LG to Ban Residential Proxy SDKs from webOS Smart TV Apps
LG to Ban Residential Proxy SDKs from webOS Smart TV Apps
LG to Suspend Apps Using Residential Proxy SDKs
LG Electronics USA has announced plans to suspend any apps on its webOS platform that convert smart televisions into always-on residential proxy nodes. This decision follows research from the security firm Spur, which found that more than 42% of apps available for download on LG smart TVs included software development kits (SDKs) that allow third parties to route internet traffic through the user's device.
LG Senior Vice President John Taylor stated that residential proxy networks are not an intended use for LG smart TVs. The company is currently working with developers to remove these options; those who fail to comply will have their apps suspended from the platform.
The Prevalence of Proxy SDKs in Smart TVs
Research conducted by Spur highlighted a widespread issue across major smart TV operating systems. While LG's webOS store saw a 42% prevalence of proxy SDKs, Samsung's Tizen OS was also affected, with more than a quarter of its apps containing similar residential proxy components.
These SDKs are often used as a monetization strategy for app developers. Proxy providers pay developers to bundle these SDKs into their apps, effectively renting the user's home IP address to paying customers. Spur found these SDKs in a diverse range of applications, including:
- Simple games (e.g., Pac-Man)
- Screensavers
- File utilities
In some instances, such as a Pac-Man app provided by Bright Data, users are given a choice between viewing advertisements or agreeing to let their TV serve as a residential proxy node.
Security and Privacy Implications
Residential proxy networks are frequently used for large-scale content scraping and can be leveraged for social media manipulation, spam, and DDoS attacks. While proxy providers like Bright Data claim to use "know-your-customer" (KYC) processes and technical countermeasures to prevent customers from accessing a user's local network, security researchers argue that the risks remain significant.
Trevor Sutter of Spur emphasized that a one-time consent prompt buried within an app is insufficient for meaningful transparency. He noted that the risk is further amplified when consent is granted by individuals in a household who should not be providing it, such as minors.
Broader Context of LG Device Security
This move comes amid other criticisms regarding LG's software practices. Recently, the YouTube channel Gamers Nexus reported that certain LG LCD monitors automatically install an application promoting paid McAfee antivirus subscriptions via Windows Update without an explicit approval prompt from the user.
Community Perspectives and Technical Concerns
Technical discussions surrounding this issue highlight several critical concerns regarding the "smart" ecosystem of home appliances:
The "Dumb TV" Preference
Many users expressed a desire for "dumb" panels—monitors or TVs without integrated operating systems—to avoid bloatware, telemetry, and security vulnerabilities. There is a growing sentiment that appliances should be treated as hostile devices if they require a network connection.
Detection and Remediation
Users have raised questions regarding how a typical consumer can detect if their TV is acting as a proxy and whether LG's suspension of apps will effectively disable SDKs already installed on consumer devices.
Impact on Web Scraping
Some observers suggest that if other non-Android-based TV manufacturers follow LG's lead, it could significantly increase the cost and difficulty of residential-based web scraping, potentially having a larger impact than current anti-bot measures like Cloudflare.
"A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended." — John Taylor, LG Senior Vice President