Your LG Smart TV Is Spying On You And Your Midget Fetish

by | 21st, November 2013

IS you new LG Smart TV spying on you?   Dr Beet, aka Hull-based Jason Huntley, found that his telly was displaying ads on the Smart landing screen. He investigated and found corporate video  advertising their data collection practices to potential advertisers. LG boasts:

LG Smart Ad analyses users favourite programs, online behaviour, search keywords and other information to offer relevant ads to target audiences. For example, LG Smart Ad can feature sharp suits to men, or alluring cosmetics and fragrances to women.
Furthermore, LG Smart Ad offers useful and various advertising performance reports. That live broadcasting ads cannot. To accurately identify actual advertising effectiveness.
The telly features a “Collection of watching info”. Unless you disable it this is active.
He went further, looking at what was being harvested: POST /ibs/v2.2/service/watchInformation.xml HTTP/1.1
Accept: */*
X-Device-Product:NETCAST 4.0
X-Authentication:YMu3V1dv8m8JD0ghrsmEToxONDI= cookie:JSESSIONID=3BB87277C55EED9489B6E6B2DEA7C9FD.node_sdpibis10; Path=/
Content-Length: 460
Content-Type: application/x-www-form-urlencoded
&chan_name= BBC TWO &device_src_idx=1&dtv_standard_type=2
&broadcast_type=2&device_platform_name=NETCAST 4.0_mtk5398&chan_code=251533454-72E0D0FB0A8A4C70E4E2D829523CA235&external_input_name=Antenna&chan_phy_no=&atsc_chan_maj_no=&atsc_chan_min_no=&chan_src_idx=1&chan_phy_no=&atsc_chan_maj_no=&atsc_chan_min_no=&chan_phy_no=47&atsc_chan_maj_no=2&atsc_chan_min_no=2&chan_src_idx=1&dvb_chan_nw_id=9018&dvb_chan_transf_id=4170&dvb_chan_svc_id=4287&watch_dvc_logging=0

He notes:
This information appears to be sent back  unencrypted  and in the clear to LG  every time you change channel , even if you have gone to the trouble of changing the setting above to switch collection of viewing information off.

It was at this point, I made an even more disturbing find within the packet data dumps.  I noticed filenames were being posted to LG’s servers and that these filenames were ones stored on my external USB hard drive.  To demonstrate this, I created a mock avi file and copied it to a USB stick.

This file didn’t really contain “midget porn” at all, I renamed it to make sure it had a unique filename that I could spot easily in the data and one that was unlikely to come from a broadcast source.

And sure enough, there is was…

I think it’s important to point out that the URL that the data is being POSTed to doesn’t in fact exist, you can see this from the HTTP 404 response in the next response from LG’s server after the ACK.

However, despite being missing at the moment, this collection URL could be implemented by LG on their server tomorrow, enabling them to start transparently collecting detailed information on what media files you have stored.

It would easily be possible to infer the presence

