Tech

Why LG is banning residential proxies from its smart TV apps

Hacker News55 min ago
A smart TV remote control in a dimly lit living room
A smart TV remote control in a dimly lit living roomPhoto: Jakub Zerdzicki / Pexels

Smart TVs are no longer just a tool for watching content — in some cases, they are being folded, without their owners' knowledge, into large-scale proxy networks. LG is preparing to address the problem by blocking the use of residential proxy services within its apps.

Residential proxy services are tools that let users route internet traffic through real home IP addresses. The technology has legitimate uses — marketing firms comparing prices, or researchers testing geographically restricted content, may rely on such services. But the same technology is also highly attractive for abuse: cybercriminals have found that residential IP addresses are viewed as far less suspicious by security systems than data-center IPs.

Where these proxy networks source their IP addresses is the crux of the problem. Some services operate with users' explicit consent, typically after users agree to share their bandwidth in exchange for a free app or service. Others, however, collect IP addresses through malware or hidden software development kits (SDKs) embedded in devices without the owner's knowledge.

Smart TVs have become an especially vulnerable target for this abuse. Many smart TV apps contain code from third-party ad networks or analytics tools, and some of that code can quietly turn a device into a proxy node without the user's awareness. Because televisions are typically always on and connected to the internet, they make ideal, low-profile targets for this kind of abuse.

LG's ban involves scanning every app in its app store for code signatures associated with known proxy service providers. When such code is detected, the app developer is asked to remove it, or the app is pulled from the store entirely.

Security researchers welcome the move but stress it does not solve the problem at its root. Proxy providers continuously alter and obfuscate their code to evade detection, creating an ongoing cat-and-mouse game. Even if LG's scanning is effective today, it could be circumvented tomorrow with a different obfuscation technique.

For consumers, the practical takeaway is the importance of caution when downloading smart TV apps. Experts note that apps downloaded from unofficial sources, or those requesting an excessive number of permissions, may carry a higher risk of unknowingly folding a device into a proxy network.

The problem is not unique to LG — similar risks exist across the broader smart home device ecosystem. Routers, IoT devices and even smart speakers have previously been counted among devices folded into similar proxy networks. That reflects a broader trend in which consumer electronics manufacturers are increasingly expected to take responsibility for preventing their devices from being abused.

Cybersecurity experts recommend that manufacturers build this kind of scanning into an ongoing app review process, rather than treating it as a one-time audit — continuous monitoring, rather than a single check. That raises the likelihood malicious code is caught before it reaches the app store.

LG's move is seen as a sign of broader awareness within the smart home device industry: consumer devices now carry a risk not just to their own users, but potentially of becoming part of global cybercrime infrastructure.

This article is an AI-curated summary based on Hacker News. The illustration is a stock photo by Jakub Zerdzicki from Pexels.

Read next