installing anything labeled as a proxy service. Instead, proxy companies pay app developers to include their software as another way to make money from free apps. Some apps reportedly gave users a choice between accepting advertisements and allowing the connection to be used for web indexing. That may technically count as disclosure, but it’s not hard to imagine someone pressing the button that removes ads and moving on without realizing the app may keep using the connection long after the game or screensaver has disappeared from the screen. They remain online for years without attracting much attention A phone that suddenly chews through battery life or mobile data usually gets noticed. A computer may show a strange startup process, an unexplained fan ramp, or an application using more bandwidth than it should. A television doesn’t give you many of those clues. It sits plugged in, connected to Wi-Fi, and mostly ignored whenever nobody is actively watching it. That makes a smart TV an unusually convenient place to run this sort of software. It has a stable home IP address, constant power, and a permanent place inside the network, but it rarely gets the same attention as a laptop or desktop. Even people who are comfortable troubleshooting computers probably aren’t regularly checking which domains their television contacts in the background. Doing that properly can mean looking at router logs, DNS queries, or network monitoring tools, which is a lot of work to find out whether a clock app is behaving itself. Its position inside the home network makes the situation more uncomfortable. Spur found that the proxy software could open connections requested by remote infrastructure, while protection against access to private network addresses depended on each provider’s own filtering and controls. Some of the examined software included blocklists for local addresses, while other samples didn’t show the same sort of protection. That doesn’t prove someone could immediately reach your NAS, printer, or security cameras through the TV. Still, it does mean the setup’s safety depended on controls the homeowner couldn’t see, inspect, or manage. The proxy companies say users agreed to participate Residential proxies have legitimate uses and several stated safeguards Not every app involved here fits the usual definition of malware. Bright Data, which Spur identified as the largest proxy provider represented in the scanned apps, says users opt in through a dedicated screen and receive something in return. The company also says it vets customers and has subjected its practices to independent review. Other providers have pointed to identity checks, traffic restrictions, monitoring systems, and filters meant to stop customers from reaching devices on the local network. Residential proxy services aren’t automatically malicious, either. Researchers, journalists, fraud teams, and businesses sometimes need to see how a public website behaves from a particular region or from a residential connection. A company might use one to verify advertising placement, compare search results, or check whether a price changes based on location. There’s room for a legitimate service here, and an informed adult could reasonably decide that trading a small amount of bandwidth for an ad-free app is worth it. It’s also fair to point out that developers were working inside app stores operated by LG and Samsung. Those platforms reviewed submissions, published the apps, and apparently didn’t ban this kind of proxy functionality at the time. A developer looking for a way to support a free app could have viewed the SDK as another approved monetization tool rather than something forbidden. LG changing its rules now doesn’t necessarily mean every developer involved was deliberately trying to deceive users. A one-time prompt still does not create meaningful consent The household accepts risks it cannot properly evaluate beforehand The problem is that pressing “accept” doesn’t mean much when the person holding the remote can’t realistically evaluate what they’re agreeing to. Most people understand the bargain behind an advertisement because they’ve seen it thousands of times. A residential proxy is different. The real risk depends on who buys access, what traffic they send, how the provider screens customers, whether local network protections work, and what happens when any of those safeguards fail. That’s far too much to squeeze into a short television prompt. A user may understand that the app will “use bandwidth” without realizing that an outside customer’s requests could appear to come from the household’s public IP address. They may not know that the activity could continue in the background after the visible app is closed. They also have no practical way to audit the service afterward, which leaves them trusting several companies they may not even know are involved. Be cautious when a smart TV app offers to remove ads in exchange for “bandwidth sharing,” “web indexing,” or vaguely described network access. That choice may allow third-party traffic to pass through your home internet connection, even after you close the app. Review who installed the app, remove anything you no longer use, and don’t approve the prompt unless you fully understand what the service does. There’s also no guarantee that the person giving consent owns the connection. A child could install a game, a guest could explore the app store, or another person in the house could choose the ad-free option without thinking much about it. The internet bill and public IP address still belong to the account holder, who may never see the prompt at all. Consent becomes pretty flimsy when one person can approve a service that affects the entire household and the decision may never appear again. "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight,” Spur’s Trevor Sutter wrote. “The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors." LG’s response is necessary, but it arrived far too late App store review should catch this before researchers do LG says residential proxy networks aren’t an intended use for its televisions and that apps failing to remove the functionality will be suspended from webOS. That’s the right response, and it should reduce the number of apps using this business model on LG televisions. It also raises an obvious question, though. How did the software spread through so many apps before the platform decided it didn’t belong there? App stores are supposed to carry some of the security burden for devices that ordinary users can’t easily inspect. Nobody should need a network monitoring setup to decide whether a basic screensaver is safe to leave installed. The television owner can read reviews, look at permissions, and avoid obviously suspicious apps, but that only goes so far when the questionable behavior comes from an SDK buried inside otherwise ordinary software. At that point, the platform operator is one of the only parties with enough visibility to catch the pattern. LG’s rule change also doesn’t solve the broader problem with smart TV software. Proxy SDKs are only one way developers and platforms can extract value from a device after it has been sold. Tracking systems, advertising frameworks, recommendation engines, and background services are already common, and most of them are difficult for users to understand or disable completely. Removing residential proxies is worthwhile, but it doesn’t make the rest of the software stack suddenly transparent. Smart TV owners should treat app stores more cautiously This research doesn’t mean every LG or Samsung television has been used as a proxy server. The proxy software had to be present in an installed app, and participation generally had to be enabled through the app’s own process. Still, it’s worth reviewing what’s installed, deleting games or utilities nobody uses anymore, and paying closer attention to any prompt that offers fewer ads in exchange for vaguely described network access. People who don’t use their television’s built-in apps may also be better off disconnecting it from the internet and relying on a separate streaming device instead. The larger issue is that a smart TV is still a computer, even when the interface tries hard to make it feel like an appliance. It runs third-party software, stays connected for years, and sits inside a network full of devices that may contain far more valuable data. Homeowners shouldn’t have to assume that a cooking app or idle screensaver might be reselling access to their connection. LG’s ban is a useful correction, but the fact that researchers had to uncover the practice in the first place is a reminder that the software behind the screen deserves much more scrutiny than most of us give it. LG C4 Smart TV $1248 $2700 Save $1452 The LG C4 offers great picture quality and a vast collection of apps to enhance your experience.
That innocent-looking game on your smart TV might be quietly routing someone else's internet traffic through your home
Full Article
Original Source
Read the full article at Xda-developers →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.