Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If you root or jailbreak your devices, you've, by their very nature, broken their security.

> If he can demonstrate someone remotely jailbreaking your TV, or flipping on those settings without you knowing or doing anything to your TV, that would be a far more damning issue, in my view.

There are ways to remotely jailbreak LG webOS TVs without user interaction, using the same (or similar) vulnerabilities you use to root your own TV voluntarily.

The main reason tools like https://rootmy.tv are prefixed with disclaimers and require user interaction is because we're being courteous, not because they're technically necessary. (source: I own the rootmy.tv domain)

 help



Most of what I’m reading on rootmy.tv says the vulnerability it exploits has been fixed. So, if one were to keep software up to date on their TV, there is an improbably small chance it can actually be remotely jailbroken — am I reading this right?

The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining. There are also more up-to-date rooting tools beyond rootmy.tv.

The security posture of webOS is absolutely terrible, at least, it is in the way LG deploys it.


> The specific vulnerabilities exploited by rootmy.tv have been patched, yes, but there are plenty more unpatched vulnerabilities remaining.

But vulnerabilities that can be remotely exploited without user interaction (CVSS grade 9-10)?


Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.

I'm guessing that you're exploiting some sort of exploit (buffer overflow???) on the DVB-T demodulator

> only RF down the TV antenna input

Holy shit. RF to zero-click exploit is a new one. I guess digital-everything wasn't always a good idea, this probably wouldn't ever have been a problem with analogue antennas and CRTs.

What are the people at LG even doing?


Teletext was available in analogue times. So I could well imagine there to be a possible avenue of exploits with it too. Would take a bit of time, but I see no reason why wouldn't some data result in a incorrect handling.

Exploiting what? There wasn’t any software hierarchy for Teletext to escape from in analogy TVs. If you found a bug in the Teletext chip you couldn’t then go on to do anything to the TV set aside print different data to the screen. And since you’re already tuned into that radio frequency and controlling the data sent on it, you already have control of what’s sent to the TV screen already anyway so who cares?

As an aside, I once interviewed one of the guys who wrote Teletext processors for analog TVs. He was a very interesting individual.


> Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.

So no responsible disclosure, I see.

Not knowing any more details, it still sounds like you'd still need the user to tune to the actual frequency on the correct receiver (to cause some buffer overflow?). But then still there's no internet to do anything. So you'd need some very specific f/up exploit to then change local settings on the device I imagine.

Either way, would be a great opportunity to demonstrate this in a video, now that there's attention on the topic, to further amplify the pressure on LG's "terrible security posture" as you say.


> So no responsible disclosure, I see.

If I, a corporation, declare that I only accept security reports carved on clay tablets in ancient greek and hand-delivered to my office in Timbuktu during a total solar eclipse - does that stop responsible security researchers from disclosing their findings publicly?

Of course not.

If the guy sends a clear message to the best public contact address he can find with 15 minutes of searching; and gives them 30 days to patch before publicly disclosing the bug; then he's performed responsible disclosure.

The vendor's corporate policies and release cycles and contact addresses and triage procedures are their problem.


> So no responsible disclosure, I see.

If the manufacturers responsibly included a responsible way to install custom software/firmware, perhaps people would feel more inclined to help them. Their current attitude buys them very little goodwill.


> So no responsible disclosure, I see.

Huh?


You stated that you're "sitting on one that doesn't even require an internet connection [..] I'm waiting for my model to go EOL before I release it"

I read this as "Wait until the model is EOL, hoping it won't be disclosed and fixed until then and also not fixed afterwards"

Is this not what you meant to say?


Responsible disclosure makes sense when the user and the manufacturer have the same goal of the product being secure. Jailbreaking is a case where the user and the manufacturer have opposing goals: the user wants to be in charge their hardware, the manufacturer wants to prevent the user from being in charge of their own hardware. Responsible disclosure doesn't make sense, the manufacturer would just patch the vulnerability before users could use it.

If manufacturers had a sanctioned way for the user to get root access to their own hardware, responsible disclosure would've made sense, but as it is, vulnerabilities are a useful tool for the owner of the device.


Exactly. This control-freak nature of manufacturers is sadly what makes me cheer for the security holes much of the time.

Yet here we are, in this thread, discussing why LG is spying on us.

While some stuff are legit issues such as ADR, people now think they are wire-tapping. Because somebody used a rooted device to show-case recording silently through their device.

Can you blame corporations having this control-freak nature when shit like this happens?

It's stuff like this that likely pushes corporations now to invest more into device security, and locking down their stuff more.

Good for security and the corporation.

Maybe mid-term good for you consumer, because they might get more cautious with tracking stuff.

But long-term bad for you consumer, too, because they will make sure to lock down their devices better.


The best solution is obviously sanctioned rooting so that vulnerabilities can be freely shared with manufacturers and fixed.

But that's not going to happen.


The solution to misleading reports about your software isn't more opacity, though, quite the opposite. If they were transparent about what they were doing then there would be much less room for speculation and misleading reports.

(And yeah, as pointed out by another comment, if you officially allow users full control of their devices, you are less likely to have people sitting on undisclosed exploits so that they can get it without your help, and as a bonus you have an easier argument for why you are not liable for what someone does with that control)


> While some stuff are legit issues such as ADR, people now think they are wire-tapping. Because somebody used a rooted device to show-case recording silently through their device.

> Can you blame corporations having this control-freak nature when shit like this happens?

Is "shit like this" referring to the corporation spying on the user, or the user discovering it? Because one happened before the other, and so impossibly could have caused the former.

> It's stuff like this that likely pushes corporations now to invest more into device security, and locking down their stuff more.

Or they could just sell the device users want, and not sell their users.


To me as a user, responsible disclosure is most-valuable for every vulnerability that could be exploited remotely without me being in control.

The video draws exactly that picture, a nefarious actor, remotely taking control over my TV and recording Audio from it


To me as a user, responsible disclosure takes away my right to do what I want with my hardware.

This would be one way to interpret it. Another way would be: "If the model is EOL, the potential attack surface gets lower, because you cannot buy it any longer and the amount of devices in use will reduce over time."

On a different note: Are you, in any way, affiliated with LG? You read to me as someone who is "unhappy" with the findings.


The attack-surface doesn't get lower, it just doesn't continue to increase UNLESS the same vulnerability is not carried over to other products.

The attack-surface only gets lower when the TV is no longer in use and is disposed. That doesn't happen at EOL, customers don't suddenly throw away their TVs after 2 years.

I'm happy with the findings and hope that it gains momentum, but unhappy with the dilution of the matter with speculation, assumptions and sensationalism, because it allows the vendor to wiggle out of it and wait for attention to wind down.

I would prefer a clear spotlight to be shined on #1 the ad-networks business model of TV-manufacturers and #2 the security of their (very powerful) products.

If the process results in regulation which also requires the TV manufacturer to offer root-access to the consumer to verify and control its operations, I would be overjoyed.

But this is unfortunately not a subject of the current narrative at all, it will actually result in the opposite (more effort to lock-down the OS to prevent future sensationalism reporting)


Not disclosing a vulnerability you found to the manufacturer (while the product can still hopefully be patched) is “not responsible”. I think that’s what the person is trying to say.

It seems that some people do not appreciate the amount of labour that can be required to turn knowledge of a vulnerability into an actionable bug report. (Before someone says "ask an LLM to do it", LG has that option available to them, too)

It is certainly not work that I would do to benefit a many-billion dollar company, for ~free. I may do it to benefit device owners such as myself, instead.

LG is solely responsible for the security of the products that they choose to sell.


Looking forward to your writeup/talk/whatever. Root via analog(?) RF signal sounds amazing.

Why do you even ask? Why do you even think this is at all unlikely?

It doesn't even matter what exploits are publicly known and closed at any given moment. What we know is that at every given moment, no matter what security hole was just found and closed right now in some device, always later it turns out there were others not yet known by you but known and used by someone. This has been everything with an OS for 40 years. So yes, of course, right now, on every tv, and everything else, from any manufacturer, there are "grade 9-10" exploits just sitting there. It's the default state not some exception.


I read the documentation and it appears that the only reason it doesn't still work is because development was "postponed for a few months" back in 2021. Presumably there is still the possibility of exploits on the latest versions, it's just nobody's bothered yet.

why would I want to keep the software on my TV updated, it's a screen

It’s a whole computer that runs YouTube, Netflix, Amazon video, etc

I've never used a TV that way, that's the job of whatever is connected to the TV. But if you do use your TV like that, didn't those things work when you got it? Why do you need software updates?

I think you're being deliberately obtuse. You would update software on a TV for all the same reasons you update software on any other device: improved performance, better compatibly, new features, etc

No. My computer is a tool I actively use. The TV is an almost entirely passive consumption device. Was performance not good enough when it was new? If it wasn't, will the new software versions truly buck the trend we've seen in software for the past few decades and improve performance? What new features are necessary? Video playback has been a solved problem for the past few decades.

All of the software on a tv is a client to some service, and the service changes constantly, and so must also the client whether anyone likes it or not, and you already knew all of this perfectly well.

The author of the comment further up this thread seemed to suggest they use their television as a traditional television rather than as a host for several streaming service clients.

I think it’s quite reasonable with this framing to question frequent update cycles.

It’s likely you understand this well and have decided to argue something else for reasons unknown.


With streaming apps unfortunately you can run in compatibility issues if you do not update. So for people using the TV for streaming, it does make sense to at least update that part of the software.

And if a streaming app stops working due to a compatibility issue, I might consider updating if it's a streaming app I use a lot. If I can update the app independent of the OS, great; if not, it might mean an OS update.

These vulnerabilities only get fixed because they're used by public rooting tools. If blackhat hackers found them instead, kept quiet about them and used them carefully, they'd never be fixed.

> So, if one were to keep software up to date on their TV,

I presume LG is like most vendors and stops issuing updates for older models after a while. It's pretty hard to keep software up to date when the vendor stops issuing updates.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: