3 ms·
It's shocking how many comments here didn't bother to read the article. At all. They're not talking about putting the TV online. The TV is completely offline.
by fckgw 1mo ago
It's shocking how many comments here didn't bother to read the article. At all.
They're not talking about putting the TV online. The TV is completely offline.
They're talking about plugging the TV into a PC or laptop via HDMI or Displayport (like if you're running an HTPC), which then triggers a companion app update on the PC via Windows Update. This was a news item a few weeks ago with their monitors. They then also discuss a hardware blocker for HDMI or DP to prevent this.
Again, this has nothing to do about the TV's smart apps.
- beloch 1mo agoI was unaware of these side-loaded malicious apps until now. This is information consumers need to have. It's very reminiscent of Sony putting rootkits on CD's. Unwanted, dangerous software is being loaded onto your computer by people you paid money to. The companies involved, including MS, should face serious blowback over this, as Sony did.
- spicyjpeg 1mo agoThis isn't even the worst payload ever delivered through Windows Update. The prize for that should probably go to chip manufacturer FTDI, which once abused the system to publish a driver that would semi-permanently brick USB serial bridge parts the driver detected as counterfeit [1] by exploiting a command that the genuine parts did not implement correctly (how ironic) [2]. The backlash was large enough that Microsoft ended up pulling the update almost immediately, but that did not stop FTDI from trying again a few years later with another driver update that deliberately corrupted data sent through detected-counterfeit parts. [1] https://en.wikipedia.org/wiki/FTDI#Driver_controversy https://en.wikipedia.org/wiki/FTDI#Driver_controversy [2] https://github.com/therealdreg/ftdibrick#diving-deep https://github.com/therealdreg/ftdibrick#diving-deep
- Henchman21 1mo agoIt’s almost like money gives some people the idea that being a cunt is 100% ok so long as you get your money.
- NuclearPM 1mo agoIt’s very annoying when people start sentences with “it’s almost like”.
- Henchman21 1mo agoDefinitely an overused phrase online. Yet, absolutely appropriate. It’s almost like I’m a native English speaker or something. ;)
- ryandrake 1mo agoIt's about time some company was prosecuted under CFAA for this kind of abuse. This should easily fit the legal definition of "intentional unauthorized computer access." But we all know, the law is enforced aginst regular people, not corporations. Are corporations ever prosecuted for invoking something on a user's computer without their authorization?
- godelski 1mo ago> I was unaware of these side-loaded malicious apps until now. This is information consumers need to have. I really want to ask, earnestly, how do we communicate these things earlier? I don't think there's a shortage of HN users that one about this type of bullshit going on. I'm not going to tell you "I told you so", and I'll even attack those that do. But when people who are concerned with these types of issues talk out they get dismissed as being conspiracy theorists or simply too sensitive. I'll admit that sometimes it can be hard to differentiate, but well respected experts in the tech field have discussed such issues for decades. So I really do want to understand, how do we reach you earlier? Before we get to this point. How do we not just come across as uppity tech nerds screaming "I use arch btw" in furry programmer socks? I really do think we as a community need to figure out how to reach the public better. We're well past what was considered terrifying in 1984. We aren't a society where big brother could be listening to you at any time, we are living in a society where uncle Mark is watching you all the time. Where uncle Pichai knows who all your friends are. Where uncle Nadella knows when you're awake. They know whose been bad and good but they don't even have the decency to deliver gifts under the Christmas tree. Are we only fighting back because their actions have become so obvious? Or are we fighting is the principle enough?
- M95D 1mo agoYou're talking as if most people care... They don't. My father can't read any emails I send to him because his inbox is drowning in ads. A coworker ask me to fix her phone where apps crashed all the time. It was full with hundrds of apps I never saw before. The generation born 2010+ doesn't even know what privacy is. "Files" and local storage are alien concepts. This is the state of the world today. So, communicate earlier to... ? people that already know and never connected their devices in the first place? Or maybe people that are "concerned" but unwilling to take the usability hit that true privacy implies? Like this guy that still has his Windows connected to the internet and then act shocked when he finds out just what exactly those 50+ background services do?
- godelski 1mo ago> You're talking as if most people care... They don't. I think most people do care > My father can't read any emails I send to him because his inbox is drowning in ads Seems like evidence your dad cares > A coworker ask me to fix her phone where apps crashed all the time Seems like you're coworker cares Don't confuse a lack of understanding with a lack of caring. We're on a site full of nerds, the metrics are different here
- abruzzi 1mo agoIts not entirely clear from the article--is the EDID telling Windows to install the driver without asking you, or is it prompting you to install a driver, you are agreeing, then along with the driver comes the junkware?
- fuzzzerd 1mo agoWhile that is an important distinction, the fact you might need a downloaded driver for a screen is a bit ridiculous to begin with.
- DANmode 1mo agoYou do not.
- Mindwipe 1mo agoThe EDID is just a model identifier and some capability metadata, it can't tell Windows to do anything. It's Windows that decides that it should download a driver from Windows Update because it recognises it hasn't got a driver from that hardware, and it's Microsoft that let the vendor submit drivers that are bundled with near malwareto Windows Update.
- warkdarrior 1mo agoThat is how you end up with walled-garden OSes. Users plug in random device into their computer, the OS vendor tries to simplify operation by installing a device driver that was not vetted, and then users complain they are not protected. Then the OS vendor will start limiting which devices they support and with very strict review processes.
- drfloyd51 1mo agoThis is a fair trade off for many. I want my OS to protect me. All things being equal, if my OS doesn’t help shitty vendors install unwanted stuff… good. It can swing the other way, my options are limited to company’s that pay my OS provider for access.
- garciansmith 1mo agoYeah, previous discussion about this issue with LG monitors and TVs is here: https://news.ycombinator.com/item?id=48956688 https://news.ycombinator.com/item?id=48956688