Skip to content
CYBERSECURITY & DATA PRIVACY

LG to Ban Residential Proxies from Smart TV Apps – Krebs on Security

The crackdown comes less than a month after independent cybersecurity researchers revealed a startling trend across major smart TV ecosystems. According to an extensive analysis published by the security firm Spur, more than 42 percent of games and other downloadable applications available on LG’s webOS store harbored software development kits (SDKs) designed to quietly route third-party internet traffic through a user’s television indefinitely. Furthermore, the researchers discovered that over a quarter of the applications developed for Samsung’s competing Tizen operating system contained similar residential proxy components, exposing millions of household devices to potential data-routing schemes.

The investigation, which was highlighted by security journalist Brian Krebs, brought widespread attention to how hidden software monetization strategies have infiltrated consumer hardware that users typically view as isolated media consumption devices rather than active network servers. Responding directly to questions regarding Spur’s findings, LG Senior Vice President John Taylor confirmed that the company has initiated collaborative efforts with application developers to actively strip the residential proxy functionality from their webOS offerings. Developers who refuse or fail to comply with these directives will face swift and permanent suspension from the platform.

Taylor emphasized that operating a residential proxy network runs entirely counter to the intended design and purpose of LG smart televisions. He noted that the technology conglomerate is moving aggressively to purge these capabilities from its app ecosystem, confirming that a comprehensive review of all platform applications is already well underway. In an emailed statement to KrebsOnSecurity, Taylor outlined the company’s broader strategy to safeguard its users, explaining that as part of ongoing efforts to elevate platform quality and protect the user experience, LG will continue to tighten and strengthen its evaluation protocols for any developer-submitted applications, particularly those attempting to integrate residential proxy SDKs.

The root of the issue lies in alternative monetization models sought by independent app makers. Developers looking for ways to generate revenue from free or low-cost applications frequently partner with residential proxy providers. These providers pay developers to bundle specialized SDKs into their products, effectively transforming the end user’s hardware into a commercial proxy node that can be rented out to paying corporate and institutional clients. Spur’s analysis revealed that on LG and Samsung smart televisions, these residential proxy SDKs were bundled into a surprisingly diverse array of software, ranging from casual arcade titles like Pac-Man to seemingly innocuous screensavers and utility applications.

One prominent example highlighted by the researchers involved a smart TV application for the classic game Pac-Man distributed by the proxy network provider Bright Data. Within the interface, users were presented with a choice between sitting through traditional commercial advertisements or agreeing to allow their television to function as an active residential proxy node in exchange for an ad-free experience.

LG to Ban Residential Proxies from Smart TV Apps – Krebs on Security

When approached for comment regarding the widespread use of its technology, Bright Data defended its operational model, stating that its network is strictly built on principles of user consent, transparency, and corporate responsibility. A statement provided by the company stressed that every single peer intentionally opts into the network through a dedicated prompt screen and receives tangible value in return. Furthermore, the company asserted that all of its enterprise customers undergo rigorous vetting procedures and that its business practices have successfully undergone a second independent audit conducted by PwC. Bright Data reiterated its ongoing commitment to supporting an open, transparent internet where legitimate businesses, academic researchers, and institutional bodies can responsibly access publicly available web data.

Bright Data and other prominent residential proxy providers named in Spur’s research maintain that they enforce stringent know-your-customer protocols to validate the legitimacy of how their services are utilized, a process heavily tied to web data collection and content-scraping activities. Additionally, these proxy companies argue that they deploy sophisticated technological countermeasures designed to prevent their network customers from interacting with, scanning, or seizing control of other connected devices sharing the same local household network.

Despite these defensive assurances, security analysts like Trevor Sutter of Spur contend that the fundamental danger does not stem from the mere existence of residential proxy networks, but rather from the stealthy scale at which they are being embedded into everyday consumer electronics. Because the average household does not perceive a modern smart television as a traditional computer, consumers are rarely equipped to audit the background network activities of their living room appliances, leaving a massive blind spot in home cybersecurity.

Sutter pointed out that relying on a single, one-time consent prompt hastily buried within the onboarding screens of a TV application is a deeply flawed substitute for genuine platform transparency, continuous monitoring, and strict oversight. This risk is exponentially magnified in shared household environments where consent might be inadvertently granted by individuals who lack the authority or technical awareness to understand the implications, such as minor children or visiting guests.

While LG’s decisive move to weed out residential proxy SDKs from its application marketplace has been welcomed by the cybersecurity community, the manufacturer simultaneously faced separate scrutiny regarding another questionable software partnership involving its high-end hardware. Earlier in the week, popular technology review channel Gamers Nexus exposed a practice wherein specific models of LG LCD monitors automatically installed an unsolicited software application designed to promote paid McAfee antivirus subscriptions. According to the findings, the promotional application bypassed traditional user consent workflows entirely, arriving silently on user machines via standard Windows Update mechanisms without displaying an approval prompt.

Leave a Reply

Your email address will not be published. Required fields are marked *