Skip to content
CYBERSECURITY & DATA PRIVACY

LG Electronics USA Takes Action Against Smart TV Apps Routing Internet Traffic Through Residential Proxies

Home appliance giant LG Electronics USA has announced plans to suspend any applications built for its smart televisions that convert users’ devices into always-on residential proxy nodes. This enforcement action comes less than a month after security researchers revealed that an alarming percentage of games and other downloadable applications on LG’s webOS platform allowed unknown third parties to route their internet traffic directly through consumer televisions.

The controversy originated from a comprehensive research report published earlier in July by the cybersecurity firm Spur. The investigation examined the widespread integration of residential proxy software development kits, commonly known as SDKs, within the smart television app ecosystem. Spur’s findings indicated that more than 42 percent of applications available for download on LG smart televisions contained SDKs capable of transforming a standard household television into an indefinite proxy node. Furthermore, the researchers discovered that more than a quarter of applications developed for Samsung’s competing Tizen operating system harbored similar residential proxy components.

When questioned about the alarming implications of Spur’s research, John Taylor, Senior Vice President at LG Electronics USA, confirmed that the company is actively collaborating with app developers to eradicate the residential proxy option from their offerings on the webOS platform. Taylor made it clear that developers who fail to comply with these safety and policy demands will face immediate suspension of their applications from the app store.

Taylor emphasized that a residential proxy network represents an entirely unintended use case for LG smart televisions, prompting the corporate leadership to take decisive corrective measures. He noted that LG is fully committed to purging residential proxy networks from its application ecosystem moving forward and revealed that the internal review of existing applications is already well underway. As part of ongoing corporate initiatives to enhance platform quality and elevate the overall user experience, LG intends to significantly strengthen its evaluation protocols for developer-submitted applications, particularly regarding those that attempt to incorporate residential proxy SDKs.

The business model driving this phenomenon relies on independent app creators seeking alternative monetization methods. Residential proxy providers routinely offer financial compensation to developers who agree to embed specialized SDKs into their software. Once installed, these SDKs silently convert the unsuspecting user’s hardware device into a residential proxy node, which the provider then rents out to paying corporate and individual customers. In the case of mainstream smart television ecosystems like those managed by LG and Samsung, Spur’s investigation revealed that residential proxy SDKs were successfully bundled into an array of casual applications, ranging from simple recreations of classic arcade games like Pac-Man to seemingly benign screensavers and file utility tools.

According to Spur’s diagnostic data, the residential proxy network operated by Bright Data accounted for the vast majority of proxy SDK deployments identified across both Samsung and LG smart television models. In an official statement shared in response to the findings, representatives for Bright Data asserted that their network is fundamentally built upon principles of user consent and corporate responsibility, maintaining strict adherence to the respective terms of service established by both LG and Samsung.

LG to Ban Residential Proxies from Smart TV Apps – Krebs on Security

Bright Data’s statement stressed that every peer on their network explicitly opts in through a dedicated user interface screen and receives tangible value in return. Furthermore, the company maintained that every commercial customer is thoroughly vetted and noted that their operational practices have successfully undergone a second independent security audit conducted by PwC. The proxy provider reiterated its dedication to maintaining an open and transparent internet environment where legitimate businesses, academic researchers, and institutional bodies can responsibly access data residing within the public domain.

Bright Data, alongside competing proxy providers highlighted in the Spur report, consistently maintains that they enforce rigorous know-your-customer protocols to validate the legitimate intentions of their service subscribers. These authorized activities are frequently tied to authorized web scraping and data gathering operations. Additionally, these proxy companies maintain that they implement sophisticated technological countermeasures designed to prevent proxy service customers from interacting with or exerting unauthorized control over other connected devices residing on the local home networks of the proxy users.

Despite these defensive assurances from proxy providers, security analysts at Spur argue that the core issue extends beyond the mere existence of residential proxy networks. Instead, the primary danger lies in the stealthy embedding of these technologies at scale within consumer hardware devices that the average person does not perceive as traditional computers and is consequently ill-equipped to monitor or audit.

Trevor Sutter of Spur pointed out that relying on a single, one-time consent prompt hastily buried within the user interface of a television application falls woefully short of providing genuine transparency, ongoing user control, and rigorous platform oversight. Sutter emphasized that this risk is drastically amplified in typical domestic environments where initial consent is frequently provided by vulnerable individuals within the household who lack the legal capacity or technical awareness to grant such permission, such as minor children.

While LG’s decisive announcement regarding the removal of residential proxy SDKs from its application marketplace has been met with widespread approval from the cybersecurity community, the hardware manufacturer recently encountered separate criticism regarding another contentious software partnership. The company faced scrutiny over its bundling of third-party security products via automated software drivers distributed directly with its high-end liquid crystal display monitors.

Earlier in the week, technology commentary channels such as Gamers Nexus demonstrated that specific LG LCD monitor models automatically deploy an application designed to promote paid subscriptions for McAfee antivirus software. Notably, this promotional software arrives silently through standard Windows Update mechanisms without presenting the user with an explicit approval prompt, drawing renewed attention to background software distribution practices within the consumer electronics sector.

Leave a Reply

Your email address will not be published. Required fields are marked *