- Kairos@lemmy.todayEnglish1 month
This is because as soon as a monitor is connected to a Windows computer, it automatically installs both the LG Monitor App Installer and McAfee Scam Detector without ever asking the user for permission.
Is this not a felony under U.S. law? Computer hacking has HUGE criminal liability.
- 1 month
Name something you do as a corporation to avoid any laws or accountability with the current administration
BRIBE THE DOJ
let’s see if that answer’s on the board…survey says…!
DING
- 1 month
The more I learn about windows the more I wish I would’ve ditched it a long time ago instead of last month…
- themurphy@lemmy.mlEnglish1 month
It probably says somewhere in the ToS, which is still a fucking disgrace that those exists, without having to make clear and obvious bullet points you click “consent”.
Even having to make consent multiple times should be mandatory for every shit they try to do.
Solution if users shouldnt hit consent multiple times? Dont do shady shit.
- psivchaz@reddthat.comEnglish1 month
I have a plan: we pass a law that any contract intended for the public (ToS, various other terms and conditions, privacy policies, etc) must be at the average reading level of the American public. We’ll either incentivize better education or better contracts. Maybe both!
- Buddahriffic@lemmy.worldEnglish1 month
Or standardize agreements that can be agreed to with just clicks so you can tell what’s up from just seeing which agreement modules are included and what parameters they have (along with a bunch of sites that explain them in easier terms for the less literate, which will be useful because they are standards used by many agreements rather than needing a unique one for each version of each document).
- themurphy@lemmy.mlEnglish1 month
Doesnt matter if it’s in kindergarten level reading, as long as it’s a few paragraphs long, people will accept it.
- UntimedDiffusion@piefed.zipEnglish1 month
I can’t remember the specifics right now, but in Gamers Nexus video from yesterday, according to LG ToS you must disclose something regarding spying and wiretapping laws to your family and anyone visiting your house
- themurphy@lemmy.mlEnglish1 month
Literally insane that you can even put that in an agreement to being with.
- Kairos@lemmy.todayEnglish1 month
Apparently it’s windows doing it. Not the monitor via the HDMI or something. I guess that’s what you get for using windows.
muusemuuse@sh.itjust.worksEnglish
1 monthYep. Windows installs manufacturer “helper” apps automatically like drivers. Got a Logitech mouse? You probably have a Logitech app in there you never asked for too because you plugged it in.
Stop using windows.
- lightnsfw@reddthat.comEnglish1 month
I had to go and find the Logitech app and install it myself. Otherwise it just used the minimal drivers that were built into windows.
muusemuuse@sh.itjust.worksEnglish
1 monthMaybe wired mice and those without rainbow barf behave differently.
skulblaka@sh.itjust.worksEnglish
1 monthI’ve got a corsair rainbow barfer and I also had to install its control program manually. Mileage probably varies by manufacturer, most likely.
muusemuuse@sh.itjust.worksEnglish
1 monthSoon-to-be-illegal-tooltip: openRGB is a thing.
OOOH! Can we manually add entries for unwanted software to windows defender?
- SCmSTR@lemmy.blahaj.zoneEnglish1 month
Also, implied consent is not consent, and if there is no consent, the entire contract is unenforceable and therefore void.
- Iusedtobeanalien@lemmy.worldEnglish1 month
Just a reminder that terms of service or any other contract never override law
ohshit604@sh.itjust.worksEnglish
1 monthLet me guess, proprietary drivers cause this and the open source or generic drivers lack “functionality”.
If it turns on, reaches its peek resolution and refresh rate that is good enough for me, I genuinely can care less for HDR or the nitty gritty features.
- deadcade@lemmy.deadca.deEnglish1 month
Monitors don’t need drivers. Your GPU needs drivers, and you might need color correction for your monitor.
Microslop decided that any device that is plugged in might need drivers. They allow device manufacturers to specify an arbitrary program to be downloaded and executed by Windows Update, any time a device they make is plugged in.
- Iusedtobeanalien@lemmy.worldEnglish1 month
And if that driver/software does evil or is so poorly written it meets driver verification but exposes vulnerabilities, how is that Microsoft’s fault
- deadcade@lemmy.deadca.deEnglish1 month
Microsoft is the company that approved the software to automatically download and run as admin when a specific device is plugged in. The OEM submitted malware and Microsoft approved it. Both are at fault for letting malware download and run on your device.
In the case of vulnerabilities, MS is fully aware of this happening frequently and has announced they want to do something about it, but hasn’t actually done anything about it.
- 1 month
No, no no. That’s only if you do it. If a huge corporation does it, see, that’s different. Corporations are “people” for the purposes of free speech (with money) or even voting (example), but when it comes time to throw somebody in jail for overtly criminal behavior, all of the sudden the legal system can’t find anyone to target.
Wispy2891@lemmy.worldEnglish
1 monthThis is 100% also Microsoft fault and they are to be held accountable for this. With many drivers it can happen that one manufacturer goes rogue, but Microsoft needs to have a zero tolerance policy for this: do it once and your signature is permanently revoked for all your drivers
- leriotdelac@lemmy.zipEnglish1 month
I wish we would stop using smart to describe surveillance technology. Smart sounds nicez but there’s nothing smart about it…
- Jiral@lemmy.worldEnglish1 month
That is the neat thing about language, it adapts. Euphemisms wear off and something like “smart device” increasingly sounds like “nasty anti-consumer surveillance home appliance” all by itself.
- WhyJiffie@sh.itjust.worksEnglish1 month
you need popular public sentiment for that. most people just shrug it off if even that
- 1 month
Not only that but my old LG smart TV (47LM8600, I think manufactured in 2012) has literal suicide timers in its built in apps. Mine has never been connected to any network and yet it mysteriously informed me after approximately three years of ownership that all of its player apps such as Youtube, Hulu, Netflix, etc. would stop working because they were “no longer supported,” all of them within the time frame of the same couple of weeks. It knew this somehow, apparently via magic, or quantum fluctuations, or psychic brain waves. Without internet connectivity.
Obviously I don’t use any of those features so I didn’t give a rat’s ass and I still don’t. But I still find that deeply suspicious.
- Elvith Ma'for@feddit.orgEnglish1 month
The only technical explanation that’s not malice would be that some certificate store on the device had expiring certificates and would need an update to continue to function (or rather connect to remote servers).
- Majestic@lemmy.mlEnglish1 month
Yes. Certs can expire after whatever time the issuer wants to set for them. That could be six months or 20 years. Some infrastructure has limits on max and min lengths (more max than min usually) but not all and there are best practices as well.
More importantly the certs could have been five years old by the time this person got the TV for a total age of 8 years.
- Elvith Ma'for@feddit.orgEnglish1 month
It depends on their use. The most common certificates that you will “use and check” (implicitly) all the time are probably those, that get served by websites and the APIs that apps talk to. Those are usually quite short lived. Let’s Encrypt IIRC issues them with a default life time of ~90 days and there’s a push industry wide to reduce their lifespan generally to… IIRC something around 40 days. But there are more usecases and certificates and those may be valid longer. E.g. a developer that signs their code/compiled binaries.
Or - and thats more relevant - when you check a certificate you do not only check it’s content, you also check that it was issued and signed by someone “you” trust (or rather the software on your device trusts). Ususally there’s a central store on your PC managed by Microsoft (for Win), Apple (for Mac) or your Linux Distribution with a list of certificates that your device trusts. Those are usually quite long lived (often several years, probably even more than a decade). But will also end. And there will be new ones to replace the old ones. Or new vendors that get added to this trust store. If you do not update your device, this trust store won’t change.
There are now several versions how this can affect the apps in this case, e.g.
- They might not be able to talk to servers using “newer” certificates, as they cannot validate them. There might even be the problem, that the update mechanism breaks, as it wouldn’t be able to get updates from the server to get new certs effectively locking you out.
- They might only allow apps that are signed by them, but their old cert is running out and if it’s invalid, they might prevent the apps from running (as their cert is now untrusted) - note that you can provide ways around that (e.g. checking if the cert was valid when it was issued vs. checking if it would be valid now), but for a device that’s designed to be able to get updates, you might have forgotten that or didn’t think it was an issue or…
- FlashMobOfOne@lemmy.worldEnglish1 month
Planned obsolescence is one of those things that just infuriates me so much about capitalism.
- 1 month
Luckily for me at least, like so many of us dweebs here, I drive my TV with a little media center PC anyway. So I couldn’t care less which of their services they disable. The more the merrier, as far as I’m concerned. The real annoying part is that these don’t work (presumably), but you still can’t remove the icons from the thing’s home screen.
- milk@discuss.tchncs.deEnglish1 month
There was some controversy a while ago about Samsung TVs finding and connecting to open WiFi networks autonomously if they weren’t connected to a network explicitly
TrackinDaKraken@lemmy.worldEnglish
1 monthCould be something as simple as a timeout. Three years of no connection, and it cuts you off.
TrackinDaKraken@lemmy.worldEnglish
1 monthAs much as I’d like a bigger TV with OLED, I’ll be sticking with my old Toshiba dumb TV. It’s good enough and doesn’t even know the internet exists.
lastlybutfirstly@lemmy.worldEnglish
1 monthDoes anyone make dumb TVs anymore? Seems like there’s a sizable market for it. I haven’t had a TV in 6 years and want one for local channels, but I really don’t want a smart TV.
- mursejoy@lemmy.zipEnglish1 month
I just never gave my smart TV network info. It’s at the factory settings and can’t connect to anything. If there isn’t a console connected to it then it is useless. Just like the good ole days.
- Sam_Bass@lemmy.worldEnglish1 month
assuming you have a coax cable connection on it, mount an antenna, go to settings and find a channel scanner to run
- fatcat@discuss.tchncs.deEnglish1 month
What? How would they do that if they are never connected to WiFi in the first place?
- SalamiDommie@lemmus.orgEnglish1 month
They still talk and connect if you want them to or not. The “permissions” is mostly for the apps to talk back and forth. It is still usable by anyone who knows how.
- LordCrom@lemmy.worldEnglish1 month
Smart TVs do not magically connect to your WiFi without credentials.
Now if there is an open WiFi available, that might be a way or if the TV has a deal with a carrier to use all that open automatic WiFi.
- poopkins@lemmy.worldEnglish1 month
I’m confused; are you suggesting the TVs ship with an embedded SIM?
- fatcat@discuss.tchncs.deEnglish1 month
A bit more technical details please. How do the connect to what? It sounds a bit like they can just magically connect via telepathy to their home base if you phrase it like that.
paulcdb@lemmy.worldEnglish
1 monthIt sounds a bit like they can just magically connect via telepathy to their home base if you phrase it like that.
Its not that difficult, scan for open wifi, if detected, connect, phone home to spy central.
The more sinister, each tv that successfully detects a connection to spy central broadcasts a 2nd wifi that the tv can scan for and connect similar to mesh networking.
There are tons of reasons to want a network connected monitor, the problem is no-one seems interested in producing one without the spyware. I’d love a 40”+ device that supported rtsp, etc but until enough people step up and boycott all this spy crap it’ll never be worth producing better devices. 😞
- fatcat@discuss.tchncs.deEnglish1 month
Mh, yeah I see the possibility of using an open network in theory, but in practice I haven’t seen a open Wifi network in years (excluding business owned ones, but usually you need to confirm something there and can’t use them forever). So not sure how feasible that is. The more sinister option is done by Echo devices for example (that: https://en.wikipedia.org/wiki/Amazon_Sidewalk), but also requires a second device nearby. Much more possible possible though, if similar devices are nearby. But that can’t be hidden anyway and it should be possible to check for that.
I feel like the best option to get the monitor network connected is still a secondary device and never using the built in firmware (and first checking if said device got things like you described).
- Sam_Bass@lemmy.worldEnglish1 month
not if you dont connect it. of course my “smart” tv allows that, your’s may not. they all will bitch and moan about turning it on when first set up but you should be able to ignore it or set it up “later”
- Teepo@sh.itjust.worksEnglish1 month
Sceptre seems to be the only company makinh consumer-grade dumb TVs.
Pueblo@feddit.orgEnglish
1 monthThere is, its called industrial tv “iiyama” for example is a brand of those
- poopkins@lemmy.worldEnglish1 month
I’ve looked into these in the past. Unfortunately, they are extremely dated TVs that are visually and aesthetically unpleasing.
- FG_3479@lemmy.worldEnglish1 month
You should just get a smart TV which allows setting it up without wi-fi instead.
GideonD@lemmy.worldEnglish
1 monthFor the PC Monitor issue: To prevent this sort of behavior. Open Group Policy Editor Computer Configuration>Administrative Templates>System>Device Installation Prevent automatic downloads of applications associated with device metadata = Set to Enable.
To get rid of it once installed you have to remove it from the Windows Store since it’s an app, not an installed program. For me, this was not possible as there was no way presented to uninstall it in the app store. I had to do it from terminal with this command, which could vary a bit depending on the exact app version:
Remove-AppxPackage LGElectronics.LGMonitorApp_1.2606.1601.0_x86__cfnzzhwkr8z5w
- brucethemoose@lemmy.worldEnglish1 month
Keep in mind this will disable plug-and-play for other devices one plugs in.
Which is excellent, from a security standpoint, but something to be cognizant of.
- WhyJiffie@sh.itjust.worksEnglish1 month
store apps can also be uninstalled from the settings app.
for the first setting, it’s easier to turn that and more off with o&o shutup10
- coolmojo@lemmy.worldEnglish1 month
store apps can also be uninstalled from the settings app.
Also using winget.
DupaCycki@lemmy.worldEnglish
1 monthTried going through this with my grandma on video call. She asked: “why is there a police group in my computer?”
- MIDItheKID@lemmy.worldEnglish1 month
You can search for it by the appx name and then use a pipe to remove the package. Then you don’t need to worry about specific version numbers:
Get-AppxPackage -Name ‘LGElectronics.LGMonitorApp’ | Remove-AppxPackage
- 1 month
Bought a LG TV and a Monitor three years ago. Last time I will do that. Really happy about my decision not to let the TV have access to the internet.
- WhoIzDisIz@lemmy.todayEnglish1 month
Good luck finding a brand NOT doing it by the time you’re ready for a new one.
Otter@lemmy.caEnglish
1 monthA lot of bad ones out there, but some are worse than others. For example, I’m not going to consider a Samsung TV because of how many times they’ve done something sketchy
LG is also falling down the list with this incident
- Kühlschrank@lemmy.worldEnglish1 month
Yeah fist time I saw an ad on my smart monitor I reset it and never connected it to my wifi again
- thenoirwolfess@fedinsfw.appEnglish1 month
What’s the point of a smart monitor? It’s connected to a PC. The PC is smart.
- TehWorld@lemmy.worldEnglish1 month
About 90% of Society. If you told my mom she was going to have to plug in a device and use another button on her remote (input) she’d look at you like you were asking her to replace a CPU on a computer. Can I do that? Yeah, I can but it’s delicate work fraught with danger.
- zackhow@programming.devEnglish1 month
Yep, mine has never reached the internet, it is connected but is blocked at the firewall so I can still hook home assistant up to it.
- 1 month
I’ve had a “smart” TV for about 4 years. It keeps asking to update the firmware.
No. Effin’. Way.
It’s just going to install more and more spyware, bloatware, and find a way to charge me for something I didn’t have to pay for before.
Ann Archy@lemmy.worldEnglish
1 monthAnd thus vulnerabilities are introduced. Either by not updating the FW, or by updating the FW.
- 1 month
The odds of someone attacking my tv via the internet are as close to zero that “never gonna happen” is just about right. If it did happen, it would be because they went via the server maintainer for the firmware to attack all the TVs, and if they did that then an updated firmware would just as likely be a culprit.
- floofloof@lemmy.caEnglish1 month
I’ve used an LG monitor for about 5 years, and never install the manufacturer’s software unless it looks genuinely useful. When I saw the Gamers Nexus video I went to check my installed apps, and sure enough there was LG’s monitor app, installed silently without my knowledge. I used Bulk Crap Uninstaller to get rid of it.
To prevent this kind of thing in future, run gpedit.msc and enable “Prevent automatic download of applications associated with device metadata” under Computer Configuration → Administrative Templates → System → Device Installation.
- 0x0@infosec.pubEnglish1 month
Or you could just change to an os that doesnt piss on its users constantly
- floofloof@lemmy.caEnglish1 month
Indeed. I use Linux most of the time, and MacOS a bit of the time, but the old Windows desktop is still there for the infrequent times when I need it to work on old music projects. I have it too dual-booting into Linux, so even it spends most of its time in a more sane OS.
- OS2Warp@lemmy.zipEnglish1 month
Great; what OS has the equivalent of Group Policy and Active Directory besides windows?
- toddestan@lemmy.worldEnglish1 month
The funny thing is, the people who care about Group Policy and Active Directory are the same people who aren’t happy about their network potentially being compromised because someone hooked up their work laptop up to a monitor at their home.
- 1 month
This is the one thing holding open source back, and the thing Linux users keep pissing on without understanding it.
The CTOs inept nephew can manage your fleet of windows machines and you get all the checkbox security you need for compliance (and some real security):
- Centrally managed
- Logs that are fairly hard to manipulate
- SecureBoot + Bitlocker
That same feature set on Linux will cost you a ton of money in skilled staff if you want to check the same compliance checkboxes. (As for real security, who cares, no one is doing that anyway)
- OS2Warp@lemmy.zipEnglish1 month
THANK YOU!
So many people just don’t get it; happy to see someone rational who does.
I WISH Linux had something like this, but it’s like NT 4.0; it doesn’t have it.
- 1 month
It’s getting there, slowly.
- Clevis can do network and TPM pinned disk decryption.
- With Linux UKIs you can do self signed secure boot, we still need the mechanisms for central signing. This would actually be better that windows, you control your own PKI and Microsoft can’t sign garbage your machines boot.
- Logs is a somewhat bogus argument - log falsification on Windows has been done too. But linux is rather unprotected in comparison.
But the biggest issue is the mentality of ”I own my computer”. Sure, you own your private machine, but your company owns the computer you use for work and the data on it and has an interest in protecting that data from you. That particular threat model is hard to communicate, as Linux users normally don’t think of themselves as a threat vector.
- OS2Warp@lemmy.zipEnglish1 month
Good to know they’re working on boot; what about something similar to AD and GPO?
- 1 month
I hope no one tries to push GPO-like stuff on Linux. I get where you are coming from, but for example Puppet will give you a lot more power and and flexibility. There is no registry. ”Everything is a file” is actually true, you just manage a bunch of config files instead.
As for AD, you have FreeIPA as the major contender. It works. You can also just join your Linux clients to your AD. Kerberos works just as expected.
(RedHat actually tried pushing management of Gnome via FreeIPA á la GPO. It sucks, because the desktop environment is just a tiny part of what you might want to manage, so suddenly you need to have both that bullshit and your normal configuration management tool.)
- thejml@sh.itjust.worksEnglish1 month
That’s what I thought was happening here. The headline is a bit incorrect… the monitor didn’t install the bloatware, Windows did.
Now the drivers/software that Windows installed is likely from the MS store/update path and was made and signed by LG, but still. Plug this monitor into linux and it’s not going to do it because linux doesn’t have that mechanism.
- NewNewAugustEast@lemmy.zipEnglish1 month
I didn’t watch the video, but maybe they said how this done.
If it installed silently, it must be getting pulled in via Windows update right? Where Microsoft just sees this a regular old driver for a device I would imagine?
I have an LG monitor, maybe about 5 years or older. But I don’t have windows so I assume it knows nothing.
EDIT: Nevermind. I went and watched the section at the beginning, and yep that is exactly how it is done. Does windows not even vet what a vendor hands them as a driver? Perhaps they don’t care, but this seems like an easily exploitable route.
- floofloof@lemmy.caEnglish1 month
I suspect the thoroughness of the vetting is inversely proportional to the size of the kickback to Microsoft.
- NewNewAugustEast@lemmy.zipEnglish1 month
Got me curious. Quick search and I found three windows drivers that had keyloggers hidden in them. Go figure it was HP!
-
HP Notebook Keyboard Drivers: Keylogging code was discovered in the SynTP.sys file, which was part of the Synaptics Touchpad driver shipped with certain HP notebook models.
-
HP Audio Drivers: Researchers found keylogging features within the Conexant HD Audio Driver (specifically version 1.0.0.46 and earlier) used in various HP laptops and other Windows systems.
-
- mertn@lemmy.worldEnglish1 month
My LG tv is too old for this shit. But it does not get ethernet or wifi password just in case they decide to update the firmware
- ExLisper@lemmy.curiana.netEnglish1 month
It’s pretty much impossible to buy a dumb TV nowadays. It’s much easier to disconnect a smart TV from the internet using a firewall.
- ExLisper@lemmy.curiana.netEnglish1 month
Jellyfin app works really well on LG TVs. I think it’s the app that gives me the least issues of all the ones I’ve used. I find it much easier to use than pluging in a laptop. In other scenario external computer may be the best option.
- RaoulDook@lemmy.worldEnglish1 month
Not impossible, several options are still out there if you actually search for “non smart TV” on retailers’ websites.
Sceptre was one brand that made decent non-smart TVs but they seem to be vanishing off the market now. Many used ones still on ebay and other secondhand markets. Their website still shows a bunch of TV models but the retail links turn up empty.
- ExLisper@lemmy.curiana.netEnglish1 month
I searched and didn’t find anything in Europe. And that was couple of years ago already. Maybe there are some sources I don’t know about but I didn’t find any in typical stores.



















