I read this as "Wait until the model is EOL, hoping it won't be disclosed and fixed until then and also not fixed afterwards"
Is this not what you meant to say?
I read this as "Wait until the model is EOL, hoping it won't be disclosed and fixed until then and also not fixed afterwards"
Is this not what you meant to say?
If manufacturers had a sanctioned way for the user to get root access to their own hardware, responsible disclosure would've made sense, but as it is, vulnerabilities are a useful tool for the owner of the device.
While some stuff are legit issues such as ADR, people now think they are wire-tapping. Because somebody used a rooted device to show-case recording silently through their device.
Can you blame corporations having this control-freak nature when shit like this happens?
It's stuff like this that likely pushes corporations now to invest more into device security, and locking down their stuff more.
Good for security and the corporation.
Maybe mid-term good for you consumer, because they might get more cautious with tracking stuff.
But long-term bad for you consumer, too, because they will make sure to lock down their devices better.
But that's not going to happen.
(And yeah, as pointed out by another comment, if you officially allow users full control of their devices, you are less likely to have people sitting on undisclosed exploits so that they can get it without your help, and as a bonus you have an easier argument for why you are not liable for what someone does with that control)
> Can you blame corporations having this control-freak nature when shit like this happens?
Is "shit like this" referring to the corporation spying on the user, or the user discovering it? Because one happened before the other, and so impossibly could have caused the former.
> It's stuff like this that likely pushes corporations now to invest more into device security, and locking down their stuff more.
Or they could just sell the device users want, and not sell their users.
The video draws exactly that picture, a nefarious actor, remotely taking control over my TV and recording Audio from it
On a different note: Are you, in any way, affiliated with LG? You read to me as someone who is "unhappy" with the findings.
The attack-surface only gets lower when the TV is no longer in use and is disposed. That doesn't happen at EOL, customers don't suddenly throw away their TVs after 2 years.
I'm happy with the findings and hope that it gains momentum, but unhappy with the dilution of the matter with speculation, assumptions and sensationalism, because it allows the vendor to wiggle out of it and wait for attention to wind down.
I would prefer a clear spotlight to be shined on #1 the ad-networks business model of TV-manufacturers and #2 the security of their (very powerful) products.
If the process results in regulation which also requires the TV manufacturer to offer root-access to the consumer to verify and control its operations, I would be overjoyed.
But this is unfortunately not a subject of the current narrative at all, it will actually result in the opposite (more effort to lock-down the OS to prevent future sensationalism reporting)