LG Electronics USA to Suspend Smart TV Apps Utilizing Residential Proxy Nodes

LG Electronics USA announced this week its decisive action to suspend any applications built for its smart TVs that transform user devices into always-on residential proxy nodes. This significant move comes less than a month after independent research revealed a widespread issue: over 42 percent of games and other applications available on LG’s webOS store were found to be allowing unknown third parties to route their internet traffic through unsuspecting users’ televisions.
The revelation has sent ripples through the smart home and cybersecurity industries, raising critical questions about user privacy, data security, and the ethical responsibilities of device manufacturers and app developers. LG’s swift response signals a commitment to addressing these concerns and safeguarding its customer base from potential misuse of their home network resources.
The Discovery of Pervasive Residential Proxy SDKs
The issue first came to light on July 2nd, when the cybersecurity firm Spur published a detailed report examining the prevalence of residential proxy software development kits (SDKs) within smart TV applications. Spur’s investigation, which meticulously analyzed the app ecosystem for both LG’s webOS and Samsung’s Tizen operating systems, uncovered a disturbing trend. On LG smart TVs, more than 42 percent of downloadable apps incorporated SDKs that effectively turned the television into a persistent proxy node, allowing external entities to utilize the user’s internet connection. Samsung’s Tizen OS was not entirely immune, with over a quarter of its apps exhibiting similar residential proxy components.
These SDKs, often bundled with seemingly innocuous applications like games, screensavers, and utility tools, function by allowing the user’s internet connection to be rented out to paying customers of proxy services. These customers can then route their internet traffic through the user’s home network, masking their own online activities and potentially engaging in activities that could be misattributed to the TV owner.
Spur’s Findings: A Widespread Vulnerability
Spur’s research detailed the specific SDKs involved, highlighting the significant reach of this practice. The image accompanying their report visually represented the prevalence, indicating that for LG’s webOS, a substantial majority of examined apps contained these proxy functionalities. For Samsung’s Tizen OS, while the percentage was lower, it still represented a significant portion of the app marketplace.
The implications of these findings are far-reaching. Residential proxy networks are often used for legitimate purposes, such as market research, competitive analysis, and content scraping for academic or business intelligence. However, the ease with which these SDKs are integrated into smart TV apps, coupled with potentially vague consent mechanisms, opens the door for exploitation. Concerns are amplified when considering that these proxy services could be used for malicious activities, such as bypassing geo-restrictions for illicit content, conducting denial-of-service attacks, or engaging in fraudulent online activities, all of which could be traced back to the unsuspecting user’s IP address.
LG Electronics USA Responds to Security Concerns
In direct response to KrebsOnSecurity’s inquiries regarding Spur’s findings, LG Senior Vice President John Taylor articulated the company’s stance and immediate action plan. Taylor confirmed that LG Electronics is actively collaborating with app developers to ensure the removal of residential proxy functionalities from their applications on the webOS platform. He unequivocally stated that failure to comply with this directive would result in the suspension of the offending applications.
"A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor stated in a communication to KrebsOnSecurity. "If this option is not removed, these apps will be suspended."
Taylor further emphasized LG’s commitment to preventing the recurrence of such issues, assuring that the company is implementing more robust evaluation processes for developer-submitted applications. This proactive approach aims to bolster platform quality and enhance the overall user experience, ensuring that smart TVs remain secure and privacy-respecting devices. The review of existing applications is described as "well underway now," indicating a sense of urgency and a clear commitment to remediation.
"As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor elaborated in his emailed statement. This suggests a long-term strategy to prevent similar vulnerabilities from emerging in the future, by tightening the gatekeeping and vetting procedures for applications seeking entry into the LG app store.
The Monetization Model Behind Residential Proxies
The integration of residential proxy SDKs into smart TV apps is often driven by developers’ desire to monetize their creations. Companies that operate residential proxy networks pay app developers to embed their SDKs, which then enable users’ devices to act as proxy nodes. These nodes are subsequently rented out to a diverse range of paying customers.
Spur’s research provided concrete examples of this practice, noting that these proxy SDKs were found bundled with a wide array of applications, ranging from classic games like Pac-Man to simple screensavers and file management utilities. This broad integration across different app categories underscores the pervasive nature of the issue and the potential for widespread impact on consumers.

Bright Data: A Major Player in the Residential Proxy Market
The security firm Spur identified Bright Data as a dominant force in the residential proxy network landscape, accounting for a significant majority of the proxy SDKs found on both LG and Samsung smart TVs. In a statement provided to KrebsOnSecurity, Bright Data defended its practices, asserting that its network is built upon principles of consent and responsibility, and that its operations adhere to the terms set forth by LG and Samsung.
"Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC," a Bright Data spokesperson stated. "We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain."
Bright Data and other proxy providers mentioned in Spur’s report maintain that they implement stringent know-your-customer (KYC) protocols to verify the legitimacy of their service users. These protocols are often linked to content-scraping activities undertaken by their clientele. Furthermore, these proxy companies claim to employ technological safeguards designed to prevent customers from accessing or controlling other devices on the user’s local network, mitigating the risk of lateral movement and unauthorized access within a user’s home network.
The Ethical Quandary of Smart TV Proxies
Despite the assurances from proxy providers, cybersecurity experts like Trevor Sutter of Spur express significant concerns about the ethical implications and inherent risks associated with embedding residential proxy functionalities in smart TV apps. Spur’s argument centers not on the existence of residential proxy networks themselves, but on their integration into devices that consumers do not typically perceive as computers and that lack robust auditing capabilities.
"A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Sutter argued. He further highlighted a critical vulnerability: "The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors." This points to a significant flaw in the consent model, where individuals who may not fully understand the implications of granting proxy access could inadvertently compromise their household’s privacy and security.
The ability for a user to grant consent through a single, often overlooked, prompt within an application does not equate to informed consent, especially when the device in question is a shared household entertainment hub. The long-term implications of such consent, particularly for children who may use the TV without parental supervision, are a serious cause for concern.
Broader Implications and Industry Trends
LG’s decision to address the residential proxy issue in its smart TV apps arrives amidst a broader trend of increased scrutiny on smart device manufacturers regarding privacy and security. Consumers are becoming increasingly aware of the potential vulnerabilities inherent in connected devices, and manufacturers are facing mounting pressure to ensure the integrity of their platforms.
This situation also highlights a growing tension between the desire for app developers to monetize their creations and the imperative to protect user privacy. While advertising and in-app purchases are common monetization strategies, the use of user devices as proxy nodes introduces a level of risk that many consumers may not be willing to accept, or even aware of.
The McAfee Incident: Another Privacy Concern for LG
Adding to a complex week for LG’s consumer electronics division, the company recently faced criticism for another questionable partnership involving the pre-installation of software drivers for McAfee security products on its high-end LCD monitors. The YouTube channel Gamers Nexus reported that certain LG LCD monitors automatically installed a McAfee application through Windows Update, without explicit user approval. This practice, which promotes paid antivirus subscriptions, raises concerns about unsolicited software installations and potential bloatware on user devices.
This incident, occurring shortly before the residential proxy announcement, suggests a pattern of partnerships that, while potentially offering value to consumers in some aspects, also raise questions about transparency and user consent in the deployment of third-party software and services.
The Path Forward: Enhanced Scrutiny and User Education
LG’s proactive stance on suspending apps with residential proxy SDKs is a positive development for consumer privacy and security in the smart TV ecosystem. The company’s commitment to strengthening its app evaluation process is a crucial step towards building greater trust and ensuring a more secure platform for its users.
However, the broader challenge remains. The prevalence of these SDKs across various smart device platforms underscores the need for continuous vigilance from both manufacturers and consumers. As the Internet of Things (IoT) continues to expand, users must be empowered with greater transparency and control over how their devices are utilized and how their personal data and network resources are accessed.
The industry as a whole needs to engage in a more robust dialogue about the ethical boundaries of app monetization and the responsibility of platform providers to act as guardians of user privacy. Enhanced regulatory oversight, coupled with improved user education on the implications of app permissions and SDK functionalities, will be critical in navigating the evolving landscape of connected technologies and ensuring that innovation does not come at the expense of fundamental privacy rights. The ongoing efforts by LG represent a significant stride in this direction, but the journey towards a truly secure and transparent smart device ecosystem is far from over.





