11 ms·
This is so much worse that the title makes it out to be: 1. Your OS installs malware (technically manufacturers software) from a 3rd party vendor in backgrou
by devttyeu 3mo ago
This is so much worse that the title makes it out to be:
1. Your OS installs malware (technically manufacturers software) from a 3rd party vendor in background, zero user interaction
2. Happens as soon as you or anyone with physical access plug in a device into the HDMI port
3. That malware has internet and full system access, no sandboxing
4. It starts with every system boot
5. This software gets installed when you plug in a new LG monitor
6. OR ALREADY HAD AN OLDER LG MONITOR PLUGGED IN, BECAUSE LG APPARENTLY ROLLED THIS OUT FOR MANY OLDER MODELS TOO!!
7. And yes, if you think that's horrendous, as mentioned in the video below, that also applies to 'Professional' LG monitors!
This situation has.. no precedent as far as I can tell..
GamersNexus has a video diving deeper into what LG did here - https://www.youtube.com/watch?v=Q9uefFYe6bM https://www.youtube.com/watch?v=Q9uefFYe6bM
- herbst 3mo agoAs if the world needs more reasons to understand that windows is activly making your life worse. Step by step.
- embedding-shape 3mo ago> This situation has.. no precedent as far as I can tell.. Microsoft has been allowing this sort of ludicrous behavior for decades at this point, it's not a new issue. What's new is how visible LG made their malware, compared to previous auto-installs that happen like this, where they try to make the thing not so in your face, as they know there will be a huge backlash. I don't know what Microsoft is thinking even allowing and enabling this sort of thing, they've lost all touch when it comes to building things for users.
- MichaelZuo 3mo agoMaybe some decision makers do indeed have negative aspirations…
- joe_mamba 3mo ago>I don't know what Microsoft is thinking even allowing and enabling this sort of thing This has been a feature since Windows 7, and it worked great since it would pull all necessary drivers after installation without you going hunting on the internet like in the Windows XP days. Just that no HW manufacturer thought to push spyware in their driver repos at that point to improve some team's KPIs.
- coldtea 3mo ago>and it worked great since it would pull all necessary drivers after installation without you going hunting on the internet like in the Windows XP days. A driver shouldn't be a front-facing program that shows ads of any kind. It should be sandboxed and follow strict APIs to talk to the OS and that's it - any extra options should be shown inline in the main e.g. printer or mouse dialog.
- threetonesun 3mo agoAnd then what, ever single gaming mouse/keyboard config is going to appear in the Windows UI dialog? I think extra options in an app is fine, but you should have to download it. At which point who knows what you’ve opened yourself to but at least you chose to do it.
- solarkraft 3mo agoYes! Extra apps suck.
- VorpalWay 3mo ago> And then what, ever single gaming mouse/keyboard config is going to appear in the Windows UI dialog? Actually, why not? The driver could declare a list/tree of extra configurable options, and windows could generate a configuration dialog for them. I think this is already is thing in Windows for NICs, I remember seeing TCP offload options when I go into properties for a NIC in the device manager. You just need to make it a bit more accessible to non-tech users and with more modern control options such as colour wheels for RGB. And the Linux software for these sort of devices (when such software exist) don't tend to be as bloated. Usually the driver just exposes some control files under /sys and someone else builds a GUI or such on top. But there is no reason you couldn't also expose a schema that describes what the options do to make a more generic GUI for those.
- threetonesun 3mo agoAs a user I agree, but I think this misunderstands the Windows market. Forget about mice for a second, if you look at GPU drivers between Linux and Windows on Linux they... just work, and you can use some apps to modify exposed features, like you said. On Windows out of the box they kind of work, but you really need a manufacturer's software suite to take full advantage of them, and that software suite is, surprise, an advertising and analytics platform, a situation I think both Microsoft and the peripheral manufacturers are very happy with.
- ihsw 3mo agoIf you have been reading the news about Windows 11 then I will enlighten you -- they view the Windows 11 consumer business as a cost center that must be mitigated. As such, all manner of monetization has been approved and it will continued to be approved without regard for user experience. This article obviates that this is not an LG problem, it is a Microsoft problem. Also, don't fool yourself if you think this won't come to the Linux world.
- Grombobulous 3mo agoJust look at Microsoft’s revenue breakdown that they publish. Windows revenue is alarmingly small. I don’t think it’s a loss leader but Microsoft gets almost nothing from OEM Windows licenses and basically nobody buys it retail. This is not coming to the Linux world. The moment this sort of thing happens, distros get forked.
- geon 3mo agoAren’t ms completely dependent on consumer windows for mindshare? I doubt anyone would bother getting into programming with ms tech unless they just happened to run it on their desktop.
- eastbound 3mo agoMS owns Typescript and NPM and Azure and LinkedIn. I know you meant programming on Windows, but even if Windows disappears, many of us will owe our job to Microsoft.
- solarkraft 3mo agoThey own Typescript? I wasn’t aware that they control the organization, but that ought to be easy enough to fork. NPM is a bigger one, but also not too huge. Azure is only used by people who already have Microsoft/Windows buy-in.
- chuckadams 3mo ago
- Kelteseth 3mo agoIt is the same when you plug in a Logitech mouse nowadays, no? At least they don't install McAfee
- vladvasiliu 3mo agoI have a logitech mouse and I'm pretty sure I was asked whether to install the logitech app, it didn't do it automatically. Same for the dell mouse I have at work, it asked to install dell somethingorother, which I declined, and it left me alone.
- d_k_f 3mo agoAnecdata from two days ago, after installing a fresh Windows 10: after inserting the dongle, a definitely non-native (styled by Logitech) popup asks me whether I want to install their app. I decline. One reboot later, the app is available in the start menu. Edit: To be fair, I immediately uninstalled it, so I don't know if this was "just" a link to their installer app or the full app. But something definitely got downloaded and moved to a place I could not have moved it myself without accepting a UAC prompt m
- vladvasiliu 3mo agoYeah, the questions showed up in non-native dialogues in both cases. I installed the Logitech one, but not the Dell. But then again, even freaking Office looks non-native on Windows, so I don't really pay attention to this aspect.
- deleted 3mo ago[deleted]
- sigio 3mo agoI can only conclude that Windows is basically malware now... Thank $deity I haven't used any form of Windows for 10+ years anymore.
- bcraven 3mo agoThis is one of those typical HN replies that adds absolutely nothing to the discussion.
- Geezus_42 3mo agoMuch like your own, and this one!
- deleted 3mo ago[deleted]
- phikappa 3mo agoI wonder if this ritual of meta-self-policing serves some particular purpose or if it's just a case of the brain drawing comfort from going through a familiar ritual. "This comment adds nothing" is like the reverse amen in church of our days.
- pseudalopex 3mo agoThe purpose was to discourage comments which added nothing I thought.
- warshinder 3mo agoAnother example of context collapse. Meta-meta commenting always adds something if only unironically.
- Geezus_42 3mo agoI think it's just people who can't help but tell others how to live their lives.
- 3mo ago
- IshKebab 3mo agoUSB devices can also do this now. I have a Razor microphone which is otherwise a great device and requires no software to function. At soon as you plug it in to windows it tries to install some Razor crapware. It's not quite as bad because it's not silent and you can say no, but I'm pretty sure that's only because Razor decided not to be completely evil.
- Findecanor 3mo agoA few years ago, plugging in a Razer USB mouse made Windows download and run a installer from which the current user could start PowerShell with administrator privileges. Razer first tried to downplay the issue, but fixed it later. [1] The USB protocol does not have any authentication, just a VendorID/ProductID pair: 2×16 bits that Windows uses for looking up the driver package to install. Programming a MCU to use any VendorID/ProductID is straightforward. A USB device could even appear innocuous at first but after a timer or external trigger disconnect and reconnect masquerading as another device. 1. https://arstechnica.com/information-technology/2021/08/need-to-get-root-on-a-windows-box-plug-in-a-razer-gaming-mouse/ https://arstechnica.com/information-technology/2021/08/need-...
- globalnode 3mo agonot a usb programmer, but are you saying i can buy any old usb chip and program it with any vendors ID and spoof windows into giving me admin? if so, gj micrcosoft.
- nottorp 3mo agoYou can pretend to be any vid:pid with usb gadget mode. For example with a raspberry pi zero something. But you can't pretend to be any vendors id, only the ones with vulnerabilities. And the drivers or spyware will be downloaded by windows from the vendor's site, not from your peripheral. But yes, usb device identifier is done through software/firmware.
- ssl-3 3mo agoOh, it's worse than that. A USB attack-widget isn't limited to just one VID:PID pair. It can present itself as as hub with as many VID:PIDs behind it as is useful. (This isn't new or exotic functionality; the very first USB thumb drive I ever owned did this as a built-in, maybe 20 years ago.) So, for instance: A single physical widget can present as a thing that makes Windows install vulnerable software, and as a keyboard that issues commands hook that vulnerability, and as a storage device that provides a payload, while also [or ultimately] appearing as the fully-functional device that the user actually intended to use. Game over. The end-user might see a brief flurry of stuff happening while this goes on, but that's no big deal: End-users are already accustomed to seeing that kind of thing when new hardware is introduced, and clicking whatever button it is that they're required to click in order to proceed.
- Sharlin 3mo agoPerhaps no precedent in hardware, but it's basically the same as the good old Sony CD autoplay rootkit fiasco. Except this one runs in mere userland AFAICS.
- orbital-decay 3mo ago>This situation has.. no precedent as far as I can tell.. Printer, mouse, tablet and display tablet makers use this to insert their crapware since at least Windows Vista or Windows 7, I think. The last one I remember is plugging a Razer mouse just to watch it instantly pulling 1.5GB of bloated junk with "telemetry" exfiltrating the data from my gaming PC in realtime. At least it doesn't leave my mouse in a non-working state when I disconnect the internet, like it used to. Thanks, Razer! Microsoft is to blame here, really. They have a mechanism to block any vendor (supposedly to avoid reputational risks to their brand due to buggy drivers, at least that was their excuse back in the day), but aren't even using it to block these contraptions. Entire businesses are built on this, e.g. Razer is probably more of a marketing/data company now rather than a hardware shop.
- stego-tech 3mo agoThis. Microsoft has chosen to allow this functionality, despite it being a very clear breach of trust with customers. LG/Dell/et al should be shamed and blamed for even trying this shit in the first place, but it’s Microsoft who holds the blame for allowing such malware and spyware trash through their own update service.
- solarkraft 3mo agoYou’re acting like Microsoft aren’t pushing malware themselves.
- silverlimetea 3mo agoBuddy let me welcome you to the Internet where your phones and emails are literally listening to your microphone like it’s Watergate. It’s not unprecedented at all for Microsoft or anyone to download what amounts to spyware. The days of antivirus were replaced by advertising a long time ago. There is no privacy. Most savvy types are hyper aware of every process running on their machine especially those using network lol Kill the process or don’t by an LG. Everyone just uses Dell, or you’re rich and you get a Mac one. I don’t make the rules
- brynnbee 3mo agoSavvy types use Linux
- ikidd 3mo agoI've gotten to the point that if you're trying to show me something and I see you're using Windows, I just assume you're an unserious person and it's worthless. All the major tools for advanced work are Linux-based, and there's maybe a Windows version, but it's probably a kludge like Docker Desktop.
- delta_p_delta_x 3mo ago> All the major tools for advanced work are Linux-based No, they aren't. Linux hasn't yet got anything remotely close to PDB symbol servers and WinDbg's record-replay debugging. perf is... an attempt. Source: worked on Windows and Linux drivers and user-mode applications. Windows tooling blows the competition out of the water in actually advanced developer experience. Vim is cool to the ricing hackerman types but not people who actually earn salaries. Windows doesn't need Docker because it has a stable user-mode ABI.
- warshinder 3mo agoI know you’re joking, but there is a very small sliver of truth in there somewhere. There are some tools on windows that stand shoulder to shoulder with better os’s.
- coldtea 3mo agoAnd people think macOS sandboxing is "hyperbolic"
- halJordan 3mo agoUnprecedented? Have you installed a Dell/Alienware monitor recently? I hope you enjoy having the unsigned awcc.exe autostarting with no visible ui doing good knows what with no documentation from Dell
- jms703 3mo agoYeah, I was looking for this comment. Dell/Alienware have been doing this for YEARS. Part of the many reasons I moved from Window to Linux.
- mcv 3mo agoIs Linux certain to be safe from this sort of thing? I used to use lots of Dell monitors. Are there any brands that are known not to do anything like this? I'd like to reward them with my patronage.
- vanc_cefepime 3mo agoI would like to know too. I purchased a OLED Alienware monitor back in 2022 when they first came out. Ive had a Linux/Windows dual-boot system but around 2023-24 I erased my Windows partition. My uneducated guess is that it would be pretty difficult for something like this to autoinstall on linux without your permission. They can "recommend" you to install their app, but just plugging it and getting adware/malware, I hope it would be difficult. Unlikely for any brand out there not to do this. Samsung will do it eventually if backlash isn't bad with this one with Alienware/Dell/LG. Maybe Benq, viewsonic, monoprice? I dont trust Asus not to do it either. I have a LG TV and never connect it to Wifi. Never did I think just plugging in a HDMI cable would do this.
- frollogaston 3mo agoLinux doesn't go install software just because you plug in a certain peripheral, so yeah. Same with Mac. This isn't even an attack, Windows is doing it intentionally.
- beAbU 3mo agoLogitech pulls (pulled?) the same shit when you connect one of their pheriferals to your PC.
- dathinab 3mo ago> This situation has.. no precedent as far as I can tell.. depending on how you look at it it has quite a bit of precedence as this falls under a long list of MS shipping "intended behavior most security researcher would assign a CVE and require it to be fixed as min. requirement for Windows usage in any company" other wtf. microslop cases include: - "install arbitrary software w. admin rights hooks" in BIOS which theoretically is there to install BIOS update software but there had been cases of 1. it installing other unwanted software, 2. the updater not fulfilling most minimal security standards (i.e. similar, due to 2. maybe even worse then the monitor case) - "on boot without password requirement boot arbitrary stuff from a USB stick if correctly named" allowing a trivial bypass of TPM based full disk encryption, yes different thing but another "MS without authentication runs potentially harmful 3rd party software" - "init scripts on USB devices", I think they stopped doing that - ... given that Microsofts security researchers are definitely _not_ incompetent idiots, you can safely assume that all of this features where implemented knowing what user hostile hazards they are and against their own security teams recommendations (or bypassing that team knowing they would say "wtf. no", or similar) most absurdly MS has in all of this cases enough means to enforce a "just drivers no ad-ware/spy-ware or you get banned" policy, and could do it in a way where they still allow non-allow-listed/ban-listed hooks to be run iff the user consented to it with appropriate warnings and "remember this decision" functionality in case they say no (which besides other aspects might be relevant from a "not steeping onto anti-trust landmines" POV, through mostly older judgements as the US kinda moved from hindering oligopoly to pushing for it). combine that with the huge f*-up of Azure in the past and their systematic mishandling of it, and no indication they will change this behavior, I really don't understand how any Company/Government agency could trust them
- DrJaws 3mo agothis has happened to me with dell monitors since years ago, also with razer peripherals.
- deleted 3mo ago[deleted]
- orblivion 3mo agoThank you for the summary. As a Linux user, am I spared because of relative obscurity, or is it that Microsoft is explicitly allowing this to happen?
- preisschild 3mo agoLinux only auto-loads the drivers in the kernel tree
- xahrepap 3mo agoI have a windows computer that tries to install HP Printer software automatically because it detects an HP printer on the WiFi. No physical access needed
- formerly_proven 3mo ago> This situation has.. no precedent as far as I can tell.. No, this has been going on for years. Vendors have been pushing malicious software through the Windows Update automatic driver installation since forever. MSI and Nahimic/A-Volute (this has watchdog daemon to instantly reinstall it as well as the main app protecting the daemon), the ASUS Armory Crate bullshit, the Lenovo garbage, which initially they only put into their own images, but then started force-installing via Windows Update, Gigabyte, ... the list is really long. If you have to use Windows, you really absolutely should disable driver installation through Windows Update.
- internet2000 3mo ago> This situation has.. no precedent as far as I can tell.. You got a lot of replies already, but there's so much precedent. Plugging a Logitech mouse installs a network capable, autolaunch capable, pop up app for at least the past 10 years. LG's thing seems grodier, but this has been common Windows-ism for a while.
- fuzzfactor 3mo agoPlus even when the Logitech mouse has been moved to a different PC, the former PC will continue to get Logitech updates anyway. Apparently so they will be one step ahead of you in case you decide to plug it in again sometime. Graphics cards can do this too, you remove the card and go back to the motherboard's built-in HDMI port, then one day here comes a big update for the non-existent graphics adapter.
- phendrenad2 3mo agoI'm tired of everything being classified as "malware". The word has no meaning anymore. Malware can mean "zero-day state-sponsored ransomware attack" or it can mean "software was automatically installed by a trusted consumer-beloved company because they forgot to make an opt-out window" (which is what I'm guessing happened here).
- hangrybear666 3mo agoLG hardware laying dormant for sometimes 3 years, then installing software through backchannels silently to record your voice continuously (if the monitor has a microphone, which some models do) and taking screenshots of your monitor content every 500ms, uploaded to their servers and likely shared with data brokers and the government qualifies as malware in my book.
- phendrenad2 3mo agoAre you thinking of some other malware? There's nothing in the article that mentions ANY of those things. And considering you made your account 2 days ago, I wonder if you hallucinated it. :)
- account42 3mo agoMalware was always an overarching term for all kinds of unwanted software, there is no definition being widened here. The only thing that has changed is how much malware "reputable" corporations are shipping to their customers.
- Someone 3mo ago> This situation has.. no precedent as far as I can tell.. - https://support.microsoft.com/en-us/windows/hardware/drivers/automatically-get-recommended-and-updated-hardware-drivers https://support.microsoft.com/en-us/windows/hardware/drivers...: “Windows can automatically download recommended drivers for the hardware and devices connected to a system by using Windows Update“ - eight years ago: https://www.reddit.com/r/Windows10/comments/8tlre3/why_is_it_so_hard_to_stop_windows_10_from/ https://www.reddit.com/r/Windows10/comments/8tlre3/why_is_it...: “I can't seem to stop it from installing device drivers, even after unchecking the 'Do you want to automatically download manufacturers' apps and custom icons available for your devices?' and saving. I uncheck it, reboot. Uninstall all drivers except USB (so I can use mouse and keyboard) and reboot. Aproximately two minutes after the reboot, I get notification ballons telling me everything is installed again. Heck, even the super old Nvidia 388.1 driver is installed (the latest now is 393.2).”
- bravo777 3mo agoHave you been using Gentoo or FreeBSD for a long time and then suddenly remembered Windows exists on the same day this news dropped?
- stockmarketer 3mo ago>This situation has.. no precedent as far as I can tell.. I want to believe you, but somehow I can't, I feel like our industry has already mastered the art of installing malware on customers' devices.
- miki123211 3mo ago8. ANd this isn't specific to LG. If LG can do it, anyone can, even if they aren't right now. Buying from companies you trust isn't a solution either. Founders sometimes get into fatal car accidents or lose some of their assets in messy divorces. THe new owners may not care about "brand reputation" and sell the company to the highest bidder.
- jakzurr 3mo agoThanks - really got my attention. And, the video makes me sick. I'm still looking at my 10 year-old LG monitor with suspicion, now, but I'm thinking (hoping) it's just too old...
- wnevets 3mo ago> OR ALREADY HAD AN OLDER LG MONITOR PLUGGED IN, BECAUSE LG APPARENTLY ROLLED THIS OUT FOR MANY OLDER MODELS TOO!! Just think about how many times hardware manufactures told customers to buy new equipment because they can't be bothered to patch the older models.
- greggsy 3mo agoLogitech have been doing this for years
- tomaskafka 3mo agoI understand shitty brands want to do this. The bit I don’t understand is Microsoft making an infrastructure that allows this, lets shine the shame light here.
- theamk 3mo agoHave you installed Windows recently? It is full of ads. If Microsoft can push ads to users, why can't LG?
- theamk 3mo agoThat's just living in the Windows world. After start menu ads, I don't understand why people are being surprised anymore.
- hulitu 3mo agoBut thanks to Secure Boot, your computer is secure. /s When will people understand that malware is signed by the vendor ?
- sixothree 3mo agoIf this were a person doing this, they would be in jail.
- mcv 3mo agoCompanies consist of people.
- chrisjj 3mo ago> Your OS installs malware Malware??
- TacticalCoder 3mo ago> 1. Your OS installs malware ... Your OS is malware. We're talking about Windows here.
- lofaszvanitt 3mo agoIn your mind. Average joes do not even know there is a firewall in windows, which is off by default. Actually none of the games, not even chrome respects the built in Windows firewall. If you have configured a firewall, it will make your life much harder, since almost nobody designs software based on the assumption that a firewall will exist. So almost everyone flies without one.
- whateverboat 3mo agoHow can HDMI affect the host computer?
- Gigachad 3mo agoBecause Windows is cooperating and installing the malware on behalf of the OEM. This kind of exploit could not be done on MacOS or Linux.
- 1vuio0pswjnm7 3mo agoLG Electronics display monitor as Trojan Horse Except this Trojan Horse isn't offered for free
- port11 3mo agoAnd the old horse you had lying around might also become Trojan now. Yuck.
- raggi 3mo agothere's tons of frustratingly equally bad precedent. for some reason it also seems like a lot of this companion software from oems is often written by part time contract / interns. years ago there was a classic example of iirc a logitech mouse driver that was writing the coordinate position of the mouse at ~100hz to the registry. microsoft should be applying _at least_ app store level / whql level rigor to these, but it seems if the oem is large enough they'll just gladly yolo a 2gb package of crap onto your machine because the oem said "this our driver package"
- surcap526 3mo ago[dead]
- m463 3mo ago> no precedent the asus bios will automatically install armoury crate on a clean windows install in the bios: advanced -> armoury crate -> install armoury crate -> enabled (by default)