cross-posted from: https://lemmy.world/post/51634640

A new Gamers Nexus investigation found a retail LG TV actively scanning the local network for phones, laptops, smartwatches and other connected devices, while also capturing microphone audio when the screen appeared to be in standby. The investigation found voice data being stored locally even after the TV was disconnected from the network, with the queued data uploaded once connectivity returned. Researchers also uncovered webOS vulnerabilities that could potentially turn the television into a remotely controlled surveillance device. The really unsettling part isn’t just the advertising angle. It’s the fact that a consumer television can sit inside your trusted network, enumerate other devices, access a microphone, store collected data locally and communicate with external infrastructure. Put that same device in a corporate office, hospital, hotel or conference room and the security implications become considerably more serious. I went through the investigation in detail, including the network scanning, microphone behavior, ACR, webOS attack surface, offline data collection and practical mitigations

  • UnLocoPoco@lemmy.worldOP
    link
    fedilink
    English
    arrow-up
    4
    ·
    11 hours ago

    You CAN do this with a few products of diff companies with the help of home assistant and plugins BUT many companies are pulling off support OR restricting features to its own app and giving free access to the bare minimum voa protocols like matter and all. I read somewhere on reddit that a robovac company had matter access technically but only the vac on off switch access was there and none of the other basic functions. For that you need their app. But again, still some companies do support all it’s features on home assistant. Many light fixtures, switches, ACs and much more support it. So yes you can run them locally BUT it all depends on the manufacturer how much control they are willing to provide openly