I was pretty put off the first time this happened. That said, I don't even know if I looked through the settings to see if I could turn it off..
I was pretty put off the first time this happened. That said, I don't even know if I looked through the settings to see if I could turn it off..
It sends audio and/or video fingerprints (not frames, for privacy and bandwidth reasons), which are matched against a fingerprint database. Whatever people see on TV is usually 10 to 60 seconds behind the real live stream at the broadcaster (which is where the reference fingerprinting happens). GeoIP data can be used to roughly deduce where the TV is located, in order to better filter out false positives out of multiple matches (e.g. in the US where lots of programming on east/west side is just shifted by ~3 hours due to time difference).
Smart TV interfaces are almost uniformly worse than set top boxes (one or more of: bad UI, slow CPU, weird quirks, few updates) so you should avoid it anyway.
The current Apple TV (which I cite only because of familiarity) has a great UI, every major app, and robust HDMI-CEC support so you might never have to touch your TV’s remote again.
And Apple respects your privacy.
E.g. Some TVs will honor wifi off setting. Or alternatively setting the TV to use the Ethernet port.
Or if it needs something on the other end, set up old underclocked Raspberry Pi as a basic router/DHCP server that connects to nothing; power it with TV's USB port.
If you've got a fancy router, connect it to your network with a fixed IP and firewall deny all packets from/to its IP.
If you've got a fancy AP, set up an alternative SSID that connects to an unused VLAN or otherwise routes to nowhere.
(I'm almost astonished that advertising networks haven't switched to using raw IP addresses everywhere.)
The firewall has the same DNS block-lists as the Pi-Hole, but also has subscription lists of IPs to avoid. Most of those are spammers or malware, but can include whatever other category of malfeasance you desire.
With 5G, you will have the same problem. And I'd be very reluctant to buy anything stationary which has 5G connectivity.
I specifically bought a smart TV with Roku instead of whatever software Samsung/Sony is doing for these reasons.
And you really believe that?
Consider that even the most trivial thing that makes Apple look bad gets leaked. If Apple was selling your private information, it would have leaked long before now. Also their financial reports show no indication of revenues that could be associated with private information marketing.
And regarding Apple - I hear this "not their business model" argument often but I see zero real life reasons why it couldn't be but we wouldn't know it. It is like saying that "John only trades tomatoes, it is impossible to him to sell cucumbers, it is not his business model". How is even related, monster corporations have multiple divisions with multiple business models, one doesn't exclude another.
PS: this is for the sake of discussion. Personally I also tend to think that Apple collects much less data than FAGM, and there were experiments that indirectly support this theory. I'm thinking about moving to Apple ecosystem but it is rather costly and will cause vendorlock. Not an easy choice.
Yes, I think most people understand this and say "selling data" as shorthand (because, for a lot of people, it's a distinction without a difference).
Yeah, exactly for their users in China.
I was actually really pissed a while back because my in-laws were over and when I came home they told me "For some reason you hadn't connected your TV to the internet. We gave it your wifi password, and now it works!" Thanks. Now I have to change wifi passwords, and the power light on the TV constantly blinks because it thinks it should be connected to the internet, but isn't.
It all comes down to lack of transparency/oversight and the option to exercise control as an individual.
Breaking down the parent's post:
""" What's funny about this is that I think this is a legitimate and relatively non-evil use case. """ - parent is saying that fingerprinting so the advertisers know who saw the ads is legitimate and relatively non-evil.
It all comes down to lack of transparency/oversight and the option to exercise control as an individual. """ - parent acknowledges that not telling the user and not making it configurable can be problematic.
If you consider tracking an anonymous identifier for the purposes of better marketing "spying" then I think that's a stretch. Calling out TV in particular for it is a bit silly - it's simply everywhere.
"...without their consent and without telling them about it."
Yes they are. You opt in or out when you buy the TV. They tell you about it then. You can be like most people and not read the fine print, but then don't be all surprised when someone's pulling the wool over your eyes.
If information about me or my machines is being collected without my express informed consent, that counts as spying.
Also "anonymous identifier" is a bit of an oxymoron. If the identifier is unique, then anonymity is not part of the equation.
Eventually the marginal increase in profit is less than the marginal increase in adtech cost. I wouldn't be surprised if many industries passed that point years ago. There's probably a lot of hype and hubris disguising that fact, but someone's going to make a successful business case out of cheap, low-creepiness spray-and-pray advertising.
"Advertisers like ACR data because it provides second-by-second feedback on how their ads are performing. Nielsen provides its data in 15-minute blocks, so if viewers tuned out after the first ad in a pod, the advertiser has no way of knowing. And since IP addresses are included, companies like iSpot.tv and Data + Math are able to use that information to create multi-touch attribution ratings that help advertisers understand how certain ads and placements helped move viewers through the sales funnel, from seeing the ad, to googling the product to actually buying it. It’s a lengthy process that requires a lot of data and a lot of rigor, but it’s an excellent way to prove to marketers that TV advertising actually works."
https://www.inscape.tv/resources/why-acr-data-is-poised-to-b...
* in theory, as a civil matter, they could make you destroy any unlicensed copies, but they would have a hard time getting criminal charges pressed, as well as proving damages from watching a TV show from an unlicensed provider vs a licensed one
And I would guess it's only audio fingerprinting, rather than full video.
When I noticed my Roku TV was sending something to some remote analytics or tracking server every 30 seconds whenever it was turned on, I just blocked everything coming from it.
Eventually though I factory-reset it and didn't bother connecting it to the network at all. All the on-TV apps are junk and I'd rather just use an Apple TV (which sends it's own analytics, I know).
And GDPR only requires that you opt in. So when you sign into the TV for the first time, it gives you an opt in choice and many do it. The States is less regulated but will be soon.
Edit: Also, on your first point, ACR is generally a variation of fingerprinting technology. It wouldn't be sending entire screenshots of whatever is being displayed even if it's not broadcast content, at least not in any variation I've heard of. It was the idea of uploading the entire image that I was questioning before.
And I also don't think it's easy to escape the scope of GDPR. I'm just saying companies come up with ways of being "GDPR compliant" and they've done so.
> We don’t use pre-ticked boxes or any other type of default consent.
> We use clear, plain language that is easy to understand.
> We specify why we want the data and what we’re going to do with it.
> We give separate distinct (‘granular’) options to consent separately to different purposes and types of processing.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
These are of course just guidelines, but if you don't explicitly inform your users that you will be sending images of what's on the screen over the Internet, you are likely to get in trouble. (And no, a giant EULA-type wall of text probably wouldn't be sufficient)