Compared to, say, random Magisk modules or some random crap the OEM developed?
24 karma · joined September 7, 2026
Compared to, say, random Magisk modules or some random crap the OEM developed?
> What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.
I'll ask naively: Why not? I can come up with a bunch of arguments why it does help the bank and why it might reduce the risk of certain attacks.
While some stuff are legit issues such as ADR, people now think they are wire-tapping. Because somebody used a rooted device to show-case recording silently through their device.
Can you blame corporations having this control-freak nature when shit like this happens?
It's stuff like this that likely pushes corporations now to invest more into device security, and locking down their stuff more.
Good for security and the corporation.
Maybe mid-term good for you consumer, because they might get more cautious with tracking stuff.
But long-term bad for you consumer, too, because they will make sure to lock down their devices better.
However, just because your TV does ACR, does not immediately mean they listen 24/7 through your TV through any conversations even if the TV is off.
That is another, also quite different level of claim.
You have to start somewhere. Better makes sense to start looking at the arguments rather than the author.
It also helps you train your brain. Stop trusting someone solely because of who they are.
Usually, this happens after a bootloader unlock because then verified boot is disabled. You can still have a rooted device and not break verified, resulting in no warning. See: jailbroken iPhones.
I wouldn't say it's a solved problem. Just have to find an exploit that works with verified / attested boot.
And device manufactures are getting more and more restrictive here, too. Why do you think that is?
> Let's pretend there aren't plenty other ways they could spy on you.
Sure, of course there are other ways to spy on people. But as we see here: If the device itself does it, then we like to blame LG. If they used an exploit to do that, then we blame LG's shitty security.
If a hotel owner installed a microphone inside one or their specific TVs, then we blame the hotel owner at least - not LG.
> If it's bad if a hotel does it, why is it okay if LG does it?
It doesn't seem like it is okay. We are discussing this right here.
> Do you honestly trust LG, and the thousands of "partners" that they sell your data to, and every government whose warrants they have to honor?
Do I trust LG more than a shady hotel / BnB owner or eBay seller? Yes. Do I trust them fully? No. It's not fully binary, I'd say.
> Your argument reduces to "if the warden lets us out of our jail cells, who will make sure we behave?"
I am just trying to say, it's really not that binary. You can extend that to other places whenever attestation is involved.
Do I like Linux and open platforms? Sure! Tampering is fun! Do I hate people using open platforms to scrape my websites and constantly cause load, steal my content and use that for AI training? Also, yes.
But how can I fight that? We run into CAPTCHAs, Cloudflare, Anubis and co. Now that issue is reduced, but the openness is also gone.
And you always see in tech spaces we rather want "dumb" devices rather than smart devices, because we cannot trust them.
Attestation buys you more trust, but at the cost of openness.
That nuance is important if you value good journalism.
Otherwise if we're just our here throwing random allegations because "corp bad", might as well say LG 's TVs are turning the frickin' frogs gay.
Of course root allows you to tinker with your device and make it run what you want, but:
- Rooted devices make devices unpredictable. As shown in the video: How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?
- Re-selling: How do you know that TV you bought is untampered? How do you know it does not have software with malware installed that steals your credentials?
That does not mean that LG does all that by default.
This is the major issue with this video: It mixes stuff done by LG (ACR) with stuff done via rooting (audio recording). And now people think LG is 24/7 recording your conversations and uploading them somewhere. This has not been proven.
Otherwise, they start a voice command service (clearly displayed on the screen) and then say your TV is recording on your conversation. Like duh, of course my TV starts recording voice when I use voice commands.
And of course you have to trust LG with their TV and (not) having access. That same logic applies to every different company.
They can just start a capture, record to RAM / storage, and retrieve it later when it is reconnected to the network.
Otherwise if it's disconnected, it is still hard to exfiltrate the data somewhere. Maybe they could get creative via Bluetooth, but then you would need a cooperating device in proximity of the device.
I might be missing something here, but I did not see the TV automatically recording stuff by itself (or them showing it is transmitted somewhere) without a visible UI element showing that the microphone is active.
It seems that they turned the TV into a wiretap via root. That is a concern and might give some lessons for LG that they need to invest more into security of their devices (privacy indicators, attested boot, anti-root / anti-persistence measures, hard-shutting off the microphone without privacy indicators)...
But you can pull of similar attacks with a compromised laptop / computer or smartphone.
Of course, it's a TV, why does it need that stuff? Still though, I think the video itself is a bit misleading that it claims (or many people think) it automatically records and transmits all this stuff, while this was not shown here (unless I miss something).
A lot of the "silent listening" they show in the video is on a TV they rooted. They start recordings through arecord manually. Or, when they show the transcripts from the recording, the AI voice search is clearly visible on the screen and was manually triggered by something.
Now, does a smart TV need all that hardware? Is a compromised TV a security hazard and smart TVs need to learn more in terms of security from modern smartphones in terms of privacy indicators, attested boot and more?
Sure.
But I do not see enough evidence that the TV is actually voice capturing all this stuff on its own, without any notice.
There is plenty of stuff on the video regarding the network scanning, ACR and more that is definitely concerning. And this is something LG actually does by themselves (when you agree to their ToS / privacy policy).
However, I think that mixing the ACR / network scanning in with "let's root the TV and actively start recording ourselves" mixes the narrative of "what LG actually does" versus "what a compromised TV can actually do", and makes it seem like LG is just recording, transcribing and submitting voice transcript automatically by themselves.
This was not proven here. And I feel that GamersNexus is just risking a lawsuit here by not separating these different concerns clear enough.