4 ms·
Stop hooking up your LG: https://www.theverge.com/tech/967983/lg-monitors-mcafee-adware-gamers-nexus https://www.theverge.com/tech/967983/lg-monitors-mcafee-adw
by 5kg 2mo ago
Stop hooking up your LG: https://www.theverge.com/tech/967983/lg-monitors-mcafee-adware-gamers-nexus https://www.theverge.com/tech/967983/lg-monitors-mcafee-adwa...
- ahartmetz 2mo agoFine with Linux though :) LG's behavior isn't fine, but their monitors don't install crapware on Linux.
- drnick1 2mo agoAnother win for the Linux security model (software installed and updated manually from vetted repos only).
- krige 2mo agoSurely you mean Linux security model (not relevant enough to be targeted by big tech)?
- dns_snek 2mo agoIt's not a weakness that they targeted and exploited, it's a feature that was purposefully implemented by Microsoft.
- krige 2mo agoIf you're trying to say that Microsoft implemented a method of delivering specifically malware executables to every PC, I've got a bridge to sell to you. Let's not diminish LG's part in all this.
- dns_snek 2mo agoNo, what I'm saying is that Linux isn't safer simply because "it's not relevant enough to be targeted", it's safer because it doesn't offer mechanisms which could be abused to do this. Nobody is diminishing LG's blame, LG is guilty of installing malware, and Microsoft is guilty of being grossly negligent and facilitating it. Microsoft implemented this feature knowing that it would eventually be abused for something like this, and it's bad enough to be indistinguishable from malice.
- trelane 2mo agoFamously, the Linux kernel does not have a stable ABI for drivers. As a result, by far the majority of drivers are in-tree, maintained by the kernel folks as part of the kernel. The Linux approach has the downside of not having the drivers if a vendor has not been working with the kernel community before launch (or for those who haven't upgraded to a kernel that has the driver, e.g. a LTS release). On the other hand, the driver is maintained by kernel developers, not created by the hardware developer who is not getting paid after they sell the device. This helps avoid abandoned / vulnerable drivers, or having the hardware dev search for... alternative revenue streams, as in this case.
- gblargg 2mo agoWait, you're saying a monitor can just advertise a URL over the video connection for its driver and then Windows will blindly install it, without user confirmation? I thought that LG had submitted these "drivers" (adware) to Microsoft and they approved it.
- bayindirh 2mo agoI believe you register your device with Microsoft so Windows can automatically obtain and install drivers for them when they are plugged in. What LG sent in for installation is not a simple .inf or .sys/.dll file. They sent in a whole bag of software which does all the nasty things, and Microsoft doesn't vet or care about the software installed as the "driver" of the hardware.
- debugnik 2mo agoThis is actually a feature of the .inf by design, an AddSoftware directive. It can even link to apps from the store instead of bundling them with the driver. This is designed to install settings panels like the ones for GPUs. https://learn.microsoft.com/en-us/windows-hardware/drivers/install/inf-addsoftware-directive https://learn.microsoft.com/en-us/windows-hardware/drivers/i... I guess that from Microsoft's perspective, the driver itself wasn't suspicious, but it installs a questionable sidecar app they would have never vetted anyway.
- ssl-3 2mo agoEh? No. It's just a device attached to a computer. But in a Plug-and-Play world, its addition is noticed by the operating system -- as has been normal for decades. Microsoft's Windows operating system sees this new hardware ID and then goes forth to install whatever-the-fuck software it associates with that identification, presumably as a service to the user. (Did Microsoft approve it? Dunno. I'm just over hear eating popcorn.)
- gblargg 2mo ago> Eh? No. That's what I thought. It is vetted software, just like on Linux. Microsoft just doesn't care if it shows ads.
- delta_p_delta_x 2mo ago> Another win for the Linux security model I swear, OSs have become sports teams. Linux's 'security model’ has plenty of holes. The very fact the kernel and much of its user-mode is written in C almost guarantees that its security model is worthless. The Linux ecosystem operates on trust and respect that can and has been easily abused by bad actors to provide supply-chain pwnage. There have been so many zero-click local privilege escalation CVEs I've lost track. Arch Linux AUR malware: https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/ https://lists.archlinux.org/archives/list/aur-general@lists....
- silver_silver 2mo agoAUR is an effectively unmoderated user repo. It’s not Arch Linux’s core repository, nor is it enabled by default or indeed even possible to use without manual downloads from outside the package manager.
- benj111 2mo agoThere's still a security there though. You have confidence you are actually downloading the same foo as everyone else. And if there were an issue there would be pushback. Not so if you get some random exe from warez.com Yes it isn't perfect, it's still a lot better than windows land.
- opan 2mo agoI think you can probably find a better example, even if less recent. The AUR is unofficial and not properly vetted in the same way as the actual Arch repos, Debian repos, etc.
- dns_snek 2mo ago> Linux's 'security model’ has plenty of holes. Implementation bugs are not holes in the security model. Linux has plenty of those, as does Windows. Windows security model trusts, downloads, and immediately executes arbitrary software when a new untrusted device is plugged in, without asking the user.
- voidUpdate 2mo agosudo dkpg -i FileYouDownloadedFromAnywhere.deb
- mDyJzDPmBdG 2mo agoLet's be real, in most cases it is: curl -s script.random-guy.net | sh It is such glaring security hole that there was an old submission about filling such install script with `sleep` commands and detecting it on server side, to send different versions for downloading (and reviewing) and for actual direct execution.
- tosti 2mo agoI use those scripts to improve the likelyhood it'll fail to do anything useful. I even used uname as a fuzzing tool, and that broke builds spectacularly. There's now a more reasonable uname in the sandbox for builds.
- redeeman 2mo agothe method you describe is clearly only done by people that are irresponsible and most probably stupid. and no, this is not how most software is installed
- amiga386 2mo agowget https://raw.githubusercontent.com/timofurrer/russian-roulette/master/russian-roulette -O - | sudo bash
- iso1631 2mo agomost of my machines use unnatended-upgrades Increasingly software is distributed by "curl dodgysite.com/get.sh|sudo bash -", no different to running "install.exe" on windows Surely Windows Update is a vetted repo as much as arch or debian
- lostmsu 2mo agoNah, install.exe must be signed by a certificate authority or you get 10 prompts, and they do revoke certificates.
- drnick1 2mo ago> Increasingly software is distributed by "curl dodgysite.com/get.sh|sudo bash -" I don't think this is the norm at all. I have seen curl/bash install scripts for tools like Claude Code, but they don't use sudo, and the expectation is that you deploy them in isolated user accounts or containers.
- zen928 2mo ago> the expectation is that you deploy them in isolated user accounts or containers. Why are you lying right now? This is a norm across the dev tools world for businesses to distribute dodgy curl piped to bash scripts that users install without question, popular examples: homebrew, docker, nvm, bun, deno, k3s. There is zero "expectation" given by any of these install scripts that they are isolated. Can you even find a single source online that suggests doing what you said for you to think its a commonly held expectation?
- drnick1 2mo ago> Can you even find a single source online that suggests doing what you said for you to think its a commonly held expectation? Isn't it common sense? Do you want coding agents to read and possibly upload somewhere the contents of your home directory? Also, the expectation on Linux is that you install tools like Docker from the distro's repos.
- iso1631 2mo ago
- ChocolateGod 2mo ago> software installed and updated manually from vetted repos only So something most desktop Linux users don't do.
- windward 2mo ago'desktop Linux' is a term used when the majority of Linux users don't support your argument.
- benj111 2mo agoAre you disputing that the repos are vetted or that users use them???
- graemep 2mo agoVirtually all desktop Linux users do. The biggest exception is AUR as its not vetted.
- preg_match 2mo agoI would say 95%+ do just this. The Debian, Ubuntu, and even Fedora repos are very large and include all the software you could ever want. And then flathub takes the rest. It’s really only arch with the AUR and some others where completely untrusted packages are used. This is legitimately a better model than what windows does, although Microsoft has been trying to change this with winget.
- deleted 2mo ago[deleted]
- meta-level 2mo agoyet? I guess with more and more consumer devices running Linux based OSes (SteamOS, Android, Bazzite, Silverblue, ..) that becomes more and more interesting. And unfortunately the "I'm safe on my non-windows-system" argument doesn't count for long, as the 99% muggle crowd justifies a shift to a world where our non-certified (=> 'insecure') systems are not supported by big companies anymore, as it's currently happening on Android.
- Gigachad 2mo agoThe LG scandal specifically relies on the fact windows will auto install OEM crapware as soon as you plug it in. No other OS does that.
- rconti 2mo agoHuh? What does WebOS have to do with windows?
- smackeyacky 2mo agoLG monitors not TVs
- ahartmetz 2mo ago"Fortunately", agent Poettering is on the case, implementing remote attestation for Linux so we can all be secure. Barf.
- TeMPOraL 2mo agoThe monitors aren't installing anything. That headline was a lie. It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs. That's why the problem affected older monitors too - it's the update side that suddenly started to ship malware.
- felooboolooomba 2mo ago> That headline was a lie. Kinda agree but let's call it "misinformed" or something, instead of a lie.
- fauigerzigerk 2mo agoI would say it's neither a lie nor misinformed. It 's a punchier headline that can be justified by what the user experiences. The user connects a monitor which causes ads to appear. The rest of this Rube Goldberg contraption is a mere detail.
- TeMPOraL 2mo agoThose details are the only thing that matter. Without them, all you have is superstition.
- fauigerzigerk 2mo agoI disagree. It matters that LG makes ads appear on their customers' screens as a deterministic consequence of connecting one of their monitors. It's not superstition. Of course the details are important on some level. But that doesn't make everything else not matter and it doesn't turn an incomplete explanation into a lie.
- TeMPOraL 2mo agoThat's my point: it's not a consequence of connecting a monitor. An external element is making it look like such. This difference tells you that, for example, you cannot fix the problem by fixing the monitor, because the problem does not exist in hardware. It's actually entirely external to the hardware you own, because it exists entirely "in the cloud" (i.e. on MS and LG servers).
- lovich 2mo agohttps://youtu.be/Q9uefFYe6bM https://youtu.be/Q9uefFYe6bM A tech YouTuber showing this off and all the anti consumer behavior. I’m assuming this threads article is for an LG PR piece trying to redirect anger at the app developers to hide the fact that they are engaged in the same behavior themselves.