Smart TVs like Samsung, LG and Roku are tracking everything
washingtonpost.com
washingtonpost.com
I have about 400% more trust of Microsoft and Sony than I do of random smart tv manufacturers. I also have a fairly high degree of confidence that the xbox one and PS4 software will remain up to date with security patches, and address critical issues quickly. I have no confidence for TVs.
Microsoft and Sony have teams of lawyers who've drafted the data collection/data sharing/opt-out policies for what their current generation game consoles track and phone home about. I've seen entirely too many reports of "smart" TVs that start reporting your entire viewing habits, and/or displaying unwanted ads.
Use the TV as a dumb display and hook it up to a PS4, Xbox One, and/or home theatre PC.
And those TV boxes are 2-way obligate devices...
It should be noted Sony's TVs are different than their game consoles in what they collect and do. They run a relatively clean version of Android TV except for "Samba TV", which is yet another piece of show-recognizing (known as ACR) analytics. However, you can apparently decline its privacy policy on initial setup and even disable the APK entirely in settings[1]. (Some people also succeeded in ripping it and other bundled video apps out via ADB)
Even given all that, Sony TVs are probably still the tamest smart TVs out there.
> Don't give it your wifi key and don't put it on your LAN.
It entirely depends on manufacturer but I've heard of some actually seeking out open networks for internet access if you don't configure their Wi-Fi. Some people reported an unconnected TV suddenly prompted to update because the neighbour's wifi was unsecured. If you can, I'd set up a specific SSID with no LAN or WAN access just in case.
[1] https://www.consumerreports.org/privacy/how-to-turn-off-smar...
Though I doubt the companies would be ballsy enough to connect to unsecured networks, if that breaches laws in a country that the tv is sold it may have legal ramifications for the company.
Edit: then again my argument is based on logic and risk, not two factors marketing and sales teams consider very often..
[0] https://github.com/skorokithakis/catt/
[1] https://ytdl-org.github.io/youtube-dl/supportedsites.html
They probably will use 5G cellphone service eventually...
I can't wait until my microwave tells the manufacturer how often I'm reheating my pizza.
Also, it will be sold to the public as "verifying that you are using the fresh and genuine product".
I don't joke. I am a frequent reader of /r/shittykickstarters and it's a popular business model amongst these startup hardware products.
I recently did it and was stunned at the amount of phoning home from Roku, both telemetry and ads to serve.
After blocking the calls home with PiHole my Roku's performance also improved considerably
For streaming and playing media from my NAS I use an Nvidia SHIELD TV. It's based on the Tegra X1 so performance is on par with the Nintendo Switch. Really great bit of kit, and of course I can just chuck it out (or repurpose it as an emulator box) if it gets too annoying.
The article seems to say Vizio TVs are better for your privacy than other TVs. The article says Vizio TVs describe ARC in 100 words and people must select accept or decline.
That page you linked to says
>However, you can accept or decline Sony's Bravia privacy policy, as well as one for Samba TV, the ACR technology Sony uses. You have to scroll through the entire Bravia policy before you'll see the options for turning off various data-gathering features, including Sony Smart TV Services, Program Recommendations, Product Improvements, and Advertisements, as well as Samba TV.
This sounds like a harder process.
Vizio was the only company willing to have an employee be interviewed by The Washington Post. Samba didn't even reply to their emails.
My Marantz is connected to Internet though (used for AirPlay) as it needs updates to its firmware, so there might be some audiophile listening...
I have many Smart TVs, all working great as dumb monitors for my AppleTVs. I wouldn’t change a thing.
Immediately thought "works for me".
I wonder if any other manufacturer offers that choice.
Edit: commercial signage panels are about as close as you get to dumb TVs these days. Rarely include any smart features, can get in quite large sizes. Not OLED or anything but if you just want a decent display...
They're good with warranty returns, but usually can't give you a replacement product due to how they do batch/bulk sales and don't keep recurring stock, so you generally end up with a refund and have to start shopping around again for an equivalent product.
As for not connecting smart TVs to Wi-Fi I read in a recent HN comment [2] that theirs connected without consent automatically to the first available unsecured Wi-Fi it found, sometime later. Seems some TVs are being extra sneaky with this.
They are mainly aimed corporate buyers, I have one 42 inch TV and one small video wall (4x42 inch) from them.
This is a really weak trust based argument. Sony put rootkits on cds (different division of sony, but still). MS has been fighting their users forever now. Ultimately, none of these trust based arguments work. If you care about privacy, use kodi, new pipe etc. Don't try to pick overlords. That's a losing battle.
which are almost certainly also tracking everything.
In general i agree with your advice, and would rather keep smart TVs off my network. but if your goal is to not be tracked, plugging in an additional piece of hardware from another big tech co isn't going to accomplish that goal.
Also, fun fact, my cable boxes from Verizon also run Linux :P
It's consistently the top blocked client on my home network! Ott. Nielsenccdata.tv
In terms of undermining user ownership, MS has done more than most with help from Apple. I can get a different webmail provider and use a different search engine. Changing operating systems to Linux from one that actively fights you to run your computer for you is something else entirely.
Good luck getting a software update for a four-year-old smart TV running some obsolete version of Android. Or WebOS.
Xbox 360s are 12+ years old now and are still generally considered something that is safe to have on your home network, and not vulnerable to any known in the wild remote code execution.
Xbox one or PlayStation 4 has considerably lower chances of becoming a malicious, virus-infected device on my home network.
Xbox One X has excellent power efficiency, it is my preferred way to gaming as I'm extremely conscious about the power consumption of my devices; but Smart TVs do consume lesser power for what they do.
Even assuming the underlying premise is something like "we suspect this is pirated and here's a legitimate option", you're suggesting I leave a task I'm in the middle of... to perform the same task elsewhere?
I could see if they had the set turn on to a Wii-style menu and they had a box that said "Since you enjoyed watching Show XYZ, you may enjoy Service EFG, featuring XYZ and more", that could possibly convert, but the timing there is completely tone-deaf.
I’ve seen that behavior only on the one model that I was analyzing. Still, I assume it’s industry wide and even applicable to every/any IOT device.
Stop trusting companies. That's what got us in today's horror show of privacy invasion. Verify what you get and buy accordingly. Trust in corporations is something that's not required and is actively detrimental to society as a whole.
Those lawyers are looking out for MS and Sony, not you. Their job is to make sure everything is legal, not ethical.
I recently upgraded to a LG 4K OLED TV. It's an absolutely gorgeous TV, but, I absolutely lament the "smart" features of this TV. I get software update prompts on a regular basis for software I don't use (I'm sure there would be some for the base system anyway, but, an order of magnitude less). The prompts when setting up the TV to accept myriad EULAs are obnoxious. Pop-ups advertising "features" on my TV which I don't want? Ugh.
I really want either a manufacturer who resells these panels with 0 features, or a mode from LG which disables all of this. "Lock to HDMI1 and disable everything but color management features".
More on-topic with the article: I'm a pretty tech and legally-savvy guy, but, even I'm not sure I've toggled the correct order of knobs and declined the correct EULAs to disable that tracking. Moreover, I'm exactly 0% sure that someone else didn't try to watch Netflix (via the TV and not the AppleTV/Shield/PS4/etc) and wasn't prompted to accept EULAs to do that. My point is, if I can't even do this properly, normal people have a near 0% chance of disabling tracking.
That said, it's a fantastically gorgeous panel. I've had a lot of fun re-watching older favorite movies in 4K.
> block it on my home network with Pi-Hole
That's a really good idea. I just configured my firewall (Palo Alto) to block the TV, I'm not sure why I didn't think of that.
[1] https://www.reddit.com/r/privacy/comments/bpr6xs/if_you_choo...
My take on this is that we should impose the kind of draconian restrictions we have here in the UK on products like cigarettes. You can buy them, age restrictions permitting, but they are legally required to cover a large part of their packaging with prominent disclosures of the harm they cause. If devices with consumer-hostile measures like phone home functionality were similarly required to disclose it, and exactly what it is doing, on their packaging and other promotional materials, average consumers might start asking more questions instead of just the relatively small and so usually insignificant class of techie consumers. If that still didn't produce meaningful competition, outright prohibition by law might be the only solution.
But equally, maybe some people wouldn't be comfortable with, "This device contains a camera and microphone that are always on and an independent Internet connection that you cannot block. We cannot guarantee that the software in this device is 100% secure and we only guarantee to update that software for 12 months after the date of purchase. We do not control some online services used by this device and Internet-connected features of this device might break at any time with no way to fix them. There is a {regulator-imposed description/statistic} chance that someone will be able to hack your device, watch and listen to the area around it including other nearby rooms, and provide hackers with access to any other devices and activity on your home network. This device will upload information about what you watch and when to {names of business(es)}, which will use the data to profile you including guessing your family make-up, wealth, interests and vulnerability to advertising, and this information will be sold to {list of recipients} who may use it to {purposes}."
The experience with GDPR in the EU so far seems to have been that the clear elements were generally felt to be reasonable, and businesses that weren't doing shady things would already have been in compliance with most of them anyway. The problems with GDPR have more been around ambiguity and the unnecessary and sometimes disproportionate red tape imposed even on "good actors". It was a similar story with the slightly earlier update to EU consumer protection rules.
I don't see why we couldn't learn from experiences like those and develop a reasonable regulatory regime for devices with embedded sensors and/or connectivity.
No external connectivity? Nothing to disclose. External connectivity? Do you use a customer-defined network connection or establish your own (and if so, how)? What's your policy on providing security updates? What guaranteed minimum support period are you offering, and what will happen to the device past the end of that period? Maybe if you or any of your business's officers or controlling interests have been responsible for a serious breach in the past, you also have to disclose that with prominence that reflects the recency and severity of the failure, so being careless about security becomes a sticky and toxic label rather than just a lawsuit that is a cost of doing business.
Not depending on outside services? No need to disclose. Depending on outside services? You need to state a minimum period where you guarantee your device/functionality will keep working, whether each outside service is under your control, what identifiable data is changing hands, what will happen to the device if each external service is changed or discontinued, etc.
Not including any sensors of defined categories (camera, microphone, location, etc.)? No need to disclose. Including sensors? You need to state how to tell whether they are in use, whether you provide a physical switch to disable them that software can't override, what they are used for, whether any data they collect could be transferred off the device, etc.
I don't see anything unreasonable about this, because anyone making such devices is going to be spending considerable time and money to include those sensors, that connectivity, or that use of outside services, so there's no credible claim that they don't (or shouldn't) know exactly what is going on. Requiring a few lines of specific details to be provided in a standardised format under the sorts of specific conditions I mentioned above doesn't seem either unrealistic or disproportionate as we move into a world where more and more devices do come with some or all of these three liabilities.
Why? It's not like there are any real consequences for these companies when they screw up and either the data gets leaked or they're found to be lying.
It has zero smart stuff, and comes with an RS232 input for which documentation exists to control _everything_ remotely. I think the latter is due to it's brother being a 24/7 rated digital signage device, which typically implies remote management.
I'm passively looking for a newer model for a potential secondary setup on a different desk/location, but haven't stumbled on anything I'd prefer.
I got my current TV off the side of the road. It’s a 42” LCD Samsung, and that’s good enough for me.
The other point is that all these features are advertised on the box (Netflix, Alexa integration, etc) but you can't even use them unless you accept those EULA prompts.
In the UK, if my shield would show freeview TV channels I'd probably never need to leave the interface, and thus I'd be happy to lock a TV into a shield slave.
Unfortunately it just doesn't work like that for us over here though.
I’m using the shield exclusively for smart features and the OLED as a dumb display.
I never connected it to my network and never will.
It was a dark pattern during setup. The options were to connect via LAN or WIFI, and only by scrolling into "nothing" did a skip option appear.
This ImO is the only option and even then I bet it's trying to exhilarate data by like trying to connect to a phone or high frequency audio or something.Pretty sure my firetv phones my hdmi content home
Is it really all that difficult to envision a legitimate need for bugfixes on a "smart tv" containing so much software? These things are as much a computer as they are a display. And modern software development practices have veered far into the direction of "ship yesterday, finish tomorrow with updates."
I get very few notifications. Obviously, when app or firmware updates are available. I also get a small and brief notification when they add a new ip channel to their lineup. I get no ads or anything like that.
I've not run a sniffer to see what it phones home with beyond info for version checks.
It was the LG 65UH series from Costco.
What am I missing that makes HDMI cables doubling as ethernet cables a problem for blocking it from accessing the network?
You block the TV from accessing the network.
You connect the TV to a device that will let you stream Netflix, via HDMI.
The TV requests internet connectivity over HDMI through that device automatically.
Blocking the network access to the TV has now been worked around and no longer matters.
Also, for that massive premium, commercial displays often don't include HDR, HDMI features (CEC, ARC), and sometimes even 4k. They aren't a realistic solution.
I connected it to the network in order to watch netflix, and unchecked all tracking and advertising related EULAs. I'm also running a pihole on my network, so most third party ads will be denied from reaching the TV.
My parents had a TV with a built-in Skype app, and at some point the TV maker stopped supporting it. After that, every single time the TV was turned on the TV popped up a vague modal error message (that didn’t even mention Skype, just “an app” or something). I verified that it is impossible to turn off this message or do anything about it. Think about the stupidity.
For example, my Samsung has apps that can stream radio, and apps for Spotify and other music services.
But it evidently failed to occur to anyone at Samsung that since these are audio apps and do not need to use the screen while playing, I might want to blank the screen once I start the stream.
I'm particularly irked at Samsung because when I searched online to see how to blank the screen (I assumed it was obvious that they would include such a feature, and I was just being dimwitted when it came to finding it), I found that they used to have that feature, and they dropped it starting with the model year of my TV!
Their reaction to a proposal was, to put it kindly, terrifying and highly defensive. They said they are doing nothing wrong, no data has been leaked snd that there is no future for our solution, sensing huge discomfort.
Quite evident they have zero interest to gamble status quo on current situation.
https://gist.github.com/peteryates/b44b70d19ccd52f62d66cdd4b...
haven't had an update since, and not upset about that.
https://www.pcwrt.com/2018/08/how-to-use-your-router-to-bloc...
Pi-Hole has a nice GUI, but if you already have openwrt, dd-wrt or pfsense, you can likely just install packages.
The amount of mostly unintentional (by the user) data transfers is out of hand.
If your corporate site, where you advertise your new high-end TVs and laptops, starts triggering warnings in all your visitors' browsers that it might be associated with malware and falling off all the SERPs for similar reasons, you're going to stop loading it with junk pretty quickly (and its trust score will improve pretty quickly as a direct result). Likewise, if your smart device tries to phone home and home has acquired negative rep, maybe that connection gets blocked automatically at the firewall.
We'd need a system that was guided by interested/aware participants who are unlikely to be successfully gamed and that mostly "just worked" for average users, but we've managed to build those in other contexts before so it doesn't seem completely out of the question.
As long as they rely on your own network for their external connectivity, you can always firewall them (at the expense of any connected features you do want to use, perhaps, but then I suspect most of us would agree that 99% of those are junk in most smart TVs anyway and be OK with that limitation).
The problem comes when they can form their own connections, but in that case they're not under your control anyway, DoH or not.
More likely just looking at the title of the file and matching that against themoviedb.
This should not suffer from the same issue: http://archive.is/8Cm3Q
From the mouth of the CTO of Visio:
> So look, it’s not just about data collection. It’s about post-purchase monetization of the TV.
> This is a cutthroat industry. It’s a 6-percent margin industry, right? I mean, you know it’s pretty ruthless. You could say it’s self-inflicted, or you could say there’s a greater strategy going on here, and there is. The greater strategy is I really don’t need to make money off of the TV. I need to cover my cost.
> And then I need to make money off those TVs. They live in households for 6.9 years — the average lifetime of a Vizio TV is 6.9 years. You would probably be amazed at the number of people come up to me saying, “I love Vizio TVs, I have one” and it’s 11 years old. I’m like, “Dude, that’s not even full HD, that’s 720p.”
> But they do last a long time and our strategy — you’ve seen this with all of our software upgrades including AirPlay 2 and HomeKit — is that we want to make things backward compatible to those TVs. So we’re continuing to invest in those older TVs to bring them up to feature level comparison with the new TVs when there’s no hardware limitation that would otherwise prevent that.
> And the reason why we do that is there are ways to monetize that TV and data is one, but not only the only one. It’s sort of like a business of singles and doubles, it’s not home runs, right? You make a little money here, a little money there. You sell some movies, you sell some TV shows, you sell some ads, you know. It’s not really that different than The Verge website.
> Q: One sort of Verge-nerd meme that I hear in our comments or on Twitter is “I just want a dumb TV. I just want a panel with no smarts and I’ll figure it out on my own.” But it sounds like that lifetime monetization problem would prevent you from just making a dumb panel that you can sell to somebody.
> A: Well, it wouldn’t prevent us, to be honest with you. What it would do is, we’d collect a little bit more margin at retail to offset it. Again, it may be an aspirational goal to not have high margins on our TV business because I can make it up downstream. On the other hand, I’m actually aggregating that monetization across a large number of users, some of which opt out.
> It’s a blended revenue model where, in the end, Vizio succeeds, but you know, it’s not wholly dependent on things like data collection.
What would be great and much easier technically would be an (open, non-google) Chromecast clone that you can plug into a smart TV and then just not give the smart TV an internet connection.
That leads me to another guess: manufacturers can’t have people not connect their TVs. So they’ll start offering rebates that you only get if you plug your tv to the internet.
The Visio CTO has been open about it
https://www.theverge.com/2019/1/7/18172397/airplay-2-homekit...
Walmart represents a store that is easy to go to for much of the US population. That means a good percentage of people in the US are buying TVs at places that don't offer non-smart TVs for sale.
Too lazy? Shameless self promotion: https://windscribe.com/features/robert
Occasionally the out-of-the-box firmware on TVs can perform poorly on certain input modes, so it's nice to have an option to get the latest patches without opening yourself up to tracking and ads.
That said, the idea of a TV needing patches is thoroughly unappealing.
Also... what if they put a 5G SIM card inside the telly? Now that would suck.
And I don't see it coming. Older people don't even seem to care that Imo is secretly recording them as longs as they can videochat with their grandchildren. Younger people are just happy for their new shiny toys.
Examples:
https://wiki.samygo.tv/index.php?title=Main_Page
https://forum.xda-developers.com/web-os/general/rooting-webo...
And since Apple TV sort of means 5 to 6 different things [1], they might as well make an actual Apple TV set to make it even more complicated.
If there are two things that I think Apple should really do, are Wireless Router and TV. I dont want a Google Nest WiFi or Amazon Eero.
I've said it before, and I'll say it again, the way we prevent this is in right to repair legislation that includes the right to root.
Just don't buy smart TVs. Buy a dumb TV, attach a RaspberryPi or an Intel NUC, install Kodi and enjoy.
Some of them are low-duty digital signage, or have a less-beefy desktop brother with the same/similar software and just mechanical/(power) electronics differentiating them between 8/5 and 24/7 usage to keep their warranty.
You are looking wrong when you make the price argument. Either your price source is weird, or you're looking at the "wrong" model. Just keep in mind that these are not your generic high-gloss consumer electronics flashy devices, but what a value-oriented engineering office might well use. I have yet to find a better LCD than their x4071uhsu-b1 ... Seriously, if you know of something comparable in contrast ratio: I dread the day mine breaks and I need to find a replacement.
I realised after spending working hours in front of Monitor/Laptop, my eyes can use some rest. So NO TV in weekdays.
I have bought 30 inch monitor, connected to home desktop and use it for entertainment - Netflix, sports etc.
NO TV is an option. Some day going to upgrade to bigger monitor.
More seriously, our privacy has been nullified by ferocious marketing and advertising tactics. Data collection has weaved its way into the design of most of the products we use, it was only a matter of time.
I know you can opt out of all of the collection on a Samsung. Just have to not agree to all of the Terms and Services. That being said, I've heavily isolated the Samsung in the house. It sits on its own VLAN that cant talk to anything else on the lan and use some heavy white/blacklisting at the DNS level to limit what it can get to on the internet. I'm sure it's still uploading something about me to somewhere though.
Menu > Smart Hub > Terms and Conditions
Inside there will be several terms of these tracking companies. Go inside each and all of them and check the box:
I don't agree with these terms
There. No consent for track.Have not tested network wise if the tracking persists, but in theory, removing consent should mean they can't collect it.
And despite GE becoming a Chinese brand, they seem to have regained a reputation for reliability somewhat, based on the reviews I read.
I personally use a Chromecast for my smart TV needs, which of course Google knows everything about. But the chromecast can't see anything else I do, no broadcast TV or if I use the DLNA function.
I wonder when right holders demand those information to sue people who watch "illegal" content on their TVs.
https://www.datainnovation.org/2019/01/national-survey-finds...
Could you imagine if your smartphone screen or your computer monitor did this? I think samsung makes the iphone screens. What if they randomly sent screenshots with personal identifiers back to samsung? Who in their company possibly would possibly think this is okay?
Even if you are prepared to exercise your rights under GDPR in my experience the usual modus operandi is asking for more data via various registration forms and accounts or sending copies of personal IDs. Then if you manage to hand in a Data Request or Deletion Request there is no way to find out whether they really complied or not, making it pointless.
That way, people with less technical know-how (like, say, my parents) can follow the instructions and get more privacy.
At least, I assume they can be disabled? I don't think it would fly with the GDPR otherwise?
cellular connection is still prohibitively expensive in many parts of the world.
As to the cost, one of the main selling points of 5G networks is their suitability for large-scale low-bandwidth uses (IoT), usage tracking among them. Samsung and others will be able to collect data from millions of devices at a very modest cost. Ericsson etc expect billions of new devices on 5G networks in the next five years. Networks are being designed for a minimum of one million devices per square km (0.39 sq mi), what do you think they will be?
We've already seen built-in connectivity. Some Amazon Kindles used to have free Amazon-provided 3G connection that worked in most of North America, Europe and other more developed parts of the world. It's only a matter of time before it becomes universal.
Samsung is launching their first 5G-enabled TV this year. 5G is there for 8K over-the-air streaming service, but can (and I am certain that will) be used for tracking purposes too, even if not subscribed to anything. The hardware is there and the cost is minimal - so why not?
Though, it's only a small step for it to report home which WiFi network is the strongest, even if it never connects, for a Google App on the TV to know who I am.
Not that it matters a ton to me. I just don't want another vector for ads, and you can bet that an always on connection will be used to tell me what streaming services the TV can offer me this week if I'd only feed it my WiFi password.
In a past life, I actually helped bridge ad attribution for a bunch of these. Funny.