Several webOS apps using residential proxy technology are being suspended by LG Electronics for routing third-party traffic through smart TVs. The company is working with developers to remove proxy functionality, and apps that fail to do so will be suspended. According to research conducted by security firm Spur, residential proxy software is embedded in a significant number of LG and Samsung smart TV apps.
A proxy SDK was identified in 2,058 of 6,038 examined applications, raising concerns about how television owners' internet connections may be exploited without clear awareness of the activity. As a result of the study, more than 42% of LG webOS apps examined contained residential proxy functionality, while 26.5% of Samsung Tizen apps did not. As a result of such software, a device's connection to the internet and public IP address can be used as part of residential proxy networks.
Web data collection, advertisement verification, optimization monitoring and market research are some of the legitimate business uses of residential proxies. However, the same infrastructure can also be misused for the purpose of concealing malicious activity. Recent takedowns of large residential proxy networks have demonstrated the dangers associated with the use of compromised consumer devices as proxy nodes.
A particular concern is associated with smart TVs because proxy software can continue to operate while connected to the internet. According to Spur researchers, unclear consent mechanisms can lead users to be unaware that their connection has been shared with other parties or that their IP address may be exposed to third parties.
In a statement provided by LG Senior Vice President John Taylor, the company is working with developers to eliminate the residential proxy option from webOS applications.
While the company has not provided a specific deadline for developers, apps that retain the functionality will be suspended. In Spur's research, some SDKs remain active after the associated TV app has been closed, making the concern even more serious when the proxy is running in the background.
Some applications are presented as alternatives to advertisements using the TV's internet connection. This model allows apps to remain ad-free and utilize the internet connection to perform activities such as web indexing while using the television's internet connection as an alternative to advertisements. This model poses a security risk that goes beyond exposing the household IP address.
A smart TV is connected to a local network that includes routers, printers, cameras, and storage units.
It is possible for the TV to provide a path to other systems on a network if proxy traffic is permitted to reach private network addresses or if filtering mechanisms are not effective. Spur's analysis also observed different implementations of proxy SDKs that enforce these boundaries.
In the sample of Bright Data, restrictions were established for private and reserved IP ranges; however, comparable protections were not observed for the local versions of Massive and Honeygain/Oxylabs SDKs examined.
It is therefore necessary to rely heavily on filtering on the provider's end, customer screening, and abuse controls to prevent this type of misuse. The wider platform policies add another level to this problem.
While Amazon explicitly prohibits the use of proxy services for third parties, Roku has also been reported to restrict similar software. LG and Samsung previously did not institute a public restriction that would prevent proxy-enabled applications from using their TV platforms.
Instead of relying solely on store descriptions or permission prompts, the research involved an analysis of actual LG webOS and Samsung Tizen application packages.
A team of researchers analyzed the applications to confirm fingerprints associated with residential proxy SDKs, such as Bright Data, Massive, and Honeygain/Oxylabs components, and has denied the suggestion that proxy networks are intrinsically unsafe.
The data provider mentioned consent, customer vetting, and governance measures, whereas Massive stated that their network employs KYC checks, server-side controls, and consent checks.
In addition, Oxylabs said it implements filtering and local-network restrictions using both infrastructure and SDK-level controls. However, LG's issue is now more complex than the removal of individual applications alone.
Through its scheduled review of webOS apps, the company may determine whether residential proxy functionality is subjected to greater scrutiny during the approval process for the platform's apps.
As a result of this change, smart TV applications are also required to disclose background network activity and obtain consent for services that continue to operate after an app is closed.
It is LG's intention to take action on its planned plans that illustrates the need for clearer disclosures, stronger app review policies, and effective controls surrounding residential
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
Read the original article: