
LG Electronics says it is working with developers to strip residential proxy functionality from apps on its webOS smart TV platform, and will suspend any app that does not comply. The move follows research from threat intelligence firm Spur showing that 42% of scanned LG smart TV apps and 26.5% of Samsung apps contained proxy SDKs that can route outside internet traffic through a user’s home connection.
What did researchers find in LG and Samsung smart TV apps?
Researchers at Spur, a firm that specializes in detecting threats hidden behind VPNs and residential proxies, scanned 6,038 apps across the LG and Samsung TV app stores. They found 2,058 of those apps contained proxy SDKs, software development kits that allow an app to resell or relay internet traffic through the device on which it is installed.
Over 42% of LG webOS apps included the functionality. Samsung Tizen apps contained it 26.5% of the time. As described in the reporting, many of the flagged titles are low-effort utilities, including fish tank screensavers, clocks, solitaire, and simple games, that quietly turn the TV into a node for paying customers of proxy services.
How do residential proxy SDKs work on a smart TV?
Residential proxy services let paying customers route web requests through the home internet connections of ordinary users. Spur’s researchers explained that prompts inside the apps usually mention that the IP address and free resources will be used “to download public web data from the internet.” Some apps split the trade-off, offering an ad-free game in exchange for letting the app use the TV’s internet connection.
A one-time click on “Agree” is treated as consent. Once granted, the app can keep monetizing the connection for as long as it stays installed, even after the user closes it. The IP addresses of these TVs end up in the security logs of whatever sites the proxy customers choose to visit.
The researchers warn that the risk goes beyond borrowing a public IP address. If a proxy provider allows requests to private or local addresses, or if its filtering fails, “that TV becomes a foothold for reaching things that were never meant to be exposed to the internet: router admin panels, NAS devices, printers, cameras, developer machines, and other apps listening on local ports,” Spur said.
Smart TVs make ideal hosts for this activity. They stay powered on and connected around the clock, with no battery drain or cellular bill spikes to alert the owner.
Why is LG acting now?
Brian Krebs, the journalist behind Krebs on Security, reports that LG plans to suspend any app that turns a TV into a residential proxy node, because this is not the intended use for smart TVs.
“LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended,” the blog quoted John Taylor, Senior Vice President at LG.
According to the report, Cybernews could not find changes or mentions of residential proxies in LG’s developer documentation at the time of writing. The existing LG Privacy guideline directs developers to build apps around “Privacy by Design” and “Secure by Design” approaches, including requesting only the least privilege necessary for operation.
Who supplies the proxy SDKs?
Spur noted that only a handful of firms are responsible for the majority of proxy SDKs found in TV apps, and that many flagged apps behave like wrappers around shovelware games, screensavers, and other low-value utilities. The most frequently flagged SDK came from Bright Data, appearing in 367 proxy-flagged apps.
Bright Data pushed back on the characterization, telling reporters that consent is what separates a legitimate network from a nefarious one. “Bright Data built this framework for consented networks that are intentionally discoverable and therefore accountable. Our practices are scrutinized by independent auditors and security companies,” the company said.
Is proxying through consumer TVs legal or common?
Residential proxy services are not all bad. Legitimate uses include ad verification, SEO monitoring, market research, and brand protection. Responsible providers say they require explicit user permission and apply safeguards.
However, the same plumbing is attractive to criminal groups. Just weeks before the LG story broke, Google and the FBI disrupted a residential proxy botnet called NetNut that had hijacked more than 2 million consumer devices, including smart TVs and streaming boxes, for covert cybercrime and espionage. Earlier in the year, Google also shut down another residential proxy operation called IPIDEA. Cybercrime gangs can easily disguise their traffic by routing it through these residential nodes.
h2>
What are other TV platforms doing?
Amazon and Roku have already banned residential proxy software on their platforms, according to Spur. The researchers have urged LG and Samsung to follow suit.
Spur summed up the consent problem in a line quoted in the coverage: “Most people do not have a working mental model for what it means to sell access to their residential IP address.”
FAQ
What did LG say it will do about residential proxy apps?
LG Electronics told Krebs on Security that it is working with developers to remove residential proxy options from apps on the webOS platform, and will suspend any app that does not comply.
How common are proxy SDKs in smart TV apps?
According to research from threat intelligence firm Spur, 42% of scanned LG webOS apps and 26.5% of Samsung Tizen apps contained proxy SDKs, out of 6,038 apps scanned across both stores.
Which proxy SDK showed up most often in TV apps?
Spur flagged Bright SDK, from Bright Data, in the largest number of proxy-flagged apps: 367. Bright Data says its framework is built around consented, discoverable networks that are independently audited.
This article summarizes reporting from cybernews.com. See our editorial disclaimer for how our articles are produced.
Run a free scan to see your AI Visibility Score, SEO rating, and local citation accuracy.