Ransomware Spreading onto Smart TVs, Is a Pain to Fix
consumerist.com
consumerist.com
The screen should be the screen. It you want to make it smart, plug in a Fire Stick, Chromecast, Apple TV or roll your own with Kodi and a Raspi.
This is getting stupid. Its to the point that I bought one of these(1) and neutered an older smart TV that we had by replacing its "motherboard" just so it would act as a simple screen.
(1) http://www.ebay.com/itm/Universal-V29-LCD-Controller-Motherb...
For example, to get 4k content on your TV, you must have one of a small list of devices that the content provider supports ... most of which are smart TVs. For example, you can't watch Netflix 4K through a computer with a 4k capable graphics card.
So the misguided and dumb concept of a "smart TV" is being forced on us.
You also must deal with the back light. Mine was modern, so easy. Just a 12 volt led. If it's an old cold cathode, you need a separate high voltage driver. I'd let a screen like that go. You've got better things to do...
I glammed mine up by 3d printing a new little plate for the back to match my new board but that's not necessary.
Where did you get the firmware from, by the way?
https://sites.google.com/site/lcd4hobby/5-lcd-as-pc-hdmi-av-...
So three years from now, whatever the new iPhone does with CarPlay it will still work in my car, only I'll get the updated features. iOS 10 improved CarPlay in a number of ways, and I expect that to continue. And since the head unit side doesn't have to change the car can't hold it back.
What I can see changing over the years is the phones being able to stream data from the cars sensors, making things like Automatic a thing of the past. It would be really nice if my car could report gas mileage to my phone and the phone be able to do whatever with it.
How did you know what LCD controller to get? Any pointers for my next TV purchase?
Btw, from an application developers perspective it gets even better. For example Samsung locks down the application store updates after one year for each SmartTV models. So right now, SmartTV app developers aren't allowed to update ANY applications for 2015 and olders models of Samsung TVs. At all! When 2017 lineup comes in a month or so, all current Samsung SmartTVs will stop receiving app updates as well.
So your applications WILL stop working and start rotting after a year or so after you buy their TV.
It's actually quite easy to buy a "dumb" screen and those dumb screens just happen to also be the nicest, longest lasting, physically tough screens you can buy.
I am speaking of commercial displays which are produced by all of the major manufacturers.
You know, airport displays.
They are fantastic displays, they typically have very, very small bezels (even if they aren't displaywall displays) and they are as dumb as dumb can be.
I highly recommend a commercial/signage display.
That doesn't seem to be true. My 3 yo Samsung TV is still getting app updates and my 5 yo Blueray player (with the same software) is also still getting app updates.
There's still a commercial/industrial market segment that manufacturers target (digital signage, hospitality/hospital TV systems, etc).
The TVs produced for those segments are either dumb, or give the owner control over the device.
This mediocrity must stop.
Also several manufacturers (I know of some Samsung versions and Phillips) will position web services in first-level UX navigation making those TVs annoying to use as dumb TVs. There are even some models that will constantly nag you to connect them to the internet!
There's bunch of places between the video source and you that add their own buffers (not to mention the actual I-frame issues). Usually the most critical are encoders themselves (need to generate closed GOPs and a lot of commercial expensive hardware stuff doesn't give you enough control) and the player software on STBs (those usually have large buffers pre-set).
In the end it's rather large amount of work most IPTV (and digital cable) providers don't care about because... hey... where are you gonna go if you're unhappy with their service? :)
I presume the TV hides that by always taking the same amount of time to change stations.
On the other hand, I have an LG. It's "smart" but it starts up instantly and has no trouble with UX.
Lo and behold every few months something would happen which would make it clear that it was connected to the internet. I'd get banner ads. I'd get notices from the mothership about important updates. That sort of thing. Each time I'd discover that the wifi was back on and each time they'd have hidden how to remove it somewhere else.
Eventually I just changed my wifi password and that seemed to have done the trick.
Everything else is handled by the Internet connected Amazon Fire TV stick I plug into it. It is effectively a dumb TV and will not get infected by malware.
That's one thing that never happened to me with a (truly) dumb TV and I've only owned this one for a month. I sure hope the CPU hardware running this OS doesn't degrade as quickly as normal consumer PC hardware and I can expect it to run as quick and reliably as it does now in ten years from now (like the TV it replaced did).
http://boingboing.net/2016/11/09/a-lightbulb-worm-could-take...
I would agree odds are low of something that insidious... but it's hard to say "it'd be impossible for my TV to get hacked" when even light bulbs are getting attacked.
Although with the way I've got my house wired, HDMI over Ethernet would be more useful.
That's one of reasons why I'll hold to my 109cm Samsung plasma TV for as long as I'll possibly can. That and the fact that it's way better at watching (artistic) movies than any LED-based TV sets.
https://firmwaresecurity.com/2016/12/12/monitordarkly-dell-m...
1. Buy a smart TV
2. Don't connect it to your Wi-Fi
3. Buy a Chromecast
However, I do think there needs to be some serious financial penalties for companies like LG, Samsung, D-Link, etc., who ship flagrantly insecure firmware that in many cases is uneccessary, is almost never supported for anything like the realistic lifetime of the device, and where it is clear to anyone with industry expertise that they have demonstrated a negligent lack of basic competency.
For example, back in 2007 it might have been acceptable to store passwords as salted MD5. Nowadays, not good enough. Any hardware made competently then might have used a salted MD5 password store. Fine. But really, patches should be provided for at leat 10 years and those patches should bring firmware into line with the current state of the art. Thus I think it would be reasonable to sue a hardware manufacturer for a device made in 2007, still in service in 2017, which cannot be updated to have better password security than salted MD5.
It of course goes without saying that things like default passwords (admin:admin etc) should be considered outright unacceptable in any network-enabled consumer device.
Obviously we can't hold device manufacturers liable forever, nor can we expect NSA-proof levels of security, but I think it is reasonable to hold all hardware to a standard of "basic competency" for at least 10 years from the date of manufacture. The standard warranty period of 1-2 years is not sufficient.
There is at the moment a serious risk/reward imbalance where it makes financial sense to ship "features" (even if nobody asked for them) at the expense of security, because the subsequent issues are someone else's problem. This is bad for device owners and bad for society as a whole, since compromised devices are commonly used for DDOS attacks, sharing child porn, etc.
If device manufacturers knew there were serious financial consequences and that all features must be kept secure for 10+ years, they would certainly be more interested in making things modular and reducing potential attack surface areas than they are now.
Consumers cannot and will not do that. It takes time, it takes money, and a company can drag it on forever and just exhaust you financially or psychologically. IMO the justice system's rules on "citizen vs. company" needs an overhaul, badly, for quite a long time now.
I should be able to call Samsung in court and have my interests protected in one week. Does this happen right now? No. I can't see any hope for the future in this regard.
There's no real punishment for companies being sloppy. One might think the capitalistic market would auto-correct things by people flocking to competitors, right? But I find this to not be the case; as you and others in this thread have pointed out, it's becoming harder and harder to buy non-smart TVs. Every OEM seems to be in the same dirty bed with everybody else, and the poor security becomes more and more excusable by "but everybody else does it too!" with each passing day. And we as consumers practically have no choice. You want the best picture quality on the market? Sorry, it comes with a lot of software (requiring internet connection) that you never asked for and you won't ever need.
Furthermore, governments are by default awfully incompetent to help with issues like these. Even if we assume zero company lobbyists, most governments simply have no idea what is the problem at all, let alone take any measures. I hope I am wrong, though.
Sorry if this is too pessimistic but quite frankly, I can't see any reason for hope at this point.
Yeah... but large lawyer companies are more than willing to fight on the behalf of consumers doing class action lawsuits for the little guy. On the behalf of you and me.
As in, they be-having all the rewards after lawyer fees get paid on the win.
For reference, don't forget to get your $9 if you are a PS3 owner. (the situations aren't the same... but it is an example of "That's not worth it for 'individuals' to sue... but big company gets sued and loses anyways)
http://www.forbes.com/sites/davidthier/2016/06/22/lawsuit-so...
Which countries do they operate in?
Look up anything that happens to a group of people - PS3 features being removed, salmonella in food, Microsoft forcing updates on Windows 10, Samsung batteries exploding, etc.
Look for anything that's affected a lot of people... and then watch as a lawyer or group of lawyers kicks up a class action lawsuit.
https://topclassactions.com/lawsuit-settlements/open-lawsuit...
it's got Chromecast built in which has been great at my last party (would like to know how to bridge that to the guest network so I don't have to let users on the main network)
Kodi installed from the Play store and works pretty well. A few hd movie can't stream without skipping over the network from my nas but I can also plug in an hd directly to the TV as storage for Android.
Has built in DVR just add hd which I did and have been using to grab a few things.
Installed an Airplay app which seems to work. Have use it from both my phone and my Mac.
Netflix and YouTube work fine.
My original plan was to use it as a dumb TV and get a mac mini but Apple hadn't updated it in years. Thought about getting a NUC but so far it's doing everything I needed.
Was able to turn off all the ads by going to every app and turning off notifications.
It's supposedly going to get and Android 6 update soon so will see if still like it then.
Large parts are useless - Yahoo Profile that can't be removed for example. The app selection is limited compared to some of the bigger companies. It sucks that the Remote Buttons are hard coded to Xumo and iHeartRadio - which I'll never use and would LOVE to switch those to say Plex and Pandora which I do use...
But other than those issues, I've actually been rather impressed that most of the needs are met. Netflix, Pandora, Prime, Plex, Youtube. Logged into all the accounts and setup within an hour with shortcuts customized (except for on the remote and the Yahoo Profile that can't be removed).
Granted... I think we will switch to ChromeCast because that works for all our other TVs and for consistency sake... but given how much hate there is towards Smart TVs, I expected to hate the "Vizio OS" (or whatever it's called)... and actually kinda like it.
I wish we had a hardware switch on these TVs, something to alternate between an old screen-and-TV-mode-only, and a smart TV. Sigh.
Open operating systems can receive security updates by the community long after the manufacturer has lost their interest in the device.
Should it even be called a "Smart TV" if its hard to recover?
Up until now I haven't really cared, since I ignore all the smart TV junk and use my device anyway. But if it's going to start getting ransomwared no matter what I do... just let me buy a dumb TV.
It's not that it's hard, it's that it wasn't in the manual.
In the future this may change - at this point some Samsungs already overlay their ads on volume change UI (and some other parts) to get additional revenue. With such incentives, I'm worried just how long you'll be able to buy a TV that can function offline.
If you look at low end TVs you'll find the "useful life" limited more by the hardware than by the software. If the hardware can't do it, for instance, no H.265 decoding for you.
H.265 is generally only used for 4K content and 4K TVs carry decoders with them mostly.
https://wiki.samygo.tv/index.php5?title=Main_Page
http://openlgtv.org.ru/wiki/index.php/Main_Page
But they support AFAIK only a limited number of devices and also only some firmware versions (it seems like both Samsung and LG are attempting to close the doors).
Yes
> Open operating systems can receive security updates by the community long after the manufacturer has lost their interest in the device.
Yes
> Should it even be called a "Smart TV" if its hard to recover?
...? Yes.
More seriously, this is bad news for bitcoin. Governments will move in and require tracking of all transactions.
If governments move in, it's my understanding that it would be at the points of currency exchange.
(I also prefer the picture quality of my plasma TV over a projector... But that's personal preference. Too bad plasma went the way of the dodo)
I always cringe when I see this "simple solution" because A) I know so many people who don't even know that updating their TV is a "thing", and B) eventually we'll have more devices than we can keep track of, each requiring weekly updates.
Not only does this avoid malware/randomeare/becoming part of a botnet but it also avoids the stupid pop ups about "The terms and conditions [sobething you don't use, care about and probably didn't know existed] have changed. <OK|Cancel>".
If you're using DVRs, STBs, etc you're getting the same effect.
Connecting to the Internet gains you nothing.
Is it for having a monolithic assemblage of computer monitor plus one-way modem that only works for certain data content streams? Do people get substantial price discounts by going the monolithic route rather than buy these devices as separate interconnecting functions that can be independently sourced for specific features and conveniently upgraded? What exactly is motivating people to buy a TV other than being susceptible to advertising?
Obviously, I've never bought a TV hence asking this question. But I've had friends who buy them, and although I've inquired about their purchase decision making I've never received a reply other than "it was on sale last Black Friday."
Yes. Most people do not care to assemble their own little batch of boxes and cables just to make television happen. Most people would rather purchase a unit that makes video play in the living room, because their lives are filled with other things to do.
Never pay a ransom. Turn the request over to the government:
the government literally exists to assure rule of law.
If we were okay with a "might makes right" world, we wouldn't need government or the rule of law. The government literally exists so this stuff doesn't happen.
If you finance it, you're a criminal and a terrorist, and you are paying for them to infect me. You are literally paying for cyber attacks. Not metaphorically but in the most direct possible terms.
Don't do it. And if you're a criminal, don't develop it. I feel this is not being stated clearly enough these articles - the people developing it are obviously talented engineers: they could be using their skills constructively. It's important to make it very clear that what they're doing is wrong, and supporting them is wrong. This isn't an optional thing. They need to stop doing this, shut down their networks, and go do something constructive with their skills. It's people's duty to let them know this, and to report these things. It's a waste of everyone's time, especially theirs.
By the way it takes considerable intelligence and engineering skill to be technically able to hold for ransom a device at a distance. I am certain that these engineers are reading this comment.
I can easily consider that they did not even consider the ethical side in evaluating the list of requirements and completing them. Articles which don't call their attention to this don't help.
This isn't a nuisance: it's criminal behavior that needs to be reported to the government, and never, ever paid for or encouraged. My grandparent comment got downvoted heavily but I am keeping it. If you're a programmer who is doing this, stop.
Wow, that's the solution we need. Telling criminals to "stahp" being criminals.
And why it's so hard to get drugs. Because of all the laws that say "You're a bad person if you use Weed" and put people who deal with drugs into prison for their first offense.
All we need to do is expand that mindset and we'll have no hackers before we know it.
Full Disclosure: I'm the seller.