Most “Smart” TVs use Automatic Content Recognition (ACR), essentially taking snapshots every 10+ms of what you watch and hear, then forwarding & selling that data to companies for ads, etc. I now feel it’s only a matter of time before this “feature” finds its way to our ever “smarter” PC monitors.

LG with the help of Windows is already installing adware when the right Device ID is detected.

☑️ To disable ACR on TV: https://www.zdnet.com/home-and-office/home-entertainment/how-to-disable-acr-tv/

  • Turret3857@infosec.pub
    link
    fedilink
    English
    arrow-up
    5
    ·
    6 days ago

    To play devils advocate for them, if whoever is packaging fwup for the monitor either doesnt catch LG packaging malicious shit with it, or is for some reason allowing it to happen, it could happen.

    but then you’d have the wrath of at least a thousand enraged linux nerds on your ass and their stock would probably get tanked for a day.

    • Victor@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      edit-2
      5 days ago

      But I’m saying, what path does the installation take in order to even end up on disk? How would it get permission to run sudo/doas or gain root access in order to install shit, without my user/admin input?

      • Turret3857@infosec.pub
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 days ago

        Most linux distros have a program called fwupd that installs hardware related updates. That was my example of the way in because most hardware updates are proprietary.

        • deadcream@sopuli.xyz
          link
          fedilink
          arrow-up
          4
          ·
          5 days ago

          Fwupd is for updating on-device firmware AFAIK. This “attack” uses windows update mechanism for automatic installation of drivers to push additional software directly on users’ PCs.

        • Nate Cox@programming.dev
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 days ago

          I don’t think I’ve ever been able to run fwupd without root privilege elevation and a confirmation prompt listing the incoming changes. Are there package managers out there running it for you? If so, gimme a list so I can stay the fuck away or break that script.