The Smart TV That Watches What You Watch and Maps Your Network

LG calls it smart home functionality. The researchers found something closer to a household census.

LG smart TVs are not only collecting data about what you’re watching, but also about what devices are connected to your home network, an investigation has found.

Other findings of the probe, conducted by Gamers Nexus in collaboration with Level1Techs’ Wendell and independent security researchers, include security flaws and the collection of voice transcripts.

The investigation looked into several LG smart TV models and found that the TVs are “identifying every device they can on our network upon activation,” as Gamers Nexus writes in its report. In one test, at least 38 devices were identified, including phones, smartwatches, printers, and thermostats. The TV sets also discover the names of devices and their internal IP addresses, as well as information about nearby Wi-Fi networks.

More: Big Brother Comes Built Into the Screen

LG is not the only TV maker that uses automatic content recognition (ACR) – but the investigation showed that its implementation is particularly difficult to evade. ACR is used to identify the content playing on a screen using digital fingerprints. The data is collected and sent to LG even when the TVs are used only as HDMI displays.

The researchers estimate that one of the tested sets was sending around 4 GB of ACR-related “fingerprint” data per month to LG’s servers. The company markets this feature as “Live Plus” and in the user manual explains that it is used for content recommendations, but also “interacting with advertisements.”

LG’s advertising business, LG Ad Solutions, promotes ACR as a means for advertisers to get “deterministic viewership data” covering content on the TV, including programs, movies, ads, games, and streaming apps. Advertisers can select audiences based on their viewing and purchase habits, subscription and service usage, location, and more.

The company’s website also goes into how advertisers can use this data to target gamers, offering categories such as “platforms, studios, brands, titles and consoles” – as well as “ad skippers or app loyalists.”

The investigation also looked into what happens when users enable voice control and discovered that the TV continues to capture ambient speech for about 10-15 seconds after the command is given. These words appear as plaintext transcripts in system logs, and during the test, a fake Social Security number was spoken and later found in the logs.

The researchers also demonstrated how LG TVs could be hacked and used as covert listening devices, with the screen appearing as if it was turned off. Audio recordings can be stored on the TV and retrieved later. Turning off the main TV microphone does not disable the secondary feedback microphone, and other possible audio inputs include a remote microphone, and attached USB or Bluetooth devices. The TV can also access audio from devices connected via HDMI.

The report also goes into how LG makes it difficult for users to properly opt out of data collection, and details several security vulnerabilities that could give attackers full control over the TV, including remote-code-execution flaws. The company’s response is that the claims are not true.

“The claims made in the recently published video are not true,” LG said in a statement to The Register.

LG also said that discovering devices on a network is standard smart home functionality and that ACR is an opt-in feature. The company also denied that it processes voice data unless the remote voice button is held or a wake word is recognized by the enabled far-field feature.