LG Electronics USA to Suspend Smart TV Apps Utilizing Residential Proxy Nodes

LG Electronics USA announced this week its intention to suspend any applications built for its smart TVs that transform a user’s television into an always-on residential proxy node. This significant move by the home appliance giant comes less than a month after a comprehensive report revealed that a substantial portion of apps available on LG’s webOS store, specifically over 42 percent, were found to allow unknown third parties to route their internet traffic through unsuspecting users’ televisions. This discovery has ignited concerns about user privacy, network security, and the ethical monetization strategies employed by app developers.
The Unveiling of Residential Proxy SDKs in Smart TVs
The revelation regarding the widespread integration of residential proxy software development kits (SDKs) in smart TV applications first came to light on July 2nd, following in-depth research conducted by the cybersecurity firm Spur. Spur’s investigation meticulously examined the prevalence of these SDKs across various smart TV platforms. Their findings were particularly alarming for LG users, indicating that more than 42 percent of the applications available for download on LG smart TVs incorporated SDKs designed to indefinitely turn the user’s television into a proxy node. This means that the television’s internet connection could be leveraged by others to browse the web, potentially for activities that users themselves would not endorse.
The report further highlighted that the issue was not confined solely to LG. Samsung’s Tizen operating system, another dominant platform in the smart TV market, also showed a considerable presence of these residential proxy components, with over a quarter of its apps exhibiting similar functionalities. The graphic accompanying Spur’s research visually depicted the stark reality, illustrating the high percentage of apps utilizing proxy SDKs on both LG (webOS) and Samsung (Tizen OS) televisions, underscoring the systemic nature of this privacy concern.
LG’s Official Response and Enforcement Measures
In direct response to the findings presented by Spur, LG Electronics USA has taken a decisive stance. John Taylor, Senior Vice President at LG, communicated to KrebsOnSecurity that the company is actively engaging with app developers to address the issue. He stated that LG is working diligently to ensure the removal of the residential proxy option from their applications on the webOS platform. Crucially, Taylor emphasized that developers who fail to comply with this directive will face the suspension of their apps.
"A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor stated in his communication. "If this option is not removed, these apps will be suspended." This clear ultimatum signals LG’s commitment to rectifying the situation and safeguarding its users’ privacy and network integrity.
Taylor further elaborated on LG’s forward-looking strategy, assuring that the company is dedicated to preventing residential proxy networks from being integrated into its smart TV applications in the future. He confirmed that the company’s review process for existing applications is already "well underway." This proactive approach involves strengthening their evaluation mechanisms for all developer-submitted apps, with a specific focus on those incorporating residential proxy SDKs.
"As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor added in his emailed statement. This indicates a systemic shift in LG’s app vetting process, aiming to prevent similar vulnerabilities from emerging in the future.
The Monetization of User Devices: A Closer Look
The practice of embedding residential proxy SDKs is a monetization strategy employed by some app developers seeking to generate revenue from their creations. These SDKs, when integrated into an application, effectively transform the user’s device – in this case, a smart TV – into a residential proxy node. This node is then rented out to paying customers, who can utilize the user’s internet connection for their own online activities.
Spur’s research uncovered that these residential proxy SDKs were not limited to obscure applications. They were found bundled within a wide array of apps on LG and Samsung smart TVs, ranging from seemingly innocuous applications like classic games such as Pac-Man to essential utilities like screensavers and file management tools. This broad integration meant that a significant number of users were unknowingly participating in these proxy networks simply by downloading and using everyday applications.

The report specifically identified the residential proxy network Bright Data as a dominant provider, accounting for a majority of the proxy SDKs found across both LG and Samsung smart TVs. Despite repeated attempts to solicit comment, Bright Data did not respond to requests for clarification or statements regarding their role in this issue.
Industry Practices and Security Countermeasures
Companies like Bright Data, and others named in Spur’s report, typically assert that they adhere to stringent "know your customer" (KYC) protocols to verify the legitimacy of their service users. These services are often utilized for activities such as large-scale data scraping, a legitimate business practice for market research and competitive analysis. Furthermore, these proxy providers often claim to implement technological countermeasures designed to prevent their proxy service customers from interfering with or controlling other devices on the residential user’s local network. This is a critical point, as the ability for external entities to access and manipulate devices on a local network poses significant security risks, including potential data breaches and the spread of malware.
However, Spur’s analysis emphasizes that the core issue lies not in the existence of residential proxy networks themselves, but in their pervasive and often opaque integration into devices that consumers do not typically consider to be full-fledged computers. Smart TVs, unlike personal computers, are not devices that the average user routinely audits for security vulnerabilities or checks the background processes of.
Trevor Sutter, a representative from Spur, articulated this concern forcefully. "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Sutter wrote. He further highlighted the amplified risk when consent is obtained from individuals within a household who may not fully understand the implications of their actions, such as minors who might use the smart TV but are not in a position to grant informed consent for such a significant privacy compromise. The implicit consent model, where users agree to terms and conditions they may not fully read or comprehend, is a recurring theme in cybersecurity discussions.
Broader Implications and the Evolving Smart TV Landscape
LG’s commitment to removing these residential proxy SDKs from its app store is undoubtedly a positive development for user privacy and network security. However, this is not the only recent instance where LG has faced scrutiny regarding its software practices. The company recently drew criticism for its partnership with McAfee, which involved bundling McAfee security products via software drivers integrated into its high-end LCD monitors.
Earlier this week, the YouTube channel Gamers Nexus brought to light that certain LG LCD monitors would automatically install an application promoting paid McAfee antivirus subscriptions. This installation occurred through Windows Update without any explicit user approval prompt, raising questions about transparency and user control over software being installed on their devices. This incident, coupled with the residential proxy issue, suggests a broader pattern of concern regarding how LG is managing the software ecosystem on its connected devices.
The implications of these findings are far-reaching. For consumers, it underscores the critical need for increased awareness and vigilance regarding the permissions and functionalities of applications downloaded onto smart TVs and other connected devices. The blurring lines between entertainment devices and networked computers mean that the security and privacy considerations traditionally applied to PCs must now extend to the entire spectrum of internet-connected home appliances.
For smart TV manufacturers like LG and Samsung, it highlights the immense responsibility they hold in curating their app stores and ensuring that third-party applications do not compromise user privacy or security. The financial incentives for app developers to monetize through unconventional means, such as residential proxies, will likely continue to present challenges. This necessitates robust and proactive platform oversight, as well as a commitment to transparent communication with users about how their devices and data are being utilized.
The ongoing evolution of the smart TV landscape, with an increasing array of connected features and services, demands a parallel evolution in security and privacy standards. The actions taken by LG, while significant, represent a crucial step in an ongoing effort to build a more secure and trustworthy smart home ecosystem. The industry as a whole will be watching closely to see how these manufacturers continue to balance innovation with the fundamental right to user privacy and data security. The precedent set by LG’s response may well influence how other manufacturers approach similar issues, ultimately shaping the future of smart TV technology and its impact on consumers worldwide.






