A new LG monitor triggering an automatic Windows companion app with a McAfee ad is more than an annoying popup. It is a reminder that hardware setup has become a software supply chain, and users often do not get meaningful control over what vendor utilities, ads, telemetry, and startup apps arrive when they connect a device.
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
Welcome to the Shared Security Podcast, the longest running cybersecurity and privacy show
for actual humans.
No jargon, no hype, just honest analysis from industry veterans who've seen everything
and survived it.
Each week we break down the stories that matter, expose the nonsense that doesn't, and give
you the tools to stay safe in a world where everything is connected and nothing
is guaranteed.
This is Shared Security.
Today on Shared Security we're talking about something that sounds like a punchline but
is actually a pretty good example of where consumer tech, security and privacy all collide.
You plug in a new monitor, Windows automatically pulls down a vendor companion app, and the
first thing you see is one of those damn Mac fjads.
Man, can't get rid of them, right?
Well, this sounds like an annoying bloatware story, but underneath is a bigger question.
Who gets to put software on your computer just because you connected a piece of hardware?
Drivers and companion apps can be useful, but when that trusted setup path becomes
an advertising channel, users lose visibility and control.
So we'll be talking about that, and we'll also touch on a related Brian Krebs story
that Scott happened to send over about LG Smart TV apps being used as residential proxy nodes.
So what the hell is going on here with LG, right?
Well joining me to explain everything in full detail are my two co-hosts, Scott Wright
and Kevin Tackett.
Everyone's back.
Look at this.
This is my front.
Oh, the front.
Yes.
Yeah.
So confusing.
We don't want to see the back.
No, no, you don't want to see the front.
I just want to point out that we're going to make fun of LG quite a bit here.
We will.
But the reality is I don't know of a quote unquote smart television
that doesn't fall into this.
This category of really thanks.
It's true.
I actually just bought last weekend a I&Ear television,
which I even said to the guy at Best Buy, like I thought Pioneer was just radios in your
car.
Yeah, I've never heard of a Pioneer TV.
That's interesting.
Neither have I.
And it was a good price and it's it's Roku based.
OK.
Yeah.
And I'm not and I want to be very clear for those listening, not a sponsor, not
recommending.
So it's not that they're bad.
I just I have no recommendation.
It's a TV that sits there.
You turn it on videos play.
And hopefully it doesn't take more than you wanted to.
Yeah, yeah.
The stuff that's built into these televisions, I recently had to buy a
small television for another reason.
I I feel as I've recently bought a lot of TVs.
But let's ignore that.
And I and I this is the small television was just a
I need a machine right there so we can hook the Nintendo Switch to it
and not worry about it and have a way to play in my office.
When the Walmart picked up the cheapest television they had that fit
the size I wanted and ran home real quick and plugged it in,
turned it on, and it immediately said to use this television.
You need a Walmart dot com account.
And I'm like, I need a what all smart TVs have this issue.
LG seems to be the one that we're going to make fun of right now.
Right.
I do think the idea of being able to proxy traffic through random
people's television seems like a bad plan.
I mean, as a pentester, I think it's pretty cool.
But no, no, not as a pentester as a pentester.
OK, let me ask you, Tom, you negotiating that in scope IP addresses
with your client. True.
Them televisions scattered around Orange Park.
I'm just saying my clients TVs. That's what I was looking at.
In that case, no.
Start out, start out, start out.
stars and scope. Hey, yeah, it's fine. It's fine. This is the risk that most people don't
think about. But the minute you have a device, television, phone, whatever, that you allow
basically anybody with a development account to publish an app that then gets downloaded
to your embedded device, TV, whatever, you run the risk of a malicious person
pushing something down. And it doesn't even have to be a malicious person building
the app. Yeah, the person building the app might have a stub intentions and have
this idea like, hey, I have a great thought about how this can work. And
then all of a sudden, some jerk like Tom comes up with a way to proxy
traffic through it, right? The ecosystem, I don't know if that's the
right word. But the ecosystem around embedded systems. So, you know, like the
supported apps, the third party ecosystem is just scary as heck, if you're worried
about privacy and security. And we hear all the time, well, Apple vets things,
Google vets things, I'm like, really? You know, yeah, they do. But they even
say we're only going to take it to here. We're not gonna stuff this
and the bad guys are always looking for ways to weaponize that stuff. And this
is a recurring theme that we've had on the on the show for maybe over a decade.
Yeah, the dolls that you know, you could, you know, program to record a saying
and it would speak, you know, in content. I'm still not allowed to discuss
those dolls. Yeah, you're banned. Kids dolls, I'm talking about. Okay.
Though I know you're talking about the kids dolls contractually, I'm
not allowed to talk about those dolls. Right? Yeah, so weaponization of
these devices that are, as you say, embedded, not as visible. And I have
a question for you guys just about the context of the first part of this
episode where we're talking about the ability to put in apps in the app
store that end up on the it's not clear to me if that ad for the Mac
if you add, is that popping up as a result of the processor in the monitor? Or
is that something that is triggered in the computer? So how I read it is that
as soon as you plug in a LG monitor, it goes automatically like windows will
detect that this is an LG monitor and it goes out to the windows
computer or acting. Yes. Okay. Yes. To pull down basically the driver
package, but it's like an app store package. Yeah. And what I've what and
how this this plays out is, it basically serves you this ad, essentially
saying, Hey, install this McAfee thing, right? Antivirus like the typical
thing you see. But it's triggered by you purchasing this monitor. The
thing that I think is is key thing that many people don't talk about very
often is that modern accessories or you know, peripherals, I think is the
right word for your computer back in the day, right? You would buy a sound
blaster and you'd flip some dip switches and you'd plug it in and you'd put
the disk get in the floppy disk ad and you install the drivers and you
might install some some software that came with it as well, whatever. And
that was the process. And I mean, it was a process that was
complicated enough for for many people that there was an entire market. I
made money doing that for people. And and then we got to the point where the
computer would detect the new peripheral and go out to the internet and
pull down the drivers. And over the last, I don't know how long, let's
say decade, maybe less than that, maybe more than that. But instead of
pulling down drivers, it pulls down an entire suite of applications that
includes the drivers. I'll pick on I just I just got a new laptop. I had a I
had a hardware issue with my laptop. We tried rebuilding it fixing it. Finally,
I got a new laptop. And the laptop I got is Lenovo. And nothing about
Lenovo. This isn't a complaint about them or anybody else. And but my
keyboard is a razor keyboard. Okay, I like the clickiest nest and
that's what I got. laptop plug it in, do all the reboots, get all the
drivers, everything else installed. I plug in the keyboard. And
immediately. Yep, it is pulling down not just keyboard drivers to
control it, but a collection of tools, cortex synapse. I don't even
know the other names, right? Now, a big part of them, they're
there to control the lights on my keyboard, because I want a rainbow
of colors to take all through on my keyboard constantly. You
didn't have a choice about pulling that stuff down. It just
came down. And my read of this LG articles, that's what
happened. It wasn't a set of drivers. It was a suite of
applications that included the drivers. And one of the things it
did was prompt you to install McAfee. Now, I will point out
because unlike some people, I won't name any names. I have zero
problems pointing out that McAfee has decades of working
with partners to embed the McAfee install, you went to
Best Buy, and you bought anything and you got handed a CD
ROM that had McAfee in it. For a while there, I don't know if
it's still this way. For a while there, if you downloaded the
Java runtime environment and installed it, there was a check
box to install McAfee. I think Adobe had the same thing. You
can get PDF reader and McAfee. And I want to point out, and
I will say this for the record, because we're recording
it, I do not believe there's been any time in my life that
I have ever thought to myself or recommended to anybody else,
you should run McAfee.
Yeah, never.
Which is why they as a company are forced similar to cold
collars and spammers, they are forced to get other people to
sneak it in, right? Because nobody in their right mind
would install this software directly. Just my opinion.
Yeah. And what's even more sad is John McAfee, the founder of
McAfee, may he rest in peace by the way, he is dead. But John
McAfee had nothing to do with the company after he sold it.
This was for what, years and decades, and he would even
post videos getting mad at McAfee for exactly what you
said, Kevin. And it's his own name in the company.
Mobile apps are just part of everyday life now. Banking,
healthcare, shopping, entertainment, you name it. And
with that comes a lot of trust, because users are putting
their personal data directly into your app. But here's the
reality. Mobile apps are a growing target. A recent
survey found that 72% of organizations experienced a
mobile app security incident last year. And 92% say
threats are only increasing. And the way attackers are
going after apps is pretty sophisticated. They're reverse
engineering them, modifying them and redistributing fake
versions through phishing campaigns, side loading, and
even third party app stores. So from a user's perspective,
everything can look completely legitimate. That's why
taking a proactive approach to mobile app security really
matters. You want to stay ahead of these threats, not
react after the damage is done. This is where Guard
Square comes in. They provide advanced protection for
both Android and iOS apps, along with automated security
testing to catch vulnerabilities early and real time
threat monitoring so you can actually see what's
happening out there. If your mobile app is critical to
your business, and it probably is, this is
something worth paying attention to. You can learn
more at GuardSquare.com. That's GuardSquare.com.
I think another example of that is printers,
right? Every time you get an HP printer or
whatever, it installs a whole bunch of stuff off either
off the, used to be the DVD, but now it's probably
doing the same thing, grabbing as much as it can
from the support site to run on your computer. So
yeah, that's one aspect of what we're talking about
here is the unauthorized installation, call it, of
AdWare or potentially worse stuff. But yeah, the
other story from Brian Krebs was around the
discovery that through a, I guess it's through an
app store of some kind of WebOS app store, I think.
Built into LG TVs, yeah. Yeah. I think it's just
LG TVs. I don't know if there's anything else, but
so people are finding ways to install, essentially
what ends up being a household proxy that you
don't know about. And in this case, again, I
don't know, I suspect it's the TV, right?
Well, what's interesting is these are actually
built into the apps as a way to get rid of ads. So
like in the article, they had an example of the
Pac-Man application, which is the game, it's
Pac-Man. And they literally say in a disclaimer,
if you want to get rid of ads, click here to
allow your TV to become a residential proxy.
Like they actually state it. Like, and so
what do people do? They're like, Oh, I want to
get rid of ads. Click the box. I just want to
play Pac-Man. And what's interesting to me is
like, the article doesn't explain like, what is
the purpose of the residential proxy? Meaning
What is the residential proxy?
I mean, I was just bowing porn.
I mean, I'm assuming it means that you're
allowing your TV to, maybe it's kind of like
that Amazon sidewalk feature where like it
spreads the network out so like your neighbors
can get, you know, better access. I'm not
really sure, but it just is bad. I wouldn't
say no, do not do this.
They're probably good and bad use cases, but
it's easier to imagine the bad ones.
Yeah. I mean, this this reminds me it's a
different name, whatever, but it reminds
me of like, you know, what was it?
World's a Warcraft used tour?
Yes. Yes. Right. Like, like you wow
client was actually sharing the client with
other people to to reduce.
I think it was World of Warcraft, right?
That was doing that. And but that was a
we understood it. Well, OK, we understood
it. I don't know that everybody did, right?
Like, that was something you accepted.
Like, yeah, OK, no problem.
I, you know, it was like companies
leveraging the BitTorrent system to
lower their own network costs.
Right. Right. Yeah.
Or imagine this is the same.
Yeah, SETI at home.
Remember the screensavers that you could
download to help find alien, you know, UFO
signals in space or the cure for cancer one.
Right. Yeah. Like, yeah.
Right. Wasn't it wasn't it us that discussed
the the SETI at home that was designed
around hacking Russian systems
to start the Ukrainian war?
Long time ago. Yeah.
Yeah. Yeah. Some time ago.
Yes. So so I was going to ask
like, do we have any tips or guidance
around anybody who has, you know, an LGTB
that might be hit them with a hammer?
Yeah, destroy them with fire.
Yeah. All seriousness.
I mean, we can talk about things,
but it's the same in my opinion.
And Tom, correct me if you disagree.
But in my opinion, this is the same
advice we're going to give with any other system.
Think about what you want to use it for.
Think about what you want to install on it.
Be reasonable and accept and understand
the risk you're opening yourself up to is that you're.
So like what I would recommend for most people
and we've recommended this before is that
evaluate how your network works, right?
Like you have a wireless network, right?
And check to see if if your network solution,
whether it's your TP-Link or your, you know, whatever.
I don't care.
Do they have some way to segment
things like smart TVs and stuff like that
away from your laptops and your devices that you care about?
Because I'm not doing online banking on my LGTB period, right?
But I am doing online banking on my laptop.
So I've segmented those two things
that they can't talk to each other to the best of your ability.
And that would be something within your network
system for less.
That's the best I can give you
because you don't have a lot of control over what the TV does.
Right. So I do have a question then.
So for less technical people who find themselves owning a TV
that happens to be, you know, affected or vulnerable.
First of all, will the TV work without you logging in or giving it any access?
It depends. I'm not anymore. Yeah, it depends.
Most likely a lot of these TVs know
like you can't use Netflix.
You can't use the apps until you agree to their policies.
You have to click through terms of service.
I mean, it's getting worse.
I can tell you that because every TV I've bought over the last several years
has gotten more invasive and there's to get out of those policies
and to like turn off like ads and all those things.
They're buried in the system settings.
And that I think that's one of my recommendations.
I was going to say people that are less technical is
you just got to go into your TV and you have to dig through the settings
and turn those things off. Yeah. Right.
Unless and some just kind of force you into you have to agree to these policies.
Otherwise, you just your TV becomes a dumb TV and you can't do anything.
Not even or won't even be a dumb TV, right?
Right. Like that that I think it was a TCL
television that I bought that works wire to wall.
I could not get past that screen without signing into Walmart.
I couldn't that could not figure out a way to just say no.
Right. Let me let me because all I was doing,
all I wanted was a display for the Nintendo Switch.
I don't have any hair.
You couldn't even plug in like a video out terminal into it and have a display.
The screen can log into this account.
I don't have a wall at the time.
I didn't have a Walmart.com account now.
So for the less technical people, the other thing I would say is one,
every less technical person I know has a computer friend.
Talk to your computer friend about your network.
If you can't do that, if you just hate people and people hate you,
me and you have to do something in your less technical,
a way to do segmentation
is to actually buy a different wireless device.
So let's say that you have a TP link device attached to your fiber connection.
Right. You can buy another different wireless device,
plug it into the device you have plugged into your
fiber, your cable, whatever and configure that as a completely different SSID
for an access point basically. Yeah. Yeah.
Right. So you would.
So now you literally have two wireless networks
and they would treat each other as external to each other.
Right. I think I said that right.
That is a I won't say it's a cheap way to do this.
It is the one of the less technical way to do it. Right.
You just and then you have two networks.
You connect to that one for your embedded stuff.
You connect to this one for your laptops,
your computers and your tablets that you care about using securely.
And then you just go that route that I don't like that answer.
But that is an answer.
If if either your network equipment doesn't support segmentation,
it's sometimes called guest networking or whatever.
If it doesn't support it or if you just don't know how to do it.
And I'll give you an example.
A lot of the less technical people,
they'll sign up for something like AT&T fiber and AT&T fiber will give them
a wireless access point that AT&T configures and manages and stuff like that.
They may I don't know what access they have,
but they may not have access to do the segmentation
and they would have to do this second option.
It's the best answer I've got. Sorry.
Yeah, or just go to like a thrift shop or something and find one of those old
CRT TVs, you know, tube TVs, which does not have ads because it's
that's literally the definition of a dumb TV.
And in fact, I mean, as somebody who sells and collects retro gaming
video games consoles, I have literally like three or four CRTs sitting around.
And I have seriously considered like plugging that back in
because I am so annoyed at these modern TVs.
And honestly, I think it's a great business idea for some company
to come out and sell a dumb like LCD
flat screen TV with no with nothing like like a monitor.
It's just a computer monitor, essentially, but it's 86 inches.
What if you could do an OEM deal, use the ones,
the cheapest ones are on the market and then put some kind of hardware
or software around the core of it to protect it from.
Oh, doing any weird stuff.
That'd be there. You have it.
Yeah, contact Scott to there we go for a new startup in Canada.
Proxy TV, something or another. Yes.
Yeah, I like it. I like it.
All right, everyone.
Well, I think that's all we have time for today.
Great topic and for anybody that has comments about this topic,
if you have ideas of, you know, how how can we make this better?
Is there any solution that you think of or what advice would you give
your friends and family when it comes to dealing with smart TV ads
and proxied servers and all this fun stuff?
Please let us know in the comments on YouTube
or you can send us an email at feedback at sharedsecurity.net.
And go check out the comments to see what.
Yeah, yeah, please do.
There's always fun comments.
And I also got great feedback from my request for for comments
on the digital legacy tree. Great.
So yeah, really happy to hear from people and love to hear,
especially ideas around people who, you know, they know it's an important
thing to do. They just haven't got around to it yet.
And so I'd love to hear any of your excuses
for why you haven't created your own digital legacy file.
Awesome. All right, everyone, well, thank you for listening.
And until next time, stay safe, stay secure and stay private.
Thank you for listening or watching.
If you like this episode, hit subscribe, share it with your friends and colleagues
or jump into our community at sharedsecurity.net
slash supporter to keep the conversation going.
Thanks again, and we'll see you next week for another episode of Shared Security.